Re: A question about the instance attribute in policy delegation

2009-06-26 Thread Victor Duchovni
On Thu, Jun 25, 2009 at 11:40:32PM -0700, Rob Tanner wrote: > On 6/25/09 10:16 PM, "Victor Duchovni" > wrote: > > > On Thu, Jun 25, 2009 at 10:36:09PM -0400, Sahil Tandon wrote: > > > >>> IIRC, the instance attribute identifies a mail transaction and is assigned > >>> before the queue-id. > >>

Re: Postfix Logfile

2009-06-26 Thread Ralf Hildebrandt
* Schwalbe, Oliver : > i have a little problem to change time of logswitch for the > postfix-logfile mail in /var/log/. the logswitch yet is every day at > 11:00 am. The switch should take place at midnight. i can't find any > parameter in main.cf or master.cf That's because postfix doesn't rota

Log Stats

2009-06-26 Thread Steve
Hi List, Before I make a feeble attempt to reinvent the wheel with a custom log parser, can anyone recommend a log file analyser which could output a single line summary of every connection be it allowed or blocked? Ideally I would like to be able to format the output for html. Really I'm asking

Re: Log Stats

2009-06-26 Thread Justin C. Le Grice
Steve wrote: Hi List, Before I make a feeble attempt to reinvent the wheel with a custom log parser, can anyone recommend a log file analyser which could output a single line summary of every connection be it allowed or blocked? Ideally I would like to be able to format the output for html. Rea

Sending mails via SMTP after SASL authentication not possible

2009-06-26 Thread konstantin-mail
Hallo! My postfix receives mails but I can not send mails via SMTP. This is a part of my log file: Jun 24 20:49:48 serverxyz postfix/smtpd[30748]: connect from -123456.pool.mediaWays.net[xx.xx.xx.xx] Jun 24 20:49:48 serverxyz authdaemond: received auth request, service=smtp, authtype=login

Re: Sending mails via SMTP after SASL authentication not possible

2009-06-26 Thread Michael Tokarev
konstantin-m...@gmx.de wrote: Hallo! My postfix receives mails but I can not send mails via SMTP. This is a part of my log file: [] Jun 24 20:49:48 serverxyz postfix/smtpd[30748]: NOQUEUE: reject: \ RCPT from -123456.pool.mediaWays.net[xx.xx.xx.xx]: \ 550 5.1.1 : Recipient address rej

Re: Sending mails via SMTP after SASL authentication not possible

2009-06-26 Thread konstantin-mail
I'm not sure, what do you want to say me with your mail. The desired behavior is the following: - postfix accepts mails whose domain is in virtual_mailbox_domains (mysql db) and stores them in the maildir (works). - courier-imap shows mails after authetication via authdaemond (works). - postfix

ISP being blocked by us

2009-06-26 Thread Ignacio Garcia
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi there. We use in our postfix servers several programs to prevent spam (amavisd-new + spamassassin, postgrey, and policyd-weight). We like very much policyd-weight because it bases its blocking decissions on a score calculated by the number of blackl

Re: ISP being blocked by us

2009-06-26 Thread José Luis Tallón
Hi, Ignacio Garcia wrote: > Hi there. We use in our postfix servers several programs to prevent spam > (amavisd-new + spamassassin, postgrey, and policyd-weight). We like very > much policyd-weight because it bases its blocking decissions on a score > calculated by the number of blacklists a serve

Re: ISP being blocked by us

2009-06-26 Thread Jan P. Kessler
Ignacio Garcia schrieb: > FROM/MX_MATCHES_NOT_HELO(DOMAIN)=2.9 The helo_name (IMPaqm2.telefonica.net) did not match the sender_domain (terra.es) nor the mx (mx.terra.es). > CLIENT_NOT_MX/A_FROM_DOMAIN=9.1 The client_name (IMPaqm2.telefonica.net) did not match the sender_domain (terra.es) nor the

Re: ISP being blocked by us

2009-06-26 Thread Jan P. Kessler
José Luis Tallón schrieb: > > What we do (without policyd-weight, however): > > Redirect these "problematic domains" to a special restriction class (we > call it from_freemail) > Then, we match the sending server with *any* valid sending server for > that domain. > > Something along the lines: > AC

Re: Header Time

2009-06-26 Thread Linux Addict
On Thu, Jun 25, 2009 at 10:18 PM, Linux Addict wrote: > > > On Thu, Jun 25, 2009 at 5:11 PM, Blake Hudson wrote: > >> >> Original Message >> Subject: Re: Header Time >> From: Linux Addict >> >> >>> I dont think this is something to do with outlook as I tested with yahoo >>> an

Re: ISP being blocked by us

2009-06-26 Thread Jorey Bump
Ignacio Garcia wrote, at 06/26/2009 08:38 AM: > FROM/MX_MATCHES_NOT_HELO(DOMAIN)=2.9 CLIENT_NOT_MX/A_FROM_DOMAIN=9.1 Both of these rules are absurd. An MX record is only relevant when determining the destination for a domain's email. It has *nothing* to do with relaying to other sites. You should

Re: Sending mails via SMTP after SASL authentication not possible

2009-06-26 Thread Noel Jones
konstantin-m...@gmx.de wrote: Hallo! My postfix receives mails but I can not send mails via SMTP. This is a part of my log file: Jun 24 20:49:48 serverxyz postfix/smtpd[30748]: NOQUEUE: reject: RCPT from -123456.pool.mediaWays.net[xx.xx.xx.xx]: 550 5.1.1 : Recipient address rejected: Use

Re: ISP being blocked by us

2009-06-26 Thread Ignacio Garcia
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 José Luis Tallón escribió: > Hi, > > Ignacio Garcia wrote: >> Hi there. We use in our postfix servers several programs to prevent spam >> (amavisd-new + spamassassin, postgrey, and policyd-weight). We like very >> much policyd-weight because it bases

Re: Sending mails via SMTP after SASL authentication not possible

2009-06-26 Thread konstantin-mail
> Postfix thinks web.de is a virtual_mailbox_domain. This has > nothing to do with SASL. > The SASL configuration looks correct, but your > virtual_mailbox_domains table is matching web.de. Yes! Thank you very much! This was the problem! I've thought, virtual_mailbox_domain must contain all

Re: Log Stats

2009-06-26 Thread Jiří Hlinka
Hi, beside pflogsumm there is postfix-logwatch and amavis-logwatch: http://www.mikecappella.com/logwatch/ Jiri Steve napsal(a): > Hi List, > > Before I make a feeble attempt to reinvent the wheel with a custom log > parser, can anyone recommend a log file analyser which could output a > single li

Re: ISP being blocked by us

2009-06-26 Thread Ignacio Garcia
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Jorey Bump escribió: > Ignacio Garcia wrote, at 06/26/2009 08:38 AM: > >> FROM/MX_MATCHES_NOT_HELO(DOMAIN)=2.9 CLIENT_NOT_MX/A_FROM_DOMAIN=9.1 > > Both of these rules are absurd. An MX record is only relevant when > determining the destination for a

trouble with ldaps in ldap lookup map

2009-06-26 Thread btb
(apologies if i'm reposting this. i forget i hadn't resubscribed before sending initially) hi- i'm having some trouble using ldaps in a lookup map for virtual_mailbox_domains (among others). here's my lookup map: >cat virtual_mailbox_domains.cf version = 3 tls_ca_cert_file = /etc/ssl/certs

Re: Log Stats

2009-06-26 Thread EASY steve.h...@digitalcertainty.co.uk
On Fri, 2009-06-26 at 17:28 +0200, Jiří Hlinka wrote: > Hi, > beside pflogsumm there is postfix-logwatch and amavis-logwatch: > http://www.mikecappella.com/logwatch/ > > Jiri > > Steve napsal(a): > > Hi List, > > > > Before I make a feeble attempt to reinvent the wheel with a custom log > > parse

