qmail Digest 8 May 1999 10:00:01 -0000 Issue 634

Topics (messages 25318 through 25364):

daemontools problems
        25318 by: "Oden Eriksson" <[EMAIL PROTECTED]>

Smarthost
        25319 by: Bernhard Duebi <[EMAIL PROTECTED]>

EZMLM question...
        25320 by: Tom Hukins <[EMAIL PROTECTED]>

FW: Web Interface to Qmail on Linux
        25321 by: "Matt D. Landry" <[EMAIL PROTECTED]>
        25360 by: Michael Mansour <[EMAIL PROTECTED]>

fastforward not working??
        25322 by: Jason <[EMAIL PROTECTED]>
        25323 by: Andy Walden <[EMAIL PROTECTED]>
        25324 by: Jason <[EMAIL PROTECTED]>
        25325 by: Andy Walden <[EMAIL PROTECTED]>
        25326 by: Chris Johnson <[EMAIL PROTECTED]>
        25327 by: Jason <[EMAIL PROTECTED]>
        25333 by: Logics <[EMAIL PROTECTED]>
        25338 by: Jason <[EMAIL PROTECTED]>

US Crypto export limits ruled unconstitutional
        25328 by: Dave Sill <[EMAIL PROTECTED]>
        25357 by: "Jay D. Dyson" <[EMAIL PROTECTED]>

RH 6.0
        25329 by: Mate Wierdl <[EMAIL PROTECTED]>
        25332 by: <[EMAIL PROTECTED]>

RH 6.0 upgrade and pine
        25330 by: Mate Wierdl <[EMAIL PROTECTED]>
        25331 by: Justin Bell <[EMAIL PROTECTED]>
        25334 by: "Sam" <[EMAIL PROTECTED]>
        25336 by: Matthew Kirkwood <[EMAIL PROTECTED]>

supervise/accustamp/cyclog
        25335 by: Helmut Michel <[EMAIL PROTECTED]>

removing header info
        25337 by: Samuel Dries-Daffner <[EMAIL PROTECTED]>

[PATCH] Resolving MAIL FROM domain
        25339 by: olli <[EMAIL PROTECTED]>
        25364 by: Balazs Nagy <[EMAIL PROTECTED]>

Attach police
        25340 by: Juan Carlos Castro y Castro <[EMAIL PROTECTED]>
        25341 by: "Petr Novotny" <[EMAIL PROTECTED]>

supervise question
        25342 by: Jeff Carneal <[EMAIL PROTECTED]>

What happens when qmail-send is killed?
        25343 by: Richard Letts <[EMAIL PROTECTED]>

tcpserver has long (10 min) delay for some domains?
        25344 by: "Greg Owen {gowen}" <[EMAIL PROTECTED]>

secondary MX
        25345 by: Florent Guillaume <[EMAIL PROTECTED]>
        25346 by: Chris Johnson <[EMAIL PROTECTED]>
        25349 by: Russell Nelson <[EMAIL PROTECTED]>
        25351 by: "Julian L.C. Brown" <[EMAIL PROTECTED]>
        25356 by: Russell Nelson <[EMAIL PROTECTED]>
        25359 by: Paul Farber <[EMAIL PROTECTED]>

qmail/serialmail queue names
        25347 by: [EMAIL PROTECTED] (Giulio Orsero)

User forcing bounce?
        25348 by: John Conover <[EMAIL PROTECTED]>
        25350 by: Russell Nelson <[EMAIL PROTECTED]>

RedHat Kickstart Files
        25352 by: <[EMAIL PROTECTED]>

Bounce to "somewhere else"
        25353 by: [EMAIL PROTECTED]
        25354 by: "Sam" <[EMAIL PROTECTED]>
        25355 by: Russell Nelson <[EMAIL PROTECTED]>
        25363 by: [EMAIL PROTECTED]

return-path:
        25358 by: John Conover <[EMAIL PROTECTED]>

From: header
        25361 by: [EMAIL PROTECTED]

xinetd & SMTP relay allowing
        25362 by: "Roland Koeckel" <[EMAIL PROTECTED]>

Administrivia:

To subscribe to the digest, e-mail:
        [EMAIL PROTECTED]

To unsubscribe from the digest, e-mail:
        [EMAIL PROTECTED]

To bug my human owner, e-mail:
        [EMAIL PROTECTED]

To post to the list, e-mail:
        [EMAIL PROTECTED]


----------------------------------------------------------------------


Hi,

Why is the command "svc -dx /var/lock/svc/pop3" not stopping the 
service ?.

When I type the comand "svstat /var/lock/svc/pop3" it says 
"blablabla up pgid blablabla, want down".

Is really "svc -dx /var/lock/svc/pop3" the right way to stop the 
service ?

I'm running RH6 + Bruce Guenter's *.rpm's.

(And yes..., I *have* mailed Bruce about this but he couldn't tell)



--

Kindest Regards//Oden Eriksson CNE+MCSE
(Linux enthusiast)
UIN: 952113




Hi,

is it possible to simulate sendmails SmartHost feature ?

Our IP management system can not handle MX records. Though, there are all
hosts in the DNS but no email domains. I want to configure qmail to send mails
to hosts in the local domain directly and all other mails (to subdomains or
internet) to the email hub.

~qmail/control/smtproutes:
.domain.org:
:mail.domain.org

Does not do what I want, because dep.domain.org is not in the DNS.
There are too many names not in the DNS to list them in the smtproutes file.

Cheers
Bernhard




On Thu, May 06, 1999 at 09:44:37PM -0500, Geordon VanTassle wrote:
> 
> I don't recall seeing it in the FAQ or docs  for EZMLM, but is there a way to
> set it to a "digest" mode for the mailing list?

How hard did you look? Digest mode is mentioned many times in
ezmlm's documentation. Try:

% apropos digest | grep ezmlm
% man ezmlm | grep digest

Tom





Greetings,
        This is *definately* not the place to ask this but perhaps
somebody good point to a good site or book.  I just recieved a message
that has header information of my own account...This gives me reason to
suspect either my mail server or box in general was hacked into...or
somebody could just me masquerading as myself.  What's the best way of
going through qmail logs and looking for suspicious activity?  I"m using
qmail 1.01 qpopper 2.53 on a redhat 4.2 box kernel 2.0.35  Thanks in
advance...

Cheers!,   
 
   Matthew Landry                       Design Trust Inc
   Systems Developer                    150 Danbury Rd.
   Network Administrator                Wilton Ct. 06897
   mailto:[EMAIL PROTECTED]         phone: (203)-761-1412
   http://www.destru.com                fax:   (203)-761-1419   





I use a program called Logwatch to scan through logs daily and report on
activity. You can get it from rpmfind.net and use it to scan for specific
things within logs as you choose.

Michael.

-----Original Message-----
From: Matt D. Landry [mailto:[EMAIL PROTECTED]]
Sent: Friday, 7 May 1999 23:58
To: [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Subject: Re: FW: Web Interface to Qmail on Linux



Greetings,
        This is *definately* not the place to ask this but perhaps
somebody good point to a good site or book.  I just recieved a message
that has header information of my own account...This gives me reason to
suspect either my mail server or box in general was hacked into...or
somebody could just me masquerading as myself.  What's the best way of
going through qmail logs and looking for suspicious activity?  I"m using
qmail 1.01 qpopper 2.53 on a redhat 4.2 box kernel 2.0.35  Thanks in
advance...

Cheers!,   
 
   Matthew Landry                       Design Trust Inc
   Systems Developer                    150 Danbury Rd.
   Network Administrator                Wilton Ct. 06897
   mailto:[EMAIL PROTECTED]         phone: (203)-761-1412
   http://www.destru.com                fax:   (203)-761-1419   




ive got it installed and it was working.. im using qmail to forward
everything via hosts listed in smtproutes. and i dont have a locals
file,
so everything gets forwarded.. but now fastforward doesnt work for 
the aliases I have defined... (ive run newaliases and stopped and
restarted 
qmail).. in my .qmail-default, i have | fastforward -d /etc/aliases.cdb

any ideas on why its not working/how to get that to work?

regards,
Jason

-- 
=======================================================================
|  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
|                                        |   good in everybody, you   |
|      http://welsh.dynip.com/           |   haven't met everybody.   |
=======================================================================




Are there local accounts created that have the same usernames as the
aliases?

andy

--
-----------------------------------------------------------------------
Andy Walden                        Work Email: [EMAIL PROTECTED]
Network Administrator,             Pers Email: [EMAIL PROTECTED]
MTCO Communications                Phone: (800) 859-6826
  " Reality is just Chaos with better lighting. "



On Fri, 7 May 1999, Jason wrote:

> ive got it installed and it was working.. im using qmail to forward
> everything via hosts listed in smtproutes. and i dont have a locals
> file,
> so everything gets forwarded.. but now fastforward doesnt work for 
> the aliases I have defined... (ive run newaliases and stopped and
> restarted 
> qmail).. in my .qmail-default, i have | fastforward -d /etc/aliases.cdb
> 
> any ideas on why its not working/how to get that to work?
> 
> regards,
> Jason
> 
> -- 
> =======================================================================
> |  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
> |                                        |   good in everybody, you   |
> |      http://welsh.dynip.com/           |   haven't met everybody.   |
> =======================================================================
> 





nope. no local accounts that have the same name..
usually in my logs i see where fastforward takes over, but now i only 
see that its trying to deliver to [EMAIL PROTECTED]
hostmaster is the alias im trying to intercept..

Andy Walden wrote:
> 
> Are there local accounts created that have the same usernames as the
> aliases?
> 
> andy
> 
> --
> -----------------------------------------------------------------------
> Andy Walden                        Work Email: [EMAIL PROTECTED]
> Network Administrator,             Pers Email: [EMAIL PROTECTED]
> MTCO Communications                Phone: (800) 859-6826
>   " Reality is just Chaos with better lighting. "
> 
> On Fri, 7 May 1999, Jason wrote:
> 
> > ive got it installed and it was working.. im using qmail to forward
> > everything via hosts listed in smtproutes. and i dont have a locals
> > file,
> > so everything gets forwarded.. but now fastforward doesnt work for
> > the aliases I have defined... (ive run newaliases and stopped and
> > restarted
> > qmail).. in my .qmail-default, i have | fastforward -d /etc/aliases.cdb
> >
> > any ideas on why its not working/how to get that to work?
> >
> > regards,
> > Jason
> >
> > --
> > =======================================================================
> > |  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
> > |                                        |   good in everybody, you   |
> > |      http://welsh.dynip.com/           |   haven't met everybody.   |
> > =======================================================================
> >

-- 
=======================================================================
|  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
|                                        |   good in everybody, you   |
|      http://welsh.dynip.com/           |   haven't met everybody.   |
=======================================================================






Where is it getting remotedomain from? Are you using virtualdomains or is
this all just local?

andy

--
-----------------------------------------------------------------------
Andy Walden                        Work Email: [EMAIL PROTECTED]
Network Administrator,             Pers Email: [EMAIL PROTECTED]
MTCO Communications                Phone: (800) 859-6826
  " Reality is just Chaos with better lighting. "



On Fri, 7 May 1999, Jason wrote:

