X-Git-Url: https://git.stderr.nl/gitweb?a=blobdiff_plain;f=etc%2Fdefault%2Fspamassassin;h=9c161389a38ac6ea18617e62c0359766b29f1be2;hb=c3fa043b03c641d2fb6997b8430786dd9af3fee8;hp=b61c44b43cad05712ca283568f1a41f2614492ae;hpb=1a2e7d393e64d34c4e2493a844f4bd99aeb3f335;p=matthijs%2Fservers%2Fdrsnuggles.git diff --git a/etc/default/spamassassin b/etc/default/spamassassin index b61c44b..9c16138 100644 --- a/etc/default/spamassassin +++ b/etc/default/spamassassin @@ -14,7 +14,14 @@ ENABLED=1 # make sure --max-children is not set to anything higher than 5, # unless you know what you're doing. -OPTIONS="--create-prefs --max-children 5 --helper-home-dir" +# We run spamd as the user "spamd", which was created specifically for running +# spamd, using: +# adduser --system --home /var/lib/spamd --disabled-login --disabled-password spamd +# By default, spamd runs as root, dropping privileges to whatever username the +# client claims to have, which is not-so-secure IMHO. There shouldn't be any +# any clients other than exim that can access spamd, but since we don't store +# any user preferences, let's just run as an unprivileged user. +OPTIONS="--create-prefs --max-children 5 --username spamd" # Pid file # Where should spamd write its PID to file? If you use the -u or