Re: TLS issue with purchase order emails from ariba.com system.

2022-06-16 Thread raf
On Wed, Jun 15, 2022 at 11:09:10PM +0530, P V Anthony wrote: > Please note, I am still finding how to force renew with the letsencrypt > certs with the new renewal settings. Something like the following should do it (after making the renewal config changes that Viktor mentioned (or including th

Re: Postfix - Mysql - howto MultipleDomain?

2022-06-16 Thread raf
On Thu, Jun 16, 2022 at 11:07:05PM +0200, Maurizio Caloro wrote: > On 13.06.2022 12:05, Benny Pedersen wrote: > > postfixadmin is make it very more helpness, move both domains to > > virtual, and make mydestination only for system users, not possible to > > send direct to from outside of mynetwo

Re: Postfix - Mysql - howto MultipleDomain?

2022-06-16 Thread raf
On Thu, Jun 16, 2022 at 07:50:40PM -0400, Viktor Dukhovni wrote: > On Thu, Jun 16, 2022 at 11:07:05PM +0200, Maurizio Caloro wrote: > > >     --> Out: 454 4.7.0 TLS not available due to local problem > > As expected. > > > smtpd_tls_chain_files = > > /etc/letsencrypt/live/nmail.caloro.

Re: Gmail specific transport

2022-06-16 Thread Bob Proulx
Viktor Dukhovni wrote: > Transport resolutiont that does remote DNS lookups will be a prohibitive > performance bottleneck on systems delivering a steady non-trivial stream > of mail. The queue manager is not multi-threaded, and each recipient > domain can/will incur some delay. Yes. That would

Re: Postfix - Mysql - howto MultipleDomain?

2022-06-16 Thread Viktor Dukhovni
On Thu, Jun 16, 2022 at 11:07:05PM +0200, Maurizio Caloro wrote: >     --> Out: 454 4.7.0 TLS not available due to local problem As expected. > smtpd_tls_chain_files = > /etc/letsencrypt/live/nmail.caloro.ch/privkey.pem, > /etc/letsencrypt/live/nmail.caloro.ch/fullchain.pem, >

Re: Gmail specific transport

2022-06-16 Thread Viktor Dukhovni
On Thu, Jun 16, 2022 at 07:35:20PM -0400, Wietse Venema wrote: > Bob Proulx: > > Is there a transport mapping equivalent to match against the MX host > > instead of against the the recipient address? That's really what is > > desired here. I didn't think such a feature existed yet. > > it would

Re: Gmail specific transport

2022-06-16 Thread Wietse Venema
Bob Proulx: > Is there a transport mapping equivalent to match against the MX host > instead of against the the recipient address? That's really what is > desired here. I didn't think such a feature existed yet. it would require a Postfix lookup table that returns MX hosts for a domain, pi

Re: Gmail specific transport

2022-06-16 Thread Bob Proulx
Jaroslaw Rafa wrote: > Dnia 15.06.2022 o godz. 22:00:45 Bob Proulx pisze: > > It is interesting that mail to domains hosted at google that are not > > @gmail.com but other named domains delivered okay. Google accepted > > the exact same message to them fine. > > It can be that some domains that ar

Re: Gmail specific transport

2022-06-16 Thread Bob Proulx
Viktor Dukhovni wrote: > No, those settings are used by the queue manager to schedule deliveries > assigned to various delivery agent processes, the delivery agents > themselves only see one message at a time and can do little to affect > concurrency, and related limits. > > So these settings go in

Re: Postfix - Mysql - howto MultipleDomain?

2022-06-16 Thread Maurizio Caloro
On 13.06.2022 12:05, Benny Pedersen wrote: postfixadmin is make it very more helpness, move both domains to virtual, and make mydestination only for system users, not possible to send direct to from outside of mynetworks https://www.howtoforge.com/how-to-set-up-a-mail-server-with-postfixadmin-

Re: Rejected mails in mailq

2022-06-16 Thread @lbutlr
On 2022 Jun 16, at 02:01, Matus UHLAR - fantomas wrote: > On 15.06.22 16:35, @lbutlr wrote: >> Google has decided to reject some mails for a local user (mails in reply to >> gmail mails and to people they correspond with regularly, but that's not wha >> this email is about). >> >> 4LNYt002TPzPl

Re: Quarantining html email

2022-06-16 Thread Bill Cole
On 2022-06-16 at 04:10:41 UTC-0400 (Thu, 16 Jun 2022 01:10:41 -0700) Jeremy Hansen is rumored to have said: Is there an established recipe or utility or filter I can configure to quarantine html emails? This would need to be a milter or content_filter. One could implement this in MIMEDefang

Re: TLS issue with purchase order emails from ariba.com system.

2022-06-16 Thread P V Anthony
On 16/6/2022 8:16 pm, Viktor Dukhovni wrote: So it is far from clear what you could do to make this client happy. Perhaps some security middlebox near the client is misbehaving, or its TLS stack is broken beyond repair. Your best may be to disable STARTTLS for connections from this client:

Re: TLS issue with purchase order emails from ariba.com system.

2022-06-16 Thread Viktor Dukhovni
On Wed, Jun 15, 2022 at 03:09:16PM -0400, Viktor Dukhovni wrote: > You can share the PCAP file with me off-list. Thanks for the PCAP file. An immediate interesting feature is how the connection is terminated ("tcpdump" output edited to trim excess detail): 22:32:13.555416 1711 > 25: [S], se

Re: Gmail specific transport

2022-06-16 Thread Jaroslaw Rafa
Dnia 15.06.2022 o godz. 22:00:45 Bob Proulx pisze: > It is interesting that mail to domains hosted at google that are not > @gmail.com but other named domains delivered okay. Google accepted > the exact same message to them fine. It can be that some domains that are actually hosting their email a

Quarantining html email

2022-06-16 Thread Jeremy Hansen
Is there an established recipe or utility or filter I can configure to quarantine html emails? Bonus would be to process these emails to convert to a full image removing links and remote images from the quarantined email. I realize links would have to be pulled to generate the image but ultimate

Re: Rejected mails in mailq

2022-06-16 Thread Matus UHLAR - fantomas
On 15.06.22 16:35, @lbutlr wrote: Google has decided to reject some mails for a local user (mails in reply to gmail mails and to people they correspond with regularly, but that's not wha this email is about). 4LNYt002TPzPlrQ 77012 Wed Jun 15 09:59:16 (host alt1.gmail-smtp-in.l.google.com