> nope. no local accounts that have the same name..
> usually in my logs i see where fastforward takes over, but now i only 
> see that its trying to deliver to [EMAIL PROTECTED]
> hostmaster is the alias im trying to intercept..
> 
> Andy Walden wrote:
> > 
> > Are there local accounts created that have the same usernames as the
> > aliases?
> > 
> > andy
> > 
> > --
> > -----------------------------------------------------------------------
> > Andy Walden                        Work Email: [EMAIL PROTECTED]
> > Network Administrator,             Pers Email: [EMAIL PROTECTED]
> > MTCO Communications                Phone: (800) 859-6826
> >   " Reality is just Chaos with better lighting. "
> > 
> > On Fri, 7 May 1999, Jason wrote:
> > 
> > > ive got it installed and it was working.. im using qmail to forward
> > > everything via hosts listed in smtproutes. and i dont have a locals
> > > file,
> > > so everything gets forwarded.. but now fastforward doesnt work for
> > > the aliases I have defined... (ive run newaliases and stopped and
> > > restarted
> > > qmail).. in my .qmail-default, i have | fastforward -d /etc/aliases.cdb
> > >
> > > any ideas on why its not working/how to get that to work?
> > >
> > > regards,
> > > Jason
> > >
> > > --
> > > =======================================================================
> > > |  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
> > > |                                        |   good in everybody, you   |
> > > |      http://welsh.dynip.com/           |   haven't met everybody.   |
> > > =======================================================================
> > >
> 
> -- 
> =======================================================================
> |  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
> |                                        |   good in everybody, you   |
> |      http://welsh.dynip.com/           |   haven't met everybody.   |
> =======================================================================
> 






On Fri, May 07, 1999 at 10:02:10AM -0400, Jason wrote:
> ive got it installed and it was working.. im using qmail to forward
> everything via hosts listed in smtproutes. and i dont have a locals
> file,
> so everything gets forwarded.. but now fastforward doesnt work for 
> the aliases I have defined... (ive run newaliases and stopped and
> restarted 
> qmail).. in my .qmail-default, i have | fastforward -d /etc/aliases.cdb
> 
> any ideas on why its not working/how to get that to work?

If you don't have any local or virtual domains, ~alias/.qmail-default never
handles the delivery. See /var/qmail/doc/PIC.local2rem. All mail is delivered
remotely by qmail-remote; only qmail-local cares about .qmail files.

What you want to do is make whatever domains you're handling in your
fastforward file virtual domains, with something like this in
control/virtualdomains:

domain1.com:alias-virtuals
domain2.com:alias-virtuals
domain3.com:alias-virtuals

In ~alias/.qmail-virtuals-default you can put your fastforward line.

Chris




ok, that works great, but now when i email a real address
[EMAIL PROTECTED] (that is not an alias) I get 
failure: Sorry,_no_mailbox_here_by_that_name
the only ones that I want intercepted by fastforward are the ones 
i have defined, the rest should not be considered local..


Chris Johnson wrote:
> 
> On Fri, May 07, 1999 at 10:02:10AM -0400, Jason wrote:
> > ive got it installed and it was working.. im using qmail to forward
> > everything via hosts listed in smtproutes. and i dont have a locals
> > file,
> > so everything gets forwarded.. but now fastforward doesnt work for
> > the aliases I have defined... (ive run newaliases and stopped and
> > restarted
> > qmail).. in my .qmail-default, i have | fastforward -d /etc/aliases.cdb
> >
> > any ideas on why its not working/how to get that to work?
> 
> If you don't have any local or virtual domains, ~alias/.qmail-default never
> handles the delivery. See /var/qmail/doc/PIC.local2rem. All mail is delivered
> remotely by qmail-remote; only qmail-local cares about .qmail files.
> 
> What you want to do is make whatever domains you're handling in your
> fastforward file virtual domains, with something like this in
> control/virtualdomains:
> 
> domain1.com:alias-virtuals
> domain2.com:alias-virtuals
> domain3.com:alias-virtuals
> 
> In ~alias/.qmail-virtuals-default you can put your fastforward line.
> 
> Chris

-- 
=======================================================================
|  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
|                                        |   good in everybody, you   |
|      http://welsh.dynip.com/           |   haven't met everybody.   |
=======================================================================




try removing /var/qmail/users/assign

On Fri, 7 May 1999, Jason wrote:

> ive got it installed and it was working.. im using qmail to forward
> everything via hosts listed in smtproutes. and i dont have a locals
> file,
> so everything gets forwarded.. but now fastforward doesnt work for 
> the aliases I have defined... (ive run newaliases and stopped and
> restarted 
> qmail).. in my .qmail-default, i have | fastforward -d /etc/aliases.cdb
> 
> any ideas on why its not working/how to get that to work?
> 
> regards,
> Jason
> 
> -- 
> =======================================================================
> |  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
> |                                        |   good in everybody, you   |
> |      http://welsh.dynip.com/           |   haven't met everybody.   |
> =======================================================================
> 





there is no /var/qmail/users/assign  :)


Logics wrote:
> 
> try removing /var/qmail/users/assign
> 
> On Fri, 7 May 1999, Jason wrote:
> 
> > ive got it installed and it was working.. im using qmail to forward
> > everything via hosts listed in smtproutes. and i dont have a locals
> > file,
> > so everything gets forwarded.. but now fastforward doesnt work for
> > the aliases I have defined... (ive run newaliases and stopped and
> > restarted
> > qmail).. in my .qmail-default, i have | fastforward -d /etc/aliases.cdb
> >
> > any ideas on why its not working/how to get that to work?
> >
> > regards,
> > Jason
> >
> > --
> > =======================================================================
> > |  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
> > |                                        |   good in everybody, you   |
> > |      http://welsh.dynip.com/           |   haven't met everybody.   |
> > =======================================================================
> >

-- 
=======================================================================
|  Jason Welsh   [EMAIL PROTECTED]   |   If you think there's     |
|                                        |   good in everybody, you   |
|      http://welsh.dynip.com/           |   haven't met everybody.   |
=======================================================================




Anyone have a GIF or JPG of Dan? I'd like to have a face to place with
the name.

