Re: postfix stats

2015-05-05 Thread Birta Levente
On 01/05/2015 17:45, Benning, Markus wrote: Hi, if you are willed to test my pflogsumm fork and to provide some sample loglines i'll implement postscreen statistics. You can find the project at Github: https://github.com/benningm/saftpresse I modularized the pflogsumm code into seperate

Re: tls_policy

2015-05-04 Thread Birta Levente
On 04/05/2015 10:45, Viktor Dukhovni wrote: On Mon, May 04, 2015 at 08:59:10AM +0300, Birta Levente wrote: Can you reproduce the problem by using -CAfile $cafile with s_client(1)? I don't see how adding a trusted CA can break the handshake if the CA is well formed. Please provide more

Re: tls_policy

2015-05-03 Thread Birta Levente
On 30/04/2015 17:38, Viktor Dukhovni wrote: On Thu, Apr 30, 2015 at 10:29:29AM +0300, Birta Levente wrote: On 30/04/2015 10:17, Viktor Dukhovni wrote: On Thu, Apr 30, 2015 at 10:09:36AM +0300, Birta Levente wrote: OK, I found the problem: I had configured the smtp_tls_CAfile. Removing

Re: tls_policy

2015-04-30 Thread Birta Levente
On 30/04/2015 09:36, DTNX Postmaster wrote: On 30 Apr 2015, at 08:25, Birta Levente blevi.li...@gmail.com wrote: On 29/04/2015 20:56, Viktor Dukhovni wrote: On Wed, Apr 29, 2015 at 03:53:00PM +0300, Birta Levente wrote: I see many SSL_connect error for different domains which mail service

Re: tls_policy

2015-04-30 Thread Birta Levente
On 30/04/2015 09:58, Viktor Dukhovni wrote: On Thu, Apr 30, 2015 at 09:25:48AM +0300, Birta Levente wrote: Perhaps some sort of middle-box is interfering with TLS on your end. Also, what version of OpenSSL are you using? Well your end can be anywhere between you and the Microsoft email

Re: tls_policy

2015-04-30 Thread Birta Levente
On 29/04/2015 20:56, Viktor Dukhovni wrote: On Wed, Apr 29, 2015 at 03:53:00PM +0300, Birta Levente wrote: I see many SSL_connect error for different domains which mail service hosted at microsoft: Apr 28 10:32:12 srv1 postfix/smtp[18296]: SSL_connect error to irs-ro.mail.eo.outlook.com

Re: tls_policy

2015-04-30 Thread Birta Levente
On 30/04/2015 10:17, Viktor Dukhovni wrote: On Thu, Apr 30, 2015 at 10:09:36AM +0300, Birta Levente wrote: OK, I found the problem: I had configured the smtp_tls_CAfile. Removing everything works fine. Was the file malformed? I have a hard time imagining any non-empty set of well-formed

tls_policy

2015-04-29 Thread Birta Levente
Hello I see many SSL_connect error for different domains which mail service hosted at microsoft: Apr 28 10:32:12 srv1 postfix/smtp[18296]: SSL_connect error to irs-ro.mail.eo.outlook.com[213.199.154.87]:25: lost connection Apr 28 10:32:12 srv1 postfix/smtp[18296]: 3lbZRv0VXQz1lvjB:

Re: tls_policy

2015-04-29 Thread Birta Levente
On 29/04/2015 16:06, DTNX Postmaster wrote: On 29 Apr 2015, at 14:53, Birta Levente blevi.li...@gmail.com wrote: Hello I see many SSL_connect error for different domains which mail service hosted at microsoft: Apr 28 10:32:12 srv1 postfix/smtp[18296]: SSL_connect error to irs

Postscreen blacklisted IP dnsbl check

2014-11-12 Thread Birta Levente
Hi all Just curiosity: it's not unwanted to check postscreen_dnsbl for an IP which is blacklisted in postscreen_access_list? Nov 12 12:18:40 srv1 postfix/postscreen[26755]: CONNECT from [94.177.23.227]:50497 to [176.223.199.54]:25 Nov 12 12:18:40 srv1 postfix/postscreen[26755]: BLACKLISTED

