[pfx] Re: postscreen segfault since 3.8.4

2024-02-04 Thread Viktor Dukhovni via Postfix-users
On Sun, Feb 04, 2024 at 08:12:56PM -0500, Christophe Kalt via Postfix-users wrote: > These are the alpine packages themselves, but I'm not familiar with how > they're built so I can't rule out a bad build. It's also possible that I > didn't let the 3.8.3 version run long enough for it to crash

[pfx] Re: postscreen segfault since 3.8.4

2024-02-04 Thread Christophe Kalt via Postfix-users
These are the alpine packages themselves, but I'm not familiar with how they're built so I can't rule out a bad build. It's also possible that I didn't let the 3.8.3 version run long enough for it to crash as it happens irregularly. Anyways, spent some time building 3.8.5 from source and am now

[pfx] Re: postscreen segfault since 3.8.4

2024-02-04 Thread Viktor Dukhovni via Postfix-users
On Sun, Feb 04, 2024 at 05:06:22PM -0500, Viktor Dukhovni via Postfix-users wrote: > > - 3.8.4 on alpine 3.19.0 > > - 3.8.5 on alpine 3.19.1 > > > > but apparently not for 3.8.3 on alpine 3.18.3 > > There's perhaps an issue in the OpenSSL or other library dependencies. > For further info we'd

[pfx] Re: postscreen segfault since 3.8.4

2024-02-04 Thread Viktor Dukhovni via Postfix-users
On Sun, Feb 04, 2024 at 01:37:18PM -0500, Christophe Kalt via Postfix-users wrote: > /usr/libexec/postfix/postscreen pid 93 killed by signal 11 > > These connections are from an SMTP probe that goes EHLO STARTTLS EHLO QUIT > > I've not run postscreen previously, so I cannot tell whether this

[pfx] Re: postscreen segfault since 3.8.4

2024-02-04 Thread Wietse Venema via Postfix-users
Christophe Kalt via Postfix-users: > Hi, > > I'm seeing regular postscreen segfaults on a test server with minimal > traffic. The patterns I noticed from the logs is that it seems to happen > when the server gets 2 ~simultaneous connections from the same host: > > 2024-02-04T14:33:31.876390 info

[pfx] Re: Adjusting smtpd_recipient_restrictions

2024-02-04 Thread Mark via Postfix-users
Hi again Viktor, ->"Best practice is to require submission users sending outbound mail do so via ports 465 and/or 587." Indeed here, I'm able to connect my smtp service *only* through; port 465 - SSL only port 587 - TLS only Authentication/login is not enabled on port 25, however port 25 is

[pfx] postscreen segfault since 3.8.4

2024-02-04 Thread Christophe Kalt via Postfix-users
Hi, I'm seeing regular postscreen segfaults on a test server with minimal traffic. The patterns I noticed from the logs is that it seems to happen when the server gets 2 ~simultaneous connections from the same host: 2024-02-04T14:33:31.876390 info postfix starting the Postfix mail system

[pfx] Re: Is there a way to reject an internal domain on our border MXes

2024-02-04 Thread Jaroslaw Rafa via Postfix-users
Dnia 4.02.2024 o godz. 11:00:39 Viktor Dukhovni via Postfix-users pisze: > > Well, I'm an old school type... :) I prefer to ssh to the server and launch > > mutt or something similar to access my mail :) > > That's fine, I also use mutt (in fact when replying to this message), > but for me mutt

[pfx] Re: Adjusting smtpd_recipient_restrictions

2024-02-04 Thread Viktor Dukhovni via Postfix-users
On Sun, Feb 04, 2024 at 01:22:45PM +0200, Mark via Postfix-users wrote: > Is it better to list reject_unauth_destination after; > > permit_mynetworks, > permit_sasl_authenticated, > > Or before these? And why? Best practice is to require submission users sending outbound mail do so via ports

[pfx] Re: Is there a way to reject an internal domain on our border MXes

2024-02-04 Thread Viktor Dukhovni via Postfix-users
On Sat, Feb 03, 2024 at 10:17:45PM +0100, Jaroslaw Rafa via Postfix-users wrote: > Dnia 3.02.2024 o godz. 12:59:27 Viktor Dukhovni via Postfix-users pisze: > > > > These days, users are far better off with delivery to an IMAP store that > > is not tied directly to any login account they may or

[pfx] Re: problem to add, alias failed

2024-02-04 Thread Maurizio Caloro via Postfix-users
Thanks for all the messages that i recieved > GRANT ALL PRIVILEGES ON mailserver.* TO markus@'domain.com > > ' IDENTIFIED BY The problem was that Markus was created on the wrong database  But me old question still exist, if

[pfx] Re: Is there a way to reject an internal domain on our border MXes

2024-02-04 Thread 황병희
Hellow Jaroslaw, On Sat, 2024-02-03 at 22:17 +0100, Jaroslaw Rafa via Postfix-users wrote: > Dnia  3.02.2024 o godz. 12:59:27 Viktor Dukhovni via Postfix-users > pisze: > > > > These days, users are far better off with delivery to an IMAP store > > that > > is not tied directly to any login

[pfx] Re: Adjusting smtpd_recipient_restrictions

2024-02-04 Thread Mark via Postfix-users
Hi Victor, Thanks so much for very useful and informative reply and opinions, much appreciated! I'm using Postfix 3.7.9 (with Dovecot through LMTP, and virtual users in MySQL). Regarding 'smtpd_relay_before_recipient_restrictions', I don't have it explicitly set in main.cf, it's as the default.