[pfx] Re: multiple certs for postfix

2024-08-17 Thread Michael W. Lucas via Postfix-users
On Sat, Aug 17, 2024 at 02:11:37PM +0800, Wesley via Postfix-users wrote: > Yes. The current hosting I am using is with a simple case: > > mail.riseup.net > smtp.riseup.net > > Both works via SSL. > > If the hosts are: > > mail.foo.com > smtp.bar.com > > That is a more complicated case. > Wher

[pfx] Re: multiple certs for postfix

2024-08-16 Thread Michael W. Lucas via Postfix-users
I'd suggest you use a single X.509 certificate with multiple SANs. ACME supports creating such certificates. ==ml On Sat, Aug 17, 2024 at 08:50:37AM +0800, Wesley via Postfix-users wrote: > for submissions service, some providers can use multi-domains for client > access. for example, > > mail.

[pfx] Re: question about postmaster account

2024-07-28 Thread Michael W. Lucas via Postfix-users
On Sun, Jul 28, 2024 at 10:03:05AM +0200, Ralph Seichter via Postfix-users wrote: > * Walt E. via Postfix-users: > > > Is there any standard that, postmaster@domain is a required account > > for this domain? > > Yes. The requirement has been specified as early as 1981 in RFC 822, and > in its su

[pfx] Re: mta-sts and smtp_tls_security_level

2024-03-08 Thread Michael W. Lucas via Postfix-users
On Fri, Mar 08, 2024 at 03:05:43PM -0500, Viktor Dukhovni via Postfix-users wrote: > On Fri, Mar 08, 2024 at 01:28:00PM -0500, Michael W. Lucas via Postfix-users > wrote: > > > Realistically, Gmail and Yahoo do not care about my MTA-STS > > reports. All they care about is

[pfx] mta-sts and smtp_tls_security_level

2024-03-08 Thread Michael W. Lucas via Postfix-users
Hi, Pondering MTA-STS validation. My understanding is the recommendation is to use DANE as the default (smtp_tls_security_level=dane), but if you want MTA-STS for select domains you can point them at a transport that requires X.509 validation. Realistically, Gmail and Yahoo do not care about my

[pfx] Re: Which DKIM application for postfix 3.9.0

2024-03-07 Thread Michael W. Lucas via Postfix-users
On Thu, Mar 07, 2024 at 03:06:45PM -0700, postfix--- via Postfix-users wrote: > I am upgrading to postfix 3.9.0. > > I have not used DKIM in previous postfix installs, but I would like to start > now with the new google rules. > > I have done some research and opendkim is the most recommended, ho

[pfx] sending not trying TLS?

2024-02-15 Thread Michael W. Lucas via Postfix-users
Hi, Running 3.8 on FreeBSD 14, with postfixadmin 3.4. I'm trying to send a message and got this bounce message. : host mx.nixnet.email[5.161.67.119] said: 530 5.7.0 Must issue a STARTTLS command first (in reply to MAIL FROM command) The default maillog is not any more helpful. Feb 15 14:52:05

[pfx] Re: 25 years today

2023-12-14 Thread Michael W. Lucas via Postfix-users
Congratulations, and thank you! And for 25 years, you have been politely answering user questions about it. I believe this makes you eligible for sainthood. :-) ==ml -- Michael W. Lucashttps://mwl.io/ author of: Absolute OpenBSD, SSH Mastery, git commit murder, Absolute FreeBSD, But

[pfx] Re: read postscreen database?

2023-10-31 Thread Michael W. Lucas via Postfix-users
On Tue, Oct 31, 2023 at 12:56:23PM -0400, Wietse Venema via Postfix-users wrote: > Michael W. Lucas via Postfix-users: > > Hi, > > > > Is there a way to dump the postscreen database, showing which > > addresses are cached and why? > > > > Running postfix 3

[pfx] read postscreen database?

2023-10-31 Thread Michael W. Lucas via Postfix-users
Hi, Is there a way to dump the postscreen database, showing which addresses are cached and why? Running postfix 3.8 on FreeBSD. Thanks, ==ml -- Michael W. Lucashttps://mwl.io/ author of: Absolute OpenBSD, SSH Mastery, git commit murder, Absolute FreeBSD, Butterfly Stomp Waltz, Forever

[pfx] Re: A new Postfix book in the making - "Run Your Own Mail Server"

2023-08-06 Thread Michael W. Lucas via Postfix-users
On Sun, Aug 06, 2023 at 01:57:34PM -0500, Scott Techlist via Postfix-users wrote: > >>Michael W. Lucas is writing a book about "Run Your Own Mail Server" > >>featuring the Postfix mail server. Michael has written and published a > >>Chapter 0 that gives an impression what the book will contain. Be