Re: Is multi factor authentication practical/feasible?

2022-07-01 Thread Rick Romero
Quoting Jochen Bern : On 27.06.22 00:52, Steve Dondley wrote: I have a small client whose insurance company insists they have MFA for their email to be covered under some kind of data protection policy. Currently I have the client set up on a Debian box for the email server coupled with

Re: Sv: 2FA/MFA with IMAP & postfix/submission

2021-07-15 Thread Rick Romero
Quoting Benny Pedersen : On 2021-07-15 16:49, Alex wrote: What about something like what we used to do with pop-b4-smtp to at least restrict by IP address? no, pop was not handle million of users share one single nat ip, weekforce cant handle that either, so allow_net cant do any better

Re: Sv: 2FA/MFA with IMAP & postfix/submission

2021-07-15 Thread Rick Romero
Quoting Alex : Hi, Unfortunately the best way to do multifactor authentication today is to use OAUTH2, which isn't currently supported for own installations. Or you can use client certs. If you want to use some kind of MFA with tokens, you end up having to feed your token all the

Re: vpopmail

2018-10-04 Thread Rick Romero
Quoting Rick Romero : Quoting Eric Broch : On 10/4/2018 7:27 AM, Rick Romero wrote: Quoting Eric Broch <mailto:ebr...@whitehorsetc.com>>: On 10/4/2018 6:34 AM, Rick Romero wrote:   Quoting Aki Tuomi <mailto:aki.tu...@open-xchange.com>>: On 03.10.2018 23:30, Eric Br

Re: vpopmail

2018-10-04 Thread Rick Romero
Quoting Eric Broch : On 10/4/2018 7:27 AM, Rick Romero wrote: Quoting Eric Broch <mailto:ebr...@whitehorsetc.com>>: On 10/4/2018 6:34 AM, Rick Romero wrote: Quoting Aki Tuomi <mailto:aki.tu...@open-xchange.com>>: On 03.10.2018 23:30, Eric Broch wrote: Hello li

Re: vpopmail

2018-10-04 Thread Rick Romero
Quoting Eric Broch : On 10/4/2018 6:34 AM, Rick Romero wrote:   Quoting Aki Tuomi : On 03.10.2018 23:30, Eric Broch wrote: Hello list, I run Dovecot with the vpopmail driver and have found that it authenticates against the clear text password in the vpopmail database

Re: vpopmail

2018-10-04 Thread Rick Romero
Quoting Aki Tuomi : On 03.10.2018 23:30, Eric Broch wrote: Hello list, I run Dovecot with the vpopmail driver and have found that it authenticates against the clear text password in the vpopmail database. Is there a configuration option either at compile time, link time, or a setting in one

Re: Best way to move mail from one server to another

2018-09-04 Thread Rick Romero
Quoting Sami Ketola : On 4 Sep 2018, at 18.45, Rick Romero wrote: https://imapsync.lamiral.info/FAQ.d/FAQ.Duplicates.txt Seems to use UIDs so that 'data' isn't lost.   No it does not. This is different thing. This is about managing duplicates on multiple syncs.Imapsync seems

Re: Best way to move mail from one server to another

2018-09-04 Thread Rick Romero
Quoting Robert Schetterer : Am 04.09.2018 um 17:18 schrieb Sami Ketola: On 4 Sep 2018, at 18.00, Robert Schetterer wrote: Am 04.09.2018 um 16:52 schrieb Sami Ketola: On 4 Sep 2018, at 17.47, Robert Schetterer wrote: Am 04.09.2018 um 09:41 schrieb Sami Ketola: imapsync always loses data

Re: Best way to move mail from one server to another

2018-09-04 Thread Rick Romero
Quoting Robert Schetterer : Am 04.09.2018 um 17:18 schrieb Sami Ketola: On 4 Sep 2018, at 18.00, Robert Schetterer wrote: Am 04.09.2018 um 16:52 schrieb Sami Ketola: On 4 Sep 2018, at 17.47, Robert Schetterer wrote: Am 04.09.2018 um 09:41 schrieb Sami Ketola: imapsync always loses data

Re: Recommendations for backup methods

2018-08-14 Thread Rick Romero
Quoting Daniel Miller : I've been re-thinking my backup strategy - I wanted to see what input others have.  At this time - I'm using sdbox as the primary storage format and running on a single server. Previously, all my backups were simple filesystem backups. Either inotify-based or

Re: application specific passwords

2017-07-20 Thread Rick Romero
Quoting mj : Hi, Further to the other thread about password guessing activities against our dovecot, I would like to implement application specific passwords on our dovecot. Googling results in some documents, but they are all a bit older:

