Re: how to set different send rate to different destination[ip]

2008-12-16 Thread Wietse Venema
You can set different rates for different destinations. For this, you MUST READ the rest of the URLs in my response. - specify a different (master.cf) transport for rate limited destinations. - specify (main.cf) mumble_destination_rate_delay values in main.cf. - specify a (main.cf) transport map

Re: smtp hangs on 4xx code response - active queue is stuck

2008-12-17 Thread Wietse Venema
> #1 0x0806d01f in read_wait (fd=-4, timeout=3600) at read_wait.c:120 > #2 0x08072241 in timed_read (fd=13, buf=0x8092d60, len=4096, timeout=3600, > unused_context=0x0) at timed_read.c:73 That makes no sense. timed_read() does not change its argument as shown below. But it does not matter. The

Re: smtp hangs on 4xx code response - active queue is stuck

2008-12-17 Thread Wietse Venema
Konrad Rzepecki: > Dnia _roda, 17 grudnia 2008, Wietse Venema napisa_: > > > > > Your defer daemons aren't working. > > > > > > If you mean this one: > > > postfix 29426 0.0 0.1 6472 1740 ?S14:24 0:00 bounce > &g

Re: smtp hangs on 4xx code response - active queue is stuck

2008-12-17 Thread Wietse Venema
Konrad Rzepecki: > > > #3 0x0806f20f in vstream_buf_get_ready (bp=0x80918f0) at vstream.c:731 > > > #4 0x0806eaf7 in vbuf_get (bp=0x80918f0) at vbuf.c:157 > > > #5 0x08063bcb in attr_vscan0 (fp=0x80918f0, flags=3, ap=0xafb16988 > > > "\001") at > > > attr_scan0.c:272 > > > #6 0x08063f9b in attr

Re: Postfix and DNSSEC

2008-12-17 Thread Wietse Venema
klondike: > Bernhard Fischer escribi?: > > I'd like to use DNSSEC with Postfix. > > I did some research on the web but although DNSSEC is there nobody really > > cares about it. > > The most recent patch for Postfix is for release 2.3 and is based on libs > > (libval, libsres) I didn't find any d

Re: Problem forwarding to a program

2008-12-18 Thread Wietse Venema
Rob Tanner: > I set up a separate instance of Postfix on one of my mail servers so > that I can deal with a special instance of a FAX server without messing > up production mail. The email messages it handles are always addressed > to @send.fax and the messages are to be delivered to a > prog

Re: Problem forwarding to a program

2008-12-18 Thread Wietse Venema
Rob Tanner: > The local aliases file and I was afraid of that. Since the only thing > going through this Postfix instance is the FAX stuff which needs to be > delivered to the program, is there some way to force all delivery to the > program unconditionally? A transport map entry: /etc/postfi

Re: Connection timeout when trying to send email to gmail address

2008-12-19 Thread Wietse Venema
Asif Iqbal: > I could skip the signing part and just a .pem file. But seems like I > will also need a Thawte certificate. You need no certificate to SEND mail. Wietse

Re: Connection timeout when trying to send email to gmail address

2008-12-19 Thread Wietse Venema
Asif Iqbal: > On Fri, Dec 19, 2008 at 12:46 PM, Wietse Venema wrote: > > Asif Iqbal: > >> I could skip the signing part and just a .pem file. But seems like I > >> will also need a Thawte certificate. > > > > You need no certificate to SEND mail. > >

Re: Special routing for mail from localhost

2008-12-19 Thread Wietse Venema
Terry Carmen: > Is there any way to have special routing for mail that's created on the > postfix server(localhost), destined for mydomain? As far as I recall, internally generated messages are not subject to the content_filter setting. Thus, you can use the content_filter parameter to send "regu

Re: Connection timeout when trying to send email to gmail address

2008-12-19 Thread Wietse Venema
Asif Iqbal: > > need to test it. Just set: > > > >smtp_tls_security_level = encrypt > > Thanks, I will put that in Just checked here that Postfix can talk SSL with [smtp.gmail.com]:587 just fine. But you need to set up client-side SASL authentication. Wietse

Re: Problems with user's mail file

2008-12-20 Thread Wietse Venema
Pedro Augusto: > If the problem is Mailscanner mangling the files, would an upgrade solve the > problem? > > How can I test if the problem is concurrent access? Just to be sure which of > these are the problems... Null bytes in mailbox files are usually the result of incorrect file locking. To f

Re: Connection timeout when trying to send email to gmail address

2008-12-20 Thread Wietse Venema
Asif Iqbal: > On Fri, Dec 19, 2008 at 5:32 PM, Wietse Venema wrote: > > Asif Iqbal: > >> > need to test it. Just set: > >> > > >> >smtp_tls_security_level = encrypt > >> > >> Thanks, I will put that in > > > > Jus

