Re: trouble with smtps

2011-01-05 Thread Victor Duchovni
On Wed, Jan 05, 2011 at 11:49:07PM -0500, brian wrote: I know I'm in over my head here. Not only am I unsure how to test this, I'm also having trouble interpreting the results I do get. That's mostly it. Your client restrictions deny access by

Re: Why use EGD instead of /dev/urandom in tls_random_source?

2011-01-05 Thread Victor Duchovni
On Thu, Jan 06, 2011 at 01:22:50AM -0500, Jerrale G wrote: 0. http://www.postfix.org/TLS_README.html 1. http://www.entropykey.co.uk/ 2. http://www.postfix.org/TLS_README.html#tlsmgr_controls We use /dev/random. Using /dev/urandom does not cause enough entropy, which may just be a problem

Re: Change error messages returned by Postfix

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 01:24:51PM +0100, John Adams wrote: 550-5.5.1u...@examplegt: Recipient address rejected: User unknown 550 5.5.1 For assistance, call 800-555-0101 This feature is available in Postfix 2.8. Cool. Thanks. Can this be configured in a multi-domain

Re: Change error messages returned by Postfix

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 03:09:01PM +0100, John Adams wrote: Yes, I understand that. But that is not how I experienced the world. Usually, if person X from domain X could not mail to person Z from domain Z for a reject reason given by mail provider M, then X would call Z (I cannot send you

Re: Change error messages returned by Postfix

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 03:36:41PM +0100, Mark Scholten wrote: Server response: 550-5.5.1 u...@examplegt: Recipient address rejected: User unknown 550 5.5.1 For assistance, call 800-555-0101 This feature is available in Postfix 2.8. Thank you. Is it

Re: body_checks ... can a header be inserted?

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 09:47:10AM -0500, Phil Howard wrote: Unlike some software, Postfix behaves as documented, so you can easily establish from the manpage how the prepend action works. So basically, the answer is no. Behaving as documented is good. But is it the case that every

Re: body_checks ... can a header be inserted?

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 10:53:56AM -0500, Phil Howard wrote: And that is part of my thinking. All the features that you can use are documented. The internals that you can use to *reason* about the behaviour of the system when things go wrong are less easily described. There MAY have been some

Re: Change error messages returned by Postfix

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 11:33:25AM -0500, Wietse Venema wrote: Thank you. Is it possible to let this new setting contain something that contains the client IP and/or something so we could identify it with a script? Identify what with a script? [talk about stuff in logfiles]

Re: body_checks ... can a header be inserted?

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 11:39:01AM -0500, Phil Howard wrote: In other words, for the test itself to be changed (as a new kind of test) to do what I need, it would either need random access to the message file (which cannot happen here if the message is not yet stored as a file), or has

Re: Change error messages returned by Postfix

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 12:54:24PM -0500, Wietse Venema wrote: What I could do for now is a contact footer with dynamic context such as the SMTP server PID and client IP address. That information is already in the maillog file. So this would change the feature to:

Re: Change error messages returned by Postfix

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 02:09:07PM -0500, Wietse Venema wrote: This would likely need to also be implemented in postscreen. :-( If keyword-substitution is supported, apart from $pid, and $client_addr also $rfc822_date would perhaps be useful to help search logs for the right day. PID

Re: Change error messages returned by Postfix

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 02:32:45PM -0500, pf at alt-ctrl-del.org wrote: But I don't see the point of adding more generic information in the response. Providing a URL of a website which explains (for the reject messages that you choose to document) what a sender needs to do to avoid being

Re: Change error messages returned by Postfix

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 04:09:04PM -0500, Wietse Venema wrote: Having implemented $name expansion, I find that it is easy produce long contact footer text, so I have added multi-line support. Unfortunately, multi-line footers can be harder to read. For example, Postfix will word-wrap

Re: Why use EGD instead of /dev/urandom in tls_random_source?

2011-01-04 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 10:42:09PM +, Ed W wrote: I have a couple now (I have several machines compiled with hardened pax and that depletes entropy extremely quickly) and they are very simple to install and extremely cheap. I believe they are even fast enough that you can buy fewer

Re: -o smtpd_banner very limited

2011-01-03 Thread Victor Duchovni
On Tue, Jan 04, 2011 at 07:14:34AM +0100, Ralf Hauser wrote: When I want to add a different banner with -o in master.cf for a secondary smtpd, this fails http://www.postfix.org/master.5.html ... -o name=value Override the named main.cf configuration

Re: Relay restrictions

2010-12-31 Thread Victor Duchovni
On Fri, Dec 31, 2010 at 12:24:13PM -0600, michael.lar...@wellsfargo.com wrote: Thanks again for trying to help, Viktor, but I'm unable to ascertain how your suggested configuration fulfills my goal. It appears to me that your config discards mail from all clients unless they're listed in the

Re: Relay restrictions

2010-12-31 Thread Victor Duchovni
On Fri, Dec 31, 2010 at 12:52:04PM -0600, michael.lar...@wellsfargo.com wrote: Thanks for your reply. How does this configuration determine if all mail from a client should be relayed, or only the mail allowed by the allowed-sender/allowed-recipient rules? There are some hosts I don't want

Re: 'include' contents of another file in mysql_*.cf (or other) maps?

2010-12-31 Thread Victor Duchovni
On Fri, Dec 31, 2010 at 03:03:03PM -0500, Charles Marcus wrote: On 2010-12-29 12:45 PM, Victor Duchovni wrote: On Wed, Dec 29, 2010 at 08:29:18AM -0500, Charles Marcus wrote: I was wondering if it is possible to 'include' the contents of a file in the mysql*.cf map files (although I guess

Re: Postfix and Postgrey Part II

2010-12-31 Thread Victor Duchovni
On Fri, Dec 31, 2010 at 05:13:24PM -0400, jason hirsh wrote: I get repeated 450 4.2.0 ja...@kasdivi.com: Recipient address rejected: Greylisted, This log entry is over-redacted. Show *all* log entries for this message being refused, IN FULL, including dates, client IPs, envelope sender

Re: Postfix and Postgrey Part II

2010-12-31 Thread Victor Duchovni
On Fri, Dec 31, 2010 at 05:38:17PM -0400, jason hirsh wrote: On Dec 31, 2010, at 5:23 PM, Victor Duchovni wrote: On Fri, Dec 31, 2010 at 05:13:24PM -0400, jason hirsh wrote: I get repeated 450 4.2.0 ja...@kasdivi.com: Recipient address rejected: Greylisted, This log entry is over

Re: Postfix and Postgrey Part II

2010-12-31 Thread Victor Duchovni
On Fri, Dec 31, 2010 at 06:26:41PM -0400, jason hirsh wrote: Where is the rest of this log entry, it too is truncated... Where are the other instances of this same client/sender/recipient triple being rejected? Dec 31 00:03:02 tuna postfix/smtpd[8857]: NOQUEUE: reject: RCPT from

Re: Postfix and Myvzw.com POP3 email

2010-12-30 Thread Victor Duchovni
On Thu, Dec 30, 2010 at 06:22:16AM -0500, Mark Khan wrote: 4. Downloaded the latest version (2.7.2) of postfix. In compiling v2.7.2, it is extremely important to pass the correct arguments to your compiler. I used the following commands for Solaris 10: # make makefiles

Re: Relay restrictions

2010-12-30 Thread Victor Duchovni
On Thu, Dec 30, 2010 at 09:15:30AM -0600, michael.lar...@wellsfargo.com wrote: With Noel's explanation I think I got it figured out, but before I try it I'd appreciate other brains validating what I've created as a sanity check. Here's what I have: snip from main.cf ###

Re: Relay restrictions

2010-12-30 Thread Victor Duchovni
On Thu, Dec 30, 2010 at 12:17:57PM -0600, michael.lar...@wellsfargo.com wrote: # See what addresses are allowed to relay as senders. # Check them against allowed recipients in recipient_access # under smtpd_restriction_classes. check_sender_access

Re: Relay restrictions

2010-12-30 Thread Victor Duchovni
On Thu, Dec 30, 2010 at 01:45:57PM -0600, michael.lar...@wellsfargo.com wrote: Thanks for trying to help Viktor, but I don't think this configuration will work for me. Let me try to explain; when I made my original post, others on the list were somewhat surprised regarding my intent. This

Re: with sasl authentication the username in sent twice

2010-12-30 Thread Victor Duchovni
On Thu, Dec 30, 2010 at 08:52:59PM +0100, Rob van Dam wrote: I want to relay my mail from a Trixbox (Centos 5.5) pbx to my password protected smtp server. The problem is that acces from the trixbox is always denied, because Postfix tries to login with username:username:password I installed

