Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Kristof Bajnok
On 2013-04-23 23:21, Viktor Dukhovni wrote: >>> After sending END-OF-MESSAGE, the Postfix smtpd_proxy_CLIENT closes >>> > >the SMTP connection to the before-queue content filter. >> > >> > And this is exactly the problem: smtpd_proxy_CLIENT closes the >> > connection without sending >> > the QUIT

Re: Postscreen DNSBL Sites

2013-04-23 Thread /dev/rob0
On Tue, Apr 23, 2013 at 08:59:41PM -0700, David Benfell wrote: > On 04/23/2013 10:42 AM, Steve Jenkins wrote: > > > > This setup has been working pretty well for me, and reduces false > > positives by not allowing any single DNSBL to block an incoming > > connection without concurrence from at l

Re: [feature request] Subzero postscreen/dnsblog score to bypass after-220 tests?

2013-04-23 Thread /dev/rob0
On Tue, Apr 23, 2013 at 08:05:34PM -0400, Wietse Venema wrote: > On Fri, Apr 12, 2013 at 06:34:24AM -0400, Wietse Venema wrote: > > /dev/rob0: > > > I finally got around to my upgrade to 2.11-20130405 and was > > > watching logs. A gmail message fell afoul of the after-220 > > > tests; each time

Re: Postscreen DNSBL Sites

2013-04-23 Thread David Benfell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 04/23/2013 10:42 AM, Steve Jenkins wrote: > > This setup has been working pretty well for me, and reduces false > positives by not allowing any single DNSBL to block an incoming > connection without concurrence from at least one other DNSBL. > F

Re: loops back to myself

2013-04-23 Thread Viktor Dukhovni
On Wed, Apr 24, 2013 at 03:05:58AM +0200, Benny Pedersen wrote: > Feel Zhou skrev den 2013-04-23 07:26: > > >How can I reject these mail before it in the queue > > $ cat main.cf > # in smtpd_sender_restrictions = > ... > check_sender_mx_access cidr:/etc/postfix/sender_mx_access > ... > > $ c

Re: loops back to myself

2013-04-23 Thread Benny Pedersen
Feel Zhou skrev den 2013-04-23 07:26: How can I reject these mail before it in the queue $ cat main.cf # in smtpd_sender_restrictions = ... check_sender_mx_access cidr:/etc/postfix/sender_mx_access ... $ cat /etc/postfix/sender_mx_access 0.0.0.0/8 REJECT MX in IANA reserved network 127.0.0

Re: [feature request] Subzero postscreen/dnsblog score to bypass after-220 tests?

2013-04-23 Thread Wietse Venema
On Fri, Apr 12, 2013 at 06:34:24AM -0400, Wietse Venema wrote: > /dev/rob0: > > I finally got around to my upgrade to 2.11-20130405 and was watching > > logs. A gmail message fell afoul of the after-220 tests; each time it > > came from a different host. Each one got a "PASS NEW" and of course >

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Wietse Venema
> > After sending END-OF-MESSAGE, the Postfix smtpd_proxy_CLIENT closes > > the SMTP connection to the before-queue content filter. > > And this is exactly the problem: smtpd_proxy_CLIENT closes the If you have a problem with "disconnect without quit", then you are spending too much time in the

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Viktor Dukhovni
On Tue, Apr 23, 2013 at 10:52:02PM +0200, Michael Storz wrote: > >After sending END-OF-MESSAGE, the Postfix smtpd_proxy_CLIENT closes > >the SMTP connection to the before-queue content filter. > > And this is exactly the problem: smtpd_proxy_CLIENT closes the > connection without sending > the QU

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Michael Storz
Am 2013-04-23 14:22, schrieb Wietse Venema: > Apr 22 14:20:08 dedi postfix/smtpd[2974]: smtp_get: timeout > Apr 22 14:20:08 dedi postfix/smtpd[2974]: > > dedi.ludosoft.org[127.0.0.1]: 421 4.4.2 dedi.ludosoft.org Error: > timeout exceeded > Apr 22 14:20:08 dedi postfix/smtpd[2974]: match_hostname:

