Re: Re: How to configure Dovecot to disable NIST's curves and still rertain EECDH?

2018-12-18 Thread Tributh via dovecot
Am 19.12.18 um 07:10 schrieb Kurt Fitzner: > My opinion is that security by RFC is not security, it's mommy > medicine.  Standards have had a terrible time keeping up with security > realities. > > NITS's curves leak side channel information all over the place.  I don't > have details on what i

Re: How to configure Dovecot to disable NIST's curves and still rertain EECDH?

2018-12-18 Thread Kurt Fitzner
My opinion is that security by RFC is not security, it's mommy medicine. Standards have had a terrible time keeping up with security realities. NITS's curves leak side channel information all over the place. I don't have details on what implementations are set to calculate the NIST curves in co

Re: How to configure Dovecot to disable NIST's curves and still rertain EECDH?

2018-12-18 Thread Tributh via dovecot
Am 19.12.18 um 04:39 schrieb Kurt Fitzner: > I am interested in configuring Dovecot's TLS so as to retain forward > secrecy, but eliminate all of NIST's elliptic curves. > > Besides being subject to side channel attacks > , in some quarters there is a

Re: High Load average on NFS Spool - v.2.1.15 & 2.2.13

2018-12-18 Thread Nick Edwards
dont play net cop here but since you want to try force your opinion down others throats heres one for you, if you want to try dictate to someone to bottom post to suite you how about you use proper net etiquette yourself and TRIM your posts On 12/19/18, admin wrote: > Am Dienstag, den 18.12.2018

How to configure Dovecot to disable NIST's curves and still rertain EECDH?

2018-12-18 Thread Kurt Fitzner
I am interested in configuring Dovecot's TLS so as to retain forward secrecy, but eliminate all of NIST's elliptic curves. Besides being subject to side channel attacks [1], in some quarters there is a general distrust of NIST's curves and any of their other cryptographic primitives after the Dua

Re: Apple mail fails with Submission

2018-12-18 Thread Adi Pircalabu via dovecot
On 2018-12-19 03:17, Ruud Voorjans wrote: Postfix debug peer logging Dec 18 17:08:11 mail postfix/submission/smtpd[10626]: > server.example.org [4][XX.XX.XX.XX]: 250 2.1.5 Ok Dec 18 17:08:11 mail postfix/submission/smtpd[10626]: watchdog_pat: 0x55ef4ec020180 Dec 18 17:08:11 mail postfix/submissi

Re: High Load average on NFS Spool - v.2.1.15 & 2.2.13

2018-12-18 Thread admin
Am Dienstag, den 18.12.2018, 14:26 -0500 schrieb Albert E. Whale, CEH CHS CISA CISSP: > I have, but I will be happy to review it once again. > > > On 12/18/18 2:14 PM, admin wrote: > > > > > > > Am Dienstag, den 18.12.2018, 14:06 -0500 schrieb Albert E. > >

Re: High Load average on NFS Spool - v.2.1.15 & 2.2.13

2018-12-18 Thread Albert E. Whale, CEH CHS CISA CISSP
I have, but I will be happy to review it once again. On 12/18/18 2:14 PM, admin wrote: Am Dienstag, den 18.12.2018, 14:06 -0500 schrieb Albert E. Whale, CEH CHS CISA CISSP: I have two servers pointing to an NFS mounted mail spool with dovecot.  Since I recently switched from using Dovecot v1.

Re: High Load average on NFS Spool - v.2.1.15 & 2.2.13

2018-12-18 Thread admin
Am Dienstag, den 18.12.2018, 14:06 -0500 schrieb Albert E. Whale, CEH CHS CISA CISSP: > I have two servers pointing to an NFS mounted mail spool with > dovecot. Since I recently switched from using Dovecot v1.X, I > have been experiencing high CPU use with the two Dovecot > servers

High Load average on NFS Spool - v.2.1.15 & 2.2.13

2018-12-18 Thread Albert E. Whale, CEH CHS CISA CISSP
I have two servers pointing to an NFS mounted mail spool with dovecot.  Since I recently switched from using Dovecot v1.X, I have been experiencing high CPU use with the two Dovecot servers. I am not certain why they are not well behaved.  Here is the configuration information. This configura

Re: Apple mail fails with Submission

2018-12-18 Thread Ruud Voorjans
Postfix debug peer logging Dec 18 17:08:11 mail postfix/submission/smtpd[10626]: > server.example.org[XX.XX.XX.XX]: 250 2.1.5 Ok Dec 18 17:08:11 mail postfix/submission/smtpd[10626]: watchdog_pat: 0x55ef4ec020180 Dec 18 17:08:11 mail postfix/submission/smtpd[10626]: vstream_fflush_some: fd 10 flus

Re: Apple mail fails with Submission

2018-12-18 Thread Ruud Voorjans
doveconf -n output: # 2.3.2.1 (0719df592): /etc/dovecot/dovecot.conf # Pigeonhole version 0.5.2 () # OS: Linux 4.18.0-12-generic x86_64 Ubuntu 18.10 # Hostname: mail.example.org auth_debug = yes auth_debug_passwords = yes auth_mechanisms = plain login auth_verbose = yes director_mail_servers = XX.X

Errors with missing links to files when using Single Instance Storage and zlib (Dovecot 2.3.4)

2018-12-18 Thread Daniel Schütze
I'm running Dovecot 2.3.4 with Single Instance Storage (SIS) and zlib and I am frequently seeing errors where files are missing in the attachments directory even though the zipped file in the hash directory is actually there.  This appears not to have been an issue in Dovecot 2.3.1 Requested ou

Re: Apple mail fails with Submission

2018-12-18 Thread Paul Hecker via dovecot
Hi, did you see this thread? https://dovecot.org/list/dovecot/2018-October/113348.html Had a similar issue with CHUNKING and Apple Mail, but could reproduce it with a Perl script, too. But I do not whether this was fixed already in v2

Change default mode for attachment files

2018-12-18 Thread Олег Кривоносов
Hi I migrated my dovecot server from Maildir to mdbox with saving attachments to external files and enabled SIS a few days ago. Everything works fine except one issue. I have both virtual and system users. Dovecot saves attachments with mode 0600. So I catch such errors for system users: dovecot: