Re: [exim] tls_certificate weirdness

2016-08-22 Thread Heiko Schlittermann
r readers, you may need to use o=r for the permissions. For delivery it may be necessary to add init_groups to the options, I think, if the cert read access is controlled via some 'ssl-cert' group). Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- S

Re: [exim] Forged FROM

2016-07-28 Thread Heiko Schlittermann
alidation), this way you can tell which bounce is in response to one of your mails and which bounce is in response to a faked message. Check the spec file for BATV and PRVS. https://en.wikipedia.org/wiki/Bounce_Address_Tag_Validation Best regards from Dresden/Germany Viele Grüße au

Re: [exim] optimizing a condition

2016-07-04 Thread Heiko Schlittermann
if match{ SQL }{TXT(A|B)}} Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted mes

Re: [exim] Need some help with Exim LDAP lookups, please?

2016-07-01 Thread Heiko Schlittermann
Gary Perkins (Fr 01 Jul 2016 19:06:24 CEST): … > > > ${lookup ldap > > > {user='uid=ldapauth,cn=users,cn=accounts,dc=company,dc=co,dc=uk' > > > pass='somepassword' > > > ldap:///cn=groups,cn=accounts,dc=company,dc=co,dc=uk?member?sub?(cn=everyone)}} > > > > Try

Re: [exim] Need some help with Exim LDAP lookups, please?

2016-07-01 Thread Heiko Schlittermann
rch -x \ -D uid=ldapauth,cn=users,cn=accounts,dc=company,dc=co,dc=uk \ -w somepassword \ -H ldap://ipa0.company.co.uk \ -b cn=groups,cn=accounts,dc=company,dc=co,dc=uk \ cn=everyone member Best regards from Dresden/Germany

Re: [exim] Router or ACL - Deny all but one domain for specific IPs

2016-06-30 Thread Heiko Schlittermann
Peter Leeman (Do 30 Jun 2016 13:43:48 CEST): > Heiko > > Thanks for the response. I'll test this out so I can get to grips with the > AND aspect. Chris suggested a different solution which I am going to use, as > it looks more efficient than the one I was trying to

Re: [exim] Retry settings not apply some times

2016-06-30 Thread Heiko Schlittermann
r.com: retry timeout > exceeded Can you dump the retry hits and check for proskauer.com? exim_dumpdb retry Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Sc

Re: [exim] Help using cutthrough_delivery

2016-06-29 Thread Heiko Schlittermann
… Rob Szarka <szli...@szarka.org> (Mi 29 Jun 2016 23:24:28 CEST): > On 6/29/2016 5:01 PM, Heiko Schlittermann wrote: > >How many recipients does the message in question have? The cutthrough > >delivery works only if all the recipients have the same destination. To make sure y

Re: [exim] Router or ACL - Deny all but one domain for specific IPs

2016-06-29 Thread Heiko Schlittermann
_host_address}{net-iplsearch;/etc/exim4/conf.d/tmc-config/relay_from_xerox}}\ {match_domain {$domain}{! thisdomain.com}}\ }\ }\ Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- S

Re: [exim] Help using cutthrough_delivery

2016-06-29 Thread Heiko Schlittermann
question have? The cutthrough delivery works only if all the recipients have the same destination. Can you tcpdump your connection to check if there is at least the cutthrough attempt? Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -

Re: [exim] Is not honoring bounces-to violation of RFC?

2016-06-28 Thread Heiko Schlittermann
; Envelope-to: l...@restaurantloot.com > From: Stan <s...@restaurantloot.com> > Bounces-To: bar...@restaurantloot.com They're free to use any header they want… Maybe some broken mail sysstems even hounour Bounces-To. But please, show me, which relevant RFC mentions this header.

Re: [exim] On host lookup fail connect if on blacklist

2016-06-27 Thread Heiko Schlittermann
hosts. And, please, start a new thread for a new question next time. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.8

Re: [exim] Decipher this one-line snippet of exigrep?