Re: Relay restrictions

2010-12-30 Thread Victor Duchovni
On Thu, Dec 30, 2010 at 02:09:57PM -0600, michael.lar...@wellsfargo.com wrote: Perhaps I misunderstood, but you said: With this all mail is discarded unless *all* (my emphasis) the conditions below are met: - From an allowed SMTP client (IP address CIDR table) - From an

Re: mail(mailutils) appending full host name instead of domain

2010-12-30 Thread Victor Duchovni
On Thu, Dec 30, 2010 at 03:09:07PM -0600, Steve Pribyl wrote: $ mail user blah Sends mail to the local host instead of the domain. What have I missed. http://www.postfix.org/BASIC_CONFIGURATION_README.html#myorigin http://www.postfix.org/MULTI_INSTANCE_README.html#quick --

Re: mail(mailutils) appending full host name instead of domain

2010-12-30 Thread Victor Duchovni
On Thu, Dec 30, 2010 at 11:00:17PM +0100, Jeroen Geilman wrote: On 12/30/10 10:09 PM, Steve Pribyl wrote: Afternoon, I am trying to setup a null or satellite client on debian system. Then you can install a null client, such as ssmtp or nullmailer. Much easier to configure than full-blown

Re: mail(mailutils) appending full host name instead of domain

2010-12-30 Thread Victor Duchovni
On Fri, Dec 31, 2010 at 12:55:31AM +0100, Jeroen Geilman wrote: Of course, I was referring more to the running an MTA that can also receive lots of spam when you don't actually want to receive anything bit. A Postfix null-client does not receive any external mail

Re: 'include' contents of another file in mysql_*.cf (or other) maps?

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 08:29:18AM -0500, Charles Marcus wrote: Hello, I was wondering if it is possible to 'include' the contents of a file in the mysql*.cf map files (although I guess if you can with these you can with others)... Use make(1) (and/or if you miss Sendmail's .mc files, m4)

Re: postscreen STARTTLS support

2010-12-29 Thread Victor Duchovni
On Tue, Dec 28, 2010 at 09:23:14PM -0500, Wietse Venema wrote: I have built an event-driven TLS proxy for postscreen(8). This addresses the problem that postscreen(8) could not be used when SMTP clients require STARTTLS support. [...] Next on the agenda is AUTH support, and that is a

Re: Spam filter not working with mailalias

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 08:26:08PM +0100, Philip Van Pelt wrote: Dennis Guhl schreef op wo 29-12-2010 om 20:14 [+0100]: [snip] It seems you have a condition in your sieve script which only matches t...@example.com but not al...@example.com. Well, I thought about that one too. But as

Re: postscreen STARTTLS support

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 02:45:39PM -0500, Wietse Venema wrote: So, unlike the TLS proxy, the AUTH proxy (as e.g. the Cyrus saslauthd service) may need to be a forking multi-process service. As long as the postscreen side is event-driven, some latency in AUTH support is not a problem. AUTH

Re: postscreen STARTTLS support

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 09:11:41PM +0100, Patrick Ben Koetter wrote: Perhaps we can encourage better hygiene, by not offering AUTH in postscreen. People who want AUTH and postscreen, can migrate their AUTH users to port 587? Or is this still too much to ask of potential Postfix users?

Re: extra headers via amavis

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 03:33:43PM -0500, Phil Howard wrote: As I understand header_checks, it removes only what is already in the message. The header_checks(5) code is implemented by cleanup(8) which processes the message passed to it by smtpd(8). The Received header that records the original

Re: postscreen STARTTLS support

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 09:46:25PM +0100, Patrick Ben Koetter wrote: The problem is very likely just ISP MUAs. Which ISPs still make money on emai users? It seems that Gmail and the other 800lb free-email gorillas have largely taken over the consumer email market. Is there in fact a

Re: postscreen STARTTLS support

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 10:08:15PM +0100, Patrick Ben Koetter wrote: In mobile networks, yes. And email usage is rising again, since mobile users found out the can cram more words in a mail than in a SMS. Do these providers combine the port 25 MX host with the port 25 MSA? So

Re: extra headers via amavis

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 04:29:51PM -0500, Phil Howard wrote: OK, sot it will apply to all headers after the instant one is added. Now the issue remains how to match the one just added and not others that existed before it ... even if those look exactly the same. They don't look *exactly* the

Re: extra headers via amavis

2010-12-29 Thread Victor Duchovni
On Wed, Dec 29, 2010 at 05:01:59PM -0500, Phil Howard wrote: Received: from localhost (localhost [127.0.0.1]) by my.mail.server (Postfix) with ESMTP id XX for u...@example.com; Wed, 29 Dec 2010 09:23:27 -0500 (EST) This is added locally, and is reasonably removed, if that's what

Re: Postfix queue in Mysql ?

