Re: SMTP Relay

2021-08-05 Thread Viktor Dukhovni
On Fri, Aug 06, 2021 at 03:05:03AM +, masstransitk...@365stops.org wrote: > I followed your advice and now the traffic is hitting my gateway as it > should. The problem is, now it's getting refused. > > Firewall rules specify input interface in DNAT rules now. So instead of > simply

Re: Inbound/Outbound Settings on a Postfix Relay-Only

2021-08-05 Thread Viktor Dukhovni
On Thu, Aug 05, 2021 at 06:14:56PM +, White, Daniel E. (GSFC-770.0)[NICS] wrote: > On my relay, I tried these settings: > > local_transport = error: local mail delivery is disabled > mail_version = 3.5.8 > relay_transport = hash:/etc/postfix/transport The "relay_transport" parametr is not

Re: Reject Code Logging

2021-08-05 Thread Bill Cole
On 2021-08-05 at 14:18:03 UTC-0400 (Thu, 05 Aug 2021 14:18:03 -0400) is rumored to have said: > I noticed when mail is rejected by a milter or header check it only logs the > DSN number and not the error code (550). > > cleanup: milter-reject: END-OF-MESSAGE from >

Re: Reject Code Logging

2021-08-05 Thread Wietse Venema
post...@ptld.com: > I noticed when mail is rejected by a milter or header check it only logs > the DSN number and not the error code (550). > > cleanup: milter-reject: END-OF-MESSAGE from > mail.example.com[111.222.333.444]: 5.7.1 Command rejected; > from= to= proto=ESMTP > helo= > > Is this

Reject Code Logging

2021-08-05 Thread postfix
I noticed when mail is rejected by a milter or header check it only logs the DSN number and not the error code (550). cleanup: milter-reject: END-OF-MESSAGE from mail.example.com[111.222.333.444]: 5.7.1 Command rejected; from= to= proto=ESMTP helo= Is this intentional or should it have the

Re: Inbound/Outbound Settings on a Postfix Relay-Only

2021-08-05 Thread White, Daniel E. (GSFC-770.0)[NICS]
On my relay, I tried these settings: local_transport = error: local mail delivery is disabled mail_version = 3.5.8 relay_transport = hash:/etc/postfix/transport .our.local.domain relay:[MDA server IP] smtpd_recipient_restrictions = permit_mynetworks relayhost = [ upstream relay ] And

Re: new install ignores transport file?

2021-08-05 Thread Noel Jones
On 8/5/2021 12:56 PM, Gomes, Rich wrote: Anywhere else to look? The logs. -- Noel Jones

Re: new install ignores transport file?

2021-08-05 Thread Viktor Dukhovni
On Thu, Aug 05, 2021 at 05:56:54PM +, Gomes, Rich wrote: > I can work with the linux team to have it tested and upgraded since I do not > control the OS portion of the servers. > I did postmap the transport file to no avail. > > Here is the results of postfix -n: > > mydestination = >

RE: new install ignores transport file?

2021-08-05 Thread Gomes, Rich
Thanks Noel I can work with the linux team to have it tested and upgraded since I do not control the OS portion of the servers. I did postmap the transport file to no avail. Here is the results of postfix -n: alias_database = hash:/etc/aliases alias_maps = hash:/etc/aliases allow_min_user =

Re: new install ignores transport file?

2021-08-05 Thread Noel Jones
On 8/5/2021 12:07 PM, Gomes, Rich wrote: Good day I have a newly built postfix server which is ignoring it's transport file and is querying DNS for MX records instead. I have googled the issue but only come up with "how to use transport file" articles. The /etc/postfix directory was copied

new install ignores transport file?

2021-08-05 Thread Gomes, Rich
Good day I have a newly built postfix server which is ignoring it's transport file and is querying DNS for MX records instead. I have googled the issue but only come up with "how to use transport file" articles. The /etc/postfix directory was copied from our Production relay and is working as

Re: [EXTERNAL] Re: Inbound/Outbound Settings on a Postfix Relay-Only

2021-08-05 Thread Wietse Venema
White, Daniel E. (GSFC-770.0)[NICS]: > This helps. > > All the outgoing mail is to go through an upstream relay cluster, so I can > set "relayhost" to that. > > Incoming mail - for a single, local domain - goes to an MDA server that has > Dovecot and Roundcube in addition to Postfix. It

Re: DANE TLSA lookup "whitelist"