2016-06-27 Thread Heiko Schlittermann
ot; in the SMTP or LMTP dialogue for outgoing messages is added to delivery log lines in the form "C=". A number of MTAs (including Exim) return an identifying string in this response. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- S

Re: [exim] Help me understand exigrep very short snippet output

2016-06-26 Thread Heiko Schlittermann
nt "google.com!bla.com > This form of attachment has been used by > recent viruses or other malware. > If you meant to send this file then please > package it up as a zip file and resend it. Your exim created that bounce, after accepting the message first. You should avo

Re: [exim] Exim not always logging Message-ID

2016-06-19 Thread Heiko Schlittermann
fixups log submission mode message fixups on a separate line fixed_message_id log submission mode fixed message id as id= But I do not see any harm in logging the fixed message id w/o a new log selector. What reason do we have not the use id=… even for a generated (fixed) id? Best rega

Re: [exim] Exim not always logging Message-ID

2016-06-13 Thread Heiko Schlittermann
Jeremy Harris <j...@wizmail.org> (Mo 13 Jun 2016 22:40:23 CEST): > On 05/06/16 23:09, Heiko Schlittermann wrote: > >> I did some coding and tested it in a very limted way. If you're > >> interested, I can share the patch. > > > I'd appreciate your feed

Re: [exim] - local user emails checked by the outgoing spamassassin

2016-06-07 Thread Heiko Schlittermann
bmitter. But the envelope From is supplied by Exim, as the Sender: is, if necessary. You're free to replace the From: with whatever you want. But think twice. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- in

Re: [exim] Exim4 route based on senders IP address

2016-06-07 Thread Heiko Schlittermann
Mike Brudenell <mike.bruden...@york.ac.uk> (Di 07 Jun 2016 10:42:02 CEST): > On 6 June 2016 at 15:46, Heiko Schlittermann <h...@schlittermann.de> wrote: > > > from_rfc1918: > > > > driver = manualroute > > condition = $

Re: [exim] Exim4 route based on senders IP address

2016-06-06 Thread Heiko Schlittermann
rom Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --- key ID: F69376C

Re: [exim] Exim not always logging Message-ID

2016-06-05 Thread Heiko Schlittermann
Hi, Heiko Schlittermann <h...@schlittermann.de> (Fr 03 Jun 2016 13:31:36 CEST): > > I did some coding and tested it in a very limted way. If you're > interested, I can share the patch. At git://git.exim.org/~heiko/exim.git you'll find two branches: exim-4_87

Re: [exim] Exim not always logging Message-ID

2016-06-03 Thread Heiko Schlittermann
Heiko Schlittermann <h...@schlittermann.de> (Fr 03 Jun 2016 13:31:36 CEST): > > I did some coding and tested it in a very limted way. If you're > interested, I can share the patch. You'll find it in git://git.exim.org/~heiko/exim.git Branch: log-message-id Best regar

Re: [exim] Exim not always logging Message-ID

2016-06-03 Thread Heiko Schlittermann
m Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --- key ID: F69376CE

Re: [exim] Logging username with client SMTP AUTH

2016-06-02 Thread Heiko Schlittermann
Frank Elsner (Do 02 Jun 2016 14:56:21 CEST): … > > You are using 'PLAIN' auth, there $auth2 contains the username. > > > > $auth1\0$auth2\0$auth3 > > userpass > > > > is sent by the client. $auth1 is empty. > $auth2 seems to be empty too, as your

Re: [exim] Logging username with client SMTP AUTH

2016-06-02 Thread Heiko Schlittermann
$auth1\0$auth2\0$auth3 userpass is sent by the client. $auth1 is empty. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing

Re: [exim] Expansion weirdness

2016-06-01 Thread Heiko Schlittermann
rmany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --- key ID: F69376CE - ! key

Re: [exim] Expansion weirdness

2016-06-01 Thread Heiko Schlittermann
Heiko Schlittermann <h...@schlittermann.de> (Mi 01 Jun 2016 18:01:52 CEST): .. > > Maybe I got something fundamentally wrong regarding expansions, but I am > > It's exim -bV: Exim version 4.87_51-e37f8a8 #12 built 24-May-2016 23:01:22 > The 4.87 (git 74d8288d7a8fa839899

Re: [exim] Expansion weirdness

2016-06-01 Thread Heiko Schlittermann
ta 127.0.0.1=local4 ::1=local6}{$value}fail}}fail}' local4 (expected) It's exim -bV: Exim version 4.87_51-e37f8a8 #12 built 24-May-2016 23:01:22 The 4.87 (git 74d8288d7a8fa83989968647149ae47ba10194f8) exposes the behaviour you describe. Git 1cf59ee7f68960237ad5cd3d599512fdbe5b3954 fixes it (Bug 1815)

Re: [exim] Exim's smtp_active_hostname option

2016-05-25 Thread Heiko Schlittermann
Hi, Sven Eschenberg (Di 24 Mai 2016 16:59:29 CEST): > The documentation states (v4.87) for smtp_active_hostname: > At the start of an incoming SMTP connection, its value is expanded and used > instead of the value of $primary_hostname in SMTP responses. … >

Re: [exim] Exim 4.87 - mail delivery or logging failure?

2016-05-19 Thread Heiko Schlittermann
d to the "defect" log files? (use eximstat for getting a histogram about processed messages) Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Di

Re: [exim] Help with body_deny

2016-05-12 Thread Heiko Schlittermann
deny condition = ${if match {$message_body}{(?i)make money fast}} Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.3

Re: [exim] SRS with Exim: feelings regarding srs_alt?

2016-05-08 Thread Heiko Schlittermann
ut to do some kind of "native" SRS integration, without using any external libraries, but please don't hold your breath… In production environment I use (Perl) Mail::SRS and it's command line interface currently. Best regards from Dresden/Germany Viele Grüße aus Dre

Re: [exim] conditional transport filters?

2016-05-04 Thread Heiko Schlittermann
if def:authenticated_id ...}" in transport > filter failed: condition name expected, but found "" I get the same, with 4.84. I'll need to investigate it. Seems odd. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -

Re: [exim] Need help with hostlist

2016-05-02 Thread Heiko Schlittermann
r words, you expect *.vpn.tu-berlin.de to be include in the above host list (by using * as an item in the list?) Where do you try to apply that condition? In some ACL? How? Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -

Re: [exim] tls_advertise_hosts

2016-04-25 Thread Heiko Schlittermann
this (insecure) default by putting it into your configuration, the warnings will go away, no matter whay value you put there. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix suppor

Re: [exim] tls_advertise_hosts

2016-04-25 Thread Heiko Schlittermann
built-in default. Maybe we *could* check if there is at least something configured for tls_{certificate,privatekey} and suppress the STARTTLS offer if these global options are missing (but continue to issue the warning.) Jeremy? What do you think? Best regards from Dresden/Germany Viele

Re: [exim] Exim 4.84_2 #1 : WARNING: purging the environment.

2016-04-18 Thread Heiko Schlittermann
> That's life ! Yes, sorry for that. But we had to introduce that incompatible change. And you should upgrade your version, for security reasons. Or try some MACRO magic .ifndef VERY_OLD_EXIM keep_environment = .endif And for your old Exim you add -DVERY_OLD_EXIM to the command line. Be

Re: [exim] Ignoring SSL-Errors on self signed certificates

2016-04-14 Thread Heiko Schlittermann
I'd like to suppress this warning, in order > to have a cleaner log. > How can I disable the verification of the certificates on sending E-Mails? Try log_selecor = … -tls_certificate_verified Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlitte

Re: [exim] 4.87 and acl_check_data

2016-04-13 Thread Heiko Schlittermann
keep_environment thing, there we *had* to change the behaviour (and we had long discussions about that). Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing.

Re: [exim] 4.87 and acl_check_data

2016-04-13 Thread Heiko Schlittermann
Jeremy Harris <j...@wizmail.org> (Mi 13 Apr 2016 12:27:57 CEST): > On 13/04/16 11:12, Heiko Schlittermann wrote: … > > I can imagine an option to force proper formatting of the message that > > is included in the bounce. I'm not sure if this was discussed already. > >

Re: [exim] :fail: vs SMTP error message

2016-04-13 Thread Heiko Schlittermann
Heiko Schlittermann <h...@schlittermann.de> (Mi 13 Apr 2016 12:17:40 CEST): > Frank Elsner <frank.els...@tu-berlin.de> (Mi 13 Apr 2016 12:11:10 CEST): > > > … > > > > denydomains = +local_domains > > message = Unknown mailbox > &

Re: [exim] :fail: vs SMTP error message

2016-04-13 Thread Heiko Schlittermann
den/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --- key ID: F69376CE - ! key