2010-12-28 Thread Victor Duchovni
On Tue, Dec 28, 2010 at 08:28:48AM -0500, Joan Moreau wrote: the postfix queue manager (qmgr) is taking far too much resources What does too much resources mean? CPU? disk I/O? RAM? when the number of email pending is growing. Treat the disease not the symptoms, why is the deferred queue

Re: Milter for handling messages bound for non-TLS-capable hosts?

2010-12-28 Thread Victor Duchovni
On Tue, Dec 28, 2010 at 01:19:49AM -0800, email builder wrote: I might need to learn how to write a milter that tries to divert outgoing messages (so a smtp/client milter) that have been sent with smtp_tls_security_level = encrypt but failed because the destination server doesn't support

Re: Postfix queue in Mysql ?

2010-12-28 Thread Victor Duchovni
On Tue, Dec 28, 2010 at 12:19:23PM -0500, Joan Moreau wrote: Well, more clearly, my question is : How can I plug Mysql as a backend of postfix to handle the mailq ? It was clear enough before. The answer is that this is not possible. The queue is file-based by design. The queue design is

Re: Postfix and Myvzw.com POP3 email

2010-12-28 Thread Victor Duchovni
On Tue, Dec 28, 2010 at 06:51:23PM +0100, mouss wrote: I have never had a problem with cyrus-sasl configuration and usage. I am presently using cyrus-sasl with mysql and it works flawlessly. I have had problems in the past with Dovecot and authentication when Dovecot was updated. I

Re: Postfix queue in Mysql ?

2010-12-28 Thread Victor Duchovni
On Tue, Dec 28, 2010 at 04:29:34PM -0500, Joan Moreau wrote: I am just looking for a MySQL bakcend to replace the hard-disk storage of the postfix mailqueue. This is not a problem, this is something I am looking for. This is surely a means and not an end. What real purpose would storing the

Re: Why use EGD instead of /dev/urandom in tls_random_source?

2010-12-27 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 01:02:51AM -0500, micah wrote: Obviously it is well understood that the security of cryptographic software, such as TLS, depends on good random numbers. Postfix's tlsmgr(8) maintains a PRNG pool, which is fed from an external source, configured via tls_random_source,

Re: Postfix and Myvzw.com POP3 email

2010-12-27 Thread Victor Duchovni
On Mon, Dec 27, 2010 at 05:29:18PM -0500, Mark Khan wrote: My postfix server works with all other POP3 email providers (AOL, Meaasgelabs, etc) except Verizon?s myvzw.com which of course is what my new droid X uses. POP3 is configured with just login and password. No TLS. What does POP3 have

Re: header_checks

2010-12-27 Thread Victor Duchovni
On Mon, Dec 27, 2010 at 04:33:26PM -0600, Noel Jones wrote: master.cf -o header_checks=pcre:header_checks.pcre The file in question is unlikely to be in the current directory. This should be: -o header_checks=pcre:${config_directory}/header_checks.pcre -- Viktor.

Re: Postfix and Myvzw.com POP3 email

2010-12-27 Thread Victor Duchovni
On Mon, Dec 27, 2010 at 07:50:18PM -0500, Mark Khan wrote: Hi Victor: Here is a snoop snippet of a failed email. I am hoping you can you tell me how to configure postfix to ignore AUTH requests? Why should it ignore AUTH? Why not configure support for AUTH, especially from mobile handsets,

Re: postfix queue tuning

2010-12-24 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 11:38:19PM +0800, Yaoxing wrote: So I must scan the log for the list, isn't it? It works of course but is there any more specific way to do that? because scanning spends a lot of time, and you don't know where you stopped last time (or not easy to find out).

Re: Smart Host Configuration

2010-12-24 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 03:20:11PM -0600, Stan Hoeppner wrote: I neglected to mention the exchange server, source outbound server, is on internal edge of the dmz. Bah, you did mention the Exchange server and I just missed it. The 587 is more geared toward MUAs like Outlook and TBird.