2021-08-05 Thread Viktor Dukhovni
On Thu, Aug 05, 2021 at 04:48:07PM +0200, Matteo Cazzador wrote: > I use a local domain "*example.local*" i want to exclude it from dane > check because i obtain this error: > > warning: DANE TLSA lookup problem: Host or domain name not found. Name > service error for

Re: DANE TLSA lookup "whitelist"

2021-08-05 Thread Wietse Venema
Matteo Cazzador: > Thank's, something like ? > > /etc/postfix/main.cf: > smtp_tls_policy_maps =hash:/etc/postfix/tls_policy > > > /etc/postfix/tls_policy: > example.local none Yes, none or 'may'. Wietse

Re: DANE TLSA lookup "whitelist"

2021-08-05 Thread Matteo Cazzador
Thank's, something like ? /etc/postfix/main.cf : smtp_tls_policy_maps =hash :/etc/postfix/tls_policy /etc/postfix/tls_policy:

Re: [EXTERNAL] Re: Inbound/Outbound Settings on a Postfix Relay-Only

2021-08-05 Thread White, Daniel E. (GSFC-770.0)[NICS]
This helps. All the outgoing mail is to go through an upstream relay cluster, so I can set "relayhost" to that. Incoming mail - for a single, local domain - goes to an MDA server that has Dovecot and Roundcube in addition to Postfix. It sounds like I can use "relay_domains" and/or

Re: DANE TLSA lookup "whitelist"

2021-08-05 Thread Wietse Venema
Matteo Cazzador: > Hi everybody,? i've this configuration active in postfix: > > smtp_dns_support_level=dnssec > smtp_tls_security_level = dane > > Is it possible to exclude some check for specific domain name ? > > Something like whitelist domain name and lookup. > > I use a local domain

Re: DANE TLSA lookup "whitelist"

2021-08-05 Thread Emmanuel Fusté
Le 05/08/2021 à 16:48, Matteo Cazzador a écrit : Hi everybody,  i've this configuration active in postfix: smtp_dns_support_level=dnssec smtp_tls_security_level = dane Is it possible to exclude some check for specific domain name ? Something like whitelist domain name and lookup. I use a

DANE TLSA lookup "whitelist"

2021-08-05 Thread Matteo Cazzador
Hi everybody,  i've this configuration active in postfix: smtp_dns_support_level=dnssec smtp_tls_security_level = dane Is it possible to exclude some check for specific domain name ? Something like whitelist domain name and lookup. I use a local domain "*example.local*" i want to exclude it

Re: Inbound/Outbound Settings on a Postfix Relay-Only

2021-08-05 Thread Wietse Venema
White, Daniel E. (GSFC-770.0)[NICS]: > I am somewhat confused about which parameters apply to an outgoing vs an > incoming message. > > I think that > > relay_transport mail that you're willing to forward > relay_domains and mail that you're willing to forward > relayhost

Inbound/Outbound Settings on a Postfix Relay-Only

2021-08-05 Thread White, Daniel E. (GSFC-770.0)[NICS]
I am somewhat confused about which parameters apply to an outgoing vs an incoming message. I think that relay_transport relay_domains and relayhost apply to outgoing messages. I think that virtual_transport and local_transport (set to " error: local delivery disabled") apply to incoming

Re: smtp_sasl_password_maps round robbin

2021-08-05 Thread Wietse Venema
Adam Barnett: > Hi, > > When was pipemap and inline introduced? Six years ago (with Postfix 3.0, which is already out of support since February 2019). Wietse > I am getting these error messages > > postfix/smtp[12689]: error: unsupported dictionary type: pipemap >

Re: smtp_sasl_password_maps round robbin

2021-08-05 Thread Adam Barnett
Hi, When was pipemap and inline introduced? I am getting these error messages postfix/smtp[12689]: error: unsupported dictionary type: pipemap postfix/smtp[12689]: error: unsupported dictionary type: inline postfix/smtp[12689]: fatal: open dictionary: expecting "type:name" form instead of "{"

Re: "parameter inet_interfaces: no local interface found for 127.0.0.2" at reboot, but not on manual systemctl start

2021-08-05 Thread Vincent Lefevre
On 2021-07-29 09:57:39 -0400, Wietse Venema wrote: > Vincent Lefevre: > > No, this was the first thing I tried in order to solve the issue[*], > > but unfortunately this didn't have any effect: it doesn't seem to work > > with on-demand automount. > > If it is always required (for Postfix) what