Re: [exim] Routing failed deliveries through an ESP

2023-04-20 Thread Andrew C Aitchison via Exim-users
On Thu, 20 Apr 2023, Lance Lovette via Exim-users wrote: There's a rational basis for an exception for 5xx before MAIL FROM, when the target only has the connection parameters and HELO name to use as a basis for rejection Unfortunately, Google, in the case of an outright IP-based block,

Re: [exim] Proxy smtp connections to multiple Exim servers behind proxy

2023-04-16 Thread Andrew C Aitchison via Exim-users
On Sun, 16 Apr 2023, Jeremy Harris via Exim-users wrote: On 15/04/2023 23:31, Sebastian Arcus via Exim-users wrote: you might be able to use cutthrough delivery from the front-end to the real server, which might allow you to reject rather than bounce some of the time; it might even help with

Re: [exim] Proxy smtp connections to multiple Exim servers behind proxy

2023-04-16 Thread Andrew C Aitchison via Exim-users
On Sat, 15 Apr 2023, Sebastian Arcus via Exim-users wrote: I don't know what sort of latency there will be between these machines, but you might be able to use cutthrough delivery from the front-end to the real server, which might allow you to reject rather than bounce some of the time; it

Re: [exim] Proxy smtp connections to multiple Exim servers behind proxy

2023-04-15 Thread Andrew C Aitchison via Exim-users
On Sat, 15 Apr 2023, Sebastian Arcus via Exim-users wrote: On 15/04/2023 21:20, Evgeniy Berdnikov via Exim-users wrote: On Sat, Apr 15, 2023 at 08:44:08PM +0100, Sebastian Arcus via Exim-users wrote: These are all separate servers belonging to different organisations. They each host their

Re: [exim] Proxy smtp connections to multiple Exim servers behind proxy

2023-04-15 Thread Andrew C Aitchison via Exim-users
On Sat, 15 Apr 2023, Sebastian Arcus wrote: On 15/04/2023 18:44, Andrew C Aitchison wrote: On Sat, 15 Apr 2023, Sebastian Arcus via Exim-users wrote: I have a number of Exim servers behind a NAT gateway (actually connected with vpn's to a cloud vps - but I'm hoping this is not relevant to

Re: [exim] Proxy smtp connections to multiple Exim servers behind proxy

2023-04-15 Thread Andrew C Aitchison via Exim-users
On Sat, 15 Apr 2023, Sebastian Arcus via Exim-users wrote: I have a number of Exim servers behind a NAT gateway (actually connected with vpn's to a cloud vps - but I'm hoping this is not relevant to this post). I would like the gateway to send incoming port 25 traffic to the correct Exim

Re: [exim] Re (2): Configuring exim to use an non-TLS connection to port 587.

2023-04-13 Thread Andrew C Aitchison via Exim-users
On Wed, 12 Apr 2023, Peter via Exim-users wrote: From: Graeme Fowler via Exim-users Date: Tue, 11 Apr 2023 18:44:22 +0100 ... problem is on your filesystem rather than on-the-wire. Another helpful tip is in https://wiki.debian.org/Exim4Gmail. /etc/exim4/passwd.client had permissions

Re: [exim] Configuring for non-encrypted MUA to localhost. TLS-on-connect, exim to smarthost.

2023-04-06 Thread Andrew C Aitchison via Exim-users
On Thu, 30 Mar 2023, Peter via Exim-users wrote: Hi, Debian 11 here with exim4 4.94.2-7. On the localhost, the MUA needs a non-encrypted connection on port 25 to exim. Exim to remote smarthost is TLS-on-connect with AUTH PLAIN. The connection was verified with this command. $ openssl

Re: [exim] Make auth unsuccessful with some conditions

2023-03-31 Thread Andrew C Aitchison via Exim-users
On Thu, 30 Mar 2023, Dzmitry Shykuts via Exim-users wrote: Hello! I have installed: Exim 4.92-8+deb10u7, Dovecot 1:2.3.4.1-5+deb10u7. Blink. They looks old. Current Exim is 4.96 and Dovecot is 2.3.20. I see that buster-backports has Exim 4.94.2-7~bpo10+1 -- Andrew C. Aitchison

Re: [exim] Hide IP address of authenticated users

2023-03-17 Thread Andrew C Aitchison via Exim-users
On Wed, 15 Mar 2023, Jasen Betts via Exim-users wrote: On 2023-03-14, Yves Goergen via Exim-users wrote: Hello, I'd like to hide the IP address of authenticated users sending their messages over my SMTP server. The address always appears in the "Received" header and remains there for the

Re: [exim] CVE-2021-38371 (was: CVE-2022-37452)

2023-03-15 Thread Andrew C Aitchison via Exim-users
On Wed, 15 Mar 2023, Andreas Metzler wrote: On 2022-08-24 17:49, Andrew C Aitchison wrote: [...] www.exim.org/static/doc/security/CVE-2021-38371.txt is advertised on a couple of CVE sites but does not exist. Like CVE-2022-37452, CVE-2021-38371 was fixed in 4.95 (the fix in git actually

Re: [exim] expansion error in OAuth2 client authenticator

2023-03-12 Thread Andrew C Aitchison via Exim-users
On Sun, 12 Mar 2023, Victor Ustugov via Exim-users wrote: Hello. # uname -sr FreeBSD 13.1-RELEASE-p6 # pkg info -E exim exim-4.96 exim compiled with all the patches from exim4_4.96-14 https://packages.debian.org/source/sid/exim4 I try to setup OAuth2 client authenticator: client_oauth2:

Re: [exim] Exim, OAUTH2 and gnutls problem

2023-03-09 Thread Andrew C Aitchison via Exim-users
On Sun, 5 Mar 2023, ael via Exim-users wrote: Hello, This is my first post to this list. This is partly to report that I have OAuth2 working with office 365 smtp servers, This is a suprise to me; as far as I know exim does not support OAUTH2. Are you using some extension such as

Re: [exim] exim rewrites the "From:" address

2023-02-27 Thread Andrew C Aitchison via Exim-users
On Mon, 27 Feb 2023, Nick via Exim-users wrote: That doesn't address the question - no-one doubted that Exim 4.xx is able to preserve the From: address. The point is, what is it in the config files that makes it rewrite the From: address; or alternatively, what should be in the config files to

Re: [exim] exim rewrites the "From:" address

2023-02-26 Thread Andrew C Aitchison via Exim-users
On Sat, 25 Feb 2023, Nick via Exim-users wrote: When I send an email using: mailx -r , specifying the from address in the form name@domain, exim rewrites the domain of the From: address and Sender: address to the first entry in the local_domains list. My server hosts multiple domains, so I need

[exim] Real data wanted for testing

2023-02-04 Thread Andrew C Aitchison via Exim-users
I'm looking for exim logfiles and message headers to test that the new exim_msgdate utility reports the correct time for all message ids. I am particularly looking for logfiles and mail folders from a) systems that use the localhost_number feature or b) non-UK time zones. I only really need

Re: [exim] Blocking a Class C

2023-01-19 Thread Andrew C Aitchison via Exim-users
On Thu, 19 Jan 2023, The Doctor wrote: On Thu, Jan 19, 2023 at 08:44:30AM +, Andrew C Aitchison via Exim-users wrote: On Wed, 18 Jan 2023, The Doctor via Exim-users wrote: On Thu, Jan 19, 2023, 00:33 The Doctor wrote: Still having problems with /var/log/exim/in_rejectlog:2023-01-18

Re: [exim] Blocking a Class C

2023-01-19 Thread Andrew C Aitchison via Exim-users
On Wed, 18 Jan 2023, The Doctor via Exim-users wrote: On Thu, Jan 19, 2023, 00:33 The Doctor wrote: Still having problems with /var/log/exim/in_rejectlog:2023-01-18 14:27:01.484 [97258] refused connection from [46.148.40.108]:61402 I=[204.209.81.246]:465 (host_reject_connection) THere are

Re: [exim] DKIM: signing failed: LONG_LINE - in paniclog

2023-01-07 Thread Andrew C Aitchison via Exim-users
On Sat, 7 Jan 2023, Julian Bradfield via Exim-users wrote: On 2023-01-06, Jeremy Harris via Exim-users wrote: You could perhaps configure to not attempt to sign such messages by using a suitable expansion for dkim_domain. If you can't use something like $sender_address then

Re: [exim] Move message to another server for spooling

2023-01-02 Thread Andrew C Aitchison via Exim-users
On Mon, 2 Jan 2023, Jeremy Harris via Exim-users wrote: On 02/01/2023 09:39, Laura Williamson via Exim-users wrote: got a few of these the last couple of days, only to outlook365 servers. Looked on google and it seems to be a random thing that happens with MS. I tried to look in the docs how

Re: [exim] exim 4.96 stopping because postfix is starting?

2022-12-19 Thread Andrew C Aitchison via Exim-users
On Mon, 19 Dec 2022, Johnnie W Adams via Exim-users wrote: Hi, folks, Twice recently, my outbound SMTP server has stopped working for no apparent reason. There's nothing in the logs but this: Dec 19 10:02:22 mailserver2 systemd: Starting Postfix Mail Transport Agent... Dec 19 10:02:22

Re: [exim] dkim=fail (body hash mismatch; body probably modified in transit)

2022-12-11 Thread Andrew C Aitchison via Exim-users
On Sun, 11 Dec 2022, Victor Sudakov via Exim-users wrote: Slavko via Exim-users wrote: Dňa 9. 12. o 8:49 Victor Sudakov via Exim-users napísal(a): Slavko via Exim-users wrote: Dňa 9. 12. o 5:15 Victor Sudakov via Exim-users napísal(a): I've just sent two messages to you with Message-IDs

Re: [exim] if you use openssl v3+ with exim

2022-12-09 Thread Andrew C Aitchison via Exim-users
On Fri, 9 Dec 2022, Cyborg via Exim-users wrote: The issue is reproduceable with openssl s_client directly: openssl s_client -connect 82.218.176.66:25 -starttls smtp I am not going to report the testssl results I got for that host:port here, but they are very worrying. Marius, do you have a

Re: [exim] Weirdness when Exim calls SpamAssassin - how to debug?