Re: [exim] 4.87 and acl_check_data

2016-04-13 Thread Heiko Schlittermann
ils were dropped. With the above configuration it's not your system sending the bounces! So it's not your problem, but the senders problem, isn't it? Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- inter

Re: [exim] 4.87 and acl_check_data

2016-04-13 Thread Heiko Schlittermann
e. I'm not sure if this was discussed already. a) cut the overlong lines and add some note for the recipient b) convert the to-be-bounced message body to some MIME format Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de --

Re: [exim] Question about ClamAV

2016-04-13 Thread Heiko Schlittermann
rough as .js packed in .zip. So - depending on your situtation - you may block some extensions after unpacking the mime parts. Search the archives for 'lena kiev' for possible solutions. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHL

Re: [exim] Spool file not found

2016-04-10 Thread Heiko Schlittermann
re messages mentioned which are not there anymore. This should not happen, it looks indeed like a corrupted retry database (or is it *_wait, having the message ids for a specific destination?) Try, if an exim_tidydb … helps. Best regards from Dresden/Germany Viele Grüße aus Dres

Re: [exim] Spool file not found

2016-04-10 Thread Heiko Schlittermann
Heiko Schlittermann <h...@schlittermann.de> (So 10 Apr 2016 16:59:32 CEST): … > > reference to an email in the database that no longer exists in the spool. > > As far as I know these databases are not used to identify messages. > They are used to lookup data for a gi

Re: [exim] Spool file not found

2016-04-10 Thread Heiko Schlittermann
esden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --- key ID: F69376CE - ! key

Re: [exim] Exclude host from sender verification

2016-04-07 Thread Heiko Schlittermann
192.168.1.1 !verify = sender Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encryp

Re: [exim] Exim 4.87 reports no server certificate but appears to work?

2016-04-07 Thread Heiko Schlittermann
u're talking about the warning you find in your panic log, than it's the leftover from the installation (check the time stamps at the log lines) Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet &

Re: [exim] Exim 4.87 reports no server certificate but appears to work?

2016-04-07 Thread Heiko Schlittermann
Heiko Schlittermann <h...@schlittermann.de> (Do 07 Apr 2016 08:59:08 CEST): > Heiko Schlittermann <h...@schlittermann.de> (Do 07 Apr 2016 08:39:03 CEST): > … > > While we suppress warnings in the test/check modes (-bt, -bv, …), we do > > not suppress warnin

Re: [exim] Exim 4.87 reports no server certificate but appears to work?

2016-04-07 Thread Heiko Schlittermann
Heiko Schlittermann <h...@schlittermann.de> (Do 07 Apr 2016 08:39:03 CEST): … > While we suppress warnings in the test/check modes (-bt, -bv, …), we do > not suppress warnings for -bV, since this is used for verification > purposes of your configuration. And while /dev/

Re: [exim] Exim 4.87 reports no server certificate but appears to work?

2016-04-07 Thread Heiko Schlittermann
from the installation step, it went into your paniclog (compare the timestamps: 00:16:35). If you - after the installation - call exim -bV, no warning should appear anymore. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -

Re: [exim] Exim 4.87 RC7 uploaded

2016-04-02 Thread Heiko Schlittermann
Heiko Schlittermann <h...@schlittermann.de> (Sa 02 Apr 2016 11:02:01 CEST): > Yes, but the Symbol __STDC_VERSION doesn't seem to have the right value in > SRC/buildconfig.c (where I took the code for my short test from). It's set for clang, or if we use gcc -std=c99 (or some ot

Re: [exim] Exim 4.87 RC7 uploaded

2016-04-02 Thread Heiko Schlittermann
Yes, but the Symbol __STDC_VERSION doesn't seem to have the right value in SRC/buildconfig.c (where I took the code for my short test from). -- Heiko Schlittermann (unterwegs) -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org

Re: [exim] Exim 4.87 RC7 uploaded

2016-04-02 Thread Heiko Schlittermann
tform. (Different platforms, different formats for displaying an size_t/ssizt_t value). For you platform it seems to be broken. Plaese try to compile and run the attached short program. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de --

Re: [exim] Exim 4.87 RC7 uploaded

2016-04-02 Thread Heiko Schlittermann
inter target type >gcc dbmdb.c >... Can you, please, provide me your Local/Makefile? Thx -- Heiko Schlittermann (unterwegs) -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org/ ## Please use the Wiki with this list - http://wiki.exim.org/

Re: [exim] TLS packets error

2016-04-01 Thread Heiko Schlittermann
olve this problem. It's in the source since 4.80 RC2, so 4.80 should contain that option already. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl

Re: [exim] Exim 4.87 RC7 uploaded

2016-04-01 Thread Heiko Schlittermann
Heiko Schlittermann <h...@schlittermann.de> (Fr 01 Apr 2016 18:55:32 CEST): > Hi, > > Odhiambo Washington <odhia...@gmail.com> (Fr 01 Apr 2016 09:18:45 CEST): > > I have been running these RCs on a few servers, all FreeBSD, and I was > > wondering if I should be

Re: [exim] Exim 4.87 RC7 uploaded

2016-04-01 Thread Heiko Schlittermann
le Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --- key ID: F69376CE - ! key id 7CBF764A and

Re: [exim] Warnings even in testing modes

2016-03-31 Thread Heiko Schlittermann
Hi, Heiko Schlittermann <h...@schlittermann.de> (Mo 14 Mär 2016 22:37:23 CET): > Andreas M. Kirchwitz <a...@spamfence.net> (Mo 07 Mär 2016 02:03:52 CET): > > Unfortunately, it looks like this warning message also has the > > potential to break existing installations

Re: [exim] MUA sends in envelope addresses in "user@host"@host form when using authentication

2016-03-27 Thread Heiko Schlittermann
in". Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome

Re: [exim] Connection not timing out

2016-03-22 Thread Heiko Schlittermann
Michael Fischer v. Mollard (Di 22 Mär 2016 11:02:13 CET): > > > other PIDs, but same situation: > # strace -p 18619 > Process 18619 attached > select(8, [7], NULL, NULL, {17, 252791}) = 0 (Timeout) > wait4(-1, 0x7ffe6b2aef8c, WNOHANG, NULL) = 0 > select(8, [7], NULL, NULL,

Re: [exim] Connection not timing out

2016-03-21 Thread Heiko Schlittermann
mation, + the item size being so much larger. Found and fixed by Wolfgang Breyha. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) -

Re: [exim] Connection not timing out

2016-03-20 Thread Heiko Schlittermann
t log line shows a forceful closed connection, but we've no idea if this is the same process as started just after the messages came in. You may add the +pid log_selector to get an idea about the processes (not) handling a message. Best regards from Dresden/Germany Viele Grüße aus Dresden Hei

[exim] Suppress warnings in tool/list modes (Was: Security release for CVE-2016-1531: 4.84.2, 4.85.2, 4.86.2, 4.87 RC5)

2016-03-20 Thread Heiko Schlittermann
ut any notice. But you're encouraged to give it a try, if all that testing/listing/checking modes work as expected and without the warnings. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -------- internet &

Re: [exim] How to disable spamassassin for outgoing messages?

2016-03-19 Thread Heiko Schlittermann
* accept hosts = +trusted_hosts warn spam = … Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351

Re: [exim] How to disable spamassassin for outgoing messages?

2016-03-18 Thread Heiko Schlittermann
lease re-post with proper formatting. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted mes

[exim] Warnings even in testing modes (Was: Security release for CVE-2016-1531: 4.84.2, 4.85.2, ) 4.86.2, 4.87 RC5

2016-03-14 Thread Heiko Schlittermann
Andreas M. Kirchwitz <a...@spamfence.net> (Mo 07 Mär 2016 02:03:52 CET): > Heiko Schlittermann <h...@schlittermann.de> wrote: > > > New options > > --- > > > > We had to introduce two new configuration options: > > &g

Re: [exim] Security release for CVE-2016-1531: 4.84.2, 4.85.2, 4.86.2, 4.87 RC5

2016-03-09 Thread Heiko Schlittermann
t privileges before reading the configuration. For the Configs of the built in list Jeremy explained, why it can be considered safe. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix

Re: [exim] Security release for CVE-2016-1531: 4.84.2, 4.85.2, 4.86.2, 4.87 RC5

2016-03-09 Thread Heiko Schlittermann
ore save, you may let keep_environment untouched (empty list) and add the variables and values you need with add_environment. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support -

