sasldb or PAM

2011-11-07 Thread gaby
Hi I use PAM authentication method for send emal via postfix with Cyrus Sasl. If use sasldb2 method instead PAM,it is more secure, or more Ok?Sasdb is more usable? Thanks

Re: sasldb or PAM

2011-11-07 Thread Patrick Ben Koetter
* gaby : > I use PAM authentication method for send emal via postfix with Cyrus Sasl. > If use sasldb2 method instead PAM,it is more secure, or more Ok?Sasdb is > more usable? There are two sections you need to pay attention for: 1. Transmission of identification data over the network 2. Stor

dkim-milter verify, but don't sign.

2011-11-07 Thread Josef Karliak
Good morning, I configured dkim-milter (2.7.2-x) to postfix (2.7.2-x) on opensuse 11.4 64-bit, generated keys (named "mail"). In the dkim-milter config I defined my options: DKIM_MODES="sv" DKIM_DOMAIN="ajetaci.cz" DKIM_SELECTOR="mail" DKIM_CANON="simple" DKIM_REJECTION="bad=a,dns=t,no=a,

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Robert Schetterer
Am 07.11.2011 10:39, schrieb Josef Karliak: > Good morning, > I configured dkim-milter (2.7.2-x) to postfix (2.7.2-x) on opensuse > 11.4 64-bit, generated keys (named "mail"). In the dkim-milter config I > defined my options: > DKIM_MODES="sv" > DKIM_DOMAIN="ajetaci.cz" > DKIM_SELECTOR="mail" >

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Robert Schetterer
Am 07.11.2011 10:46, schrieb Robert Schetterer: > Am 07.11.2011 10:39, schrieb Josef Karliak: >> Good morning, >> I configured dkim-milter (2.7.2-x) to postfix (2.7.2-x) on opensuse >> 11.4 64-bit, generated keys (named "mail"). In the dkim-milter config I >> defined my options: >> DKIM_MODES="

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Josef Karliak
Hi, modes "sv" is configured - see my config bellow. That's crazy on that. When I "ps -ef" : /usr/bin/dkim-filter -p inet:8891@localhost -b sv -c simple -C bad=a,dns=t,no=a,sec=t -d ajetaci.cz -S rsa-sha256 -s mail -k /etc/mail/dkim/mail.private -l -h -D Thanks J.K. Cituji Robert

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Josef Karliak
Hi, modes "sv" is configured - see my config bellow. That's crazy on that. When I "ps -ef" : /usr/bin/dkim-filter -p inet:8891@localhost -b sv -c simple -C bad=a,dns=t,no=a,sec=t -d ajetaci.cz -S rsa-sha256 -s mail -k /etc/mail/dkim/mail.private -l -h -D Thanks J.K. Cituji Robert

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Josef Karliak
In the message header I've : X-DKIM: Sendmail DKIM Filter v2.7.2 kostnew.ajetaci.cz 8840B239C3 Authentication-Results: kostnew.ajetaci.cz; dkim=none (no signature) header.i=unknown; dkim-adsp=fail And in the mail log: Nov 7 10:48:37 kostnew dkim-filter[16623]: 8840B239C3 external host [192

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Robert Schetterer
Am 07.11.2011 10:56, schrieb Josef Karliak: > In the message header I've : > X-DKIM: Sendmail DKIM Filter v2.7.2 kostnew.ajetaci.cz 8840B239C3 > Authentication-Results: kostnew.ajetaci.cz; dkim=none (no signature) > header.i=unknown; dkim-adsp=fail > > And in the mail log: > Nov 7 10:48:37 ko

redirecting mail from a particular server

2011-11-07 Thread Timothy Smith
Hi Users, I am relaying mail for many IPs using postfix version 2.1.6. For some particular IPs, I would like to just drop their email (rather than turn off relaying for them). Is that possible? I appreciate your help. Tim

Re: redirecting mail from a particular server

2011-11-07 Thread Robert Schetterer
Am 07.11.2011 11:02, schrieb Timothy Smith: > Hi Users, > > I am relaying mail for many IPs using postfix version 2.1.6. For some > particular IPs, I would like to just drop their email (rather than > turn off relaying for them). Is that possible? > > I appreciate your help. > > Tim rejecting i

Re: redirecting mail from a particular server

2011-11-07 Thread Robert Schetterer
Am 07.11.2011 11:10, schrieb Robert Schetterer: > Am 07.11.2011 11:02, schrieb Timothy Smith: >> Hi Users, >> >> I am relaying mail for many IPs using postfix version 2.1.6. For some >> particular IPs, I would like to just drop their email (rather than >> turn off relaying for them). Is that possib

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Josef Karliak
Hi, thanks for tips, I used "-i ilistfile containing list of internal (signing) hosts". It is signing now, but signature fails on the verifier : Nov 7 12:40:54 celer dkim-filter[4888]: 5CCC8C750A SSL error:04077068:rsa routines:RSA_verify:bad signature Nov 7 12:40:54 celer dk

Re: redirecting mail from a particular server

2011-11-07 Thread Timothy Smith
Thank you Robert, I was able to follow your instructions and achieved what I want. I am now rejecting with a message. Sorry about the misleading subject. Kind Regards, Tim On Mon, Nov 7, 2011 at 1:10 PM, Robert Schetterer wrote: > Am 07.11.2011 11:02, schrieb Timothy Smith: >> Hi Users, >> >>

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Robert Schetterer
Am 07.11.2011 12:50, schrieb Josef Karliak: > Hi, > thanks for tips, I used "-i ilistfile containing list of > internal (signing) hosts". > It is signing now, but signature fails on the verifier : > Nov 7 12:40:54 celer dkim-filter[4888]: 5CCC8C750A SSL > error:04077068:rsa routines:

Quota for mail

2011-11-07 Thread Leslie León Sinclair
Hi: I have a Postfix+MySQL+Dovecot+PostfixAdmin[Lenny server] setup, and works very nice. But I need to put quota in my webmail[RoundCube], and after a long research in Internet, I see DoveAdm as a good option,the issue is... - It´s DoveAdm a command part of Dovecot, if so, where is it? - O

Re: Quota for mail

2011-11-07 Thread Duane Hill
On Monday, November 07, 2011 at 15:41:38 UTC, les...@electrica.cujae.edu.cu confabulated: > Hi: > I have a Postfix+MySQL+Dovecot+PostfixAdmin[Lenny server] setup, and > works very nice. But I need to put quota in my webmail[RoundCube], and > after a long research in Internet, I see DoveAdm as a

Postfix stable release 2.8.7

2011-11-07 Thread Wietse Venema
[An on-line version of this announcement will be available at http://www.postfix.org/announcements/postfix-2.8.7.html] Postfix stable release 2.8.7 is available. This contains a workaround for a problem that is fixed in Postfix 2.9. * The postscreen daemon, which is not enabled by default,

Re: Quota for mail

2011-11-07 Thread Nikolaos Milas
On 7/11/2011 5:41 μμ, Leslie León Sinclair wrote: But I need to put quota in my webmail Hi, Use postfix and dovecot, with lda or lmtp and setup quotas in dovecot. See: http://www.dovecot.org/list/dovecot/2011-February/057630.html Hope that helps, Nick smime.p7s Description: S/MIME Crypto

Re: Quota for mail

2011-11-07 Thread Robert Schetterer
Am 07.11.2011 15:48, schrieb Duane Hill: > On Monday, November 07, 2011 at 15:41:38 UTC, les...@electrica.cujae.edu.cu > confabulated: > >> Hi: > >> I have a Postfix+MySQL+Dovecot+PostfixAdmin[Lenny server] setup, and >> works very nice. But I need to put quota in my webmail[RoundCube], and >>

