Re: TLSA debugging

2021-08-25 Thread Bastien Durel
Le mardi 24 août 2021 à 11:02 -0400, Viktor Dukhovni a écrit : > On Tue, Aug 24, 2021 at 04:24:30PM +0200, Bastien Durel wrote: > > Hello, > > > > Since I upgraded to debian 11 (postfix 3.5.6, was 3.4.14), my > > cluster > > fails inter-node deliveries. > >

TLSA debugging

2021-08-24 Thread Bastien Durel
Hello, Since I upgraded to debian 11 (postfix 3.5.6, was 3.4.14), my cluster fails inter-node deliveries. I have TLSA errors in logs: Aug 24 16:09:26 arrakeen postfix/cluster/smtp[992382]: warning: TLS policy lookup error for [corrin.geekwu.org]:26/corrin.geekwu.org: no TLSA records found Aug 2

Re: TLSv1.2 only for auth connection

2018-10-25 Thread Bastien Durel
Le jeudi 25 octobre 2018 à 15:31 +0200, Matus UHLAR - fantomas a écrit : > maybe port 465 was originally taken (by microsoft, btw) for server- > to-server > smtp over ssl, but I think I ever saw anyone using it as such. > > for now, many companies use port 465 as authenticated submission-only > p

message_size_limit

2017-11-27 Thread Bastien Durel
Hello, I have 2 questions about message_size_limit : - is there a value meaning "unlimited ?" - can it be configured with a table, so it may differ from account to account ? Thanks, -- Bastien

Re: how to reject disabled LDAP users

2017-10-03 Thread Bastien Durel
d)) result_attribute = uid result_format = discard: (Actually I discard mails, I do not reject them) It's plugged in main.cf as this : transport_maps = ldap:/etc/postfix/ldap-trash.cf, ldap:/etc/postfix/ldap-virtual-transport.cf, ldap:/etc/postfix/ldap- local-transport.cf Regards, -- Bastien Dur

Re: don't use ADH in server-to-server

2017-07-06 Thread Bastien Durel
n client config is what I needed, thanks :) -- Bastien Durel

don't use ADH in server-to-server

2017-07-06 Thread Bastien Durel
Hello, I have a setup where a MTA will forward mail to another node, based on ldap configuration. It works well, but it uses ADH Received: from corrin.geekwu.org (unknown [87.98.180.13]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate req

Relay loop

2014-08-28 Thread Bastien Durel
Hello. I'm trying to enable SRS for external aliases, but not for intra-cluster communication (mailboxes are split on different hosts, and mails are forwared on the right one if the come by another node) I disabled virtual_alias_maps in general smtpd, I've added a map in transport_maps which matc