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 11:50:12AM -0400, btb wrote: > >cat virtual_mailbox_domains.cf > version = 3 > tls_ca_cert_file = /etc/ssl/certs/ca-certificates.crt > server_host = ldaps://ldap.example.com > bind_dn = cn=postfix,ou=services,ou=accounts,dc=example,dc=com > bind_pw = xx > search

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread btb
Victor Duchovni wrote: On Fri, Jun 26, 2009 at 11:50:12AM -0400, btb wrote: cat virtual_mailbox_domains.cf version = 3 tls_ca_cert_file = /etc/ssl/certs/ca-certificates.crt server_host = ldaps://ldap.example.com bind_dn = cn=postfix,ou=services,ou=accounts,dc=example,dc=com bind_pw = x

Re: Message with 300,000+ recips via alias_maps

2009-06-26 Thread Matthew Snyder
Following-up to an older thread: Wietse Venema wrote: > Barney Desmond: > > 2009/6/13 Wietse Venema : > > > One final input: be sure to give each alias an owner-alias so that > > > Postfix will store the result of alias expansion in new queue > > > files. > > > > > > Otherwise, the result of expan

Re: slow link

2009-06-26 Thread Ing. Davy Leon
Hi again I'm having troubles with these again, let me explain myself better this time. I have a LAN with 10 PC conected to my linux box with postfix in it. I have a dialup link from the linux machine to the internet to deliver and fetch mail from our ISP. Due to bandwith limitation, I want Pos

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 02:12:12PM -0400, btb wrote: >>> testing with postmap returns: postmap -q 'example.com' ldap:./virtual_mailbox_domains.cf >>> postmap: warning: dict_ldap_set_tls_options: Unable to allocate new TLS >>> context -1: Can't contact LDAP server >> Have you tried with "star

Re: Message with 300,000+ recips via alias_maps

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 02:26:14PM -0400, Matthew Snyder wrote: > Following-up to an older thread: > > Wietse Venema wrote: > > Barney Desmond: > > > 2009/6/13 Wietse Venema : > > > > One final input: be sure to give each alias an owner-alias so that > > > > Postfix will store the result of alias

Re: slow link

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 02:37:34PM -0500, Ing. Davy Leon wrote: > Hi again > > I'm having troubles with these again, let me explain myself better this > time. I have a LAN with 10 PC conected to my linux box with postfix in it. > I have a dialup link from the linux machine to the internet to del

Re: slow link

2009-06-26 Thread Wietse Venema
Ing. Davy Leon: > Hi again > > I'm having troubles with these again, let me explain myself better this > time. I have a LAN with 10 PC conected to my linux box with postfix in it. I > have a dialup link from the linux machine to the internet to deliver and > fetch mail from our ISP. Due to band

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread Quanah Gibson-Mount
--On Friday, June 26, 2009 2:37 PM -0400 Victor Duchovni wrote: openldap appear to be using gnutls: > ldd /usr/sbin/slapd | egrep -i '(tls|ssl)' libgnutls.so.26 => /usr/lib/libgnutls.so.26 (0xb7d01000) Not sure it is a good idea to mix both in the same address space... I've only eve

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 02:37:32PM -0400, Victor Duchovni wrote: > What exactly was working before and what did you change? You need > a version of the LDAP library with debugging symbols. Then single-step > "gdb" (debugging "postmap") through ldap_int_tls_init_ctx() > > called from ldap_pvt_tl

Hi every one

2009-06-26 Thread David Glez Romero
Hello!! I need to know by default, how many connections SMTP IN accept Posftix?? I can define sessions for incoming or outgoing postfix?? Or i need to do tow instances for Postfix?? Regards, David -- _ Lic. David González Romero Network/System

Alias Expansion Problem

2009-06-26 Thread Hirayama, Pat
Hello, I've recently converted from sendmail, and postfix seems to be having problem with a recursive alias we use. So, in our aliases file, we have an address like this: allstaff: user1, user2, user3 ... user79, user80, allstaff80 allstaff80: user81, user82, ... user159, user160, allstaff160 a

