recipient_delimiter with virtual_* setup: undeliverable address

2014-01-22 Thread Patrick Lists
Hi, On a CentOS 6.5 box with a virtual_mailbox_domains, virtual_mailbox_maps, virtual_alias_maps setup all accessing openldap I added in main.cf (and restarted postfix afterwards): recipient_delimiter = + with the goal to get patrick+...@example.org working. Unfortunately there is a

Re: recipient_delimiter with virtual_* setup: undeliverable address

2014-01-22 Thread Patrick Lists
Hi Viktor, TL;DR fixed, case closed. On 22-01-14 17:18, Viktor Dukhovni wrote: On Wed, Jan 22, 2014 at 04:59:25PM +0100, Patrick Lists wrote: On a CentOS 6.5 box with a virtual_mailbox_domains, virtual_mailbox_maps, virtual_alias_maps setup all accessing openldap I added in main.cf

Re: Separate per (sub)domain delivery method?

2014-01-13 Thread Patrick Lists
Hi, Did my question slip through the cracks or doesn't anyone have an idea? Would appreciate a hint if I'm looking at this the right way. Regards, Patrick On 10-01-14 05:04, Patrick Lists wrote: Hi, An EL6 box is working great as my personal mailserver using virtual_mailbox_domains

Re: Separate per (sub)domain delivery method?

2014-01-13 Thread Patrick Lists
Hi Noel, On 13-01-14 16:18, Noel Jones wrote: [snip] The virtual_transport parameter is the (single) default transport for virtual_mailbox_domains. Override this default using transport_maps. Please see the docs. http://www.postfix.org/postconf.5.html#virtual_transport

Separate per (sub)domain delivery method?

2014-01-09 Thread Patrick Lists
Hi, An EL6 box is working great as my personal mailserver using virtual_mailbox_domains, virtual_mailbox_maps, virtual_alias_maps all accessing openldap and delivered via virtual_transport to an LMTP backend. I would like to use that same box for receiving email from about 40 mailing lists

Re: EC_GROUP_new_by_curve_name:unknown group:ec_curve.c:316

2013-10-24 Thread Patrick Lists
On 10/23/2013 10:57 PM, Viktor Dukhovni wrote: [snip] The problem turns out to be that RedHat's patch did not prune the list of curves advertised by the TLS client! They're going to update the code to only advertise secp{256,384}r1, which will make connections to gmx.de work again (but without

Re: EC_GROUP_new_by_curve_name:unknown group:ec_curve.c:316

2013-10-24 Thread Patrick Lists
On 10/24/2013 11:15 AM, li...@rhsoft.net wrote: Am 24.10.2013 11:11, schrieb Patrick Lists: On 10/23/2013 10:57 PM, Viktor Dukhovni wrote: [snip] The problem turns out to be that RedHat's patch did not prune the list of curves advertised by the TLS client! They're going to update the code

Re: Google rejecting IPv6 mails

2013-10-09 Thread Patrick Lists
On 10/10/2013 01:37 AM, Wietse Venema wrote: James Cloos: Unfortunately it is not uncommon with v6. I've had to whitelist a number of sites over the last year where the outoing mta added a v6 address w/o a ptr. Mostly it appeared to be due to new v6 routes and autoconfig surprising the mta

Re: Google rejecting IPv6 mails

2013-10-07 Thread Patrick Lists
On 10/07/2013 07:49 PM, Luigi Rosa wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Wietse Venema said the following on 07/10/2013 16:25: And here is the corrected example in one place. BTW it seems the real fix is to set up one PTR record, with a matching record. No, it doesn't

Re: Block certain remote hosts on submission port

2013-08-23 Thread Patrick Lists
On 08/23/2013 12:47 PM, Mikael Bak wrote: [snip] In fact it's not a good idea at all IMO. People do travel and they need to read and write email while they are abroad. Laptop and/or smartphone users will not like your new restriction policy when they try to get some work done while visiting a

Re: OT: amavisd-new-milter rpm

2013-08-19 Thread Patrick Lists
On 08/19/2013 07:29 PM, Patrick Ben Koetter wrote: Has anyone seen a recent (= 1.5.0) RHEL 6 RPM for amavisd-new-milter or a src.rpm to work/build from? EPEL has amavisd-new 2.8.0: http://koji.fedoraproject.org/koji/buildinfo?buildID=397472 Regards, Patrick