Re: Connection timeout when trying to send email to gmail address

2008-12-20 Thread Wietse Venema
Asif Iqbal: > Dec 20 21:25:20 improvise postfix/smtp[7157]: warning: SASL > authentication failure: No worthy mechs found This means that the SASL (NOT: SSL) mechanisms are not properly configured. > So I tried the openssl test and looks like I need a real certificate?! No, you need to fix the S

Re: transport documentation update proposed

2008-12-22 Thread Wietse Venema
Victor Duchovni: > On Mon, Dec 22, 2008 at 02:05:12AM -0300, Reinaldo de Carvalho wrote: > > > I suggest update transport documentation changing '*' to last lookup order. > > > > Beacause users can to deduct erroneously that '*' is a wildcard, and > > isn't. '*' is choosed caracter to represent a

Re: Stop retrying sending deferred messages when mailserver starts to tempfail?

2008-12-22 Thread Wietse Venema
Bas van Schaik: > Hi all, > > I have two company mailservers, both running Postfix. One of them is > "public" (accessible from the internet) and the other is used for > internal purposes only (i.e.: sending/recieving internal mail and > sending mail to the internet via the public mailserver). > >

Re: Subdomain matching problem

2008-12-22 Thread Wietse Venema
Munroe Sollog: > I will try to be as verbose as possible. I have been working with a > few people in IRC and can't seem to get the functionality wanted. I > have half a dozen servers, all with hostnames on a fake domain. I > want mail bound for r...@hostname to be forwarded to a central > locati

Re: Stop retrying sending deferred messages when mailserver starts to tempfail?

2008-12-22 Thread Wietse Venema
Bas van Schaik: > >> Eventually, all mail from the internal server gets through and other > >> mail traveling through the public mailserver does not get affected by > >> large delays. However, I think the internal mailserver should stop > >> processing the large batch of mail as soon as it notices

Re: warning: mysql query failed: MySQL server has gone away

2008-12-24 Thread Wietse Venema
J. Bakshi: > error3> warning: lookup owner-postmaster, NIS domain infoservices.in, > map mail.aliases: internal yp server or client error > ~~~` When reporting a problem, please do NOT remove useful information such as the name of the program that reports the pr

Re: DIGEST-MD5 user/realm mismatch with Dovecot auth

2008-12-25 Thread Wietse Venema
Darren Pilgrim: > Is it possible to alter how postfix sets the username and realm used by > the smtp client? Is the problem within cyrus-sasl or postfix? The Postfix SMTP client sends no realm information. If the server expects a login name in the form "u...@domain" then it is up to you to confi

Re: Reject/Discard mails to a Receipient

2008-12-26 Thread Wietse Venema
Linux Addict: > Sahil Tandon wrote: > > Linux Addict wrote: > > > > > >> Hello, I have clients sending mails to an non-existent email > >> address/domain, emailerm...@exchange.example.net. I want to discard any > >> mail sent to this address. I looked at smtpd_recipient_restrictions, but >

Re: Weaning myself off of procmail: .forward+tag

2008-12-26 Thread Wietse Venema
/dev/rob0: > First problem: well, I thought the alias would still have the Tag > extension, but no, ~rob0/.forward+Postfix was not used. According to > local(8), SECURITY: "The local(8) delivery agent disallows regular > expression substitution of $1 etc. in alias_maps, because that would > ope

Re: howto setup outgoing port to 587 ?

2008-12-27 Thread Wietse Venema
Vidar Salberg Normann: > Does this mean you can't make postfix treat traffic on port 587 exactly like > normal SMTP traffic on port 25, while also accepting SASL and/or AUTH > LOGIN if used? The only difference between 25 and 587 is in the Postfix master.cf file. Wietse

Re: flush daemon

2008-12-29 Thread Wietse Venema
punit jain: > > Don't look under the hood unless you know what you are looking at. > > I agree with you Viktor but i am just trying to get a clear picture of > postfix as a novice. > > What my concern is what will happen after setting fast_flush_domains to > relay domains and flushing the que

Re: Trying to use uppercase names in Postfix.

2008-12-29 Thread Wietse Venema
Xn Nooby: > I am using Postfix to replace an existing email system, and I am > inheriting usernames that are in uppercase. Apparently Postfix > converts all email addresses to lowercase, so I cannot receive mail to > the accounts that are in uppercase. This surprised me, because the > linux user a

Re: VERP uses the recipient name after virtual_regexp rewriting

2008-12-29 Thread Wietse Venema
Jesper Dybdal: > I have just installed a mailing list manager (Mailman) for use with my > Postfix installation (which has just been upgraded to 2.5.5). I have > patched Mailman to use the XVERP option on MAIL FROM. > > This works, but I was surprised to see that when the recipient address > provi

Re: Trying to use uppercase names in Postfix.

