Re: New filters auth and sign

2024-06-01 Thread Kirill A . Korinsky
On Sat, 01 Jun 2024 08:45:00 +0100, "Corey Hickman" wrote: > > does it have policy server included? for instance, when DKIM fails, the > policy can be set up to deny the message. > Right now it ignores DMARC as if it doesn't exist. Doing a DMARC lookup for domain and inserting it's results

Re: New filters auth and sign

2024-06-01 Thread Corey Hickman
June 1, 2024 at 7:34 AM, "Kirill A. Korinsky" wrote: > > Greetings, > > I'd like to announce a two new filters for OpenSMTD which better to use > > together: auth and sign. > does it have policy server included? for instance, when DKIM fails, the policy ca

Re: New filters auth and sign

2024-05-31 Thread Kirill A . Korinsky
On Sat, 01 Jun 2024 00:34:41 +0100, Kirill A. Korinsky wrote: > > Greetings, > > I'd like to announce a two new filters for OpenSMTD which better to use > together: auth and sign. > Oops, wrong list. It should be m...@opensmtpd.org. Sorry for nosy. -- wbr, Kirill

New filters auth and sign

2024-05-31 Thread Kirill A . Korinsky
Greetings, I'd like to announce a two new filters for OpenSMTD which better to use together: auth and sign. auth is a filter which verify DKMI, ARC and SPF, and iprev. It adds Authentication-Results header or ARC-Authentication-Results. sign is a filter which adds DKMI or ARC signature, or ARC

Re: OpenSMTPD + rspamd to sign mail.

2021-08-12 Thread latincom
> On 8/12/21 5:09 AM, latin...@vcn.bc.ca wrote: >> Hello >> >> After: >> # pkg_add redis rspamd opensmtpd-filter-rspamd successfully >> >> i got: >> # rcctl start rspamd >> rspamd(failed) >> >> then I did: >> # rspamd -d >> 2021-08-12 09:23:41 #0(main) ; main; detect_priv: cannot run >> rspamd

Re: OpenSMTPD + rspamd to sign mail.

2021-08-12 Thread Chris Eidem
On 8/12/21 5:09 AM, latin...@vcn.bc.ca wrote: Hello After: # pkg_add redis rspamd opensmtpd-filter-rspamd successfully i got: # rcctl start rspamd rspamd(failed) then I did: # rspamd -d 2021-08-12 09:23:41 #0(main) ; main; detect_priv: cannot run rspamd workers as root user, please add -u and

OpenSMTPD + rspamd to sign mail.

2021-08-12 Thread latincom
Hello After: # pkg_add redis rspamd opensmtpd-filter-rspamd successfully i got: # rcctl start rspamd rspamd(failed) then I did: # rspamd -d 2021-08-12 09:23:41 #0(main) ; main; detect_priv: cannot run rspamd workers as root user, please add -u and -g options to select a proper unprivilleged

[patch] use acme-client to sign certificated with ecdsa keys

2019-05-22 Thread Renaud Allard
Hello, This is a short patch to let acme-client accept ECDSA keys now that letsencrypt accepts signing certificates with those keys. This functionality is present in certbot, so it might be a good idea to let acme-client accept that too. The key needs to be generated manually i.e.: openssl

Re: mail sign/encrypt

2018-05-09 Thread Stuart Longland
ning. > So for now I sign and send email (prepared in message.txt) with this: > > openssl smime -sign -in message.txt -text -signer sec/certCVUT.mycrt.pem \ > -inkey sec/certCVUT.mykey.pem -certfile sec/certCVUT.caChain.pem \ > -from rudolf.syk...@cvut.cz -to rsyk...@disroot.org \ >

Re: mail sign/encrypt

2018-05-09 Thread Rudolf Sykora
. Even snail is way too complex. So for now I sign and send email (prepared in message.txt) with this: openssl smime -sign -in message.txt -text -signer sec/certCVUT.mycrt.pem \ -inkey sec/certCVUT.mykey.pem -certfile sec/certCVUT.caChain.pem \ -from rudolf.syk...@cvut.cz -to rsyk...@disroot.org \ -s

