postmulti woes

2015-09-24 Thread Patrick Ben Koetter
Yesterday I ran into a situation where I tried to create a new postfix instance, but the *.proto files where missing (i.e. they were there, but in the wrong place): # postmulti -I postfix-test -e create cp: cannot stat '/etc/postfix/main.cf.proto': No such file or directory Nevertheless the

fine-tuning smtpd_client_*_rate_limit

2015-09-24 Thread Thomas Keller
I am using Postfix as personal mailserver, with very light traffic. I do, however, get a lot of open-relay attacks. Often, these attacks come in bursts, tens of attacks within couple of seconds, from the same IP. Would this situation be a good use of "rate_limits" ? Any suggestion how I should

Questions about SSL for outgoing emails

2015-09-24 Thread Michael Peter
Hello, smtpd_tls_security_level = encrypt smtp_tls_security_level = encrypt I configured postfix to use encryption for incoming and outgoing emails. but incase the receipt has untrusted certificate or self signed certificate, postfix still deliver the email. How to enforce postfix not to send

Re: Bounce template

2015-09-24 Thread Baptiste Lhoste
Thanks for the response. Since I can not specify the MAIL FROM address for bounce emails, how can I log theirs headers and content to give them to my dedicated server provider ? Baptiste On 24/09/2015 12:25, Wietse Venema wrote: Baptiste Lhoste: Hi everybody, First of all, sorry for my

Bounce template

2015-09-24 Thread Baptiste Lhoste
Hi everybody, First of all, sorry for my bad english. Since yesterday, I have an issue with my dedicated server provider. They consider my bounce emails as spam. They said that my bounces have an empty "from" so they are considered as spam by their "anti-spam" system. They ask me to define

Re: Bounce template

2015-09-24 Thread Wietse Venema
Baptiste Lhoste: > Hi everybody, > > First of all, sorry for my bad english. > > Since yesterday, I have an issue with my dedicated server provider. > > They consider my bounce emails as spam. > > They said that my bounces have an empty "from" so they are considered as > spam by their

Re: PATCH: smtpd_upstream_proxy_protocol + smtpd_tls_wrappermode

2015-09-24 Thread Lukas Erlacher
Hi, Please try this. Wietse [patch] Works like a charm! I couldn't just patch our live server of course but I grabbed the ubuntu 14.04 postfix 2.11.0 source package on a VM, and the haproxy1.5 from trusty-backports and it works. Thanks for the prompt support! Will you be merging

postmulti woes: Invalid 'delete' option suggested as option in output

2015-09-24 Thread Patrick Ben Koetter
Erroneously I tried to use the option 'delete' instead of 'destroy' when I ran the postmulti-command. My fault, but then the output - among many other options - stated, I should use 'delete' instead of 'delete': # postmulti -i postfix-test -e delete postmulti: fatal: Invalid '-e' edit action

Re: PATCH: smtpd_upstream_proxy_protocol + smtpd_tls_wrappermode

2015-09-24 Thread Lukas Erlacher
Thanks, I will try that! Best, Luke

Delivery Status Notifications (DSN)

2015-09-24 Thread Evgeniy Serykh
In Postfix's log I can see something lines like this: Sep 24 01:54:21 smtp01 postfix/smtp[22577]: 4A38422A536: to=< some.em...@gmail.com>, relay=gmail-smtp-in.l.google.com[74.125.143.26]:25, delay=35, delays=33/0/0.85/0.73, dsn=2.0.0, status=sent (250 2.0.0 OK 1443074061 xf5si4002770lbb.93 -

Re: Bounce template

2015-09-24 Thread Wietse Venema
Tell them that the SMTP protocol requires support for the MAIL FROM null sender. https://tools.ietf.org/html/rfc5321#section-4.5.5 Wietse Baptiste Lhoste: > Thanks for the response. > > Since I can not specify the MAIL FROM address for bounce emails, how can > I log theirs headers and