New Postfix log analyzer tool V0.9.13 released (PostgreSQL DB 9.2.x based)

2013-04-23 Thread Nicolas HAHN
Dear Community, VERSION 0.9.13 of the tool has been released. My tool is able to parse Postfix Logs (version < 2.8 for now), generates statistics, propose you a great EXTJS 4.1.3 Web 2.0 interface, offers powerfull search features and so on... It is also able to parse Microsoft Exchange Server

Re: Correlate client IP address with queue ID

2013-04-23 Thread Rolf E. Sonneveld
On 04/23/2013 10:14 PM, Wietse Venema wrote: Rolf E. Sonneveld: Apr 23 20:26:38 helium postfix-cust1/smtpd[9220]: 3ZwCmG272nz1L8Zd: client=D57E1702.static.ziggozakelijk.nl[213.126.23.2] The above logging gives you the link between client and queue ID. client = D57E1702.static.ziggozakel

Re: Correlate client IP address with queue ID

2013-04-23 Thread Wietse Venema
Rolf E. Sonneveld: > Apr 23 20:26:38 helium postfix-cust1/smtpd[9220]: 3ZwCmG272nz1L8Zd: > client=D57E1702.static.ziggozakelijk.nl[213.126.23.2] The above logging gives you the link between client and queue ID. client = D57E1702.static.ziggozakelijk.nl[213.126.23.2] queue ID = 3ZwCmG27

Re: Correlate client IP address with queue ID

2013-04-23 Thread /dev/rob0
On Tue, Apr 23, 2013 at 09:45:02PM +0200, Rolf E. Sonneveld wrote: > running Postfix 2.10.0, see for output postconf -n below. > > What I want to achieve is to track and trace a message from first > connection until final delivery, _including the client IP address_ > that enqueued the message. T

Correlate client IP address with queue ID

2013-04-23 Thread Rolf E. Sonneveld
Hi, all running Postfix 2.10.0, see for output postconf -n below. What I want to achieve is to track and trace a message from first connection until final delivery, _including the client IP address_ that enqueued the message. The queue ID is very useful to correlate a number of log records. H

Re: Postscreen DNSBL Sites

2013-04-23 Thread /dev/rob0
On Tue, Apr 23, 2013 at 11:41:42AM -0700, Steve Jenkins wrote: > On Tue, Apr 23, 2013 at 11:23 AM, /dev/rob0 wrote: > > > Looks very similar to mine, http://rob0.nodns4.us/postscreen.html > > > > > postscreen_dnsbl_threshold = 3 [snip] > > I'm fine with blocking for Zen alone, thus I give it 3. O

Re: "421 4.4.2" (fqdn hostname) "Error: timeout exceeded" with ssl

2013-04-23 Thread Juri Grabowski
The problem is solved, thanks for yours hints. It is too bad connection to server and few RAM. The following lines should help other people by the same problem. /etc/postfix/main.cf +smtpd_timeout = ${stress?300}${stress:300}s +address_verify_poll_count = ${stress?5}${stress:5} +smtpd_hard_error_

Re: Postscreen DNSBL Sites

2013-04-23 Thread Steve Jenkins
On Tue, Apr 23, 2013 at 11:23 AM, /dev/rob0 wrote: > Looks very similar to mine, http://rob0.nodns4.us/postscreen.html > > > postscreen_dnsbl_threshold = 3 > > postscreen_dnsbl_sites = > > zen.spamhaus.org*2, > > b.barracudacentral.org*2, > > dnsbl.mjabl.org, > > What? $ w

