Re: Oauth2 MFA config

2024-05-24 Thread A. Schulze via dovecot
Am 23.05.24 um 22:07 schrieb Scott Q. via dovecot: Anyone managed to get Dovecot working as smoothly with OAUTH2 as Gmail has with Outlook ? So that for example when you add the account up in Outlook it performs all the required steps for saving the device, getting tokens, etc. Ideally with

using keycloak

2024-04-25 Thread A. Schulze via dovecot
Hello, I'm relative new to oauth2. I like to understand a setup for dovecot but https://doc.dovecot.org/configuration_manual/authentication/oauth2/ is not enough for me. Could anybody describe a simple setup where dovecot uses keycloak. For simplification I would start with keycloak's builtin

Re: "make check" fail at test_program_refused

2022-10-14 Thread A. Schulze
A. Schulze: Hello, I moved my buildsystem to an other platform (I do not fully control) and now receive this error on "make check" Error: program tcp:127.0.0.2:42027: connect(::1) failed: Connection refused test_program_refused

"make check" fail at test_program_refused

2022-10-10 Thread A. Schulze
Hello, I moved my buildsystem to an other platform (I do not fully control) and now receive this error on "make check" Error: program tcp:127.0.0.2:42027: connect(::1) failed: Connection refused test_program_refused . : FAILED The build

Re: Pigeonhole redirect is adding a message-id header when it already exists

2022-10-04 Thread A. Schulze
Am 02.10.22 um 11:37 schrieb Emmanuel Fusté: Le 02/10/2022 à 06:35, Sébastien Riccio a écrit : - What options could we have to resolve this? a) Having dovecot core to remove the Message-ID header line from the mail if it is not going to consider it valid ? (So there is no dupe headers when

dovecot and openssl3

2022-06-21 Thread A. Schulze
Hello, I tried to build dovecot-2.3.19.1 with openssl-3.0.2 "make test" failed. Good, the test-suite found a problem! I found similar reports and patches: - https://sources.debian.org/src/dovecot/1%3A2.3.19%2Bdfsg1-1/debian/patches/Support-openssl-3.0.patch/ -

Re: [EXT] Re: Dovecot v2.3.19 released

2022-05-11 Thread A. Schulze
Am 11.05.22 um 07:26 schrieb Michael Tokarev: You are using something like `libssl-dv` instead of libssl, hence me asking. It does not appear to be using the stock libssl. Hello Aki & Michael I reviewed my build and indeed found a glitch. So: sorry for the noise. dovecot-2.3.19 can be

Re: Dovecot v2.3.19 released

2022-05-10 Thread A. Schulze
Am 11.05.22 um 06:52 schrieb Aki Tuomi: What ssl library are you using? It's what Debian provides: https://packages.debian.org/bullseye/libssl1.1 Andreas

Re: Dovecot v2.3.19 released

2022-05-10 Thread A. Schulze
Am 10.05.22 um 23:35 schrieb John Stoffel: "A" == A Schulze writes: A> Am 10.05.22 um 08:33 schrieb Aki Tuomi: Hi all! We are pleased to release v2.3.19 of Dovecot. The docker images have been upgraded to use bullseye as base image. https://dovecot.org/releases/2.3/d

Re: Dovecot v2.3.19 released

2022-05-10 Thread A. Schulze
Am 10.05.22 um 08:33 schrieb Aki Tuomi: Hi all! We are pleased to release v2.3.19 of Dovecot. The docker images have been upgraded to use bullseye as base image. https://dovecot.org/releases/2.3/dovecot-2.3.19.tar.gz https://dovecot.org/releases/2.3/dovecot-2.3.19.tar.gz.sig Hello,

Re: Dovecot (>= 2.3.15) is not properly replicating Expunge commands running in a containerised environment

2021-08-12 Thread A. Schulze
Am 05.08.21 um 13:03 schrieb A. Schulze: Hello, nobody else seeing such issues? Any hints are highly appreciated. Andreas >> doveadm: Info: copy from INBOX: box=INBOX, uid=13, msgid=<[MID of the >> message in question]>, size=1793 >> doveadm: Info: expunge: box=IN

Dovecot (>= 2.3.15) is not properly replicating Expunge commands running in a containerised environment

2021-08-05 Thread A. Schulze
Hello *, migrating a mailbox setup for several tens of thousands of customers to Docker containers running on Debian VMs, we are currently observing Expunge commands not being replicated properly between two Dovecot containers. Delivering a new message into someones' inbox is replicated