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread jakjr
Try to use smtp without chroot: master.cf: smtp inet n - n - - smtpd On Fri, Jun 26, 2009 at 4:30 PM, Victor Duchovni < victor.ducho...@morganstanley.com> wrote: > On Fri, Jun 26, 2009 at 02:37:32PM -0400, Victor Duchovni wrote: > > > What exactly was working before and what did

Re: Hi every one

2009-06-26 Thread Magnus Bäck
On Friday, June 26, 2009 at 21:54 CEST, David Glez Romero wrote: > I need to know by default, how many connections SMTP IN accept Posftix?? See the maxproc column for smtpd in master.cf. If it's "-", default_process_limit applies (default 100). > I can define sessions for incoming or outgo

Re: slow link

2009-06-26 Thread Noel Jones
Ing. Davy Leon wrote: Hi again I'm having troubles with these again, let me explain myself better this time. I have a LAN with 10 PC conected to my linux box with postfix in it. I have a dialup link from the linux machine to the internet to deliver and fetch mail from our ISP. Due to bandwith

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread btb
Victor Duchovni wrote: On Fri, Jun 26, 2009 at 02:12:12PM -0400, btb wrote: testing with postmap returns: postmap -q 'example.com' ldap:./virtual_mailbox_domains.cf postmap: warning: dict_ldap_set_tls_options: Unable to allocate new TLS context -1: Can't contact LDAP server Have you tried

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 04:53:39PM -0300, jakjr wrote: > Try to use smtp without chroot: > > master.cf: > smtp inet n - n - - smtpd This is completely irrelevant. The OP's problem is reproducible with postmap(1) outside any chroot jail. The OP's problem report shows an error in

Re: slow link

2009-06-26 Thread Ing. Davy Leon
thank I will test it - Original Message - From: "Noel Jones" To: "Postfix users" Sent: Friday, June 26, 2009 3:15 PM Subject: Re: slow link Ing. Davy Leon wrote: Hi again I'm having troubles with these again, let me explain myself better this time. I have a LAN with 10 PC conect

Re: Hi every one

2009-06-26 Thread David Glez Romero
I can define sessions for incoming or outgoing postfix?? Or i need to do tow instances for Postfix?? What you do mean? Ok i sory, i not explain what want do... I want migrate the MDaemon to Postfix. In Madeamon i limited the sessions for controller the process in my server, because my bandwhi

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread Quanah Gibson-Mount
--On Friday, June 26, 2009 4:23 PM -0400 Victor Duchovni wrote: On Fri, Jun 26, 2009 at 04:53:39PM -0300, jakjr wrote: Try to use smtp without chroot: master.cf: smtp inet n - n - - smtpd This is completely irrelevant. The OP's problem is reproducible with postmap(1) outs

Re: Hi every one

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 04:23:53PM -0400, David Glez Romero wrote: >>> I can define sessions for incoming or outgoing postfix?? Or i need to >>> do tow instances for Postfix?? >> What you do mean? > Ok i sory, i not explain what want do... > > I want migrate the MDaemon to Postfix. In Madeamon i l

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 01:32:42PM -0700, Quanah Gibson-Mount wrote: > OpenLDAP 2.4.16 Release (2009/04/05) > Fixed libldap GnuTLS with x509v1 CA certs (ITS#5992) > Fixed libldap GnuTLS with CA chains (ITS#5991) > Fixed libldap GnuTLS TLSVerifyCilent try (ITS#5981) > > OpenLDAP 2

Re: trouble with ldaps in ldap lookup map

2009-06-26 Thread Quanah Gibson-Mount
--On Friday, June 26, 2009 4:48 PM -0400 Victor Duchovni wrote: On Fri, Jun 26, 2009 at 01:32:42PM -0700, Quanah Gibson-Mount wrote: OpenLDAP 2.4.16 Release (2009/04/05) Fixed libldap GnuTLS with x509v1 CA certs (ITS#5992) Fixed libldap GnuTLS with CA chains (ITS#5991)

