Re: [exim] IRC channel for Exim

2021-05-27 Thread Slavko via Exim-users
Hi, Dňa Wed, 26 May 2021 09:55:50 +0100 Jeremy Harris via Exim-users napísal: > We have used Freenode for an IRC channel (#exim) for many years. > Recent developments are making me consider a move, possibly > to irc.libera.chat (port 6697 for SSL; #exim). The channel > exists but I've not yet

Re: [exim] Obfuscating $authresults

2021-06-06 Thread Slavko via Exim-users
Hi, Dňa Sat, 5 Jun 2021 20:35:56 +1000 Richard Salts via Exim-users napísal: > I'm looking to obfuscate the smtp.auth=username and > smtp.remote-ip=x.x.x.x in messages which are authenticated. AFAIK, the authresults header is intended to record authentication results of incoming (remote)

Re: [exim] GnuTLS vs OpenSSL

2021-09-18 Thread Slavko via Exim-users
Ahoj, Dňa Sat, 18 Sep 2021 10:58:33 +0100 Sabahattin Gucukoglu via Exim-users napísal: > Is there really a good reason? I do it chiefly because I like > OpenSSL’s cipher selection (I want very permissive, ordered by > @STRENGTH, and TLS 1.3 would be nice). There were also horror stories > about

Re: [exim] GnuTLS vs OpenSSL

2021-09-18 Thread Slavko via Exim-users
Ahoj, Dňa Sat, 18 Sep 2021 18:25:07 +0200 exim-users--- via Exim-users napísal: > tls_require_ciphers = > PFS:SECURE256:SECURE192:-3DES-CBC:-CURVE-SECP192R1:-CURVE-SECP224R1:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1:-NULL:+VERS-TLS1.3:-MD5:%SERVER_PRECEDENCE:%FORCE_ETM I have something similar,

[exim] Failed DKIM without selector

2021-09-21 Thread Slavko via Exim-users
Hi, i use dual DKIm sign with RSA and ED25519 keys (the selectors are named with "r" and "e" at start respectively, to distinguish them). Recently i enabled receiving DMARC reports and i see from google (i didn't get from others yet), that the that RSA signatures passes and ED25519 DKIM

Re: [exim] exim.org still incorrectly configured

2021-10-16 Thread Slavko via Exim-users
Hi, Dňa Sat, 16 Oct 2021 16:43:57 +0100 "Adam D. Barratt via Exim-users" napísal: > FWIW, I've also seen two of these, at 23:53:41UTC yesterday and > 11:08:41UTC today. The server in question is running Debian's 4.92- > 8+deb10u6 exim4-daemon-heavy package and has "tls_sni" set in the log >

Re: [exim] exim.org still incorrectly configured

2021-10-16 Thread Slavko via Exim-users
Hi, Dňa Sat, 16 Oct 2021 17:22:30 +0200 Heiko Schlittermann via Exim-users napísal: > This hh.schlittermann.de runs the latest Exim, and probaby sends you > an SNI your server for some reason doesn't accept? My MX doesn't rejects emails based on SNI. It uses SNI to serve different

Re: [exim] How to use DKIM with Ed25519 - Dual DKIM signing

2021-10-14 Thread Slavko via Exim-users
Dňa 14. októbra 2021 14:50:23 UTC používateľ Odhiambo Washington via Exim-users napísal: >> | This sets the key selector string. After expansion, which can use >> | $dkim_domain, this can be a list. Each element in turn is put in the >> | expansion variable $dkim_selector which may be used

Re: [exim] DKIM d= field and corresponding key

2021-10-15 Thread Slavko via Exim-users
Dňa 14. októbra 2021 22:22:34 UTC používateľ Andy Bennett via Exim-users napísal: >Is there any reason why the default settings are not optimal? > >...and how to choose between relaxed and strict modes? I mean not optimal for me, of course. By derault "the header names listed in RFC4871 will be

Re: [exim] DKIM d= field and corresponding key

2021-10-14 Thread Slavko via Exim-users
Hi, Dňa Thu, 14 Oct 2021 14:34:19 +0100 Andy Bennett via Exim-users napísal: > I have been trying to find good resources for how DKIM is commonly > deployed on The Internet: all the DKIM RFCs and early guides seem to > shift almost all of the policy decisions to the implementors and >

Re: [exim] exim.org still incorrectly configured

2021-10-16 Thread Slavko via Exim-users
Hi, I am not sure if it is related to migration, but recently i start to see something as this in my exim log: TLS error on connection from hh.schlittermann.de [213.128.132.49] (gnutls_handshake): A disallowed SNI server name has been received. The recent one was today at 2021-10-16

Re: [exim] 15s delay after SMTP authentication

2021-12-23 Thread Slavko via Exim-users
Ahoj, Dňa Thu, 23 Dec 2021 12:21:06 +0300 Evgeniy Berdnikov via Exim-users napísal: > Looks like a resolver's timeout, probably while resolving > 5.45.110.153 to hostname. or the thunderleon EHLO? -- Slavko https://www.slavino.sk pgpGTX7I7lxwO.pgp Description: Digitálny podpis OpenPGP --