Re: Dovecot mailing list and DKIM

2021-06-28 Thread A. Schulze
Am 28.06.21 um 07:40 schrieb Aki Tuomi: >> BTW: >> the ARC-Seal added by dovecot.org is invalid here, too >> >> Andreas > > Can you give any more insight on why it's invalid? Last time I checked the > ARC-Seal was fine. well, my dovecot folder with 30k messages (8 years) contain ~4k messages

Re: Dovecot mailing list and DKIM

2021-06-19 Thread A. Schulze
Am 19.06.21 um 16:21 schrieb Kevin N.: > Going through my mail logs I noticed that a couple of messages from the > Dovecot mailing list failed DKIM validation. > > For example, this one has failed: > https://markmail.org/message/te7tycmpiutw4kia dovecot.org use mailman-2.1.15 which is "a

error: "The certificate is empty"

2021-06-18 Thread A. Schulze
Hello, on a farm of multiple identical dovecot servers I start seeing this error on usual POP3S access on one of many servers: pop3-login: Error: Failed to initialize SSL server context: Can't load SSL certificate (ssl_cert setting): The certificate is empty: I'm running 2.3.14 compiled

Re: Definitive guide to running ObjectiveFS on top of a Clustered File System?

2021-06-06 Thread A. Schulze
Am 02.06.21 um 17:09 schrieb Roel van Duijnhoven: > I am working on migrating a Dovecot system with + 50.000 users / 5TB on mail > data to a new set-up that is better scalable. But I found it difficult to > find a good solution. In this email I lay out what I learned, in the hope > that

Re: Recommended Protocols?

2020-11-10 Thread A. Schulze
Am 10.11.20 um 06:42 schrieb Raymond Herrera: > I am preparing a new server, with Dovecot 2.2.36 and would like to know the > currently recommended protocols. Should I stick to what I have? I would > prefer to start with the easiest configuration possible, which I will revise > later. > >

Re: got a listener on 993

2020-04-14 Thread A. Schulze
Am 13.04.20 um 20:52 schrieb David Mehler: > Hello, > > Before I get in to my question is ssl on 993 or starttls on 143 better > from a security perspective? implicit TLS is recommended: https://tools.ietf.org/html/rfc8314#section-3 Andreas

Re: doveadm: Error: open(/proc/self/io) failed

2019-07-31 Thread A. Schulze via dovecot
Am 31.07.19 um 08:27 schrieb Sami Ketola via dovecot: > service lmtp { > user = vmail > } > > please remove user = vmail from here or change it to root. > > for security reasons lmtp service must be started as root since version > 2.2.36. lmtp will drop root privileges after initialisation

Re: Dovecot not surviving OpenLDAP restart

2019-05-12 Thread A. Schulze via dovecot
Dag Nygren via dovecot: One more obvious line from the log: dovecot[26621]: auth: Error: LDAP: Connection lost to LDAP server, reconnecting usually reconnecting works. If it doesn't for you, it's probably not dovecot's fault. I suggest to inspect openldap logs. Try to stop slapd and

Re: Dovecot not surviving OpenLDAP restart

2019-05-08 Thread A. Schulze via dovecot
Am 08.05.19 um 15:32 schrieb Dag Nygren via dovecot: > Now since some update of dovecot it will not be able to authenticate > your logins after a restart of the LDAP service is restarted > without a reboot of the dovecot server. Hello, This sounds more like a configuration glitch. Could you

Re: Feature request: exclude IP/network in allow_nets extra field

2019-05-01 Thread A. Schulze via dovecot
defaults in case my ldap userdb do not return any overwriting. Patch attached... Andreas Description: additional defaults for allow_nets Author: A. Schulze --- This patch header follows DEP-3: http://dep.debian.net/deps/dep3/ Index: dovecot-2.3.6/src/auth/auth-request.c =

Re: Dovecot v2.3.5 released

2019-03-07 Thread A. Schulze via dovecot
Am 07.03.19 um 17:33 schrieb Aki Tuomi via dovecot: >> test-http-client-errors.c:2989: Assert failed: FALSE >> connection timed out . : >> FAILED Hello Aki, > Are you running with valgrind or on really slow system? I'm not aware my buildsystem

Re: Dovecot v2.3.5 released

2019-03-07 Thread A. Schulze via dovecot
Am 05.03.19 um 17:26 schrieb Aki Tuomi via dovecot: > We are happy to release dovecot v2.3.5. Hello, it build but tests fail... make[4]: Entering directory '/<>/src/lib-http' for bin in test-http-date test-http-url test-http-header-parser test-http-transfer test-http-auth

Re: offtopic: rant about thoughtless enabling DMARC checks [was: Re: Bounces?]