Re: Master auth only

2017-07-12 Thread Rick Romero
Quoting Rick Romero <r...@havokmon.com>: Quoting Aki Tuomi <aki.tu...@dovecot.fi>: On July 11, 2017 at 11:50 AM azu...@pobox.sk wrote: Citát azu...@pobox.sk: Citát Aki Tuomi <aki.tu...@dovecot.fi>: On July 10, 2017 at 1:45 PM azu...@pobox.sk wrote: Citát Aki Tuomi <

Re: Master auth only

2017-07-12 Thread Rick Romero
Quoting Aki Tuomi : On July 11, 2017 at 11:50 AM azu...@pobox.sk wrote: Citát azu...@pobox.sk: Citát Aki Tuomi : On July 10, 2017 at 1:45 PM azu...@pobox.sk wrote: Citát Aki Tuomi : On July 10, 2017 at 12:33 PM

Re: per user procmail filtering and dovecot-lda

2017-05-18 Thread Rick Romero
Quoting Kenneth Porter : On 5/17/2017 11:26 AM, Adam Shostack wrote: Also, procmail is way out of date, no longer maintained, and there are "semi" known vulnerabilities that haven't been fixed.  See http://marc.info/?l=openbsd-ports=141634350915839=2  & the wikipedia

Re: per user procmail filtering and dovecot-lda

2017-05-17 Thread Rick Romero
Quoting James Nord : Hi all, I recently migrated my system (postfix/Dovecot)from mbox to Maildir. Almost everything is working (phone and thunderbird show all my mail and folders with mail) However I am stuck on my .procmailrc rules   :0 w   *

Re: Detect IMAP server domain name in Dovecot IMAP proxy

2016-10-12 Thread Rick Romero
Quoting KT Walrus <ke...@my.walr.us>: On Oct 12, 2016, at 2:07 PM, Rick Romero <ad...@vfemail.net> wrote: Quoting KT Walrus <ke...@my.walr.us>: I’m in the process of setting up a Dovecot IMAP proxy to handle a number of IMAP server domains. At the current time, I hav

Re: Detect IMAP server domain name in Dovecot IMAP proxy

2016-10-12 Thread Rick Romero
Quoting KT Walrus : I’m in the process of setting up a Dovecot IMAP proxy to handle a number of IMAP server domains. At the current time, I have my users divided into 70 different groups of users (call them G1 to G70). I want each group to configure their email client to

Re: Replication issue EOF or unknown flag V

2016-08-10 Thread Rick Romero
Quoting Rick Romero <r...@havokmon.com>: Hi, I'm trying to sort out a replication error:   It was working initially, but now it no longer works.  Dovecot 2.2.25, Maildir format On the 'master' side I see : Aug 09 14:02:17 dsync-server(rick at havokmon.com[1]): Error: read(172.16.1.86)

Replication issue EOF or unknown flag V

2016-08-09 Thread Rick Romero
Hi, I'm trying to sort out a replication error:   It was working initially, but now it no longer works.  Dovecot 2.2.25, Maildir format Delivering via LMTP.  If I run doveadm replicator replicate r...@havokmon.com On the 'master' side I see : Aug 09 14:02:17 dsync-server(r...@havokmon.com):

Re: Master-Master replication question

2016-07-29 Thread Rick Romero
Quoting Rick Romero <r...@havokmon.com>: Quoting "William L. Thomson Jr." <wlt...@o-sinc.com>: On Monday, July 11, 2016 10:53:05 AM Rick Romero wrote: I don't think that'll help.  From what I understand, LMTP is required for replication on delivery. Whe

Re: Master-Master replication question

2016-07-11 Thread Rick Romero
Quoting "William L. Thomson Jr." <wlt...@o-sinc.com>: On Monday, July 11, 2016 10:53:05 AM Rick Romero wrote: I don't think that'll help.  From what I understand, LMTP is required for replication on delivery. Where did you come across that requirement? I do not recall

Re: Master-Master replication question

2016-07-11 Thread Rick Romero
Quoting Remko Lodder <re...@freebsd.org>: On 11 Jul 2016, at 17:36, Rick Romero <r...@havokmon.com> wrote: Quoting "William L. Thomson Jr." <wlt...@o-sinc.com>: You are not alone! On Wednesday, July 06, 2016 01:15:34 PM Remko Lodder wrote: Dear list,

Re: Master-Master replication question

2016-07-11 Thread Rick Romero
Quoting "William L. Thomson Jr." : You are not alone! On Wednesday, July 06, 2016 01:15:34 PM Remko Lodder wrote: Dear list, I have setup a master-master replication setup. My primairy MX's send email over on a DNS loadbalanced way, so DNS is doing some kind of

Re: nginx proxy to dovecot servers

2016-06-03 Thread Rick Romero
Quoting KT Walrus : Dovecot supports real IP forwarding with HAproxy. Yes. I was aware of this, but that doesn’t answer my question of how to configure a Dovecot proxy to listen on many IPs/ports and do authentication based on the incoming IP/port. If I could do this

Re: nginx proxy to dovecot servers

2016-06-03 Thread Rick Romero
Quoting KT Walrus : Dovecot supports real IP forwarding with HAproxy. Yes. I was aware of this, but that doesn’t answer my question of how to configure a Dovecot proxy to listen on many IPs/ports and do authentication based on the incoming IP/port. If I could do this

Re: overview zlib efficiency?

