Re: Grsecurity, ssh and postfix

On Fri, 5 Dec 2003 21:45:01 +0100
Florian Weimer <fw@deneb.enyo.de> wrote:

> The privilege separation code invokes chroot(), too.
> Is there a "do not create any new file descriptors" process attribute
> in grsecurity?  If there is, OpenSSH should toggle instead of calling
> chroot() to an empty directory, which is a poor replacement.


Thanks for your explanation but i don't know how to do that with
grsecurity. I am looking after this.

I have done a chroot environment for ssh to log in for fetch, read and
send mails with mutt, procmail, fetchmail and postfix. But i would like
to know how i can integrate postfix to this chroot environment. Could
you give me some advices about this ?

