Re: Authentication per Service

2020-01-18 Thread Oliver Welter
Hi Aki Am 18.01.20 um 14:58 schrieb Aki Tuomi: > You can also use %s to expand into service name. See > https://doc.dovecot.org/configuration_manual/config_file/config_variables/ > Thanks - this was exactly the informatio

Authentication per Service

2020-01-18 Thread Oliver Welter
Hi All, I use dovecot (v2.3.4) with a SQL backend for user authentication, passwords are stored in CRAMMD5 format. My SMTP server uses "doveadm auth" via auth-socket to perform sender authentification. To shut down SMTP access for hacked passwords I want to have a dedicated flag in the user datab

Re: IP drop list

2015-03-04 Thread Oliver Welter
Am 04.03.2015 um 21:45 schrieb Dave McGuire: On 03/04/2015 03:37 PM, Oliver Welter wrote: I would like to reiterate Reindl Harald's point above, since subsequent discussion has gotten away from it. If Dovecot had DNS RBL support similar to Postfix, I think quite a few people would use it

Re: IP drop list

2015-03-04 Thread Oliver Welter
Am 04.03.2015 um 21:03 schrieb Dave McGuire: On 03/04/2015 02:12 PM, Michael Orlitzky wrote: I would like to reiterate Reindl Harald's point above, since subsequent discussion has gotten away from it. If Dovecot had DNS RBL support similar to Postfix, I think quite a few people would use it, and

Re: IP drop list

2015-03-03 Thread Oliver Welter
Am 03.03.2015 um 12:40 schrieb Dave McGuire: On 03/02/2015 09:41 PM, Joseph Tam wrote: then setup fail2ban to manage extrafields Now that's a very interesting idea, thank you! I will investigate this. If you don't expect yor firewall to handle 45K+ IPs, I'm not how you expect dovecot will

Re: Connect failed to database

2015-03-02 Thread Oliver Welter
Am 02.03.2015 um 19:30 schrieb Dan LaSota: Just some quick ideas * check if the mysql socket file has rw permissions for the dovecot user # ls -l /var/lib/mysql/mysql.sock srwxrwxrwx. 1 mysql mysql 0 Mar 1 19:33 /var/lib/mysql/mysql.sock * Try to run the mysql query as user dovecot (su dove

Re: Connect failed to database

2015-03-01 Thread Oliver Welter
Am 02.03.2015 um 06:03 schrieb Dan LaSota: I have dovecot version 2.2.10 dovecot -n output below I am seeing connection errors being written to my dovecot error log: Mar 1 19:51:15 mail dovecot: auth-worker(2224): Error: mysql(localhost): Connect failed to database (servermail): Access denied

Re: IP drop list

2015-03-01 Thread Oliver Welter
Am 01.03.2015 um 23:16 schrieb Dave McGuire: On 03/01/2015 04:25 AM, Reindl Harald wrote: I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped? I have accumulated 45,000+ IPs which routinely try dictionary and 12345678 password atte

Re: TLS config check

2015-02-07 Thread Oliver Welter
Am 07.02.2015 um 10:10 schrieb SW: > I've just done a test with K9 mail on Android 4.4.2 and this is what I > see in the log: > > ECDHE-ECDSA-AES128-SHA (128/128 bits) > > But when using Thunderbird I see: > > ECDHE-ECDSA-AES128-GCM-SHA256 (128/128 bits) > > I'm happy that Thunderbird is using

Re: TLS config check

2015-02-07 Thread Oliver Welter
Am 07.02.2015 um 04:47 schrieb Reindl Harald: > > Am 06.02.2015 um 23:13 schrieb SW: >> According to https://cipherli.st/ >>> ssl = yes >>> ssl_cert = >> ssl_key = >> ssl_protocols = !SSLv2 !SSLv3 >>> ssl_cipher_list = AES128+EECDH:AES128+EDH >>> ssl_prefer_server_ciphers = yes # >Dovecot 2.2.6

Re: Corruption of index files

2015-02-03 Thread Oliver Welter
Am 25.01.2015 um 12:45 schrieb Oliver Welter: > Hi Andreas, > > Am 25.01.2015 um 12:41 schrieb Andreas Schulze: >> Oliver Welter: >>>> after upgrading my mail server (dovecot 1.1.7 -> 2.2.13) I get tons of >>>> messages about corrupted index files in the

Re: Corruption of index files

2015-01-25 Thread Oliver Welter
Hi Andreas, Am 25.01.2015 um 12:41 schrieb Andreas Schulze: > Oliver Welter: >>> after upgrading my mail server (dovecot 1.1.7 -> 2.2.13) I get tons of >>> messages about corrupted index files in the syslog ("Error: Corrupted >>> transaction log" and &q

Re: Corruption of index files

2015-01-24 Thread Oliver Welter
Hi List, Am 21.01.2015 um 13:24 schrieb Oliver Welter: Hi All, after upgrading my mail server (dovecot 1.1.7 -> 2.2.13) I get tons of messages about corrupted index files in the syslog ("Error: Corrupted transaction log" and "Warning: fscking index file .. dovecot.index&qu

Corruption of index files

2015-01-21 Thread Oliver Welter
Hi All, after upgrading my mail server (dovecot 1.1.7 -> 2.2.13) I get tons of messages about corrupted index files in the syslog ("Error: Corrupted transaction log" and "Warning: fscking index file .. dovecot.index". I tried flock and even dotlock, but the problems persist. The system is a VPS

Re: Outlook and TLSv.1

2015-01-19 Thread Oliver Welter
Hi All, Am 19.01.2015 um 22:55 schrieb Darren Pilgrim: > On 1/18/2015 12:45 AM, Robert Schetterer wrote: >> Am 16.01.2015 um 12:24 schrieb Oliver Welter: >>> Hi Folks, >>> >>> after adding TLSv1.2 to by TLS options a lot of Outlook users complaint >>>

Outlook and TLSv.1

2015-01-17 Thread Oliver Welter
Hi Folks, after adding TLSv1.2 to by TLS options a lot of Outlook users complaint about connection errors, openssl s_client and Thunderbird works fine. I found some posts about this but none of them had a real solution on this - I meanwhile disabled TLSv1.2 which made the Outlook users happy. I

File locking issues

2015-01-17 Thread Oliver Welter
Hi All, I upgrade my mail server from doveot 1.1.7 to 2.2.13 and encounter problems with file locking issues. The server has around 400 clients using IMAP and I get tons of "Warning: fscking index file .. dovecot.index" and "Error: Corrupted transaction log". Sometimes the transaction log proble