]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/exim/templates/default/exim4.conf.erb
Avoid using tainted data to construct file names in exim configuration
[chef.git] / cookbooks / exim / templates / default / exim4.conf.erb
index ab832999d6d977aca5700efd6e7104380dd62121..17160ecf3a4290fb45711cb595b5256ef56bfb1e 100644 (file)
@@ -710,7 +710,7 @@ remote_smtp:
 
 signed_smtp:
   driver = smtp
-  dkim_domain = ${lc:${domain:$h_from:}}
+  dkim_domain = ${lookup{${domain:$h_from:}}partial-lsearch{/etc/exim4/dkim-domains}{$value}}
   dkim_selector = ${lookup{$dkim_domain}lsearch{/etc/exim4/dkim-selectors}{$value}}
   dkim_private_key = /etc/exim4/dkim-keys/${dkim_domain}
   dkim_identity = ${lc:${address:$h_from:}}
@@ -768,7 +768,7 @@ noreply:
   to = $sender_address
   subject = Re: $header_subject:
   headers = MIME-Version: 1.0\nContent-Type: text/plain; charset=utf-8
-  file = /etc/exim4/noreply/$local_part
+  file = /etc/exim4/noreply/$local_part_data
   user = Debian-exim
   group = Debian-exim