Re: mail sign/encrypt

2018-05-04 Thread Stuart Longland
On 05/05/18 08:31, Tony Boston wrote: > On 05/03/18 10:30, Rudolf Sykora wrote: >> Hello misc, >> >> I'd like to be able to optionally >> - sign my email, >> - encrypt the email. >> >> I have a certificate in the .p12 form, >> containing my pr

Re: mail sign/encrypt

2018-05-04 Thread Tony Boston
On 05/03/18 10:30, Rudolf Sykora wrote: > Hello misc, > > I'd like to be able to optionally > - sign my email, > - encrypt the email. > > I have a certificate in the .p12 form, > containing my private key and two certificates, > one of them mine. > > I want to

Re: mail sign/encrypt

2018-05-03 Thread Steffen Nurpmeso
Hello again Rudolf. Rudolf Sykora <rudolf.syk...@gmail.com> wrote: |I'd like to be able to optionally |- sign my email, |- encrypt the email. | |I have a certificate in the .p12 form, |containing my private key and two certificates, |one of them mine. | |I want to prepare mail l

mail sign/encrypt

2018-05-03 Thread Rudolf Sykora
Hello misc, I'd like to be able to optionally - sign my email, - encrypt the email. I have a certificate in the .p12 form, containing my private key and two certificates, one of them mine. I want to prepare mail locally, i.e. to use some simple locally installed MUA. Is there a way

Re: How does dpb sign packages in 6.1 ?

2017-04-05 Thread Noth
uilt just once with the signature inside. Now that the signature is outside, there is no gain to having pkg_create(1) sign directly, so that was scraped out.

Re: How does dpb sign packages in 6.1 ?

2017-04-05 Thread Marc Espie
dpb no longer does. Use pkg_sign(1) directly like sthen says. Before, signing directly during pkg_create(1) made some sense, since the archive was built just once with the signature inside. Now that the signature is outside, there is no gain to having pkg_create(1) sign directly, so

Re: How does dpb sign packages in 6.1 ?

2017-04-05 Thread Stuart Henderson
On 2017-04-04, Noth <nothingn...@citycable.ch> wrote: >I'm trying to use dpb in 6.1-current, and my setup works till it > tries to sign the package it makes and then fails with this message: .. > I've updated my signify keys and placed them in $CHROOT/etc/signify. I > can't

How does dpb sign packages in 6.1 ?

2017-04-04 Thread Noth
Hi all, I'm trying to use dpb in 6.1-current, and my setup works till it tries to sign the package it makes and then fails with this message: ==> Building package for bzip2-1.0.6p8 Create /data/packages/amd64/all/bzip2-1.0.6p8.tgz ^Mreading plist|ESC[KESC[K^Mchecking dependencies|

Re: dkimproxy_out doesn't sign my outgoing messages

2016-11-09 Thread Walter Alejandro Iglesias
On Wed, Nov 09, 2016 at 06:13:47PM +0100, Walter Alejandro Iglesias wrote: > Taking in care /etc/rc.d/dkimproxy_out flags: > > daemon_flags="--conf_file=/etc/dkimproxy_out.conf --user=_dkimproxy > --group=_dkimproxy" > > These files should be owned by _dkimproxy user and group. > It worked!

Re: dkimproxy_out doesn't sign my outgoing messages

2016-11-09 Thread Walter Alejandro Iglesias
On Wed, Nov 09, 2016 at 11:57:18AM -0500, trondd wrote: > Should also be in the maillog. Hey, I think I found the problem: Nov 9 10:37:12 server dkimproxy.out[38514]: signing error: Error: cannot read /var/dkimproxy/default.private: Permission denied The permissions are: # ls -l

Re: dkimproxy_out doesn't sign my outgoing messages

2016-11-09 Thread Walter Alejandro Iglesias
trondd, Your response was also useful to me in another more important way. I took a look to the headers of your message and I observe gmail says your dkim is correct: Authentication-Results: mx.google.com; dkim=pass header.i=@kagu-tsuchi.com; However, I had to rescue your message from