-Dave




-----BEGIN PGP SIGNED MESSAGE-----

On Thu, 6 May 1999, Dax Kelson wrote:

> Go DAN!!!  I can wait for qmail2 if this is what your up too...
> 
> http://www.news.com/News/Item/0,4,0-36217,00.html?st.ne.lh..ni

        For those interested in the court's opinion (thanks to Cindy
Cohn): http://jya.com/bernstein-9th.htm

        Or from the 9th Court of Appeals:

http://www.ce9.uscourts.gov/web/newopinions.nsf/f606ac175e010d64882566eb0065
8118/febd2452a8a4d79b8825676900685b71?OpenDocument

        My take: the ruling is great.  However, I will not for a moment
believe that the NSA (through the EAR) will let this slide.  They'll press
for an additional ruling which will overturn this ruling.  'Round and
'round it'll go, like a dog chasing its tail.  Finally, it'll go up to the
U.S. Supreme Court (following an unfavorable ruling), and the Supreme
Court will "mysteriously" refuse to hear it, and thus the lower court
ruling against Bernstein will stand.

        Been there, seen it, done it, got the t-shirt.

- -Jay

   (                                                             ______
   ))   .-- "There's always time for a good cup of coffee." --.   >===<--.
 C|~~| (>-- Jay D. Dyson -- [EMAIL PROTECTED] --<) |   = |-'
  `--'  `- Superman had Kryptonite, I got NT.  Life is real. -'  `-----'

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2

iQCVAwUBNzO0/s2OVDpaKXD9AQHG8gP8DRP+ah9MRpdPiriH4SR5VueeZ39B9Irm
VZ8fQ9v1MWd9VGH+QtBVdt/YDUwq1J3KhBOjCF8ZTL4AXJwQDEut5OzoquhVi8WW
MPK4CELJ8hz1Y8Nb16Rq2ikrWl/uVTskUVu6phyosOSZlbDV44xN6zipAaiFBqHg
kOitzXt+ZG4=
=xuV1
-----END PGP SIGNATURE-----





   
   I haven't yet tried this, but I believe you can get RH to stop throwing
   sendmail at you during the install simply by creating an empty RPM, naming
   it sendmail, and setting it's version to 99.99, or something like that.  I
   do not believe that RH's installer overwrites high-versioned RPMs.

Well, I have not tried to do this with sendmail proper, but I had
nmh-1.0 installed, and it got replaced by 6.0's nmh-0.27 during the upgrade.
Sad.

Mate




The RedHat Kickstart install alleviates all your sendmail woes. I use the
Kickstart install method on our network here and it's great! I have one
floppy that I use for all our servers: I stick in the floppy and walk
away. No sendmail, all qmail.

It works just as well installing from the local CD-ROM. I have never used
it for an upgrade but I'm sure the same lines I used for removing sendmail
in the install would work the same for upgrade. You have full control
after the install. It's like typing in commands at the bash prompt on the
second VT, but it's all automated.

If anyone is interested I have a big slew of Kickstart files. I think it's
the best way to install, it's probably just as good for upgrading aswell.

jason.


On Fri, 7 May 1999, Mate Wierdl wrote:

>    
>    I haven't yet tried this, but I believe you can get RH to stop throwing
>    sendmail at you during the install simply by creating an empty RPM, naming
>    it sendmail, and setting it's version to 99.99, or something like that.  I
>    do not believe that RH's installer overwrites high-versioned RPMs.
> 
> Well, I have not tried to do this with sendmail proper, but I had
> nmh-1.0 installed, and it got replaced by 6.0's nmh-0.27 during the upgrade.
> Sad.
> 
> Mate
> 





Another funny thing is that the 6.0 upgrade moved my pine.conf to
pine.conf.rpmsave, and replaced it with *nothing*.  Funny, funny...


Mate




On Fri, May 07, 1999 at 10:42:11AM -0500, Mate Wierdl wrote:
# Another funny thing is that the 6.0 upgrade moved my pine.conf to
# pine.conf.rpmsave, and replaced it with *nothing*.  Funny, funny...
# 

I hope you are reporting these problems to RedHat

-- 
/- [EMAIL PROTECTED] --------------- [EMAIL PROTECTED] -\
|Justin Bell  NIC:JB3084| Time and rules are changing.         |
|Pearson                | Attention span is quickening.        |
|Developer              | Welcome to the Information Age.      |
\-------- http://www.superlibrary.com/people/justin/ ----------/




Justin Bell writes:

> On Fri, May 07, 1999 at 10:42:11AM -0500, Mate Wierdl wrote:
> # Another funny thing is that the 6.0 upgrade moved my pine.conf to
> # pine.conf.rpmsave, and replaced it with *nothing*.  Funny, funny...
> # 
> 
> I hope you are reporting these problems to RedHat

It's not a bug, it's a feature.  When upgrading, RPM will keep
configuration files only if it is reasonably sure that any custom-made
changes to config files won't break the new version.  Hopefully, there will
be messages in /tmp/INSTALL.LOG specifying which config files have been
reset, and where.


-- 
Sam





On Fri, 7 May 1999, Sam wrote:

> > On Fri, May 07, 1999 at 10:42:11AM -0500, Mate Wierdl wrote:
> > # Another funny thing is that the 6.0 upgrade moved my pine.conf to
> > # pine.conf.rpmsave, and replaced it with *nothing*.  Funny, funny...

rpm -ql pine will probably tell you that the new pine doesn't include a
pine.conf in /usr/lib.  It's now (correctly) in /etc.

> > I hope you are reporting these problems to RedHat
> 
> It's not a bug, it's a feature.  When upgrading, RPM will keep
> configuration files only if it is reasonably sure that any custom-made
> changes to config files won't break the new version.  Hopefully, there
> will be messages in /tmp/INSTALL.LOG specifying which config files have
> been reset, and where.

Exactly.

Matthew.





I decided to run a supervised copy of qmail. As I found in the list archiv, 
I was not the first one who has trouble with the pipe in the /var/qmail/rc 
file:
  exec env - PATH="/var/qmail/bin:$PATH" \
  qmail-start ./Mailbox accustamp | setuser qmaill cyclog /var/log/qmail

But I also found that the online FAQ on djb's qmail page has changed on how 
to use cyclog. It says now: 
Replace splogger qmail with sh -c 'accustamp | cyclog /var/qmail/log'.