2008-12-29 Thread Wietse Venema
Xn Nooby: [ Charset ISO-8859-1 unsupported, converting... ] > On Mon, Dec 29, 2008 at 3:02 PM, Wietse Venema wrote: > > Xn Nooby: > >> I am using Postfix to replace an existing email system, and I am > >> inheriting usernames that are in uppercase. Apparently Post

Re: Trying to use uppercase names in Postfix.

2008-12-29 Thread Wietse Venema
Xn Nooby: > > Your options are: > > > > 1) Create lower-case UNIX password file entries with the same > > numerical UID and GID fields as the upper-case names, and with a > > "*" password. > > I was able to resolve my problem by creating the duplicate entry in > the /etc/passwd file, I will use t

Re: VERP uses the recipient name after virtual_regexp rewriting

2008-12-30 Thread Wietse Venema
Jesper Dybdal: > On Tue, 30 Dec 2008 01:10:16 +0100, I wrote: > > >Since my first mail, I have tried an experiment where the rewriting of > >the sender address is done by a .forward file instead of by > >virtual_regexp; in that case, VERP actually uses the recipient address > >before it has been c

Re: Handling VERP bounces

2008-12-30 Thread Wietse Venema
ram: > If I am getting bounces for VERP ids With VERP, the envelope recipient rcptn...@rcptdomain is embedded in the bounce address as owner-listname+rcptname=rcptdom...@example.com (assuming recipient delimiters of "+="). > The postfix VERP HOWTO describes how to handle the emails that bou

Re: Enforcing sending domain from the inside network

2008-12-30 Thread Wietse Venema
D. Karapiperis: > I did the from_inside_network thing to do the logical AND regarding the > sending domain. Is there any way to do this woth permit_mynetworks? > > Is there any way to permit local users (from the inside network) to send > emails using the business domain in a clear and nice way

Re: Enforcing sending domain from the inside network

2008-12-30 Thread Wietse Venema
Victor Duchovni: > On Tue, Dec 30, 2008 at 12:38:38PM -0500, Wietse Venema wrote: > > > For example > > > > /etc/postfix/main.cf: > > smtpd_sender_restrictions = > > check_sender_access hash:/etc/postfix/sender_access > > check_client_a

Re: Segmentation errors

2008-12-30 Thread Wietse Venema
webmas...@aus-city.com: > Hi, > > I keep getting these errors in /var/log/messages and can't work out why.. > > Dec 31 10:07:59 server kernel: postfix-queue[1323]: segfault at > 2068616e ip 08049f09 sp bfc13920 error 4 in postfix-queue[8047000+e000] > Dec 31 10:12:01 server kernel: postfix-queu

Re: Alias piping + mysql in virtual domains

2008-12-30 Thread Wietse Venema
Sahil Tandon: > Joselito wrote: > > > I'm moving an existing domain to virtual mailboxes. All the info is > > stored in a mysql database. Currently all devlivery and alias mapping > > is working correctly; I'm using virtual_mailbox_maps, > > virtual_alias_maps and virtual_mailbox_domains stored

Re: Delivered to command difference if .procmailrc exists

2008-12-30 Thread Wietse Venema
Jacob Anawalt: > Hello, > > My configured mailbox_command has been 'procmail -a "$EXTENSION"' for > the longest time. I did not notice the difference between emails > 'delivered to command: procmail -a "$EXTENSION" and those 'delivered > to command: /usr/bin/procmail' because it was procmail in bo

Re: rewrite recipients after /etc/aliases is processed

2008-12-31 Thread Wietse Venema
Hanspeter Kunz: > well, my intention was to use /etc/aliases for forwarding mail adresses > like root, webmaster, logcheck, etc. to real users. This would be > different users on every host. That's why I want first to > process /etc/aliases and then route the mail to our central mail server. /etc/

Re: postfix questions: when emails are being rejected...

2008-12-31 Thread Wietse Venema
Hwan Dong: > > Hi there, > ? > Instead of?paying email professionals, I set up a postfix SMTP server to s >-end emails to the club members. I have also successfully enabled the delay b >-etween sending to some ISPs. But as more as I am sending, I could still get >-rejection. Do you have similar e

Re: Delivered to command difference if .procmailrc exists

2008-12-31 Thread Wietse Venema
Your measurements use two different users, one with .procmailrc file and one without .procmailrc file. To prove that the difference in behavior is caused by the presence or absence of .procmailrc files, you need to deliver mail to the EXACT SAME user and change NOTHING except the presence/existenc