Re: Postscreen DNSBL Sites

2013-04-23 Thread DTNX Postmaster
On Apr 23, 2013, at 20:23, /dev/rob0 wrote: >> postscreen_dnsbl_threshold = 3 >> postscreen_dnsbl_sites = >>zen.spamhaus.org*2, >>b.barracudacentral.org*2, >>dnsbl.mjabl.org, > > What? $ whois mjabl.org >

Re: Postscreen DNSBL Sites

2013-04-23 Thread DTNX Postmaster
On Apr 23, 2013, at 19:42, Steve Jenkins wrote: > I recently removed TRBLSPAM from my postscreen_dnsbl_sites lists after they > went offline earlier this month (this should be a reminder to do the same for > anyone here who also used them). That got me wondering about what DNSBL sites > others

Re: Postscreen DNSBL Sites

2013-04-23 Thread /dev/rob0
On Tue, Apr 23, 2013 at 10:42:36AM -0700, Steve Jenkins wrote: > I recently removed TRBLSPAM from my postscreen_dnsbl_sites lists > after they went offline earlier this month (this should be a > reminder to do the same for anyone here who also used them). That > got me wondering about what DNSBL

Re: Add a log line in postfix logs

2013-04-23 Thread DTNX Postmaster
On Apr 23, 2013, at 19:23, Abhijeet Rastogi wrote: > So, what exactly is the solution now? My sole requirement is getting > "queueid", "from" and "to" in the same log line. Getting other headers > is just a secondary thing. Parse the logs, or write/use an external program that integrates with P

Re: Add a log line in postfix logs

2013-04-23 Thread Wietse Venema
Abhijeet Rastogi: > I missed one thing. I can't even use "to:" as it's not a required > header. So, I thought of using "Received;" header. That'll work most > of the times but then there is another issue now. > > Doc says that: > > Each message header or message body line is compared >

Re: PATCH: Odd trivial-rewrite complaint

2013-04-23 Thread Quanah Gibson-Mount
--On Tuesday, April 23, 2013 1:45 PM -0400 Wietse Venema wrote: Quanah Gibson-Mount: Apr 22 14:42:50 zqa-061 postfix/trivial-rewrite[30487]: warning: do not list domain zqa-061.eng.vmware.com in BOTH mydestination and virtual_mailbox_domains ... mydestination = localhost This may happen w

PATCH: Odd trivial-rewrite complaint

2013-04-23 Thread Wietse Venema
Quanah Gibson-Mount: > Apr 22 14:42:50 zqa-061 postfix/trivial-rewrite[30487]: warning: do not > list domain zqa-061.eng.vmware.com in BOTH mydestination and > virtual_mailbox_domains ... > mydestination = localhost This may happen with any Postfix release when $myhostname is not listed in mydes

Postscreen DNSBL Sites

2013-04-23 Thread Steve Jenkins
I recently removed TRBLSPAM from my postscreen_dnsbl_sites lists after they went offline earlier this month (this should be a reminder to do the same for anyone here who also used them). That got me wondering about what DNSBL sites others have been successfully using with Postscreen. Here's my cur

Re: Add a log line in postfix logs

2013-04-23 Thread Abhijeet Rastogi
I missed one thing. I can't even use "to:" as it's not a required header. So, I thought of using "Received;" header. That'll work most of the times but then there is another issue now. Doc says that: Each message header or message body line is compared against a list of patterns. Wh

Re: Add a log line in postfix logs

2013-04-23 Thread Abhijeet Rastogi
Hi, Thanks all for your reply. I mistyped "/^to:/" (actually it was Subject only) because I was testing with ways to display "from" and "to" (my original intent) in logs and WARN was not getting executed when email had no Subject. Regarding the argument that they all come from different parts of

Re: Add a log line in postfix logs

2013-04-23 Thread /dev/rob0
On Tue, Apr 23, 2013 at 08:10:19PM +0530, Abhijeet Rastogi wrote: > How flexible is postfix-2.8.7 to add one more log line in logs. > > My requirement is to have a line which will contain "queueid", > "form", "to" & "subject" header in the same log line. > > If I add in header_checks a line like:

Re: Add a log line in postfix logs

2013-04-23 Thread Reindl Harald
Am 23.04.2013 16:40, schrieb Abhijeet Rastogi: > How flexible is postfix-2.8.7 to add one more log line in logs. > > My requirement is to have a line which will contain "queueid", "form", > "to" & "subject" header in the same log line the problem is that the specific lines are from different pr

Add a log line in postfix logs

2013-04-23 Thread Abhijeet Rastogi
Hi all, How flexible is postfix-2.8.7 to add one more log line in logs. My requirement is to have a line which will contain "queueid", "form", "to" & "subject" header in the same log line. If I add in header_checks a line like: /^to:/ WARN I get what I want but it also adds other stuff like "

Re: "421 4.4.2" (fqdn hostname) "Error: timeout exceeded" with ssl

2013-04-23 Thread Viktor Dukhovni
On Tue, Apr 23, 2013 at 11:05:14AM +0200, Juri Grabowski wrote: > On Mon, Apr 22, 2013 at 02:41:56PM -0400, Wietse Venema wrote: > address_verify_negative_expire_time = 2m > address_verify_negative_refresh_time = 1m A 2 minute timeout seems rather aggressive to me. Try 15 minutes or more, in pra

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Ludovic LEVET
Hi Wietse, I'm agree with you, after sending END-OF-MESSAGE, the Postfix smtpd_proxy_CLIENT closes the SMTP connection to the before-queue content filter without sending QUIT command and wait for a 221 reply. But Postfix smtpd complain to be compatible with ESMTP protocol (http://www.postfix

Re: Odd trivial-rewrite complaint with postfix 2.10

2013-04-23 Thread btb
On 2013.04.22 13.35, Quanah Gibson-Mount wrote: This started showing up sporadically in our logs after upgrading to postfix 2.10: Apr 22 14:42:50 zqa-061 postfix/trivial-rewrite[30487]: warning: do not list domain zqa-061.eng.vmware.com in BOTH mydestination and virtual_mailbox_domains However,

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Wietse Venema
> > Apr 22 14:20:08 dedi postfix/smtpd[2974]: smtp_get: timeout > > Apr 22 14:20:08 dedi postfix/smtpd[2974]: > > > dedi.ludosoft.org[127.0.0.1]: 421 4.4.2 dedi.ludosoft.org Error: > > timeout exceeded > > Apr 22 14:20:08 dedi postfix/smtpd[2974]: match_hostname: > > dedi.ludosoft.org ~? 127.0.0.0/

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Bastian Blank
Don't send copies, I'm subscribed. On Tue, Apr 23, 2013 at 01:01:20PM +0200, Ludovic LEVET wrote: > The transcription is on mail first mail : This is no transcript. This is several smtpd sessions intermingled. > Why nobody complain ? the response is in the session transcription : > ... > Apr 22

Re: loops back to myself

2013-04-23 Thread Noel Jones
On 4/23/2013 12:26 AM, Feel Zhou wrote: > Hello, my friend > This is tom, I'm sending my greeting from China > I got some problem, and need your help > This mail is in the queue, but I hold it,just like that > C94C6AC00D4!3372 Wed Apr 17 19:07:51 MAILER-DAEMON >

Re: Short burst of errors

2013-04-23 Thread Noel Jones
On 4/23/2013 5:09 AM, Embedding Linux wrote: > Hello, > > Yesterday, our postfix did print some fatal errors, during > approximatively 45 minutes. The errors are all identical, about the > inet_interfaces variable : > > Apr 22 16:45:36 my_server postfix/flush[10510]: fatal: config variable > inet

Re: "421 4.4.2" (fqdn hostname) "Error: timeout exceeded" with ssl

2013-04-23 Thread Wietse Venema
Juri Grabowski: > On Mon, Apr 22, 2013 at 02:41:56PM -0400, Wietse Venema wrote: > > Perhaps you did not notice that you should send "postconf -n" output. > thanks for the hint, here is "postconf -n" output: What does the server log when a client connects and times out? Show complete logfile recor

