Re: Mitigating DROWN

2016-03-09 Thread Marc Patermann
Am 03.03.2016 um 19:29 Uhr schrieb Viktor Dukhovni: Postfix 2.6 and later, with the recommended settings is sufficient, but it is recommended that you also deploy OpenSSL 1.0.1s or 1.0.2g, or your O/S vendor's "equivalent" update. It is sadly common to selectively backport fixes without

Re: OT: TLS and SNI (was Re: Postfix 3.1 and TLS Cert Files)

2016-03-09 Thread Curtis Villamizar
In message <56e0ccb4.6010...@spectralmud.org> Richard James Salts writes: > > On 10/03/16 09:32, Curtis Villamizar wrote: > > In message <56dfcd11.5010...@spectralmud.org> > > Richard James Salts writes: > > > >> On 09/03/16 06:44, Viktor Dukhovni wrote: > On Mar 8, 2016, at 2:31 PM, Curtis

Re: OT: TLS and SNI (was Re: Postfix 3.1 and TLS Cert Files)

2016-03-09 Thread Richard James Salts
On 10/03/16 09:32, Curtis Villamizar wrote: In message <56dfcd11.5010...@spectralmud.org> Richard James Salts writes: On 09/03/16 06:44, Viktor Dukhovni wrote: On Mar 8, 2016, at 2:31 PM, Curtis Villamizar wrote: With HTTP the server cert is provided after HTTP

OT: TLS and SNI (was Re: Postfix 3.1 and TLS Cert Files)

2016-03-09 Thread Curtis Villamizar
In message <56dfcd11.5010...@spectralmud.org> Richard James Salts writes: > On 09/03/16 06:44, Viktor Dukhovni wrote: > >> On Mar 8, 2016, at 2:31 PM, Curtis Villamizar > >> wrote: > >> > >> With HTTP the server cert is provided after HTTP identifies which > >>

Re: sender IP dependent outgoing IP address after content_filter

2016-03-09 Thread Wietse Venema
gsotsas: > Dear postfix users, > I have the following outbound relayhost configuration: > {client that sends mail to smtp relay} -> {postfix:587} -> {policyd} -> > {postfix} -> {amavis:10024} -> {postfix:10025} -> {postfix relays mail > to destination mailserver} > > What I need is that the

Re: Rewrite issue...

2016-03-09 Thread Viktor Dukhovni
On Wed, Mar 09, 2016 at 03:51:23PM -0500, fschnit...@execulink.com wrote: > We have a large number of machines sending mail to an > internal postfix relay. So the sender address is in the format of: > sen...@server.domain.com > where server is a variable and can be one > of any of 1000 servers >

Re: Rewrite issue...

2016-03-09 Thread fschnittke
Hello: I'm trying to perform some address rewriting in postfix. Here is my scenario. We have a large number of machines sending mail to an internal postfix relay. So the sender address is in the format of: sen...@server.domain.com where server is a variable and can be one of any of 1000

Re: Postfix 3.1 and TLS Cert Files

2016-03-09 Thread Curtis Villamizar
In message

Re: warning: rcpt count mismatch with Milter

2016-03-09 Thread Wietse Venema
J?rg Backschues: > Am 09.03.2016 um 01:20 schrieb Wietse Venema: > > > How many recipients are there before the bcc action? > > I've verified the issue with one recipient only and multiple recipients. > > > That would be a bug. I'd appreciate it if you could run the cleanup > > server with the

Re: warning: rcpt count mismatch with Milter

2016-03-09 Thread Jörg Backschues
Am 09.03.2016 um 01:20 schrieb Wietse Venema: How many recipients are there before the bcc action? I've verified the issue with one recipient only and multiple recipients. That would be a bug. I'd appreciate it if you could run the cleanup server with the -v action and log what Postfix and

Re: Postfix 3.1 and TLS Cert Files

2016-03-09 Thread Tom Browder
On Tuesday, March 8, 2016, Curtis Villamizar wrote: > Tom, > > I've been following this thread and also not clear on your > objectives. See inline. > As Viktor pointed out, look at the examples. Your home machine is a > "null client". Your remote server is not a "null

Re: Right way to force autresponder script to authenticate against postfix

2016-03-09 Thread Pau Peris
Ok, thanks!! On Tue, Mar 8, 2016 at 8:36 PM, Wietse Venema wrote: > The third option was: > - submit autoreplies with /usr/sbin/sendmail instead of SMTP. > > Pau Peris: >> If i'd go by the third option, sending through sendmail instead of >> SMTP, i would loose the headers

sender IP dependent outgoing IP address after content_filter

2016-03-09 Thread gsotsas
Dear postfix users, I have the following outbound relayhost configuration: {client that sends mail to smtp relay} -> {postfix:587} -> {policyd} -> {postfix} -> {amavis:10024} -> {postfix:10025} -> {postfix relays mail to destination mailserver} What I need is that the last postfix process

Re: postfix drown attack migation on version 2.3 (rhel5)?

2016-03-09 Thread Benning, Markus
On 2016-03-03 08:12, Eero Volotinen wrote: Can some one give working migation intructions for postfix 2.3 (postfix-2.3.3-7.el5) many of instructions are not working correctly on so old version. (as settings are not supported) Just install the RHSA errata: