Re: [Dovecot-news] v2.2.30.1 released

2017-05-31 Thread Reindl Harald
Am 31.05.2017 um 16:35 schrieb Timo Sirainen: On 31 May 2017, at 16.53, Reindl Harald <mailto:h.rei...@thelounge.net>> wrote: LTO build is as broken as 2.2.30 libtool: link: ( cd ".libs" && rm -f "lib10_quota_plugin.la" && ln -s "../lib

Re: [Dovecot-news] v2.2.30.1 released

2017-05-31 Thread Reindl Harald
Am 31.05.2017 um 17:19 schrieb Timo Sirainen: On 31 May 2017, at 18.03, Reindl Harald wrote: libtool: link: ( cd ".libs" && rm -f "lib10_quota_plugin.la" && ln -s "../lib10_quota_plugin.la" "lib10_quota_plugin.la" ) /tmp/ccGO7JSw.ltr

Re: [Dovecot-news] v2.2.30.1 released

2017-05-31 Thread Reindl Harald
Am 31.05.2017 um 15:24 schrieb Timo Sirainen: https://dovecot.org/releases/2.2/dovecot-2.2.30.1.tar.gz https://dovecot.org/releases/2.2/dovecot-2.2.30.1.tar.gz.sig Due to some release process changes I didn't notice that one important bugfix wasn't included in the v2.2.30 release branch before

Re: Dovecot Oy merger with Open-Xchange AG

2015-04-03 Thread Reindl Harald
Am 03.04.2015 um 21:14 schrieb Benny Pedersen: Andreas Kasenides skrev den 2015-04-03 15:53: Please share. I know its easy to do, but share anyway! require ["imap4flags"]; # rule:[h.rei...@thelounge.net] if header :contains "From" "h.rei...@thelounge.net" { addflag "\\Seen"; } this don

Re: Dovecot Oy merger with Open-Xchange AG

2015-04-03 Thread Reindl Harald
Am 03.04.2015 um 15:53 schrieb Andreas Kasenides: On 03/04/15 16:09, Jerry wrote: On Fri, 03 Apr 2015 08:42:42 -0400, Charles Marcus stated: People, PLEASE do not engage Reindl on the list, it always results in this kind of garbage that the adults on the list could do without. If you feel c

Re: Dovecot Oy merger with Open-Xchange AG

2015-04-03 Thread Reindl Harald
/msg91823.html On 4/3/15, Reindl Harald wrote: Am 02.04.2015 um 18:19 schrieb Jogi Hofmüller: Am 2015-04-02 um 17:49 schrieb Reindl Harald: Am 02.04.2015 um 14:30 schrieb Edwardo Garcia: On 4/1/15, Reindl Harald wrote: Am 01.04.2015 um 14:33 schrieb Bernd Petrovitsch: On Mit, 2015-04-01 at

Re: Dovecot Oy merger with Open-Xchange AG

2015-04-02 Thread Reindl Harald
Am 02.04.2015 um 18:19 schrieb Jogi Hofmüller: Am 2015-04-02 um 17:49 schrieb Reindl Harald: Am 02.04.2015 um 14:30 schrieb Edwardo Garcia: On 4/1/15, Reindl Harald wrote: Am 01.04.2015 um 14:33 schrieb Bernd Petrovitsch: On Mit, 2015-04-01 at 13:07 +0200, Reindl Harald wrote: Am

Re: Dovecot Oy merger with Open-Xchange AG

2015-04-02 Thread Reindl Harald
Am 02.04.2015 um 14:30 schrieb Edwardo Garcia: On 4/1/15, Reindl Harald wrote: Am 01.04.2015 um 14:33 schrieb Bernd Petrovitsch: On Mit, 2015-04-01 at 13:07 +0200, Reindl Harald wrote: Am 01.04.2015 um 13:04 schrieb Bernd Petrovitsch: IMHO the larger the corporation is, the less are the

Re: Dovecot Oy merger with Open-Xchange AG

2015-04-01 Thread Reindl Harald
Am 01.04.2015 um 14:33 schrieb Bernd Petrovitsch: On Mit, 2015-04-01 at 13:07 +0200, Reindl Harald wrote: Am 01.04.2015 um 13:04 schrieb Bernd Petrovitsch: IMHO the larger the corporation is, the less are the chances for *long-term* benefits of the OSS/free software (mainly because: usually

Re: Dovecot Oy merger with Open-Xchange AG

2015-04-01 Thread Reindl Harald
Am 01.04.2015 um 13:04 schrieb Bernd Petrovitsch: IMHO the larger the corporation is, the less are the chances for *long-term* benefits of the OSS/free software (mainly because: usually commercial success is driven and defined from marketing to sales[1] sown to the techies which are forced into

Re: sieve rule for "header don't exist"

2015-03-30 Thread Reindl Harald
Am 30.03.2015 um 11:41 schrieb Christian Kivalo: On 2015-03-30 11:25, Reindl Harald wrote: is there a way to expresse when the header "X-Spam-Status" *do not* exist move the message to a different folder? :contains, :matches and :is are not helpful here Have you tried using

sieve rule for "header don't exist"

2015-03-30 Thread Reindl Harald
is there a way to expresse when the header "X-Spam-Status" *do not* exist move the message to a different folder? :contains, :matches and :is are not helpful here background: the spamass-milter option -B is lacking the spamassassin headers in case of milter-rejects and via sendmail generated B

Re: Error after setting up fts /solr for Open-Xchange

2015-03-28 Thread Reindl Harald
Am 28.03.2015 um 18:02 schrieb zu...@systemschmiede.com: Well...That seemed to have worked in fact. Updated to 2:2.2.16-1~auto+36. "All folders"-search works, and no errors are being shown. Besides, the all folder search in Open-Xchange looks great and is lightning fast! well, the first step

Re: postfix sasl -> haproxy -> dovecot auth

2015-03-27 Thread Reindl Harald
Am 27.03.2015 um 15:04 schrieb Benny Pedersen: Gedalya skrev den 2015-03-27 14:48: is it possible to configure configure haproxy to work with postfix sasl and dovecot auth like this: clients -> 25:postfix -> 20025:haproxy -> 20025:auth-backend-1, 20025:auth-backend-2 Why don't you set up a do

Re: postfix sasl -> haproxy -> dovecot auth

2015-03-27 Thread Reindl Harald
Am 27.03.2015 um 14:49 schrieb Benny Pedersen: What I need is to make smtp authentication balanced and keep everything in backend (private network) dovecot is not a smtp server, thats why i say cyrus-sasl jesus christ keep your smart-ass responses for yourself http://wiki2.dovecot.org/HowTo/

Re: Dovecot Oy merger with Open-Xchange AG

2015-03-25 Thread Reindl Harald
Am 25.03.2015 um 20:34 schrieb Benny Pedersen: Brad Smith skrev den 2015-03-25 20:20: only paid here by compileing time, still have dovecot v1 working, so open source it not complete free, as long it compiles fine i am happy Not making any sense. punktum ? "only paid here by compileing

Re: Dovecot Oy merger with Open-Xchange AG

2015-03-25 Thread Reindl Harald
Am 25.03.2015 um 18:28 schrieb Benny Pedersen: Reindl Harald skrev den 2015-03-25 18:08: with your argumentation making a shit would also not be completly free because you need to pinch ass bakes. and you write this on public walls? DON'T QUOTE OUT OF CONTEXT BOY, YOU HAVE MISSED

Re: Dovecot Oy merger with Open-Xchange AG

2015-03-25 Thread Reindl Harald
Am 25.03.2015 um 18:03 schrieb Benny Pedersen: Brad Smith skrev den 2015-03-25 16:58: On 03/25/15 08:46, Peter Chiochetti wrote: Am 25.03.2015 um 13:23 schrieb Nick Edwards: So there *is* a chance it will be commercialised Hasn't it been commercial for a long time? When was the last time yo

Re: Dovecot Oy merger with Open-Xchange AG

2015-03-25 Thread Reindl Harald
Am 25.03.2015 um 16:58 schrieb Brad Smith: On 03/25/15 08:46, Peter Chiochetti wrote: Am 25.03.2015 um 13:23 schrieb Nick Edwards: So there *is* a chance it will be commercialised Hasn't it been commercial for a long time? When was the last time you paid for Dovecot? The base product is o

Re: imap-login SSLv3 causes signal 11, core dump and DoS. ssl_protocols = ??

2015-03-21 Thread Reindl Harald
Am 21.03.2015 um 12:12 schrieb James: On 21/03/2015 11:07, Reindl Harald wrote: well, remove that brickage of "special compile" I'm sorry but I did not understand your comment why do you compile openssl that way? What way? With or without ssl3? I've now done it

Re: imap-login SSLv3 causes signal 11, core dump and DoS. ssl_protocols = ??

2015-03-21 Thread Reindl Harald
Am 21.03.2015 um 12:02 schrieb James: On 21/03/2015 10:55, Reindl Harald wrote: well, remove that brickage of "special compile" I'm sorry but I did not understand your comment why do you compile openssl that way? signature.asc Description: OpenPGP digital signature

Re: imap-login SSLv3 causes signal 11, core dump and DoS. ssl_protocols = ??

2015-03-21 Thread Reindl Harald
Am 21.03.2015 um 11:51 schrieb James: On 21/03/2015 10:00, James wrote: the "SSL23_GET_CLIENT_HELLO:unsupported protocol" seems to do what I thought the ssl_protocols setting did. Do I still need, if I ever needed, the "ssl_protocols = " setting? All these ssl_* settings just go to OpenSSL

Re: Support for multiple passwords?

2015-03-18 Thread Reindl Harald
Am 18.03.2015 um 20:56 schrieb Conrad Kostecki: Am 2015-03-18 20:46, schrieb Reindl Harald: Am 18.03.2015 um 20:40 schrieb Conrad Kostecki: Hi! Currently, the passwords are stored in plaintext for my dovecot, as I am still using cram-md5 AND digest-md5. I have still to offer that, as I have

Re: Support for multiple passwords?