2022-11-30 Thread Andrew C Aitchison via Exim-users
On Wed, 30 Nov 2022, Adam Nielsen via Exim-users wrote: Hi all, I'm running into an issue with the way Exim 4.94.2 invokes SpamAssassin (SA). I have added some custom rules to SA, however when Exim invokes it, my custom rules are ignored. However if I use the "spamc" command to manually pass

Re: [exim] Storing messages in Maildir format with symmetric encryption

2022-11-24 Thread Andrew C Aitchison via Exim-users
On Thu, 24 Nov 2022, Jasen Betts via Exim-users wrote: On 2022-11-23, Jeremy Harris via Exim-users wrote: On 23/11/2022 00:16, Dengler, Gabriel via Exim-users wrote: I want to store the incoming e-mails using the Maildir file format encrypted by using some symmetric encryption using the

Re: [exim] Storing messages in Maildir format with symmetric encryption

2022-11-23 Thread Andrew C Aitchison via Exim-users
On Wed, 23 Nov 2022, Dengler, Gabriel via Exim-users wrote: I want to store the incoming e-mails using the Maildir file format encrypted by using some symmetric encryption using the user's password Which user: the sender or the recipient ? -- Andrew C. Aitchison Kendal,

Re: [exim] Keep local_part_suffix in redirect router

2022-11-08 Thread Andrew C Aitchison via Exim-users
On Tue, 8 Nov 2022, Frank Richter via Exim-users wrote: we'd like to allow subaddresses like user+sub@domain to deliver to users’s folder sub (if existent) via lmtp. Target system is cyrus-imapd. We have these routers: global_aliases: driver = redirect allow_defer allow_fail data =

Re: [exim] licensing and SPDX

2022-11-02 Thread Andrew C Aitchison via Exim-users
On Mon, 31 Oct 2022, Heiko Schlittermann via Exim-users wrote: From a legal point of view (but IANAL by any means), we probably could find an SPDX identifier matching the *current* license statement of each individual file, to match the *current* intent. This implicates that the *current*

Re: [exim] Exim MariaDB and SSL

2022-11-02 Thread Andrew C Aitchison via Exim-users
On Wed, 2 Nov 2022, Brent Clark via Exim-users wrote: On 2022/11/01 13:06, Heiko Schlittermann via Exim-users wrote: ::()[group>]/// (I missed the related function call in Exim's sources.) So having TLS options in one of the my.cnf should work. Maybe you used the wrong option group (as JGH

Re: [exim] Broken pipe > MYSQL: no data found

2022-10-25 Thread Andrew C Aitchison via Exim-users
On Tue, 25 Oct 2022, Jeremy Harris via Exim-users wrote: On 25/10/2022 09:10, Cyborg via Exim-users wrote: 2022-10-25 07:36:45 1onCcF-002IAu-0b malware acl condition: clamd  : unable to send file body to socket (83.x.x.x): Broken pipe That "broken pipe" is from the "malware" ACL condition

Re: [exim] raw mime_filename

2022-10-14 Thread Andrew C Aitchison via Exim-users
On Fri, 14 Oct 2022, Mikhail Golub via Exim-users wrote: One more example. In letter: Content-Description: =?windows-1251?B?wvXu5F/C+/Xu5C54bHN4?= In $mime_content_description: =?windows-1251?b?wvxu5f/c+/xu5c54bhn4?= Compare it: =?windows-1251?B?wvXu5F/C+/Xu5C54bHN4?=

Re: [exim] GnuTTS woes

2022-09-29 Thread Andrew C Aitchison via Exim-users
On Fri, 30 Sep 2022, Jasen Betts via Exim-users wrote: On 2022-09-30, Viktor Dukhovni via Exim-users wrote: On Fri, Sep 30, 2022 at 01:21:21AM -, Jasen Betts via Exim-users wrote: With the older Exim, GnuTLS appears to consider six cipher suites before finding a suitable choice (after

Re: [exim] Setting Exim to always remove DKIM signatures

2022-09-29 Thread Andrew C Aitchison via Exim-users
On Thu, 29 Sep 2022, Johnnie W Adams via Exim-users wrote: Well, it's a moral victory. I did get the acl to do what I wanted and give me only the final DKIM signature. No go. Then I turned back on the LISTSERV DKIM service so I'd get a LISTSERV signature +followed+ by an SMTP signature. That

[exim] MacOS development was Re: After upgrade to Exim 4.95 or 4.96: "setgroups: Invalid argument"

2022-09-28 Thread Andrew C Aitchison via Exim-users
On Tue, 20 Sep 2022, Martin D Kealey via Exim-users wrote: Lasse Törngren wrote: I am using a couple of Macs as servers, and has one server running MacOS Mojave and Exim 4.94 without any issue. I have tried to upgrade to Exim 4.95 on this machine, and to Exim 4.96 on a new server that I am

Re: [exim] Problem sending to google.com

2022-09-28 Thread Andrew C Aitchison via Exim-users
On Wed, 28 Sep 2022, Victor Sudakov via Exim-users wrote: Dear Colleagues, Has anyone had problems recently sending to aspmx.l.google.com ? Yes. This is a known issue https://bugs.exim.org/show_bug.cgi?id=2907 The bug is not actually in exim, but in Linux kernel TCP Fast Open code

Re: [exim] problem Tainted permission to file autoreply once

2022-09-27 Thread Andrew C Aitchison via Exim-users
On Mon, 26 Sep 2022, Sławomir Dworaczek via Exim-users wrote: I wanted to limit the reflection of mail with the autoresponder turned on, but after adding the option ONCE_FILE = /var/spool/exim/db/autoreply_${local_part}_${domain}.db What happens if you change that to ONCE_FILE =

Re: [exim] After upgrade to Exim 4.95 or 4.96: "setgroups: Invalid argument"

2022-09-22 Thread Andrew C Aitchison via Exim-users
On Thu, 22 Sep 2022, Lasse Törngren via Exim-users wrote: Hello again Andrew, Thanks for the new patch. Sorry to hear about the family emergency. I hope it will turn out well. After applying your second patch, I get a slightly different error message (I think this is the last line I put in

Re: [exim] After upgrade to Exim 4.95 or 4.96: "setgroups: Invalid argument"

