[courier-users] Re: grrrr

2004-05-24 Thread m
Jerry Amundson writes: 

You have just the one file in smtpaccess/ right?
Just to emphasize, /all/ files are processed in this directory. That 
includes editor backup files (*~) and editor autosave files (#*#). 

I've been bitten by this more than once. 

Sam would you accept patches that exclude these files (and some other known 
artifacts)? 

M4
--
Courier-mta rocks! 


---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


[courier-users] Re: grrrr

2004-05-24 Thread Sam Varshavchik
[EMAIL PROTECTED] writes:
Jerry Amundson writes:
You have just the one file in smtpaccess/ right?
Just to emphasize, /all/ files are processed in this directory. That
includes editor backup files (*~) and editor autosave files (#*#).
I've been bitten by this more than once.
Sam would you accept patches that exclude these files (and some other known
artifacts)?
Sure.  The script in the current version already excludes any subdirectory
named CVS.



pgpQ7Vtr8RnzQ.pgp
Description: PGP signature


[courier-users] Re: grrrr

2004-05-21 Thread Lloyd Zusman
The other day, I posted a syslog-based proceure that you can use to
detect when undeliverable error bounces are getting repeatedly queued on
your side, and then to automatically remove them from your queue.

Look back in the mailing list for posts by me during this week, and
you'll find a description of the method that I use within syslog, and in
a second message by me, you'll find the Perl script that I use to
actually delete the messages.

This script can be modified to look at any criteria in the queue control
file and any headers or body data in the message, and to use that info
to decide whether the message should be removed from the queue.

It's a bit of a hack, but it works well for me.


 I am sorry to keep bringing this up, but I have tried everything and am
 not sure where to turn next!

 The issue: one particular domain *appears* to be using me as a
 relay. The messages sit in my mailq and my log grows and grows.  I have
 only a few actual users right now and I want to get this addressed
 before I get too many.

 My smtpaccess file ONLY has allow,RELAYCLIENT for localhost and the IP I
 registered for my domain. My locals file only has localhost and my
 domain and my esmtpacceptmailfor also is localhost and my domain as is
 hosteddomains. My installation is nothing special nor have I made any
 drastic changes to anything.

 Now, to be clear, I do not receive ANY spam from this domain or any
 other for that matter so I do not think this is a filtering issue,
 although it may be.

 So I guess my question has a few options:

 A.) How do I prevent this one domain from attempting to go through me
 and further HOW are they doing it?

 B.) How can I set the mailq so it does not hold onto these emails
 thereby slowing MY mail down? NOTE: I am not asking how to remove all
 the messages, I know how to do that. :)

 C.) Is there some place that I have not looked that I should be looking?
 Is this perhaps not even a courier issue but perhaps something in my
 system? (I don't think so but it does not hurt to consider it.)

 I am running an LFS system with the 2.4.25 kernel.

 Again I apologize for the continued whining and posting, but this is
 very frustrating to me and I would very much like to make it stop, so
 any help whatsoever, even if you think it is obscure, would be greatly
 appreciated.

 Thanks in advance,

 Rob



 ---
 This SF.Net email is sponsored by: Oracle 10g
 Get certified on the hottest thing ever to hit the market... Oracle
 10g. Take an Oracle 10g class now, and we'll give you the exam FREE.
 http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
 ___
 courier-users mailing list
 [EMAIL PROTECTED]
 Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


-- 
 Lloyd Zusman
 [EMAIL PROTECTED]
 God bless you.



---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


[courier-users] Re: grrrr

2004-05-21 Thread Jerry Amundson
Robert Horton writes: 

I am sorry to keep bringing this up, but I have tried everything and am 
not sure where to turn next! 

The issue: one particular domain *appears* to be using me as a relay. The 
messages sit in my mailq and my log grows and grows.  I have only a few 
actual users right now and I want to get this addressed before I get too 
many.
Try posting entries from syslog which show when these messages are delivered 
to you. The session will have something like  courieresmtpd: started,ip= 
and continue from there... 