2016-03-15 Thread Rick Romero
Quoting Rick Romero <r...@havokmon.com>: Quoting Robert L Mathews <li...@tigertech.com>: On 3/15/16 10:13 AM, Sven Hartge wrote: I don't have a script, but I can provide some numbers. I did a test with a server for about 10.000 users and 2TB worth of mail, converting

Re: overview zlib efficiency?

2016-03-15 Thread Rick Romero
Quoting Robert L Mathews : On 3/15/16 10:13 AM, Sven Hartge wrote: I don't have a script, but I can provide some numbers. I did a test with a server for about 10.000 users and 2TB worth of mail, converting from Maildir++ to mdbox with zlib (level = 6) and had a final

Re: OT - Re: hunting the fatty

2015-11-11 Thread Rick Romero
Quoting mancyb...@gmail.com: On Wed, 11 Nov 2015 09:50:29 -0600 Rick Romero <r...@havokmon.com> wrote: LOL. This is a horrible subject line.  I've been trying to resolve a DDOS issue, and ignoring a lot of email.  Here I had been thinking this was a sex-spam, and I just got

OT - Re: hunting the fatty

2015-11-11 Thread Rick Romero
LOL. This is a horrible subject line.  I've been trying to resolve a DDOS issue, and ignoring a lot of email.  Here I had been thinking this was a sex-spam, and I just got around to wondering why the spam system isn't working quite right and they kept coming in.  :P Not sure if this was

Re: FreeBSD 10 & default_vsz_limit causing reboots?

2015-09-24 Thread Rick Romero
h 6 removable, self powered Sep 17 11:25:39 romulus kernel: Trying to mount root from ufs:/dev/mfid0p2 [rw]... Sep 17 11:25:39 romulus kernel: WARNING: / was not properly dismounted Sep 17 11:25:39 romulus kernel: WARNING: /: mount pending error: blocks 8 files 1 Sep 17 11:25:39 romulus

FreeBSD 10 & default_vsz_limit causing reboots?

2015-09-15 Thread Rick Romero
Ok, So this is really more of an observation than anything else.  I had a FreeBSD 10.1 server that was running great. Some SSL issue came up, or I upgrade Dovecot in ports - something occurred and the machine started rebooting randomly.  It would run for 2 weeks, then reboot.  It might run for

Re: How to "Windows Authenticate"

2015-09-10 Thread Rick Romero
Quoting Mark Foley : Rick, Samba4 AD/DC and Dovecot work perfectly for everything including access from SmartPhones.  I've got roaming domain logins, redirected folders, calendars and contacts work just fine with Outlook and WebDav for sharing calendars; don't need them in

Re: How to "Windows Authenticate"

2015-09-09 Thread Rick Romero
ment System To: dovecot@dovecot.org Subject: Re: How to "Windows Authenticate" Comments interspersed with yours ... --Mark -Original Message- Date: Sun, 06 Sep 2015 20:00:11 -0500 From: Rick Romero <r...@havokmon.com> To: dovecot@dovecot.org Subject: Re: How to "Windows Aut

Re: How to "Windows Authenticate"

2015-09-07 Thread Rick Romero
, method=NTLM, rip=192.168.0.58, lip=192.168.0.2, mpid=13491, session= Thanks --Mark -Original Message----- Date: Thu, 03 Sep 2015 06:53:19 -0500 From: Rick Romero <r...@havokmon.com> To: dovecot@dovecot.org Subject: Re: How to "Windows Authenticate"   Hi Mark, I haven't

Re: How to "Windows Authenticate"

2015-09-03 Thread Rick Romero
Hi Mark, I haven't done it, but I've played with the scenario enough to have an idea. What you want to do is have Outlook auth via NTLM to Dovecot.  First that means having the machine be a domain member (usually via Samba) in order to properly process NTLM/Kerberos handshake - which it

Re: backing up IMAP server on a hard drive

2015-08-06 Thread Rick Romero
Quoting Kevin Laurie superinterstel...@gmail.com: Hi, I am trying to back up my IMAP server to a hard drive. Later I intend to extract all mails for attachments. What do you reckon is the best too to perform this ? Imapsync or Thunderbird (or something else, please recommend) One problem I

Re: backing up IMAP server on a hard drive

2015-08-06 Thread Rick Romero
not.   Please advise.  Regards Kevin        On Thursday, August 6, 2015, Rick Romero r...@havokmon.com wrote:  Quoting Kevin Laurie superinterstel...@gmail.com[1]: Hi, I am trying to back up my IMAP server to a hard drive. Later I intend to extract all mails for attachments. What