2022-09-22 Thread Andrew C Aitchison via Exim-users
On Thu, 22 Sep 2022, Lasse Törngren via Exim-users wrote: Hello Andrew, Thank you for your feedback, your commitment and the patch. When applying your patch, the compilation gets through without any error. After rebooting and trying this version of Exim 4.96 I get a new error though: It

Re: [exim] After upgrade to Exim 4.95 or 4.96: "setgroups: Invalid argument"

2022-09-22 Thread Andrew C Aitchison via Exim-users
On Wed, 21 Sep 2022, Lasse Törngren via Exim-users wrote: Hello Martin, I tried your patching of the code and I am getting this error: The changed code in priv.c: if (priv_euid == root_uid)   {   if (seteuid(priv_euid) != 0)     log_write(0, LOG_PANIC_DIE, "seteuid(%d): %s", priv_euid,

Re: [exim] After upgrade to Exim 4.95 or 4.96: "setgroups: Invalid argument"

2022-09-20 Thread Andrew C Aitchison via Exim-users
On Wed, 21 Sep 2022, Lasse Törngren via Exim-users wrote: Hello Bill, Many thanks for the input. It's beyond my skill level, but you absolutely point to where I can start digging. One thing that might be useful is to change the lines log_write(0, LOG_PANIC_DIE, "setgroups: %s",

Re: [exim] Exim 4.96 compile fails on Devuan 4

2022-09-13 Thread Andrew C Aitchison via Exim-users
On Mon, 12 Sep 2022, Victor Ustugov via Exim-users wrote: Mike Tubby via Exim-users wrote on 12.09.2022 00:27: Compiling Exim 4.96 fails on Devuan 4.0 Chimaera (basically Debian but without systemd). Try to install libpcre2-dev From Mike's original email: and installed the bits I

Re: [exim] Exim 4.96 compile fails on Devuan 4

2022-09-12 Thread Andrew C Aitchison via Exim-users
On Sun, 11 Sep 2022, Mike Tubby via Exim-users wrote: On 11/09/2022 22:15, Andrew C Aitchison via Exim-users wrote: On Sun, 11 Sep 2022, Mike Tubby via Exim-users wrote: Hi all, Compiling Exim 4.96 fails on Devuan 4.0 Chimaera (basically Debian but without systemd). Firstly it complained

Re: [exim] Exim 4.96 compile fails on Devuan 4

2022-09-11 Thread Andrew C Aitchison via Exim-users
On Sun, 11 Sep 2022, Mike Tubby via Exim-users wrote: Hi all, Compiling Exim 4.96 fails on Devuan 4.0 Chimaera (basically Debian but without systemd). Firstly it complained that I didn't have "pcre2.h" - which it has never asked for before:     /bin/sh ../scripts/Configure-os.h     cc

Re: [exim] How to enable smtp verify in exim4?

2022-09-01 Thread Andrew C Aitchison via Exim-users
On Thu, 1 Sep 2022, 吴栋淦 via Exim-users wrote: Hi, I am new to exim4,and I want to build a exim4 server with VRFY command supported.But I don't know how to enable smtp verify in quickly way.Any sugguestions should be appriciated! Read doc.spec.txt 56.8 The VRFY, EXPN, and ETRN commands in

Re: [exim] CVE-2022-37452

2022-08-24 Thread Andrew C Aitchison via Exim-users
On Wed, 24 Aug 2022, Cyborg via Exim-users wrote: Am 24.08.22 um 18:14 schrieb Jeremy Harris via Exim-users: On 24/08/2022 16:45, Ken Olum via Exim-users wrote: How serious is CVE-2022-37452: buffer overflow for the alias list in host_name_lookup? The associated bug, 2747, reported it as a

Re: [exim] Does exim4's `${sqlite_quote ... }` expansion de-taint the expanded value?

2022-08-19 Thread Andrew C Aitchison via Exim-users
On Fri, 19 Aug 2022, Andrew C Aitchison via Exim-users wrote: On Fri, 19 Aug 2022, Nick via Exim-users wrote: Hello Exim users, I've a problem with Sqlite lookups and tainting. I've composed a question on Stack Exchange, since it's easier to access than this list (and I forgot i

Re: [exim] Does exim4's `${sqlite_quote ... }` expansion de-taint the expanded value?

2022-08-19 Thread Andrew C Aitchison via Exim-users
On Fri, 19 Aug 2022, Nick via Exim-users wrote: Hello Exim users, I've a problem with Sqlite lookups and tainting. I've composed a question on Stack Exchange, since it's easier to access than this list (and I forgot i was already subscribed here long ago!)

Re: [exim] Some Emails to gmail now hang

2022-08-11 Thread Andrew C Aitchison via Exim-users
On Wed, 10 Aug 2022, Viktor Dukhovni via Exim-users wrote: On Wed, Aug 10, 2022 at 04:00:51PM -0700, Marc MERLIN wrote: I've also reached out to the Gmail team. They're aware. Which is not to say that there's a quick fix in the works, the front-end connection termination devices are both

Re: [exim] Some Emails to gmail now hang

2022-08-10 Thread Andrew C Aitchison via Exim-users
On Wed, 10 Aug 2022, Marc MERLIN via Exim-users wrote: On Wed, Aug 10, 2022 at 06:29:47PM +0100, Jeremy Harris via Exim-users wrote: That's extremwly weird. I can't see a logical connection between the TCP startup detail and a problem that late in the SMTP conversation. That was my thought