My smtpaccess file ONLY has allow,RELAYCLIENT for localhost and the IP I 
registered for my domain. My locals file only has localhost and my domain 
and my esmtpacceptmailfor also is localhost and my domain as is 
hosteddomains. My installation is nothing special nor have I made any 
drastic changes to anything.
You have just the one file in smtpaccess/ right?
And in it the IP addresses and actions are separated by *a single tab 
character* right?
You should not have the IP I registered for my domain in it - that IP does 
not *relay* to you - it is you! 

jerry 


---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


[courier-users] Re: grrrr

2004-05-21 Thread Robert Horton
On Friday, May 21, 2004, at 10:03 US/Pacific, Jerry Amundson wrote:
Robert Horton writes:
I am sorry to keep bringing this up, but I have tried everything and  
am not sure where to turn next! The issue: one particular domain  
*appears* to be using me as a relay. The messages sit in my mailq and  
my log grows and grows.  I have only a few actual users right now and  
I want to get this addressed before I get too many.
Try posting entries from syslog which show when these messages are  
delivered to you. The session will have something like   
courieresmtpd: started,ip= and continue from there...

 Here are the last 40 lines of my syslog:
May 21 10:01:56 kitykage courierd:  
started,id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],m 
odule=esmtp,host=sinamail.com,addr=[EMAIL PROTECTED]
May 21 10:01:56 kitykage courierd:  
started,id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],m 
odule=esmtp,host=sinamail.com,addr=[EMAIL PROTECTED]
May 21 10:01:56 kitykage courierd:  
started,id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],m 
odule=esmtp,host=sinamail.com,addr=[EMAIL PROTECTED]
May 21 10:01:56 kitykage courierd:  
started,id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],m 
odule=esmtp,host=sinamail.com,addr=[EMAIL PROTECTED]
May 21 10:01:56 kitykage courierd:  
started,id=0008EC36.40AE34C4.3751,from=[EMAIL PROTECTED],module 
=esmtp,host=sinamail.com,addr=[EMAIL PROTECTED]
May 21 10:01:56 kitykage courierd: Waiting.  shutdown time=none, wakeup  
time=Fri May 21 10:02:00 2004, queuedelivering=360, inprogress=16
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],addr=jxz 
[EMAIL PROTECTED]: Connection timed out
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],addr=jxz 
[EMAIL PROTECTED],status: deferred
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],addr=jxz 
[EMAIL PROTECTED]: Connection timed out
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],addr=jxz 
[EMAIL PROTECTED],status: deferred
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],addr=jxz 
[EMAIL PROTECTED]: Connection timed out
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],addr=jxz 
[EMAIL PROTECTED],status: deferred
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],addr=jxz 
[EMAIL PROTECTED]: Connection timed out
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC3F.40AE34D0.3767,from=[EMAIL PROTECTED],addr=jxz 
[EMAIL PROTECTED],status: deferred
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC36.40AE34C4.3751,from=[EMAIL PROTECTED],addr=[EMAIL PROTECTED] 
amail.com: Connection timed out
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC36.40AE34C4.3751,from=[EMAIL PROTECTED],addr=[EMAIL PROTECTED] 
amail.com,status: deferred
May 21 10:01:56 kitykage courierd:  
completed,id=0008EC36.40AE34C4.3751
May 21 10:01:56 kitykage courierd:  
completed,id=0008EC3F.40AE34D0.3767
May 21 10:01:56 kitykage courierd: Waiting.  shutdown time=none, wakeup  
time=Fri May 21 10:02:00 2004, queuedelivering=360, inprogress=14
May 21 10:01:56 kitykage courieresmtp:  
id=0008EBCF.40AE35F4.3CF6,from=[EMAIL PROTECTED],addr=fu 
[EMAIL PROTECTED]: 250  
[EMAIL PROTECTED] Queued mail for  
delivery
May 21 10:01:56 kitykage courieresmtp:  
id=0008EBCF.40AE35F4.3CF6,from=[EMAIL PROTECTED],addr=fu 
[EMAIL PROTECTED],size=3623,success: delivered: mx3.hotmail.com  
[65.54.167.5]
May 21 10:01:56 kitykage courieresmtp:  
id=0008EBCF.40AE35F4.3CF6,from=[EMAIL PROTECTED],addr=fu 
[EMAIL PROTECTED],size=3623,status: success
May 21 10:01:56 kitykage courierd:  
completed,id=0008EBCF.40AE35F4.3CF6
May 21 10:01:56 kitykage courierd: Waiting.  shutdown time=none, wakeup  
time=Fri May 21 10:02:00 2004, queuedelivering=359, inprogress=13
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC88.40AE3602.3D28,from=[EMAIL PROTECTED],addr= 
[EMAIL PROTECTED]: 554 delivery error: dd This user doesn't  
have a yahoo.com.tw account ([EMAIL PROTECTED]) [0] -  
mta128.mail.tpe.yahoo.com
May 21 10:01:56 kitykage courieresmtp:  
id=0008EC88.40AE3602.3D28,from=[EMAIL PROTECTED],addr= 
[EMAIL PROTECTED],status: failure
May 21 10:01:56 kitykage courierd:  
completed,id=0008EC88.40AE3602.3D28
May 21 10:01:56 kitykage courierd:  
started,id=0008EC88.40AE3602.3D28,from=,module=dsn,host=,addr=4ho 
[EMAIL PROTECTED]
May 21 10:01:56 kitykage courierd: Waiting.  shutdown time=none, wakeup  
time=Fri May 21 10:02:00 2004, queuedelivering=359, inprogress=13
May 21 10:01:56 kitykage courieresmtpd:  
started,ip=[:::219.91.111.230]
May 21 10:01:56 kitykage courierd:  
newmsg,id=0008EBCF.40AE3604.3D5A: dns; localhost (localhost  
[127.0.0.1])
May 21 10:01:56 kitykage courierd:  

