Re: Connect failed to database

2015-03-01 Thread Steffen Kaiser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Mon, 2 Mar 2015, Oliver Welter wrote: Am 02.03.2015 um 06:03 schrieb Dan LaSota: I have dovecot version 2.2.10 dovecot -n output below I am seeing connection errors being written to my dovecot error log: Mar 1 19:51:15 mail dovecot: auth-worker

Re: Require certificate for external clients

2015-03-01 Thread Steffen Kaiser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Fri, 27 Feb 2015, Karol Babioch wrote: I'm currently looking into ways of making use of client certificates. I want to force external clients (i.e. anything outside the local subnet) to use client certificates. It is my understanding that this in

Re: Connect failed to database

2015-03-01 Thread Oliver Welter
Am 02.03.2015 um 06:03 schrieb Dan LaSota: I have dovecot version 2.2.10 dovecot -n output below I am seeing connection errors being written to my dovecot error log: Mar 1 19:51:15 mail dovecot: auth-worker(2224): Error: mysql(localhost): Connect failed to database (servermail): Access denied

Re: IP drop list

2015-03-01 Thread Oliver Welter
Am 01.03.2015 um 23:16 schrieb Dave McGuire: On 03/01/2015 04:25 AM, Reindl Harald wrote: I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped? I have accumulated 45,000+ IPs which routinely try dictionary and 12345678 password atte

Re: userdb passwd-file default_fields uid not expanding %variable

2015-03-01 Thread Steffen Kaiser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Fri, 27 Feb 2015, Tim Jones wrote: userdb { args = username_format=%n /home/%d/mail_users default_fields = uid=%d gid=%d home=/home/%d/mail/%n mail=maildir:/home/%d/mail/%n driver = passwd-file } Every time I try to authenticate via imap, I g

Connect failed to database

2015-03-01 Thread Dan LaSota
I have dovecot version 2.2.10 dovecot -n output below I am seeing connection errors being written to my dovecot error log: Mar 1 19:51:15 mail dovecot: auth-worker(2224): Error: mysql(localhost): Connect failed to database (servermail): Access denied for user 'usermail'@'localhost' (using passw

Re: Require certificate for external clients

2015-03-01 Thread Joseph Tam
Karol Babioch writes: You can share libraries, binaries, log files, but use separate configuration files, specifying different ports/addresses/ssl-configs/auth/access parameters. Then you can fire them both up dovecot -c /dovecot/etc/dovecot-1.conf dovecot -c /dovecot/etc/dovecot-2.co

Re: IP drop list

2015-03-01 Thread Benny Pedersen
The other side of this equation, Postfix, has had this capability for years. Why it hasn't been added to dovecot is a mystery. It's the only thing (really, the ONLY thing!) that I dislike about dovecot. http://wiki2.dovecot.org/PasswordDatabase/ExtraFields/AllowNets then setup fail2ban to

Re: IP drop list

2015-03-01 Thread Reindl Harald
Am 02.03.2015 um 00:08 schrieb Benny Pedersen: On March 1, 2015 10:26:40 AM Reindl Harald wrote: i guess for a C-programmer it takes not much more than 10 minutens include a config option to list rbl servers and close connections absed on the DNS responses close pop3, set imap to listen on

Re: IP drop list

2015-03-01 Thread Benny Pedersen
On March 1, 2015 10:26:40 AM Reindl Harald wrote: i guess for a C-programmer it takes not much more than 10 minutens include a config option to list rbl servers and close connections absed on the DNS responses close pop3, set imap to listen only in lo interface, setup webmail with smtp auth,

dsync panic

2015-03-01 Thread Greg Rivers
As per , I'm running the following command on a local dovecot server to replicate email for a single user from a remote IMAP server: doveadm -D \ -o imapc_host=remote.imap.server \ -o imapc_user=gcr \ -o imapc_password= \

Re: IP drop list

2015-03-01 Thread Reindl Harald
Am 01.03.2015 um 23:16 schrieb Dave McGuire: On 03/01/2015 04:25 AM, Reindl Harald wrote: I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped? I have accumulated 45,000+ IPs which routinely try dictionary and 12345678 password att

Re: IP drop list

2015-03-01 Thread Dave McGuire
On 03/01/2015 04:25 AM, Reindl Harald wrote: >> I wonder if there is an easy way to provide dovecot a flat text >> file of ipv4 #'s which should be ignored or dropped? >> >> I have accumulated 45,000+ IPs which routinely try dictionary >> and 12345678 password attempts. The file is too big to crea

full text index "per user"?

2015-03-01 Thread Ralf Hildebrandt
Is there any way of disabling the creation of a full text index on a per user basis? -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 Vorstand: Patrick Ben Koetter, Marc Schiffbauer Aufsichts

Re: IP drop list

2015-03-01 Thread Marc Stuermer
Am 01.03.2015 um 08:53 schrieb Jim Pazarena: > I have accumulated 45,000+ IPs which routinely try dictionary and > 12345678 password attempts. The file is too big to create firewall > drops, and I don't want to compile with wrappers *if* dovecot has an Have you ever tried using IP sets on Linux?

Re: Require certificate for external clients

2015-03-01 Thread Karol Babioch
Hi, Am 28.02.2015 um 00:28 schrieb Joseph Tam: > That should be qualified as "Is it possible to have Dovecot imap/pop > daemons listening on multiple ports for a single running instance." Yes, exactly. > You can share libraries, binaries, > log files, but use separate configuration files, specif

Re: IP drop list

2015-03-01 Thread Reindl Harald
Am 01.03.2015 um 08:53 schrieb Jim Pazarena: I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped? I have accumulated 45,000+ IPs which routinely try dictionary and 12345678 password attempts. The file is too big to create firewall

Re: IP drop list

2015-03-01 Thread Hardy Flor
fail2ban blocked dynamically addresses for a period of time. It has a module for dovecot. I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped? I have accumulated 45,000+ IPs which routinely try dictionary and 12345678 password a