Backup MX whitelisted by primary MX: Open hole for spam?

2014-05-09 Thread deoren
Setup: * backup MX with light anti-spam policies (for the moment) * primary MX with current policies. Also whitelists the backup MX via check_client_access directive and via permit_mynetworks Question: If a spam email makes it "in" through the backup MX and is delivered to the primary, wil

Inbound email delay

2014-05-09 Thread kornsnap
Hello, We recently moved our postfix smtp gateway to point to our new Exchange 2010 environment and have incurred significant delays. The delay are inbound only and from what I've ready the delay seems to be in the "time in queue manager". I am not familiar with postifix and information would be

Re: Client side DANE - minimum openssl version

2014-05-09 Thread Andreas Schulze
Viktor Dukhovni: > It may be simpler to upgrade your system. yes, upgrade would be best but sometimes, older crypto is not as painfull as it should be Andreas

Re: Client side DANE - minimum openssl version

2014-05-09 Thread Viktor Dukhovni
On Fri, May 09, 2014 at 10:58:30AM -0400, Wietse Venema wrote: > > Any hint's to build postfix + openssl-1.x on a system based on > > openssl-0.9.x ??? I also avoided building openssl from source for > > good reasons over the last years. It is rather easy to build on Unix-like systems. Unpack t

Re: Client side DANE - minimum openssl version

2014-05-09 Thread Wietse Venema
Andreas Schulze: > Robert Schetterer: > > > openssl 0.9.8j and Postfix 2.11.1. > > maybe a suboptimal mixture > > any hint's to build postfix + openssl-1.x on a system based on > openssl-0.9.x ??? I also avoided building openssl from source for > good reasons over the last years. > > But I'm open

Re: Client side DANE - minimum openssl version

2014-05-09 Thread Andreas Schulze
Robert Schetterer: > > openssl 0.9.8j and Postfix 2.11.1. > maybe a suboptimal mixture any hint's to build postfix + openssl-1.x on a system based on openssl-0.9.x ??? I also avoided building openssl from source for good reasons over the last years. But I'm open to try. Andreas

Re: Postfix dynamicmaps.cf support

2014-05-09 Thread Wietse Venema
Viktor Dukhovni: > On Thu, May 08, 2014 at 08:13:00PM -0400, Wietse Venema wrote: > > > postfix-files can be shared because it references files that are > > shared. > > > > dynamicmaps.cf can be shared provided as you ALSO share the > > dynamicmaps.cf plugins by ALSO putting them into $daemon_di

Re: Using check_policy_service for greylisting with sqlgrey

2014-05-09 Thread Wietse Venema
Alex: > When I run it manually from the command-line, it reports that it's binded > successfully to the postfix socket. Then, you cannot run it under the spawn daemon, which requires that the program reads and writes (NOT LISTENS) on stdin/stdout. Wietse

Re: Setting the domain name of outgoing e-mail

2014-05-09 Thread li...@rhsoft.net
Am 08.05.2014 20:33, schrieb Gabor Szabo: > Jan, thanks for the suggestions. > Adding [::1]/128 to mynetworks solved the problem. > > On Thu, May 8, 2014 at 7:07 PM, li...@rhsoft.net wrote: >> >> Am 08.05.2014 18:02, schrieb Gabor Szabo: >>> So let me show you the real problem >> >> why did y