Re: OT: amavisd-new-milter rpm

2013-08-19 Thread Patrick Lists
On 08/19/2013 08:07 PM, Patrick Lists wrote: On 08/19/2013 07:29 PM, Patrick Ben Koetter wrote: Has anyone seen a recent (= 1.5.0) RHEL 6 RPM for amavisd-new-milter or a src.rpm to work/build from? EPEL has amavisd-new 2.8.0: http://koji.fedoraproject.org/koji/buildinfo?buildID=397472 Saw

Re: Would somebody let me know what I need to do to improve this setup.

2013-08-07 Thread Patrick Lists
On 08/07/2013 12:03 PM, John Allen wrote: [snip] Yes. We support a business that designs and manufactures packaging and displays. The sort of thing you might see in the aisle of a supermarket or store selling gum, personal care products. The graphics, art work and design of these need to be

Problem with transport setup

2013-06-10 Thread Patrick Lists
Hi, I'm looking at integrating dspam into postfix in a Non-Postfix mailbox store: separate domains, non-UNIX accounts setup as described here: http://www.postfix.org/VIRTUAL_README.html#in_virtual_other The problem I have is getting the retraining to work. The idea is to forward an email with

Re: Problem with transport setup

2013-06-10 Thread Patrick Lists
On 06/10/2013 09:38 PM, Tom Hendrikx wrote: Normally, you'd tell dspam to not deliver the messages passed while retraining by adding '--deliver=' (i.e. deliver never) to the retrain command line. I'm missing support for that in the script (as available in the dspam git repo), but I'm not sure

Re: reject_unknown_reverse_client_hostname safe?

2013-05-07 Thread Patrick Lists
On 05/07/2013 02:02 PM, Vincent Lefevre wrote: [snip] A PTR is not associated with a host, but with an IP address. That's important because mail may be sent from different IP addresses, depending on the recipient or other factors. And it seems that some users forget to set up a PTR for all their

Re: need advice

2013-04-01 Thread Patrick Lists
On 04/01/2013 04:59 PM, Muhammad Yousuf Khan wrote: so what you please have to suggest. and obviously no option of third party like google calender etc. we are looking for some centralized solution In addition to the previous suggestions you can also check out Zarafa and Open-Xchange.

Re: LDAP canonical_maps and domain rewriting

2013-03-20 Thread Patrick Lists
Hi Fernando, On 03/20/2013 05:40 PM, Fernando Maior wrote: Patrick, I do not use canonical maps at all when using LDAP. I do not need it, because I just use mailForwardingAddress (actually an alias) to map the incoming email to the real mailbox. What I do: 1. Use the qmail.schema in

Re: LDAP canonical_maps and domain rewriting

2013-03-19 Thread Patrick Lists
Hi Fernando, On 03/19/2013 01:02 PM, Fernando Maior wrote: Hello, All this seems to be something very different from what postfix and other smtp usually does. So, may be the problem is with the concept, not with the implementation. May I ask you why you need to change the domain name part of

Re: LDAP canonical_maps and domain rewriting

2013-03-19 Thread Patrick Lists
Hi Viktor, My apologies for getting your name wrong on the previous email. On 03/19/2013 04:22 PM, Viktor Dukhovni wrote: Nothing unusual at all about canonical mapping, the only anomaly I'm making a fuss about is the underlying data model. It is OK to turn secondary addresses into primary,

Re: LDAP canonical_maps and domain rewriting

2013-03-17 Thread Patrick Lists
Hi Fernando, On 03/16/2013 07:43 PM, Fernando Maior wrote: Hi Patrick, If you use the hash table, and issue the postmap command, what is the output? Here is the output: $ cat /etc/postfix/canonical @domainA.org@domainB.org $ postmap -q t...@domaina.org hash:/etc/postfix/canonical

Re: LDAP canonical_maps and domain rewriting

2013-03-17 Thread Patrick Lists
Hi Victor, On 03/16/2013 11:25 PM, Viktor Dukhovni wrote: [snip] I've always avoided wildcard rewrites with LDAP, do the rewrite only with actual valid user addresses. Ok. @domainA.org @domainB.org I don't recall whether %d works with @domain input keys. I would have guessed it does,

