Re: How to change the sender of an e-mail ?

2016-10-07 Thread msd+postfix-users

r...@gmx.co.uk:
> It sounds like you might want VERP, did you review this one:
> http://www.postfix.org/VERP_README.html
> ?

Yes, I have already read this. But I really need the recipient address 
and the sasl_username (to identify my user when I get the bounce) and, 
except if I'm wrong, I can't do this with postfix VERP.


For now, I'm looking at "MILTER" (on the advice of Wietse) or 
"SMTPD_PROXY" (which seems easier to implement for me).


Thanks,


Msd


Re: can't reload the configuration

2016-10-07 Thread Postfix User
On Thu, 6 Oct 2016 22:33:11 +0200, Geert Stappers stated:

>On Thu, Oct 06, 2016 at 09:53:10PM +0200, Gary Luck wrote:
>> Wietse Venema schrieb:  
>> >Gary Luck:
>> >[ Charset ISO-8859-15 converted... ]  
>> >> Hello,
>> >>I made some changes in the file /etc/postfix/recipient_access
>> >>and would like to tell postfix to use the new configuration.  
>> >
>> >Perhaps you should "postmap /etc/postfix/recipient_access".
>> >  
>> 
>> Hurray!! It finally works!
>> 
>> Thank you very much.
>> 
>> Do I have to run this command after every change of the
>> "recipient_access"-file?  
>
> man postmap
>
>
>> I didn't have to in the past.  
>
>Seems unlikely.

If you have several tables, it might be more convenient to create a
"Makefile" to handle the chore. There is an example on the
http://www.postfix.com/DATABASE_README.html page; "Updating Berkeley DB
files safely". It has certainly saved me a lot of work.

-- 
Jerry




Re: warning: network_biopair_interop

2016-10-07 Thread geekster
I have updated Postfix and this is what im getting:

Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: connect from
mail-qk0-f179.google.com[209.85.220.179]
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: smtp_stream_setup:
maxtime=300 enable_deadline=0
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_hostname:
smtpd_client_event_limit_exceptions: mail-qk0-f179.google.com ~? 127.0.0.0/8
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_hostaddr:
smtpd_client_event_limit_exceptions: 209.85.220.179 ~? 127.0.0.0/8
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_hostname:
smtpd_client_event_limit_exceptions: mail-qk0-f179.google.com ~?
[:::127.0.0.0]/104
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_hostaddr:
smtpd_client_event_limit_exceptions: 209.85.220.179 ~?
[:::127.0.0.0]/104
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_hostname:
smtpd_client_event_limit_exceptions: mail-qk0-f179.google.com ~? [::1]/128
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_hostaddr:
smtpd_client_event_limit_exceptions: 209.85.220.179 ~? [::1]/128
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_list_match:
mail-qk0-f179.google.com: no match
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_list_match:
209.85.220.179: no match
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: send attr request = connect
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: send attr ident =
smtp:209.85.220.179
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: vstream_fflush_some: fd 24
flush 43
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: vstream_buf_get_ready: fd 24
got 25
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: private/anvil: wanted
attribute: status
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: input attribute name: status
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: input attribute value: 0
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: private/anvil: wanted
attribute: count
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: input attribute name: count
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: input attribute value: 1
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: private/anvil: wanted
attribute: rate
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: input attribute name: rate
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: input attribute value: 1
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: private/anvil: wanted
attribute: (list terminator)
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: input attribute name: (end)
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 220 mail.onssi.com ESMTP Postfix
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: xsasl_cyrus_server_create:
SASL service=smtp, realm=(null)
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: name_mask: noanonymous
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: watchdog_pat: 0x7f92a9c80630
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: vstream_fflush_some: fd 9
flush 34
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: vstream_buf_get_ready: fd 9
got 31
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: <
mail-qk0-f179.google.com[209.85.220.179]: EHLO mail-qk0-f179.google.com
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_list_match:
mail-qk0-f179.google.com: no match
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: match_list_match:
209.85.220.179: no match
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-NY-STARFOX.onssi.local
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-PIPELINING
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-SIZE 2500
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-ETRN
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-STARTTLS
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-AUTH CRAM-MD5 PLAIN DIGEST-MD5
LOGIN
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-AUTH=CRAM-MD5 PLAIN DIGEST-MD5
LOGIN
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-ENHANCEDSTATUSCODES
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250-8BITMIME
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 250 DSN
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: watchdog_pat: 0x7f92a9c80630
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: vstream_fflush_some: fd 9
flush 219
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: vstream_buf_get_ready: fd 9
got 10
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: <
mail-qk0-f179.google.com[209.85.220.179]: STARTTLS
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
mail-qk0-f179.google.com[209.85.220.179]: 220 2.0.0 Ready to start TLS
Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: vstre

Re: warning: network_biopair_interop

2016-10-07 Thread Wietse Venema
geekster:
> I have updated Postfix and this is what im getting:

> Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
> mail-qk0-f179.google.com[209.85.220.179]: 220 2.0.0 Ready to start TLS
...
> Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: Anonymous TLS connection
> established from mail-qk0-f179.google.com[209.85.220.179]: TLSv1.2 with
> cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)
> Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: xsasl_cyrus_server_create:
> SASL service=smtp, realm=(null)
> Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: name_mask: noanonymous
> Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: watchdog_pat: 0x7f92a9c80630
> Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: smtp_get: EOF

Did you build Postfix, OpenSSL, etc., by hand? If so, what versions?