Re: Postscreen blacklisted IP dnsbl check

2014-11-12 Thread Birta Levente
On 12/11/2014 14:21, Wietse Venema wrote: Birta Levente: Hi all Just curiosity: it's not unwanted to check postscreen_dnsbl for an IP which is blacklisted in postscreen_access_list? That would be a waste of Postfix resources. It would make Postfix less resistant against abuse from a known-bad

Re: Postscreen blacklisted IP dnsbl check

2014-11-12 Thread Birta Levente
On 12/11/2014 15:53, Wietse Venema wrote: Birta Levente: Just curiosity: it's not unwanted to check postscreen_dnsbl for an IP which is blacklisted in postscreen_access_list? Note: don't use no double negatives. Wietse: That would be a waste of Postfix resources. It would make Postfix less

Re: Postfix incompatibility safety net

2014-10-02 Thread Birta Levente
On 01/10/2014 18:57, Wietse Venema wrote: Postfix will log all uses of any old default value that will be affected by an incompatible change. This is not implemented yet (I installed 20141001 snapshot)? Or there is other way to see the affected parameters? Thanks, -- Levi

Re: Postfix incompatibility safety net

2014-10-02 Thread Birta Levente
On 02/10/2014 14:17, Wietse Venema wrote: Birta Levente: On 01/10/2014 18:57, Wietse Venema wrote: Postfix will log all uses of any old default value that will be affected by an incompatible change. This is not implemented yet (I installed 20141001 snapshot)? Or there is other way to see

Re: Postfix incompatibility safety net

2014-10-02 Thread Birta Levente
On 02/10/2014 15:36, Wietse Venema wrote: Birta Levente: On 02/10/2014 14:17, Wietse Venema wrote: Birta Levente: On 01/10/2014 18:57, Wietse Venema wrote: Postfix will log all uses of any old default value that will be affected by an incompatible change. This is not implemented yet (I

Re: blocking spam IP with netfitler good idea or not ?

2014-06-19 Thread Birta Levente
On 19/06/2014 16:57, Giuseppe De Nicolo' wrote: Hi, I have a question for you more experienced admin , I have some good abuse on my servers by IP listed in spam list , since I am using postscreen to block those all is good , anyway I thought then a good idea to just drop that traffic

Re: allow an email account to receive emails from a blacklisted IP

2014-06-03 Thread Birta Levente
On 03/06/2014 15:33, mancyb...@gmail.com wrote: Hi I have the same configuration and situation as the following: http://serverfault.com/questions/132750/postfix-whitelist-before-recipient-restrictions In short: So i need a method of whitelisting ANY email that comes to domain.com, however i

Latest snapshot not found

2014-05-20 Thread Birta Levente
Hello Could anyone download the latest 2.12-20140518 snapshot ? thanks -- Levi

Re: [PATCH] Re: Delivery problem in postfix-2.12-20140316 -- 20140508

2014-05-16 Thread Birta Levente
On 15/05/2014 18:17, Viktor Dukhovni wrote: On Thu, May 15, 2014 at 03:32:22PM +0300, Birta Levente wrote: with all received mails I got warning: process /usr/libexec/postfix/pipe pid 2078 killed by signal 11. diff --git a/src/pipe/pipe.c b/src/pipe/pipe.c index d63aca8..954fecf 100644

Delivery problem in 2.12

2014-05-15 Thread Birta Levente
Hi I use postfix 2.12-20140223 with virtual domains and users and dovecot LDA. Now, if I upgrade to 20140508 or 20140406 (I haven't other snapshot downloaded), with all received mails I got warning: process /usr/libexec/postfix/pipe pid 2078 killed by signal 11. I even tried to downgrade and

Re: Backup relay possible?

2014-03-27 Thread Birta Levente
On 27/03/2014 13:49, Nikolaos Milas wrote: Hello, On our gateway server, we have: transport_maps = hash:/etc/postfix/transportmap /etc/postfix/transportmap noa.gr relay:[vmail.noa.gr] admin.noa.grrelay:[vmail.noa.gr] nestor.noa.gr relay:[vmail.noa.gr]

Re: Backup relay possible?

2014-03-27 Thread Birta Levente
On 27/03/2014 15:05, Nikolaos Milas wrote: On 27/3/2014 2:04 μμ, Birta Levente wrote: http://www.postfix.org/postconf.5.html#fallback_relay Oh, thanks! So, since the two conditions are by default fulfilled: * In main.cf specify relay_transport = relay, * In master.cf specify -o

Re: Backup relay possible?

2014-03-27 Thread Birta Levente
On 27/03/2014 16:26, Nikolaos Milas wrote: On 27/3/2014 4:10 μμ, Birta Levente wrote: Not really IMHO AFAIK since you have two entries with same key in transport map, postfix will choose the first. I think this is the way: main.cf: fallback_relay=[vmail1.noa.gr] transport_map: noa.gr

Re: Permit SASL authenticated users to bypass DMARC

2014-03-17 Thread Birta Levente
On 17/03/2014 10:32, Oriental Sensation wrote: Hello group, I have an issue with Postfix, Dovecot, OpenDKIM and OpenDMARC cooperating together to achieve the following: Enable me to send Email from my phone device after authenticating my identity with SASL. It seems OpenDMARC is not

Re: qmgr_queue_throttle not fired up in 2.12.20140209

2014-02-28 Thread Birta Levente
On 24/02/2014 02:59, Wietse Venema wrote: Wietse Venema: Birta Levente: On 21/02/2014 15:44, Wietse Venema wrote: The behavior that you seem to prefer (throttle down domains after 4XX reply to MAIL FROM) is really a bug in the Postfix SMTP client implementation. Postfix normally does

Re: Bounce mails manually

2014-02-25 Thread Birta Levente
On 25/02/2014 10:10, Peer Heinlein wrote: I'm thinking about a way how to bounce mails manually *without* setting up a transport-map. Just bei CLI by the admin for a given Queue-ID. I'd love having a postsuper-commando to move a mail into the bounce queue. Is something like that possible?

Re: Bounce mails manually

2014-02-25 Thread Birta Levente
On 25/02/2014 10:49, Andreas Schulze wrote: Birta Levente: Why not just delete from the queue? from senders perspective that message is lost. sometimes it's useful to clear bounce back to sender. Yes, but you sould give some reason why is bounced ... which IMHO is something permanent

Re: Bounce mails manually

2014-02-25 Thread Birta Levente
On 25/02/2014 11:02, Andreas Schulze wrote: Birta Levente: Yes, but you sould give some reason why is bounced ... which IMHO is something permanent ... good point! # postbounce queue-id reason so you just set up one time some map and no more care about that problem. just this is unwanted

Re: qmgr_queue_throttle not fired up in 2.12.20140209

2014-02-21 Thread Birta Levente
On 19/02/2014 17:15, Viktor Dukhovni wrote: On Wed, Feb 19, 2014 at 03:00:25PM +0200, Birta Levente wrote: With 2.12.20140209 I get hundreds defferals because: Feb 19 05:21:59 srv2 postfix-slow/smtp[14313]: Untrusted TLS connection established to mta5.am0.yahoodns.net[98.138.112.38]:25: TLSv1

Re: qmgr_queue_throttle not fired up in 2.12.20140209

2014-02-21 Thread Birta Levente
On 21/02/2014 13:41, Wietse Venema wrote: Birta Levente: plaintext retries possibily raising this to four. We had considered special-casing 4XX replies as a reason to not retry plaintext when TLS connections are lost. If your more complete logs demonstrate a need to do that, we may add

Re: qmgr_queue_throttle not fired up in 2.12.20140209

2014-02-21 Thread Birta Levente
On 21/02/2014 15:44, Wietse Venema wrote: Wietse Venema: The behavior that you seem to prefer (throttle down domains after 4XX reply to MAIL FROM) is really a bug in the Postfix SMTP client implementation. Postfix normally does not throttle down domains after 4XX reply to MAIL FROM. The bug is