2019-02-09 Thread A. Schulze via dovecot
Am 09.02.19 um 19:56 schrieb Aki Tuomi via dovecot: > I'll review the settings when we manage to upgrade to mailman3 Hello Aki, before updating to mailman3 consider an simpler update to latest mailman2. you're using 2.1.15, current mailman2 is 2.1.29 Your missing an /significant amount/ of

Re: LDAP login fails after LDAP server restart

2018-11-25 Thread A. Schulze
Am 25.11.18 um 14:27 schrieb Dag Nygren: > Just udated my Fedora dovecot to version 2.2.36 and > found that after the update dovecot will fail all > LDAP logins after slapd has been restarted during the logrotate. > > Restarting dovecot fixes the problem. must be something special on your

Re: different TLS protocols on different ports

2018-11-14 Thread A. Schulze
Am 14.11.18 um 22:46 schrieb Joseph Tam: > Couldn't you run two different instances that is the idea: Yes, I can run multiple instances... Thanks!

Re: different TLS protocols on different ports

2018-11-14 Thread A. Schulze
Am 14.11.18 um 21:21 schrieb Michael Slusarz: > These ports are well-known and well used. OK, to be clear: they're not in /my/ networks :-)

Re: different TLS protocols on different ports

2018-11-14 Thread A. Schulze
Am 14.11.18 um 20:22 schrieb Aki Tuomi: > Not possible I'm afraid. Hello Aki, is it not possible in 2.2.36 or not possible at all? I stumbled upon RFC 8314 *) and I found it a welcome option to enforce more modern protocols/ciphers. IMAPS/SUBMISSIONS aren't used widely (at least to my

different TLS protocols on different ports

2018-11-14 Thread A. Schulze
Hello, I'm providing IMAP+Starttls on port 143 for users with legacy MUA. So I've to enable TLS1.0 up to TLS1.3 For IMAPS / port 993 I like to enable TLS1.2 and TLS1.3 only. Is this possible with dovecot-2.2.36 / how to setup this? Thanks for suggestions, Andreas

Re: LMTP tcp listener with auth?

2018-09-13 Thread A. Schulze
Am 12.09.18 um 13:41 schrieb Andreas Thienemann: > Hi Stephan, > > On Wed, 12 Sep 2018, Stephan Bosch wrote: > >> LMTP currently does not support AUTH. > > Bummer. Thought so. > > >> What is your use case? Most people hide LMTP behind a firewall, or don't >> expose it through TCP/IP in

lmtp + tcpwrap

2018-07-31 Thread A. Schulze
Hello, Using the TCP Wrapper Dovecot could control access to IMAP and POP3 servers. Is it also possible to controll access to an LMTP Server listening on Port 24? Andreas

2.3.2.1 - EC keys suppport?

2018-07-29 Thread A. Schulze
Am 29.07.2018 um 21:06 schrieb ѽ҉ᶬḳ℠: > facing [ no shared cipher ] error with EC private keys. the client connecting to your instance has to support ecdsa Andreas

Re: use instance-name for syslog?

2018-05-31 Thread A. Schulze
Am 31.05.2018 um 20:40 schrieb Timo Sirainen: > >> On 30 May 2018, at 19.08, SATOH Fumiyasu wrote: >> I have a patchset to implement that. Please see the attachment. >> Subject: [PATCH 1/2] master: Do not prepend "dovecot-" to a process name > > Why not? I'd think it would be useful to

Re: use instance-name for syslog? (SOLVED)

2018-05-31 Thread A. Schulze
Am 30.05.2018 um 21:21 schrieb A. Schulze: > Am 30.05.2018 um 18:08 schrieb SATOH Fumiyasu: >> I have a patchset to implement that. Please see the attachment. > > Thanks!, I'll try to apply the patch on 2.2.36 and report my results... done && looks good.

Re: use instance-name for syslog?

2018-05-30 Thread A. Schulze
Am 30.05.2018 um 18:08 schrieb SATOH Fumiyasu: > Hi! > > On Thu, 31 May 2018 00:44:58 +0900, > A. Schulze wrote: >> When running multiple instances of dovecot on the same host (or running >> multiple docker container), >> it is hard to distinguish logs from d

use instance-name for syslog?