Wietse


Re: warning: network_biopair_interop

2016-10-07 Thread geekster
No. I didnt build it by hand. I use EFA-Project and I updated to the latest
version which updates to postfix 3.0.4

[root@NY-STARFOX MailScanner]# openssl version
OpenSSL 1.0.1e-fips 11 Feb 2013
[root@NY-STARFOX MailScanner]# postconf -d |grep version
disable_mime_output_conversion = no
mail_version = 3.0.4
milter_helo_macros = {tls_version} {cipher} {cipher_bits} {cert_subject}
{cert_issuer}
milter_macro_v = $mail_name $mail_version
[root@NY-STARFOX MailScanner]# sudo /usr/local/sbin/EFA-Update -check
[EFA] Getting latest version number from http://dl.efa-project.org
[EFA] You are already running version EFA-3.0.1.5, no update needed


[root@NY-STARFOX MailScanner]# openssl version
OpenSSL 1.0.1e-fips 11 Feb 2013
[root@NY-STARFOX MailScanner]# postconf -d |grep version
disable_mime_output_conversion = no
mail_version = 3.0.4
milter_helo_macros = {tls_version} {cipher} {cipher_bits} {cert_subject}
{cert_issuer}
milter_macro_v = $mail_name $mail_version
[root@NY-STARFOX MailScanner]#


On Fri, Oct 7, 2016 at 11:16 AM, Wietse Venema [via Postfix] <
ml-node+s1071664n86638...@n5.nabble.com> wrote:

> geekster:
> > I have updated Postfix and this is what im getting:
>
> > Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: >
> > mail-qk0-f179.google.com[209.85.220.179]: 220 2.0.0 Ready to start TLS
> ...
> > Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: Anonymous TLS connection
> > established from mail-qk0-f179.google.com[209.85.220.179]: TLSv1.2 with
> > cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)
> > Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]:
> xsasl_cyrus_server_create:
> > SASL service=smtp, realm=(null)
> > Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: name_mask: noanonymous
> > Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: watchdog_pat:
> 0x7f92a9c80630
> > Oct  6 16:41:59 NY-STARFOX postfix/smtpd[7971]: smtp_get: EOF
>
> Did you build Postfix, OpenSSL, etc., by hand? If so, what versions?
>
> Wietse
>
>
> --
> If you reply to this email, your message will be added to the discussion
> below:
> http://postfix.1071664.n5.nabble.com/warning-network-
> biopair-interop-tp86484p86638.html
> To unsubscribe from warning: network_biopair_interop, click here
> 
> .
> NAML
> 
>




--
View this message in context: 
http://postfix.1071664.n5.nabble.com/warning-network-biopair-interop-tp86484p86639.html
Sent from the Postfix Users mailing list archive at Nabble.com.


Re: warning: network_biopair_interop

2016-10-07 Thread Wietse Venema
OK. Turn OFF -v logging, and turn on TLS logging:

postconf 'smtpd_tls_loglevel = 1' 
postfix reload

Wietse


Re: warning: network_biopair_interop

2016-10-07 Thread geekster
Hi Wietse,

loglevel was already set to 1. I turned off the additional logging. Then i
sent a test email from my gmail account to myself and I got this in the log:

Oct  7 13:43:46 NY-STARFOX postfix/smtpd[30901]: connect from
mail-qk0-f182.google.com[209.85.220.182]
Oct  7 13:43:46 NY-STARFOX postfix/smtpd[30901]: lost connection after
CONNECT from mail-qk0-f182.google.com[209.85.220.182]
Oct  7 13:43:46 NY-STARFOX postfix/smtpd[30901]: disconnect from
mail-qk0-f182.google.com[209.85.220.182] commands=0/0

Should i set TLS loglevel to 2?



On Fri, Oct 7, 2016 at 1:34 PM, Wietse Venema [via Postfix] <
ml-node+s1071664n86640...@n5.nabble.com> wrote:

> OK. Turn OFF -v logging, and turn on TLS logging:
>
> postconf 'smtpd_tls_loglevel = 1'
> postfix reload
>
> Wietse
>
>
> --
> If you reply to this email, your message will be added to the discussion
> below:
> http://postfix.1071664.n5.nabble.com/warning-network-
> biopair-interop-tp86484p86640.html
> To unsubscribe from warning: network_biopair_interop, click here
> 
> .
> NAML
> 
>




--
View this message in context: 
http://postfix.1071664.n5.nabble.com/warning-network-biopair-interop-tp86484p86641.html
Sent from the Postfix Users mailing list archive at Nabble.com.


Re: warning: network_biopair_interop

2016-10-07 Thread Viktor Dukhovni
On Fri, Oct 07, 2016 at 10:45:46AM -0700, geekster wrote:

> Hi Wietse,
> 
> loglevel was already set to 1. I turned off the additional logging. Then i
> sent a test email from my gmail account to myself and I got this in the log:

Did you also receive the email via some separate connection?
If not, is Google retrying the delivery?

> Oct  7 13:43:46 NY-STARFOX postfix/smtpd[30901]: connect from
> mail-qk0-f182.google.com[209.85.220.182]
> Oct  7 13:43:46 NY-STARFOX postfix/smtpd[30901]: lost connection after
> CONNECT from mail-qk0-f182.google.com[209.85.220.182]
> Oct  7 13:43:46 NY-STARFOX postfix/smtpd[30901]: disconnect from
> mail-qk0-f182.google.com[209.85.220.182] commands=0/0
> 
> Should i set TLS loglevel to 2?

No, there was no attempted use of TLS in the session above.  The
connection dropped even before/as your server accepted it.

Your problem (if there is one, and Google is not just setting up
idle connections) is likely at the network layer, and what's needed
is a PCAP file containing a complete (single) session recording of
a failed connection from Google, not more logs.

You might however turn on client source port logging, to make it
easier to pull out the right session from a multi-session tcpdump.

smtpd_client_port_logging = yes

-- 
Viktor.