Re: LDAP canonical_maps and domain rewriting

2013-03-17 Thread Patrick Lists
Hi Victor, On 03/17/2013 07:38 PM, Viktor Dukhovni wrote: [snip] You really should not do this. Instead take the high road: query_filter = mailDeliveryAddress=%s result = mail Will try that. Keep in mind that there are many different LDAP email schemas and yours may keep

Re: LDAP canonical_maps and domain rewriting

2013-03-17 Thread Patrick Lists
On 03/17/2013 11:48 PM, Viktor Dukhovni wrote: [snip] Googling around I found a small postfix.schema and used the maildrop attribute which works fine using this This may not be the right choice. The schema that uses maildrop IIRC typically uses: mail: primary

LDAP canonical_maps and domain rewriting

2013-03-16 Thread Patrick Lists
Hi all, Venturing into postfix+openldap country I bumped into a challenge: is it possible to use an LDAP table for canonical_maps to generically rewrite domainA to domainB (so for all email addresses @domainA.org)? It works fine when I use this in a hash table: @domainA.org @domainB.org

Re: Support for MDB in postfix 2.10?

2013-02-25 Thread Patrick Lists
On 02/25/2013 02:14 PM, Wietse Venema wrote: Quanah Gibson-Mount: I will evaluate the MDB client once there is an MDB library package for a main-stream Linux or *BSD platform. That is, something that installs MDB include files, an MDB object library file, and MDB documentation in

Re: Support for MDB in postfix 2.10?

2013-02-25 Thread Patrick Lists
On 02/25/2013 02:53 PM, Wietse Venema wrote: [snip] I will evaluate the MDB client once there is a package for a mainstream LINUX or *BSD distribution that people can install by typing one or two commands. (Resend without the (S)RPMs since it exceeded the allowed size) Hi Wietse, It seems

Re: Support for MDB in postfix 2.10?

2013-02-25 Thread Patrick Lists
On 02/25/2013 07:19 PM, Wietse Venema wrote: FYI, in order to maintain Postfix in a meaningful manner I need to know what the library will look like on OTHER people's systems. Therefore I will wait until there is a package for a mainstream LINUX or *BSD distribution that OTHER people can install

Re: Out Of Office Responders

2012-12-29 Thread Patrick Lists
On 12/29/2012 04:08 PM, Tim Smith wrote: Hi Wietse, Thanks for the response. Using Dovecot which is Sieve enabled so no problem there. I also found a list of Sieve enabled clients http://sieve.info/clients but can't see that Outlook or any MS products are available there. My clients are

Re: Latest package for RHEL6

2012-10-22 Thread Patrick Lists
On 10/22/2012 04:56 PM, Morten Stevens wrote: [snip] I have backported Postfix 2.9.x for my company and I am also package maintainer for Fedora. Here are my latest builds for el6: http://mstevens.fedorapeople.org/el6/postfix/ Would you mind making the SRPM also available? Regards, Patrick

Re: Latest package for RHEL6

2012-10-22 Thread Patrick Lists
On 10/22/2012 05:29 PM, Patrick Lists wrote: On 10/22/2012 04:56 PM, Morten Stevens wrote: [snip] I have backported Postfix 2.9.x for my company and I am also package maintainer for Fedora. Here are my latest builds for el6: http://mstevens.fedorapeople.org/el6/postfix/ Would you mind

Re: Block sending from non-US IPs

2012-10-18 Thread Patrick Lists
On 10/18/2012 10:24 PM, mouss wrote: you can try http://countries.nerd.dk/more.html you can also try GeoIP. Also check out http://ipdeny.com/ Regards, Patrick

How to block forged From: in DATA section?

2012-05-31 Thread Patrick Lists
Hi, My Postfix setup works quite well blocking most spam. But I sometimes get spam with (to my untrained eye) valid MAIL from: and RCPT to: email addresses but in the DATA section there is a forged From: m...@mydomain.com. At least that's how it works when I use telnet to port 25 on my Postfix

Re: How to block forged From: in DATA section?

