From Debian package 0.2.20091117-2 Updated in 0.2.20100524-6 Add dkim_stream_connect interface. Allow postfix to talk to dkim. This was present in Russell's old dkim module, which was superseded by upstream 5a6b1fe2 (2009-09-17) 0.2.20100524-6 * Fixed a bug in the previous release that stopped MTAs from talking to the dkim-milter, the .if file had the wrong type. Index: policy/modules/services/dkim.if =================================================================== --- policy/modules/services/dkim.if.orig +++ policy/modules/services/dkim.if @@ -1 +1,20 @@ ## DomainKeys Identified Mail milter. + +######################################## +## +## Connect to dkim-milter. +## +## +## +## Domain allowed to connect. +## +## +# +interface(`dkim_stream_connect',` + gen_require(` + type dkim_milter_t, dkim_milter_data_t; + ') + + stream_connect_pattern($1,dkim_milter_data_t,dkim_milter_data_t,dkim_milter_t) +') + Index: policy/modules/services/postfix.te =================================================================== --- policy/modules/services/postfix.te.orig +++ policy/modules/services/postfix.te @@ -618,6 +618,11 @@ ') optional_policy(` + dkim_stream_connect(postfix_smtpd_t) + dkim_stream_connect(postfix_cleanup_t) +') + +optional_policy(` sasl_connect(postfix_smtpd_t) ')