Re: How to detect the receiving of mail for sure from only that relay and then make action only in that case?

2015-01-30 Thread Michael Ströder
Viktor Dukhovni wrote: > On Fri, Jan 30, 2015 at 05:27:59AM +, srach wrote: > ?1. Know for sure that the relay mail comes from the #1 server.? A added header can be made fake so I look for a better way that is not possible to fake. >> >>> Restrict access to the non-default port

Re: Re: How to detect the receiving of mail for sure from only that relay and then make action only in that case?

2015-01-30 Thread Andy Wright
On Fri, 2015-01-30 at 05:35 +, Viktor Dukhovni wrote: > On Fri, Jan 30, 2015 at 05:27:59AM +, srach wrote: > > > >> ?1. Know for sure that the relay mail comes from the #1 server.? A added > > >> header can be made fake so I look for a better way that is not possible > > >> to > > >> fake

Unable to receive mail: Relay access denied

2015-01-30 Thread Andreas Fagschlunger
Hello! I'm trying to setup a mail server with postfix, dovecot and MySQL. At this point dovecot seems to work (pop3, imap), but I'm unable to receive mails. The postfix error is (replaced user/domains): Jan 28 23:04:22 k002867vsa postfix/smtpd[22830]: NOQUEUE: reject: RCPT from node-mec2.wormly.c

Re: Unable to receive mail: Relay access denied

2015-01-30 Thread li...@rhsoft.net
Am 30.01.2015 um 14:59 schrieb Andreas Fagschlunger: What I found out so far is, that postfix doesn't feel responsible for mydomain.com. When I change mydestination to mydomain.com, postfix accepts mails. But I want postfix to lookup the domain against mysql. I've read all the tutorials around

Re: Re: Re: How to detect the receiving of mail for sure from only that relay and then make action only in that case?

2015-01-30 Thread srach
Hello all Thanks for the multiple advises. 30. Jan 2015 13:46 by a...@extracted.org: > On Fri, 2015-01-30 at 05:35 +, Viktor Dukhovni wrote: > >> And I often find it easier to configure client certs, no SASL or >> PAM configuration nightmares. :-) >>  I have made the easy decisision for

Re: Unable to receive mail: Relay access denied

2015-01-30 Thread Andreas Fagschlunger
Since the virtual_mailbox_domains default value is virtual_mailbox_maps I thought I didn't need a new query, but it works! Thank you a lot!

Re: A strange problem when adding DSPAM to Postfix

2015-01-30 Thread Noel Jones
Postfix logs all transactions. No logs suggests that either your logging is broken or something other than postfix is providing mail service to outside clients. For the logging, make sure that chroot column in master.cf is set to "n" for all services. Use lsof or some other system tool to see wh

Re: Re: Re: How to detect the receiving of mail for sure from only that relay and then make action only in that case?

2015-01-30 Thread Viktor Dukhovni
On Fri, Jan 30, 2015 at 02:44:48PM +, srach wrote: > But at the document > > http://www.postfix.org/TLS_README.html > > I think the tls_policy is for "destinations".? So only for the sending side. > > I too want the #2 server to only ACCEPT the relay mail from the #1 server if > the #1 ser

control outgoing mail

2015-01-30 Thread rupesh chandurkar
Hi All, Please help me about control outgoing mail delivery.I want to delay "1s" in every mail delivery. Approx 30 mail per/min. How I can do .. Regards, Rupesh Thanks & Regards, Rupesh Chandurkar

Unexpected reject messages

2015-01-30 Thread James B. Byrne
I see this in our maillog: Jan 30 11:15:47 inet08 postfix-p25/smtpd[4796]: NOQUEUE: reject: RCPT from unknown[69.17.131.33]: 450 4.7.1 : Helo command rejected: Host not found; from= to= proto=ESMTP helo= dig -x 69.17.131.33 ; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.30.rc1.el6_6.1 <<>> -x 69.17.131.33

Re: Unexpected reject messages

2015-01-30 Thread Noel Jones
On 1/30/2015 10:41 AM, James B. Byrne wrote: > I see this in our maillog: > > Jan 30 11:15:47 inet08 postfix-p25/smtpd[4796]: NOQUEUE: reject: RCPT > from unknown[69.17.131.33]: 450 4.7.1 : Helo > command rejected: Host not found; from= > to= proto=ESMTP helo= > > > dig -x 69.17.131.33 > > ; <<

Re: Unexpected reject messages

2015-01-30 Thread James B. Byrne
On Fri, January 30, 2015 11:52, Noel Jones wrote: > On 1/30/2015 10:41 AM, James B. Byrne wrote: >> I see this in our maillog: >> >> Jan 30 11:15:47 inet08 postfix-p25/smtpd[4796]: NOQUEUE: reject: >> RCPT >> from unknown[69.17.131.33]: 450 4.7.1 : Helo >> command rejected: Host not found; from= >

"postfix users"

2015-01-30 Thread James B. Byrne
Never mind. I finally realized what you were telling me. There is no forward dns for that address. I will contact them. -- *** E-Mail is NOT a SECURE channel *** James B. Byrnemailto:byrn...@harte-lyne.ca Harte & Lyne Limited http://www.harte-lyne.ca

Re: Unexpected reject messages

2015-01-30 Thread Viktor Dukhovni
On Fri, Jan 30, 2015 at 11:56:27AM -0500, James B. Byrne wrote: > >> Jan 30 11:15:47 inet08 postfix-p25/smtpd[4796]: NOQUEUE: reject: RCPT > >> from unknown[69.17.131.33]: 450 4.7.1 : Helo > >> command rejected: Host not found; from= > >> to= proto=ESMTP helo= > >> > >> 33.131.17.69.in-addr.arpa.

