Limiting smtpd_upstream_proxy_protocol to certain IPs

2020-08-20 Thread Andreas Thienemann
Hi, I had the unfortunate situation the other day, that the network my postfix mailserver is in, was suddenly not reachable from parts of the Internet. Basically Vodafone messed up some internal filters. While they were trying to sort things out, I was having a look to see how I could reduce

Re: Limiting smtpd_upstream_proxy_protocol to certain IPs

2020-08-20 Thread Wietse Venema
Andreas Thienemann: > That being said, I think that it would be a really nifty feature - > similiar to the smtpd_authorized_xclient_hosts setting - to have a > smtpd_upstream_proxy_hosts setting which limits the > hangup-if-no-proxy-information-available functionality to these peers. > e.g. regul

Re: Limiting smtpd_upstream_proxy_protocol to certain IPs

2020-08-20 Thread Bastian Blank
Hi Andreas On Thu, Aug 20, 2020 at 01:28:38PM +0200, Andreas Thienemann wrote: > My plan was to setup a proxy on a backup machine somewhere else and just > proxy 25/tcp to my primary MX. My initial plan was to use > smtpd_upstream_proxy_protocol = haproxy and thus inform the smtpd of the > real so

Re: TLS client certificates and auth external

2020-08-20 Thread Steffen Nurpmeso
Hello. Wietse Venema wrote in <4bwxll093mzj...@spike.porcupine.org>: |Steffen Nurpmeso: |> I have no idea of the inner sensitivities of postfix, but i do not |> understand where the problem lies. Why does postfix "wave |> through" the SASL offering of EXTERNAL when it does not support |> it

Re: TLS client certificates and auth external

2020-08-20 Thread Wietse Venema
Steffen Nurpmeso: > Hello. > > Wietse Venema wrote in > <4bwxll093mzj...@spike.porcupine.org>: > |Steffen Nurpmeso: > |> I have no idea of the inner sensitivities of postfix, but i do not > |> understand where the problem lies. Why does postfix "wave > |> through" the SASL offering of EXTERN

Re: TLS client certificates and auth external

2020-08-20 Thread Viktor Dukhovni
On Thu, Aug 20, 2020 at 10:59:06AM -0400, Wietse Venema wrote: > There's a chicken and egg question in there somewhere. > > https://wiki1.dovecot.org/Authentication%20Protocol mentions > two attributes that might be relevant, and that Postfix can send: > > secured > Remote user has secured t

Re: how do I pass thru incomplete destination email addr to relayhost for 'To' rewrite?

2020-08-20 Thread Bob Proulx
Matthew Patton wrote: > > Why send mail as user@myhostname, when the named host will never > > ever receive email? > > Because I need to retain FROM what host it originated. If I see an > email from root@domain I have no idea which host it came from. In my mailer I would immediately look at the

Re: TLS client certificates and auth external

2020-08-20 Thread Steffen Nurpmeso
Good evening from Germany. Please excuse the late reply, it is midsummer here and i spend as much time as possible on the outside (mostly bicycling). (And just one more day, then the weather will change and it will be 10 degrees colder.) Wietse Venema wrote in <4bxstk189nzj...@spike.porcupine.o

Re: TLS client certificates and auth external

2020-08-20 Thread Steffen Nurpmeso
Viktor Dukhovni wrote in <20200820163012.gl86...@straasha.imrryr.org>: |On Thu, Aug 20, 2020 at 10:59:06AM -0400, Wietse Venema wrote: | |> There's a chicken and egg question in there somewhere. |> |> https://wiki1.dovecot.org/Authentication%20Protocol mentions |> two attributes that might