Re: [courier-users] Courier forward

2013-08-20 Thread Matus UHLAR - fantomas
On 19.08.13 15:23, Michael Chonlahan wrote: We are looking at going to a new email system but want to forward current email to the new system need some help setting this up. If you post a question to a list, and people ask for details to you on the list, you should send your responses to the

Re: [courier-users] Relay Control

2013-08-20 Thread Matus UHLAR - fantomas
On 19.08.13 21:09, Nick Ellson wrote: I seem to have found my final mail issues when I saw my mail queue had over 900 megs of mail backed up that looks like I was an open relay. can you provide headers of any such message? The local network is easy, that is what the smtpaccess/default file is

Re: [courier-users] Perfect Forward Secrecy - please implement this on courier

2013-08-20 Thread Gerald Hopf
Thanks for the quick reply! On 20.08.2013 01:34, Sam Varshavchik wrote: I do not see the connection between PFS and these two specific key exchange protocols. PFS is just a generic concept, not tied to any particular technology. To my knowledge the ciphers starting with DHE and ECDHE are the

Re: [courier-users] Relay Control

2013-08-20 Thread Nick Ellson
Hello Matus, and thank you. 1. Yes, I can provide quite a few as a buddy's answer to quieting my system down so we can look at what happened was to rename /var/lib/courier/msgq / msgs and tmp adding the .foo extension... gubbie /var/lib/courier/msgq.foo # ls 137108 137143 137178 137213

Re: [courier-users] Perfect Forward Secrecy - please implement this on courier

2013-08-20 Thread Sam Varshavchik
Gerald Hopf writes: I don't recall offhand if you are required to use a DH certificate, instead of an RSA certificate, or if having DH parameters is sufficient. Use 'openssl dhparams to generate a set of new DH parameters, and append them to your certificate file, and see if it helps. If

Re: [courier-users] Relay Control

2013-08-20 Thread Matus UHLAR - fantomas
On 20.08.13 05:18, Nick Ellson wrote: gubbie /var/lib/courier/msgq.foo/137108 # cat C1487564.1371088460 sgr...@nickellson.com fdns; habmpq ([181.66.48.149]) e t M0016B2CC.51B92649.1CA1 rewheele...@yahoo.com yes, here it looks like spam. But I meant the headers from D* file, most

Re: [courier-users] Relay Control

2013-08-20 Thread Nick Ellson
OK, I am scanning the .foo directories looking for that file. Right now I am back online, but I guess I now require authentication to even receive mail? From a system on my 10 net. My mail server only accepts nickellson.com, this used to work as my not trying anything funny test. If I add the -a

Re: [courier-users] Relay Control

2013-08-20 Thread Nick Ellson
While watching my logs reject most everything that connects... I saw a flash of e-mail addresses and rushed to look at my queue gubbie ~ # mailq Size Queue IDDate User From Status Recipient

Re: [courier-users] Relay Control

2013-08-20 Thread Nick Ellson
I shut down outbound SMTP at my firewall in hopes of trapping the problem... found it.. someone got my password.. gubbie /var/lib/courier/msgs/54 # cat D1395754 Received: from kzjevialvhn ([31.133.50.72]) (AUTH: LOGIN gr...@nickellson.com) by nickellson.com with ESMTPA; Tue, 20 Aug 2013

Re: [courier-users] Perfect Forward Secrecy - please implement this on courier

2013-08-20 Thread Gerald Hopf
openssl dhparams generates DH parameters. couriertls checks if the certificate file contains DH parameters, and if so, they get loaded. As you know, Courier reads both the private key and the certificate from the same file. PEM-formatted files may have multiple contents, like a private

Re: [courier-users] Relay Control

2013-08-20 Thread Martin Schuster (IFKL IT OS DC CD)
On 2013-08-20 14:18, Nick Ellson wrote: [...] (BTW, that LS still is not done... cringe) Hint: ls -l will do a stat for each and every file, AND a sort afterwards. Especially when you just want to know the number of files, or some example filenames, ls -f is much faster :) hth, -- Infineon

Re: [courier-users] Relay Control

2013-08-20 Thread Nick Ellson
Still searching for that message.. gubbie /var/lib/courier/msgs.foo # find . -name D1487564* Been running 30 mins now. anyone know a faster way to locate this one for Matus? Nick On Tue, Aug 20, 2013 at 5:32 AM, Matus UHLAR - fantomas uh...@fantomas.skwrote: On 20.08.13 05:18, Nick Ellson

Re: [courier-users] Relay Control

2013-08-20 Thread Nick Ellson
Found it, and yup, it shows authenticated.. so courier was not the relay.. my password got owned.. it's been changed. gubbie /var/lib/courier/msgs.foo # cat ./64/D1487564 Received: from habmpq ([181.66.48.149]) (AUTH: LOGIN gr...@nickellson.com) by nickellson.com with ESMTPA; Wed, 12 Jun

Re: [courier-users] SPF check fails on items that used to work?

