[pfx] server does not pick up new certificates

2023-07-20 Thread lejeczek via Postfix-users
Hi guys. I use what I believe is pretty much vanilla-common setup - snis.map I had to restart the deamon/server in order for _postix_ to notice new certs - naturally located in same one place - reload did not do. My question - is this some kind of a glitch? I'd not think 'postfix' would beh

[pfx] Re: server does not pick up new certificates

2023-07-23 Thread lejeczek via Postfix-users
On 20/07/2023 21:14, Viktor Dukhovni via Postfix-users wrote: On Thu, Jul 20, 2023 at 07:11:41PM +0200, lejeczek via Postfix-users wrote: I use what I believe is pretty much vanilla-common setup - snis.map I had to restart the deamon/server in order for _postix_ to notice new certs

[pfx] Re: server does not pick up new certificates

2023-07-23 Thread lejeczek via Postfix-users
On 23/07/2023 16:00, Wietse Venema wrote: lejeczek via Postfix-users: -> $ postfix reload # did not work, new certs/files where only picked up with "full" restart, with "systemd" in this case. and when done, then server-postifx supplied new certs immediately - clie

[pfx] Re: server does not pick up new certificates

2023-07-23 Thread lejeczek via Postfix-users
On 23/07/2023 16:00, Wietse Venema wrote: lejeczek via Postfix-users: -> $ postfix reload # did not work, new certs/files where only picked up with "full" restart, with "systemd" in this case. and when done, then server-postifx supplied new certs immediately - clie

[pfx] Re: server does not pick up new certificates

2023-07-23 Thread lejeczek via Postfix-users
On 23/07/2023 18:50, Viktor Dukhovni via Postfix-users wrote: On Sun, Jul 23, 2023 at 09:39:52AM +0200, lejeczek via Postfix-users wrote: What is "snis.map", and how is it used in your configuration? tls_server_sni_maps = hash:/etc/postfix/snis.map And when did you r

[pfx] Re: server does not pick up new certificates

2023-07-24 Thread lejeczek via Postfix-users
On 23/07/2023 22:44, Viktor Dukhovni via Postfix-users wrote: On 23 Jul 2023, at 4:21 pm, Charles Sprickman via Postfix-users wrote: In the case of the dehydrated ACME client (https://github.com/dehydrated-io/dehydrated) there's an option to run a bunch of commands on successful update, in

[pfx] Relay access denied (Dovecot)

2023-09-04 Thread lejeczek via Postfix-users
Hi guys. Having a goal to use Dovecot's auth & delivery I have this (before I dump whole config the snippet I guess is relevant) : ... smtpd_sasl_type = dovecot smtpd_sasl_path = private/auth smtpd_sasl_local_domain = aa.dom bb.dom cc.dom smtpd_sasl_security_options = noanonymous broken_sasl_au

[pfx] Re: Relay access denied (Dovecot)

2023-09-04 Thread lejeczek via Postfix-users
On 04/09/2023 15:05, Jaroslaw Rafa via Postfix-users wrote: Dnia 4.09.2023 o godz. 14:53:42 lejeczek via Postfix-users pisze: Postfix logs when mail is sent to it: ... connect from smtpo71.interia.pl[217.74.67.71] Anonymous TLS connection established from smtpo71.interia.pl[217.74.67.71

[pfx] local ROOT - forward + keep copy

2023-11-06 Thread lejeczek via Postfix-users
Hi guys. I'd hope some experts here have it figured out long time ago & would be happy to advise on: How to keep root's mail locally, on each machine + at the same time have a copy forwarder to another address. More specifics on what I'm thinking: r...@box1.my.private r...@box2.my.private e

[pfx] local domain email collection

2023-11-06 Thread lejeczek via Postfix-users
Hi guys. How do you do your local domain local root mail collection? Having a numer of boxes, say: r...@box1.my.private r...@box2.my.private etc.. I'm thinking having each box's root I'd forward to _allmail@my.private_ - probably it's how many, if not everybody, do it. Here, my 'allmail' is a