2018-05-30 Thread A. Schulze
Hello, When running multiple instances of dovecot on the same host (or running multiple docker container), it is hard to distinguish logs from different processes: the syslog entries are all prefixed with the same identifier "dovecot" It is hardcoded here:

Re: SSL error after upgrading to 2.31

2018-05-30 Thread A. Schulze
Aki Tuomi: There is already ssl_client_ca, for verifying clients. ssl_ca verifies certs when dovecot is connecting somewhere. For clarification: there is a third use case an admin may need intermediate certificates: And that's where dovecot act as server providing imap/pop3/lmtp/sieve

Re: Compatibility of Submission in 2.3.1

2018-04-06 Thread A. Schulze
Stephan Bosch: Here is the debug log (note the space between “From:" and ">”): Any idea which client is doing that? older android mail app for example... see https://marc.info/?l=postfix-users=141600120612100

Re: debian lintian warn: hardening-no-fortify-functions

2018-03-30 Thread A. Schulze
> Hi! Dovecot 2.3 has hardening enabled. OK, I'll give it a try and report if I've results... Thanks Andreas

debian lintian warn: hardening-no-fortify-functions

2018-03-30 Thread A. Schulze
Hello, to build + packages dovecot I use the usual Debian tool chain. That includes build with selected GCC options and running lintian. I notice since a long time (read: many earlier versions, up to 2.2.35) this lintian warnings: I: dovecot-core: hardening-no-fortify-functions

Re: dovecot logging

2018-03-27 Thread A. Schulze
Am 27.03.2018 um 17:28 schrieb Alex JOST: > Did you try running rsyslog inside the container... no, I like follow the preferred way to run container: one process per container. Andreas

dovecot logging

2018-03-27 Thread A. Schulze
Hello, I'm currently playing with a number of dovecot instances to evaluate my "next generation setup" For now I run 6 instances of dovecot, one per docker container: - 2x redirector - 2x backend #1 - 2x backend #2 All docker container use syslog. And there the problems starts. Every

Re: How to grant user access to his .dovecot.sieve.log?

2018-02-04 Thread A. Schulze
Am 04.02.2018 um 03:44 schrieb Sergey Ivanov: > can you explain "magic folder"? ... a not yet existing implementation in dovecot... The idea is simple: extend dovecot-sieve to deliver the logdata as message in a (special?) folder instead/on top of creating a simple logfile. I'm unable to

Re: How to grant user access to his .dovecot.sieve.log?

2018-02-02 Thread A. Schulze
Am 01.02.2018 um 18:01 schrieb Sergey Ivanov: > Hi, > What are the recommended ways to give access to their .dovecot.sieve.log > messages to the users? > I am thinking about placing this file into users Maildir/new, or piping to > dovecot-lda. or serve the log as "magic folder". If the user

Re: set parameter per user

2017-11-23 Thread A. Schulze
Am 23.11.2017 um 14:40 schrieb Sami Ketola: > can you verify if the value is correctly formed in userdb. Ie. is it visible > in output: > > doveadm -o service=lmtp user # doveadm -o service=lmtp user us...@example.org field value uid 8 gid 8 home/mail/user1 mail

Re: set parameter per user

2017-11-23 Thread A. Schulze
Steffen Kaiser: Is the detail delived to Dovecot by the MTA at all? sure! have to say: I faked that example. In reality I tested the inverse way: My lab setup actually *do* deliver to folders and I saw, setting lmtp_save_to_detail_mailbox to 'no' still deliver to folder while INBOX was

set parameter per user

2017-11-21 Thread A. Schulze
Hello, My dovecot server (2.2.33.2) work with "lmtp_save_to_detail_mailbox = no" Now I would like to enable the feature for /some/ users. Is that an option that could be set from an LDAP entry? I tried the following: modify my ldap schema to allow an optional attribute

Re: dmarc report faild ?

2017-08-24 Thread A. Schulze
Maurizio Caloro: Please i have new following Error, from DMARC Report, if i check my domain on example mxtoolbox i dont see any problems. Any from you know this Eror report, what i need to do to fix this issue? I guess, the reports are about messages you sent to the list:

Re: v2.2.32 release candidate released (on Debian 8/Jessie)

2017-08-16 Thread A. Schulze
c1-2017081601_amd64.build.txt Andreas Description: lintian: wich -> which Author: A. Schulze --- This patch header follows DEP-3: http://dep.debian.net/deps/dep3/ Index: dovecot-2.2.32~rc1/doc/man/doveadm-exec.1.in === --- dovecot-2.2.32~

Re: Duplicate mailing list messages

2017-06-20 Thread A. Schulze
Alexander Dalloz: The suspicious doubled messages contain and addressing to a local.dovecot newsgroup and have the mail header "Newsgroups: local.dovecot". Timo fixed that already yesterday...

