Re: Authentication Penalty with ID x-originating-ip, HAproxy

2016-06-24 Thread Tobias
A quick test confirms that HAproxy header IP information does properly delay the authentication failures upon successive failed login attempts from the same IP. And furthermore if the webmail client is delayed on the IMAP level, this could potentially be exploited for DoS and as such may not b

Re: auth_bind with "()" in username not working

2016-06-24 Thread Matthias Lay
Hi again, did some more tseting on this. I think the problem is the ldap userlookup, where "("s are evil and have to be quoted, but these quotes should be removed for the bind request. I get my usernames from ldap with a filter like this user_filter = (sAMAccountName=%Ln) so I think in betwe

exempt local auth-client UNIX socket from failed login penalty // add to login_trusted_networks ?

2016-06-24 Thread Steffen Kaiser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I'm using Dovecot v2.2 with unix_listener auth-client { } to verify passwords for a different service. However, it looks like that auth_failure_delay effects all connects going through that socket. I mean: connect /var/run/dovecot2.2/auth-cl

Postfix and Dovecot LDA vs. LMTP

2016-06-24 Thread Michael Fox
I'm new to Dovecot and will be using it with Postfix. I'm looking for recommendations regarding the use of Dovecot's LDA or LMTP for virtual mailbox delivery. Many of the simple examples on the wiki use LDA. So I've set that up initially. But apparently an advantage of LMTP is recipient veri

Re: Postfix and Dovecot LDA vs. LMTP

2016-06-24 Thread Jan Büren
Hi Michael, > I'd appreciate comments from experienced users of postfix with dovecot. > Are > you using Dovecot LDA or LMTP and why? I have LMTP with dovecot running on Ubuntu 14.04 and Ubuntu 16.04. LDA is the worser solution, this is best explained in chapter LTMP in Peers dovecot book, which i

Re: Postfix and Dovecot LDA vs. LMTP

2016-06-24 Thread aki . tuomi
The most crucial difference is that LDA is intended for delivering email to a *real* user. Aki > On June 24, 2016 at 7:59 PM Jan Büren wrote: > > > Hi Michael, > > > I'd appreciate comments from experienced users of postfix with dovecot. > > Are > > you using Dovecot LDA or LMTP and why? > I

Re: Postfix and Dovecot LDA vs. LMTP

2016-06-24 Thread Jan Büren
Hi, > But you can easily grasp the configuration details and reverse engineer > the technical german phrases ... Ah well, the link: http://www.dovecot-buch.de/buch/vorwort-timo-sirainen/ > > >> >> >> >> Thanks much, >> >> Michael >> >> >> >> > > > -- > kivitendo mit Schnelleinstieg zu RB-Druckvorl

Re: mail-search backtrace

2016-06-24 Thread Hugh Bragg
On 22/05/16 05:17, Hugh Bragg wrote: On 13/04/16 06:41, Timo Sirainen wrote: On 09 Apr 2016, at 21:48, Hugh Bragg wrote: I'm repeatedly getting this error: Apr 07 04:37:27 imap(mymail@address): Panic: file mail-search.c: line 84 (mail_search_arg_init): assertion failed: (arg->initialized