2015-03-18 Thread Reindl Harald
Am 18.03.2015 um 20:40 schrieb Conrad Kostecki: Hi! Currently, the passwords are stored in plaintext for my dovecot, as I am still using cram-md5 AND digest-md5. I have still to offer that, as I have some deprecated clients, therefore, I am unable to hash at least those passwords for that accoun

Re: How to detect out-of-sync condition

2015-03-13 Thread Reindl Harald
Am 13.03.2015 um 14:29 schrieb Cliff Hayes: I looked in the place where dovecot logs everything ... the maillog. I didn't see anything but the log is huge and I could have easily missed it. Is there a certain error or phrase I should look for? If so please advise. man grep grep -i 'sync' mail

Re: v2.2.16 released

2015-03-13 Thread Reindl Harald
Am 13.03.2015 um 11:23 schrieb Timo Sirainen: On 12 Mar 2015, at 21:09, Reindl Harald wrote: /usr/lib64/dovecot/stats/libstats_mail.so why in the world a new sub-directory containing just one so-file enforcing pakcage buildsers to change SPEC files? So that external plugins can add more

Re: v2.2.16 released

2015-03-12 Thread Reindl Harald
/usr/lib64/dovecot/stats/libstats_mail.so why in the world a new sub-directory containing just one so-file enforcing pakcage buildsers to change SPEC files? Am 12.03.2015 um 18:30 schrieb Timo Sirainen: http://dovecot.org/releases/2.2/dovecot-2.2.16.tar.gz http://dovecot.org/releases/2.2/dove

Re: location of dovecot.rawlog-directory

2015-03-12 Thread Reindl Harald
Am 12.03.2015 um 15:18 schrieb Hardy Flor: I want running servers, not with each new version have to compile. well, rpm-SPECs allow including of patches if you rely on distribution packages you won't see a update even if upstream would introduce a config option for years Am 12.03.2015 um

Re: doveconf -a Segmentation Fault

2015-03-12 Thread Reindl Harald
Am 12.03.2015 um 15:07 schrieb Dan LaSota: Getting "Segmentation Fault" When I run doveconf -a i don't in other words: bad for you but what's the purpose of the information without any debugging like strace? signature.asc Description: OpenPGP digital signature

Re: libdriver_msql.so

2015-03-11 Thread Reindl Harald
setup 2015-03-11 15:41 GMT+01:00 Reindl Harald : Am 11.03.2015 um 15:37 schrieb kaniggl: To make it clear, architecture is PowerPC 64bit Then i installed dovecot via apt-get. But the file /usr/lib/dovecot/modules/auth/libdriver_mysql.so is missing. install the sub-package "dovecot-mysq

Re: libdriver_msql.so

2015-03-11 Thread Reindl Harald
Am 11.03.2015 um 15:37 schrieb kaniggl: To make it clear, architecture is PowerPC 64bit Then i installed dovecot via apt-get. But the file /usr/lib/dovecot/modules/auth/libdriver_mysql.so is missing. install the sub-package "dovecot-mysql" and the next time *ask before* you ruin your system

Re: LMTP error: Too many concurrent deliveries for user (in reply to end of DATA command)

2015-03-06 Thread Reindl Harald
Am 06.03.2015 um 14:59 schrieb Ralf Hildebrandt: * Reindl Harald : lmtp_destination_concurrency_limit on postfix side It's not a postfix issue. postfix is merely reporting what Dovecot said i know that on my own since i can read maillogs :-) anyways, we even use a lmtp concurrency

Re: LMTP error: Too many concurrent deliveries for user (in reply to end of DATA command)

2015-03-06 Thread Reindl Harald
Am 06.03.2015 um 14:44 schrieb Ralf Hildebrandt: I updated dovecot today and all over a sudden I'm getting: Mar 6 14:40:46 mail postfix/lmtp[3150]: 3kz95y3nX3zCtTS: to=, relay=127.0.0.1[private/dovecot-lmtp], delay=88, delays=87/0.94/0.01/0.01, dsn=4.3.0, status=deferred (host 127.0.0.1[priva

Re: RBL with stock Dovecot 2.2.15 (was Re: IP drop list)

2015-03-05 Thread Reindl Harald
Am 05.03.2015 um 22:45 schrieb Steffen: Steffen Kaiser wrote: passdb { driver = ipdeny args = /matchpattern/action *** } With next passdb{} as 1st in chain: passdb { driver = checkpassword args = "/tmp/chktst ip=%r service=%s" result_success = continue result_failure = retu

Re: IP drop list

2015-03-05 Thread Reindl Harald
Am 05.03.2015 um 20:23 schrieb @lbutlr: On 04 Mar 2015, at 21:46 , Jim Pazarena wrote: On 2015-03-02 2:02 AM, Jochen Bern wrote: On 03/01/2015 08:53 AM, Jim Pazarena wrote: I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped?