Re: NIS and postfix

2015-09-24 Thread Wietse Venema
Wietse Venema: > Il Neofita: > > Hi > > I have a server NIS that has a wrong domain name, therefore, everytime that > > I am receiving an email the user is changed as user@NISDOMAIN despite the > > fact that my postfix is configured with a mydomain variable. > > I tried to modify the domain with >

Re: Questions about SSL for outgoing emails

2015-09-24 Thread lst_hoe02
Zitat von Michael Peter : Hello, smtpd_tls_security_level = encrypt smtp_tls_security_level = encrypt I configured postfix to use encryption for incoming and outgoing emails. but incase the receipt has untrusted certificate or self signed certificate, postfix

Re: PATCH: smtpd_upstream_proxy_protocol + smtpd_tls_wrappermode

2015-09-24 Thread Lukas Erlacher
Thanks for the prompt support! Will you be merging this? In the next 3.1 development release, and in a month or so, in the next stable releases (2.9 .. 3.0). Wietse That's great to hear! Best, Luke smime.p7s Description: S/MIME Cryptographic Signature

Re: NIS and postfix

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 09:12:00AM -0400, Il Neofita wrote: > I have a server NIS that has a wrong domain name, therefore, everytime that > I am receiving an email the user is changed as user@NISDOMAIN despite the > fact that my postfix is configured with a mydomain variable. The "mydomain"

Re: PATCH: smtpd_upstream_proxy_protocol + smtpd_tls_wrappermode

2015-09-24 Thread Wietse Venema
Lukas Erlacher: > Hi, > > > Please try this. > > > > Wietse > > > > [patch] > > Works like a charm! I couldn't just patch our live server of course > but I grabbed the ubuntu 14.04 postfix 2.11.0 source package on a > VM, and the haproxy1.5 from trusty-backports and it works. > > Thanks for

Postfix and (Open)DKIM: Received Email?

2015-09-24 Thread Jim Seymour
Hi All, I just installed, configured and have working OpenDKIM. I can see outgoing email is being properly signed, but not certain what it's doing for me on the receiving side of things? All the searching and reading I've done talks all about how to get it going, and how to test your outgoing

NIS and postfix

2015-09-24 Thread Il Neofita
Hi I have a server NIS that has a wrong domain name, therefore, everytime that I am receiving an email the user is changed as user@NISDOMAIN despite the fact that my postfix is configured with a mydomain variable. I tried to modify the domain with recipient_canonical_maps or smtp_generic_maps or

Re: NIS and postfix

2015-09-24 Thread Wietse Venema
Il Neofita: > Hi > I have a server NIS that has a wrong domain name, therefore, everytime that > I am receiving an email the user is changed as user@NISDOMAIN despite the > fact that my postfix is configured with a mydomain variable. > I tried to modify the domain with > recipient_canonical_maps

Re: Postfix and (Open)DKIM: Received Email?

2015-09-24 Thread Jim Seymour
On Thu, 24 Sep 2015 08:48:24 -0400 (EDT) wie...@porcupine.org (Wietse Venema) wrote: > Jim Seymour: > > Hi All, > > > > I just installed, configured and have working OpenDKIM. I can see > > outgoing email is being properly signed, but not certain what it's > > doing for me on the receiving side

Re: Questions about SSL for outgoing emails

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 02:14:47PM +0200, lst_ho...@kwsoft.de wrote: > >How to enforce postfix not to send the email incase the receipt > >certificate is untrusted or self signed? > > You will need "verify" level for this : > http://www.postfix.org/TLS_README.html#client_tls_verify The default

Re: postmulti woes

2015-09-24 Thread Patrick Ben Koetter
* Viktor Dukhovni : > On Thu, Sep 24, 2015 at 08:52:45AM +0200, Patrick Ben Koetter wrote: > > > Yesterday I ran into a situation where I tried to create a new postfix > > instance, but the *.proto files where missing (i.e. they were there, but in > > the wrong place):