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Ludovic LEVET
Hi Bastian, The transcription is on mail first mail : A copy : Debug : Before with postfix 2.6.18 : ... Apr 22 14:36:47 dedi dkimproxy.in[18373]: DKIM verify - none; from= Apr 22 14:36:47 dedi postfix/cleanup[4973]: B2FCF261729: message-id=<20130422123631.b2fcf26

Re: Short burst of errors

2013-04-23 Thread Ludovic LEVET
Hi, The best is to put your fqdn in your /etc/hosts to avoid this problem. Ludo. Le 23/04/2013 12:35, Embedding Linux a écrit : Hi, On 23/04/13 12:13, Bastian Blank wrote: On Tue, Apr 23, 2013 at 12:09:19PM +0200, Embedding Linux wrote: Apr 22 16:45:36 my_server postfix/flush[10510]: fatal:

Re: Short burst of errors

2013-04-23 Thread Embedding Linux
Hi, On 23/04/13 12:13, Bastian Blank wrote: > On Tue, Apr 23, 2013 at 12:09:19PM +0200, Embedding Linux wrote: >> Apr 22 16:45:36 my_server postfix/flush[10510]: fatal: config variable >> inet_interfaces: host not found: server.fqdn.name > > Not quite unexpected: > | $ drill server.fqdn.name > |

Re: Short burst of errors

2013-04-23 Thread Bastian Blank
On Tue, Apr 23, 2013 at 12:09:19PM +0200, Embedding Linux wrote: > Apr 22 16:45:36 my_server postfix/flush[10510]: fatal: config variable > inet_interfaces: host not found: server.fqdn.name Not quite unexpected: | $ drill server.fqdn.name | ;; ->>HEADER<<- opcode: QUERY, rcode: SERVFAIL, id: 4402

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Bastian Blank
Please fix your MUA, it produces TOFU. On Tue, Apr 23, 2013 at 11:48:42AM +0200, Ludovic LEVET wrote: > This is not a reply ... Not showing what the actual problem is, is no question either. Especially, why are you the only person experiencing this in over three years? > http://www.ietf.org/rfc/

Short burst of errors

2013-04-23 Thread Embedding Linux
Hello, Yesterday, our postfix did print some fatal errors, during approximatively 45 minutes. The errors are all identical, about the inet_interfaces variable : Apr 22 16:45:36 my_server postfix/flush[10510]: fatal: config variable inet_interfaces: host not found: server.fqdn.name The error mess

Re: postfix 2.8 and upper don't close connection with smtpd_proxy_filter

2013-04-23 Thread Ludovic LEVET
This is not a reply ... http://www.ietf.org/rfc/rfc5321.txt Chapter 4.1.1.10. If we can't write proper code and respect RFC for interoperability, the better is to change of work ... We are not in the world of Microsoft, and made what we want like we want and the rest of the world must be comp

Re: "421 4.4.2" (fqdn hostname) "Error: timeout exceeded" with ssl

2013-04-23 Thread Juri Grabowski
On Mon, Apr 22, 2013 at 02:41:56PM -0400, Wietse Venema wrote: > Perhaps you did not notice that you should send "postconf -n" output. thanks for the hint, here is "postconf -n" output: address_verify_map = btree:$data_directory/verify_cache address_verify_negative_cache = yes address_verify_negat

Re: File descriptor issue in Solaris 11.1 ?

2013-04-23 Thread Jaco Lesch
Wietse Thanks, the upgrade to Postfix 2.10 on Solaris 11.1 resolved the "file descriptor" issue. The recommendation to disable connection caching helped for the smtpd process, but other processes still complained on Postfix 2.9.4. Regards On 15/04/2013 16:16, Wietse Venema wrote: Jaco Le