Re: Delivered to command difference if .procmailrc exists

2008-12-31 Thread Wietse Venema
Jacob Anawalt: > On Wed, Dec 31, 2008 at 7:39 AM, Wietse Venema wrote: > > To prove that the difference in behavior is caused by the presence > > or absence of .procmailrc files, you need to deliver mail to the > > EXACT SAME user and change NOTHING except the presence

Re: Postfix and multiple smarthosts

2008-12-31 Thread Wietse Venema
Andrew Hodgson: > Hi, > > I am trying to find the answer whether Postfix will support multiple > smarthosts - i.e, sending to specific smarthosts, and if one fails, it > will try to send to the next one in the list, or will just use any > smart host in the list without issue? relayhost = [one.exa

Re: RCPT TO problem using relay host

2009-01-01 Thread Wietse Venema
Dennis Putnam: > I have a machine running postfix that is required to relay mail > through my ISP's mail server. When I try to send mail, I get this error: > > 550 [PERMFAIL] destination not valid within DNS (in reply to RCPT TO > command) > > Can someone explain what this error means? If I u

Re: rate limit outgoing mails with mailman

2009-01-02 Thread Wietse Venema
ja...@monsterjam.org: > hey folks.. Im running the latest postfix on an ubuntu server with > mailmain for mailing list management.. everything is pretty much working > fine except that Im trying to get some kind of rate-limiting or > throttling working for all outbound messages. Ive searched all ov

Re: rate limit outgoing mails with mailman

2009-01-02 Thread Wietse Venema
ja...@monsterjam.org: > > The following requires Postfix 2.5 or later: > > > > /etc/postfix/main.cf: > > # Deliver all mail via the "smtp" transport in master.cf. > > # Use [] to suppress MX lookup. > > relayhost = [mail.example.com] > > default_transport = smtp > > smtp_destin

Re: keep "Sensitivity" MIME header upon bounces/DSNs

2009-01-02 Thread Wietse Venema
Ralf Hauser: > Since certain MUAs such as MS Outlook allow the user to label messages as > "confidential" which according to http://www.faqs.org/rfcs/rfc1327.html gets > translated into MIME header "Sensitivity=Company-Confidential", quite some > secure mail gateways ensure higher transmission secr

Re: Finding the envelope-sender after always_bcc? (SOLVED)

2009-01-02 Thread Wietse Venema
Jeff Weinberger: [ Charset ISO-8859-1 unsupported, converting... ] > On Jan 2, 2009, at 2:30 AM, mouss wrote: > > > Jeff Weinberger a ?crit : > >> > >> I used a pcre: table for smtpd_sender_restrictions and the PREPEND > >> action as follows: > >> > >> main.cf: > >> smtpd_sender_restrictions =

Re: VERP uses the recipient name after virtual_regexp rewriting

2009-01-02 Thread Wietse Venema
Jesper Dybdal: > On Mon, 29 Dec 2008 21:54:52 +0100, I wrote: > > >... I was surprised to see that when the recipient address > >provided by Mailman is rewritten by Postfix' virtual_regexp, then the > >recipient address that Postfix encodes in the envelope return path is > >the rewritten address,

Re: rate limit outgoing mails with mailman

2009-01-02 Thread Wietse Venema
ja...@monsterjam.org: > excellent idea, so I did install the 2.5.4 version from the backport > and I now have > r...@ohs:~# grep smtp_destination_rate_delay /etc/postfix/main.cf > smtp_destination_rate_delay = 10 > r...@ohs:~# > and I restarted postfix > Jan 2 08:03:56 ohs postfix/master[16208]:

Re: rate limit outgoing mails with mailman

2009-01-02 Thread Wietse Venema
Jason Welsh: > my apologies.. here is the output of postconf -n Did you notice that there is no smtp_destination_rate_delay Wietse

Re: rate limit outgoing mails with mailman

2009-01-02 Thread Wietse Venema
> Jan 2 16:04:57 ohs postfix/smtp[18389]: B08B018A00: > to=, relay=outgoing.verizon.net[206.46.232.12]:25, > delay=0.89, delays=0.08/0.28/0.35/0.17, dsn=2.5.0, status=sent (250 2.5.0 Ok.) > Jan 2 16:04:57 ohs postfix/qmgr[18371]: B08B018A00: removed > Jan 2 16:05:12 ohs postfix/smtp[18389]: E5

Re: Finding the envelope-sender after always_bcc? (SOLVED)

2009-01-02 Thread Wietse Venema
Jeff Weinberger: > That said, here's the current configuration: > > content_filter=dspam:dspam > > and in master.cf: > > dspam unix - n n - 10 pipe > flags=Ru user=_dspam argv=/usr/local/bin/dspam -- > deliver=innocent --user ${recipient} -