Re: postfix queue tuning

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 07:03:45PM +0800, Yaoxing wrote: qshape active T 5 10 20 40 80 160 320 640 1280 1280+ TOTAL 1000 0 0 0 0 0 0 0 00 1000 gmail.com 254 0 0 0 0 0 0 0 00 254

Re: postfix queue tuning

2010-12-23 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 01:07:58AM +0800, Yaoxing wrote: I think the bandwidths is OK. I have a 100Mb ethernet but until now it's like15Mb/s according to iftop -i eth1 For the concurrency issue, what parameter would you suggest to change? I found some parameters from the documents but do

Re: Updating SSL cert

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 11:55:45AM -0500, Dave Filchak wrote: We had another person managing our mail server and during that time, he set up an SSL cert to manage secure connections. That cert is out of date and I have been trying to update the cert. I have run the normal openssl commands to

Re: postfix queue tuning

2010-12-23 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 01:17:48AM +0800, Yaoxing wrote: It's a newsletter group. because it's congesting so I stopped posting new mails. I think that's why all mails are from 1280+ min ago. No. This is wrong, the incoming queue contains fairly fresh mail. I use find active/ | wc -l which

Re: postfix queue tuning

2010-12-23 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 01:29:00AM +0800, Yaoxing wrote: Waste of time. Post NON-VERBOSE LOGGING by smtp(8) and qmgr(8). logfiles=/some/where egrep 'postfix/(qmgr|smtp)\[' $logfiles | tail -100 Dec 23 11:23:25 e postfix/qmgr[29972]: 3C15BFB9143: removed Dec 23 11:23:25 e

Re: postfix queue tuning

2010-12-23 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 01:37:48AM +0800, Yaoxing wrote: There's nothing in my hold queue. MailScanner do you mean amavis? I stopped that 10 hours ago. but it doesn't seem to make the situation better. You can't just stop the content filter, existing messages have the content_filter transport

Re: Updating SSL cert

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 12:43:44PM -0500, Dave Filchak wrote: Well ... OK then: sorry, I am not overly expert in managing the server and am learning as I go so please bear with me. Here is the output from postconf -n smtp_tls_note_starttls_offer = yes smtp_use_tls = yes smtpd_tls_CAfile

Re: postfix queue tuning

2010-12-23 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 01:51:13AM +0800, Yaoxing wrote: Dec 23 11:38:35 e postfix/qmgr[29972]: 6FC51297C081: from=n...@e.xxx.com, size=18380, nrcpt=1 (queue active) Some new mail is entering the active queue either from incoming or deferred queue. Do you really want the hostname

Re: DSN action code expanded with lmtp_assume_final=yes

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 02:39:23PM +0100, lst_ho...@kwsoft.de wrote: To summarize: DSN as of RFC 3461 is only recommended as internal status indicator for message relayed out of the own scope. End-to-end status is neither supported nor technically possible at the moment. This is a

Re: postfix queue tuning

2010-12-23 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 02:53:15AM +0800, Yaoxing wrote: My company is a ecommerce company which send newsletters to our subscribed clients weekly. we have nothing to do with spammers. Sufficiently poor list management and/or privacy policies are indistinguishable from spam. If you want to

Re: Multiple instances mode: Each instance per processor

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 08:58:31PM +0100, David Touzeau wrote: I have a server with 8 processors. I would like to create 8 postfix instances and each instance use a dedicated processor. Is it possible to do that ? Let your O/S do the scheduling. Locking down each instance of Postfix to a

Re: Trying to debug mesage relay

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 01:08:53PM -0700, Ray wrote: Dec 23 10:33:37 wserver postfix/smtp[16665]: 5B80F1B173C: to=postfix- us...@postfix.org, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=0.1/0/0.01/15, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=16134-09, from MTA([127.0.0.1]:10025): 250

Re: [SOLVED] how to keep multiple recipients to different domains in one message?

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 02:24:32PM +0100, Robert Linden wrote: Make that: content_filter=my_filter:dummy. Otherwise, each destination domain is a separate sub-queue. Yes, that was precisely what I had overlooked. I think it used to work differently, This has not changed since

Re: [SOLVED] how to keep multiple recipients to different domains in one message?

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 05:15:06PM -0500, Wietse Venema wrote: Yes, that was precisely what I had overlooked. I think it used to work differently, This has not changed since at least Postfix 1.0, the design of the queue manager is fundamentally based around transport:nexthop pairs.