Now my /var/qmail/rc file with
  exec env - PATH="/var/qmail/bin:$PATH" \
  qmail-start ./Mailbox sh -c 'accustamp | cyclog /var/log/qmail'
works without any problem under supervise.

I hope this information is helpful.

-- Helmut





I have written a perl script using the NNTPClient module that forwards 
from a .qmail-alias to a local newsgroup. The script work fine, but I
would like some help to see if I can get the header info removed from the
top of each message as it appears in the forwarded posting.

Also, if there is interest in the script I can forward to individuals or
the list.

Samuel

This is the header info I would like to get rid of:

Received: (qmail 1008607 invoked by uid 400); 7 May 1999 09:44:04 -0700
Date: Fri, 7 May 1999 09:44:04 -0700 (PDT)
From: Test Student Account <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: my third posting
Message-ID: <[EMAIL PROTECTED]>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII






On Thu, 6 May 1999, Sam wrote:
> > Nowadays I just bored to get mail from illegal hostnames and I created a
> > diff against vanilla qmail-1.03 (see attachment).
> > It is simple.  It checks for a DNS entry for the MAIL FROM domain if
> > control/mfcheck or the MFCHECK environment variable is set to nonzero.
> > Please check it out.  Any comments/bugfixes/etc are welcomed.
> A) It's been done before.
Could you give an url then? I wanna disallow receiving/sending mail from 
_some_ illegal domains too..

Bye.Olli.





On Fri, 7 May 1999, olli wrote:

> Could you give an url then? I wanna disallow receiving/sending mail from 
> _some_ illegal domains too..

On Monday I'll go working and I'll upload the most recent version to a
public site.  I've put the error sending directly after checking (eg. into
the MAIL FROM: parsing) and implemented distinguish between DNS hard and
soft errors.

Film at 11.
-- 
Regards: Kevin (Balazs)





I want to bounce back EVERYTHING that arrives on my mail server (qmail)
and has an attachment of type .exe, no matter how many .qmail-this and
.qmail-that are scattered around.

Filtering the body against the appropriate MIME headers shouldn't be a
problem. My question is, where is the place to intercept ALL incoming
messages?