Re: [exim] 15s delay after SMTP authentication

2021-12-23 Thread Slavko via Exim-users
Ahoj, Dňa Thu, 23 Dec 2021 14:26:38 +0300 Evgeniy Berdnikov via Exim-users napísal: > On Thu, Dec 23, 2021 at 11:38:58AM +0100, Leon Fellows via Exim-users > wrote: > > I have started the daemon from commandline like this: > > exim -bd -q15m -d > > > > Now I get A LOT of debug messages. But I

Re: [exim] $local_part_data is empty

2021-12-20 Thread Slavko via Exim-users
Ahoj, Dňa Mon, 20 Dec 2021 19:35:19 +0100 Leon Fellows via Exim-users napísal: > local_parts = lsearch;/etc/mail/domains/$domain_data try: local_parts = /etc/mail/domains/$domain_data or: local_parts = lsearch,ret=key;/etc/mail/domains/$domain_data regards -- Slavko

Re: [exim] Exim4 delay at boot

2021-11-10 Thread Slavko via Exim-users
Hi, Dňa Wed, 10 Nov 2021 14:25:13 -0300 Fabio Martins via Exim-users napísal: > to see what it is querying, add those entries to /etc/hosts in the > exim-machine mostly items from /etc/mailname and /etc/hostname are enough to start exim "normally" ;-) eg: 127.0.0.1 localhost regards --

Re: [exim] Exim4 delay at boot

2021-11-14 Thread Slavko via Exim-users
Hi, Dňa Sat, 13 Nov 2021 20:07:36 -0300 JHM via Exim-users napísal: > Hello: > > On 13 Nov 2021 at 22:09, Jeremy Harris via Exim-users wrote: > > > > So, there's no IPv6 in the system or anywhere near it because I > > > disabled it. > I must insist on this: > IPv6 is explicitly disabled on

Re: [exim] Certificate validation failed

2021-10-30 Thread Slavko via Exim-users
Hi, Dňa Sat, 30 Oct 2021 02:56:40 -0400 Viktor Dukhovni via Exim-users napísal: > Thus: > > smtp_tls_security_level = none | may | encrypt | fingerprint | > dane | secure I think, that ideal MTA must have option: guess_tls_verify = no | user | admin in "admin" mode, it will reject

Re: [exim] Certificate validation failed

2021-10-30 Thread Slavko via Exim-users
Ahoj, Dňa Sat, 30 Oct 2021 07:11:18 -0400 Viktor Dukhovni via Exim-users napísal: > No. Rather than random ad-hoc policies, we implement and evolve > standards. Thus we have: It seems, that we are talking about different cases. You are talking about remote/foreign hosts, and i am talking

Re: [exim] Certificate validation failed

2021-10-30 Thread Slavko via Exim-users
Hi, Dňa Sat, 30 Oct 2021 00:01:39 +0100 Dominik Vogt via Exim-users napísal: > How can this be fixed or at least debugged? As you pointed elsewhere, you are using self signed certificate. Self signed certificates are OK with one exception, they can be validated only by self (as name

Re: [exim] Certificate validation failed

2021-10-30 Thread Slavko via Exim-users
Ahoj, Dňa Sat, 30 Oct 2021 13:38:40 +0100 Dominik Vogt via Exim-users napísal: > That says that all of these are undefined. So, to enforce TLS and > certificate verification I sould set > > MAIN_TLS_VERIFY_HOSTS = * > REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS = * yes > Somewhere at the

Re: [exim] How to determine 'acl_check_rcpt' failure point?

2021-10-26 Thread Slavko via Exim-users
Hi, Dňa Tue, 26 Oct 2021 18:17:09 +0200 Marco Gaiarin via Exim-users napísal: > and put HELO, MAIL FROM: and RCPT TO: by hand; and effectively the > ACL fail; at the last i have: I often store commands in that.file, eg.: EHLO somename MAIL FROM: RCPT TO: QUIT And then i

Re: [exim] Sender verify and Null MX (localhost.)

2021-11-03 Thread Slavko via Exim-users
Hi, Dňa 3. 11. o 4:30 Niels Kobschätzki via Exim-users napísal(a): > LOG: lowest numbered MX record points to local host: senderdomain.com (while > verifying from host rs224.mailgun.us > [209.61.151.224]) have you tried to play with "self", the generic router option? -- Slavko -- ## List

Re: [exim] Mailma3 integrations

2021-10-31 Thread Slavko via Exim-users
Hi, Dňa Sun, 31 Oct 2021 23:06:24 +0530 Sherin A via Exim-users napísal: > if we can setup a reverse look up exclude for host localhost , it > will be nice. it seems, that you know very little about DNS: host localhost localhost has address 127.0.0.1 localhost has IPv6 address ::1 host

Re: [exim] Mailma3 integrations

2021-10-31 Thread Slavko via Exim-users
Hi, Dňa 31. októbra 2021 18:31:59 UTC používateľ Sherin A via Exim-users napísal: >It looks like you are not familiar with internet severs. I really don't >want to setup a local or intranet resolver and revese dns lookup server >for localhost. The best practice for MTA is to have own

Re: [exim] Mailma3 integrations

2021-10-31 Thread Slavko via Exim-users
Dňa 31. októbra 2021 13:33:41 UTC používateľ Sherin A via Exim-users napísal: >   Everything on mailmal3 is ok , except exim is not delivering to >mailman lmtp service on 127.0.0.1:8024  it is sending the following >error log, > >1mhAnW-004vCv-It == my-l...@domain.com R=mailman3_router