Re: control outgoing mail

2015-01-30 Thread Noel Jones
On 1/30/2015 10:38 AM, rupesh chandurkar wrote: > Hi All, > > Please help me about control outgoing mail delivery.I want to delay > "1s" in every mail delivery. > Approx 30 mail per/min. > > How I can do .. > > Regards, > Rupesh Postfix doesn't have a global delivery limit. You can use sm

Re: Re: Re: Re: How to detect the receiving of mail for sure from only that relay and then make action only in that case?

2015-01-30 Thread srach
Hello Viktor 30. Jan 2015 16:05 by postfix-us...@dukhovni.org: > > http://www.postfix.org/postconf.5.html#check_ccert_access > I did it with this option for Postfix server #2 config.  I need to have the opportunity to set many relay clients some day so I use the access map. I also set

Re: Re: Re: Re: How to detect the receiving of mail for sure from only that relay and then make action only in that case?

2015-01-30 Thread Viktor Dukhovni
On Fri, Jan 30, 2015 at 06:39:36PM +, srach wrote: > I also set the unique port to listen for the relay AUTH using TLS cert check > so there is no conflict with the other ports and the options they are set > with. > > The unique port to listen to for TLS cert AUTH on # server is 9443. What

Re: Re: Re: Re: Re: How to detect the receiving of mail for sure from only that relay and then make action only in that case?

2015-01-30 Thread srach
30. Jan 2015 19:21 by postfix-us...@dukhovni.org: > What software is listening on that port? > I see it is the Postfix part of the Zimbra commercail mail server. I am told that it must be a unique port for only using TLS AUTH. >> I can check this now with simple telnet >> >> ?telne

Re: Re: Re: Re: Re: How to detect the receiving of mail for sure from only that relay and then make action only in that case?

2015-01-30 Thread Viktor Dukhovni
On Fri, Jan 30, 2015 at 07:49:29PM +, srach wrote: [ Please stop using HTML email, it garbles your replies. Use text/plain, thanks.] > > What software is listening on that port? > > I see it is the Postfix part of the Zimbra commercail mail server. EVIDENCE? master.cf entry? > I am told

simplfied test of Postfix->Postfix TLS auth. smtp_client_restrictions only executes 'generic_checks' not specific DB

2015-01-30 Thread hndlsrch2
I am now simple-testing Postfix->Postfix TLS AUTH.  It is all on internal test network on the LAN. I create on the receiving server this service in http://master.cf     1234  inet  n  -  n  -  -  smtpd -v     -o smtp_helo_name=auth.srachnet.loc     -o smtpd_tls_security_level=may     -o smtpd_tl

Re: simplfied test of Postfix->Postfix TLS auth. smtp_client_restrictions only executes 'generic_checks' not specific DB

2015-01-30 Thread Wietse Venema
hndlsr...@tutanota.de: > I am now simple-testing Postfix->Postfix TLS AUTH.? It is all on internal > test network on the LAN. > > I create on the receiving server this service in http://master.cf > > ??? 1234? inet? n? -? n? -? -? smtpd -v > ??? -o smtp_helo_name=auth.srachnet.loc > ??? -o smtpd

Re: Re: simplfied test of Postfix->Postfix TLS auth. smtp_client_restrictions only executes 'generic_checks' not specific DB

2015-01-30 Thread hndlsrch2
Hello Wietse > How do you know that the client actually SENDS a certificate? I do not know because I do not yet see the proof of it in the right log.  But I try to configure for it.  I am trying to make a simple example all under my control so that I can see the certs exchanged and then verifie

Re: simplfied test of Postfix->Postfix TLS auth. smtp_client_restrictions only executes 'generic_checks' not specific DB

2015-01-30 Thread Viktor Dukhovni
On Fri, Jan 30, 2015 at 11:18:29PM +, hndlsr...@tutanota.de wrote: > I create on the receiving server this service in http://master.cf > > 1234 inet n - n - - smtpd -v > -o smtp_helo_name=auth.srachnet.loc > -o smtpd_tls_security_level=may > -o smtpd_tls_fingerprint_digest=sha1 > -o

Re: Re: simplfied test of Postfix->Postfix TLS auth. smtp_client_restrictions only executes 'generic_checks' not specific DB

2015-01-30 Thread hndlsrch2
> And where is "smtpd_tls_req_ccert=yes" or "smtpd_tls_ask_ccert=yes"? > And why not "smtpd_tls_security_level=encrypt"? >> Excuse me if things are changing from last message. I am working on it. These have been added to the server already since.  In the moment the server configuration is 1234 

Re: Re: simplfied test of Postfix->Postfix TLS auth. smtp_client_restrictions only executes 'generic_checks' not specific DB

2015-01-30 Thread Viktor Dukhovni
On Sat, Jan 31, 2015 at 03:06:06AM +, hndlsr...@tutanota.de wrote: > > And where is "smtpd_tls_req_ccert=yes" or "smtpd_tls_ask_ccert=yes"? > > And why not "smtpd_tls_security_level=encrypt"? > > >> Excuse me if things are changing from last message. I am working on it. > > These have been a

unused parameter: mx_access=hash:/etc/postfix/mx_access

2015-01-30 Thread Joey J
Hello, I'm getting the following when I start postfix ( literally that many times) /usr/sbin/postconf: warning: /etc/postfix/main.cf: unused parameter: mx_access=hash:/etc/postfix/mx_access /usr/sbin/postconf: warning: /etc/postfix/main.cf: unused parameter: mx_access=hash:/etc/postfix/mx_access