Re: postmulti woes

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 08:52:45AM +0200, Patrick Ben Koetter wrote: > Yesterday I ran into a situation where I tried to create a new postfix > instance, but the *.proto files where missing (i.e. they were there, but in > the wrong place): Distribution packaging problem? With Postfix 3.0 and

Re: postmulti woes: Invalid 'delete' option suggested as option in output

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 09:00:43AM +0200, Patrick Ben Koetter wrote: > Erroneously I tried to use the option 'delete' instead of 'destroy' when I ran > the postmulti-command. My fault, but then the output - among many other > options - stated, I should use 'delete' instead of 'delete': > > #

Re: postmulti woes (patch)

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 05:05:34PM +0200, Patrick Ben Koetter wrote: > > That can happen. We could test more pre-conditions, but ultimately, > > the administrator may need to recover from situations where automated > > deletion is risky. > > Agreed. I wouldn't reach out to test any thinkable

Re: NIS and postfix

2015-09-24 Thread Il Neofita
The problem is with the forward using the aliases, therefore, should be postfix If I change the domainname I will have problem with the nis the nisdomain is using capital letter, and mydomain is using lower letter therefore, the to is changed during the forward with capital letter On Thu, Sep

Re: NIS and postfix

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 12:03:16PM -0400, Il Neofita wrote: > The problem is with the forward using the aliases, therefore, should be > postfix > > If I change the domainname I will have problem with the nis > > the nisdomain is using capital letter, and mydomain is using lower letter >

Re: fine-tuning smtpd_client_*_rate_limit

2015-09-24 Thread Noel Jones
On 9/24/2015 3:28 AM, Thomas Keller wrote: > I am using Postfix as personal mailserver, with very light traffic. > > I do, however, get a lot of open-relay attacks. > Often, these attacks come in bursts, tens of attacks within couple of > seconds, from the same IP. > > Would this situation be a

Re: NIS and postfix

2015-09-24 Thread Il Neofita
Thank you for the reply, I tried without the relayhost, also check in the alias,and mydomain is wrote correctly and I remove forward_path since the file was empty I have also tried to put the forward in the alias therefore, pluto: a...@gmail.com however, in the header the from on the message

Re: NIS and postfix

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 05:15:03PM -0400, Il Neofita wrote: > When the server receive an email, the TO field is changed using the domain > from the system and not the domain configured in postfix. > Therefore, if the server receive an email with the field u...@a.aa is > changed in

Re: NIS and postfix

2015-09-24 Thread Il Neofita
When the server receive an email, the TO field is changed using the domain from the system and not the domain configured in postfix. Therefore, if the server receive an email with the field u...@a.aa is changed in u...@a.aa, which A.AA is the nis domain. On Thu, Sep 24, 2015 at 1:55

Re: NIS and postfix

2015-09-24 Thread Il Neofita
alias_database = hash:/etc/aliases alias_maps = hash:/etc/aliases command_directory = /usr/sbin daemon_directory = /usr/libexec/postfix data_directory = /var/lib/postfix debug_peer_level = 2 debugger_command = PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin ddd $daemon_directory/$process_name

Re: NIS and postfix

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 12:54:37PM -0400, Il Neofita wrote: > alias_maps = hash:/etc/aliases > forward_path = /etc/postfix/destination > mailbox_command = /usr/libexec/dovecot/deliver > mydomain = aaa.aaa > myorigin = $mydomain > relayhost = aaa.a.aa The above are potentially

Re: NIS and postfix

2015-09-24 Thread Viktor Dukhovni
On Thu, Sep 24, 2015 at 01:40:21PM -0400, Il Neofita wrote: > In the header the from on the message received by gmail is in > capital letters and dovecot is not involved in that transfer. > I tought that mydomain was suppose to overwrite the unix domainname It appears you're unable to explain