Re: [exim] Unqualified Reply-To address issue

2022-03-07 Thread Slavko via Exim-users
Ahoj, Dňa Mon, 7 Mar 2022 17:15:55 + Zakaria via Exim-users napísal: > I received an Email from Vodafone, with following relevant headers:- > > From: > Reply-To: Vodafone IMO, you have three options: 1. leave responsibility to sender side (thus ignore it) 2. remove (deny on) header

Re: [exim] (re)solve retrydb issues

2022-02-21 Thread Slavko via Exim-users
Ahoj, Dňa Mon, 21 Feb 2022 11:56:41 +0200 Brent Clark via Exim-users napísal: > Where I work, we keep getting the following message "retry time not > reached for any host". Exim has retry rules, which defines how often, or more precise when next, delivery have to happen, if previous delivery

Re: [exim] Hit with some kind of hidden multiple recipients relay hack?

2022-02-25 Thread Slavko via Exim-users
Ahoj, Dňa Fri, 25 Feb 2022 13:18:27 +0100 Cyborg via Exim-users napísal: > acl_check_data: > >   deny    condition  = ${if eq{$authenticated_id}{} {1}{0}} >   domains = ! +local_domains > will not be better to do this check in RCPT ACL and simplify it as this (eventualy add

Re: [exim] 4.95 failed to stat log directory /var/spool/exim/log:

2022-05-21 Thread Slavko via Exim-users
Dňa 21. mája 2022 14:43:43 UTC používateľ Bill Cole via Exim-users napísal: > >*** That's not how computers work! *** > >Is says "/var/spool/exim/log" and it means "/var/spool/exim/log" because that >is configured *somewhere* as a log directory. Are you sure? From MS Windows (7) log:

Re: [exim] stopping spam with forged from:

2022-05-25 Thread Slavko via Exim-users
Ahoj, Dňa Wed, 25 May 2022 08:38:32 -0600 "Chad Leigh Shire.Net LLC via Exim-users" napísal: > What is the best strategy to combat and right out reject mail that > has the from: and the recipient address the same? Or alternately to > force things like SPF checking against the from: in

Re: [exim] configure exim4 against incoming rogue local parts

2022-06-02 Thread Slavko via Exim-users
Ahoj, Dňa Thu, 2 Jun 2022 16:19:18 +0100 Jeremy Harris via Exim-users napísal: > I don't see that your config actually uses > CHECK_RCPT_REMOTE_LOCALPARTS, having defined it. It is, only not at start of the file, see: ... acl_check_mail: accept CHECK_RCPT_LOCAL_LOCALPARTS = ^[.]

Re: [exim] google bounce messages

2022-06-23 Thread Slavko via Exim-users
Dňa 23. júna 2022 16:25:14 UTC používateľ Randy Bush via Exim-users napísal: >i have the rdns, the TXT RRs, ... but, I deleted old messages already, but at that time your IPv6 has not PTR... Please, do not send reply direct to me, one message via ML is enough... regards Slavko -- ## List

Re: [exim] google bounce messages

2022-06-22 Thread Slavko via Exim-users
Ahoj, Dňa Wed, 22 Jun 2022 10:14:27 -0400 Robert Steinmetz via Exim-users napísal: > There are no IPv6 records set up and I've gone through with my ISP > (Comcast) to check the PTR records. The odd thing is that this only > seems to affect some users and usually those that have their own >

Re: [exim] Closing off Port to non-SSL traffic

2022-06-26 Thread Slavko via Exim-users
Ahoj, Dňa Sun, 26 Jun 2022 00:00:40 +0200 Kirill Miazine via Exim-users napísal: > According to docs, AuthBL is both: > "AuthBL is basically that: a collection of bots known to use stolen > credentials or authentication bruteforce." Yes, my mistake. I didn't check its docs, only my notes and

Re: [exim] Closing off Port to non-SSL traffic

2022-06-26 Thread Slavko via Exim-users
Ahoj, Dňa Sun, 26 Jun 2022 15:52:56 +0200 Mark Elkins via Exim-users napísal: > urd        465/tcp        smtps ssmtp    # URL Rendesvous Directory > for SSM / smtp protocol over TLS/SSL > igmpv3lite    465/udp        smtps ssmtp    # IGMP over UDP for SSM > > submission    587/tcp             

Re: [exim] Closing off Port to non-SSL traffic

2022-06-26 Thread Slavko via Exim-users
Ahoj, Dňa Sun, 26 Jun 2022 10:41:47 -0400 Viktor Dukhovni via Exim-users napísal: > On Sun, Jun 26, 2022 at 04:30:14PM +0200, Slavko via Exim-users wrote: > > > Not MAY, they SHOULD (if they support it), the 587 is as fallback > > for old clients only, the 25/tcp is d

Re: [exim] Closing off Port to non-SSL traffic

2022-06-24 Thread Slavko via Exim-users
Dňa 24. júna 2022 9:14:41 UTC používateľ Kirill Miazine via Exim-users napísal: >I've found AuthBL from Spamhaus and Abusix to be very useful. AFAIK Spamhaus's AuthBL is about hosts, which uses stolen credentials (to send SPAM), not those attacking AUTH. While i use it in rsdpamd and MX, only