Re: Multiple instances mode: Each instance per processor

2010-12-23 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 12:40:02AM +0100, David Touzeau wrote: Many thanks Stan But to be honest, you document is very hard to understand... for my skills cpusets are set to create cpu tasks environnements my problem is to ensure that all postfix tasks will go into the defined cpuset

Re: postfix queue tuning

2010-12-23 Thread Victor Duchovni
On Fri, Dec 24, 2010 at 09:11:19AM +0800, ? wrote: I cannot really understand based on what do u insist on I'm spamer? Ok I didn't obfusecate the clients email that's my fault. But why do u think I post only a few lines at first? Besides, I did not exit from the thread, removing

Re: Smart Host Configuration

2010-12-23 Thread Victor Duchovni
On Thu, Dec 23, 2010 at 11:01:44PM -0500, Roman Gelfand wrote: I am using postfix server as an smtp gateway to exchange server. I have configured a series of services and filters with postfix. One of antispam daemons is dspam, content filter. I have configured it to replace smtp server.

Re: Postfix and external content filter

2010-12-22 Thread Victor Duchovni
On Wed, Dec 22, 2010 at 10:28:01AM +, Stuart Bailey wrote: You may be able to use mail marshall as a postfix smtpd_proxy_filter, but that has performance implications you will need to investigate. http://www.postfix.org/SMTPD_PROXY_README.html Thanks Noel, I'll try this today.

Re: How to change - resend recipient in the bounce queue

2010-12-22 Thread Victor Duchovni
On Wed, Dec 22, 2010 at 02:41:04PM +0100, David Touzeau wrote: Dear Postfix Masters Some users have made mistake in the recipient email address. So the message turn into bounce queue that is normal. I would like to know : How to modify mails stored in the bounce queue to change the

Re: DSN action code expanded with lmtp_assume_final=yes

2010-12-22 Thread Victor Duchovni
On Wed, Dec 22, 2010 at 02:54:02PM +0100, lst_ho...@kwsoft.de wrote: This really means what it says: some alias was expanded *before* LMTP got involved (this includes virtual aliasing. local aliasing, and ~/.forward file expansion). Wietse Ok, this means i can't get a final DSN if

Re: DSN action code expanded with lmtp_assume_final=yes

2010-12-22 Thread Victor Duchovni
On Wed, Dec 22, 2010 at 09:35:59AM -0500, Wietse Venema wrote: 3 - Propagate ENVID, NOTIFY, RET, and ORCPT to one result from alias expansion only, and send no DSN. Postfix does this with one-to-one virtual aliases that translate one address into itself. The only thing I can

Re: DSN action code expanded with lmtp_assume_final=yes

2010-12-22 Thread Victor Duchovni
On Wed, Dec 22, 2010 at 05:06:03PM +0100, lst_ho...@kwsoft.de wrote: For a long time i also prayed if you don't get a error all is fine. Unfortunately this is more and more not the case. After repeatedly disapearing mail in some content filters it was decided to try some more modern

Re: how to keep multiple recipients to different domains in one message?

2010-12-22 Thread Victor Duchovni
On Wed, Dec 22, 2010 at 07:03:24PM +0100, Robert Linden wrote: Hello! Could someone please tell me if and how I can control the grouping of recipients in one delivery via pipe? If I have a content filter and I want it to receive each recipient in a seperate message I can have them split up

Re: Length of a Postfix QueueID

2010-12-22 Thread Victor Duchovni
On Wed, Dec 22, 2010 at 02:21:45PM -0500, Wietse Venema wrote: Ralf Hildebrandt: How long is a Postfix queueid? Sometimes I'm seeing 10 Hex-Characters, sometimes 11 (on different machines, though). The current implementation, subject to change, uses the inode number followed by the

Re: mycingular listed on xbl

2010-12-21 Thread Victor Duchovni
On Tue, Dec 21, 2010 at 12:37:24PM -0500, Randy Ramsdell wrote: It appears mycingular ( iphone ) ips are listed on spamhaus ( XBL and PBL ) for 8 days. I have reject at the smtpd level if found. So my users are complaining and I am stuck on the phone with ATT to get them to fix this. Which

Re: Postfix and external content filter

2010-12-21 Thread Victor Duchovni
On Tue, Dec 21, 2010 at 05:46:06PM +, Stuart Bailey wrote: Mail marshall is configured to send emails to port 10027. This works OK. However, if Mail Marshall detects SPAM, rather than modify the header and send it on, it responds directly with a 550 error code. Unfortunately, postfix

