the "owner of mail address" is defined in smtp_sender_login_maps:
Sure, and that's where I defined them via the regexp type table so that
any sender gets an equal SASL username to be checked against.
the regexp is just shortcut so every address is owned by the login
name same as the address.
As above, that's why I did it.
I think I did not explain myself correctly, English is not my first
language.
First, I'm not debugging a setup which I don't know. I'm trying to
understand how to reconcile something that I built from scratch and had
to build it that way (namely, the regexp table that makes address ==
SASL username) to what it's actually documented.
Reading from man 5 postconf:
"Reject the request when the client is authenticated with SASL, but
either the MAIL FROM address is not listed in $smtpd_sender_login_maps,
or the SASL login name is not an owner for that address.
This prevents an authenticated client from using a MAIL FROM address
that they do not explicitly own."
If we break down what is supposed to happen, according to the man page:
Reject the request when the client is authenticated with SASL
WHEN
(1) the MAIL FROM address is not listed in $smtpd_sender_login_maps
OR
(2) the SASL login name is not an owner for that address
Now, we need just one of (1) or (2) to be true. The point is that (2)
never appears to be true; if it was true there would never have been the
necessity of the third mapping table. Actually, if nobody had the need
to send a message with a different MAIL FROM from it's SASL username
there wouldn't be the need of any mapping table at all; but that's not
what happens. If you remove the mapping table no message pass this check.
I probably already had a reply which explains this behavior from you:
No. I guess it's easier to add mapping of address to login name than
remove it if it was there by default.
So I just have to accept the man page is poorly worded and needs an
update, short of a maintainer coming thru and explaining it (and if
that's the case better clarify it in the man page for posterity also).
On 30/09/26 12:30, Matus UHLAR - fantomas via Postfix-users wrote:
On 30.09.26 11:27, Luca Cavana via Postfix-users wrote:
... because what I read from "but either the MAIL FROM address is not
listed in $smtpd_sender_login_maps, or the SASL login name is not an
owner for that address" is "but either the MAIL FROM address is not
listed in $smtpd_sender_login_maps, or the SASL login name is not
equal to that address".
What does "is not an owner of" implies that I'm missing?
the "owner of mail address" is defined in smtp_sender_login_maps:
"Optional lookup table with the SASL login names that own the envelope
sender (MAIL FROM) addresses."
Either there's no map entry at all, or the map entry does not list the
SASL name.
On 30.09.26 12:01, Luca Cavana via Postfix-users wrote:
If there is no map entry at all the mail is rejected, if the map
entry does not list the SASL username that's equal to the MAIL FROM:
command the email is rejected (hence the need for the third "regexp"
list in my setup).
the regexp is just shortcut so every address is owned by the login
name same as the address.
The behavior still does not explain the man page statement "Reject
the request when the client is authenticated with SASL, but [...] the
SASL login name is not an owner for that address." because that's not
what happens.
According to your former mail, that's exactly what happens:
NOQUEUE: reject: RCPT from unknown[2001:67c:d68:13::e]: 553 5.7.1
<[email protected]>: Sender address rejected: not owned
by user
[email protected]; from=<[email protected]>
to=<redacted> proto=ESMTP helo=<[IPV6:2001:67c:d68:13::e]>
this happened when you removed the regexp.
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]