Mercurial > dnsbl
view dnsbl.spec.in @ 48:5ef10dc14457
properly drop root privs
author | carl |
---|---|
date | Fri, 09 Jul 2004 13:57:59 -0700 |
parents | acbe44bbba22 |
children | 9f2971c692d0 |
line wrap: on
line source
Summary: DNSBL Sendmail Milter Name: dnsbl Version: 3.1 Release: 2 Copyright: GPL Group: System Environment/Daemons Source: http://www.five-ten-sg.com/util/dnsbl.tar.gz Patch0: dnsbl.rc.patch BuildRoot: %{_tmppath}/%{name}-%{version} Requires(pre): /usr/sbin/groupadd Requires(pre): /usr/sbin/useradd Requires(pre): /usr/bin/getent Requires(postun): /usr/sbin/userdel Requires(postun): /usr/sbin/groupdel Requires(post,preun): /sbin/chkconfig BuildRequires: sendmail-devel >= 8.12.1 Requires: sendmail >= 8.12.1 Requires: sendmail-cf %description We present here a mechanism whereby the backup mail server can use the correct set of DNSBLs for each recipient for each message. As a side-effect, it gives us the ability to customize the set of DNSBLs on a per-recipient basis, so that fred@example.com could use SPEWS and the SBL, where all other users @example.com use only the SBL. This milter will also decode (base64, mime, html entity, url encodings) and scan for HTTP and HTTPS URLs and bare hostnames in the body of the mail. If any of those host names have A or NS records on the SBL (or a single configurable DNSBL), the mail will be rejected unless previously whitelisted. This milter also counts the number of invalid HTML tags, and can reject mail if that count exceeds your specified limit. The DNSBL milter reads a text configuration file (dnsbl.conf) on startup, and whenever the config file (or any of the referenced include files) is changed. The entire configuration file is case insensitive. %prep %setup %patch0 -p1 %build pwd g++ -c $CXXFLAGS -pthread dnsbl.cpp g++ -o dnsbl dnsbl.o /usr/lib/libresolv.a -lmilter -pthread %install DST=%{buildroot} if [ "%{buildroot}" = "/" -o -z "%{buildroot}" ] ; then echo sorry, you probably do not want me to delete the old buildroot at %{buildroot} exit 1 fi rm -rf %{buildroot} mkdir -p %{buildroot}/etc/dnsbl install -m 644 dnsbl.conf %{buildroot}/etc/dnsbl/dnsbl.conf install -m 644 html-tags.conf %{buildroot}/etc/dnsbl/html-tags.conf install -m 644 tld.conf %{buildroot}/etc/dnsbl/tld.conf mkdir -p %{buildroot}/usr/sbin install -m 755 dnsbl %{buildroot}/usr/sbin/dnsbl mkdir -p %{buildroot}/etc/init.d install -m 755 dnsbl.rc %{buildroot}/etc/init.d/dnsbl mkdir -p %{buildroot}/var/run/dnsbl %pre /usr/bin/getent passwd dnsbl || useradd -r -d /etc/dnsbl -M -c "dnsbl pseudo-user" -s /sbin/nologin dnsbl #[JOG] Attempt to migrate an existing, non-rpm install. # WARNING! This may cause blindness, loss of appetite, and a general # feeling of ill will towards the author of this script. Please refer # to the Licence file for warranty information... if [ -f "/var/dnsbl/dnsbl.conf" -a ! -f "/etc/dnsbl/dnsbl.conf" ] ; then echo Existing installation found at /var/dnsbl/ Migrating configuation... # create the conf directory so rpm can find it in a minute... mkdir /etc/dnsbl/ # and try to copy all of the relavent config files that are below this directory cd /var/dnsbl/ grep '^include ' /var/dnsbl/dnsbl.conf | cut -d ' ' -f 2 | grep -v '^/' | xargs cp --target-directory=/etc/dnsbl/ /var/dnsbl/dnsbl.conf fi %post /sbin/chkconfig --add dnsbl /sbin/chkconfig dnsbl on /sbin/service dnsbl start echo Remember to edit /etc/dnsbl.conf and add the following line to your sendmail.mc: echo "INPUT_MAIL_FILTER(\`dnsbl\', \`S=local:/var/run/dnsbl/dnsbl.sock, F=T, T=C:30s;S:2m;R:2m;E:5m\')" echo %preun if [ $1 -eq 0 ]; then /sbin/service dnsbl stop || : /sbin/chkconfig --del dnsbl userdel dnsbl || : fi %postun %clean %files %defattr(-,root,root) %config /etc/dnsbl/ /etc/init.d/dnsbl /usr/sbin/dnsbl %dir %attr(0750,dnsbl,root) /var/run/dnsbl %changelog * Mon Jul 05 2004 John Gunkel <jgunkel@palliser.ca> 1.2 - Fixed some typos - removed patch into separate file - added config migration as suggested by Carl - Added reminder to edit sendmail.mc * Wed Jun 30 2004 John Gunkel <jgunkel@palliser.ca> 1.1 - Initial revision of spec file. Need to add a better description, docs and a sendmail.mc message