Re: "Correct" way to override cipher list?

2021-10-29 Thread Viktor Dukhovni
On Fri, Oct 29, 2021 at 10:39:50PM -0700, Dan Mahoney wrote: > >> tls_export_cipherlist = aNULL:-aNULL:HIGH:MEDIUM:LOW:EXPORT:+RC4:@STRENGTH > > > > The export and low ciphers are no longer supported by OpenSSL (1.1.x and > > 3.0.0), the parameters are dead code, but no need to remove them, just

Re: "Correct" way to override cipher list?

2021-10-29 Thread Dan Mahoney
> On Oct 29, 2021, at 10:01 PM, Viktor Dukhovni > wrote: > > On Fri, Oct 29, 2021 at 08:36:38PM -0700, Dan Mahoney (Gushi) wrote: > >> I see sites like cipherlist.eu suggesting overriding the "medium" cipher >> set to only be: > > Ignore much of their misguided advice.. >> When I look at

Re: "Correct" way to override cipher list?

2021-10-29 Thread Viktor Dukhovni
On Fri, Oct 29, 2021 at 08:36:38PM -0700, Dan Mahoney (Gushi) wrote: > I see sites like cipherlist.eu suggesting overriding the "medium" cipher > set to only be: Ignore much of their misguided advice.. > smtpd_use_tls = yes > smtpd_tls_security_level = may These are fine. > smtpd_tls_protocol

"Correct" way to override cipher list?

2021-10-29 Thread Dan Mahoney (Gushi)
Hey there all, I'm in the process of vetting historical postfix configs -- comparing so many things in a historic config where prior employees overrode the defaults and perhaps why. Wietse, let me say thank you for making it easier than it would be with sendmail.cf :) I see sites like ciph

Re: Nessus says I have an open relay

2021-10-29 Thread White, Daniel E. (GSFC-770.0)[NICS]
AFAIK, it is on a different subnet than the ones in "mynetworks" I can triple check with the team that runs them. -Original Message- From: on behalf of Matus UHLAR - fantomas Date: Friday, October 29, 2021 at 06:40 To: "postfix-users@postfix.org" Subject: [EXTERNAL] Re: Nessus says I h

Re: Nessus says I have an open relay

2021-10-29 Thread Matus UHLAR - fantomas
On 29.10.21 10:33, White, Daniel E. (GSFC-770.0)[NICS] wrote: Nessus Plugin 10167: NTMail3 Arbitrary Mail Relay TCP post 25 [...] Nessus Plugin 11852: MTA Open Mail Relaying Allowed (thorough test) TCP port 25 Plugin Output: Nessus was able to relay mails by sending those sequences : [...]

Nessus says I have an open relay

2021-10-29 Thread White, Daniel E. (GSFC-770.0)[NICS]
Two "findings" Nessus Plugin 10167: NTMail3 Arbitrary Mail Relay TCP post 25 An open SMTP relay is running on the remote host. Nessus has detected that the remote SMTP server allows anyone to use it as a mail relay provided that the source address is set to '<>'. This issue allows any spammer

Re: delete from hold queue

2021-10-29 Thread richard lucassen
On Fri, 29 Oct 2021 00:24:36 -0400 Viktor Dukhovni wrote: > On Thu, Oct 28, 2021 at 10:14:15PM -0400, Viktor Dukhovni wrote: > > > postqueue -j | jq -nr --argjson $days ' > > Correction, that first line should be: > > postqueue -j | jq -nr --argjson days $days ' > > Setting the "jq"

Re: Postfix with Kibana, help with configuration?

2021-10-29 Thread Tom Hendrikx
On 27-10-2021 07:43, raf wrote: On Tue, Oct 26, 2021 at 02:01:11PM -0300, SysAdmin EM wrote: Hello everyone? Has anyone correctly configured kibana to read postfix logs? I read this documentation, but in kibana 7 not work for me. https://github.com/whyscream/postfix-grok-patterns postfix_