Re: [exim] Closing off Port to non-SSL traffic

2022-06-24 Thread Slavko via Exim-users
Dňa 23. júna 2022 22:15:48 UTC používateľ Sebastian Nielsen via Exim-users napísal: >I solved that with: >auth_advertise_hosts = 192.168.0.0/16 : 127.0.0.1 : 1 This helps only for single user MTA, my real users connects even from multiple countries... >2022-06-10 23:50:20 SMTP protocol

Re: [exim] tip: use -odf when calling exim from a systemd oneshot service

2022-06-16 Thread Slavko via Exim-users
Dňa 14. júna 2022 23:40:21 UTC používateľ Gedalya via Exim-users napísal: >Try Type=forking Nice, i was use KillMode=process before, but your solution looks better ;-) I initially afraid if it will work without pid file, but it is not needed, at least it was not needed in my test and behaves

Re: [exim] configure exim4 against incoming rogue local parts

2022-06-06 Thread Slavko via Exim-users
Ahoj, Dňa Thu, 2 Jun 2022 17:59:51 +0200 Ale via Exim-users napísal: > As far as I understand, exim4-config leaves the default definition, > unless you put a different one in the file exim4.conf.localmacros or > in exim4.conf.template, but I didn't. Some time ago i post you command to test

Re: [exim] drop connection on auth failure

2022-07-16 Thread Slavko via Exim-users
Dňa 15. júla 2022 20:04:37 UTC používateľ Jeremy Harris via Exim-users napísal: >On 15/07/2022 20:19, Julian Bradfield via Exim-users wrote: >> How do you do this? Abusing server_condition doesn't work, as it's >> only expanded if the base authentication succeeds. >> (My authentication method is

Re: [exim] drop connection on auth failure

2022-07-17 Thread Slavko via Exim-users
Dňa 17. júla 2022 11:16:22 UTC používateľ Jeremy Harris via Exim-users napísal: >>Beside the auth failed event, i miss acl and error related events, eg, >>acl:reject, >>acl:drop, acl:etc, or even more detailed, eg. acl:reject:stage (with >>log_message >>in event_data variable), Ideally with

Re: [exim] drop connection on auth failure

2022-07-15 Thread Slavko via Exim-users
Ahoj, Dňa Fri, 15 Jul 2022 17:12:48 +0300 Evgeniy Berdnikov via Exim-users napísal: > Note that fail2ban is not a realtime service, it scans logs in timely > manner (typically by cron, every 10-15 min). So probability for > active connection to be blocked by fail2ban is very low. I do not

Re: [exim] Taint checking and exim 4.96rc0

2022-04-30 Thread Slavko via Exim-users
Hi, Dňa Sat, 30 Apr 2022 10:10:08 +0100 Jeremy Harris via Exim-users napísal: > On 30/04/2022 00:54, Slavko (tblt) via Exim-users wrote: > > Yes, as i wrote the same already some time ago, some generic > > ${detaint:...} expansion is missing. > > That would be instantly abused. I

Re: [exim] Callout defer (was: Taint checking and exim 4.96rc0)

2022-05-01 Thread Slavko via Exim-users
Ahoj, Dňa Sun, 1 May 2022 11:54:32 +0100 Jeremy Harris via Exim-users napísal: > On 30/04/2022 12:04, Slavko via Exim-users wrote: > >> That's worthy of consideration; thank you for the idea. > >> Essentially, it would be treating a backend MTA as a trusted DB > >>

Re: [exim] Callout defer (was: Taint checking and exim 4.96rc0)

2022-05-02 Thread Slavko via Exim-users
Hi, Dňa Sun, 1 May 2022 15:49:01 +0100 Jeremy Harris via Exim-users napísal: > For instance, I have: Thanks, seems to be better than the one of which i am aware, as callout is doing only once. > > cannot distinguish network vs. real temporary errors > > That's true. You might be able to

Re: [exim] smarthost Outsmarting me so Far

2022-05-11 Thread Slavko via Exim-users
Dňa 11. mája 2022 13:34:47 UTC používateľ Martin McCormick via Exim-users napísal: > So, the question is, Does this look like I can rearrange >things somewhere to correct what is happening? You can even do auth with swaks... > When Suddenlink.net upgraded something around March 14,

Re: [exim] multiple cc: headers

2022-05-09 Thread Slavko via Exim-users
Dňa 9. 5. o 10:53 Julian Bradfield via Exim-users napísal(a): I'd never seen this before, so I went off to check RFC5822, and I see that in the 5822 version, only one of the To:, CC: or BCC: headers is allowed to be generated. RFC 5822 doesn't exists. However, the RFC says that

Re: [exim] smarthost Outsmarting me so Far

2022-05-11 Thread Slavko via Exim-users
Dňa 11. mája 2022 13:34:47 UTC používateľ Martin McCormick via Exim-users napísal: >Connecting to smtp.mx-altice.prod.cloud.synchronoss.net [208.180.40.68]:587 >... connected > SMTP<< 220 omta02.suddenlink.net ESMTP server (InterMail vM.8.04.03.22.02 > 201-2389-100-169-20190213) ready Wed,