Re: FREAK/Logjam, and SSL protocols to use

2015-05-27 Thread Rick Romero
Quoting Gedalya geda...@gedalya.net: On 05/26/2015 10:37 AM, Ron Leach wrote: https://weakdh.org/sysadmin.html includes altering DH parameters length to 2048, and re-specifying the allowable cipher suites - they give their suggestion. It looks like there is an error on this page regarding

Re: FREAK/Logjam, and SSL protocols to use

2015-05-27 Thread Rick Romero
Quoting Gedalya geda...@gedalya.net: On 05/27/2015 09:55 AM, Rick Romero wrote: Quoting Gedalya geda...@gedalya.net: On 05/26/2015 10:37 AM, Ron Leach wrote: https://weakdh.org/sysadmin.html includes altering DH parameters length to 2048, and re-specifying the allowable cipher suites

Re: Support for multiple passwords?

2015-03-18 Thread Rick Romero
Quoting Reindl Harald h.rei...@thelounge.net: Am 18.03.2015 um 20:56 schrieb Conrad Kostecki: Am 2015-03-18 20:46, schrieb Reindl Harald: Am 18.03.2015 um 20:40 schrieb Conrad Kostecki: Hi! Currently, the passwords are stored in plaintext for my dovecot, as I am still using cram-md5 AND

Re: Support for multiple passwords?

2015-03-18 Thread Rick Romero
Quoting Conrad Kostecki ck+dove...@bl4ckb0x.de: Am 2015-03-18 21:10, schrieb Rick Romero: Quoting Reindl Harald h.rei...@thelounge.net: Am 18.03.2015 um 20:56 schrieb Conrad Kostecki: Am 2015-03-18 20:46, schrieb Reindl Harald: Am 18.03.2015 um 20:40 schrieb Conrad Kostecki: Hi

Re: Require certificate for external clients

2015-02-27 Thread Rick Romero
Quoting Karol Babioch ka...@babioch.de: Hi list, I'm currently looking into ways of making use of client certificates. I want to force external clients (i.e. anything outside the local subnet) to use client certificates. It is my understanding that this in itself can be achieved with the

Re: Howto NTML

2015-02-13 Thread Rick Romero
Quoting Mark Foley mfo...@novatec-inc.com: Has anyone gotten NTLM working with Dovecot and Outlook? I have a Samba4 domain controller / active directory running just fine on Linux Slackware64 14.1.  PLAIN authenticiation works just fine if I create /etc/passwd accounts for the domain users.

Re: Howto NTML

2015-02-13 Thread Rick Romero
Quoting Mark Foley mfo...@novatec-inc.com: Has anyone gotten NTLM working with Dovecot and Outlook? I have a Samba4 domain controller / active directory running just fine on Linux Slackware64 14.1.  PLAIN authenticiation works just fine if I create /etc/passwd accounts for the domain users.

Re: TLS config check

2015-02-06 Thread Rick Romero
Quoting SW dove...@bsdpanic.com: Hi All First the essentials: dovecot --version: 2.2.15 /usr/local/etc/dovecot/conf.d/10-ssl.conf: ssl = required ssl_cert = /usr/local/openssl/certs/mail.domain.com.chained.dovecot.ecdsa.crt ssl_key = /usr/local/openssl/certs/mail.domain.com.ecdsa.key

Re: [2.3 feature request]: multiple passwords for single user

2014-12-15 Thread Rick Romero
Quoting Arkadiusz Miśkiewicz ar...@maven.pl: Hi. I wonder if there any plans of finishing multiple passwords for single user feature? snip Untill that happens (not that great) workaround exists: http://wiki2.dovecot.org/Authentication/MultipleDatabases No, just use multiple fields in SQL

Re: [2.3 feature request]: multiple passwords for single user

2014-12-15 Thread Rick Romero
Quoting Arkadiusz Miśkiewicz ar...@maven.pl: Hi. I wonder if there any plans of finishing multiple passwords for single user feature? snip Untill that happens (not that great) workaround exists: http://wiki2.dovecot.org/Authentication/MultipleDatabases   Whoops misfired Unless you want a

Re: identify MUA connecting?

