Re: [exim] Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Ian Z via Exim-users
On Fri, Mar 31, 2023 at 07:18:21PM +0300, Evgeniy Berdnikov via Exim-users wrote: > AFAIR, it has not. There are lot of macros used in Debian config, > I'm pretty sure that only small part of them is covered by wizard. IIRC (I have not used the debian style configuration for a long time), the

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Dzmitry Shykuts via Exim-users
There is no error since I am using dovecot authenticator. I already checked the config in the case, everything works as it should. The plaintext authenticator really needs to use $auth2 as the username. For other authenticators, from the Exim documentation: "For the other authenticators,

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Jeremy Harris via Exim-users
On 31/03/2023 20:28, Evgeniy Berdnikov via Exim-users wrote: while $auth1 should always be null string for PLAIN. Wups, not for the dovecot driver. You're thinking of the plaintext driver. -- Cheers, Jeremy -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Evgeniy Berdnikov via Exim-users
On Fri, Mar 31, 2023 at 04:19:05PM +0300, Dzmitry Shykuts via Exim-users wrote: > I found where the problem was! > > It turns out that the Thunderbird mail client uses two types of > authentication with an unencrypted password at the same time: PLAIN and > LOGIN. First it tries PLAIN (and my

Re: [exim] Re (2): Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Evgeniy Berdnikov via Exim-users
On Fri, Mar 31, 2023 at 04:22:43PM +0100, Jeremy Harris via Exim-users wrote: > On 31/03/2023 16:15, Evgeniy Berdnikov via Exim-users wrote: > > .ifdef REMOTE_SMTP_SMARTHOST_PROTOCOL > > protocol = REMOTE_SMTP_SMARTHOST_PROTOCOL > > .endif > > Doesn't that imply the wizard has a question that

Re: [exim] Re (2): Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Slavko via Exim-users
Dňa 31. marca 2023 15:22:43 UTC používateľ Jeremy Harris via Exim-users napísal: >On 31/03/2023 16:15, Evgeniy Berdnikov via Exim-users wrote: >> .ifdef REMOTE_SMTP_SMARTHOST_PROTOCOL >> protocol = REMOTE_SMTP_SMARTHOST_PROTOCOL >> .endif > >Doesn't that imply the wizard has a question that

Re: [exim] Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Jeremy Harris via Exim-users
On 31/03/2023 16:36, Peter via Exim-users wrote: submissions 465/tcp ssmtp smtps urd # Submission over TLS [RFC8314] Should a line beginning smtps be added?  Eg. smtps 465/tcp  ... Not needed. The "smtps" values for the exim smtp transport driver is a keyword, not a reference

Re: [exim] Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Peter via Exim-users
From: Heiko Schlittermann via Exim-users Date: Fri, 31 Mar 2023 16:09:10 +0200 Try adding=20 protocol =3D smtps to your smtp transport. +-+ |protocol|Use: smtp|Type: string|Default: smtp| +-+

Re: [exim] Re (2): Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Jeremy Harris via Exim-users
On 31/03/2023 16:15, Evgeniy Berdnikov via Exim-users wrote: .ifdef REMOTE_SMTP_SMARTHOST_PROTOCOL protocol = REMOTE_SMTP_SMARTHOST_PROTOCOL .endif Doesn't that imply the wizard has a question that sets that? -- Cheers, Jeremy -- ## List details at

Re: [exim] Re (2): Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Evgeniy Berdnikov via Exim-users
On Fri, Mar 31, 2023 at 04:09:10PM +0200, Heiko Schlittermann via Exim-users wrote: > Peter via Exim-users (Fr 31 Mär 2023 15:40:35 CEST): > > From: Jeremy Harris via Exim-users > > Subject: Re: [exim] Configuring for non-encrypted MUA to localhost. > > TLS-on-connect, exim to smarthost. >

Re: [exim] Re (2): Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Heiko Schlittermann via Exim-users
Peter via Exim-users (Fr 31 Mär 2023 15:40:35 CEST): > From: Jeremy Harris via Exim-users > Subject: Re: [exim] Configuring for non-encrypted MUA to localhost. > TLS-on-connect, exim to smarthost. > > Debian has a configuration wizard. In what respect is > > not offering what you need? >

[exim] Re (2): Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Peter via Exim-users
From: Jeremy Harris via Exim-users Subject: Re: [exim] Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost. Debian has a configuration wizard. In what respect is not offering what you need? MUA to exim is OK. The configuration appears to impose STARTTLS to

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Dzmitry Shykuts via Exim-users
So far I am working with Debian 10, so the package versions are old, but current for Debian 10. In the near future I plan to switch to version 11, and maybe immediately to 12, which seems to be released in the fall. In the meantime, you have to protect the current running server. 31.03.2023