Re: IP drop list

2015-03-04 Thread Reindl Harald
Am 04.03.2015 um 23:00 schrieb Felix Zandanel: I am not against block lists. I just say their use should be justified as they may decrease overall service quality as well. There is another solution for auth based services: As soon as you detect a possible attack (# auth reqs > x etc.), keep t

Re: IP drop list

2015-03-04 Thread Reindl Harald
Am 04.03.2015 um 21:51 schrieb Oliver Welter: Please add this support to iptables instead of Dovecot. It's a waste of effort to code it into every application that listens on the network. Would you care to integrate it into IOS on my Cisco as well? There are things connected to

Re: IP drop list

2015-03-04 Thread Reindl Harald
Am 04.03.2015 um 20:12 schrieb Michael Orlitzky: On 03/03/2015 11:03 PM, Earl Killian wrote: On 2015/3/2 10:03, Reindl Harald wrote: that is all nice but the main benefit of RBL's is always ignored: * centralized * no log parsing at all * honeypot data are "delivered" to

Re: IP drop list

2015-03-04 Thread Reindl Harald
ue on POP3/IMAP after locked out from postfix without write firewall rules the whole point of a *locally administered* RBL is that you don't need to care about hown many mailservers you have and where they are nor need you to open security holes between them for sharing data On 03/03/2015

Re: IP drop list

2015-03-03 Thread Reindl Harald
Am 03.03.2015 um 22:31 schrieb Oliver Welter: I did a quick hack for exactly this purpose - send offending IPs from my mail server to the firewall "in a secure way". Its a python script that uses the fail2ban syntax on the one end and feeds a (patched) pfSense on the other end. You can find the

Re: IP drop list

2015-03-02 Thread Reindl Harald
Am 03.03.2015 um 00:45 schrieb Benny Pedersen: On March 2, 2015 10:50:59 PM Dave McGuire wrote: On 03/02/2015 05:34 AM, Joseph Tam wrote: >>> http://wiki2.dovecot.org/PasswordDatabase/ExtraFields/AllowNets its not a big hint its not called denynets is it ? I myself just want a mechanism

Re: Connect failed to database

2015-03-02 Thread Reindl Harald
Am 02.03.2015 um 19:53 schrieb Dan LaSota: still doesn't work: Mar 2 04:58:48 mail dovecot: auth-worker(5745): Error: mysql(127.0.0.1): Connect failed to database (servermail): Access denied for user 'usermail'@'localhost' (using password: YES) - waiting for 1 seconds before retry that i

Re: Connect failed to database

2015-03-02 Thread Reindl Harald
Am 02.03.2015 um 19:30 schrieb Dan LaSota: Just some quick ideas * check if the mysql socket file has rw permissions for the dovecot user # ls -l /var/lib/mysql/mysql.sock srwxrwxrwx. 1 mysql mysql 0 Mar 1 19:33 /var/lib/mysql/mysql.sock that's not the problem I have tried with connect =

Re: IP drop list

2015-03-02 Thread Reindl Harald
Am 02.03.2015 um 18:56 schrieb Robert Schetterer: perhaps and i mean really "perhaps" go this way https://sys4.de/de/blog/2014/03/27/fighting-smtp-auth-brute-force-attacks/ https://sys4.de/de/blog/2012/12/28/botnets-mit-rsyslog-und-iptables-recent-modul-abwehren/ 45K+ IPs will work in a recen

Re: IP drop list

2015-03-02 Thread Reindl Harald
Am 02.03.2015 um 11:02 schrieb Jochen Bern: On 03/01/2015 08:53 AM, Jim Pazarena wrote: I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped? I have accumulated 45,000+ IPs which routinely try dictionary and 12345678 password atte

Re: IP drop list

2015-03-02 Thread Reindl Harald
Am 02.03.2015 um 10:33 schrieb Steffen Kaiser: hence RBL's make sense in the core because *in front* of any other protocol specific code That's TCP wrapper or a firewall, IMHO. (for a file list, not RBL). However, there used to be a RBL patch for TCP wrapper and some distribution provide other

Re: IP drop list

2015-03-02 Thread Reindl Harald
Am 02.03.2015 um 10:06 schrieb Steffen Kaiser: If such plugin(?) is available, I would expect immediate complains, it does not support: + local file lists with various sets of syntaxes + RBLs with a fine grained response matching + use the same RBL response for multiple match-action pairs or

Re: IP drop list

2015-03-02 Thread Reindl Harald
Am 02.03.2015 um 08:38 schrieb Oliver Welter: I am really tired of reading this kind of complaints on OSS lists. and because it's free everybody has to shut up? that's your defintion of free? your definition is broken? as said on a other list: if the developer of the OSS sais "listen, i am

Re: IP drop list

2015-03-01 Thread Reindl Harald
Am 02.03.2015 um 00:08 schrieb Benny Pedersen: On March 1, 2015 10:26:40 AM Reindl Harald wrote: i guess for a C-programmer it takes not much more than 10 minutens include a config option to list rbl servers and close connections absed on the DNS responses close pop3, set imap to listen

Re: IP drop list

2015-03-01 Thread Reindl Harald
Am 01.03.2015 um 23:16 schrieb Dave McGuire: On 03/01/2015 04:25 AM, Reindl Harald wrote: I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped? I have accumulated 45,000+ IPs which routinely try dictionary and 12345678 pas

Re: IP drop list

2015-03-01 Thread Reindl Harald
Am 01.03.2015 um 08:53 schrieb Jim Pazarena: I wonder if there is an easy way to provide dovecot a flat text file of ipv4 #'s which should be ignored or dropped? I have accumulated 45,000+ IPs which routinely try dictionary and 12345678 password attempts. The file is too big to create firewall

Re: Conditional SASL authentication

2015-02-24 Thread Reindl Harald
Am 24.02.2015 um 19:48 schrieb Adrian Minta: On 24.02.2015 20:40, Reindl Harald wrote: Am 24.02.2015 um 19:37 schrieb Adrian Minta: On 24.02.2015 20:29, Reindl Harald wrote: don't allow senders which you would not receive mail for - period Seems interesting, at least until the

Re: Conditional SASL authentication

2015-02-24 Thread Reindl Harald
Am 24.02.2015 um 19:37 schrieb Adrian Minta: On 24.02.2015 20:29, Reindl Harald wrote: don't allow senders which you would not receive mail for - period Seems interesting, at least until the bots adapt to this. Any idea how could this be implemented? with the configuration i have p

Re: Conditional SASL authentication

2015-02-24 Thread Reindl Harald
Am 24.02.2015 um 19:20 schrieb Luciano Mannucci: On Tue, 24 Feb 2015 19:00:32 +0100 Reindl Harald wrote: so you allow random envelope senders on your servers? why? I know it is not necessarily a good idea... :) It is basicaly to allow fake home addresses from the office for some managers

Re: Conditional SASL authentication

2015-02-24 Thread Reindl Harald
Am 24.02.2015 um 19:04 schrieb Luciano Mannucci: On Tue, 24 Feb 2015 18:56:03 +0100 Reindl Harald wrote: * if you cahnge the pwd SASL auth is taken away True. But this way the user will be unable to read his/her mail, including my message saying "Hey, you've got a new virus!

Re: Conditional SASL authentication

2015-02-24 Thread Reindl Harald
Am 24.02.2015 um 18:28 schrieb Luciano Mannucci: for the virus doesn't necessarily use the e-mail of the user as its from, just the user and password for the authentication phase so you allow random envelope senders on your servers? why? smtpd_recipient_restrictions = permit_mynetworks rejec

Re: Conditional SASL authentication

2015-02-24 Thread Reindl Harald
Am 24.02.2015 um 18:28 schrieb Luciano Mannucci: I have a few users that are often hit by a trojan virus that steals e-mail user and password. Having a very little (if not null) power on their machines, I need to be able to block the outgoing mail wich is handled by postfix via dovecot SASL. Blo

Re: Bug#776094: dovecot-imapd: corrupts mailbox after trying to retrieve it (fwd)

2015-02-20 Thread Reindl Harald
Am 20.02.2015 um 15:03 schrieb Charles Marcus: On 2/19/2015 4:34 PM, Santiago Vila wrote: In such case we would love to know what is the commit that fixed this, so that we can apply it to the 2.2.13 version in Debian. We have frozen the distribution as we are about to release jessie as Debian

Re: how to run dovecot imap on separate server from postfix?

2015-02-18 Thread Reindl Harald
t the packet filter, sooner or later somebody will change something without realize the impact and hence if it comes to security put at least 2 safety nets in front of server ports On Wed, Feb 18, 2015 at 12:37 PM, Reindl Harald wrote: Am 18.02.2015 um 18:20 schrieb Reindl Harald: Am 18.0

Re: how to run dovecot imap on separate server from postfix?

2015-02-18 Thread Reindl Harald
Am 18.02.2015 um 18:20 schrieb Reindl Harald: Am 18.02.2015 um 18:15 schrieb Robert Fantini: I'm trying to figure out the exact line to put to /etc/postfix/main.cf for local lmtp deliver we use: mailbox_transport = *lmtp:unix:private/dovecot-lmtp* for remote it is supposed

Re: how to run dovecot imap on separate server from postfix?

2015-02-18 Thread Reindl Harald
Am 18.02.2015 um 18:15 schrieb Robert Fantini: I'm trying to figure out the exact line to put to /etc/postfix/main.cf for local lmtp deliver we use: mailbox_transport = *lmtp:unix:private/dovecot-lmtp* for remote it is supposed to be:* lmtp:host:port* yet at the remote lmtp does not use por

Re: how to run dovecot imap on separate server from postfix?

2015-02-17 Thread Reindl Harald
the lmtpd on localhost is reachable 365/7/24 and hence any sane MTA handles errors properly On Tue, Feb 17, 2015 at 4:37 PM, Reindl Harald wrote: Am 17.02.2015 um 22:29 schrieb Robert Fantini: we are using version 2.2.13 on debian. currently imap runs on the same system a

Re: how to run dovecot imap on separate server from postfix?

2015-02-17 Thread Reindl Harald
Am 17.02.2015 um 22:29 schrieb Robert Fantini: we are using version 2.2.13 on debian. currently imap runs on the same system as postfix , spamassassin and other mail related software. I'd like to move dovecot imapd and mail storage to its own system. I've search google and wiki an

Re: /etc/ssl/certs/dovecot.pem erased by OpenSuse's update mechanism

2015-02-16 Thread Reindl Harald
n for those programs suggests putting the CRLs in a separate file (e.g. apache SSLCARevocationFile) or doesn't talk about putting CRLs in with the certs (e.g. postfix smtpd_tls_cert_file). If it works to put them all in one file for those programs, that's good to know. On 2015/2/16 07

Re: /etc/ssl/certs/dovecot.pem erased by OpenSuse's update mechanism

2015-02-16 Thread Reindl Harald
Am 16.02.2015 um 15:53 schrieb dove...@lists.killian.com: Why not /etc/dovecot/private? That's where I put my dovecot certs. Dovecot's needs are a bit different from other software, and so it is unclear whether the files won't be unique to it. For example, I haven't seen the following before I

Re: Server switching

2015-02-10 Thread Reindl Harald
Am 10.02.2015 um 16:35 schrieb The Doctor: Quick question. We are using both IMAP and POP#. Question : how can you avoid retrieving an e-mail that has been already retrieved? by just rsync the complete data from the old to the new server * first rsync hot while servicers running * stop serv

Re: Postfix , Dovecot & the Spam fight

2015-02-09 Thread Reindl Harald
Am 09.02.2015 um 22:29 schrieb Leander Schäfer: I'm currently busy with a substiution of my current mail server. I'm currently using * Clam-SMTP and * SpamAssassin to fight Spam. I wonder if it is worth implementing AmaViS with SpamAssassin backend instead and also using AmaViS to speak to

Re: TLS config check

2015-02-06 Thread Reindl Harald
Am 06.02.2015 um 23:13 schrieb SW: According to https://cipherli.st/ ssl = yes ssl_cert = Dovecot 2.2.6 Is what you want. Ok, so I have changed my ssl_cipher_list to: ssl_cipher_list = AES128+EECDH:AES128+EDH Before I made this change clients were connecting with the following cipher in th

Re: auth: Warning: DNS lookup took 1.550 s

2015-02-04 Thread Reindl Harald
how do you come to the conclusion that it matters how busy "this server is"? jesus christ you are asking *remote servers* for their answers and the request as well the answer passes different routers, ISP's and likely a *chain of forwarders* until you don't recursion at your own and even if you

Re: quote strings passed to sql

2015-02-02 Thread Reindl Harald
Am 02.02.2015 um 18:17 schrieb Juan Bernhard: Am 02.02.2015 um 18:07 schrieb Juan Bernhard: Hello list. I'm thinking to migrate the hole user db from system users to mysql. I already did it in a test environment, but something is annoying my OCD... I don't quote the variables username and passw

Re: quote strings passed to sql

2015-02-02 Thread Reindl Harald
Am 02.02.2015 um 18:07 schrieb Juan Bernhard: Hello list. I'm thinking to migrate the hole user db from system users to mysql. I already did it in a test environment, but something is annoying my OCD... I don't quote the variables username and password sent to the mysql server. I know, the mysql

Re: auth: Error: auth worker: Aborted request: Lookup timed out

2015-02-01 Thread Reindl Harald
Am 01.02.2015 um 22:44 schrieb ML mail: Thanks for your tip regarding the busy network. I am using a one year old Cisco Catalyst 2960S (WS-C2960S-48TD-L) with cat6e cables and my network should not be overloaded as far as I know. My mailbox and mail proxy servers are on two different virtual

Re: Thunderbird: improper command pipelining after EHLO

2015-01-26 Thread Reindl Harald
Am 26.01.2015 um 15:22 schrieb Leander Schäfer: I couldn't find working solutions for this anomalie on the net. What does this mean and does someone know how to fix this? postfix/smtpd[18757]: improper command pipelining after EHLO from unknown[192.168.10.233]: QUIT\r\n that's hardly a doveco

Re: LDA input validation

2015-01-26 Thread Reindl Harald
Am 26.01.2015 um 10:52 schrieb Stéphane Cottin: Le 26 janv. 2015 à 10:09, Reindl Harald a écrit : You're stilling going to lose contents. If dspam fails, the mail is dumped, the LDA returns exit code 75, and the MTA will probably issue a bounce Email to the sender. which would be O

Re: LDA input validation

2015-01-26 Thread Reindl Harald
Am 26.01.2015 um 08:52 schrieb Steffen Kaiser: On Sun, 25 Jan 2015, Joseph Tam wrote: St?phane Cottin writes: dspam already send errors to syslog, the point here is to never loose email contents. This was a wrong design, i'm now use a wrapper instead ( see my previous post for details ).

Re: imap-login: Fatal: pipe() failed: Too many open files

2015-01-25 Thread Reindl Harald
Am 26.01.2015 um 02:13 schrieb Leander Schäfer: I just checked my ulimit again and it really seems like it has more than enough - so I still don't understand what I've configured wrong here ;/ root@WM-01 [~]$ su -m dovecot -c "ulimit -a" socket buffer size (bytes, -b) unlimited core file

Re: Client shows null Sender & date

2015-01-23 Thread Reindl Harald
Am 23.01.2015 um 16:06 schrieb John Hendrich: I'm using Postfix and Dovecot 2.0.19 and Virtual domains & users (mysql). Incoming mail is handled by Postfix and then handed off to Dovecot LMTP for delivery. However, the Sender and Date are essentially null when viewing the email with either the

Re: Outlook and TLSv.1

2015-01-18 Thread Reindl Harald
Am 18.01.2015 um 12:07 schrieb Jerry: I have: ssl_cipher_list = ALL:!LOW:!SSLv2:!SSLv3:!EXP:!aNULL and Outlook 2013 works fine but you break *for sure* older clients and should *not* recommend that broken setup untested and believe you are helping with it !SSLv3 has no business in the ciph

Re: Outlook and TLSv.1

2015-01-18 Thread Reindl Harald
Am 16.01.2015 um 12:24 schrieb Oliver Welter: after adding TLSv1.2 to by TLS options how did you do that? there is no need to add it as long you did not break your configuration intentional the time before a lot of Outlook users complaint about connection errors, openssl s_client and Thund

Re: [SERVERBUG] failed to send mail with SA and antispam plugin

2015-01-16 Thread Reindl Harald
Am 16.01.2015 um 09:46 schrieb ML mail: Thanks to your help Steffen I was able to find out the issue which was simply the size of the Spam mail as you can see here: spamc[16545]: skipped message, greater than max message size (512000 bytes) The spam mail was around 900 kbytes as such I have c

Re: pigeonhole ereject vs reject

2015-01-13 Thread Reindl Harald
Am 14.01.2015 um 02:40 schrieb Robert Blayzor: On Jan 13, 2015, at 8:30 PM, Reindl Harald wrote: so what you want in your OP is just DISCARD in a sieve script and there is no point in "Using Dovecot LMTP it would be more optimal to kick a 5xx back" when the desired result is DI

Re: pigeonhole ereject vs reject

2015-01-13 Thread Reindl Harald
Am 14.01.2015 um 02:23 schrieb Robert Blayzor: On Jan 13, 2015, at 7:34 PM, Reindl Harald wrote: and what would that change? nothing if you think about how mail works! * the MTA receives the message * the MTA confirms with 2xx status code * later the delivery server rejects * the MTA *must

Re: pigeonhole ereject vs reject

2015-01-13 Thread Reindl Harald
Am 14.01.2015 um 01:28 schrieb Robert Blayzor: Currently pigeonhole supports reject which would generate a NDR for each message. (If I understand the current documentation) Using Dovecot LMTP it would be more optimal to kick a 5xx back to the primary MTA to reject the delivery rather than gen

Re: Dovecot replication over TCP/SSL, certificate error

2015-01-12 Thread Reindl Harald
Am 12.01.2015 um 13:29 schrieb Jonas Plitt: *doveadm(exam...@example.com ): Error: Couldn't initialize SSL context: Can't load CA certs from directory /etc/ssl/certs: error:02001024:system library:fopen:File name too longdoveadm: Error: Failed to iterate through some users*" this is my config

Re: Dovecot on Fedora 20 or 21

2015-01-10 Thread Reindl Harald
Am 10.01.2015 um 19:34 schrieb David Mehler: Is anyone running Dovecot on either a Fedora 20 or 21 system? surely having an issue, on a system reboot, which I admit does not happen often, Dovecot fails to start in the systemctl list, output is status failed. The issue seems to be Dovecot can

Re: 'ssl_cipher_list' setting

2015-01-05 Thread Reindl Harald
Am 05.01.2015 um 21:53 schrieb Yoshito Takeuchi: I used FreeBSD 10.1 Dovecot 2.2.15 I want pop3s, so I made /usr/local/etc/dovecot/local.conf ssl = yes ssl_cert = SSLv3 ) I did trouble /var/log/maillog Jan 6 05:41:53 example dovecot: pop3-login: Disconnected (no auth attempts in 0 secs)

Re: Awfully slow dovecot

2014-12-26 Thread Reindl Harald
Am 26.12.2014 um 17:16 schrieb Nick Edwards: On 12/26/14, Reindl Harald wrote: sure, you can manage anything if you write enough tools to automate things, nothing new for me as software developer, but don't you think there is a reason why advanced package management exists and 95% o

Re: Awfully slow dovecot

2014-12-25 Thread Reindl Harald
Am 26.12.2014 um 02:20 schrieb Edwardo Garcia: On 12/26/14, Jeff Mitchell wrote: On Dec 25, 2014 3:15 PM, "Reindl Harald" wrote: your Gentoo is nice in a small environment on larger setups someone is using binary packages and can setup his own repo with overrides while maintain

Re: Awfully slow dovecot

2014-12-25 Thread Reindl Harald
Am 25.12.2014 um 21:09 schrieb Benny Pedersen: Robert Schetterer skrev den 2014-12-25 19:49: Am 18.12.2014 um 17:56 schrieb Robin Helgelin: We’re using dovecot 1.0.7 that version is total out of date , update to recent version centos is a precompiled problem :=) no it is not do you realy

Re: replication - more than 2 servers?

