Re: Question about disabling SSLv2 and SSLv3 and Opportunistic TLS

2018-05-21 Thread Viktor Dukhovni
> On May 21, 2018, at 5:16 PM, Sean Son > wrote: > > lmtp_tls_mandatory_protocols = !SSLv2 > lmtp_tls_protocols = !SSLv2 > smtp_tls_mandatory_protocols = !SSLv2 > smtp_tls_protocols = !SSLv2 > smtpd_tls_mandatory_protocols = !SSLv2 > smtpd_tls_protocols = >

Re: Question about disabling SSLv2 and SSLv3 and Opportunistic TLS

2018-05-21 Thread Sean Son
On Mon, May 21, 2018 at 2:08 PM, Viktor Dukhovni wrote: > > > > On May 21, 2018, at 1:16 PM, Sean Son > wrote: > > > > Hello all > > > > I have opportunistic TLS (offering STARTLS) configured in my main.cf > file. I have been

Re: Question about disabling SSLv2 and SSLv3 and Opportunistic TLS

2018-05-21 Thread Viktor Dukhovni
> On May 21, 2018, at 1:16 PM, Sean Son > wrote: > > Hello all > > I have opportunistic TLS (offering STARTLS) configured in my main.cf file. > I have been tasked to disable SSLv2 and SSLv3 as well as disable medium > strength ciphers (to use high

Re: Question about disabling SSLv2 and SSLv3 and Opportunistic TLS

2018-05-21 Thread Bill Cole
On 21 May 2018, at 13:16 (-0400), Sean Son wrote: Hello all I have opportunistic TLS (offering STARTLS) configured in my main.cf file. I have been tasked to disable SSLv2 and SSLv3 as well as disable medium strength ciphers (to use high strength ones instead) in my postfix server. If I

Question about disabling SSLv2 and SSLv3 and Opportunistic TLS

2018-05-21 Thread Sean Son
Hello all I have opportunistic TLS (offering STARTLS) configured in my main.cf file. I have been tasked to disable SSLv2 and SSLv3 as well as disable medium strength ciphers (to use high strength ones instead) in my postfix server. If I was to add the following to my main.cf:

Re: Mail being delayed for 5 minutes in active queue before being relayed

2018-05-21 Thread jmct
I seem to have fixed this. It appears that DNS WAS the cause. Resolution was not happening to me when doing requests, but when Postfix was attempting to make the same request, it appears to have failed from time to time. I saw this in the logs: May 21 15:28:53 mail postfix/scache[13448]:

Re: Mail being delayed for 5 minutes in active queue before being relayed

2018-05-21 Thread jmct
Thanks for all the replies. Yes, DNS is working as expected. I can resolve the relay host's address no problem. There is a firewall between them. Traffic is open between both sides. My postfix server is running on 25587/tcp and the relay hosts are both listening on the same. I can successfully

Re: Mail being delayed for 5 minutes in active queue before being relayed

2018-05-21 Thread Stephen Satchell
On 05/21/2018 07:31 AM, Stephen Satchell wrote: On 05/21/2018 07:06 AM, Postfix User wrote: I would suggest that you read this:http://www.postfix.com/DEBUG_README.html Suggest adding a section "Using a remote filesystem", asking if the clocks between the PostFix server and the remote file

Re: Mail being delayed for 5 minutes in active queue before being relayed

2018-05-21 Thread Wietse Venema
Stephen Satchell: > On 05/21/2018 07:06 AM, Postfix User wrote: > > I would suggest that you read this:http://www.postfix.com/DEBUG_README.html > > > Suggest adding a section "Using a remote filesystem", asking if the > clocks between the PostFix server and the remote file system are >

Re: Mail being delayed for 5 minutes in active queue before being relayed

2018-05-21 Thread Stephen Satchell
On 05/21/2018 07:06 AM, Postfix User wrote: I would suggest that you read this:http://www.postfix.com/DEBUG_README.html Suggest adding a section "Using a remote filesystem", asking if the clocks between the PostFix server and the remote file system are synchronized.

Postfix stable release 3.3.1, and legacy releases 3.2.6, 3.1.9, 3.0.13

2018-05-21 Thread Wietse Venema
[An on-line version of this announcement will be available at http://www.postfix.org/announcements/postfix-3.3.1.html] Fixed in Postfix 3.3: * Postfix did not support running as a PID=1 process, which complicated Postfix deployment in containers. The "postfix start-fg" command will now

Re: Mail being delayed for 5 minutes in active queue before being relayed

2018-05-21 Thread Postfix User
On Sun, 20 May 2018 15:08:11 -0700 (MST), jmct stated: >Hi there, > >I've set up a mail server that should be relaying messages to a different >cluster of Postfix boxes. When I attempt to send a message to the first box, >mail sits in the active queue for 5 minutes before being (successfully)

Re: Mail being delayed for 5 minutes in active queue before being relayed

2018-05-21 Thread Wietse Venema
Matus UHLAR - fantomas: > On 20.05.18 15:08, jmct wrote: > >I've set up a mail server that should be relaying messages to a different > >cluster of Postfix boxes. When I attempt to send a message to the first box, > >mail sits in the active queue for 5 minutes before being (successfully) >

Re: Mail being delayed for 5 minutes in active queue before being relayed

2018-05-21 Thread Matus UHLAR - fantomas
On 20.05.18 15:08, jmct wrote: I've set up a mail server that should be relaying messages to a different cluster of Postfix boxes. When I attempt to send a message to the first box, mail sits in the active queue for 5 minutes before being (successfully) relayed to the cluster of Postfix boxes.

Re: openDKIM and postfix

2018-05-21 Thread A. Schulze
On May 20, 2018, at 7:24 PM, John Levine wrote: > > Has anyone actually seen it happen in the > wild in the past decade? yes, web.de, gmx.net and other domains operated by 1&1 for example. or freemail.de or all the domains hosted by Eleven (today Cyren) For that it /is/ a