Re: qmgr_queue_throttle not fired up in 2.12.20140209

2014-02-19 Thread Birta Levente
On 19/02/2014 13:57, Wietse Venema wrote: Birta Levente: I have a problem with Postfix 2.12 Snapshot 20140209. The qmgr_queue_throttle never fired up for destinations which go through slow transport and obviously the delivery never suspended to these few destinations. Mails which go out

qmgr_queue_throttle not fired up in 2.12.20140209

2014-02-18 Thread Birta Levente
Hi I have a problem with Postfix 2.12 Snapshot 20140209. The qmgr_queue_throttle never fired up for destinations which go through slow transport and obviously the delivery never suspended to these few destinations. Mails which go out normally, i.e. not through slow transport, seems to throttle:

Slow destination fine tunning

2013-11-29 Thread Birta Levente
Hello I have special transport for slow destinations. As documented if transport_destination_rate_delay1s then applied for the same domain. slow_initial_destination_concurrency=4 slow_destination_concurrency_limit=8 slow_destination_recipient_limit=10 slow_destination_rate_delay=2s

Re: Slow destination fine tunning

2013-11-29 Thread Birta Levente
On 29/11/2013 21:20, Viktor Dukhovni wrote: On Fri, Nov 29, 2013 at 12:40:03PM +0200, Birta Levente wrote: I have special transport for slow destinations. As documented if transport_destination_rate_delay1s then applied for the same domain. There is no such documentation. Setting it to 1s

Re: Monitoring

2013-07-17 Thread Birta Levente
On 17/07/2013 15:14, Roman Gelfand wrote: Is there open source web based postfix server monitoring software? I am looking to see if there is something to monitor queue size, etc... Thanks in advance mailgraph: http://mailgraph.schweikert.ch/ queuegraph:

Re: Is this an attack?

2013-06-20 Thread Birta Levente
On 20/06/2013 13:49, Andreas Kasenides wrote: On 19-06-2013 14:37, lst_ho...@kwsoft.de wrote: Zitat von Andreas Kasenides andr...@cymail.eu: One of my mail servers (postfix 2.6) has been target of what seems to me to be an attack. The attacker tried to deliver messages to a non-existent user

Re: Is this an attack?

2013-06-19 Thread Birta Levente
On 19/06/2013 14:37, lst_ho...@kwsoft.de wrote: Zitat von Andreas Kasenides andr...@cymail.eu: One of my mail servers (postfix 2.6) has been target of what seems to me to be an attack. The attacker tried to deliver messages to a non-existent user names formed as a long hex string. It only

Re: New Postfix log analyzer tool V0.9.13 released (PostgreSQL DB 9.2.x based)

2013-04-24 Thread Birta Levente
On 23/04/2013 23:29, Nicolas HAHN wrote: Dear Community, *Version 0.9.13* of the tool has been released. My tool is able to parse Postfix Logs (version 2.8 for now), generates statistics, propose you a great EXTJS 4.1.3 Web 2.0 interface, offers powerfull search features and so on... It is

Re: Building el6 RPMs for v2.10

2013-02-27 Thread Birta Levente
On 27/02/2013 21:54, Nikolaos Milas wrote: Hello, I have been building el6 (CentOS 6, RHEL 6) RPMs using J. Mudd's SRPMs (http://ftp.wl0.org/official/2.9/SRPMS/). Does anyone have experience on building v2.10.x RPMs using the same SRPMs? Are these safe, or has anyone adjusted the above

Re: is possible to use different SSL certificates for different domains?

2013-02-25 Thread Birta Levente
On 25/02/2013 12:38, marcos gonzalez wrote: Hi Thanks for the answer. I'm reading how more of you separates http of mail, is correct but If you needs the same SSL certificate for more than one domain, and for legal questions you can't include all domains in one certificate, I don't know If

Re: is possible to use different SSL certificates for different domains?

2013-02-25 Thread Birta Levente
On 25/02/2013 22:59, Reindl Harald wrote: Am 25.02.2013 21:54, schrieb Birta Levente: On 25/02/2013 12:38, marcos gonzalez wrote: Hi Thanks for the answer. I'm reading how more of you separates http of mail, is correct but If you needs the same SSL certificate for more than one domain

Re: setting up postscreen on a system with multiple external interfaces

2013-02-21 Thread Birta Levente
On 21/02/2013 15:32, Erik Slagter wrote: On 21-02-13 13:04, DTNX Postmaster wrote: Please help me with the following. I have here a postfix system that listens on multiple (external) interfaces, e.g. one of them receives e-mail from the internet, one of them receives more or less secure mail