Re: mycingular listed on xbl

2010-12-21 Thread Victor Duchovni
On Tue, Dec 21, 2010 at 01:01:25PM -0500, Randy Ramsdell wrote: Yes, they should be listed. Why should they? They have mail servers too. I just don't get this. The individual phones sending directly to your MX host should be black-listed. The ISP's outbound SMTP servers should not. Which

Re: mycingular listed on xbl

2010-12-21 Thread Victor Duchovni
On Tue, Dec 21, 2010 at 01:07:03PM -0500, Randy Ramsdell wrote: Victor Duchovni wrote: On Tue, Dec 21, 2010 at 12:37:24PM -0500, Randy Ramsdell wrote: It appears mycingular ( iphone ) ips are listed on spamhaus ( XBL and PBL ) for 8 days. I have reject at the smtpd level if found. So my

Re: Trying to debug mesage relay

2010-12-21 Thread Victor Duchovni
On Tue, Dec 21, 2010 at 02:51:31PM -0700, Ray wrote: Hello, I'm having an issue with email just disappearing. I have been looking at the documentation and logs. I have made the logs more verbose. http://www.postfix.org/DEBUG_README.html#verbose Don't, this just drowns the problem in

Re: Sender Reputation

2010-12-21 Thread Victor Duchovni
On Tue, Dec 21, 2010 at 05:11:12PM -0500, Roman Gelfand wrote: Actually, I am using dspam for content filter. I was looking to add sender reputation query results to message header. As it turns out opendkim did the trick. Did you mean reputation or authentication? If the former, which

Re: automatic email reassembly at reception ?

2010-12-20 Thread Victor Duchovni
On Mon, Dec 20, 2010 at 01:11:16PM +0100, Frank Bonnet wrote: I'm searching for an automated solution that will split bigs emails in several parts ( as we do with mpack manually ) then reassemble them at reception. It would be transparent for the user that would receive only one big email.

Re: Transport maps with LDAP.

2010-12-20 Thread Victor Duchovni
implementation did not skip unknown SMTP client attributes, causing a syntax error when sending a PORT attribute. Reported by Victor Duchovni. File: smtp/smtp_proto.c. 20100526 Cleanup: a unit-test driver (for stand-alone tests) was not updated after

Re: qmgr killed by signal 15

2010-12-18 Thread Victor Duchovni
On Sat, Dec 18, 2010 at 06:17:08PM -0600, Jeff Morris wrote: postfix/master[20377]: warning: process /usr/libexec/postfix/qmgr pid 20380 killed by signal 15 This is SIGTERM. Are you running postfix stop frequently? I've done some troubleshooting and can't figure out why qmgr is being

Re: PATCH: using yahoo smtp with several accounts

2010-12-17 Thread Victor Duchovni
On Fri, Dec 17, 2010 at 07:24:24AM -0500, Jerry wrote: On Thu, 16 Dec 2010 17:07:33 -0500 (EST) Wietse Venema wie...@porcupine.org articulated: This is a mis-diagnosis. The variable in question is a boolean type, and there is no way that Postfix can resuse an SMTP connection while

Re: Character in Email address

2010-12-17 Thread Victor Duchovni
On Fri, Dec 17, 2010 at 02:44:35PM +0200, K bharathan wrote: can i use '' character in the local part of the email address ? Yes, but don't, such an address will run in a variety of interoperability issues. -- Viktor.

Re: implement MDN for incoming messages

2010-12-17 Thread Victor Duchovni
On Fri, Dec 17, 2010 at 04:47:41PM -0500, Zhou, Yan wrote: Hi there, I am using a script to process each incoming message into Postfix. In master.cf, I have something like this. The python script calls another Java program do the heavy-lifting message processing. connector unix

Re: implement MDN for incoming messages

2010-12-17 Thread Victor Duchovni
On Fri, Dec 17, 2010 at 05:28:27PM -0500, Wietse Venema wrote: And whatever you send back, NEVER NEVER NEVER USE the address in the FROM and TO message header. Instead, use the envelope sender, which are supplied with the pipe(8) ${sender} and ${recipient} macros. Again, if you respond to the

Re: How can content filter tell if upstream client authenticated?