Re: [exim] Security release for CVE-2016-1531: 4.84.2, 4.85.2, 4.86.2, 4.87 RC5

2016-03-08 Thread Heiko Schlittermann
Heiko Schlichting <exim-us...@fu-berlin.de> (Di 08 Mär 2016 10:29:51 CET): > Heiko Schlittermann wrote: > > > > keep_environment = TZ : LANG : ^LC_ : ^LDAP > > add_environment = <; PATH=/bin:/usr/bin:/usr/local/bin > > > > could be a good startin

Re: [exim] Security release for CVE-2016-1531: 4.84.2, 4.85.2, 4.86.2, 4.87 RC5

2016-03-07 Thread Heiko Schlittermann
Hi, Andreas M. Kirchwitz <a...@spamfence.net> (Mo 07 Mär 2016 02:03:52 CET): > Heiko Schlittermann <h...@schlittermann.de> wrote: > Thanks for the security updates! Highly appreciated. > > Unfortunately, it looks like this warning message also has the > potential to b

Re: [exim] different acl data malware settings per recipient domain?

2016-03-06 Thread Heiko Schlittermann
g_dir/skip_scan malware = * DRAFT, not tested! Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{

[exim] Older versions of Exim (CVE-2016-1531)

2016-03-05 Thread Heiko Schlittermann
. Older versions of Exim don't understand these options and just die. Maybe I'm the only stupid one, maybe someone else got bitten too :) Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix supp

Re: [exim] Missing normal message delivery logs

2016-03-03 Thread Heiko Schlittermann
following entries: > 1aZKh4-0004z4-FG == . > 1ab40O-0005ES-RC <= . Do you see them containing just that single dot? Or is this a result of the obfuscation? Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de

Re: [exim] Security release for CVE-2016-1531: 4.84.2, 4.85.2, 4.86.2, 4.87 RC5

2016-03-03 Thread Heiko Schlittermann
root bit from the binary. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are we

Re: [exim] Use uname() in exim configuration file

2016-03-02 Thread Heiko Schlittermann
Nicolas Dorfsman (Mi 02 Mär 2016 21:28:13 CET): > > > > So, if you leave this unset and then refer to $primary_hostname in sections > > of your configuration it will pull in from a call uname() and do exactly > > what you specify. > > > Sure…but I need to set it to a

[exim] Security release for CVE-2016-1531: 4.84.2, 4.85.2, 4.86.2, 4.87 RC5

2016-03-02 Thread Heiko Schlittermann
pts an absolute configuration file path now, when using the -C option. Thank you for your understanding. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlitterman

Re: [exim] Commercial Antivirus

2016-03-02 Thread Heiko Schlittermann
Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --- key ID

Re: [exim] Quota Problem

2016-02-15 Thread Heiko Schlittermann
${quote_mysql:$domain}' \ > > and users.domain_id = domains.domain_id}{${value}M}} > ---^ Was was looking for such typo, but didn't see it. Thank you for pointing it out. Best regards from Dresden/Germany

Re: [exim] http://exim.org/ broken since Monday

2016-02-10 Thread Heiko Schlittermann
tly no intention of changing this unless there is a strong > argument to do so (argument to not do so is key management is a pain). It would cost us two certs. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -

Re: [exim] Benchmarking an MTA?

2016-02-05 Thread Heiko Schlittermann
vered at any given time. That is, the impact of a huge queue … Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de -------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +

Re: [exim] Benchmarking an MTA?

2016-02-05 Thread Heiko Schlittermann
Viktor Dukhovni <exim-us...@dukhovni.org> (Mi 03 Feb 2016 09:20:49 CET): > On Wed, Feb 03, 2016 at 08:33:06AM +0100, Heiko Schlittermann wrote: > > > Does anybody know anything about benchmarking an MTA? > > What do we count as performance? > > > > e.g.:

Re: [exim] Benchmarking an MTA?

2016-02-05 Thread Heiko Schlittermann
gards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --- key ID: F69376C

Re: [exim] can I suppress the "message frozen by system filter" log line?