Re: setting up postscreen on a system with multiple external interfaces

2013-02-21 Thread Birta Levente
On 21/02/2013 15:56, Erik Slagter wrote: On 21-02-13 14:41, Birta Levente wrote: Postfix does start, but it doesn't honour the options, on both instances. It's very simple to check, because I have postcheck report another welcome string on every interface. Now it shows the default welcome

proxymap permission denied

2013-02-19 Thread Birta Levente
Hi all Today I restarted the postfix server because one misconfiguration in the master.cf: unknown smtpd restriction: reject_unauth_destionation Then in the maillog appears other errors, I think not related to above: /proxymap[9105]: error: open /etc/postfix/mysql-virtual_forwardings.cf:

Re: proxymap permission denied

2013-02-19 Thread Birta Levente
On 19/02/2013 11:58, Reindl Harald wrote: and why do you reply off-list? Am 19.02.2013 10:36, schrieb Birta Levente: On 19/02/2013 11:29, Reindl Harald wrote: Am 19.02.2013 10:04, schrieb Birta Levente: Today I restarted the postfix server because one misconfiguration in the master.cf

Re: [SOLVED] proxymap permission denied

2013-02-19 Thread Birta Levente
On 19/02/2013 11:58, Reindl Harald wrote: and why do you reply off-list? Am 19.02.2013 10:36, schrieb Birta Levente: On 19/02/2013 11:29, Reindl Harald wrote: Am 19.02.2013 10:04, schrieb Birta Levente: Today I restarted the postfix server because one misconfiguration in the master.cf

Re: Graphing mail stats

2013-02-18 Thread Birta Levente
On 16/02/2013 12:59, Nikolaos Milas wrote: On 15/2/2013 9:47 μμ, Nikolaos Milas wrote: However, although I have successfully patched both mailgraph.pl and mailgraph.cgi, it doesn't seem to work. (I did it twice to confirm.) In the place of the Bounced-Virus-... etc diagram nothing appears

Re: postfix multiple WAN-IP setup

2013-02-15 Thread Birta Levente
On 15/02/2013 16:14, Tom Loewen wrote: EHLO list, we have two WAN connections. One has the RDNS entry mx0.example.com the other has mx1.example.com. Is there a way to setup postfix so that he will reply with the correct hostname? I know that you can do this in master.cf but the server is behind

Re: Graphing mail stats

2013-02-15 Thread Birta Levente
On 15/02/2013 16:29, Nikolaos Milas wrote: Hello, Does anyone know of any app like mailgraph, smart enough to combine data from amavis and postfix and provide more detailed stats like: Mail dropped by postscreen Mail dropped by amavis as spam (through spamassassin) Mail dropped by amavis as

Re: Testing out SMTPS

2013-02-05 Thread Birta Levente
On 05/02/2013 12:25, Geoff Shang wrote: On Mon, 4 Feb 2013, Robert Moskowitz wrote: Well the online tester made me aware of it, and some of my clients are stuck with Outlook Express, thus my interest in it. Outlook Express can use port 587 quite happily. You just have to tell it to.

slow down deferred destination

2013-01-29 Thread Birta Levente
Hi all How can I slow down deliveries to specified domain after temporary deferred? I have a list for marketing purposes and 2/3 part of subscribed users is on yahoo. To yahoo, deliveries go through slow transport: slow_destination_recipient_limit=10 slow_destination_concurrency_limit=1

Re: slow down deferred destination

2013-01-29 Thread Birta Levente
On 29/01/2013 10:49, Titanus Eramius wrote: Tue, 29 Jan 2013 08:30:05 + skrev James Griffin jmz.grif...@kode5.net: * Birta Levente blevi.li...@gmail.com [2013-01-29 10:18:15 +0200]: Hi all How can I slow down deliveries to specified domain after temporary deferred? I have a list

Re: Redirecting queued messages

2012-12-07 Thread Birta Levente
On 07/12/2012 09:12, Luigi Rosa wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I have a border SMTP server that has some local mailbox and relays other recipients to an internal Exchange server Relay to Exchange is done via transport file with something like this: exchange.acme.com

