--- postfix_org 2008-07-14 04:43:40.000000000 +0200
+++ postfix 2008-07-14 02:05:07.000000000 +0200
@@ -12,7 +12,8 @@
start() {
ebegin "Starting postfix"
- postfix /usr/sbin/postfix start >/dev/null 2>&1
+ run-jail postfix /usr/sbin/postfix start
+ #>/dev/null 2>&1
eend $?
}
@@ -24,6 +25,7 @@
reload() {
ebegin "Reloading postfix"
- postfix /usr/sbin/postfix reload >/dev/null 2>&1
+ run-jail postfix /usr/sbin/postfix reload
+ #>/dev/null 2>&1
eend $?
}
;
; RSBAC JAIL definition for postfix
;
; 20061025 20111301
;
; Installed versions: 2.7.4(19:13:06 13.05.2011)(hardened pam sasl ssl -cdb -doc -dovecot-sasl -examples -ipv6 -ldap -mbox -mysql -nis -postgres -selinux -vda)
;
; Testers:
; Jens Kasten (igraltist)
; Peter Busser (peter)
;
; tested on gentoo(hardened)
;
""
""
(allow-dev-read
allow-dev-write
allow-netlink
allow-ipc-syslog
allow-external-ipc
allow-inet-raw
)
(net-bind-service
setgid
setuid
dac-override
chown
kill)
()
(rlimit)
Deprecated:
;
; RSBAC JAIL definition for postfix
; 20061025
;
; Testers:
; Jens Kasten (igraltist)
; Peter Busser (peter)
;
""
"0.0.0.0"
(allow-external-ipc
allow-dev-read
allow-dev-write
allow-ipc-syslog)
()
()
(rlimit)
This is execute now:
rsbac_jail -i -d -D -y -M rlimit /usr/sbin/postfix start
postfix/postfix-script: starting the Postfix mail system