Re: dkimproxy_out doesn't sign my outgoing messages

2016-11-09 Thread trondd
On Wed, November 9, 2016 11:39 am, Walter Alejandro Iglesias wrote: > On Wed, Nov 09, 2016 at 09:27:58AM -0500, trondd wrote: >> On Wed, November 9, 2016 9:14 am, Walter Alejandro Iglesias wrote: >> > Hi everyone, >> > >> > First of all, is dkimproxy a work in progress? >> > >> > If it's not, then

Re: dkimproxy_out doesn't sign my outgoing messages

2016-11-09 Thread Walter Alejandro Iglesias
On Wed, Nov 09, 2016 at 09:27:58AM -0500, trondd wrote: > On Wed, November 9, 2016 9:14 am, Walter Alejandro Iglesias wrote: > > Hi everyone, > > > > First of all, is dkimproxy a work in progress? > > > > If it's not, then the long one. I've tried something similar to > > the example in

Re: dkimproxy_out doesn't sign my outgoing messages

2016-11-09 Thread trondd
On Wed, November 9, 2016 9:14 am, Walter Alejandro Iglesias wrote: > Hi everyone, > > First of all, is dkimproxy a work in progress? > > If it's not, then the long one. I've tried something similar to > the example in smtpd.conf(5). Outgoing messages don't get signed. > > > # dkim-genkey -s

dkimproxy_out doesn't sign my outgoing messages

2016-11-09 Thread Walter Alejandro Iglesias
Hi everyone, First of all, is dkimproxy a work in progress? If it's not, then the long one. I've tried something similar to the example in smtpd.conf(5). Outgoing messages don't get signed. # dkim-genkey -s default -d mydomain.com -r -D /var/dkimproxy /etc/dkimproxy_out.conf

# sign

2015-06-17 Thread Max Power
Hi guys! In Enghlish_US way, you have no certainties. # symbol, I've always named 'hash', but from recent research I found which is also named: number, pound, octothorpe, octothorp, octothorn... which is the exact name for it? (In computer way naturally...) Thanks for reply.

Re: # sign

2015-06-17 Thread Terry Tyson
On 6/17/2015 12:52 PM, Max Power wrote: Hi guys! In Enghlish_US way, you have no certainties. # symbol, I've always named 'hash', but from recent research I found which is also named: number, pound, octothorpe, octothorp, octothorn... which is the exact name for it? (In computer way

Re: # sign

2015-06-17 Thread Miod Vallat
hash Wikipedia says that he use of hash for this sign may have come from Baudot, which predated both ASCII and EBCDIC. I thought everyone here knew that this sign is actually historically called `sliced unicorn hearts' after the specific pattern their heart display when thinly sliced. Oh

Re: # sign

2015-06-17 Thread Mikkel C. Simonsen
Max Power wrote: which is the exact name for it? (In computer way naturally...) Havelåge - the Danish way. Best regards, Mikkel C. Simonsen

Re: # sign

2015-06-17 Thread Josh Grosse
name for it? (In computer way naturally...) Thanks for reply. Computer way? Which computer? If you mean ASCII representation, # would be 0010 0011. If instead you prefer EBCDIC, # would be 0111 1011. hash Wikipedia says that he use of hash for this sign may have come from Baudot, which

Re: Daemons can't have hyphen (-) sign in the name

2015-03-16 Thread Igor Konforti
Well I guess that explains :S Thanks On Sun, Mar 15, 2015 at 7:24 PM, Antoine Jacoutot ajacou...@bsdfrog.org wrote: On Sun, Mar 15, 2015 at 07:08:52PM +0200, Igor Konforti wrote: I was writing Deamon by name /etc/rc.d/example-client and all a time I was getting error that ${daemon_user} is

Daemons can't have hyphen (-) sign in the name

2015-03-15 Thread Igor Konforti
I was writing Deamon by name /etc/rc.d/example-client and all a time I was getting error that ${daemon_user} is client After looking at source code of rc.subr http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/etc/rc.d/rc.subr?rev=1.92content-type=text/x-cvsweb-markup I saw the following: ```