[]'s,
-- 

 ___THE___ "Commercial OS vendors are, at the moment, all closed
 \  \ /  /  economies, and doomed to fall in their competition with
  \  V  /   open economies just as communism eventually fell."
   \   /                            -- H. Reiser, Unix OS developer
   /   \     _____________________________________________________
  /  ^  \   | Juan Carlos Castro y Castro - [EMAIL PROTECTED] |
 /  / \  \  |  Diretor de Inform�tica e Eventos Sobrenaturais da  |
 ~~~   ~~~  |                 E-RACE CORPORATION                  |
   RACER     -----------------------------------------------------




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> I want to bounce back EVERYTHING that arrives on my mail server (qmail)
> and has an attachment of type .exe, no matter how many .qmail-this and
> .qmail-that are scattered around.
> 
> Filtering the body against the appropriate MIME headers shouldn't be a
> problem. My question is, where is the place to intercept ALL incoming
> messages?

The three easiest picks are
1. A wrapper around qmail-smtpd - but it's too much a work 
probably
2. A wrapper around qmail-queue (see www.qmail.org for patch that 
allows you to run another program) - you would probably return 
SMTP hard error
3. A catch-all virtual domain; you'll have probably to fiddle around 
with two instances of qmail and/or RELAYCLIENTs.

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.0.2 -- QDPGP 2.60 
Comment: http://community.wow.net/grt/qdpgp.html

iQA/AwUBNzM37VMwP8g7qbw/EQIURgCfYSvFxRgGpM71fB/jUr0B+fH2pIIAn21W
gqX67T8LcxGsa6lUzGMlEHNo
=VwOt
-----END PGP SIGNATURE-----
--
Petr Novotny, ANTEK CS
[EMAIL PROTECTED]
http://www.antek.cz
PGP key ID: 0x3BA9BC3F
-- Don't you know there ain't no devil there's just God when he's drunk.
                                                             [Tom Waits]





Sorry if this has been discussed before.  Only thing I could find related
was a short thread on running sshd with supervise.

I'm trying to supervise a daemon that forks and detaches itself from the
TTY, but supervise appears to be trying to restart it every second.  The
daemon I want to supervise has no switch to tell it not to detach from the
TTY, so is there anything I can do to use supervise with this daemon?

Also, what is the major factor in this scenario...is the problem that the
parent immediately forks, or that it detaches from the TTY.  It would seem
that supervise could simply watch the parent and restart it...so I'm
inclined to think the fork (without exit) isn't the real problem.  Am I
wrong?

--
  Jeff Carneal - Sys Admin - Apex Internet          
  [EMAIL PROTECTED] http://www.apex.net (502) 442-5363

  The opinions expressed above aren't really mine.
  They belong to someone else who also refuses to 
  take responsibility for them. 





On Wed, 5 May 1999, Fred Lindberg wrote:

> Thanks for confirming this! This means that a cleaner shutdown might be
> to kill all qmail-remote[/local] as well as qmail-send.

possibly, but you don't know if it's /just/ done the CRLF '.' CRLF at the
end of the message and is waiting for the confirmation back, in that case
you might end up with duplication.

myself, for a linux system only (killall behaving completely differently
on a solaris machine!!] I do the following in my qmail.init script

svc -d -x /var/qmail/supervise
while (killall -0 qmail-send) do
   echo waiting for qmail to exit
   sleep 5
done

the shutdown script then spins waiting for qmail-send to shutdown tidily
before proceeding with the rest of the shutdown scripts 

Richard






    Were you having problems with all outside hosts, or just some?

    We're running ~2000 inbound and ~1000 outbound messages a day, and so
far only had one site (or one ISP, covering two sites) let us know they have
this problem.

> I had a similar problem - took a very long time to establish connections
> from outside my own network. It turned out to be DNS-related. Basically, I
> only allow specific ports through the router, and deny everything else.
i.e.
> I allow ports 22,25,110
> What I had to do was to allow packets with the ACK bit set to pass on
other
> ports i.e. the connection is established, and a port is negotiated for the
> server and client to talk on. The server then continues listening on the
> default SMTP and POP3 ports.

--
    gowen -- Greg Owen -- [EMAIL PROTECTED]






Hello,

What would be a basic configuration for a secondary MX, whose
only role would be "queue everything allowed (rcpthosts) and
send'em when primary comes back up ?"

Is rcpthosts + smtproutes sufficient ?

Thanks.




On Fri, May 07, 1999 at 10:46:45PM +0200, Florent Guillaume wrote:
> Hello,
> 
> What would be a basic configuration for a secondary MX, whose
> only role would be "queue everything allowed (rcpthosts) and
> send'em when primary comes back up ?"
> 
> Is rcpthosts + smtproutes sufficient ?

rcpthosts is all you need. Add any domain you're secondary MX for to rcpthosts
and nowhere else.

Chris




Florent Guillaume writes:
 > Hello,
 > 
 > What would be a basic configuration for a secondary MX, whose
 > only role would be "queue everything allowed (rcpthosts) and
 > send'em when primary comes back up ?"

What problem are you trying to solve?

 > Is rcpthosts + smtproutes sufficient ?

rcpthosts is sufficient; smtproutes is not needed unless the DNS is
misconfigured.

-- 
-russ nelson <[EMAIL PROTECTED]>  http://crynwr.com/~nelson
Crynwr supports Open Source(tm) Software| PGPok |   There is good evidence
521 Pleasant Valley Rd. | +1 315 268 1925 voice |   that freedom is the
Potsdam, NY 13676-3213  | +1 315 268 9201 FAX   |   cause of world peace.




> > Is rcpthosts + smtproutes sufficient ?
>
>rcpthosts is sufficient; smtproutes is not needed unless the DNS is
>misconfigured.

Isn't smtproutes needed for when the primary MX goes down? Otherwise QMAIL
will attempt to deliver locally rather than store messages until the
primary MX goes back up?  


Regards,

Julian L.C. Brown
Interware.Net Inc.
mailto:[EMAIL PROTECTED]
http://www.interware.net






Julian L.C. Brown writes:
 > > > Is rcpthosts + smtproutes sufficient ?
 > >
 > >rcpthosts is sufficient; smtproutes is not needed unless the DNS is
 > >misconfigured.
 > 
 > Isn't smtproutes needed for when the primary MX goes down? Otherwise QMAIL
 > will attempt to deliver locally rather than store messages until the
 > primary MX goes back up?  

Nope, that's why you don't put it anywhere but rcpthosts.  If the
primary host is down, an SMTP client will deliver it here.  This
machine will happily receive it since it's in rcpthosts, however
there's no entry in locals or virtualdomains, the mail is marked as
remote.  If there was no better MX record, THEN the mail would
bounce.  But there is -- the primary server.

I didn't see your explanation of the problem that you expect to solve
with a secondary MX record, though.

-- 
-russ nelson <[EMAIL PROTECTED]>  http://crynwr.com/~nelson
Crynwr supports Open Source(tm) Software| PGPok |   There is good evidence
521 Pleasant Valley Rd. | +1 315 268 1925 voice |   that freedom is the
Potsdam, NY 13676-3213  | +1 315 268 9201 FAX   |   cause of world peace.




Qmail should see that it is not the best MX for a domain and then send it
to the best MX periodically.

Paul D. Farber II
Farber Technology
Ph. 570-628-5303
Fax 570-628-5545
[EMAIL PROTECTED]