2012-05-31 Thread Patrick Lists
Hi Reindl, On 01-06-12 02:10, Reindl Harald wrote: I tried the example header_checks [1] from the BACKSCATTER_README which work fine except that they also block my own email. What is the proper way to block forged From: addresses in the DATA section? there is no proper way simply because

Re: Anyone else getting lots of spam from Plesk web sites?

2012-03-07 Thread Patrick Lists
On 08-03-12 03:01, francis picabia wrote: Just starting today we've received dozens of spam from websites, all coming from anonym...@www.example.com where www.example.com is a website showing Plesk. I've blocked dozens of IPs. Has anyone else seen this? Iirc recently there was a hole in

Re: Plesk or equivalent to manage Postfix ?

2011-11-04 Thread Patrick Lists
On 11/04/2011 02:13 PM, Frank Bonnet wrote: Hello Does anyone has ever use Plesk or another graphical interface to manage Postfix ? Maybe http://sourceforge.net/projects/postfixadmin/ Regards, Patrick

Re: Throttling

2011-09-29 Thread Patrick Lists
On 09/29/2011 12:00 PM, Tolga wrote: mydestination = vps.ozses.net, localhost.ozses.net, , localhost To my untrained eye the two comma's (.net, , localhost) don't seem right and the error seems to suggest that you need to install, configure and start cyrus-sasl. Regards, Patrick

Fighting virtual_mailbox_domain errors

2011-09-03 Thread Patrick Lists
Hi all, On a CentOS 6 box with postfix-2.6.6-2.1.el6_0 I'm trying to setup a virtual_mailbox_domain that is fed into Zarafa (the Open Source Exchange replacement). I can't seem to get past the helo_access and relay denied errors. So clearly I am doing something wrong but the postfix book and

Re: Fighting virtual_mailbox_domain errors

2011-09-03 Thread Patrick Lists
On 09/03/2011 08:28 PM, Noel Jones wrote: mynetworks = 127.0.0.0/8, 10.0.0.0/24, 10.0.1.0/24 Oops, mynetworks contains only ip4 addresses. Solution is to either disable ip6: inet_protocols = ipv4 or add ip6 localhost to mynetworks: mynetworks = [::1]/128 127.0.0.0/8, 10.0.0.0/24, 10.0.1.0/24

Re: allow mutual authentication with ssl certificate

2011-08-22 Thread Patrick Lists
On 08/22/2011 05:31 PM, Noel Jones wrote: [snip] On a side note, very few desktop mail clients support TLS certificate authentication. Make sure Thunderbird supports this feature before you spend too much time on it. TLS certificate authentication is mostly used for MTA-to-MTA auth. I used

Regexp for blocking dynamic hosts?

2010-08-30 Thread Patrick Lists
Hi, I got a lot of spam lately from dynamic hosts so gradually I have been adding rules to block them with the help of the rules from http://gabacho.reto.jp/en/anti-spam/anti-spam-system.html Unfortunately this type keeps slipping through: Received: from 200-161-108-143.dsl.telesp.net.br My

Re: Regexp for blocking dynamic hosts?

2010-08-30 Thread Patrick Lists
On 08/31/2010 12:40 AM, Stan Hoeppner wrote: [snip] /^[12]?[0-9]{1,2}(-[12]?[0-9]{1,2}){3}\.(customer|dsl|dial-up)\.telesp\.net\.br$/ REJECT Generic - Please relay via ISP (telesp.net.br) That's all one line, TB wrapped it. You may as well just use this. Over 1600 regex patterns matching

Allowing only certain From:... to send email to a specific To:... possible?

2010-05-06 Thread Patrick Lists
Hi list, I use a unique email address (alias) for every web(service) registration. I would like to limit or even block spam sent to these unique addresses. I glanced through the Postfix book but couldn't find an answer. Example of what should be blocked: From: Twitter System

Re: Allowing only certain From:... to send email to a specific To:... possible?

2010-05-06 Thread Patrick Lists
On 05/06/2010 04:07 PM, Noel Jones wrote: [snip] You can use an external policy service such as postfwd to compare envelope sender and recipient. But it sounds as if you really need to compare the From: header with the envelope recipient. You'll need a content_filter or milter to do that. --