Package: tripwire
Version: 2.3.1.2.0-10
Severity: grave
Justification: renders package unusable


If you use the emailto= option and email-report mode in your tripwire 
daily cron job on a Debian Etch machine to get reports on tripwire 
anomalies, you will not receive them.

This is the only way I have come accross to make it work if you *dont* 
receive the root@ email, and hence have to route directly from tripwire
to a remote address.

Because they will be sent out with the short host name, exim will go on 
to reject them with log entries of the form:

2008-09-13 13:07:27 1KeTuG-00087b-3C ** [EMAIL PROTECTED] 
R=dnslookup T=remote_smtp: SMTP error from remote mail server after RCPT 
TO:<[EMAIL PROTECTED]>: host mailhost.DOMAIN.COM [X.Y.Z.Q]: 
553 5.1.8 <[EMAIL PROTECTED]>... Domain of sender address 
[EMAIL PROTECTED] does not exist

I believe that this is a tripwire issue, and not an exim4 issue, because 
it makes no sense to use the short hostname for emailing to external 
addresses.

Wherever it is deemed the fault lies, I would be interested in secure 
workarounds for this in the short term. Adding SHORT-HOSTNAME into 
exim's MAIN_LOCAL_DOMAINS or whatever it is seems overkill? I'm going to 
try a local alias to the desired remote address for the time being.

K.

-- System Information:
Debian Release: 4.0
  APT prefers stable
  APT policy: (990, 'stable')
Architecture: i386 (i686)
Shell:  /bin/sh linked to /bin/bash
Kernel: Linux 2.6.18-4-686
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)

Versions of packages tripwire depends on:
ii  debconf [debconf-2.0]  1.5.11etch2       Debian configuration management sy
ii  exim4                  4.63-17           metapackage to ease exim MTA (v4) 
ii  exim4-daemon-heavy [ma 4.63-17           exim MTA (v4) daemon with extended
ii  libc6                  2.3.6.ds1-13etch7 GNU C Library: Shared libraries
ii  libgcc1                1:4.1.1-21        GCC support library
ii  libstdc++6             4.1.1-21          The GNU Standard C++ Library v3

tripwire recommends no packages.

-- debconf information:
* tripwire/rebuild-config: true
  tripwire/email-report:
  tripwire/broken-passphrase:
* tripwire/installed:
  tripwire/site-passphrase-incorrect: false
* tripwire/use-localkey: true
  tripwire/change-in-default-policy:
* tripwire/use-sitekey: true
  tripwire/upgrade: true
* tripwire/rebuild-policy: true
  tripwire/local-passphrase-incorrect: false



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to