Re: Dovecot pop3 feature

2017-05-22 Thread A. Schulze
Am 22.05.2017 um 14:07 schrieb Markus Eckerl: > Is it possible to send a pop3 "LOGIN-DELAY" if the customers last login is > only a few seconds away? you may try postlogin script voodoo: https://wiki.dovecot.org/PostLoginScripting#Last-login_tracking

patches: spelling errors

2017-04-12 Thread A. Schulze
(const struct sieve_dumptime_env *denv, sieve_size_t *addres, int *opt_code); But as this isn't obviously text I don't touch that. Andreas Description: lintian: reseting -> resetting Author: A. Schulze --- This patch header follows DEP-3: http://dep.debian.net/deps/dep3/ Index: dovecot-2.

pigeonhole / vacation

2017-03-15 Thread A. Schulze
Hello, we use the sieve vacation module to answer messages for certain mailboxes. vacation send back answers to most but not all messages wich is fine and intended. .dovecot.sieve looks like this: require ["vacation", "variables"]; if header :matches "subject" "*" { vacation

Re: Messages on this list are often marked as spam.

2017-02-09 Thread A. Schulze
Am 09.02.2017 um 17:14 schrieb Juri Haberland: > But it uses MimeDel, presumably to delete the HTML part of some messages > thus invalidating the DKIM signature... > X-Mailman-Version: 2.1.17 and it's using an old version. Newer releases fix some points where Mailman modify messages in subtile

Re: CVE-2016-8562 in dovecot

2016-12-02 Thread A. Schulze
Am 02.12.2016 um 08:00 schrieb Aki Tuomi: > Workaround is to disable auth-policy component until fix is in place. > This can be done by commenting out all auth_policy_* settings. Hello, could you be more verbose on how to verify if administrators are affected? # doveconf -n | grep

Re: [PATCH] Manually cleanup OpenSSL from dovecot_openssl_common_global_unref()

2016-11-14 Thread A. Schulze
Am 13.11.2016 um 19:04 schrieb Apollon Oikonomopoulos: > OpenSSL 1.1 features a cleanup function that is automatically run on shutdown > using atexit(3). This function frees all OpenSSL-allocated resources. > > In dovecot, OpenSSL is loaded indirectly using dlopen(3) against the relevant >

Re: dovecot / tcp-wrappers / FBSD 10.3

2016-11-14 Thread A. Schulze
Am 14.11.2016 um 18:50 schrieb Larry Rosenman: > # Space separated list of login access check sockets (e.g. tcpwrap) > #login_access_sockets = > login_access_sockets = tcpwrap > > service tcpwrap { > unix_listener login/tcpwrap { > group = $default_login_user > mode = 0600 > user

fail to compile with openssl-1.1.x

2016-09-25 Thread A. Schulze
Hi again, now I get compile errors. Is openssl-1.1.xy supported? iostream-openssl.c: In function 'openssl_iostream_verify_client_cert': iostream-openssl.c:118:37: error: dereferencing pointer to incomplete type subject = X509_get_subject_name(ctx->current_cert);

Re: configure fail if libssl is named libssl-opt

2016-09-25 Thread A. Schulze
Am 25.09.2016 um 18:23 schrieb A. Schulze: Is there an other way to tell configure the ssl libraries have other names? solved: using pkg-config and correct .pc files :-) Andreas

configure fail if libssl is named libssl-opt

2016-09-25 Thread A. Schulze
Hello, I try to build dovecot with my own version of openssl. It's compiled in a way the libraries can coexist without symbol conflict with the real OpenSSL in /usr: They are named libssl-opt and libcrypto-opt. Now configure fail to find my libssl-opt: CFLAGS="..." CXXFLAGS="..."