Re: bounce_size_limit

2009-01-03 Thread Wietse Venema
Ralf Hauser: > Hi Wietse, > > Thx for the quick reply. > > > This can cause contents to be disclosed since not treated properly by > > > above-mentioned gateways (in particular, if the main.cf doesn't say > > > bounce_size_limit=1 [the value 0 is not permitted??]). > > > > Normally, "zero" means

Re: running a second custom smtpd on second IP address

2009-01-03 Thread Wietse Venema
Drew Derbyshire: > I've got a postfix server running which accepts several domains on it's > primary smtpd (kew.com, *.wild.kew.com, thinfilmmfg.com, > *.wild.thinfilmmfg.com, ...), all protected by the usual (and some > unusual) SPAM filters. Life is good. > > I'd like to set up a secondary s

Re: running a second custom smtpd on second IP address

2009-01-03 Thread Wietse Venema
Drew Derbyshire: [ Charset ISO-8859-1 unsupported, converting... ] > Wietse Venema wrote: > > > > The problem is that the distinction between domain classes > > (mydestination, relay_domains, virtual_alias_domains, > > virtual_mailbox_domains) is made by

Re: Postix relay gateway - "Recipient address rejected" notification verbosity ...

2009-01-03 Thread Wietse Venema
Postfix 2.6 and later allow you to override the SMTP server response with the unverified_recipient_reject_reason parameter. See http://www.postfix.org/ADDRESS_VERIFICATION_README.html Wietse

Re: Postix relay gateway - "Recipient address rejected" notification verbosity ...

2009-01-03 Thread Wietse Venema
eject_reason parameter. > Antony > > -Message d'origine- > De?: owner-postfix-us...@postfix.org > [mailto:owner-postfix-us...@postfix.org] De la part de Wietse Venema > Envoy??: dimanche 4 janvier 2009 00:36 > ??: Postfix users > Objet?: Re: Postix re

Re: Header/body checks question, problem.

2009-01-04 Thread Wietse Venema
KLaM Postmaster: > Among the stuff being rejected is the output of pflogsumm, I run a daily > a report and email it to postmaster. I was not getting the reports so I See http://www.postfix.org/http://www.postfix.org/BUILTIN_FILTER_README.html section "Preventing daily mail status reports from bein

Re: Compile error Slackware 12.2 postfix 2.5.6 smtp_reuse.c

2009-01-04 Thread Wietse Venema
This is the result of a cut-and-paste error. I have re-issued the releases. Wietse

Postfix stable release 2.5.6, 2.4.10 and 2.3.16 available

2009-01-04 Thread Wietse Venema
Postfix stable releases 2.5.6, 2.4.10 and 2.3.16 catch up on fixes that were applied in the past three months. Postfix versions 2.2 and earlier are no longer updated. - Postfix 2.5: the SMTP server did not ask for a client certificate with "smtpd_tls_req_ccert = yes". Reported by Rob Foehl. - Po

Re: per recipient transport [Was: Evaluation of maps in local or virtual address classes]

2009-01-04 Thread Wietse Venema
mouss: > Victor Duchovni a ?crit : > > On Mon, Jan 05, 2009 at 03:31:52AM +0100, mouss wrote: > > > >> Victor Duchovni a ?crit : > >>> [snip] > >>> Why per-recipient transport lookups? Often better to rewrite to a domain > >>> where the entire domain is handled by lmtp(8). > >>> > >> is there a be

Re: Using Postfix for business continuity

2009-01-05 Thread Wietse Venema
Kenneth Kalmer: > Hi all > > Just got asked by one our sales guys if we could implement a Postfix > business continuity service, by his definition it means that Postfix acts as > a normal backup MX but gives the users access to their email via webmail of > sorts. > > I understand the issues of us

Re: Why relay_domains defaults to mydestination?

2009-01-05 Thread Wietse Venema
Jeremie Le Hen: > Hi list again, > > Wietse, I take advantage of this new email to thank you for your reply > to my earlier email. > > This time I just wonder why relay_domains defaults to mydestination? Backwards compatibility. Wietse

Re: virtual_alias_maps/relay_recipient_maps in smtpd_recipient_restrictions

2009-01-05 Thread Wietse Venema
Jeremie Le Hen: > Hi list ! > > As far as I understand, there is an "implicit" check in the > smtpd_recipient_restrictions parameter when virtual_alias_maps > or relay_recipient_maps is specified. But when does it append? By default, the check happens at the end. However, you can specify the do

Re: CDB map files for virtual alias maps

2009-01-06 Thread Wietse Venema
ram: > if I use >virtual_alias_maps = cdb:/path/mapfile > This doesnt work if mails are sent to users in uppercase Please show evidence of this in the form of SMTP commands and Postfix logging. Wietse