Re: Postfix on Virtual Guest Cannot send mail

2011-11-07 Thread Blair, Rick
Thanks That was the clue I was needing. I had to explicitly set mynetworks on the guest OS. seemed to fix it. RIck On Nov 6, 2011, at 11:17 AM, Wietse Venema wrote: > Blair, Rick: >> [root@guestServer init.d]# telnet fileserver 25 >> Trying 192.168.1.31... >> Connected to fileserver. >> Esc

Re: Quota for mail

2011-11-07 Thread Leslie León Sinclair
The problem is the query for MySQL... I have quotas in a table in mysql, but there´s a lot of parameters that I dont know when to use it. For example: 1- The quota query in MySQL -> query = SELECT quota FROM mailbox WHERE username='%s' 2- The quota query in Dovecot -> user_query = SELECT home,

Re: Quota for mail

2011-11-07 Thread Leslie León Sinclair
The issue is that I have multiple quotas/domains, for my users. Some users have 10MB, others have 100MB, and Admin/Root[postmaster, webmaster, abuse, hostmaster] have 500MB and I need to fetch the quota, for the specific user with MySQL. Best regards. -- /*

Re: Quota for mail

2011-11-07 Thread Reindl Harald
Am 07.11.2011 18:02, schrieb Leslie León Sinclair: > The issue is that I have multiple quotas/domains, for my users. Some users > have 10MB, others have 100MB, and > Admin/Root[postmaster, webmaster, abuse, hostmaster] have 500MB and I need to > fetch the quota, for the specific > user with MyS

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Steve Jenkins
2011/11/7 Robert Schetterer : > post your problem dkim-milter list > > http://sourceforge.net/mail/?group_id=139420 FYI - that list doesn't exist any more. dkim-milter has been deprecated in favor of OpenDKIM (http://opendkim.org/). It's an actively-supported milter project, and switching over fro

Re: Quota for mail

2011-11-07 Thread Duane Hill
On Monday, November 07, 2011 at 17:02:24 UTC, les...@electrica.cujae.edu.cu confabulated: > The issue is that I have multiple quotas/domains, for my users. Some > users have 10MB, others have 100MB, and Admin/Root[postmaster, > webmaster, abuse, hostmaster] have 500MB and I need to fetch the qu

Re: dkim-milter verify, but don't sign.

2011-11-07 Thread Frank Bonnet
On 11/07/2011 05:15 PM, Steve Jenkins wrote: 2011/11/7 Robert Schetterer: post your problem dkim-milter list http://sourceforge.net/mail/?group_id=139420 FYI - that list doesn't exist any more. dkim-milter has been deprecated in favor of OpenDKIM (http://opendkim.org/). It's an actively-suppor

Re: Quota for mail

2011-11-07 Thread Leslie León Sinclair
Thanks again, and sorry the thread, I´am stacked here. Almost near the solution. Best regards. You should move this discussion over to the Dovecot mailing list. -- /*** *Leslie León Sinclair *Administrador de Redes *Facultad de Ingenieria E

Fw: sasldb or PAM

2011-11-07 Thread gaby
I use TLS withPAM,but what is disadvantage PAM versus sasldb ? Sasldb is more security? - Original Message - From: Patrick Ben Koetter To: postfix-users@postfix.org Sent: Monday, November 07, 2011 11:06 AM Subject: Re: sasldb or PAM * gaby : > I use PAM authentication method for send

Re: Fw: sasldb or PAM

2011-11-07 Thread Patrick Ben Koetter
* gaby : > I use TLS withPAM,but what is disadvantage PAM versus sasldb ? > Sasldb is more security? sasldb must be read/write protected from other uses, but remain readable to the user postfix or one of the groups it is in e.g. group sasl. sasldb must reside on the same machine as the Postfix ins

RE: dkim-milter verify, but don't sign.