Re: Where Dovecot stores subscribtions for shared folder

2016-06-27 Thread A. Schulze
Hello, my location: location = maildir:%%h/Maildir:INDEX=~/.dovecot.shared/%%u/:INDEXPVT=~/.dovecot.shared/%%u/:CONTROL=~/.dovecot.shared/%%u/ Am 27.06.2016 um 14:21 schrieb Miloslav Hůla: could please someone hint me, where Dovecot stores subscribtions for shared folder? Our

Re: Enabling tcpwrappers

2016-03-27 Thread A. Schulze
kepa: I would like use Dovecot with tcpwrappers enabled to control remote access using hosts.deny and hosts.allow. I followed http://wiki2.dovecot.org/LoginProcess#TCP_wrappers_support and "man 5 hosts.deny" - to allow all clients and deny a specific address /etc/hosts.deny imap:

Re: Dovecot stops responding when I update SSL certificate

2016-03-06 Thread A. Schulze
aki.tuomi: We are going to provide ssl_dh parameter in v2.3 which replaces the current ssl parameters daemon with simple PEM encoded file that you provide. good thing. that simplify the process of dh regeneration to a method admins are more familiar with. --- Aki Tuomi Dovecot Oy

Re: Implementation of TLS OCSP Stapling

2016-03-03 Thread A. Schulze
dovecot: So I would like to know if Dovecot is planning to feature OCSP stapling. That way I know for sure my "must staple" certificates can be used by Dovecot. And in my opinion, every TLS offering daemon should be up to par to the capabilities of TLS.. Not lag behind :) What's your opinion

Re: [Feature Request] doveadm option to return number of messages acted upon

2016-02-25 Thread A. Schulze
Haravikk: So I have a script for handling my specific archive and expunge needs, but it’d be nice to be able to track how many messages are being affected. Currently I’m doing it by firing the same search queries into doveadm search and counting the lines of the result with wc -l, but

Re: ANNOTATE plugin? Squirrel uses it for EXPIRATION information

2016-02-14 Thread A. Schulze
Am 13.02.2016 um 23:24 schrieb Heiko Schlittermann: it seems that Squirrel mail uses Mailbox annotations for storing Expire times on the Server. It's an Cyrus server currently. (I've no clue how cyrexpire is able to read it's information from the annotiations) Does dovecot support some

Re: R: Re: Mail User Agent?

2016-02-04 Thread A. Schulze
absolutely_free: the info but, in my logs, there's no single ID info. Do i need to enable logging of it or something? imap_id_log = * I guess you simply have clients which don't care about the offered ID extension. A recent Thunderbird should make you happy :-) Andreas

Re: Running without anvil?

2016-01-17 Thread A. Schulze
Dave Abrahams: The only thing is, I keep getting these in var/log/mail.log: anvil: Fatal: chroot(/Users/dave/brew/var/run/dovecot/empty) failed: Operation not permitted master: Error: service(anvil): command startup failed, throttling for 60 secs auth: Error:

Re: doveconf syntax question

2016-01-15 Thread A. Schulze
Am 05.01.2016 um 15:31 schrieb A. Schulze: I have one sieve extension enabled: /etc/dovecot/conf.d/20-sieve.conf: plugin { sieve_extensions = +vacation-seconds } now (months later) we want to enable an other extension. no big deal: /etc/dovecot/local.conf: plugin

doveconf syntax question

2016-01-05 Thread A. Schulze
Hello, I have one sieve extension enabled: /etc/dovecot/conf.d/20-sieve.conf: plugin { sieve_extensions = +vacation-seconds } now (months later) we want to enable an other extension. no big deal: /etc/dovecot/local.conf: plugin { sieve_extensions = +editheaders ...

Re: ssl-params: slow startup (patch for consideration)

2015-11-05 Thread A. Schulze
Joseph Tam: A. Schulze writes: precomputing ssl-params is also possible without patching but it's a little bit tricky ... Long version in german: https://andreasschulze.de/dovecot/ssl-params Nice. (You should probably point out to ensure ssl_parameters_regenerate is zero, otherwise all

Re: ssl-params: slow startup (patch for consideration)

2015-11-04 Thread A. Schulze
Joseph Tam: Based on the recent found weaknesses in DH key exchange, http://weakdh.org/ I increased ssl_dh_parameters_length to 2048 bits, and found waited for 5+ minutes for dovecot to come back online after a restart. Unless you got a fast machine, the initialization of DH

Re: Webmail accessive Dovecot logins

2015-10-30 Thread A. Schulze
David Mehler: Second question, in the doveconf -n there's reference to my ssl_cipher am I using current tls ciphers that support pfs? ssl_cipher_list = ALL:!LOW:!SSLv3:!SSLv2:!EXP:!aNULL some non pfs cipher would be still active. check yourself: # openssl ciphers -v

Re: v2.2.19 released

2015-10-02 Thread A. Schulze
Am 02.10.2015 um 18:13 schrieb Timo Sirainen: http://dovecot.org/releases/2.2/dovecot-2.2.19.tar.gz http://dovecot.org/releases/2.2/dovecot-2.2.19.tar.gz.sig Thanks Timo!