Re: [exim] SMTP transport interface IPv4/IPv6

2022-09-07 Thread Slavko via Exim-users
Hi, Dňa 7. 9. o 9:01 Kai Bojens via Exim-users napísal(a): As for the why: we are separating some domains from each other and for the forseeable future we want them to use IPv4 only. Other mails can of course be routed via IPv6. But then why you have record for them (their MX), when it

Re: [exim] Sender/envelope-from rewrite question

2022-08-31 Thread Slavko via Exim-users
Dňa 29. augusta 2022 22:27:42 UTC používateľ Kevin Hegel via Exim-users napísal: >This has partly fixed the problem. Now the sender is >"u...@example.com"@example.com AFAIK, the value from domain= option is appended to $authenticated_id, thus if your authenticated_id already contains domain

Re: [exim] Exim relaying but shouldn't

2022-09-28 Thread Slavko via Exim-users
Dňa 26. septembra 2022 18:05:32 UTC používateľ Eric Grammatico via Exim-users napísal: >2022-09-26 16:15:24 [10] 1ocotI-0A-0g <= #xxx'uuss+...@grammatico.me >H=(localhost) [45.123.190.53] P=esmtpsa X=TLS1.2:AES256-GCM-SHA384:256 CV=no >A=login_server:#xxx'uuss+zzz S=736 ...

Re: [exim] Exim relaying but shouldn't

2022-09-28 Thread Slavko via Exim-users
Dňa 28. septembra 2022 12:59:20 UTC používateľ Eric Grammatico via Exim-users napísal: >I'm in Docker, I'll investigate in that direction. Thanks. Do you really need system users in docker? If not, use separate file in user:password form, use encrypted password of course (any system user's

Re: [exim] Setting Exim to always remove DKIM signatures

2022-09-29 Thread Slavko via Exim-users
Dňa 29. septembra 2022 16:32:33 UTC používateľ Viktor Dukhovni via Exim-users napísal: >On Thu, Sep 29, 2022 at 04:11:35PM +0000, Slavko via Exim-users wrote: >SHOULD NOT is not "MUST NOT". Especially if the signatures are one's >own from a prior internal SMTP relay hop

Re: [exim] Setting Exim to always remove DKIM signatures

2022-09-29 Thread Slavko via Exim-users
Dňa 29. septembra 2022 15:28:16 UTC používateľ Johnnie W Adams via Exim-users napísal: > I +think+ the issue is that the DKIM signature from our SMTP server is >from the first pass through and not the second pass. So what I would like >to do is tell Exim to remove any DKIM signatures from

[exim] Recipient callout use_sender,hold and BATV

2022-08-10 Thread Slavko via Exim-users
Hi all, i use BATV for some time, it is done in remote transport by: return_path = ${if def:return_path \ {${prvs{$return_path}{BATV_SIGNKEY}{BATV_KEYNUM}}}fail} And it works (worked) as expected. But recently i setup recipient callout, to catch failed recipients, where i setup

Re: [exim] Some Emails to gmail now hang

2022-08-11 Thread Slavko via Exim-users
Dňa 10. augusta 2022 23:39:08 UTC používateľ Viktor Dukhovni via Exim-users napísal: >It would perhaps be useful to also see any reports of success sending >sufficiently large messages to Gmail from the reported Exim builds and >Linux versions. If some users are not seeing any issues, then it

Re: [exim] Some Emails to gmail now hang

2022-08-15 Thread Slavko via Exim-users
Dňa 15. augusta 2022 13:49:37 UTC používateľ Jeremy Harris via Exim-users napísal: >Marc, the best route will be for you to open a Debian bug including the >above. According to https://www.debian.org/Bugs/Reporting there is a utility >"reportbug" to use. The 5.18 kernel is available in debian

Re: [exim] Some Emails to gmail now hang

2022-08-15 Thread Slavko via Exim-users
Dňa 15. augusta 2022 16:19:51 UTC používateľ Evgeniy Berdnikov via Exim-users napísal: > patch was presented in April (12.04.2022), but only 12.08.2022 (3 days ago) > has been pushed to git-master. Oh, i miss that it was pushed only 3 days ago. You are right, it will not be in debian yet (IMO

Re: [exim] exim report: (gnutls_handshake): Certificate is bad

2022-08-12 Thread Slavko via Exim-users
Hi, Dňa 10. augusta 2022 9:58:12 UTC používateľ "朱超 via Exim-users" napísal: >- Status: The certificate is NOT trusted. The certificate issuer is unknown. >The name in the certificate does not match the expected. >*** PKI verification of server certificate failed... >*** Fatal error: Error in

Re: [exim] Autoreply empty mail from

2022-08-01 Thread Slavko via Exim-users
Ahoj, Dňa Tue, 26 Jul 2022 12:33:04 +0300 Timur via Exim-users napísal: > Hi all! > > Exim 4.94 > I have trouble with autoreply transport (and any email from > Exim-self) in check DMARK when Exim send bounce/autoreply messages to > ... > MAIL FROM and $sender_address_domain - empty For SPF

