Re: Postfix 3.1 and TLS Cert Files

2016-03-11 Thread Tom Browder
On Wednesday, March 9, 2016, Curtis Villamizar wrote: > > In message > ... > > > You need to instances of smtpd. One on port 587 (MSA) and a mail > > > transfer agent (MTA) on port 25 which is where the MX record point to. ... > What an MSA does is well defined in RFC 6409 "Message Submission f

OT yahoo

2016-03-11 Thread @lbutlr
I’ve been trying to track down why users have stopped receiving any mail from yahoo users and after searching the logs and even going so far as to create a yahoo mail account and send mail to myself, I see no attempts by yahoo to connect to my server. It seems anything sent to my mail server sim

Re: OT yahoo

2016-03-11 Thread Wietse Venema
@lbutlr: > I=E2=80=99ve been trying to track down why users have stopped receiving = > any mail from yahoo users and after searching the logs and even going so = > far as to create a yahoo mail account and send mail to myself, I see no = > attempts by yahoo to connect to my server. It seems anythin

Re: postfix

2016-03-11 Thread Wietse Venema
Lytton Hou: > Dear Sir/Madam, > This is a confirmation letter regarding registration of postfix, > please read it carefully. We are a service agency for registering > domain names. Our center received an application from PERF Asia > Limited today. They applied for the registration of postfix as > t

Re: OT yahoo

2016-03-11 Thread /dev/rob0
On Fri, Mar 11, 2016 at 07:05:34AM -0700, @lbutlr wrote: > I’ve been trying to track down why users have stopped receiving any > mail from yahoo users and after searching the logs and even going > so far as to create a yahoo mail account and send mail to myself, I > see no attempts by yahoo to c

Re: postfix

2016-03-11 Thread Robert Chalmers
This is spam from China usually, and often India. I’ve seen a few of these over the years. I can’t imagine the end game, but responding is a waste of time - it’s spam > On 11 Mar 2016, at 14:36, Wietse Venema wrote: > > Lytton Hou: >> Dear Sir/Madam, >> This is a confirmation letter regarding

Milter not to all messages

2016-03-11 Thread Alfredo Saldanha
Is there some way to use milter check in a type of conditional ? In my situation here, it can not be mandatory to each message. I'm asking this because some users here want to receive all messages without Spam verification. Part of my main.cf: http://dpaste.com/3HFRR6V Thanks.

Re: Milter not to all messages

2016-03-11 Thread Wietse Venema
Alfredo Saldanha: > Is there some way to use milter check in a type of conditional ? No. Milters can't start somewhere in the middle of an SMTP session. They must be able to inspect and respond to all connection stages. Wietse > In my situation here, it can not be mandatory to each messa

Re: Milter not to all messages

2016-03-11 Thread Alfredo Saldanha
So I need another Postfix instance to do this. I can use transport maps to select which user will pass in milter. Thanks Wietse. - Mensagem original - De: "Wietse Venema" Para: "postfix-users" Enviadas: Sexta-feira, 11 de março de 2016 11:52:48 Assunto: Re: Milter not to all messages A

In some rare cases Postfix connect to a wrong MX server

2016-03-11 Thread Msd
Hello, I note in some rare case that Postfix tries to deliver an email to a wrong MX server. I have opened a bug to describe my problem here : https://bugs.launchpad.net/ubuntu/+source/postfix/+bug/1549388/ Do you know what happens ? Thanks, Guillaume

Re: sender IP dependent outgoing IP address after content_filter

2016-03-11 Thread gsotsas
Thanks once again! Do you see any possibility to use the client IP from the XFORWARD header? And to pass it to an external policy daemon? Amda On 09.03.2016 22:41, Wietse Venema wrote: gsotsas: Dear postfix users, I have the following outbound relayhost configuration: {client that sends mai

Re: Mitigating DROWN

2016-03-11 Thread John A @ KLaM
As yhe result of following various - how tos, warnings, notices etc., I currentky exclude from both smtp & smtpd "aNULL, DES, 3DES, MD5, RC2. RC4. RC5, IDEA, SRP, PSK, aDDS, kECDhe, kECDhr, kDHd, kDHr, SEED, IDEA, LOW, EXPORT" Is this list reasonable and/or accurate.

Re: How can/could I redirect based upon sender.

2016-03-11 Thread John A @ KLaM
Thanks to everybody who helped. Using the info collected the young lady was able to get a restraining order which, hopefully will put a stop to the harrasment.