Re: Postfix 2.8.x and archive options

2012-10-11 Thread Birta Levente
On 11/10/2012 12:40, Robert Schetterer wrote: Am 11.10.2012 11:12, schrieb Josef Karliak: Hi, I want all emails. Email could be filtered as a spam (false positive). Co I want to have an option to resend the email - copy it into a spool or so. First option is that I've all emails in the

Postfix multiple instances

2012-08-16 Thread Birta Levente
Hi all How can direct through specified instance the locally submitted mail? For example: server with 3 domains, 3 different ip address, 3 postfix instances for this 3 domains with different myhostname, certs. Through which instance going out the mail submitted with phpmailer for example? (Of

Re: Postfix stable release 2.9.4 and legacy releases 2.8.12, 2.7.11, 2.6.17

2012-08-02 Thread Birta Levente
On 02/08/2012 02:21, Wietse Venema wrote: [An on-line version of this announcement will be available at http://www.postfix.org/announcements/postfix-2.9.4.html] Postfix stable release 2.9.4, and legacy releases 2.8.12, 2.7.11, 2.6.17 are available. They contain fixes and workarounds that are

Graph postfix/postscreen with mailgraph 1.14 patch

2012-05-07 Thread Birta Levente
://store.birkosan.com/mailgraph/mailgraph.cgi_postscreen.patch http://store.birkosan.com/mailgraph/mailgraph.pl_postscreen.patch Birta Levente

Re: logging transport route

2012-04-02 Thread Birta Levente
On 02/04/2012 14:31, Mikael Bak wrote: Hi list, I have configured an alternate transport route for mail going to specific destination domains. I call this transport slowsmtp. My problem is that I see no evidence in my logs that email sent to the specific domains uses slowsmtp route for

postfix duplicated dkim signature

2012-02-16 Thread Birta Levente
Hello I use postfix 2.7.2 with amavisd-new, opendkim and dk-milter. My problem is dkim signature appear 2 times in mail header. It is ok? how can i fix this? thanks Levi

Re: postfix duplicated dkim signature

2012-02-16 Thread Birta Levente
On 16/02/2012 15:02, li...@coffeehabit.net wrote: On 16/02/12 09:46, Birta Levente wrote: Hello I use postfix 2.7.2 with amavisd-new, opendkim and dk-milter. I'm curious to know why you're using opendkim and dk-milter instead of using the built-in DKIM signing/checking in amavisd-new? I

Re: Spam notification

2010-06-18 Thread Birta Levente
On 18/06/2010 11:36, Antoine Nguyen wrote: Hi all, I'm facing a stupid situation and I'm looking for advises. I'm using a postfix relay to filter viruses and spams. All is working well except with spam that use the same declared address for both sender and recipient. What happened in this

Re: DKIM-milter only for outgoing

2010-04-16 Thread Birta Levente
On 15/04/2010 18:26, Tomoyuki Murakami wrote: From: Birta Leventeblevi.li...@gmail.com Subject: DKIM-milter only for outgoing Date: Thu, 15 Apr 2010 17:23:12 +0300 My postfix server is set up with amavisd-new and dkim-milter. In the main.cf: content_filter =

DKIM-milter only for outgoing

2010-04-15 Thread Birta Levente
Hi all My postfix server is set up with amavisd-new and dkim-milter. In the main.cf: content_filter = smtp-amavis:[127.0.0.1]:10024 smtpd_milters = inet:localhost:20209 non_smtpd_milters = inet:localhost:20209 milter_protocol = 2 milter_default_action = accept With this configuration the

Re: How to configure spamassassin

2010-04-09 Thread Birta Levente
On 09/04/2010 13:43, hateSpam wrote: Dear All, I have Spamassassin on my Centos 5.4. For send and receive email I use postfix and Dovecot and Sendmail version 8.13.8. Since I have installed the spamassassin I have not configured it. We are getting about 20 spams per day. I want to configure it

Re: Have some local transport issues

2010-04-07 Thread Birta Levente
On 07/04/2010 15:10, CT wrote: I had posted some of this before but since I wasn't a valid subscriber I was silently ignored.. mybad.. :-) --- I have an internal relay that I am replacing (sendmail with postfix) I have followed :