Re: [exim] Problems with rewriting a domain

2022-08-10 Thread Andrew C Aitchison via Exim-users
On Wed, 10 Aug 2022, Olaf Hopp (SCC) via Exim-users wrote: On 8/9/22 17:54, Andrew C Aitchison wrote: On Tue, 9 Aug 2022, Olaf Hopp (SCC) via Exim-users wrote: [...] You have: ^(.*)@(.*)\.olddomain\.org $1@$2.newdomain.org TS The examples suggest that: *@*olddomain.org

Re: [exim] Problems with rewriting a domain

2022-08-09 Thread Andrew C Aitchison via Exim-users
On Tue, 9 Aug 2022, Olaf Hopp (SCC) via Exim-users wrote: Dear collegues, we moved some internal domains from "olddomain.org" to "newdomain.org" we have internal routing for the new and old domain Now we want to get rid of the routing for "olddomain.org" and I want to rewrite "olddomain.org" to

Re: [exim] 4.96 simplegreylist taint

2022-08-04 Thread Andrew C Aitchison via Exim-users
On Thu, 4 Aug 2022, jacob dahl pind via Exim-users wrote: using the example at https://github.com/Exim/exim/wiki/SimpleGreylisting with 4.96 the following line throws an error set acl_m_dontcare = ${lookup sqlite {INSERT INTO greylist \VALUES ( '$acl_m_greyident', \

Re: [exim] Tainted arg 2 for mailman_transport transport command

2022-07-21 Thread Andrew C Aitchison via Exim-users
On Thu, 21 Jul 2022, Jeremy Harris via Exim-users wrote: On 21/07/2022 07:27, Thomas Krichel via Exim-users wrote: 2022-07-21 06:19:30 1oEPWy-002t7O-0x == nep-t...@lists.repec.org R=mailman_router T=mailman_transport defer (0): Expansion of

Re: [exim] Tainted arg 2 for mailman_transport transport command

2022-07-20 Thread Andrew C Aitchison via Exim-users
Argh. Still wrong. Is ${sg{sg{$MM_LISTCHK}{\/config.pck$}{}}{.*\/}{}} a better replacement for $local_part ? On Wed, 20 Jul 2022, Andrew C Aitchison wrote: On Wed, 20 Jul 2022, Andrew C Aitchison via Exim-users wrote: On Wed, 20 Jul 2022, Thomas Krichel via Exim-users wrote: root

Re: [exim] Tainted arg 2 for mailman_transport transport command

2022-07-20 Thread Andrew C Aitchison via Exim-users
On Wed, 20 Jul 2022, Andrew C Aitchison via Exim-users wrote: On Wed, 20 Jul 2022, Thomas Krichel via Exim-users wrote: root@darni /etc/exim4 # cat ./conf.d/transport/14_exim4-config_mailman mailman_transport: driver = pipe command = MM_WRAP \ '${if def:local_part_suffix

Re: [exim] Tainted arg 2 for mailman_transport transport command

2022-07-20 Thread Andrew C Aitchison via Exim-users
On Wed, 20 Jul 2022, Thomas Krichel via Exim-users wrote: I've been running Mailman with exim4 for about 20 years now! Yesterday, I upgraded my Debian to exim 4.96-3. Then I got hit by this mailman problem. Log entry | 2022-07-20 11:43:44 1oE87D-007hOf-2N **

Re: [exim] Eximfilter rule delivery

2022-07-18 Thread Andrew C Aitchison via Exim-users
On Mon, 18 Jul 2022, Sławomir Dworaczek via Exim-users wrote: tries to make a rule to bypass the filtering of specific messages containing $ h_X-Bogosity: MATCH "Spam" to deliver messages to recipients follow my rule. what should I put for "deliver ??" if $h_X-Bogosity: MATCH

Re: [exim] drop connection on auth failure

2022-07-16 Thread Andrew C Aitchison via Exim-users
On Fri, 15 Jul 2022, Julian Bradfield via Exim-users wrote: I should like exim to drop the connection on a client AUTH failure. (Because as soon it's seen in the log, fail2ban will DROP the client IP, and so the exim process will hang around until the SMTP session times out.) I haven't used

Re: [exim] Closing off Port to non-SSL traffic

2022-06-26 Thread Andrew C Aitchison via Exim-users
On Sun, 26 Jun 2022, Mark Elkins via Exim-users wrote: Seems I need to do more learning On 6/26/22 9:19 AM, Andrew C Aitchison via Exim-users wrote: On Sat, 25 Jun 2022, Mark Elkins via Exim-users wrote: Not sure if I'm missing the boat or what but - for one of my users to send email

Re: [exim] Closing off Port to non-SSL traffic

2022-06-26 Thread Andrew C Aitchison via Exim-users
On Sat, 25 Jun 2022, Mark Elkins via Exim-users wrote: Not sure if I'm missing the boat or what but - for one of my users to send email - they must use mail Submission port 587 - and nothing else. That's on a server that only listens on port 587. This works fine until a user "shares" their

Re: [exim] google bounce messages

2022-06-22 Thread Andrew C Aitchison via Exim-users
On Wed, 22 Jun 2022, Robert Steinmetz via Exim-users wrote: I'm getting some messages bounced from google with the following message host aspmx.l.google.com [2607:f8b0:4002:c08::1a] SMTP error from remote mail server after pipelined end of data: 550-5.7.1

Re: [exim] Additional line in body when submitting?