Re: [exim] Rspamd 3.3 , exim 4.9.4 no scan incoming mails

2022-12-23 Thread Slavko via Exim-users
Ahoj, Dňa Fri, 23 Dec 2022 11:25:24 +0100 Mueller via Exim-users napísal: > Dear all, > I set up spam filtering with rspamd and exim. > But only internal emails are scanned. Emails fetched by fetchmail are > not scanned. How fetchmail sends emails to exim? AFAIK fetchmail delivers emails

Re: [exim] Move message to another server for spooling

2023-01-02 Thread Slavko via Exim-users
Dňa 2. januára 2023 15:46:45 UTC používateľ Jeremy Harris via Exim-users napísal: >Exim does support multiple (named) queues within a single installation, >but I don't see you wanting that here. Would not be more simple to move message to named queue instead of freeze/unfreeze steps? And one

Re: [exim] exiqgrep stops to work

2023-01-04 Thread Slavko via Exim-users
I got off list reply, continue in ML... Dňa 4. januára 2023 13:08:52 UTC používateľ Jeremy Harris napísal: >On 04/01/2023 12:05, Slavko via Exim-users wrote: >> exiqgrep -i > >You didn't say what use you'll be making of the info, >which could make for neater s

[exim] Filter/reject own messages by target MX IP

2023-01-12 Thread Slavko via Exim-users
Hi, recently i start to get medical SPAMs, every message is slighty different, they use group of different sender domains and different sender IPs (even from multiple net blocks). Body is simillar, but about different products. I have no problem to filter them in rspamd, thus i have no problem

Re: [exim] Ideas for blocking addresses with quotation marks in them?

2022-12-27 Thread Slavko via Exim-users
Dňa 27. decembra 2022 0:58:51 UTC používateľ Jarland Donnell via Exim-users napísal: >2022-12-26 18:20:59 1p9s5q-0007aL-2S <= >""@server12.sistemthfl[breakforfilters]ineamarket.com >H=server12.sistemthflineamarket.com [91.234[breakforfilters].198.105] P=esmtps

Re: [exim] Ideas for blocking addresses with quotation marks in them?

2022-12-27 Thread Slavko via Exim-users
Dňa 27. decembra 2022 10:07:19 UTC používateľ Slavko via Exim-users napísal: >First technical question -- is not that equivalent to "@..." address? I >didn't check sytax in RFC right now, only from memory... If so, >then IMO it have be rejected as syntax error by exim (

Re: [exim] Blocking a Class C

2022-12-08 Thread Slavko via Exim-users
Dňa 8. decembra 2022 14:33:01 UTC používateľ Jeremy Harris via Exim-users napísal: >For those, use the main-config option "host_reject_connection" rather than the >connect ACL - it operates before the TLS startup for TLS-on-connect ports, >while the ACL is run after. > >I'm considering changing

Re: [exim] Blocking a Class C

2022-12-11 Thread Slavko via Exim-users
Dňa 11. decembra 2022 17:15:10 UTC používateľ Jeremy Harris via Exim-users napísal: >> I am using the SNI variable in connect ACL, to filter rogue >> connections eg. with my MX name or no SNI at all (465). > >Doing that never would have worked for non- TLS-on-connect, >and now it won't work

Re: [exim] dkim=fail (body hash mismatch; body probably modified in transit)

2022-12-12 Thread Slavko via Exim-users
Dňa 12. decembra 2022 9:21:11 UTC používateľ Victor Sudakov via Exim-users napísal: >I'm using a single /etc/exim4/exim4.conf file as I have a FreeBSD >background and am used to a single exim config. In fact, I hate the >split stuff very much. It must do not matter until you switch from one to

Re: [exim] dkim=fail (body hash mismatch; body probably modified in transit)

2022-12-05 Thread Slavko via Exim-users
Dňa 5. decembra 2022 5:46:07 UTC používateľ Victor Sudakov via Exim-users napísal: >Can you give me an address to send a test mail to on one of your >Debian receivers? And we will look at what it says about the body. Be free to send test mesage to me, if your IP is not on RBLs. Try small and

Re: [exim] Blocking a Class C

2022-12-13 Thread Slavko via Exim-users
Dňa 12. decembra 2022 23:25:53 UTC používateľ Jeremy Harris via Exim-users napísal: >The latter was in April 2003. There isn't any commentary for the >rationale for the lockout; the docs do say "called for HELO or EHLO" >for the ACL. Perhaps just the EHLO after STARTTLS was forgotten.

Re: [exim] failed to expand ACL string after upgrade

2022-12-03 Thread Slavko via Exim-users
Dňa 3. decembra 2022 18:05:05 UTC používateľ Jeremy Harris via Exim-users napísal: >- so that expansion is questionable around the ${if }'s. But that doesn't >explain >the complaint about ${quote:$sender_host_address}. It fails (v4.96) with the same error even with as simple expansion:

Re: [exim] Blocking a Class C

2022-12-10 Thread Slavko via Exim-users
Dňa 10. decembra 2022 17:01:52 UTC používateľ Jeremy Harris via Exim-users napísal: >Yes, for SNI it have to be after the first bit of the TLS startup >exchange. Now i am confused. I read that commit (docs changes), but it is not clear for me, will have $tls_in_* variables values in connect

