cannot load Certificate Authority data

2010-08-25 Thread Edward avanti
Halo list, Happy report full conversion away qmail near finish, only one problem remain we can see. noki7 postfix/smtpd[8512]: cannot load Certificate Authority data: disabling TLS support is this error because client not use TLS? Is this error safe to ignore or does have problem reading local

Re: DNS Whitelisting

2010-08-25 Thread Stan Hoeppner
Noel Jones put forth on 8/24/2010 2:18 PM: - This is specific for dnswl.org. Postfix needs a general mechanism. Other whitelists are not required to follow dnswl.org's 127.0.x.y mechanism. Yeah, I used this example as dnswl is, afaik, the most established of the dns whitelists. I haven't

build custom milter with milter_protocol=6

2010-08-25 Thread Ram
I have a custom milter for userwise blacklists/whitelists I have been running with postfix 2.3.4 Now when I upgraded to postfix 2.7 I get this error can't read SMFIC_DATA reply packet header: Success This works if I use milter_protocol=2. But how do I build my milter again with protocol=6.

Re: build custom milter with milter_protocol=6

2010-08-25 Thread Wietse Venema
Wietse Venema: Ram: I have a custom milter for userwise blacklists/whitelists I have been running with postfix 2.3.4 Now when I upgraded to postfix 2.7 I get this error can't read SMFIC_DATA reply packet header: Success This works if I use milter_protocol=2. But how do I

TLS for dummies

2010-08-25 Thread Security Admin (NetSec)
This is more of an annoyance than anything else. When my Postfix (v 2.6.7) attempts to send a message via TLS the following warning is received: postfix/smtp[28338]: certificate verification failed for mail.x.org[xxx.xxx.xxx.xxx]:25: untrusted issuer

Re: DNS Whitelisting

2010-08-25 Thread Stan Hoeppner
Wietse Venema put forth on 8/24/2010 2:37 PM: With reject_rbl_client etc. Postfix can use different DNSXLs names in different access lists, and filter the result. For example, to select responses from some.example.com with value 127.0.0.4: smtpd_mumble_restrictions = ...

Postfix integration: Oracle or LDAP?

2010-08-25 Thread Zhou, Yan
Hi there, We want to implement SMTP authentication in Postfix and support multiple virtual domains. Rather than having user/domain/endpoint in different files, we prefer them either in database (Oracle) or LDAP. I am trying to weigh the pros and cons of both options. I have not seen examples

Re: DNS Whitelisting

2010-08-25 Thread Steve Linford
On 24 Aug 2010, at 21:37, Wietse Venema wrote: Stan Hoeppner: Wietse Venema put forth on 8/23/2010 10:11 AM: Noel Jones: (Might be time to revisit DNS whitelists in postfix.) Maybe someone can draft a strawman user interface: - what is the configuration syntax - what does that

Re: pickup: fatal: watchdog timeout

2010-08-25 Thread Wietse Venema
Stefan Foerster: Hello world, I am concerned about those log entries: Aug 24 21:16:51 drought postfix/pickup[23165]: fatal: watchdog timeout Aug 24 21:16:52 drought postfix/master[4713]: warning: process /usr/libexec/postfix/pickup pid 23165 exit status 1 Aug 24 21:33:31 drought

Re: DNS Whitelisting

2010-08-25 Thread Stan Hoeppner
Steve Linford put forth on 8/25/2010 8:27 AM: Just to add to the mix if Postfix is working on whitelist implementation... Spamhaus has assigned 127.0.2.0/24 for whitelist return codes. The new Spamhaus Whitelist (SWL) due out very shortly will return 127.0.2.2 and 127.0.2.3 and Spamhaus'

Remove Received lines when SMTP Auth is used ?

2010-08-25 Thread Xavier Beaudouin
Hello there, Maybe this is already spoken here, but it seems that more and more spam system looks into Received headers to score the mails. Those stupid things doesn't honor such SMTP auth and then I really need to remove the Received line when SMTP Auth is used (and succesfull). Is there

Re: Postfix integration: Oracle or LDAP?

2010-08-25 Thread Patrick Ben Koetter
* Zhou, Yan yz...@medplus.com: We want to implement SMTP authentication in Postfix and support multiple virtual domains. Rather than having user/domain/endpoint in different files, we prefer them either in database (Oracle) or LDAP. I am trying to weigh the pros and cons of both options. I

Re: Selective smtpd_helo_restrictions question

2010-08-25 Thread Charles Marcus
On 2010-08-24 8:58 AM, Noel Jones njo...@megan.vbhcs.org wrote: On 8/24/2010 7:41 AM, Charles Marcus wrote: I guess I need some clarification now... My understanding is this is not true if you have all checks under recipient_restrictions (and delay_reject enabled) - an OK in this case

Re: Postfix integration: Oracle or LDAP?

2010-08-25 Thread Wietse Venema
Zhou, Yan: Hi there, We want to implement SMTP authentication in Postfix and support multiple virtual domains. Rather than having user/domain/endpoint in different files, we prefer them either in database (Oracle) or LDAP. I am trying to weigh the pros and cons of both options. I have not

Re: TLS for dummies

2010-08-25 Thread Jeroen Geilman
On 08/25/2010 02:59 PM, Security Admin (NetSec) wrote: This is more of an annoyance than anything else. When my Postfix (v 2.6.7) attempts to send a message via TLS the following warning is received: postfix/smtp[28338]: certificate verification failed for

Re: submission port annoyance

2010-08-25 Thread Jeroen Geilman
On 08/24/2010 02:48 PM, Noel Jones wrote: On 8/24/2010 7:24 AM, Edward avanti wrote: Halo, We are have odd occasional problem where, some customer that have made up name in hostname on pc and try send mail get rejected by us submission is told use - submission inet n - n -

How to drop the recipient address hostname when delivering mail via LMTP?

