Welcome!

Linux Containers Authors: Liz McMillan, Lori MacVittie, Carmen Gonzalez, Pat Romanski, Elizabeth White

Related Topics: Linux Containers

Linux Containers: Article

qmail

Delivering security and performance

In the area of Mail Transfer Agents (MTAs), most people would look at sendmail as the most popular solution in the open source/Linux arena. However, it's not the only solution. Although postfix is popular with a number of administrators (especially those with multiple domains and many users), qmail is the unknown underdog that the experts use.

John Levine, well-known book author and Internet guru, talks about his new book, qmail, which covers the entire gamut of qmail administration from installation to configuration and filtering.

LWM: Another title in the successful mail-management series. Can you tell me the main benefits of qmail over other MTAs such as sendmail?

John Levine: qmail's two strongest points are security and performance. qmail was designed and written by a computer security geek, and is small enough so that if you want, you can read all the source. There's never been a security bug in qmail, that is, one that lets one user damage another's mail or get access to unauthorized parts of the system.

In the kind of environment for which it was designed, with lots of bandwidth, qmail pumps out mail at a phenomenal rate. Dan Bernstein's original motivation for writing qmail was to get mailing list mail delivered fast, and it does that really well.

qmail has always struck me as complex to set up, but easier to manage in the long term. Is that a fair assessment?

It's not so much that it's complex to set up but that it's utterly different from sendmail. The basic configuration is pretty simple, but it's in a bunch of separate files rather than the barococo majesty of sendmail.cf.

The other problem in setting up qmail is due to its peculiar license that doesn't permit people to redistribute modified versions, so you have to pick up the original 1998 code and patch it to add new stuff. Fortunately, earlier this year several members of the qmail community put together netqmail, which combines qmail with a set of widely used patches and it's all you need.

Spam and UBE are obviously big headaches for managers today. What features does qmail support to help combat this?

Nothing built in, but just about every anti-spam scheme you ever heard of is available as a qmail add-on. Dan offers a program called rbldnsd that uses DNS blocklists like the SBL, and people add spam filters such as procmail, greylists, you name it. qmail's modular structure makes it easy to splice new features in.

Do you think there is a solution to spam, or is it something we'll all just have to live with?

There's certainly no magic bullet, but I think that combinations of technical and legal measures will eventually get it under control, although never make it completely go away.

You're a long-time author, well known for a large number of titles and the Internet Gurus group. Can I ask you how you manage the mountains of e-mail you must receive?

It's all standard Unix tools. I use procmail to sort my mail, Pine to read it, and I put most of the mailing lists to local newsgroups so I can read them with trn.

qmail handles a dizzying array of potential delivery and mail routing options. What's the best way to approach a new installation?

Start with a basic installation, then figure out what extra stuff you need. The configuration is mostly driven out of text files so it's easy enough to add new bits to your configuration. You'll also find that once you get some experience with qmail, what you want to add will be more evident.

Migration from an existing setup seems even more complicated. Is there some way of easing the migration from sendmail or postfix?

 Well, there is a chapter in my book on it. You have to figure out what your current setup is doing, then run down the list and make qmail do all the things you care about. I've often found that old sendmail setups have mountains of cruft, and you can throw a lot of it away when you see what your mail system is really doing.

You cover both IMAP and POP in your book. Which do you recommend?

Depends on your usual connection. If it's on a LAN or broadband, IMAP rocks, particularly if you're using one of the Maildir-based IMAP servers (Courier or binc) that supports multiple simultaneous sessions. I can have Pine on my BSD box, Thunderbird on my PC, and Web mail all open at once, and it just works, all viewing the same mailboxes.

On the other hand, if you do dialup, you're still better off with POP since IMAP can be painfully slow over a slow connection.

Could you tell us what we can expect to see from you next?

Internet for Dummies, fabulous all new 10th edition coming next summer.

About John R. Levine

John R. Levine writes, speaks, and consults on the Internet, electronic mail, cybersecurity, and related topics (www.johnlevine.com).