2011-11-07 Thread Murray S. Kucherawy
> -Original Message- > From: owner-postfix-us...@postfix.org > [mailto:owner-postfix-us...@postfix.org] On Behalf Of Josef Karliak > Sent: Monday, November 07, 2011 3:50 AM > To: Robert Schetterer > Cc: postfix-users@postfix.org > Subject: Re: dkim-milter verify, but don't sign. > >Hi

Symlink problem = file is a symbolic link or Mailbox vulnerable - directory /var/spool/mail must have 1777 protection

2011-11-07 Thread Marek Królikowski
Hello Guys Yesterday i buy new EMC storage and i want move few ppl from old SATA HDD to new FC EMC HDD but i got problem and don`t know how resolve this problem mayby You help me: 1. I mount new storage to /mnt/EMC 2. I create a /mnt/EMC/var/spool/mail/ 3. i move user file (test) from /var/spool/

Re: Symlink problem = file is a symbolic link or Mailbox vulnerable - directory /var/spool/mail must have 1777 protection

2011-11-07 Thread Wietse Venema
Marek Kr?likowski: > Hello Guys > Yesterday i buy new EMC storage and i want move few ppl from old SATA HDD to > new FC EMC HDD but i got problem and don`t know how resolve this problem > mayby You help me: > 1. I mount new storage to /mnt/EMC > 2. I create a /mnt/EMC/var/spool/mail/ > 3. i move

Re: Symlink problem = file is a symbolic link or Mailbox vulnerable - directory /var/spool/mail must have 1777 protection

2011-11-07 Thread Marek Królikowski
-Oryginalna wiadomość- From: Wietse Venema Sent: Tuesday, November 08, 2011 2:27 AM To: Postfix users Subject: Re: Symlink problem = file is a symbolic link or Mailbox vulnerable - directory /var/spool/mail must have 1777 protection Marek Krolikowski: Hello Guys Yesterday i buy new EMC

Distribute mail based on sending domain?

2011-11-07 Thread vr
We have Exchange 2010 with a few domains and have run across the need to split outgoing mail direct to the Internet and also to smart hosts depending on their @domain.tld. Exchange 2010 does not support this "by design" so if Postfix does, is this functionality a relay? Looking at the BASIC_CON

understanding the logs

2011-11-07 Thread Geert Mak
Hi, We had a user account hacked (weak password) and our SMTP server was used for sending spam. We discovered it after our mail server IP began to show up in RBLs. We improved the passwords, however the question is how best to watch the server in case a similar thing happens again. We created

Re: Symlink problem = file is a symbolic link or Mailbox vulnerable - directory /var/spool/mail must have 1777 protection

2011-11-07 Thread Stan Hoeppner
On 11/7/2011 11:13 PM, Marek Królikowski wrote: > -Oryginalna wiadomość- From: Wietse Venema > Sent: Tuesday, November 08, 2011 2:27 AM > To: Postfix users > Subject: Re: Symlink problem = file is a symbolic link or Mailbox > vulnerable - directory /var/spool/mail must have 1777 protection

Re: Symlink problem = file is a symbolic link or Mailbox vulnerable - directory /var/spool/mail must have 1777 protection

2011-11-07 Thread Marek Krolikowski
-Oryginalna wiadomość- From: Stan Hoeppner Sent: Tuesday, November 08, 2011 8:26 AM To: postfix-users@postfix.org Subject: Re: Symlink problem = file is a symbolic link or Mailbox vulnerable - directory /var/spool/mail must have 1777 protection Simply mount the EMC device to a tempora

Re: understanding the logs

2011-11-07 Thread Stan Hoeppner
On 11/8/2011 1:13 AM, Geert Mak wrote: > We had a user account hacked (weak password) and our SMTP server was used for > sending spam. We discovered it after our mail server IP began to show up in > RBLs. We improved the passwords, however the question is how best to watch > the server in case

Re: Symlink problem = file is a symbolic link or Mailbox vulnerable - directory /var/spool/mail must have 1777 protection

2011-11-07 Thread Stan Hoeppner
On 11/8/2011 1:29 AM, Marek Krolikowski wrote: >> -Oryginalna wiadomość- From: Stan Hoeppner >> Sent: Tuesday, November 08, 2011 8:26 AM >> To: postfix-users@postfix.org >> Subject: Re: Symlink problem = file is a symbolic link or Mailbox >> vulnerable - directory /var/spool/mail must have