2022-06-02 Thread Andrew C Aitchison via Exim-users
On Thu, 2 Jun 2022, Kamil Jońca via Exim-users wrote: Jeremy Harris via Exim-users writes: Doh. I am so stupid. I finally looked at the docs for the pipe transport, and there is the answer staring at me. === message_suffix Use: pipe Type: string† Default:

Re: [exim] Additional line in body when submitting?

2022-05-31 Thread Andrew C Aitchison via Exim-users
On Tue, 31 May 2022, Kamil Jońca via Exim-users wrote: I have some instances, which generates mail from stdin (ie something like "echo bla|mail root") and recently I found that there exists additional empty line in such emails, ie instead of --8<---cut

Re: [exim] stopping spam with forged from:

2022-05-25 Thread Andrew C Aitchison via Exim-users
On Wed, 25 May 2022, Evgeniy Berdnikov via Exim-users wrote: Valid mail with ( From == To || From in To || From in CC ) can be relayed from external, by manual redirection or automatical forward. ... or mailing lists that don't rewrite From: -- Andrew C. Aitchison

Re: [exim] The No Certificate Warning and the Right Way to Stop it

2022-05-16 Thread Andrew C Aitchison via Exim-users
On Mon, 16 May 2022, Martin McCormick via Exim-users wrote: Jeremy Harris via Exim-users writes: What is the output of "exim4 -bP tls_certificate tls_privatekey" ? This is a followup to that question. As I previously reported, neither of those variables are set even though I went through

Re: [exim] Outgoing From header field format

2022-05-13 Thread Andrew C Aitchison via Exim-users
On Thu, 12 May 2022, AC via Exim-users wrote: What configuration within exim defines how the outbound From header is formatted? What I mean is whether the header has just an email: u...@example.com vs. a name and email in brackets: A User I'm asking because I have several machines that

Re: [exim] exim-4.96RC0 - broken Mailman (2.x)

2022-05-06 Thread Andrew C Aitchison via Exim-users
On Fri, 6 May 2022, Michael Haardt via Exim-users wrote: Odhiambo Washington via Exim-users wrote: I must admit I have zero clue how to detaint this: LOG: MAIN ** mail...@lists.mydomain.name R=mailman_router T=mailman_transport: Tainted arg 1 for mailman_transport transport command:

Re: [exim] exim-4.96RC0 - broken Mailman (2.x)

2022-05-06 Thread Andrew C Aitchison via Exim-users
On Fri, 6 May 2022, Odhiambo Washington via Exim-users wrote: I must admit I have zero clue how to detaint this: LOG: MAIN ** mail...@lists.mydomain.name R=mailman_router T=mailman_transport: Tainted arg 1 for mailman_transport transport command: 'bounces' mailman_router: driver

[exim] Taint checking and exim 4.96rc0

2022-04-29 Thread Andrew C Aitchison via Exim-users
On Mon, 25 Apr 2022, Kirill Miazine via Exim-dev wrote: Beware that the just released RC0 for Exim 4.96 may break your Dovecot LDA delivery. It did break mine, which is similar to what is described on https://wiki.dovecot.org/LDA/Exim Here is the relevant ChangeLog entry: JH/25 Taint-check

Re: [exim] 2 hours delay (gnutls_handshake): timed out: delivering unencrypted to

2022-04-24 Thread Andrew C Aitchison via Exim-users
von Andrew C Aitchison via Exim-users Gesendet: Donnerstag, 31. März 2022 12:35 An: tt-admin Cc: exim-users@exim.org Betreff: Re: [exim] 2 hours delay (gnutls_handshake): timed out: delivering unencrypted to On Thu, 31 Mar 2022, tt-admin via Exim-users wrote: exiwhat says: waiting for a remote

Re: [exim] 2 hours delay (gnutls_handshake): timed out: delivering unencrypted to

2022-04-07 Thread Andrew C Aitchison via Exim-users
On Thu, 7 Apr 2022, tt-admin via Exim-users wrote: Ah. If it is a mail gateway, the question might be whether their gateway starts to send the message on to their mail server (cut-through delivery) or not. Does the Symantec Messaging Gateway advertise PIPELINING and do you use it ? Yes,

Re: [exim] 2 hours delay (gnutls_handshake): timed out: delivering unencrypted to

2022-03-31 Thread Andrew C Aitchison via Exim-users
On Thu, 31 Mar 2022, tt-admin via Exim-users wrote: exiwhat says: waiting for a remote delivery subprocess to finish started a new strace with longer lines (-s 256) and date column. I will try to contact the remote administrator, but my hopes for a trace from their side are low (Symantec

Re: [exim] 2 hours delay (gnutls_handshake): timed out: delivering unencrypted to

2022-03-30 Thread Andrew C Aitchison via Exim-users
On Wed, 30 Mar 2022, tt-admin via Exim-users wrote: Does exigrep 1nWC1t-0001kn-G2 /var/log/exim4/mainlog-202203* (or where ever your exim logs are) show anything for the "other process" ? I'm afraid not, here you see two logs from yesterday (complete exigrep output without sensitive

Re: [exim] 2 hours delay (gnutls_handshake): timed out: delivering unencrypted to

2022-03-29 Thread Andrew C Aitchison via Exim-users
On Tue, 22 Mar 2022, tt-admin via Exim-users wrote: Hi all, got a sending e-mail relay here, Ubuntu 18.04 LTS. About 22k e-mails sending volume per day. There are two receiving e-mail servers that are experiencing delays (~2 hours) when receiving e-mails from us. This does not happen for every