More Stories By Martin C. Brown

Martin C. Brown is a former IT director with experience in cross-platform integration. A keen developer, he has produced dynamic sites for blue-chip customers, including HP and Oracle, and is the technical director of Foodware.net. Now a freelance writer and consultant, MC, as he is better known, works closely with Microsoft as an SME; has a regular column on both ServerWatch.com and IBM's DeveloperWorks Grid Computing site; is a core member of the AnswerSquad.com team; and has written books such as XML Processing with Perl, Python and PHP, and the Microsoft IIS 6 Delta Guide.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
Unsecured IoT devices were used to launch crippling DDOS attacks in October 2016, targeting services such as Twitter, Spotify, and GitHub. Subsequent testimony to Congress about potential attacks on office buildings, schools, and hospitals raised the possibility for the IoT to harm and even kill people. What should be done? Does the government need to intervene? This panel at @ThingExpo New York brings together leading IoT and security experts to discuss this very serious topic.
Internet of @ThingsExpo has announced today that Chris Matthieu has been named tech chair of Internet of @ThingsExpo 2017 New York The 7th Internet of @ThingsExpo will take place on June 6-8, 2017, at the Javits Center in New York City, New York. Chris Matthieu is the co-founder and CTO of Octoblu, a revolutionary real-time IoT platform recently acquired by Citrix. Octoblu connects things, systems, people and clouds to a global mesh network allowing users to automate and control design flo...
Everyone knows that truly innovative companies learn as they go along, pushing boundaries in response to market changes and demands. What's more of a mystery is how to balance innovation on a fresh platform built from scratch with the legacy tech stack, product suite and customers that continue to serve as the business' foundation. In his General Session at 19th Cloud Expo, Michael Chambliss, Head of Engineering at ReadyTalk, discussed why and how ReadyTalk diverted from healthy revenue and mor...
SYS-CON Events has announced today that Roger Strukhoff has been named conference chair of Cloud Expo and @ThingsExpo 2017 New York. The 20th Cloud Expo and 7th @ThingsExpo will take place on June 6-8, 2017, at the Javits Center in New York City, NY. "The Internet of Things brings trillions of dollars of opportunity to developers and enterprise IT, no matter how you measure it," stated Roger Strukhoff. "More importantly, it leverages the power of devices and the Internet to enable us all to im...
Information technology is an industry that has always experienced change, and the dramatic change sweeping across the industry today could not be truthfully described as the first time we've seen such widespread change impacting customer investments. However, the rate of the change, and the potential outcomes from today's digital transformation has the distinct potential to separate the industry into two camps: Organizations that see the change coming, embrace it, and successful leverage it; and...
The 20th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held June 6-8, 2017, at the Javits Center in New York City, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Containers, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal ...
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
You have great SaaS business app ideas. You want to turn your idea quickly into a functional and engaging proof of concept. You need to be able to modify it to meet customers' needs, and you need to deliver a complete and secure SaaS application. How could you achieve all the above and yet avoid unforeseen IT requirements that add unnecessary cost and complexity? You also want your app to be responsive in any device at any time. In his session at 19th Cloud Expo, Mark Allen, General Manager of...
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
Bert Loomis was a visionary. This general session will highlight how Bert Loomis and people like him inspire us to build great things with small inventions. In their general session at 19th Cloud Expo, Harold Hannon, Architect at IBM Bluemix, and Michael O'Neill, Strategic Business Development at Nvidia, discussed the accelerating pace of AI development and how IBM Cloud and NVIDIA are partnering to bring AI capabilities to "every day," on-demand. They also reviewed two "free infrastructure" pr...
Financial Technology has become a topic of intense interest throughout the cloud developer and enterprise IT communities. Accordingly, attendees at the upcoming 20th Cloud Expo at the Javits Center in New York, June 6-8, 2017, will find fresh new content in a new track called FinTech.
"Dice has been around for the last 20 years. We have been helping tech professionals find new jobs and career opportunities," explained Manish Dixit, VP of Product and Engineering at Dice, in this SYS-CON.tv interview at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
An IoT product’s log files speak volumes about what’s happening with your products in the field, pinpointing current and potential issues, and enabling you to predict failures and save millions of dollars in inventory. But until recently, no one knew how to listen. In his session at @ThingsExpo, Dan Gettens, Chief Research Officer at OnProcess, discussed recent research by Massachusetts Institute of Technology and OnProcess Technology, where MIT created a new, breakthrough analytics model for ...
"At ROHA we develop an app called Catcha. It was developed after we spent a year meeting with, talking to, interacting with senior citizens watching them use their smartphones and talking to them about how they use their smartphones so we could get to know their smartphone behavior," explained Dave Woods, Chief Innovation Officer at ROHA, in this SYS-CON.tv interview at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
"ReadyTalk is an audio and web video conferencing provider. We've really come to embrace WebRTC as the platform for our future of technology," explained Dan Cunningham, CTO of ReadyTalk, in this SYS-CON.tv interview at WebRTC Summit at 19th Cloud Expo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Whether your IoT service is connecting cars, homes, appliances, wearable, cameras or other devices, one question hangs in the balance – how do you actually make money from this service? The ability to turn your IoT service into profit requires the ability to create a monetization strategy that is flexible, scalable and working for you in real-time. It must be a transparent, smoothly implemented strategy that all stakeholders – from customers to the board – will be able to understand and comprehe...
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, provided an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life sett...
Successful digital transformation requires new organizational competencies and capabilities. Research tells us that the biggest impediment to successful transformation is human; consequently, the biggest enabler is a properly skilled and empowered workforce. In the digital age, new individual and collective competencies are required. In his session at 19th Cloud Expo, Bob Newhouse, CEO and founder of Agilitiv, drew together recent research and lessons learned from emerging and established compa...
The WebRTC Summit New York, to be held June 6-8, 2017, at the Javits Center in New York City, NY, announces that its Call for Papers is now open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo and @ThingsExpo. WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web co...
WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web communications world. The 6th WebRTC Summit continues our tradition of delivering the latest and greatest presentations within the world of WebRTC. Topics include voice calling, video chat, P2P file sharing, and use cases that have already leveraged the power and convenience of WebRTC.