Re: Getting reject_sender_login_mismatch/smtpd_sender_login_maps and mysql to work together

2009-01-06 Thread Wietse Venema
Jeff Weinberger: > I then added the line: > > smtpd_sender_login_maps=hash:/path/to/map > > to my main.cf and send a few messages. Postfix correctly allowed and > rejected all of the test messaages, and the logs showed the correct > reason for the rejection, and no log entries showing a succe

Re: CDB map files for virtual alias maps

2009-01-07 Thread Wietse Venema
ram: > > On Tue, 2009-01-06 at 09:57 -0500, Victor Duchovni wrote: > > On Tue, Jan 06, 2009 at 07:58:07PM +0530, ram wrote: > > > > > [r...@50.133 postfix]# postmap -q t...@netcore.co.in cdb:/etc/postfix/vmap > > > r...@netcore.co.in > > > [r...@50.133 postfix]# postmap -q t...@netcore.co.in cdb:

Re: CDB map files for virtual alias maps

2009-01-07 Thread Wietse Venema
ram: > > With all Postfix versions, the postmap command by default always > > case folds CDB lookup keys, both on create and on query. > > > > If someone is distributing "improved" Postfix versions then you > > need to file a complaint. > > > > So that seems to be it. I would really need to comp

Re: Problem with notifications

2009-01-07 Thread Wietse Venema
Michael JOLY: > Hello, > > I have a problem. When i sent a mail to mailboxes of my domain and i > request notifications of delivery, i receive two notifications : one says > that the message is delivered (that's right) and another that tells the > message has not been delivered. Postfix delivery

Re: Question regarding reject_unlisted_sender

2009-01-07 Thread Wietse Venema
Bill Landry: > I'm following a discussion on another list regarding a Communigate > gateway that is rejecting spoofed "MAIL FROM" before "RCPT TO" is > received. This is perfectly legitimate usage of SMTP. Clients that cannot handle this are broken. Postfix's delayed "reject" works around broken

Re: fatal: open file trace :Permission denied

2009-01-07 Thread Wietse Venema
I'd say, run "postfix set-permissions" and if that does not do the job, kill off or update SELINUX, APPARMOR, etc. Wietse

Re: Access and smtpd_sender_restrictions

2009-01-08 Thread Wietse Venema
Martin Spinassi: [ Charset UTF-8 unsupported, converting... ] > Hi list! > > I'm trying to install a postfix with some restrictions, including a > sender restriction, but I'm just missing something. > > The idea is to allow only one domain to send mails from that server, but > I'm having access d

PATCH: bug from May 19, 1997

2009-01-08 Thread Wietse Venema
While adding a feature I ran into a problem that is so old that I had to dig into my pre-alpha source code to find when it was introduced. Bugfix (introduced May 19, 1997): removing a parameter setting from main.cf did not reset the parameter to its default value. File: gl

Re: PATCH: bug from May 19, 1997

2009-01-09 Thread Wietse Venema
Victor Duchovni: > Translation, this only matters for parameters that change the behaviour > of the master daemon. Removing such a parameter from main.cf did not > result in changed master(8) behaviour without a full restart. > > Most users don't modify master(8) parameters other than inet_interfa

Re: Preventing domain mails from outside

2009-01-09 Thread Wietse Venema
Norm Mackey: > Received: by www.thisisireallymydomain.com (Postfix) > id 3C916254775; Tue, 30 Dec 2008 03:50:01 -0800 (PST) That mail did not arrive via SMTP. Look in your maillog file around that time. If this mail comes from your HTTP account, the look in the HTTP logs for details. If the HT

Re: Problem with http://www.postfix.org/postconf.5.html

2009-01-10 Thread Wietse Venema
mouss: > Luigi Rosa a ?crit : > > Markus Sch?nhaber said the following on 10/01/09 13:35: > > > >> Is there something wrong with the server / anyone else seeing this? I typo-ed in the source file. Bad: Specify a value > 0 and < 65536 to enable this feature. Good:Specify a value > 0 and < 65536

Re: Preventing domain mails from outside

2009-01-10 Thread Wietse Venema
Sahil Tandon: > > > > > Received: by www.thisisireallymydomain.com (Postfix) > > > > id 3C916254775; Tue, 30 Dec 2008 03:50:01 -0800 (PST) > > > > Delivered-To: n...@thisisireallymydomain.com > > > > Received: from alkhorayef.com (unknown [91.189.132.54]) I repeat, this mail did not arrive via t

Re: Question about transport

2009-01-10 Thread Wietse Venema
Sahil Tandon: > M Mollar wrote: > > > For my docent activity, I need to setup a transport like this: > > > > /(.*.dyn.nisu.org)/smtp:[$1]:2500 > > > > My students will setup a postfix server in their computers, but they > > cannot listen port 25. I update dns dynamically, so the mail dir