Re: [exim] stuck exim processes

2022-03-18 Thread Andrew C Aitchison via Exim-users
On Fri, 18 Mar 2022, Patrik Peng via Exim-users wrote: On 17.03.22 21:20, Jeremy Harris via Exim-users wrote: Being certain would be better. Indeed. To be sure we created a new build based on the portstree + the following changes: -

Re: [exim] stuck exim processes

2022-03-09 Thread Andrew C Aitchison via Exim-users
On Wed, 9 Mar 2022, Patrik Peng via Exim-users wrote: On 08.03.22 14:47, Jeremy Harris via Exim-users wrote: There was an entire thread in the mailing list. Hi Jeremy You mean the one i just replied? Yes I did follow it, but apart from the solution with `hosts_avoid_tls` I didn't see any

Re: [exim] Truncated warning messages (again)

2022-02-19 Thread Andrew C Aitchison via Exim-users
On Sat, 19 Feb 2022, Christian Balzer via Exim-users wrote: On Fri, 18 Feb 2022 10:58:35 + (GMT) Andrew C Aitchison via Exim-users wrote: On Fri, 18 Feb 2022, Christian Balzer via Exim-users wrote: On Thu, 17 Feb 2022 11:25:01 + Jeremy Harris via Exim-users wrote: On 17/02/2022 05

Re: [exim] Truncated warning messages (again)

2022-02-18 Thread Andrew C Aitchison via Exim-users
On Fri, 18 Feb 2022, Christian Balzer via Exim-users wrote: On Thu, 17 Feb 2022 11:25:01 + Jeremy Harris via Exim-users wrote: On 17/02/2022 05:04, Christian Balzer via Exim-users wrote: Maybe phrasing here, but clearly the previous behavior of displaying the full response of the remote

Re: [exim] exim maildirsize quota calculation in the face of symlinks

2022-02-10 Thread Andrew C Aitchison via Exim-users
On Thu, 10 Feb 2022, Jasen Betts via Exim-users wrote: On 2022-02-10, Maarten van Baarsel via Exim-users wrote: Currently, I'm also using a plugin in dovecot: https://wiki.dovecot.org/Plugins/MailboxAlias However, this plugin solves the alias problem with a symlink in the Maildir directory,

Re: [exim] Running our own email server on GCP

2022-01-29 Thread Andrew C Aitchison via Exim-users
On Sat, 29 Jan 2022, Terrance Devor via Exim-users wrote: Hello Heiko, It was posted here https://cloud.google.com/compute/docs/tutorials/sending-mail/ I would really like to deploy a containerized EXIM using docker to GCP to manage sending email, and also a POP3 server such as dovecot to

Re: [exim] [Transport error]: message has lines too long for transport

2022-01-29 Thread Andrew C Aitchison via Exim-users
On Fri, 28 Jan 2022, Bill Cole via Exim-users wrote: On 2022-01-27 at 14:31:41 UTC-0500 (Thu, 27 Jan 2022 19:31:41 + (GMT)) Andrew C Aitchison via Exim-users is rumored to have said: On Thu, 27 Jan 2022, Marcin Gryszkalis via Exim-users wrote: [...] - What do you think about

Re: [exim] [Transport error]: message has lines too long for transport

2022-01-27 Thread Andrew C Aitchison via Exim-users
On Thu, 27 Jan 2022, Marcin Gryszkalis via Exim-users wrote: On 18.11.2021 21:00, Jeremy Harris via Exim-users wrote:> On 18/11/2021 10:35, Andrea Biscuola via Exim-users wrote: is. From what I was able to understand, we should modify the remote_smtp and remote_smtp_forward_transport sections

Re: [exim] Inap^Pp^Propriate File Type or Format

2022-01-21 Thread Andrew C Aitchison via Exim-users
On Fri, 21 Jan 2022, Cyborg via Exim-users wrote: Am 20.01.22 um 22:52 schrieb Jeremy Harris via Exim-users: On 20/01/2022 18:45, Pete Long via Exim-users wrote: failed to open DB file /var/spool/exim/db/wait-remote_smtp: Inappropriate file type or format You have a corrupt DB file, or one

Re: [exim] sendind email to an intermittently connected host

2022-01-17 Thread Andrew C Aitchison via Exim-users
On Mon, 17 Jan 2022, Leonardo Boselli via Exim-users wrote: I have two hosts a.example.com and p.example.com . mail for example com arrive to A, but for some users is forwarded to u...@p.example.com . Nothing special until here, you do with a procmail option at user level. The problem is that

Re: [exim] converting from debian package to source

2022-01-08 Thread Andrew C Aitchison via Exim-users
On Sat, 8 Jan 2022, Julian Bradfield via Exim-users wrote: On 2022-01-08, Andreas Barth via Exim-users wrote: * Julian Bradfield via Exim-users (exim-users@exim.org) [220108 15:18]: The pain of dealing with Debian's antiquated versions (4.92) and gratuitous messing around with upstream's

Re: [exim] problem with mails in queue while config changes routers

2021-12-29 Thread Andrew C Aitchison via Exim-users
On Wed, 29 Dec 2021, Jeremy Harris via Exim-users wrote: On 29/12/2021 09:45, Cyborg via Exim-users wrote: It was about changing environments while in queue. There's two parts to this. 1) (The bit Evgeny spoke to): Once a message is frozen, that frozen state is on the message in the

[exim] GMail and TCP Fast Open

2021-12-03 Thread Andrew C Aitchison via Exim-users
I am just passing on, with permission, something exim related from the mai...@mailop.org list. https://list.mailop.org/private/mailop/2021-December/020647.html On 02/12/2021 12:50, Andrew Hearn via mailop wrote: Hello, We're a UK ISP, and relay email for our customers as well as send our

