Re: Yet another relay access denied problem

2014-12-30 Thread li...@rhsoft.net
Am 31.12.2014 um 05:58 schrieb Thom Miller: On 12/30/2014 09:35 PM, Jonathan Hermann wrote: Ok, then it's by design. So spamassassin/amavis will have to do. don't get me wrong but re-consider setup a complex, public reachable mailserver without have *basic* understanding how email works at a

Re: Migration from qmail to postfix

2014-12-30 Thread Nickitas
Hi Viktor , I am using virtual alias maps for lookup , and I can see at the debug log that forwarding mail addresses and alternate addresses are calculated correctly . Anyway I got a idea yesterday (to disable amavis-new) , so after that postfix , delivered the emails correctly to all mailboxes .

Re: DNSSEC - DANE

2014-12-30 Thread John
/smtpd_tls_security_level = dane/. postconf does not show any error for the above, but postfix itself does "fatal: invalid TLS level "dane" - I have switched back to may -- John Allen KLaM -- You are off the edge of the map, mate. Here there be monsters!

Re: DNSSEC - DANE

2014-12-30 Thread John
https://tools.ietf.org/draft-ietf-dane-ops-07#section-8.1 https://tools.ietf.org/draft-ietf-dane-ops-07#section-8.4 Both of the above return "object not found" I assume that as they are both draft docs they come and go as the editors update them. I will keep an eye on the site, hopefully catch t

Re: DNSSEC - DANE

2014-12-30 Thread John
On 12/30/2014 11:19 PM, Viktor Dukhovni wrote: On Tue, Dec 30, 2014 at 07:47:24PM -0500, John wrote: I have setup my DNS server for DNSSEC + DANE. I am using inline signing on Bind9 and it appears to be working for HTTPS access. I have a minor problem with key rolling, it seems to be a rather c

Re: Yet another relay access denied problem

2014-12-30 Thread Thom Miller
On 12/30/2014 09:35 PM, Jonathan Hermann wrote: > Ok, then it's by design. So spamassassin/amavis will have to do. > > Thanks everybody for your time and input. Really appreciate it! > > Regards > Nathan > > > Am 28.12.2014 um 21:50 schrieb Wietse Venema: >> Jonathan Hermann: >>> I can send m

Re: Yet another relay access denied problem

2014-12-30 Thread Jonathan Hermann
Ok, then it's by design. So spamassassin/amavis will have to do. Thanks everybody for your time and input. Really appreciate it! Regards Nathan Am 28.12.2014 um 21:50 schrieb Wietse Venema: Jonathan Hermann: I can send mail from an external source (e.g. mail client on my notebook) to a local

Re: DNSSEC - DANE

2014-12-30 Thread Viktor Dukhovni
On Tue, Dec 30, 2014 at 07:47:24PM -0500, John wrote: > I have setup my DNS server for DNSSEC + DANE. I am using inline signing on > Bind9 and it appears to be working for HTTPS access. > I have a minor problem with key rolling, it seems to be a rather cumbersome > process at the moment, but I sus

Re: DNSSEC - DANE

2014-12-30 Thread John
On 12/30/2014 7:58 PM, wie...@porcupine.org (Wietse Venema) wrote: Wietse Venema: John: *Dec 30 19:16:35 bilbo postfix/smtp[3376]: warning: [127.0.0.1]:10024: dane configured with dnssec lookups disabled* Have you noticed the "unused parameter" warning for smtp_dns_supporta_level? That is, wh

Re: DNSSEC - DANE

2014-12-30 Thread Wietse Venema
Wietse Venema: > John: > > *Dec 30 19:16:35 bilbo postfix/smtp[3376]: warning: [127.0.0.1]:10024: > > dane configured with dnssec lookups disabled* > > Have you noticed the "unused parameter" warning for smtp_dns_supporta_level? That is, when you use the postconf command to show the configurati

Re: DNSSEC - DANE

2014-12-30 Thread Wietse Venema
John: > *Dec 30 19:16:35 bilbo postfix/smtp[3376]: warning: [127.0.0.1]:10024: > dane configured with dnssec lookups disabled* Have you noticed the "unused parameter" warning for smtp_dns_supporta_level? Wietse

DNSSEC - DANE

2014-12-30 Thread John
I have setup my DNS server for DNSSEC + DANE. I am using inline signing on Bind9 and it appears to be working for HTTPS access. I have a minor problem with key rolling, it seems to be a rather cumbersome process at the moment, but I suspect that it is me rather than the process. Having got it

Re: post-install not working when hostname is numeric

2014-12-30 Thread li...@rhsoft.net
Am 31.12.2014 um 01:00 schrieb Tomas Carnecky: I was trying to install postfix into an VM image which used an auto-generated hostname. It happened that the hostname was fully numeric (7593408), and the post-install script failed to execute properly. Here's an excerpt from the install log: inst

Re: post-install not working when hostname is numeric

2014-12-30 Thread Wietse Venema
Tomas Carnecky: > I was trying to install postfix into an VM image which used an > auto-generated hostname. It happened that the hostname was fully numeric > (7593408), and the post-install script failed to execute properly. Here's > an excerpt from the install log: Postfix requires that the myhos

post-install not working when hostname is numeric

2014-12-30 Thread Tomas Carnecky
I was trying to install postfix into an VM image which used an auto-generated hostname. It happened that the hostname was fully numeric (7593408), and the post-install script failed to execute properly. Here's an excerpt from the install log: installing postfix... /usr/bin/postconf: warning: valid

Re: Migration from qmail to postfix

2014-12-30 Thread Viktor Dukhovni
On Tue, Dec 30, 2014 at 09:29:38AM +0200, Nickitas wrote: > I know that postfix does not include a ldap schema (i wish it did > though , it would make things simpler) . I have done almost all db > related stuff already ( authentication , domain and user lookup ) , I am > only - for the time being

Re: Migration from qmail to postfix

2014-12-30 Thread Nickitas
Hi Viktor , Thanx for clearing some things out :) Regards, Nickitas On 29/12/2014 06:07 μμ, Viktor Dukhovni wrote: > On Mon, Dec 29, 2014 at 04:45:32PM +0100, postfix wrote: > >> Hi Nickitas >> we use postfix at our site and all mail parameters are in the openldap >> server. Because postfix ha

Re: Migration from qmail to postfix

2014-12-30 Thread Nickitas
Hi Suomi , I have more or less the same ldap lookups set up already , I am only using a more strict query filter and another scope . This does not solve my forwarding problem , I ve seen it working in zimbra that uses postfix , however I was not able to figure it out how it was implemented . Tha