Re: [exim] Blocking a Class C

2022-12-10 Thread Slavko via Exim-users
I am sorry for delay... Dňa 8. decembra 2022 21:37:32 UTC používateľ Jeremy Harris via Exim-users napísal: >We could just drop the connection at the TCP level, silently; that wouldn't >be hard to code. I don't think it'd make any difference to a client >that didn't have a human peering at a

Re: [exim] dkim=fail (body hash mismatch; body probably modified in transit)

2022-12-09 Thread Slavko via Exim-users
Dňa 9. 12. o 8:49 Victor Sudakov via Exim-users napísal(a): Slavko via Exim-users wrote: Dňa 9. 12. o 5:15 Victor Sudakov via Exim-users napísal(a): > I've just sent two messages to you with Message-IDs and I got both and both has DKIM=pass in both, the exim (4.94.2) and rspamd What

Re: [exim] dkim=fail (body hash mismatch; body probably modified in transit)

2022-12-08 Thread Slavko via Exim-users
Dňa 9. 12. o 5:15 Victor Sudakov via Exim-users napísal(a): I've just sent two messages to you with Message-IDs and I got both and both has DKIM=pass in both, the exim (4.94.2) and rspamd (3.4) -- some headers (wrapped by me): The small message: Authentication-Results:

Re: [exim] Stumped on router conditions

2022-11-29 Thread Slavko via Exim-users
Ahoj, Dňa Tue, 29 Nov 2022 17:46:42 +0100 Sander Smeenk via Exim-users napísal: > So, "! true" must mean "false", right? No, "! true" is just string, not Boolean negation. From router's condition docs: The string is expanded, and if the result is a forced failure, or an empty string, or one

Re: [exim] Filter/reject own messages by target MX IP

2023-01-15 Thread Slavko via Exim-users
Hi, Finally i found solution, i created verify_only router, which fail recipient verification for particular remote host IP: dnslookup_vrfy: debug_print = "R: $router_name for $local_part@$domain" driver = dnslookup domains = !+local_domains : !+relay_to_domains

Re: [exim] autoreply sql from date to date

2023-01-24 Thread Slavko via Exim-users
Dňa 24. januára 2023 13:31:38 UTC používateľ basti via Exim-users napísal: >Today I use Sieve mostly. The disadvantage of this solution is that every mail >per recipient will be auto replay in vacation time. > >Within sieve you can say: Answer only once per week and sender. I don't use

[exim] exiqgrep stops to work

2023-01-04 Thread Slavko via Exim-users
Hi, i start to play with exim 4.96 (debian testing, if that matter) and i cannot get exiqgrep to work. I want to retrieve message IDs in queue with: exiqgrep -i but it returns help message only with return code 1 now, instead of IDs as in 4.94. I found that at least the -c or -h option have

Re: [exim] Keep local_part_suffix in redirect router

2022-11-08 Thread Slavko via Exim-users
Dňa 8. novembra 2022 15:17:23 UTC používateľ Frank Richter via Exim-users napísal: >Hello, > >we'd like to allow subaddresses like user+sub@domain to deliver to users’s >folder sub (if existent) via lmtp. Target system is cyrus-imapd. >We have these routers: > >global_aliases: > driver =

Re: [exim] Exim MariaDB and SSL

2022-11-01 Thread Slavko via Exim-users
Dňa 1. novembra 2022 8:22:33 UTC používateľ Brent Clark via Exim-users napísal: >Im connected to a Galera cluster for vmail. Connot be stunnel workaround? Quick search results in https://uit.stanford.edu/service/sql/configuring_stunnel (I do not use mysql/mariadb from exim) regards --

Re: [exim] Ratelimiting recipients per sender_address

2023-03-09 Thread Slavko via Exim-users
Dňa 9. marca 2023 16:08:08 UTC používateľ Jeremy Harris via Exim-users napísal: >On 09/03/2023 15:47, Olaf Hopp (SCC) via Exim-users wrote: >>  "x recipients per distinct sender per time period y  > z" ? > >If yoe used $sender_address@$recipient as the key, would >it do what you want? Are

Re: [exim] Hide IP address of authenticated users

2023-03-14 Thread Slavko via Exim-users
Dňa 14. marca 2023 22:02:24 UTC používateľ Yves Goergen via Exim-users napísal: >I couldn't find any information about the suggested solution. That all-caps >name is mentioned in very long Debian package listings, but I couldn't find >any documentation. The name also doesn't appear in Exim's

Re: [exim] Is that SPAM? Or am I compromised?

2023-03-13 Thread Slavko via Exim-users
Dňa 12. 3. o 22:34 Yves via Exim-users napísal(a): I have no solution for you, but some comments: — This email went through very few intermediaries to reach my server (yalis.fr). Apparently, it actually came directly from the sender (a Palestinian ISP). Received: headers can be faked,

Re: [exim] Is that SPAM? Or am I compromised?

2023-03-13 Thread Slavko via Exim-users
Hi, Dňa 13. marca 2023 19:12:20 UTC používateľ Yves via Exim-users napísal: >which returned nothing, and $?==0. So the signature is valid! I never used OpenDKIM, thus i cannot comment. >I checked per your advice on the server: > >[root@seuil3 etc]# journalctl --grep 640E42D8.7020207 >mars 12

Re: [exim] exim rewrites the "From:" address

2023-02-27 Thread Slavko via Exim-users
Ahoj, Dňa Mon, 27 Feb 2023 16:01:19 + Nick via Exim-users napísal: > That doesn't address the question - no-one doubted that Exim 4.xx > is able to preserve the From: address. > The point is, what is it in the config files that makes it rewrite > the From: address; or alternatively, what

Re: [exim] OT: are BCC header lines legitimate ?