Re: [courier-users] Re: grrrr

2004-05-21 Thread Gordon Messmer
Robert Horton wrote:
Yes I have one smtpaccess file called default. I shall post what I  
have for you to see as well:

Did you run makesmtpaccess after the last time you updated the file?
check:
ls -l /etc/courier/smtpaccess*
Compare the modification time on smtpaccess.dat to the mtime on the 
files in the smtpaccess directory.


---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


Re: [courier-users] Re: grrrr

2004-05-21 Thread Robert Horton
Yup..
mtime is the same. I did run makesmtpaccess and the restarted courierd. 
:)

On Friday, May 21, 2004, at 11:46 US/Pacific, Gordon Messmer wrote:
Robert Horton wrote:
Yes I have one smtpaccess file called default. I shall post what I  
have for you to see as well:
Did you run makesmtpaccess after the last time you updated the file?
check:
ls -l /etc/courier/smtpaccess*
Compare the modification time on smtpaccess.dat to the mtime on the 
files in the smtpaccess directory.


---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 
10g. Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


[courier-users] Re: grrrr

2004-05-21 Thread Robert Horton
On Friday, May 21, 2004, at 12:24 US/Pacific, Jerry Amundson wrote:
Robert Horton writes:
 Here are the last 40 lines of my syslog:
You need to go farther back. That only shows your servers attempts to 
*deliver* - we need to see how they were received in the first place, 
though it may not matter.
How much farther would you like? It looks pretty much (to my untrained 
eye) to be all the same, but I can give you as much as you like. As you 
can imagine it is pretty large at the moment.

Your message didn't indicate whether you only have a *single* tab 
character - I can't emphasize this one enough.
After you removed the registered IP, you ran makesmtpaccess, right?
Yes. I just double checked. There is but one single tab character after 
my declarations. And yes I ran makesmtpaccess and restarted the server.

Yes, as of this writing, you are an open relay - I don't know how it's 
possible, but you are...
jerry

Nor do I and hence my confusion. :)

---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


Re: [courier-users] Re: grrrr

2004-05-21 Thread keith
Title: Message



Is it possible that 
what you are seeing is just stacked up in the mail queue? I had a similar 
problem with Postfix. I was an open relay for one day and spent 4 days 
tracking down where all these messages in my logs were coming from even after I 
was certain I was no longer and open relay. turned out the mail queue was 
trying to send the backed up spam to addresses that were no longer valid or 
rejecting the spam. Once I cleaned out my mail queue everything was back 
to normal.

Not sure if this 
will help, but just a thought.

Keith 
Woolston-Young

BTW I'm not sure how 
to reply and get this quotedOutlook kept wanting to reply to people's 
addresses.


Re: [courier-users] Re: grrrr

2004-05-21 Thread Robert Horton

On Friday, May 21, 2004, at 13:27 US/Pacific, keith wrote:

Is it possible that what you are seeing is just stacked up in the mail queue?  I had a similar problem with Postfix.  I was an open relay for one day and spent 4 days tracking down where all these messages in my logs were coming from even after I was certain I was no longer and open relay.  turned out the mail queue was trying to send the backed up spam to addresses that were no longer valid or rejecting the spam.  Once I cleaned out my mail queue everything was back to normal.
 
Not sure if this will help, but just a thought.
 
Keith Woolston-Young
 
BTW I'm not sure how to reply and get this quoted Outlook kept wanting to reply to people's addresses.


I have cleared the mailq completely a few times and restarted courier and it immediately starts again. :) Good suggestion though. :D

Thanks!


