KumoProxy security

Hi,

We are in the process of setup and trial of KumoMTA, we have one site which will run KumoMTA (+ supportive services) and a second site which will run KumoProxy, the KumoMTA site will socks proxy through KumoProxy at the second site, I notice there is no metion of auth for the proxy, is that by design? Is there another way to secure traffic? I’m assuming firewall ip allow list only?

Thanks!

+1, would be nice to have authentication. Currently, using a firewall, but would feel more comfy with a username/password.

Another option would be to create a WireGuard VPN and have your MTA and proxy join as clients, but sadly it adds another point of failure

At this time it is expected that users are limiting what traffic can reach the proxy. Authentication is not something that has been sponsored yet.

I created an issue for this. If you are interested in supporting it in some way, please note that in the issue or ping one of us.