X-Git-Url: https://git.stderr.nl/gitweb?a=blobdiff_plain;f=etc%2Fdefault%2Fspamassassin;h=9c161389a38ac6ea18617e62c0359766b29f1be2;hb=82efcc09270561838217672592dbe6e651aafa88;hp=b61c44b43cad05712ca283568f1a41f2614492ae;hpb=2f2a8ce796aa85df8b6ecea7c526aa60755db0f6;p=matthijs%2Fservers%2Fdrsnuggles.git diff --git a/etc/default/spamassassin b/etc/default/spamassassin index b61c44b..9c16138 100644 --- a/etc/default/spamassassin +++ b/etc/default/spamassassin @@ -14,7 +14,14 @@ ENABLED=1 # make sure --max-children is not set to anything higher than 5, # unless you know what you're doing. -OPTIONS="--create-prefs --max-children 5 --helper-home-dir" +# We run spamd as the user "spamd", which was created specifically for running +# spamd, using: +# adduser --system --home /var/lib/spamd --disabled-login --disabled-password spamd +# By default, spamd runs as root, dropping privileges to whatever username the +# client claims to have, which is not-so-secure IMHO. There shouldn't be any +# any clients other than exim that can access spamd, but since we don't store +# any user preferences, let's just run as an unprivileged user. +OPTIONS="--create-prefs --max-children 5 --username spamd" # Pid file # Where should spamd write its PID to file? If you use the -u or