Re: Daemons can't have hyphen (-) sign in the name

2015-03-15 Thread Antoine Jacoutot
On Sun, Mar 15, 2015 at 07:08:52PM +0200, Igor Konforti wrote: I was writing Deamon by name /etc/rc.d/example-client and all a time I was getting error that ${daemon_user} is client After looking at source code of rc.subr

Sign A Rama souhaite s'implanter dans votre ville

2010-09-05 Thread Franchise Sign A Rama
Si ce message ne s'affiche pas correctement, cliquez ICI ( http://www.benoitfougerais.fr/Franchise/Signarama/Emailing/SAR-NewsLetter201 0.html ) ( https://spreadsheets.google.com/viewform?hl=frcfg=trueformkey=dEFkaDNXWXNn TDRMOHRiSXFXOVJLa2c6MA ) Votre parcours vous donne maintenant la confiance

Re: Real men don't attack sign men

2007-12-16 Thread Breen Ouellette
Marc Balmer wrote: Richard Stallman wrote: I doubt someone who is truly unfriendly could organize a hackathon, a friendly social event. He may be perfectly friendly to others. What is relevant is that he tends to be unfriendly to me. What is relevant is that you are a hypocrite

Re: Real men don't attack sign men

2007-12-15 Thread Richard Stallman
I doubt someone who is truly unfriendly could organize a hackathon, a friendly social event. He may be perfectly friendly to others. What is relevant is that he tends to be unfriendly to me. The same argument could be made about your unfriendliness. We could not talk to you

Re: Real men don't attack sign men

2007-12-15 Thread Marc Balmer
Richard Stallman wrote: I doubt someone who is truly unfriendly could organize a hackathon, a friendly social event. He may be perfectly friendly to others. What is relevant is that he tends to be unfriendly to me. What is relevant is that you are a hypocrite and come to our

Re: Real men don't attack sign men

2007-12-13 Thread L
Not calling someone unfriendly and just focusing on the conversation/technical details at hand, would be much more friendly.. even considering friendship wasn't the subject of discussion in the first place. Someone else attacked me on this list for not discussing this with

Re: sign and timestamp

2007-10-05 Thread Douglas A. Tutty
On Thu, Oct 04, 2007 at 05:03:41PM +0200, G?bri M?t? wrote: There'll be two main servers, a web server and a sql server. We have to insert a timestamp and a signature in the specified rows of tables. Periodically the sql server will make pdf documents from the data and we have to sign

Re: sign and timestamp

2007-10-04 Thread Joachim Schipper
On Wed, Oct 03, 2007 at 05:21:09PM -0700, Ted Unangst wrote: On 10/3/07, Gabri Mati [EMAIL PROTECTED] wrote: I've read a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign

Re: sign and timestamp

2007-10-04 Thread Gábri Máté
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 There'll be two main servers, a web server and a sql server. We have to insert a timestamp and a signature in the specified rows of tables. Periodically the sql server will make pdf documents from the data and we have to sign and timestamp these docs

sign and timestamp

2007-10-03 Thread Gábri Máté
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey there! I've read a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before the process how can i

Re: sign and timestamp

2007-10-03 Thread Gábri Máté
mrta: On Wed, Oct 03, 2007 at 06:21:53PM +0200, G??bri M??t?? wrote: I've read a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before the process how

Re: sign and timestamp

2007-10-03 Thread Douglas A. Tutty
On Wed, Oct 03, 2007 at 06:21:53PM +0200, G??bri M??t?? wrote: I've read a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before the process how

Re: sign and timestamp

2007-10-03 Thread Douglas A. Tutty
it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before the process how can i timestamp it? Sorry for the stupid question but i really can't imagine it. I suppose the first question

Re: sign and timestamp

2007-10-03 Thread Joachim Schipper
On Wed, Oct 03, 2007 at 06:21:53PM +0200, G??bri M??t?? wrote: Hey there! I've read a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before