2010-08-25 Thread Ralph Seichter
There is a thread in the Dovecot mailing list discussing this subject, but I think it best to ask here aswell: My Dovecot 2.0 configuration contains these lines auth_username_format = %Ln service lmtp { unix_listener /var/spool/postfix/private/dovecot-lmtp { user = postfix

Re: Postfix integration: Oracle or LDAP?

2010-08-25 Thread Patrick Ben Koetter
* Wietse Venema postfix-users@postfix.org: Zhou, Yan: Hi there, We want to implement SMTP authentication in Postfix and support multiple virtual domains. Rather than having user/domain/endpoint in different files, we prefer them either in database (Oracle) or LDAP. I am trying to

Re: Multiple Domains; No Local Accounts - bad uid in virtual_uid_maps

2010-08-25 Thread mouss
Le 25/08/2010 03:04, Mike a écrit : Thank you, gentlemen. I always appreciate a good RTFM from talented folks who actually know where they are pointing. :-) I do appreciate the help and definitely do not intend to aggravate and vex. I forgot to say that you can use your own file as a

Re: DNS Whitelisting

2010-08-25 Thread Noel Jones
As I see it, there are two complementary paths we can take with DNS whitelists, each with a slightly different purpose. While these are both useful, neither depends on the other, so postfix can implement either or both. My proposals: A) scoring in postscreen A dns whitelist/blacklist scoring

Re: TLS for dummies

2010-08-25 Thread Victor Duchovni
On Wed, Aug 25, 2010 at 05:59:10AM -0700, Security Admin (NetSec) wrote: postfix/smtp[28338]: certificate verification failed for mail.x.org[xxx.xxx.xxx.xxx]:25: untrusted issuer /C=US/O=Entrust.net/OU=www.entrust.net/CPS incorp. by ref. (limits liab.)/OU=(c) 1999 Entrust.net

Re: Remove Received lines when SMTP Auth is used ?

2010-08-25 Thread Noel Jones
On 8/25/2010 10:49 AM, Xavier Beaudouin wrote: Hello there, Maybe this is already spoken here, but it seems that more and more spam system looks into Received headers to score the mails. Those stupid things doesn't honor such SMTP auth and then I really need to remove the Received line when

Re: Selective smtpd_helo_restrictions question

2010-08-25 Thread Noel Jones
On 8/25/2010 12:50 PM, Charles Marcus wrote: On 2010-08-24 8:58 AM, Noel Jonesnjo...@megan.vbhcs.org wrote: On 8/24/2010 7:41 AM, Charles Marcus wrote: I guess I need some clarification now... My understanding is this is not true if you have all checks under recipient_restrictions (and

super selective spamassassin via filter

2010-08-25 Thread Stan Hoeppner
Would anyone happen to have an example guide showing the proper master.cf and main.cf parameters for setting up daemonized spamassassin to run super selectively via FILTER? I've reached the point that I'm killing about 98% of my spam load but I'm tired of the few phish/419 that make it into my

Re: Postfix integration: Oracle or LDAP?

2010-08-25 Thread Wietse Venema
Patrick Ben Koetter: There currently exists no Oracle client for Postfix. Maybe someone can donate an ODBC (or other cross-platform) client. It would be a little slower, but would allow Postfix to talk to lots of databases without needing a driver for everything and the kitchen sink. An

Re: DNS Whitelisting

2010-08-25 Thread Wietse Venema
Noel Jones: As I see it, there are two complementary paths we can take with DNS whitelists, each with a slightly different purpose. While these are both useful, neither depends on the other, so postfix can implement either or both. I'll read the entire proposal later. Would this notation

Re: DNS Whitelisting

2010-08-25 Thread Noel Jones
On 8/25/2010 6:17 PM, Wietse Venema wrote: Noel Jones: On 8/25/2010 4:27 PM, Wietse Venema wrote: Noel Jones: As I see it, there are two complementary paths we can take with DNS whitelists, each with a slightly different purpose. While these are both useful, neither depends on the other, so

RE: TLS for dummies

2010-08-25 Thread Security Admin (NetSec)
smtp_tls_CAfile = /etc/postfix/exchange.pem You can list more CAs in this file if you wish. Is there an existing file or a weblink that would list the current accepted global root CAs? Since the only one in the exchange.pem file is from my Exchange Server, I could append to this file all the

Invitación a conectarnos en LinkedIn

2010-08-25 Thread Ricardo Carrillo
LinkedIn Ricardo Carrillo requested to add you as a connection on LinkedIn: -- James, Me gustaría añadirte a mi red profesional en LinkedIn. -Ricardo Accept invitation from Ricardo Carrillo

Re: super selective spamassassin via filter

2010-08-25 Thread Noel Jones
On 8/25/2010 7:05 PM, Stan Hoeppner wrote: Noel Jones put forth on 8/25/2010 4:24 PM: FILTER is a poor choice for per-recipient filtering. FILTER is a per-message action, with only one FILTER action per message (if there are multiple FILTER actions triggered, only the last will be used). If