2014-07-28 Thread Rick Romero
Quoting Reindl Harald h.rei...@thelounge.net: Am 28.07.2014 19:58, schrieb Juan Pablo: Hello I am using dovecot 1.2.15 on ubuntu. Is it possible to somehow log the MUA information that is connecting to Dovecot? The reason I am wanting to do this is I would like to know if people are getting

Re: Multiple passwords with sql authentication

2014-07-23 Thread Rick Romero
Quoting BlackVoid blackvoid+dove...@fantas.in: I'm currently working on a control panel which is using postfix, dovecot and other applications and I want to add application specific passwords to increase security. I found one solution [1], however it requires the password to be included in

Re: Multiple passwords with sql authentication

2014-07-23 Thread Rick Romero
Quoting BlackVoid blackvoid+dove...@fantas.in: On 2014-07-23 18:07, Rick Romero wrote: Quoting BlackVoid blackvoid+dove...@fantas.in: I'm currently working on a control panel which is using postfix, dovecot and other applications and I want to add application specific passwords

Re: Multiple passwords with sql authentication

2014-07-23 Thread Rick Romero
Quoting BlackVoid blackvoid+dove...@fantas.in: On 2014-07-23 18:07, Rick Romero wrote: Quoting BlackVoid blackvoid+dove...@fantas.in: I'm currently working on a control panel which is using postfix, dovecot and other applications and I want to add application specific passwords

Re: Multiple passwords with sql authentication

2014-07-23 Thread Rick Romero
Quoting BlackVoid blackvoid+dove...@fantas.in: On 2014-07-23 18:40, Rick Romero wrote: Quoting BlackVoid blackvoid+dove...@fantas.in: On 2014-07-23 18:07, Rick Romero wrote: Quoting BlackVoid blackvoid+dove...@fantas.in: I'm currently working on a control panel which is using postfix

Re: Defer email via LMTP when there is 'no space left on device' instead of rejecting it

2014-07-22 Thread Rick Romero
Quoting Reindl Harald h.rei...@thelounge.net: Am 22.07.2014 17:11, schrieb Christian Rohmann: In consequence this means the configuration option quota_full_tempfail is applied in both cases. But to me there is a major difference between a full disk (a.k.a admin fucked up) and over-quota

Re: Mailboxes are in Maildir format. Any good backup tips? Had success with version control?

2014-06-30 Thread Rick Romero
Quoting Bob Miller b...@computerisms.ca: Hi, Suggestions and warnings are most welcome. Thanks! Since you're using maildir, you might want to check rsync out as well, especially with --link-dest. In short, you call rsync on your backup machine like this: rsync

Re: [Dovecot] Architecture for large Dovecot cluster

2014-01-24 Thread Rick Romero
Quoting Urban Loesch b...@enas.net: Hi, and some other Dovecot mailing list threads but I am not sure how many users such a setup will handle.  I have a concern about the I/O performance of NFS in the suggested architecture above.  One possible option available to us is to split up the

Re: [Dovecot] Server Migration Attempt - new messages DELETED after secondary rsyncs

2013-12-27 Thread Rick Romero
Quoting Charles Marcus cmar...@media-brokers.com: Starting a new thread, as I've got a lot more details now... rsync command (dovecot is STOPPED before performing, source is the latest snapshot of the active server): rsync -rltgovDHP --delete --delete-excluded --exclude-from

Re: [Dovecot] Accessing plain text password from memory

2013-12-13 Thread Rick Romero
Quoting Stanislas SABATIER s.sabat...@pobox.com: Is there a way to retrieve the client's password in plain text from memory ? I don't store the password in plain text in my postgreSQL but I need it when the client is connected to make crypto computation. Hi Stan, I hope you're not trying to

Re: [Dovecot] Accessing plain text password from memory

2013-12-13 Thread Rick Romero
As long as you're not claiming that you can't access the data, then I won't get uppity :) Though I honestly don't see any advantage to the approach you're taking. It was useless for Lavabit, it's a poor method that's not going to fair any better under anyone else's watch. Why not just

Re: [Dovecot] Accessing plain text password from memory

2013-12-13 Thread Rick Romero
Quoting Stanislas SABATIER s.sabat...@pobox.com: 2013/12/13 Rick Romero r...@havokmon.com ​(…) IMHO, your time is better spent creating a PGP plugin that uses public keys to encrypt the email contents. Rick ​That's exactly what I'm doing. Inbound mails are all encrypted with each

Re: [Dovecot] 2.2.9

2013-11-22 Thread Rick Romero
Thanks for providing and maintaining a great piece of software. Rick

Re: [Dovecot] 2.2.9

2013-11-22 Thread Rick Romero
Noel, I include you in the gang of three, and I only read half the posts on this list. I have no specific reason to, but it isn't a good association. A decade ago I was active on the Pegasus mail and Mercury lists, and names stood out after a while. Unfortunately on this list, the names stand

Re: [Dovecot] Odd Feature Request - RBL blacklist lookup to prevent authentication

2013-10-22 Thread Rick Romero
Quoting Marc Perkel m...@perkel.com: I would like to have a list of IPs (hacker list) that I can do a lookup on so that if anyone tries to authenticate to dovecot they always fail if they are on my list. I have the list - and the list is available as a DNS blacklist. I'd like to have it work