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Dzmitry Shykuts via Exim-users
I found where the problem was! It turns out that the Thunderbird mail client uses two types of authentication with an unencrypted password at the same time: PLAIN and LOGIN. First it tries PLAIN (and my condition just worked correctly and there was a standard entry about "Incorrect

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Andrew C Aitchison via Exim-users
On Thu, 30 Mar 2023, Dzmitry Shykuts via Exim-users wrote: Hello! I have installed: Exim 4.92-8+deb10u7, Dovecot 1:2.3.4.1-5+deb10u7. Blink. They looks old. Current Exim is 4.96 and Dovecot is 2.3.20. I see that buster-backports has Exim 4.94.2-7~bpo10+1 -- Andrew C. Aitchison

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Jeremy Harris via Exim-users
On 30/03/2023 13:58, Dzmitry Shykuts via Exim-users wrote: I'm trying to deny users successful authentication if they connect not from the internal network but from the Internet. At the same time, I have a file with exception users. server_condition is used to deny authentication. At the same

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Dzmitry Shykuts via Exim-users
I'm sorry, I did not specify, but it does not affect the result. AUTH_ADVERTISE_CONDITION = ${if or{{match_ip{$sender_host_address}{LAN}}{!and{{eq{$tls_in_cipher}{}}{eq{$received_port}{25}{*}{}} 31.03.2023 13:16, Jeremy Harris via Exim-users пишет: On 30/03/2023 13:58, Dzmitry Shykuts

Re: [exim] Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Jeremy Harris via Exim-users
On 30/03/2023 20:00, Peter via Exim-users wrote: Debian 11 here with exim4 4.94.2-7. Debian has a configuration wizard. In what respect is not offering what you need? -- Cheers, Jeremy -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Jeremy Harris via Exim-users
On 30/03/2023 13:58, Dzmitry Shykuts via Exim-users wrote: I have a file with exception users But the server_advertise_condition wants an emtpty/nonempty string, and you appear to be handing it a filename. -- Cheers, Jeremy -- ## List details at

Re: [exim] nwildlsearch does not match

2023-03-31 Thread Jeremy Harris via Exim-users
On 31/03/2023 07:51, Niels Kobschätzki via Exim-users wrote: What am I doing wrong? I thought that nwildlsearch can use wildcards and * and .* are wildcards to me. https://exim.org/exim-html-current/doc/html/spec_html/ch-file_and_database_lookups.html#SECTsinglekeylookups -- Cheers, Jeremy

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Dzmitry Shykuts via Exim-users
31.03.2023 11:20, Odhiambo Washington via Exim-users : What server resources are you saving with selective authentication? The goal is not to conserve server resources but to prevent hackers from guessing passwords. Even if the hacker enters the correct user password, if that user is not

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Odhiambo Washington via Exim-users
On Fri, Mar 31, 2023 at 11:08 AM Dzmitry Shykuts via Exim-users < exim-users@exim.org> wrote: > Hello! > > I have installed: Exim 4.92-8+deb10u7, Dovecot 1:2.3.4.1-5+deb10u7. > > I'm trying to deny users successful authentication if they connect not > from the internal network but from the

[exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Dzmitry Shykuts via Exim-users
Hello! I have installed: Exim 4.92-8+deb10u7, Dovecot 1:2.3.4.1-5+deb10u7. I'm trying to deny users successful authentication if they connect not from the internal network but from the Internet. At the same time, I have a file with exception users. server_condition is used to deny

[exim] Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-03-31 Thread Peter via Exim-users
Hi, Debian 11 here with exim4 4.94.2-7. On the localhost, the MUA needs a non-encrypted connection on port 25 to exim. Exim to remote smarthost is TLS-on-connect with AUTH PLAIN. The connection was verified with this command. $ openssl s_client -crlf -connect mail.easthope.ca:465 How should

Re: [exim] nwildlsearch does not match

2023-03-31 Thread nb via Exim-users
Le 2023-03-31 08:51, Niels Kobschätzki via Exim-users a écrit : > Hi, > > I have set up a ratelimit for my users and also a whitelist-file. > > The acl for the ratelimit looks like this: > > defer authenticated = * > ratelimit = 30 / 5m / strict / $authenticated_id > condition = >

[exim] nwildlsearch does not match

2023-03-31 Thread Niels Kobschätzki via Exim-users
Hi, I have set up a ratelimit for my users and also a whitelist-file. The acl for the ratelimit looks like this: defer authenticated = * ratelimit = 30 / 5m / strict / $authenticated_id condition =