[courier-users] Re: grrrr

2004-05-21 Thread Robert Horton

SNIP

Yes. I just double checked. There is but one single tab character 
after my declarations. And yes I ran makesmtpaccess and restarted the 
server.
I'll bypass the list for the moment for the sake of speed... look for 
the -access parameter of couriertcpd to make sure we're on the same 
page...

[EMAIL PROTECTED] courier]# ps -ewwf | grep esmtpd
courier  18449 1  0 May14 ?00:00:16 
/usr/lib/courier/sbin/couriertcpd 
-stderrlogger=/usr/lib/courier/sbin/courierlogger -user=courier 
-group=courier -access=/etc/courier/smtpaccess.dat -maxprocs=20 
-maxperc=2 -maxperip=1 -pid=/home/courier/var/tmp/esmtpd.pid smtp 
/usr/lib/courier/sbin/courieresmtpd

Here is my output from the above command:
courier374 1  0 13:51 ?00:00:00 /usr/sbin/couriertcpd 
-stderrlogger=/usr/sbin/courierlogger -user=courier -group=courier 
-access=/etc/courier/smtpaccess.dat -maxprocs=40 -maxperc=5 -maxperip=5 
-pid=/var/run/courier/esmtpd.pid smtp /usr/sbin/courieresmtpd 
/usr/lib/courier/courier/modules/esmtp/authstart authdaemon
courier377 1  0 13:51 ?00:00:00 /usr/sbin/courierlogger 
courieresmtpd
courier388 1  0 13:51 ?00:00:00 /usr/sbin/couriertcpd 
-stderrlogger=/usr/sbin/courierlogger -stderrloggername=esmtpd-ssl 
-maxprocs=40 -maxperip=5 -maxperc=5 
-pid=/var/run/courier/esmtpd-ssl.pid 
-stderrlogger=/usr/sbin/courierlogger -user=courier -group=courier 
-access=/etc/courier/smtpaccess.dat -address=0 465 /usr/bin/couriertls 
-server -tcpd /usr/sbin/courieresmtpd 
/usr/lib/courier/courier/modules/esmtp/authstart authdaemon
courier391 1  0 13:51 ?00:00:00 /usr/sbin/courierlogger 
esmtpd-ssl


If it looks different, it's getting set incorrectly with ACCESSFILE in 
/etc/courier/esmtpd.

Also, what OS and file system? I recall seeing LFS, but am not 
positive...

jerry


Here is the line out of my esmptd file:
ACCESSFILE=${sysconfdir}/smtpaccess
and sysconfdir is /etc/courierNow...should that say 
${sysconfdir}/smtpaccess/[name_of_file]?

And, yes. LFS running 2.4.25 kernel.
Thanks for all your help in this. :) I really appreciate it.
Rob

---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


[courier-users] Re: grrrr

2004-05-21 Thread Robert Horton
Ok, the situation has changed slightly:
I now see lots of 513s in my logs, relaying denied, so I am wondering 
if removing my ip from the smtpaccess file was the culprit?

Anyway, now when I try to send mail to any other email address but mine 
(e.g. [EMAIL PROTECTED]) from work, which is not my localhost, it 
will not relay. Does this mean that for every user that is a remote 
user I have to add their IP to the smtpaccess file to allow them to 
send email?

(If any are wondering I changed my smtp host at work to my work smtp 
server, otherwise these emails would not have reached you all!) :D

Thanks!

---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


[courier-users] Re: grrrr

2004-05-21 Thread Sam Varshavchik
Robert Horton writes:
Yes I have one smtpaccess file called default. I shall post what I  
have for you to see as well:

  Default access policies for courieresmtpd
localhost   allow,RELAYCLIENT
Although this has nothing to do with your issue, what exactly gave you the 
idea that the smtpaccess files can contain hostnames?

Additionally, post the contains of your esmtpacceptmailfor file.


pgpBKCaa5oiun.pgp
Description: PGP signature


Re: [courier-users] Re: grrrr

2004-05-21 Thread Chris Petersen
 Anyway, now when I try to send mail to any other email address but mine 
 (e.g. [EMAIL PROTECTED]) from work, which is not my localhost, it 
 will not relay. Does this mean that for every user that is a remote 
 user I have to add their IP to the smtpaccess file to allow them to 
 send email?

Why not just turn on authenticated SMTP?  No need to open ANY IP's to
relayclient.

-Chris



---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


Re: [courier-users] Re: grrrr

2004-05-21 Thread Robert Horton
On Friday, May 21, 2004, at 15:31 US/Pacific, Sam Varshavchik wrote:
Robert Horton writes:
Yes I have one smtpaccess file called default. I shall post what I  
have for you to see as well:
  Default access policies for courieresmtpd
localhost   allow,RELAYCLIENT
Although this has nothing to do with your issue, what exactly gave you 
the idea that the smtpaccess files can contain hostnames?
I was just curious actually :)
Additionally, post the contains of your esmtpacceptmailfor file.
Here it is:
agarithil-nost.com
agarithil-nost.com

---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


Re: [courier-users] Re: grrrr

2004-05-21 Thread Jeff Jansen
Looks like you fixed it, whatever you did.

[EMAIL PROTECTED] jeff]$ telnet  24.17.224.197 25
Trying 24.17.224.197...
Connected to 24.17.224.197.
Escape character is '^]'.
helo domain.com
220 mail.agarithil-nost.com ESMTP
250 mail.agarithil-nost.com Ok.
mail from:[EMAIL PROTECTED]
250 Ok.
rcpt to:[EMAIL PROTECTED]
513 Relaying denied.

Now just make sure any roaming users have authenticated SMTP enabled in 
their mail clients and you're set to go.  (I'd also make sure they using 
encryption, especially if they use LOGIN or PLAIN authentication.)

Jeff Jansen


---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


[courier-users] Re: grrrr

2004-05-21 Thread Sam Varshavchik
Jeff Jansen writes:
Looks like you fixed it, whatever you did.
[EMAIL PROTECTED] jeff]$ telnet  24.17.224.197 25
Trying 24.17.224.197...
Connected to 24.17.224.197.
Escape character is '^]'.
helo domain.com
220 mail.agarithil-nost.com ESMTP
250 mail.agarithil-nost.com Ok.
mail from:[EMAIL PROTECTED]
250 Ok.
rcpt to:[EMAIL PROTECTED]
513 Relaying denied.
Now just make sure any roaming users have authenticated SMTP enabled in 
their mail clients and you're set to go.  (I'd also make sure they using 
encryption, especially if they use LOGIN or PLAIN authentication.)
I suspect that he had a NAT firewall which forwarded all incoming port 25 
connections to his server.

Naturally, everyone who would connect to the server would have, from the 
server's perspective, the firewall's IP address, to which he granted 
relaying privileges.




pgpsjQuKJtlRH.pgp
Description: PGP signature


Re: [courier-users] Re: grrrr

2004-05-21 Thread Jeff Jansen
On Friday 21 May 2004 23:56, Sam Varshavchik wrote:
 I suspect that he had a NAT firewall which forwarded all incoming port 25 
 connections to his server.
 
 Naturally, everyone who would connect to the server would have, from the 
 server's perspective, the firewall's IP address, to which he granted 
 relaying privileges.

That would mean that he was doing Source NAT from outside to his internal 
network, right?  That would seem to me to be a *very* bad idea and a really 
misconfigured firewall.   Port forwarding should be Destination NAT and leave 
the source ip address alone.  Or am I missing something?  

Jeff Jansen


---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


Re: [courier-users] Re: grrrr

2004-05-21 Thread William Hue
Robert,

See AUTHMODULELIST in courier's etc/esmtpd file.

William


Robert Horton wrote:
 
 Ok, the situation has changed slightly:
 
 I now see lots of 513s in my logs, relaying denied, so I am wondering
 if removing my ip from the smtpaccess file was the culprit?
 
 Anyway, now when I try to send mail to any other email address but mine
 (e.g. [EMAIL PROTECTED]) from work, which is not my localhost, it
 will not relay. Does this mean that for every user that is a remote
 user I have to add their IP to the smtpaccess file to allow them to
 send email?
 
 (If any are wondering I changed my smtp host at work to my work smtp
 server, otherwise these emails would not have reached you all!) :D
 
 Thanks!
 
 ---
 This SF.Net email is sponsored by: Oracle 10g
 Get certified on the hottest thing ever to hit the market... Oracle 10g.
 Take an Oracle 10g class now, and we'll give you the exam FREE.
 http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
 ___
 courier-users mailing list
 [EMAIL PROTECTED]
 Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users


---
This SF.Net email is sponsored by: Oracle 10g
Get certified on the hottest thing ever to hit the market... Oracle 10g. 
Take an Oracle 10g class now, and we'll give you the exam FREE.
http://ads.osdn.com/?ad_id=3149alloc_id=8166op=click
___
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users