Re: [Dovecot] lda and home directory

2013-08-15 Thread Rick Romero
Quoting Bob Miller b...@computerisms.ca: Hello, I am using qmail and lda configured such that lda should not have to do a lookup for delivery.  I set my defaultdelivery like so: |HOME=/home/mail/$USER /var/qmail/bin/preline -f /usr/local/libexec/dovecot/dovecot-lda Given that the email

Re: [Dovecot] IMAP

2013-06-10 Thread Rick Romero
Quoting Jason Lock jl...@csolve.net: We are using version 1.2.17 and recently are experiencing major issues with performance, which we believe have isolated to IMAP sessions. We have 3 servers running Dovecot, with a central store shared via NFS.  Things have been running quite well for

[Dovecot] Dovecot and time (again)

2013-06-05 Thread Rick Romero
I'm rehashing/reliving my issues from 2010: http://www.dovecot.org/list/dovecot/2010-October/053528.html In short, when calling deliver from vdelivermail (or procmail), and delivering via NFS to Maildir, the timestamp on the file is GMT.  If procmail or vdelivermail completely handle the email,

Re: [Dovecot] dovecot and time

2013-06-05 Thread Rick Romero
I found something interesting via strace. lda is writing a timestamp with utime before doign the fsync, but I'm really not a C guy, so I have no idea why that's going on via procmail and not via commandline. I assume it's related to the choice of pread64 vs read. when called from

Re: [Dovecot] dovecot and time

2013-06-05 Thread Rick Romero
Quoting Rick Romero r...@havokmon.com: I found something interesting via strace.  lda is writing a timestamp with utime before doign the fsync, but I'm really not a C guy, so I have no idea why that's going on via procmail and not via commandline.  I assume it's related to the choice

Re: [Dovecot] How to serve a subset of IMAP folders for hand held devices.

2011-12-28 Thread Rick Romero
Quoting David Pottage da...@electric-spoon.com: On 28/12/11 10:39, Andraž 'ruskie' Levstik wrote: :2011-12-28T10:26:David Pottage: I solved the problem by creating a second instance of dovecot running on a non standard port, and configured it to serve only a subset my email folders, so that

Re: [Dovecot] Can I block dovecot from deleting read messages, after being fetched?

2011-12-21 Thread Rick Romero
The policy apparently doesn't cover archiving outgoing email ? Typically you set up your SMTP service to 'BCC' an archive mailbox to achieve a complete archive of both incoming and outgoing mail. Rick Quoting Vasiliu Adrian vadr...@gmail.com: Hi all, Is there an option to disable

[Dovecot] IMP, Dovecot and multiple namespaces

2011-11-02 Thread Rick Romero
Hey guys, I'm wondering what the best way is to be backwards compatible with Courier mailbox formats and not duplicate mailbox trees with Dovecot. Is anyone doing this right now? My Dovecot 2.0.13 is configured as follows for Namespaces: namespace { inbox = yes location = prefix =

Re: [Dovecot] inbox issue

2011-10-10 Thread Rick Romero
Quoting Eric Broch ebr...@whitehorsetc.com: I have dovecot 2.0.11 installed on a CentOS 5.7 email server. Two of the server email clients, one using Outlook and the other Thunderbird, have had all the contents of their inbox disappear only to reappear at a later time. One client's inbox email

Re: [Dovecot] 64.31.19.48 attempt to break into my computer

2011-09-22 Thread Rick Romero
Quoting Mike Cardwell dove...@lists.grepular.com: On 22/09/11 15:21, Ralf Hildebrandt wrote: Perhaps, if you have a list of the plain text passwords in advance you could use ClamAV. In our case, we don't as we're using an AD. I actually copied the ClamAV tcp and local interface API so that

Re: [Dovecot] 64.31.19.48 attempt to break into my computer

2011-09-22 Thread Rick Romero
Quoting Ralf Hildebrandt ralf.hildebra...@charite.de: * Rick Romero r...@havokmon.com: There are additional 'non-official' ClamAV signatures that are meant to detect phishing attempts. They do work, but aren't perfect. Got a link? Or are you thinking of the SaneSecurity Signatures? Yep

Re: [Dovecot] 64.31.19.48 attempt to break into my computer

2011-09-22 Thread Rick Romero
Quoting Alex ot...@ahhyes.net: It [fail2ban] is a great tool. Unfortunately dovecot allows infinate incorrect logins during a single session. When fail2ban has firewalled the ip its pointless as the rule only affects new sessions, not established ones. I am disappointed that the author of

Re: [Dovecot] dumb Q: how to search for email hack attempts ?