Re: sign and timestamp

2007-10-03 Thread Gábri Máté
?rta: On Wed, Oct 03, 2007 at 06:21:53PM +0200, G??bri M??t?? wrote: I've read a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before the process

Re: sign and timestamp

2007-10-03 Thread Stuart Henderson
encrypt or sign a document with gnupg, but before the process how can i timestamp it? google/patent search: haber stornetta dead trees: there's a little section in Applied Cryptography (surprise!), the basics are fairly obvious (send TTP a hash, they append a timestamp and sign the lot

Re: sign and timestamp

2007-10-03 Thread Gábri Máté
a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before the process how can i timestamp it? Sorry for the stupid question but i really can't imagine

Re: sign and timestamp

2007-10-03 Thread Steve McConville
I don't know if there's an accepted strategy, but if I had to create one from scratch, off the top of my head I'm thinking some time of time server. It would have to publish a signed file of the current time, say once per minute, so that you could include the hash in the above noted tarball.

Re: sign and timestamp

2007-10-03 Thread Joachim Schipper
: Hey there! I've read a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before the process how can i timestamp it? Sorry for the stupid question

Re: sign and timestamp

2007-10-03 Thread Ted Unangst
On 10/3/07, Gabri Mati [EMAIL PROTECTED] wrote: I've read a lot about timestamping a document, but dunno how it works in practice. How can i apply a timestamp to a digitally signed or encrypted document? Like i encrypt or sign a document with gnupg, but before the process how can i timestamp

Re: sign and timestamp

2007-10-03 Thread Douglas A. Tutty
correclty: Database the data-gatherer can query. You set up a dedicated, physically secure box and provide it with a secure source of time (GPS?). Assuming that you don't want the latency for them to email the box a hash, have the box append a time stamp, sign it, and mail it back. You need

Please sign in your USAA account, verify and update your profile immediately

2005-12-14 Thread United Services Automobile Association
-10 minutes out of your online experience and renew service. Once you have updated your records, your USAA session will not be interrupted and will continue as normal. Please sign in your USAA account, verify and update your profile by clicking this link: https://www.usaa.com/inet/ent_logon

Re: bgpd.conf md5sig, iBGP and redistributing routes to/from ospf [forgot to sign it]

2005-11-02 Thread Claudio Jeker
On Wed, Nov 02, 2005 at 12:34:29AM +0100, per engelbrecht wrote: Hi all [20051019 snap i386] I've made a setup with two identical bgp routers. On each router there's 3 peers (BGP and eBGP), one failover (carp/iBGP/ospf) interconnecting these routers and finally pipes backwards to the

Re: bgpd.conf md5sig, iBGP and redistributing routes to/from ospf [forgot to sign it]

2005-11-02 Thread per engelbrecht
Claudio Jeker wrote: On Wed, Nov 02, 2005 at 12:34:29AM +0100, per engelbrecht wrote: Hi all [20051019 snap i386] I've made a setup with two identical bgp routers. On each router there's 3 peers (BGP and eBGP), one failover (carp/iBGP/ospf) interconnecting these routers and finally pipes

Re: bgpd.conf md5sig, iBGP and redistributing routes to/from ospf [forgot to sign it]

2005-11-02 Thread Henning Brauer
* per engelbrecht [EMAIL PROTECTED] [2005-11-02 00:52]: I've made a setup with two identical bgp routers. On each router there's 3 peers (BGP and eBGP), one failover (carp/iBGP/ospf) interconnecting these routers and finally pipes backwards to the internal nets. Part of bgpd.conf further

bgpd.conf md5sig, iBGP and redistributing routes to/from ospf [forgot to sign it]

2005-11-01 Thread per engelbrecht
Hi all [20051019 snap i386] I've made a setup with two identical bgp routers. On each router there's 3 peers (BGP and eBGP), one failover (carp/iBGP/ospf) interconnecting these routers and finally pipes backwards to the internal nets. Part of bgpd.conf further down. I'm replacing a single