Re: [exim] ouauth2 and sendmail

2021-11-12 Thread Andrew C Aitchison via Exim-users
On Fri, 12 Nov 2021, Martin McCormick via Exim-users wrote: I currently use my ISP's email gateway as a smarthost so exim4 is configured this way which is how you are able to read this message. I authenticate using a secret password and ssl which all works right now but I found out I

Re: [exim] Exim4 delay at boot

2021-11-10 Thread Andrew C Aitchison via Exim-users
On Mon, 8 Nov 2021, JHM via Exim-users wrote: Hello: My box runs Devuan Beowulf and within it runs a (VBox) Devuan ascii virtual machine set up to start up automatically when I boot. It is not kept on 24/07 but is booted up a few times every 24 hours. The Devuan ascii virtual machine runs

Re: [exim] Add disclaimer message to all incoming emails

2021-11-01 Thread Andrew C Aitchison via Exim-users
[ Reformatted to top-posting for consistency. ] I guess he wants to make it obvious that it is an *external* message, thus "not as trustworthy" and to remind people not to put trade secrets in any reply.. On Mon, 1 Nov 2021, Odhiambo Washington via Exim-users wrote: Why would you want to

Re: [exim] GnuTLS vs OpenSSL

2021-09-20 Thread Andrew C Aitchison via Exim-users
On Mon, 20 Sep 2021, Viktor Dukhovni via Exim-users wrote: On Mon, 20 Sep 2021 "Thomas" wrote: Any site, that does not support at least TLS 1.2 is running absolutely outdated software. GnuTLS handshake errors are logged very few times (<<1% of the messages), I suppose that enabling TLS1.1 and

Re: [exim] GnuTLS vs OpenSSL

2021-09-18 Thread Andrew C Aitchison via Exim-users
On Sat, 18 Sep 2021, exim-us...@thomas.freit.ag via Exim-users wrote: I use testssl.sh (https://testssl.sh/) to verify my configuration (as there is nothing handy like the Qualys Test for HTTPS, IMHO). Hardenize https://www.hardenize.com/ is not bad. Testing robust (perfect) forward

Re: [exim] exim can't handle 521 response from remote MX

2021-09-04 Thread Andrew C Aitchison via Exim-users
On Sat, 4 Sep 2021, Viktor Dukhovni via Exim-users wrote: On Sat, Sep 04, 2021 at 01:18:17PM -0400, John C Klensin wrote: Absent a time-machine, and given that the ultimate decision is made after the initial banner and greet pause, and that refusing SMTP service (521 banner) is supposed to

Re: [exim] Receive Mail From a Secondary-MX Proxy

2021-08-29 Thread Andrew C Aitchison via Exim-users
On Wed, 25 Aug 2021, Sabahattin Gucukoglu via Exim-users wrote: What about if I extent this setup so that my mailer machine only makes outbound connections to the proxy host—can I still receive inbound mail, through a forwarded port perhaps? SSH seems like the obvious answer, but then I’d lose

Re: [exim] backup servers and self-pointing MX

2021-07-20 Thread Andrew C Aitchison via Exim-users
On Mon, 19 Jul 2021, Julian Bradfield via Exim-users wrote: I'm not sure of how to achieve the following aim. My setup is that I have two mail servers, call them FIRST and SECOND. Their exim configurations are almost identical, with one difference conditioned upon the presence of

Re: [exim] backup servers and self-pointing MX

2021-07-19 Thread Andrew C Aitchison via Exim-users
On Mon, 19 Jul 2021, Julian Bradfield via Exim-users wrote: I'm not sure of how to achieve the following aim. My setup is that I have two mail servers, call them FIRST and SECOND. Their exim configurations are almost identical, with one difference conditioned upon the presence of

Re: [exim] Strange problem with the communication to ClamAV

2021-07-12 Thread Andrew C Aitchison via Exim-users
On Mon, 12 Jul 2021, Luca Bertoncello via Exim-users wrote: Am 09.07.2021 12:53, schrieb Heiko Schlittermann via Exim-users: Hi Heiko, Do these issues have correlation to the freshclam triggered clamav reloads? Yesterday happens the problem again, using ClamAV with TCP instead of

Re: [exim] Exim in systemd system (queue mode)

2021-07-08 Thread Andrew C Aitchison via Exim-users
On Fri, 2 Jul 2021, michael--- via Exim-users wrote: In a backup script for SysV init system I used to: 1. stop exim MTA, /etc/init.d/exim stop 2. run exim in queue-only mode: /etc/init.d/exim queue 3. stop imap MDA. 4. option: enable file-system snapshot feature 5. create backup of locally

Re: [exim] too long line but which one?

2021-06-30 Thread Andrew C Aitchison via Exim-users
On Wed, 30 Jun 2021, Arkadiusz Miśkiewicz via Exim-users wrote: Hi, how to log that too long line(s), so it will be easy to point where the problem is in case of mail incoming via smtp ? deny message = maximum allowed line length is 998 octets, \ got

Re: [exim] Perl integration - context?

2021-06-10 Thread Andrew C Aitchison via Exim-users
On Thu, 10 Jun 2021, Felipe Gasper via Exim-users wrote: On Jun 10, 2021, at 00:52, Andrew C Aitchison wrote: On Wed, 9 Jun 2021, Felipe Gasper via Exim-users wrote: The idea is more to prevent message delivery during a backup or account reconfiguration. exim_lock is the tool you are

  1   2   >