Re: Configuration Syntax

2017-07-07 Thread Noel Jones
On 7/7/2017 12:37 AM, Doug Hardie wrote: > >> On 6 July 2017, at 12:40, Doug Hardie wrote: >> >>> >>> On 6 July 2017, at 12:06, Noel Jones wrote: >>> >>> main.cf doesn't allow spaces in the options. The supported syntax >>> is to either use commas "," rather than spaces; enclose the option >>>

Require TLS on internet-facing servers?

2017-07-07 Thread robgane
Hello, I am starting to setup a Postfix server for our office. I'm looking at TLS policy. Reading old posts on the Postfix mailing lists there's lots of comments that REQUIRING tls should never be done on an public internet-facing server. But those comments are from 5-7 yrs ago. Is that still

Re: Require TLS on internet-facing servers?

2017-07-07 Thread Wietse Venema
robg...@nospammail.net: > Hello, > > I am starting to setup a Postfix server for our office. > > I'm looking at TLS policy. > > Reading old posts on the Postfix mailing lists there's lots of > comments that REQUIRING tls should never be done on an public > internet-facing server. > > But those c

Re: Require TLS on internet-facing servers?

2017-07-07 Thread Wietse Venema
Correction: my numbers were off because I used case-insensitive search. robg...@nospammail.net: > Hello, > > I am starting to setup a Postfix server for our office. > > I'm looking at TLS policy. > > Reading old posts on the Postfix mailing lists there's lots of > comments that REQUIRING tls sh

postscreen delay inprovement - multple IP addresses

2017-07-07 Thread techlist06
I'm working on converting to using postscreen. Studying the details. I have a question from the docs related to the delays due to the effective greylisting caused by "Tests after the 220 SMTP server greeting". I believe my server would qualify as a small site receiving mail for just a few hundre

Re: Require TLS on internet-facing servers?

2017-07-07 Thread lists
Would there be some way to redirect unencrypted email to some other server. Gmail for instance.  I would then force encryption on my personal server. I'm down to one contact (as in a person I know) that isn't using encryption. I made two converts!  I haven't checked mailing lists for encryption.

postscreen with postgrey - can they cause a double reject?

2017-07-07 Thread techlist06
- postscreen with postgrey - can they cause a double reject? I searched for answers regarding using both postscreen and greylisting. I saw some differing opinions. But I did not see this point covered. Assuming a clients first connection to me to deliver and Assuming that postscreen is configur

Re: Require TLS on internet-facing servers?

2017-07-07 Thread Viktor Dukhovni
On Fri, Jul 07, 2017 at 03:04:11PM -0700, li...@lazygranch.com wrote: > Would there be some way to redirect unencrypted email to some other server. > Gmail for instance.  I would then force encryption on my personal server. SMTP does not have "redirects". SMTP security policy is up to the client

Re: postscreen delay inprovement - multple IP addresses

2017-07-07 Thread Wietse Venema
techlist06: > I'm working on converting to using postscreen. Studying the details. I > have a question from the docs related to the delays due to the effective > greylisting caused by "Tests after the 220 SMTP server greeting". I believe > my server would qualify as a small site receiving mail f

Re: Require TLS on internet-facing servers?

2017-07-07 Thread /dev/rob0
On Fri, Jul 07, 2017 at 10:40:47AM -0700, robg...@nospammail.net wrote: > I am starting to setup a Postfix server for our office. > > I'm looking at TLS policy. > > Reading old posts on the Postfix mailing lists there's lots of > comments that REQUIRING tls should never be done on an public >

Re: postscreen with postgrey - can they cause a double reject?

2017-07-07 Thread /dev/rob0
On Fri, Jul 07, 2017 at 05:18:49PM -0500, techlist06 wrote: > - postscreen with postgrey - can they cause a double reject? Reject, no; deferral, of course yes. > I searched for answers regarding using both postscreen and > greylisting. I saw some differing opinions. But I did not > see this po

Re: postscreen delay inprovement - multple IP addresses

2017-07-07 Thread Noel Jones
On 7/7/2017 4:34 PM, techlist06 wrote: > I'm working on converting to using postscreen. Studying the details. I > have a question from the docs related to the delays due to the effective > greylisting caused by "Tests after the 220 SMTP server greeting". I believe > my server would qualify as a

Re: postscreen delay inprovement - multple IP addresses

2017-07-07 Thread techlist06
Thanks guys, I understand now. Much appreciated. -- View this message in context: http://postfix.1071664.n5.nabble.com/postscreen-delay-inprovement-multple-IP-addresses-tp91174p91182.html Sent from the Postfix Users mailing list archive at Nabble.com.

Re: postscreen with postgrey - can they cause a double reject?

2017-07-07 Thread techlist06
Thank you for the expert input. I will heed your advise. Scott -- View this message in context: http://postfix.1071664.n5.nabble.com/postscreen-with-postgrey-can-they-cause-a-double-reject-tp91176p91183.html Sent from the Postfix Users mailing list archive at Nabble.com.

Re: Configuration Syntax

2017-07-07 Thread Doug Hardie
> On 7 July 2017, at 08:44, Noel Jones wrote: > > On 7/7/2017 12:37 AM, Doug Hardie wrote: >> >>> On 6 July 2017, at 12:40, Doug Hardie wrote: >>> On 6 July 2017, at 12:06, Noel Jones wrote: main.cf doesn't allow spaces in the options. The supported syntax is to e