On Fri, 7 May 1999, Julian L.C. Brown wrote:

> > > Is rcpthosts + smtproutes sufficient ?
> >
> >rcpthosts is sufficient; smtproutes is not needed unless the DNS is
> >misconfigured.
> 
> Isn't smtproutes needed for when the primary MX goes down? Otherwise QMAIL
> will attempt to deliver locally rather than store messages until the
> primary MX goes back up?  
> 
> 
> Regards,
> 
> Julian L.C. Brown
> Interware.Net Inc.
> mailto:[EMAIL PROTECTED]
> http://www.interware.net
> 
> 
> 





On Thu, 6 May 1999 10:29:52 +0100, hai scritto:

>For readability and manageability I would prefer to create the queues by
>hostname, however when I do this the target can no longer initiate the
>transfer, although I can still push mail to them when they are up.

If you are using AutoTURN:

Standard autoturn does:

maildirsmtp $TCPREMOTEIP autoturn-$TCPREMOTEIP- $TCPREMOTEIP AutoTURN

man maildirsmtp:
maildirsmtp dir prefix host helohost

So autoturn is looking for a maildir called "as an ip address".


If you are not using AutoTURN:
I don't know :-)


-- 
Giulio
[EMAIL PROTECTED]




Is there a way for a user to force a bounce out of ~/.qmail, with an
unknown error?

        Thanks,

        John

BTW, its to automatically refuse email, and return to sender.   

-- 

John Conover, 631 Lamont Ct., Campbell, CA., 95008, USA.
VOX 408.370.2688, FAX 408.379.9602, whois '!JC154'
[EMAIL PROTECTED], http://www2.inow.com/~conover/john.html





John Conover writes:
 > Is there a way for a user to force a bounce out of ~/.qmail, with an
 > unknown error?

The canonical method is:

|echo "Go away, you clueless luser"; exit 100

The only problem is when you get spammed at that address, because
typically a spammer's envelope sender is a total fabrication.

-- 
-russ nelson <[EMAIL PROTECTED]>  http://crynwr.com/~nelson
Crynwr supports Open Source(tm) Software| PGPok |   There is good evidence
521 Pleasant Valley Rd. | +1 315 268 1925 voice |   that freedom is the
Potsdam, NY 13676-3213  | +1 315 268 9201 FAX   |   cause of world peace.




A few people asked to see a kickstart install, so I'll post them here. I
know this is more system administration, but it is generally useful.

This is the kickstart file. You put it on your boot floppy and call it
ks.cfg. Then at the lilo prompt type linux ks=floppy. And you walk away
and have a coffee. The last server I build took 6 minutes.

You usually have to erase the *.msg files on the boot disk to make room
for the kickstart configuration file.

If you want to have the boot floppy go immediately into the install then
change the syslinux.cfg to read:

default ks
label ks
    prompt 0
    kernel vmlinuz
    append ks initrd=initrd.img

Then you just stick in the floppy and walk away.

There is also a good KickStart-HOWTO at one of the many LDP sites. Tells
you how to make your own custom install. I just keep everything here on
our network and just FTP anything else I need from our repository machine
on the network. Whatever floats your boat!

This file works great for 5.2, but the rpm install in the %post section
of the kickstart doesn't seem to want to work in 6.0. I've asked some @
Redhat about it so we'll see. The source for the install doesn't seem to
be on any of the redhat FTP sites so I can't tell what's wrong (the source
wasn't anywhere I could find it anyway.). I'm sure it will work by the
time Redhat is selling CDs, which will be in a couple of days.

If anyone has anymore kickstart questions, feel free to drop me a line.
It's saved me billions of hours. And it's a great way to have a set of
consistent machines.

jason.

# -----------------------------------------------------------------------------
# L A N G U A G E   S P E C I F I C A T I O N (Required for upgrade)
# -----------------------------------------------------------------------------

lang en

# -----------------------------------------------------------------------------
# N E T W O R K   C O N F I G U R A T I O N
# -----------------------------------------------------------------------------

network --bootproto dhcp

# -----------------------------------------------------------------------------
# I N S T A L L A T I O N   M E T H O D (Required for upgrade)
# -----------------------------------------------------------------------------

nfs --server 10.10.1.3 --dir /repository/redhat5.2

# -----------------------------------------------------------------------------
# K E Y M A P   S P E C I F I C A T I O N (Required for upgrade)
# -----------------------------------------------------------------------------
 
keyboard us

# -----------------------------------------------------------------------------
# P A R T I T I O N   S P E C I F I C A T I O N
# -----------------------------------------------------------------------------
zerombr yes
clearpart           --all
part /              --size  500
part swap           --size  128
part /www           --size 2000
part /tmp           --size  200

# -----------------------------------------------------------------------------
# I N S T A L L / U P G R A D E   S P E C I F I C A T I O N (Required for upgrade)
# -----------------------------------------------------------------------------
 
install

# -----------------------------------------------------------------------------
# R O D E N T   S P E C I F I A T I O N
# -----------------------------------------------------------------------------

mouse --kickstart --noprobe none

# -----------------------------------------------------------------------------
# T I M E Z O N E   S P E C I F I C A T I O N
# -----------------------------------------------------------------------------

timezone --utc US/Eastern

# -----------------------------------------------------------------------------
# R O O T   P A S S W O R D
# -----------------------------------------------------------------------------
#
rootpw youthinkso
#
# -----------------------------------------------------------------------------
# A U T H E N T I C A T I O N  C O N F I G U R A T I O N
# -----------------------------------------------------------------------------

#auth # This is for 6.0 only

# -----------------------------------------------------------------------------
# L I L O   C O N F I G U R A T I O N (Required for upgrade)
# -----------------------------------------------------------------------------

lilo --location mbr

# -----------------------------------------------------------------------------
# P A C K A G E   S P E C I F I C A T I O N
# -----------------------------------------------------------------------------
#
# For a server we want some base packages. We take as much stock
# RedHat as we can, but if we need newer versions of packages, or
# we need packages that aren't GPL'd then we'll install those
# later via ftp.

%packages
@ Network Management Workstation
@ C Development
@ C++ Development
cvs
bzip2
dhcp
dhcpcd
expect
howto
jed
lynx
mc
mgetty
mkisofs
nfs-server
rsync
samba
tcl
tk
wu-ftpd
xntp3

# -----------------------------------------------------------------------------
# P O S T - I N S T A L L A T I O N   C O M M A N D S
# -----------------------------------------------------------------------------

%post

mkdir /cdrom
mkdir /floppy
makewhatis
updatedb

rpm -e sendmail --nodeps
rpm -e bind-utils --nodeps
/usr/sbin/useradd -d / -s /bin/false named

LOGFILE="/tmp/install.log 2>&1"

