On 15-Mar-2009, at 14:25, Victor Duchovni wrote:

On Sun, Mar 15, 2009 at 12:27:37PM -0400, Wietse Venema wrote:

smtpd_tls_session_cache_database = btree:$data_directory/ smtpd_sessions

postfix/smtpd[67779]: fatal: open database /var/db/postfix/
smtpd_sessions.db: No such file or directory

smtpd never uses the smtpd_tls_session_cache_database setting.
You have that file configured via some other main.cf parameter.

Indeed this file is managed by trivial-rewrite(8), not smtpd(8).
Perhaps the OP is trying to this file as access table? In any case
no official Postfix release with TLS (2.2 or later) has smtpd(8)
accessing the cache directly.

There was a leading space on the smtpd_tls* lines, so they got glommed onto the previous statement (smtpd_sender_restrictions).

I can connect now to the submission port from my MUA (mail.app) as long as I authenticate against the sasldb. I cannot connect from the command-line with openssl s_client:

$ openssl s_client -connect mail.covisp.net:587
CONNECTED(00000003)
4001:error:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol:s23_clnt.c:601:

but from Mail.app:

CONNECTED Mar 15 15:21:03.180 [kCFStreamSocketSecurityLevelNone] -- host:mail.covisp.net -- port:587 -- socket:0x30226650 -- thread: 0x326adb70

READ Mar 15 15:21:03.247 [kCFStreamSocketSecurityLevelNone] -- host:mail.covisp.net -- port:587 -- socket:0x30226650 -- thread: 0x326adb70
220 mail.covisp.net ESMTP Postfix 2.5.6

etc.  I wonder at the SecurityLevelNone, but there is:

WROTE Mar 15 15:22:03.909 [kCFStreamSocketSecurityLevelNegotiatedSSL] -- host:mail.covisp.net -- port:993 -- socket:0x1eb59230 -- thread: 0x3542dc40
1.251 LOGIN user ********

READ Mar 15 15:22:03.951 [kCFStreamSocketSecurityLevelNegotiatedSSL] -- host:mail.covisp.net -- port:993 -- socket:0x1eb59230 -- thread: 0x3542dc40
1.251 OK LOGIN Ok.

with

submission       inet  n       -       n       -       -       smtpd
  -o smtpd_enforce_tls=yes
  -o smtpd_sasl_auth_enable=yes
  -o smtpd_recipient_restrictions=permit_sasl_authenticated,reject
  -o syslog_name=submit


Also, changing the password or login causes it to fail, so it is working from the MUA, just not from the CLI. Of course, I need it to authenticate against the postfixadmin sql database instead (and PAM), but that is an issue for a different list.


--
I do believe Marsellus Wallace, my husband, your boss, told you to
        take *me* out and do *whatever I wanted*. Now I wanna dance, I
        wanna win. I want that trophy, so dance good.

Reply via email to