Re: fatal: open file trace :Permission denied

2009-01-11 Thread Wietse Venema
N. Yaakov Ziskind: > In: DATA > Out: 354 End data with . > Out: 451 4.3.0 Error: queue file write error > > puzzling. The actual problem is logged in the MAILLOG file. Postfix does not divulge internal problem details to SMTP clients. Wietse

Re: fatal: open file trace :Permission denied

2009-01-11 Thread Wietse Venema
N. Yaakov Ziskind: > Wietse Venema wrote (on Wed, Jan 07, 2009 at 09:03:42PM -0500): > > I'd say, run "postfix set-permissions" and if that does not > > do the job, kill off or update SELINUX, APPARMOR, etc. > > > > Wietse > > # postfix/post

Re: Is it possible to run 2 or more Postfix instances on a single machine?

2009-01-11 Thread Wietse Venema
Jet Wilda: > Hi, > > Is it possible to run 2 or more postfix instances on a single machine? > If so what steps are necessary to make it work? Thanks in advance for any > and all help. You need a new config_directory, and it needs a main.cf and master.cf file The main.cf file specifies a mail

Re: Adding a table to proxy_read_maps...

2009-01-11 Thread Wietse Venema
Charles Marcus: > First question... is there a reason that none of the *_limit_maps are > included in proxy_read_maps by default? I.e., maybe doing this is not > recommended? There are no _limit_maps parameters in Postfix. Someone must have introduced these with a patch, and botched the job by not

Re: Can't stop UNDELIVERED MAIL RETURNED TO SENDER emails

2009-01-12 Thread Wietse Venema
David Cottle: > Content-Description: Undelivered Message > Content-Type: message/rfc822 > Content-Transfer-Encoding: 8bit > > Received: from server.engineering.idb (unknown [127.0.0.1]) > by server.engineering.idb (Postfix) with ESMTP id C3F5B13C002D > for ; Sun, 11 Jan 2009 23:43:36 +

Re: Can't stop UNDELIVERED MAIL RETURNED TO SENDER emails

2009-01-12 Thread Wietse Venema
David Cottle: > On 13/01/2009, at 10:13, wie...@porcupine.org (Wietse Venema) wrote: > > > David Cottle: > >> Content-Description: Undelivered Message > >> Content-Type: message/rfc822 > >> Content-Transfer-Encoding: 8bit > >> > >>

Re: Can't stop UNDELIVERED MAIL RETURNED TO SENDER emails

2009-01-12 Thread Wietse Venema
David Cottle: > > On 13/01/2009, at 11:44, wie...@porcupine.org (Wietse Venema) wrote: > > > David Cottle: > >> On 13/01/2009, at 10:13, wie...@porcupine.org (Wietse Venema) wrote: > >> > >>> David Cottle: > >>>> Content-Descript

Re: Can't stop UNDELIVERED MAIL RETURNED TO SENDER emails

2009-01-12 Thread Wietse Venema
David Cottle: > >> Received: from server.engineering.idb (unknown [127.0.0.1]) > >> by server.engineering.idb (Postfix) with ESMTP id C3F5B13C002D > >> for ; Sun, 11 Jan 2009 23:43:36 + ... > > THIS WAS MAIL FOR webmas...@aus-city.com. > > The postmaster address on every domain e

Re: Problem with Zen filtering legit e-mail

2009-01-13 Thread Wietse Venema
Roland Pl??ss: > I never received nor got pointed to a DEBUG_README at all. Where's this one? > Below is the mailing list welcome that you ignored. Wieste TO REPORT A PROBLEM see http://www.postfix.org/DEBUG_README.html#mail TO (UN)SUBSCRIBE see http://www.postfix.org/lists.html Thank

Re: Parameter %s to %...@%d

2009-01-13 Thread Wietse Venema
MSG Support: > Hi, > > Our mail server encounter below error on the log: > > Dec 4 04:34:09 localhost postfix/cleanup[26596]: warning: > 3E0582648E7: virtual_alias_maps map lookup problem for > u...@internaldomain Your logfile has much more information on this. See: http://www.postfix

Re: xforward and 503 errors

2009-01-13 Thread Wietse Venema
Eric S. Johansson: > I've been over the documentation, mailing list archives, Google a few times > but > I'm not seeing what's wrong. I would appreciate some help. http://www.postfix.org/XFORWARD_README.html After receiving the server's announcement for XFORWARD support, the client may send XFO

Re: backscattering

2009-01-13 Thread Wietse Venema
Bruno GRANDJEAN: > how can I reject mail from outside claiming to be from my domain? > > with a 'from:' header only in the header_checks internal users > cannot send emails, outgoing traffic was completely blocked. If you reject mail from outside with your address in the From: header, then you wo

Re: How to restrict ACCESS not RELAY to the SMTP daemon?

