security level fingerprint does also check peername?

2019-12-19 Thread Max-Julian Pogner
Hi List! for a particular connection, i always received the error message "Server certificate not verified". client was postfix, server was postfix. both as distributed by debian stretch, version 3.1.12-0+deb9u1. i was using the following settings on the smtp-postfix:   relayhost=[localhost]:24  

Re: security level fingerprint does also check peername?

2019-12-19 Thread Viktor Dukhovni
On Thu, Dec 19, 2019 at 09:34:49AM +0100, Max-Julian Pogner wrote: > For a particular connection, I always received the error message > "Server certificate not verified". client was postfix, server was > postfix. Both as distributed by debian stretch, version > 3.1.12-0+deb9u1. > I was using the

Re: Postfix does not evaluate smtpd_recipient_restrictions when email is sent from localhost

2019-12-19 Thread postpeter
Hello Viktor, thank you for suggested solution. I am not advanced postfix admin so it is not easy to understand all and setup it quickly by above links. Do you know some other way how to restrict emails sent from PHP on localhost ? For example can I force PHP to send email through SMTP instead of

Re: Postfix does not evaluate smtpd_recipient_restrictions when email is sent from localhost

2019-12-19 Thread Wietse Venema
postpeter: > Hello Viktor, > thank you for suggested solution. I am not advanced postfix admin so it is > not easy to understand all and setup it quickly by above links. > > Do you know some other way how to restrict emails sent from PHP on localhost > ? > For example can I force PHP to send emai

Re: Postfix does not evaluate smtpd_recipient_restrictions when email is sent from localhost

2019-12-19 Thread Viktor Dukhovni
On Thu, Dec 19, 2019 at 04:31:20AM -0700, postpeter wrote: > Hello Viktor, > thank you for suggested solution. I am not advanced postfix admin so it is > not easy to understand all and setup it quickly by above links. I posted a solution on the Postfix side, that works regardless of the local su

When a 554 acts like a 471?

2019-12-19 Thread Bob Proulx
I have a case that is odd to me and I can't figure it out. Hopefully someone here will be able to set me straight. This is on a friend's system that I am helping to maintain. My friend somewhat out of the blue decided to start sending mail from a rented VM server. I hadn't expected and don't th

Re: When a 554 acts like a 471?

2019-12-19 Thread Noel Jones
On 12/19/2019 3:54 PM, Bob Proulx wrote: I have a case that is odd to me and I can't figure it out. Hopefully someone here will be able to set me straight. This is on a friend's system that I am helping to maintain. My friend somewhat out of the blue decided to start sending mail from a rented

Re: When a 554 acts like a 471?

2019-12-19 Thread Bob Proulx
Noel Jones wrote: > Bob Proulx wrote: > > But this confuses me. It appears to me that the message was rejected > > at SMTP time with a 554 code. Therefore shouldn't that generate a > > bounce message immediately? Why is dsn=4.7.1 being logged there? > > The remote server greeted postfix with a

Re: When a 554 acts like a 471?

2019-12-19 Thread Viktor Dukhovni
> On Dec 19, 2019, at 7:00 PM, Bob Proulx wrote: > > "By default, the Postfix SMTP client moves on the next mail > exchanger. Specify "smtp_skip_5xx_greeting = no" if Postfix should > bounce the mail immediately. Caution: the latter behavior appears to > contradict RFC 2821." > > But rega

Re: When a 554 acts like a 471?

2019-12-19 Thread Bob Proulx
Viktor Dukhovni wrote: > > Bob Proulx wrote: > > "By default, the Postfix SMTP client moves on the next mail > > exchanger. Specify "smtp_skip_5xx_greeting = no" if Postfix should > > bounce the mail immediately. Caution: the latter behavior appears to > > contradict RFC 2821." > > > > But reg