2013-08-20 Thread Alessandro Vesely
On Tue 20/Aug/2013 01:33:34 +0200 Sam Varshavchik wrote: I agree that in this situation, 'none' would be the more technically proper result. This will be changed. BTW, 4408bis just entered Last Call. There are not many differences, but it seems to be a good occasion to review SPF

[courier-users] DSN Problem

2013-08-20 Thread Bernd Prünster
Hello, I need assistance fixing a (configuration?) problem: courier does not send Delivery Status Notifications. I am willing to pastebin logs (I am not smart enough to use the SMTP dialog for debugging), DNS records, config files, wireshark captures, etc. as needed. best regards, Bernd PS:

Re: [courier-users] IMAP in general use

2013-08-20 Thread Harry Duncan
On Fri, Aug 16, 2013 at 3:04 AM, Sam Varshavchik mr...@courier-mta.comwrote: I don't have any figures or stats. But everywhere I look, I see no signs of life. On Usenet, comp.mail.imap used to carry respectable daily traffic a while ago. It's a ghost town now, maybe a dozen posts a year, for

Re: [courier-users] Relay Control

2013-08-20 Thread Nick Ellson
Thanks everyone that gave me advice. I seem to be back up and running again, and not relaying for bad people ;-) It appears that the main issue was that my account credentials were compromised for a 1 month period, which loaded my system up with so much spam things would not function. This made

Re: [courier-users] DSN Problem

2013-08-20 Thread Sam Varshavchik
Bernd Prünster writes: Hello, I need assistance fixing a (configuration?) problem: courier does not send Delivery Status Notifications. I am willing to pastebin logs (I am not smart enough to use the SMTP dialog for debugging), DNS records, config files, wireshark captures, etc. as needed.

[courier-users] Changing a users homedirectory

2013-08-20 Thread Lisa Muir
I need to change the path to users homedirectory for a mailserver management overhaul. I'm using an LDAP backend. When I script it, Presumably if I change the homedirectory location in ldap first, THEN carry out the physical directory move, I won't leave any mails in queues with delivery failures

Re: [courier-users] Changing a users homedirectory

2013-08-20 Thread Sam Varshavchik
Lisa Muir writes: « HTML content follows » I need to change the path to users homedirectory for a mailserver management overhaul. I'm using an LDAP backend. When I script it, Presumably if I change the homedirectory location in ldap first, THEN carry out the physical directory move, I

Re: [courier-users] Perfect Forward Secrecy - please implement this on courier

2013-08-20 Thread Sam Varshavchik
Gerald Hopf writes: default. If even the official courier-mta.org MX server doesn't have this correctly enabled, I somehow doubt anyone else does... And somehow dovecot/postfix seem to manage to have this as default without generation special DH parameter files ? It's two opposite

Re: [courier-users] Relay Control

2013-08-20 Thread Lindsay Haisley
On Tue, 2013-08-20 at 13:59 -0700, Nick Ellson wrote: It appears that the main issue was that my account credentials were compromised for a 1 month period, which loaded my system up with so much spam things would not function. This made the rest of it look very bad. I had this happen a while

Re: [courier-users] Relay Control

2013-08-20 Thread Nick Ellson
It's absolute murder on my poor hard drives trying to clean off all that chaff... Found a find script that is holding the fastest file per second delete rate.. Still looking at more than a day to dump it all. :-/ thinking if I drop to a rescue DVD to quiet the other use it might finish in a day

Re: [courier-users] Perfect Forward Secrecy - please implement this on courier

2013-08-20 Thread Sam Varshavchik
Sam Varshavchik writes: Gerald Hopf writes: default. If even the official courier-mta.org MX server doesn't have this correctly enabled, I somehow doubt anyone else does... And somehow dovecot/postfix seem to manage to have this as default without generation special DH parameter files ?

Re: [courier-users] IMAP in general use

2013-08-20 Thread John Saunders
For Android I have found that AquaMail is a very reliable IMAP client that works perfectly well with my Courier install. I have SSL port 993 exposed on my firewall and am able to access my email via the cellular network wherever I am. I tried a lot of email clients before AquaMail and they

Re: [courier-users] Perfect Forward Secrecy - please implement this on courier

2013-08-20 Thread Bernd Wurst
Hi. Am 21.08.2013 03:09, schrieb Sam Varshavchik: Ok, here's exactly what I mean. In your esmtpd-ssl, imapd-ssl, or pop3-ssl configuration file, set the TLS_DHCERTFILE setting to the file that has your DH parameters, in PEM format. It can be the same file as the TLS_CERTFILE. Thanks for your