Re: In some rare cases Postfix connect to a wrong MX server

2016-03-11 Thread Wietse Venema
Msd: > Hello, > > I note in some rare case that Postfix tries to deliver an email to a > wrong MX server. > > I have opened a bug to describe my problem here : > https://bugs.launchpad.net/ubuntu/+source/postfix/+bug/1549388/ > > Do you know what happens ? There was an MX lookup bugfix for Po

Re: Mitigating DROWN

2016-03-11 Thread Viktor Dukhovni
On Fri, Mar 11, 2016 at 10:27:17AM -0500, John A @ KLaM wrote: > As a result of following various - how tos, warnings, notices etc., I > currentky exclude from both smtp & smtpd > > aNULL, DES, 3DES, MD5, RC2. RC4, > RC5, IDEA, SRP, PSK, aDDS, kECDhe, > kECDhr, kDHd, kDHr, SEED,

Re: sender IP dependent outgoing IP address after content_filter

2016-03-11 Thread Wietse Venema
gsotsas: > Thanks once again! > > Do you see any possibility to use the client IP from the XFORWARD > header? And to pass it to an external policy daemon? There is no such thing as an xforward header. I describe the system as it exists today. I could also describe a system that does not exist,

Re: sender IP dependent outgoing IP address after content_filter

2016-03-11 Thread Noel Jones
On 3/11/2016 9:22 AM, gsotsas wrote: > Thanks once again! > > Do you see any possibility to use the client IP from the XFORWARD > header? And to pass it to an external policy daemon? > > Amda No. > > On 09.03.2016 22:41, Wietse Venema wrote: >> gsotsas: >>> Dear postfix users, >>> I have th

Re: OT yahoo

2016-03-11 Thread @lbutlr
> On Mar 11, 2016, at 7:37 AM, /dev/rob0 wrote: > > On Fri, Mar 11, 2016 at 07:05:34AM -0700, @lbutlr wrote: >> I’ve been trying to track down why users have stopped receiving any >> mail from yahoo users and after searching the logs and even going >> so far as to create a yahoo mail account a

Re: OT yahoo

2016-03-11 Thread Viktor Dukhovni
On Fri, Mar 11, 2016 at 08:57:48AM -0700, @lbutlr wrote: > I have MX monitoring that says I am not on any blacklists and that the server > is secure > > # dig @8.8.8.8 covisp.net any My first SMTP connection attempt to your server resulted in: $ posttls-finger covisp.net posttls-finge

Re: OT yahoo

2016-03-11 Thread Wietse Venema
Viktor Dukhovni: > On Fri, Mar 11, 2016 at 08:57:48AM -0700, @lbutlr wrote: > > > I have MX monitoring that says I am not on any blacklists and that the > > server is secure > > > > # dig @8.8.8.8 covisp.net any > > My first SMTP connection attempt to your server resulted in: > > $ posttl

Re: Milter not to all messages

2016-03-11 Thread Stephen Satchell
On 03/11/2016 06:48 AM, Alfredo Saldanha wrote: Is there some way to use milter check in a type of conditional ? In my situation here, it can not be mandatory to each message. I'm asking this because some users here want to receive all messages without Spam verification. When I was running mai

Re: In some rare cases Postfix connect to a wrong MX server

2016-03-11 Thread Msd
Hello, I have updated the bug with your information. Thank you very much for your help ! Guillaume Le 11/03/2016 16:48, Wietse Venema a écrit : Msd: Hello, I note in some rare case that Postfix tries to deliver an email to a wrong MX server. I have opened a bug to describe my problem here

Re: Milter not to all messages

2016-03-11 Thread Alfredo Saldanha
Nice way, Stephen. I'll think about that. Thank you. - Mensagem original - De: "Stephen Satchell" Para: "Alfredo Saldanha" , "postfix-users" Enviadas: Sexta-feira, 11 de março de 2016 14:11:11 Assunto: Re: Milter not to all messages On 03/11/2016 06:48 AM, Alfredo Saldanha wrote: > I

Re: In some rare cases Postfix connect to a wrong MX server

2016-03-11 Thread Viktor Dukhovni
On Fri, Mar 11, 2016 at 06:21:06PM +0100, Msd wrote: > >There was an MX lookup bugfix for Postfix 2.11 in May 2014. > > > > Wietse > > > >Bugfixes (fixed in Postfix 2.11 and Postfix 2.12): > > > > * With connection caching enabled (the default), recipients > > could be given to the wrong