2011-09-06 Thread Rick Romero
Quoting Voytek voy...@sbt.net.au: one of the users thinks someone hacked his email, I don't have time this morning to analyze mail logs in detail, but does some one has some tips to simply searching mail logs for multiple log in attempts, etc, I'd appreciate some grepping for failed logins

Re: [Dovecot] mail spool filesystem

2011-08-31 Thread Rick Romero
Quoting Nick Rosier nick+dove...@bunbun.be: Kelsey Cummings wrote: On Fri, Aug 19, 2011 at 03:48:00AM -0500, Stan Hoeppner wrote: On 8/17/2011 9:42 AM, Adrian Ulrich wrote: I read that XFS is a good choice, but is not too reliable... Are you using Maildir or MBOX? In any case: XFS would

Re: [Dovecot] Post-login scripting with virtual users

2011-08-24 Thread Rick Romero
Quoting Mark Willcox will...@datahelper.com: I am running Dovecot 2.0.13 on Fedora 15. I have migrated from a bincimap installation using checklocalpwd. All email is in folders owned by a unprivileged user, popuser. The email users are entirely virtual and have no relationship to actual

Re: [Dovecot] Dovecot rejecting Vpopmail User 89

2011-08-24 Thread Rick Romero
Quoting ho...@rumormillnews.com: I'm working to get Dovecot 2.0.13 working along with qmail, Vpopmail and Squirrelmail on a Debian 6.0.2 system, Dovecot compiled, not from a package. Vpopmail has a widely known assigned user/group ID of 89 and is the owner of all the mail folders. Regardless

Re: [Dovecot] Dovecot rejecting Vpopmail User 89

2011-08-24 Thread Rick Romero
Enable auth_verbose and check the logs. But I'm pretty sure that means Dovecot can't change to the Maildir folder. I assume the user's folder is owned by vpopmail:vchkpw? Is the Maildir NFS mounted or local? Rick Quoting ho...@rumormillnews.com: Thanks, Rick. :) Changed first/last

Re: [Dovecot] Post-login scripting with virtual users

2011-08-24 Thread Rick Romero
. Also, when I get this working, can I set up a pop3 equivalent? _ Mark Willcox Data Helper, Inc. On 8/24/2011 2:06 PM, Rick Romero wrote: Quoting Mark Willcox will...@datahelper.com: I am running Dovecot 2.0.13 on Fedora 15. I have migrated from a bincimap installation using

Re: [Dovecot] May 05 07:20:21 imap: Warning: Time jumped forwards 16 seconds

2011-05-05 Thread Rick Romero
Quoting Noel noeld...@gmail.com: On 5/5/2011 1:54 PM, Spyros Tsiolis wrote: --- On Thu, 5/5/11, Timo Sirainent...@iki.fi wrote: From: Timo Sirainent...@iki.fi Subject: Re: [Dovecot] May 05 07:20:21 imap: Warning: Time jumped forwards 16 seconds To: Spyros Tsiolissts...@yahoo.co.uk Cc:

Re: [Dovecot] Restricting IMAP

2011-05-02 Thread Rick Romero
Quoting Matt lm7...@gmail.com: I want to restrict IMAP use too 127.0.0.1 and to only certain usernames. Such as f...@my777domain.com would be allowed to use IMAP. How would I do that with Dovecot or can I? Basically I want webmail to work with IMAP regardless of username but I only want

Re: [Dovecot] Vpopmail and lastauth

2011-04-12 Thread Rick Romero
I had the same issue - Dovecot has it's own method of updating lastauth and doesn't put the IP address in the field, but 'pop' or 'imap'. I'd rather have the IP. It was easier to just write my own postauth script. I've added a 'type' field so I can keep track of pop/imap/smtp

Re: [Dovecot] SSL Compatibility? SNI vs SAN (Subject Alternative Names) and multiple domains

2011-03-16 Thread Rick Romero
On Mar 16, 2011, at 6:21 PM, Ed W li...@wildgooses.com wrote: Hi How big of an issue is a cert with half a dozen or a dozen SANs attached? Do most mail clients handle that sort of certificate properly in order to access their mailboxes? I think it's been discussed here before, but

[Dovecot] 2.0.7 - missing SORT/THREAD

2011-03-15 Thread Rick Romero
Obviously I did something wrong, but I don't have SORT and THREAD Capabilities built into my 2.0.7 server (OpenSolaris 5.11 snv_134 i86pc i386 i86xpv Solaris) What do I need to do? * OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE IDLE STARTTLS AUTH=PLAIN AUTH=LOGIN

Re: [Dovecot] Best way to migrate versions and machines

2011-02-21 Thread Rick Romero
Quoting Ed W li...@wildgooses.com: On 17/02/2011 15:29, Donny Brooks wrote: We are looking to migrate from our current mail server running dovecot-1.2.11-3 to a new mail server running the latest dovecot (2.0.9?). So this would not only be a version change but also a machine change. We

Re: [Dovecot] Maintaining data integrity through proper power supplies (slightly referencing Best filesystem)

2011-02-02 Thread Rick Romero
If you have a proper-sized UPS, combined with notification from the UPS to the servers to perform orderly shutdowns - including telling the application servers to shutdown prior to the storage servers, etc. - doesn't that render the (possibly more than theoretical) chances of data

Re: [Dovecot] Best way to calculate concurrent users?