2010-12-16 Thread Victor Duchovni
On Thu, Dec 16, 2010 at 10:16:08AM -0800, Jack Bates wrote: How can a Postfix content filter tell whether the upstream client authenticated or not? If the top-most Received header matches with (SMTP|ESMTPS?A?), the ESMTPSA and ESMTPA cases correspond to an authenticated client, with or without

Re: using yahoo smtp with several accounts

2010-12-16 Thread Victor Duchovni
On Wed, Dec 15, 2010 at 02:42:00PM +, Roger Dura?ona Vargas wrote: I have set up sasl and a saslpass file with the first account: smtp.correo.yahoo.es u...@yahoo.es:pass This is wrong. The lookup key needs to be the sender address, and you need to enable sender-specific SASL lookups, see

Re: call scripts for each of the incoming emails

2010-12-15 Thread Victor Duchovni
On Wed, Dec 15, 2010 at 05:36:19PM +1100, James Gray wrote: At the risk of being blacklisted on this rather robust forum, when I've needed a DB backend for mail I've invariably ended up with a product designed for that purpose. The idea of piping or scripting may seem desirable at first, but

Re: call scripts for each of the incoming emails

2010-12-15 Thread Victor Duchovni
On Wed, Dec 15, 2010 at 10:51:13AM -0500, Wietse Venema wrote: Spacelee: hi everything, I met a problem recently because we need to add a new function to our product. the problem is for each valid incoming email, we need to call a script to insert it to different databases, someone said

Re: Compile error

2010-12-15 Thread Victor Duchovni
On Wed, Dec 15, 2010 at 03:11:26PM -0300, M. Rodrigo Monteiro wrote: The make command: make -f Makefile.init makefiles \ 'CCARGS=-DHAS_MYSQL -I/usr/include/mysql -DHAS_PCRE -I/usr/include No need for -I/usr/include, this is always included. -DHAS_DB -I/usr/include/db4 -DUSE_TLS

Re: Load issues with Postfix on FreeBSD

2010-12-15 Thread Victor Duchovni
On Wed, Dec 15, 2010 at 01:37:48PM -0500, Dave Brodin wrote: I ran the following command: time /usr/local/bin/smtp-source -s 10 -l 10120 -m 500 -c \ -f t...@bluemarble.net -t dbro...@bluemarble.net localhost:25 OK, this is smtp-source with 10 (modest) parallel sessions, 10KB (modest)

Re: Compile error

2010-12-15 Thread Victor Duchovni
On Wed, Dec 15, 2010 at 03:41:18PM -0300, M. Rodrigo Monteiro wrote: With the makefile below, Postfix compile without even warning errors. make -f Makefile.init makefiles \ 'CCARGS=-DHAS_MYSQL -I/usr/include/mysql -DHAS_PCRE -DUSE_TLS -DUSE_SASL_AUTH -DDEF_SERVER_SASL_TYPE=\dovecot\' \

Re: postscreen request: pcre support

2010-12-15 Thread Victor Duchovni
On Thu, Dec 16, 2010 at 12:38:46AM +0100, Jeroen Koekkoek wrote: I've read through the postscreen code and got a general understanding of how it works internally. But judging from the documentation: is postscreen intended to ever do more than allowing/disallowing client connections? e.g.

Re: Append orig_to messages subject

2010-12-15 Thread Victor Duchovni
On Wed, Dec 15, 2010 at 01:28:17PM -0800, selcukyazar wrote: Hi again, my .forward manupulation works. | sed -e 's/Subject:/Subject:FW: /g' -e '/'Received:\.\*'/{N;d}'| /usr/sbin/sendmail -i mail_ad...@hotmail.com This creates bounce loops. DO NOT ignore the envelope sender when

Re: line 615: missing '=' after attribute name: 3

2010-12-15 Thread Victor Duchovni
On Wed, Dec 15, 2010 at 09:35:01PM -0600, Noel Jones wrote: Line 615 is the middle line above -- '# This is the Send...' The error is complaining about a line that starts with 3 and the next character is not =. Postfix parameter setting are multi-line with folding on white-space abc =

Re: selective behaviour for reject_sender_login_mismatch ?

2010-12-14 Thread Victor Duchovni
On Tue, Dec 14, 2010 at 07:10:01AM -0500, Wietse Venema wrote: but I can't find an access table that is indexed by sasl userid. Is there a way to do this without a policy server? It would take very little code to add a check_sasluser_access feature (this would do only exact match -

Re: selective behaviour for reject_sender_login_mismatch ?

2010-12-14 Thread Victor Duchovni
On Tue, Dec 14, 2010 at 02:01:31PM +0100, Per Jessen wrote: The problem is that the SASL user name may well contain white-space, and postmap(1) cannot create indexed tables with keys that contain white-space. You could create the tables with other tools, but then you can't update the

<    1   2   3   4   5   6   7   8   9   10   >