2023-04-12 Thread Slavko via Exim-users
Dňa 12. apríla 2023 11:18:28 UTC používateľ Claus Assmann via Exim-users napísal: >> is there any legitimate use to have a BCC header present > >Have you checked the fine documentation? >RFC 5322 Internet Message Forma While legitimate, it is not common and can be used as spam indicator. Of

Re: [exim] From header with encoding not parsed?

2023-04-12 Thread Slavko via Exim-users
Dňa 12. apríla 2023 16:50:29 UTC používateľ MRob via Exim-users napísal: >Hi, I have a variable to extract the email address in from header set like >this: > >${lc:${address:$h_From:}} Header is valid, but after decoding it contains comma without qoutes, the comma is address separator and thus

Re: [exim] From header with encoding not parsed?

2023-04-12 Thread Slavko via Exim-users
Dňa 12. apríla 2023 19:15:19 UTC používateľ MRob via Exim-users napísal: >On 2023-04-12 17:42, Slavko via Exim-users wrote: >> Use raw header for address extracting -- $rh_From: that works >> for both, quoted and encoded content... > >If using rh_From: is there risk to ge

Re: [exim] From header with encoding not parsed?

2023-04-12 Thread Slavko via Exim-users
Dňa 12. apríla 2023 18:43:09 UTC používateľ Victor Ustugov via Exim-users napísal: >Slavko via Exim-users wrote on 12.04.2023 20:42: >> Dňa 12. apríla 2023 16:50:29 UTC používateľ MRob via Exim-users >> napísal: >>> Hi, I have a variable to extract the email address

Re: [exim] Routing failed deliveries through an ESP

2023-04-21 Thread Slavko via Exim-users
Dňa 21. apríla 2023 4:43:45 UTC používateľ Jasen Betts via Exim-users napísal: >you can detect rejections using event_action > >When you detect a fake rejection you could then store the fact in a ratelimit. > >the ratelimit can then be tested in the main delivery router (again via a >${acl...

Re: [exim] Routing failed deliveries through an ESP

2023-04-24 Thread Slavko via Exim-users
Dňa 21. apríla 2023 13:40:47 UTC používateľ Jeremy Harris via Exim-users napísal: >per_addr can only be used in the rcpt acl. >You'd possibly be able to just use count=1, >if this was and event raised once per thing >you want counted. OK i got idea, thanks. Previously i did wrong decision,

Re: [exim] Dynamic certificate paths

2023-04-16 Thread Slavko via Exim-users
Dňa 16. apríla 2023 20:28:30 UTC používateľ Lance Lovette via Exim-users napísal: >tls_certificate = >/etc/letsencrypt/live/${readfile{/etc/mailname}{}}/fullchain.pem I lost context, but content of /etc/mailname is in ETC_MAILNAME macro on debian systems. regards -- Slavko

Re: [exim] Routing failed deliveries through an ESP

2023-04-21 Thread Slavko via Exim-users
Dňa 21. apríla 2023 8:23:50 UTC používateľ Jeremy Harris via Exim-users napísal: >On 21/04/2023 06:55, Slavko via Exim-users wrote: >> Did i something wrong? > >Would need the actual error message to guess. OK, i have not exact message already, but IIRC it can be related to

Re: [exim] Something like "domains_require_tls"

2023-03-27 Thread Slavko via Exim-users
Dňa 27. 3. o 10:49 Jasen Betts via Exim-users napísal(a): On 2023-03-23, Jeremy Harris via Exim-users wrote: rather than the multi_domain; I'm not certain that there's coding in the transport to check for all-same-domain when expanding $domain. It did check the last time that I looked, if

Re: [exim] Re (2): Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Slavko via Exim-users
Dňa 31. marca 2023 15:22:43 UTC používateľ Jeremy Harris via Exim-users napísal: >On 31/03/2023 16:15, Evgeniy Berdnikov via Exim-users wrote: >> .ifdef REMOTE_SMTP_SMARTHOST_PROTOCOL >> protocol = REMOTE_SMTP_SMARTHOST_PROTOCOL >> .endif > >Doesn't that imply the wizard has a question that

Re: [exim] Re (2): Syntactic validity of configuration.

2023-04-11 Thread Slavko via Exim-users
Dňa 10. apríla 2023 22:57:49 UTC používateľ Odhiambo Washington via Exim-users napísal: >For me I am okay. I always blow away the Debian split config for my own >monolithic one. I do it opposite and i use that split style in many other daemons, including eg. sshd, dovecot, nginx, uwsgi,

Re: [exim] Re (2): Syntactic validity of configuration.

2023-04-11 Thread Slavko via Exim-users
Ahoj, Dňa Tue, 11 Apr 2023 08:39:30 +0100 Jeremy Harris via Exim-users napísal: > On 11/04/2023 07:44, Slavko via Exim-users wrote: > > The only downside with exim is, that this split (as implemented > > in debian) is not directly supported by exim, and one have to > > rel

  1   2   >