2016-02-04 Thread Heiko Schlittermann
can (eg: retry time not > reached). Can't you implement the new requirement in the DATA acl or even in the QUIT acl? (About QUIT I'm not sure if it fires even on connection loss after the final dot.) Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann --

Re: [exim] Finding largest senders

2016-02-03 Thread Heiko Schlittermann
mtrai...@cloud-free.com (Mi 03 Feb 2016 09:49:07 CET): > We are currently using the command below to find the 30 largest > authenticated senders on our exim mta's so we can check if it is valid > email or spam: … > The problem with this is that it only counts emails and

Re: [exim] Slow email sending and spool file not found

2016-02-02 Thread Heiko Schlittermann
as much as possible checking is good to avoid bounces. BUT as a probably authenticated MUA is talking to you, you might accept the message first and then bounce later to that authenticated user. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.d

[exim] Benchmarking an MTA?

2016-02-02 Thread Heiko Schlittermann
: messages/time the MTA can accept¹ Any other suggestions? Would anybody be willing to share performance stats? (In a first step: submit the results from a tailored eximstats output?) Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de

Re: [exim] route to smarthost only emails that would be send to MX dns ending with .google.com

2016-02-01 Thread Heiko Schlittermann
${if forany{<\n ${lookup dnsdb{mxh=$domain}}}{match{$item}{\N(?i)\.google\.com$\N}}}' Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Di

Re: [exim] freeze instead of bounce on specified remote response?

2016-02-01 Thread Heiko Schlittermann
.* > abcd". or "550 defg" I *think* so, after what I understood from a short talk with jgh. You should read about the EXPERIMENTAL_EVENTS feature. It should be suiteable for exactly that. Best regards from Dresden/Germany Viele Grüße aus Dresden Hei

Re: [exim] Exim proliferation

2016-01-31 Thread Heiko Schlittermann
only 20% of exim servers are up to date :( What range of versions do you count as "up to date"? Viele Grüße Heiko Schlittermann -- SCHLITTERMANN.de -------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.35

[exim] New Commit for exim-4_86+fixes

2016-01-25 Thread Heiko Schlittermann
erized testsuite for {debian7,debian8,fedora{21,22},opensuse}-{openssl,gnutls} with the usual failures. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann,

Re: [exim] Help with log message: failed to find host name

2015-12-17 Thread Heiko Schlittermann
st matching forced to fail: failed to find > host name for 14.175.26.108 14.175.26.108 -> N.A. Probably you do host list matching. How does the list you use for matching look like? Because the steps involving DNS depend on the list you check against. Best regards from Dresden/Germany

Re: [exim] Exim misses some attachments.

2015-12-17 Thread Heiko Schlittermann
cab|chm|cmd|com|\ {\\.(?i:ace|bat|btm|cab|chm|cmd|com|\ I'd use case insensitive matching or convert the mime file name to lower case in the first place. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlitt

Re: [exim] Debugging .forward

2015-12-13 Thread Heiko Schlittermann
e bounce. Therefore this should be the account of a person taking care about the sending system (often postmas...@example.com). But as always, it's my understanding of what's going on, it might be completly wrong. Best regards from Dresden/Germany Viele Grüße aus Dresden Hei

Re: [exim] exim4, gmail and 550-5.7.1

2015-12-13 Thread Heiko Schlittermann
t as I'm much more familiar with the native configuration I can't do that job, as most of the other supporters, I suppose. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Hei

Re: [exim] Debugging .forward

2015-12-13 Thread Heiko Schlittermann
ss) somebody > may > have access to their systems. Meanwhile it's spread around the globe via this mailing list :) Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support -

Re: [exim] Debugging .forward

2015-12-12 Thread Heiko Schlittermann
645 <= <> H=(115.73.55.172) > [115.73.16.126] P=smtp S=2605 Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49

Re: [exim] Cannot send specific attachment from my domain to anybody except ours.

2015-12-11 Thread Heiko Schlittermann
re there any rewrite rules? Or does your MUA set different senders, depending on the destination? Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---- internet & unix support - Heiko Schlittermann, Dipl.-

Re: [exim] acl_check_content doesn't get applied to all mails

2015-12-11 Thread Heiko Schlittermann
> accept It should work. Maybe you can keep such message that should have be rejected. (See the 'no_mbox_unspool'). And, maybe you should move to acl_smtp_mime, instead of using the obsoleted demime extension. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlitter

<    2   3   4   5   6   7   8   9   10   11   >