[pfx] Re: local domain email collection

2023-11-06 Thread lejeczek via Postfix-users
On 06/11/2023 15:25, Wietse Venema via Postfix-users wrote: lejeczek via Postfix-users: Hi guys. How do you do your local domain local root mail collection? Having a numer of boxes, say: r...@box1.my.private r...@box2.my.private etc.. Have you considerd using local aliases to forward mail

[pfx] should a local relay be paranoid

2023-11-06 Thread lejeczek via Postfix-users
Hi guys. Even though it's only local network, a relay which is final destination only to: mydestination = $myhostname, localhost.$mydomain, localhost has to _relay_ to central, also local postfix which postfix takes "all" the required security precautions in. Should such _relaying_ postfix

[pfx] localhost rejected ?

2023-12-04 Thread lejeczek via Postfix-users
Hi guys. I can send email to root@localhost and I thought it was all good but today a tool/client wanted to send an email to that address and it got: ... connect from localhost[127.0.0.1] NOQUEUE: reject: RCPT from localhost[127.0.0.1]: 504 5.5.2 : Recipient address rejected: need fully-qual

[pfx] warning: table lmdb key malformed value

2025-05-06 Thread lejeczek via Postfix-users
Hi guys. I postmaped my: ... tls_server_sni_maps = lmdb:/etc/postfix/snis.map .. but when I try to send out I get: May 06 12:31:20 brama.mine.priv postfix/submission/smtpd[80067]: warning: run-time library vs. compile-time header version mismatch: OpenSSL 3.5.0 may not be compatible with Ope

[pfx] Re: warning: table lmdb key malformed value

2025-05-06 Thread lejeczek via Postfix-users
thanks, Even had it my notes, I skipped two releases of OS and some changes to binaries made me anxious a bit, unnecessarily. ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org

[pfx] Re: more SELinux denials - fifo_file

2025-06-18 Thread lejeczek via Postfix-users
hi guys. All these SELinux denials were caused by an external tool (part of the HA management actually & running on the same box as postfix), a script which part is:     sendmail)     sendmail -t -r "${email_sender}" <<__EOF__ From: ${email_sender} To: ${email_recipient} Return-Pat

[pfx] more SELinux denials - fifo_file

2025-06-17 Thread lejeczek via Postfix-users
Hi guys. I have a seemingly healthy, working postfix yet logs are full of denials, one specific denial, so I wonder if that is perhaps some misconfiguration on my part, although again, all seem to work. Any/all thoughts are much appreciated. Thanks. In short, that would be needed (at least)

[pfx] Re: more SELinux denials - fifo_file

2025-06-17 Thread lejeczek via Postfix-users
-> $ postconf -Mf | egrep -i '(pickup|qmgr)' pickup unix  n   -   n   60  1   pickup qmgr   unix  n   -   n   300 1   qmgr  in full: -> $ postconf -Mf amavisfeed unix  -   -   n   -   2   lmtp     -o lmtp_data_done_timeout=1200

[pfx] Re: more SELinux denials - fifo_file

2025-06-17 Thread lejeczek via Postfix-users
Ii only removed lines with: smtpd_sasl_local_domain & virtual_mailbox_domains, for privacy reason -> $ postconf -nf | egrep -v '(smtpd_sasl_local_domain|virtual_mailbox_domains|jatymy.xyz|ubunt)' | __grepColorIt ubunt alias_database = hash:/etc/aliases alias_maps = hash:/etc/aliases broken_sa

[pfx] Re: more SELinux denials - fifo_file

2025-06-17 Thread lejeczek via Postfix-users
Maybe you have multiple Postfixen installed. Well, I have a kind of HA setup which comprises of three boxes, One of those boxes is a "master" which might (configs/output shown earlier) float, migrate & run on any of of those boxes - just one at any given time - then remaining two "switch" to "r

[pfx] Re: more SELinux denials - fifo_file

2025-06-17 Thread lejeczek via Postfix-users
Could it be something that postfix uses, something calls out, a third-party? There is nothing 'explicit' in my master.cf nor in main.cf which mentions 'fifo/file'. I find in 'dovecot' which is used for auth (& delivery I think), this: ... service director {   unix_listener login/director {