PACKAGES="SSLeay            \
          arkeia-client     \
          arkeia-server     \
          arkeia-gui        \
          apcupsd           \
          apache-mod_ssl    \
          analog            \
          bind-chroot       \
          bind-chroot-utils \
          cdrecord          \
          cyrus-imapd       \
          mon               \
          smtpclient        \
          sniffit           \
          ssh               \
          qmail             \
          tripwire          \
          xinetd"

for package in $PACKAGES
do

    echo "-----------"                          >> /tmp/install.log 2>&1
    echo "Installing $package ..."              >> /tmp/install.log 2>&1
    rpm -i ftp://10.10.1.3/rpms/$package.rpm    >> /tmp/install.log 2>&1
    echo "Done installing $package"             >> /tmp/install.log 2>&1
    echo                                        >> /tmp/install.log 2>&1

done

DORMANT_SERVICES="arkeia    \
                  dhcpd     \
                  gpm       \
                  inet      \
                  lpd       \
                  named     \
                  nfs       \
                  pcmcia    \
                  qmail     \
                  smb"

for service in $DORMANT_SERVICES
do
    /sbin/chkconfig --del $service
done

ACTIVE_SERVICES="httpd      \
                 sshd       \
                 xinetd     \
                 xntpd"
                          
for service in $ACTIVE_SERVICES
do
    /sbin/chkconfig --add $service
done

# These are the time servers out on the net. This is
# where xntpd looks for hosts to use as timeservers.

echo "gw.compusense.com"    >> /etc/ntp/step-tickers
echo "tock.usno.navy.mil"   >> /etc/ntp/step-tickers
echo "clock.llnl.gov"       >> /etc/ntp/step-tickers
echo    "norad.arc.nasa.gov"   >> /etc/ntp/step-tickers

# We'll have to fix the rpm. I'm not sure why
# chkconfig isn't making xntpd startup on boot.
# We will just make it startup on the standard
# run levels.

/sbin/chkconfig --level 3 xntpd on
/sbin/chkconfig --level 4 xntpd on
/sbin/chkconfig --level 5 xntpd on

# This should fix the stupid thing that redhat installer
# is doing. It keeps giving me bootp and not dhcp. I ask
# for dhcp and it gives me bootp what za hell. We'll just
# put in the proper network scripts.

cat <<EOF > /etc/sysconfig/network
NETWORKING=yes
FORWARD_IPV4=false
EOF

cat <<EOF > /etc/sysconfig/network-scripts/ifcfg-eth0
DEVICE=eth0
BOOTPROTO=dhcp
ONBOOT=yes
EOF

# Now we want to run initialize the tripwire database
# so we get a clean snapshot of what our system is
# at install time.

(

PWD=`pwd`
cd /security/tripwire
./tripwire -c /security/tripwire/tw.config -initialize >> /tmp/install.log 2>&1
cd $PWD

# We need the proper hostname so that we can correctly name the
# database the tripwire just created. When the OS is layed down
# the first time the machine has no host name so we'll have to
# help it out. If the bootproto dhcp worked maybe I wouldn't
# have to do this. Oh well.

mv ./databases/tw.db* ./databases/tw.db_www

)







Hi,

Can anyone tell me how to cause bounced message to go to "another
address".  We send out messages to customers on behalf of our agents.
When a message bounces, we want it to bounce to the "agent", not to the
sender of the message.

Each agent has their own email address.  Is there something I can put in
the header like:

    Bounce-to: [EMAIL PROTECTED]

Or is there any other way to do it?  We run Qmail and are VERY happy
with it.

Thanks,
Dick




On 7 May 1999 [EMAIL PROTECTED] wrote:

> Hi,
> 
> Can anyone tell me how to cause bounced message to go to "another
> address".  We send out messages to customers on behalf of our agents.
> When a message bounces, we want it to bounce to the "agent", not to the
> sender of the message.

RTFM RFC821.

Set the correct message envelope sender for your outgoing mail, using the
-f option to qmail-inject.






[EMAIL PROTECTED] writes:
 >     Bounce-to: [EMAIL PROTECTED]
 > 
 > Or is there any other way to do it?

Set the envelope sender:

/var/qmail/bin/qmail-inject -f [EMAIL PROTECTED]

-- 
-russ nelson <[EMAIL PROTECTED]>  http://crynwr.com/~nelson
Crynwr supports Open Source(tm) Software| PGPok |   There is good evidence
521 Pleasant Valley Rd. | +1 315 268 1925 voice |   that freedom is the
Potsdam, NY 13676-3213  | +1 315 268 9201 FAX   |   cause of world peace.





It also seemed to work to set Return-path: [EMAIL PROTECTED] in
the header (which is easier given my application).  Is this expected or
did I mis-interpret my results?

Thanks,
Dick

> [EMAIL PROTECTED] writes:
>  >     Bounce-to: [EMAIL PROTECTED]
>  > 
>  > Or is there any other way to do it?
> 
> Set the envelope sender:
> 
> /var/qmail/bin/qmail-inject -f [EMAIL PROTECTED]
> 
> -- 
> -russ nelson <[EMAIL PROTECTED]>  http://crynwr.com/~nelson
> Crynwr supports Open Source(tm) Software| PGPok |   There is good evidence
> 521 Pleasant Valley Rd. | +1 315 268 1925 voice |   that freedom is the
> Potsdam, NY 13676-3213  | +1 315 268 9201 FAX   |   cause of world peace.
> 





Just as a clarification, Return-Path: contains the envelope address?

This would be taken from the "MAIL FROM:" in the sendmail dialog,
right?

        Thanks,

        John

-- 

John Conover, 631 Lamont Ct., Campbell, CA., 95008, USA.
VOX 408.370.2688, FAX 408.379.9602, whois '!JC154'
[EMAIL PROTECTED], http://www2.inow.com/~conover/john.html





When I set the From: field in an outgoing message, qmail changes it to
me.  The way I read the qmail documentation, it is not supposed to do
this (by default anyway).  I expect I must have something configured to
be causing this.

When I set the From: field, I want qmail to leave it alone.

Can anyone suggest what I may have mis-configured, or why qmail is
changing my From: field on all my outgoing messages?

I have read all the qmail doc's and am just not able to find it.

Thanks,
Dick




Hi folks

I found an easy way to allow clients to use qmail as a relay form the
Intranet and
to disable relaying from the Internet. This applys only to a server with two
network
devices (One connected to the Intranet and one connected to the Internet).
But since xinetd allows multible configurations for the same service as long
as they have unique id's you could restrict relaying with "only_from" as
well.

service smtp
{
        socket_type     = stream
        protocol        = tcp
        wait            = no
        user            = qmaild
        id              = qmail-extern
        interface       = X.X.X.X (real Internet IP-Address)
        server          = /var/qmail/bin/tcp-env
        server_args     = /var/qmail/bin/qmail-smtpd
}

service smtp
{
        socket_type     = stream
        protocol        = tcp
        wait            = no
        user            = qmaild
        id              = qmail-intern
        interface       = 192.168.1.1
        env             = RELAYCLIENT=
        server          = /var/qmail/bin/tcp-env
        server_args     = /var/qmail/bin/qmail-smtpd
}

Put both configurations in your /etc/xinetd.conf and enable smtp. The only
thing added to the second configuration is the  "env = RELAYCLIENT=" line.
This tells qmail to relay every mail incoming on the internal interface
without checking control/rcpthosts. Now you can get rid of tcpd.

Greetings

Roland




Reply via email to