2009-01-13 Thread Wietse Venema
Thomas: > Hello, > i try to figure out how to restrict ACCESS to the SMTP daemon. > > With that, i mean something like the tcpwrapper for SMTP/SMTPS ... > > For what? > > I have several root-Servers, vServer and Xen domains - only one is the > mail system and should be available for mail from t

Re: Share postfix config directory

2009-01-14 Thread Wietse Venema
Rocco Scappatura: > Hello, > > I have different SMTP gateways each one configurred exactly at the same > manner. The only difference is the hostname. > > I would like to know if I could define "/etc/postfix" as an NFS share > somewhere and export it on each of my SMTP gateways. The aim is > obvio

Re: connection timeout on win2007 exchange

2009-01-14 Thread Wietse Venema
bharathan kailath: > Hi > > Jan 13 15:43:41 relay1 postfix/smtp[18476]: 5BF411611EE: to=< > valer...@example.com>, relay=xxx.xxx.xxx.xxx[1xxx.xxx.xxx.xxx > ]:25, delay=101565, delays=100962/0.02/3.4/600, dsn=4.4.1, status=deferred > (host xxx.xxx.xxx.xxx[xxx.xxx.xxx.xxx] said: 421 4 > .4.1 Connect

Re: ETRN

2009-01-14 Thread Wietse Venema
bharathan kailath: > we've got a gateway postfix server with which we provide mails to hosted > domains; postfix is configured with Separate Domains with System Accounts > (virtual alias domains and virtual alias maps); clients mail server pop up > and collect all the their mails; it works great; b

Re: Share postfix config directory

2009-01-14 Thread Wietse Venema
Rocco Scappatura: > > > I have different SMTP gateways each one configurred exactly at the > > same > > > manner. The only difference is the hostname. > > > > > > I would like to know if I could define "/etc/postfix" as an NFS > share > > > somewhere and export it on each of my SMTP gateways. The a

Re: Configure an Alternate Interface for Destination

2009-01-14 Thread Wietse Venema
Chris Babcock: Checking application/pgp-signature: FAILURE -- Start of PGP signed section. > On Wed, 14 Jan 2009 10:50:01 -0600 (CST) > "Matt Rude" wrote: > > > > > > > /etc/postfix-asciiking/main.cf: > > > transport_maps = hash:/etc/postfix-asciiking/transport Show "postconf -n" output instead

Re: SPF Checking

2009-01-14 Thread Wietse Venema
Russ Lavoy: > Hello List, > > I am wondering about an SPF checking addition for postfix. Where I see al >-l of the addon software, I am not 100% comfortable modifying the postfix cod >-e and still have it be as secure as it was when I first set it up. > > Are there any plans on integrating SPF c

Re: holding messages for one address or one domain in the queue?

2009-01-14 Thread Wietse Venema
Jeff Weinberger: > This may seem like an odd question, but I need to find a way to > suspend delivery of mail to one account or one domain for a short > period of time to allow me to do a bit of maintenance. > > As it stands now, I use maildrop as my delivery transport for virtual > mailboxe

Re: Share postfix config directory

2009-01-15 Thread Wietse Venema
Rocco Scappatura: > > > > > I have different SMTP gateways each one configurred exactly at > > the > > > > same > > > > > manner. The only difference is the hostname. > > > > > > > > > > I would like to know if I could define "/etc/postfix" as an NFS > > > share > > > > > somewhere and export it on

Re: vServer system resources

2009-01-15 Thread Wietse Venema
Nathan H?sken: > Hi, > > I have installed postfix on a small vServer (256Mb Ram, 10GB HD). I > installed it with dovecot, mysql and postfixadmin. > When I tested it, I got lots of "Cannot allocate Memory" errors. The primary MX for porcupine.org runs on a "non-virtual" machine with 256MB and neve

Re: running on different ports

2009-01-15 Thread Wietse Venema
Leonardo Rodrigues Magalh?es: > > Let's suppose i have postfix running smtpd processes in two > different ports. 25 and 587, for example. > > is it possible, in the logs, to differ which connections came from > 25 and which came from 587 ?? I know i can analyze the full transaction ht

Re: Requirement to "always_bcc" except when email is internal

2009-01-15 Thread Wietse Venema
Eric Sammons: > I have a requirement to always_bcc except when email is internal. Instead of always_bcc use sender_bcc_maps or recipient_bcc_maps. > I have > investigated options such as always_bcc, sender|recipient_bcc_maps and none > seem to fully address the issue. Yes they do. Just configur

  1   2   3   4   5   6   7   8   9   10   >