Re: v2.2.19 released / imap-hibernate

2015-10-02 Thread A. Schulze
Am 02.10.2015 um 18:13 schrieb Timo Sirainen: + Added imap-hibernate processes (see imap_hibernate_timeout setting). IDLEing IMAP connections can be hibernated, which saves memory. here is my config to enable the new function: imap_hibernate_timeout = 60s service imap-hibernate {

Re: v2.2.19 release candidate released

2015-09-24 Thread A. Schulze
Am 23.09.2015 um 15:30 schrieb Timo Sirainen: http://dovecot.org/releases/2.2/rc/dovecot-2.2.19.rc1.tar.gz http://dovecot.org/releases/2.2/rc/dovecot-2.2.19.rc1.tar.gz.sig A lot of changes since v2.2.18, so here's a release candidate first. If no bugs are reported, I'm planning on making the

Re: Importing mbox archives into a inbox?

2015-07-27 Thread A. Schulze
Paul Hoffman: Greetings from a dovecot newbie. I have a bunch of mailing list archives (in mbox) format that I want to dump into the inbox for a particular account on the system. I want them to retain all of their information, particularly the date. I'm not seeing how to do this, but I

Re: Authenticate system user with alternate password

2015-07-22 Thread A. Schulze
AC: Is there a way to configure Dovecot to authenticate a system user against a different password list? sure! I want to give my own personal account on my machine a password for IMAP and have that be different from the password I use to log into the system for maintenance purposes.

suggestion: avoid help keeping XP alive

2015-06-10 Thread A. Schulze
Hello, if possible encourage people to update then helping them keeping horribly outdated XP + OE still alive... Thanks Andreas

Re: Misleading SSL/TLS Log Messages

2015-06-03 Thread A. Schulze
Yahooguntu: 14:51:13 : imap-login: Debug: SSL: where=0x2001, ret=1: SSLv3 read client hello A [127.0.0.1] not a bug. sslv3 and tlsv1.0 are not very different. programmers usually shared large portions of code. Remember: sslv3 and tls1.0 are 15 years old... it's common not only to

Re: Dovecot 2.1.7 still accepting SSLv3 though disabled?

2015-03-15 Thread A. Schulze
Thomas Preissler: ssl_protocols = !SSLv3 !SSLv2 that disable SSLv3 When I enable verbose_ssl I get this: 2015-03-15 08:27:39 imap-login: Warning: SSL: where=0x2001, ret=1: SSLv3 flush data [$CLIENTIP] ... Is this right? Is SSLv3 used on this connection? The logging is

Re: Indexing Mail faster

2015-01-25 Thread Andreas Schulze
Thomas Leuxner: I have a view defined (virtual plugin) with around 22.000 messages in it interesting. I assume you drop multiple mailing lists together in a mailbox and separate them using the virtual plugin, right? could publish how you configured dovecot virtual plugin? I never had success on

Re: Corruption of index files

2015-01-25 Thread Andreas Schulze
Oliver Welter: after upgrading my mail server (dovecot 1.1.7 - 2.2.13) I get tons of messages about corrupted index files in the syslog (Error: Corrupted transaction log and Warning: fscking index file .. dovecot.index. Some more debugging - I did a fuser on a broken dovecot.index file and

Re: Indexing Mail faster

2015-01-25 Thread A. Schulze
Thomas Leuxner: namespace { location = virtual:~/mdbox/virtual prefix = Virtual/ separator = / } $ cat virtual/Flagged/dovecot-virtual * Public/* flagged once setup correctly it works like expected :-) Another example, the one I used in the original reply, is 'gluing' together

does lda_save_to_detail_mailbox exist?

2014-12-04 Thread A. Schulze
Hello, there is a nice feature in lmtp to save messages to user+foo@domain in INBOX/foo Looks like that doesn't work as good if lda is used. I have dovecot-2.2.13 mail_location = maildir:%h/ lda_mailbox_autocreate = yes lda_mailbox_autosubscribe = yes *lmtp*_save_to_detail_mailbox

SOLVED: does lda_save_to_detail_mailbox exist?

2014-12-04 Thread A. Schulze
A. Schulze: there is a nice feature in lmtp to save messages to user+foo@domain in INBOX/foo Looks like that doesn't work as good if lda is used. It works! for some reasons I don't follow the suggestion on http://wiki2.dovecot.org/LDA/Qmail I use '/var/qmail/bin/preline -f /usr/lib

Re: Disabling SSLv3 protocol

2014-11-11 Thread A. Schulze
Timo Sirainen: ... I don't think SSLv3 is especially exploitable with IMAP/POP3 protocols. It's well known SSLv3 *is* a problem for HTTP, we assume, it isn't for SMTP/POP/IMAP Administrators, also responsible for putting new paper in the printer, may not have the skill to distinguish

Re: Dovecote 1.2.17 poodle

2014-10-25 Thread A. Schulze
Marc Rantanen: Hi, how do I protect dovecot 1.2.17 against poodle? anything without warranty, totally untested ... I just looked into the sourcecode. looks like there was an option ssl_protocols in dovecot.conf. ( check: dovecot -a | grep ssl_protocols ) then you should be able to set

Re: special what's my ip pop account

2014-10-23 Thread A. Schulze
Steffen Kaiser: I would give the http://wiki2.dovecot.org/PostLoginScripting a try. I never used PostLoginScripting before. I have concerns about additional serverload if that scripting is executed for every pop3 login and every user. ( and there are *many* ) Maybe you can enable it for

special what's my ip pop account

2014-10-22 Thread A. Schulze
Hello, I like to enable the allow_nets Feature (http://wiki2.dovecot.org/PasswordDatabase/ExtraFields/AllowNets) for my customers. To help them knowing there own IP I imagine a special mailbox/loginuser at the pop3 server. That user could give a valid pop3 answer from a dummy pop3 server

Re: special what's my ip pop account

2014-10-22 Thread A. Schulze
Reindl Harald: why that complex? just point them to a website webtraffic goes other ways via proxy server then pop3

Re: sieve: is it possible to filter ALL mailing lists (with header List-Id) to their folders with ONE rule?

2014-09-12 Thread A. Schulze
Lev Serebryakov: List-Id: This is decription of list list-name.host.org will be put into folder org.host.list-name where . is namespace separator (so, such folders will be shown as hierarchy in mail client)? :-) had the same idea while writing my sieve file ... Another idea would be a key

Re: namspace management

2014-08-15 Thread A. Schulze
Timo Sirainen: On 13 Aug 2014, at 09:58, Steffen Kaiser location = maildir:/data/mail_public/Maildir/:INDEXPVT=~/.dovecot.index.public/:CONTROL=~/.dovecot.index.public/ Not recommended, because it also moves dovecot-keywords file so any keywords added to the public folder won't be shared

namspace management

2014-08-12 Thread A. Schulze
Hello, since some weeks I'm playing with namespaces. But I still did nod found a solution for all faces of different problems. Current issue: Public namespace. I have users inbox as follow: mail_home = /data/mail/%Ln/ mail_location = maildir:~/Maildir:INDEX=~/.dovecot.index namespace {

maildir: could lda/lmtp log filenames?

2014-08-06 Thread A. Schulze
hello, on a mailstorage server receiving messages per lda/lmtp I like to pimp my logfile. when starting to search for a specific message I have a queueid. I like to combine that id with the filename the message has after delivery to a maildir. I know, that will not work with other formats

TRANSLATION extension to the NAMESPACE response supported?

2014-07-15 Thread A. Schulze
Hello, I would like to ask if the TRANSLATION extension to the NAMESPACE response is supported by dovecot. context: http://lists.horde.org/archives/horde/Week-of-Mon-20140714/052136.html Thanks, Andreas

Re: [Dovecot] dovecot: disable ssl compression

2014-07-03 Thread A. Schulze
Timo Sirainen: But now I'm wondering if no-compression should be enabled by default?.. to not potential break something I would not change the default now but maybe later... Thanks! Andreas

Re: [Dovecot] dovecot: disable ssl compression

2014-07-03 Thread A. Schulze
Jiri Bourek: As I understand it, any program using the library has compression turned off by default. yes, and any program using an older library version can turn off compression now, too.

[Dovecot] LDAP: allow pop3, restrict imap

2014-05-26 Thread Andreas Schulze
Hello, I have all userdata in a ldapserver. Every user has the right to use pop3. There is no explicit attribute allowing that. It's simply possible. Now I like to add imap. For a starting period I like to restrict, who may use imap. http://wiki2.dovecot.org/Authentication/RestrictAccess

  1   2   >