2014-12-16 Thread Reindl Harald
Am 16.12.2014 um 21:13 schrieb Ron Cleven: We tested dovecot for a fair amount of time and decided finally to put it into production under CentOS 7 (we are running 2.2.10). I just joined the list, so I apologize for what is probably a question that has been answered many times, but I was wonder

Re: dovecot.index.log files: what are they?

2014-12-10 Thread Reindl Harald
Am 10.12.2014 um 21:48 schrieb Thomas Klausner: On Wed, Dec 10, 2014 at 09:26:31PM +0100, Reindl Harald wrote: Am 10.12.2014 um 21:19 schrieb Thomas Klausner: I have lots of these files: /home/wiz/Mail/my-folder-name/cur/.imap/1238738125.13533_23713.danbala:2,S/dovecot.index.log What are

Re: dovecot.index.log files: what are they?

2014-12-10 Thread Reindl Harald
Am 10.12.2014 um 21:19 schrieb Thomas Klausner: I have lots of these files: /home/wiz/Mail/my-folder-name/cur/.imap/1238738125.13533_23713.danbala:2,S/dovecot.index.log What are they for? Why are they here? Can I remove them? RTFM: http://wiki2.dovecot.org/IndexFiles https://www.google.at/s

Re: MD5-CRYPT/CRAM-MD5 vs SHA512-CRYPT/PLAIN

2014-12-06 Thread Reindl Harald
Am 06.12.2014 um 14:40 schrieb Daniel Parthey: Am 6. Dezember 2014 13:10:58 MEZ, schrieb Reindl Harald : Am 06.12.2014 um 06:56 schrieb Jan Wideł: If you add disable_plaintext_auth=yes ssl=required settings, then dovecot will drop authentication without STARTTLS. But damage will be done

Re: MD5-CRYPT/CRAM-MD5 vs SHA512-CRYPT/PLAIN

2014-12-06 Thread Reindl Harald
Am 06.12.2014 um 06:56 schrieb Jan Wideł: If you add disable_plaintext_auth=yes ssl=required settings, then dovecot will drop authentication without STARTTLS. But damage will be done, client will send unencrypted (or in this scenario MD5 or SHA512 hash) login/password no, damage will *not* be

Re: disabling certain ciphers

2014-12-02 Thread Reindl Harald
Am 02.12.2014 um 17:33 schrieb Darren Pilgrim: On 12/2/2014 1:32 AM, Reindl Harald wrote: ssl_cipher_list = HIGH:!RC4:!MD5:!SRP:!PSK:!aNULL:@STRENGTH ssl_dh_parameters_length = 2048 ssl_parameters_regenerate = 0 ssl_protocols = !SSLv2 !SSLv3 TLSv1 TLSv1.1 TLSv1.2 But why does ssl_protocols

Re: disabling certain ciphers

2014-12-02 Thread Reindl Harald
Am 02.12.2014 um 06:44 schrieb Will Yardley: On Mon, Dec 01, 2014 at 09:27:48PM -0800, Darren Pilgrim wrote: On 12/1/2014 4:43 PM, Will Yardley wrote: Can you use both ssl_protocols *and* ssl_cipher_list in the same config (in a way that's sane)? Is there a way to exclude these ciphers, whi

Re: best file system ?

2014-12-01 Thread Reindl Harald
Am 01.12.2014 um 21:13 schrieb Marcin Mirosław: W dniu 2014-12-01 o 18:19, Alessio Cecchi pisze: Il 01/12/2014 17:24, absolutely_f...@libero.it ha scritto: Hi, I'm going to set up a new storage for our email users (about 10k). It's a network attached storage (Coraid). In your opinion, what i

Re: SORT capability

2014-12-01 Thread Reindl Harald
Am 01.12.2014 um 12:32 schrieb absolutely_f...@libero.it: # dovecot -n |grep -i sort (nothing) i meant post the complete output you can't grep for something not existing but you or some config-include may set something wrong Maybe to full list is only available after authentication? like

Re: SORT capability

2014-12-01 Thread Reindl Harald
Am 01.12.2014 um 12:19 schrieb absolutely_f...@libero.it: why I don't see SORT capability on my dovecot server? # telnet localhost 143 Trying ::1... Connected to localhost. Escape character is '^]'. * OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE IDLE STARTTLS AUTH=PLAIN

Re: Offtopic, spam+AV

2014-11-28 Thread Reindl Harald
Am 28.11.2014 um 17:45 schrieb Jorge Bastos: In my previous servers I have clamav+spamassassin configured in postfix, but things as, scan only outgoing emails it's not possible. What's the best option for these two filtering now adays? besides that this is the wrong list why should it not be

  1   2   3   4   5   6   7   8   >