the "owner of mail address" is defined in smtp_sender_login_maps:
Sure, and that's where I defined them via the regexp type table so that any sender gets an equal SASL username to be checked against.

the regexp is just shortcut so every address is owned by the login name same as the address.
As above, that's why I did it.

I think I did not explain myself correctly, English is not my first language. First, I'm not debugging a setup which I don't know. I'm trying to understand how to reconcile something that I built from scratch and had to build it that way (namely, the regexp table that makes address == SASL username) to what it's actually documented.
Reading from man 5 postconf:

"Reject  the  request when the client is authenticated with SASL, but either the MAIL FROM address is not listed in $smtpd_sender_login_maps, or the SASL login name is not an owner for that address. This prevents an authenticated client from using a MAIL FROM address that they do not explicitly own."

If we break down what is supposed to happen, according to the man page:

Reject  the  request when the client is authenticated with SASL
WHEN
(1) the MAIL FROM address is not listed in $smtpd_sender_login_maps
OR
(2) the SASL login name is not an owner for that address

Now, we need just one of (1) or (2) to be true. The point is that (2) never appears to be true; if it was true there would never have been the necessity of the third mapping table. Actually, if nobody had the need to send a message with a different MAIL FROM from it's SASL username there wouldn't be the need of any mapping table at all; but that's not what happens. If you remove the mapping table no message pass this check.

I probably already had a reply which explains this behavior from you:

No. I guess it's easier to add mapping of address to login name than remove it if it was there by default.
So I just have to accept the man page is poorly worded and needs an update, short of a maintainer coming thru and explaining it (and if that's the case better clarify it in the man page for posterity also).

On 30/09/26 12:30, Matus UHLAR - fantomas via Postfix-users wrote:
On 30.09.26 11:27, Luca Cavana via Postfix-users wrote:
... because what I read from "but either the MAIL FROM address is not listed in $smtpd_sender_login_maps, or the SASL login name is not an owner for that address"  is "but either the MAIL FROM address is not listed in $smtpd_sender_login_maps, or the SASL login name is not equal to that address".
What does "is not an owner of" implies that I'm missing?

the "owner of mail address" is defined in smtp_sender_login_maps:

"Optional lookup table with the SASL login names that own the envelope sender (MAIL FROM)  addresses."

Either there's no map entry at all, or the map entry does not list the
SASL name.

On 30.09.26 12:01, Luca Cavana via Postfix-users wrote:
If there is no map entry at all the mail is rejected, if the map entry does not list the SASL username that's equal to the MAIL FROM: command the email is rejected (hence the need for the third "regexp" list in my setup).

the regexp is just shortcut so every address is owned by the login name same as the address.

The behavior still does not explain the man page statement "Reject the request when the client is authenticated with SASL, but [...] the SASL login name is not an owner for that address." because that's not what happens.

According to your former mail, that's exactly what happens:

NOQUEUE: reject: RCPT from unknown[2001:67c:d68:13::e]: 553 5.7.1
<[email protected]>: Sender address rejected: not owned by user
[email protected]; from=<[email protected]>
to=<redacted> proto=ESMTP helo=<[IPV6:2001:67c:d68:13::e]>

this happened when you removed the regexp.


_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to