Showing posts with label proxy. Show all posts
Showing posts with label proxy. Show all posts

Wednesday, 11 April 2012

Getting Mac OS X to use google apps as a mail proxy

First of all, I have a macbook air which mails me everytime it wakes up, it's status and it's current IP.

I had this originally use my firewall at home as a mail proxy, but obviously, when am *not* at home, this doesn't work.

So what I configured is how to use google's mail server to act as my SMTP server over SSL - great huh?

I would suggest you setup a sub domain e.g. sub.domain.com so that it was it's own set of credentials and security, and doesn't use your main account (which will have admi rights for the entire domain) e.g. I own bobcats.org, and the address phil@bobcats.org, so I'll setup root@sub.bobcats.org as the subdomain and email address for my mac's admin account.

So what do you need to do?

*/ Setup postfix
*/ setup google
*/ setup DNS
*/ setup site verification (web)
*/ setup site verification (mail)
*/ Profit

Setup postfix

You'll need to setup a Simple Authentication and Security Layer (SASL)

vi /etc/postfix/sasl_passwd

with the following:
smtp.gmail.com:587 your.name@gmail.com:your.password

Create a postfix lookup table for SASL:
postmap /etc/postfix/sasl_passwd

Configure postfix with:

vi /etc/postfix/main.cf

with the following:
# Minimum Postfix-specific configurations.
mydomain_fallback = localhost
mail_owner = _postfix
setgid_group = _postdrop
relayhost=smtp.gmail.com:587
# Enable SASL authentication in the Postfix SMTP client.
smtp_sasl_auth_enable=yes
smtp_sasl_password_maps=hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options=

# Enable Transport Layer Security (TLS), i.e. SSL.
smtp_use_tls=yes
smtp_tls_security_level=encrypt
tls_random_source=dev:/dev/urandom

Setup google


This will involve going into your dashboard - just google "google apps"
add your (sub) domain into the domain tab of settings.

Setup DNS

Point DNS to a webserver that you own 

Setup site verification (web)

This will involve placing a specially crafted text file (supplied by google) onto that site


Setup site verification (mail)

This will involve adding a TXT record for the above (sub)domain

Profit

Saturday, 19 March 2011

Squid proxying for BBC iplayer and such...

Well this started as my friends will be moving back to their respective home countries.... they wanted to be able to stream bbc iplayer. This also enabled them to view BBC streams from Japan during the on going disaster...
First install squid (linux/win). Linux get the RPM or apt-get. Windows get the native port from http://squid.acmeconsulting.it/index.html

Ok... well on to the config!

Firstly, squid is being installed (2.7) compile or install the package

Despite what all the documentation says on the net - some of it is just plain god-damn wrong!

The important parts of the squid config are:
auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/squid_users
auth_param basic children 5
auth_param basic realm Phil's streaming proxy
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off

acl auth_users proxy_auth REQUIRED
acl all src all
acl all_others dst 0.0.0.0/0.0.0.0
acl safe_sites dstdomain "/etc/squid/allowed_sites"
# Only allow cachemgr access from localhost
acl filetypes urlpath_regex -i "/etc/squid/denied_files"
http_access allow purge localhost
http_access allow safe_sites
http_access deny purge

http_access deny to_localhost
http_access deny all_others
cache_dir null /tmp
cache_deny all


with allowed_sites:
.bbc.co.uk
.bbcimg.co.uk
.edgefcs.net
.llnwd.net
.markiza.sk
.itv.co.uk
.itv.com
.national-lottery.co.uk
.securesuite.co.uk

and the squid_users file full of htpasswd entries
 e.g.
phil:xxxxxxx
bob:xxxxxx


with denied_files in regex format:
\.(mp4)$