2011-01-28 Thread Rick Romero
this problem, but it should also speed up your webmail sessions. Rick Quoting Henrique Fernandes sf.ri...@gmail.com: I don't use imap proxy. Other ideias ? []'sf.rique   On Thu, Jan 27, 2011 at 6:01 PM, Rick Romero r...@havokmon.com wrote: Quoting Henrique Fernandes sf.ri...@gmail.com

Re: [Dovecot] SSD drives are really fast running Dovecot

2011-01-15 Thread Rick Romero
Quoting Stan Hoeppner s...@hardwarefreak.com: Rick Romero put forth on 1/14/2011 8:29 PM: And that's assuming a platter squeezing in 1TB of data at 7200RPMs doesn't get a comparable performance improvement to a higher rotational speed on a lower volume platter... Size

Re: [Dovecot] SSD drives are really fast running Dovecot

2011-01-14 Thread Rick Romero
Quoting Stan Hoeppner s...@hardwarefreak.com: David Jonas put forth on 1/14/2011 2:08 PM: Raid10 is our normal go to, but giving up half the storage in this case seemed unnecessary. I was looking at SAS drives and it was getting pricy. I'll work SATA into my considerations.

Re: [Dovecot] SSD drives are really fast running Dovecot

2011-01-12 Thread Rick Romero
Quoting Marc Perkel m...@perkel.com: I just replaced my drives for Dovecot using Maildir format with a pair of Solid State Drives (SSD) in a raid 0 configuration. It's really really fast. Kind of expensive but it's like getting 20x the speed for 20x the price. I think the big gain is

Re: [Dovecot] Fatal crash during a user search

2011-01-11 Thread Rick Romero
On Dovecot 2.0.7   sorry Quoting Rick Romero r...@havokmon.com: Well, it looks like it occurred during the search to me...   Jan 10 17:05:37 sysvolone dovecot: [ID 583609 mail.crit] imap(u...@host.com): Panic: file istream-header-filter.c: line 520 (i_stream_create_header_filter

Re: [Dovecot] utility to copy/sync IMAP mailboxes

2011-01-06 Thread Rick Romero
Quoting Don Buchholz buchh...@easystreet.net: Any suggestions for a stable, reliable (copy/duplicate/mirror/sync) tool that can do the job using only IMAP access? (No SSL support required.) I've used IMAPSync fairly successfully (Perl), though I hear iSync is supposed to be better (C)..

[Dovecot] Help - custom vpopmail

2010-11-16 Thread Rick Romero
Hi, First, I'm not sure if dovecot should alter this, but it seems vpopmail writes the IP into the 'remote_ip' field instead of the auth type. Dovecot still writes the auth type.  I want both. So I modified my vpopmail install to write an additional field into the lastauth table.  My custom

Re: [Dovecot] Help - custom vpopmail

2010-11-16 Thread Rick Romero
Quoting Timo Sirainen t...@iki.fi: On Tue, 2010-11-16 at 10:30 -0600, Rick Romero wrote:    So I modified my vpopmail install to write an additional field into the lastauth table.  My custom vpopmail writes the remote IP into remote_ip, and the auth type into a 'type' field. I tested

Re: [Dovecot] qmail + dovecot-lda

2010-11-16 Thread Rick Romero
Google vdelivermail + dovecot for some code snippets Are you running latest vpopmail for qmailamim integration? Rick Sent from my iPhone On Nov 16, 2010, at 8:55 PM, ckubu ck...@so36.net wrote: hallo, i am changing my mailsetups to qmail+vpopmail+dovecot. is it possible to let dovecot's

Re: [Dovecot] blackberry emails

2010-10-27 Thread Rick Romero
There is a BES that works with IMAP. You can also get a 'real' Java IMAP client for blackberry - http://www.logicprobe.org/proj/logicmail Rick Quoting Donny Brooks dbro...@mdah.state.ms.us: On 10/27/2010 8:17 AM, dhottin...@harrisonburg.k12.va.us wrote: Does anyone have clients using

Re: [Dovecot] Significant performance problems

2010-10-06 Thread Rick Romero
On 10/6/2010 7:41 PM, Chris Hobbs wrote: On 10/6/10 5:22 PM, Timo Sirainen wrote: login_processes_count: 20 Probably could use less then 20. login_max_connections: 64 And this could be higher. In general you should have maybe 1-2x the number of login processes than CPU cores. Since this is

[Dovecot] deliver and time

2010-10-04 Thread Rick Romero
Hi All, I've been experimenting with deliver on my personal domain, and so far everything has been peachy except for Mail.app. Mail.app (on multiple devices) is showing what looks to be GMT times, rather than the date header. Initially I thought it was something I did on my Mac, until I

  1   2   >