Re: OT yahoo

2016-03-11 Thread @lbutlr
On Fri Mar 11 2016 09:09:29 Viktor Dukhovni said: > > On Fri, Mar 11, 2016 at 08:57:48AM -0700, @lbutlr wrote: > >> I have MX monitoring that says I am not on any blacklists and that the >> server is secure >> >> # dig @8.8.8.8 covisp.net any > > My first SMTP connection attempt to your

Re: OT yahoo

2016-03-11 Thread Viktor Dukhovni
On Fri, Mar 11, 2016 at 11:38:13AM -0700, @lbutlr wrote: > > You have some sort of proxy in front of your Postfix server. The > > proxy may be blocking Yahoo's servers. > > That is postscreen, which has a 4 or 5 second delay for new connections > however, that connection would be logged, would

Re: Mitigating DROWN

2016-03-11 Thread John A @ KLaM
Thanks, I will keep 3DES for now. My dentist does not have to worry, it was a transcription error.

yahoo vs. postscreen

2016-03-11 Thread /dev/rob0
On Fri, Mar 11, 2016 at 11:38:13AM -0700, @lbutlr wrote: > That is postscreen, which has a 4 or 5 second delay for new > connections however, that connection would be logged, wouldn’t > it? Yes, but if Y! outbound servers are not getting past 220, ... > The only instances of yahoo.com I see in t

Re: OT yahoo

2016-03-11 Thread @lbutlr
On Fri Mar 11 2016 11:45:31 Viktor Dukhovni said: > > On Fri, Mar 11, 2016 at 11:38:13AM -0700, @lbutlr wrote: > >>> You have some sort of proxy in front of your Postfix server. The >>> proxy may be blocking Yahoo's servers. >> >> That is postscreen, which has a 4 or 5 second delay for ne

Re: yahoo vs. postscreen

2016-03-11 Thread @lbutlr
On Fri Mar 11 2016 11:49:44 /dev/rob0said: > > Also, at this point "postconf -nf ; postconf -Mf" are appropriate, > because there might indeed be a Postfix issue. $ postconf -nf alias_database = hash:$config_directory/aliases alias_maps = hash:$config_directory/aliases, hash:/usr/local/m

Re: OT yahoo

2016-03-11 Thread @lbutlr
On Fri Mar 11 2016 07:05:34 @lbutlr <@lbutlr> said: > > I know this isn;t a postfix problem since postfix is not ever getting > anything, but I’m hoping someone on the list has some ideas? I just found out that someone turned off the static IP pool for one of the DNS servers, so that may be

Re: Milter not to all messages

2016-03-11 Thread Tom Hendrikx
On 11-03-16 15:48, Alfredo Saldanha wrote: > Is there some way to use milter check in a type of conditional ? > In my situation here, it can not be mandatory to each message. > I'm asking this because some users here want to receive all messages without > Spam verification. > > Part of my main.cf

Re: OT yahoo

2016-03-11 Thread Noel Jones
On 3/11/2016 12:54 PM, @lbutlr wrote: > On Fri Mar 11 2016 11:45:31 Viktor Dukhovni > said: >> >> On Fri, Mar 11, 2016 at 11:38:13AM -0700, @lbutlr wrote: >> You have some sort of proxy in front of your Postfix server. The proxy may be blocking Yahoo's servers. >>> >>> That is postsc

Re: Milter not to all messages

2016-03-11 Thread Andrzej A. Filip
Alfredo Saldanha wrote: > Is there some way to use milter check in a type of conditional ? > In my situation here, it can not be mandatory to each message. > I'm asking this because some users here want to receive all messages without > Spam verification. > > Part of my main.cf: > http://dpaste.c

Re: OT yahoo

2016-03-11 Thread @lbutlr
On Fri Mar 11 2016 12:21:07 Noel Jones said: > > This problem (postscreen delays legit mail server) is nicely solved > by using a dns whitelist such as dnswl.org to bypass postscreen > tests for known mail servers... not necessarily "known good" > servers, just known to not be a bot. Then your

PATCH: rcpt count mismatch with Milter

2016-03-11 Thread Wietse Venema
Wietse Venema: > J?rg Backschues: > > Am 09.03.2016 um 01:20 schrieb Wietse Venema: > > > > > How many recipients are there before the bcc action? > > > > I've verified the issue with one recipient only and multiple recipients. > > > > > That would be a bug. I'd appreciate it if you could run th