Re: Hi every one

2009-06-26 Thread David Glez Romero
Ask about the goals you want to achieve, not the means by you believe these unstated goals can be achieved. In many cases when someone needs help with implementation, they have chosen the wrong approach to the real problem, and helping them fine-tune the wrong approach is counter-productive. Ok,

Re: Hi every one

2009-06-26 Thread Magnus Bäck
On Friday, June 26, 2009 at 22:23 CEST, David Glez Romero wrote: > Ok i sory, i not explain what want do... > > I want migrate the MDaemon to Postfix. In Madeamon i limited the > sessions for controller the process in my server, because my bandwhit > is very limited and i have 12000 user re

Re: Alias Expansion Problem

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 12:52:33PM -0700, Hirayama, Pat wrote: > Hello, > > I've recently converted from sendmail, and postfix seems to be having problem > with a recursive alias we use. > > So, in our aliases file, we have an address like this: > > allstaff: user1, user2, user3 ... user79, us

Re: greylist and then still RBL?

2009-06-26 Thread mouss
LuKreme a écrit : > I have the following in my main.cf: > > < #smtpd_reject_unlisted_sender = yes > mime_header_checks = pcre:$config_directory/mime_headers.pcre > smtpd_restriction_classes = check_greylist > check_greylist = check_policy_service inet:127.0.0.1:10023 > > MAINCF > > (there are no

Re: greylist and then still RBL?

2009-06-26 Thread Victor Duchovni
On Fri, Jun 26, 2009 at 11:46:13PM +0200, mouss wrote: > > Is that simply because the check_greylist directive is, itself, > > nonstandard and so not shown by postconf -n? > > yes, this is a known limitation of postconf. it only supports "known" > parameters. so you can't do > # postconf -e "joe=

Re: matching IP ranges in headers

2009-06-26 Thread mouss
Louis-David Mitterrand a écrit : > Hi, > > A lot of spam comes from certain ip ranges (e.g. west africa) through > relays (large ISPs) that would be too onerous to block. To filter these > I am presently matching: > > /^((Received|X-Originating-IP):.+\b(124\.120\.1\.( REGEX>)\b/ > > in pc

Re: matching IP ranges in headers

2009-06-26 Thread Victor Duchovni
On Sat, Jun 27, 2009 at 12:00:09AM +0200, mouss wrote: > Louis-David Mitterrand a ?crit : > > Hi, > > > > A lot of spam comes from certain ip ranges (e.g. west africa) through > > relays (large ISPs) that would be too onerous to block. To filter these > > I am presently matching: > > > > /^

Re: Tip: Restricting mail reception using a remote service's SPF records

2009-06-26 Thread mouss
Ville Walveranta a écrit : > Here's an idea.. maybe it's useful for someone, so I post it here. > > I'm setting up a local mail server to cache remote service's mail for > faster access on the LAN. The remote server has an up-to-date SPF > record that is updated whenever the sending IP ranges chan

Re: matching IP ranges in headers

2009-06-26 Thread mouss
Victor Duchovni a écrit : > On Sat, Jun 27, 2009 at 12:00:09AM +0200, mouss wrote: > >> Louis-David Mitterrand a ?crit : >>> Hi, >>> >>> A lot of spam comes from certain ip ranges (e.g. west africa) through >>> relays (large ISPs) that would be too onerous to block. To filter these >>> I am presen

RE: Alias Expansion Problem

2009-06-26 Thread Hirayama, Pat
So, the problem is with the recursion, and in fact, if it were just an alias with 3000+ addresses in a flat file, that will be handled without difficulty? -p -Original Message- From: Victor Duchovni [mailto:victor.ducho...@morganstanley.com] Sent: Fri 6/26/2009 2:41 PM To: Hirayam

Re: matching IP ranges in headers

2009-06-26 Thread Erwan David
Le Sat 27/06/2009, mouss disait > > but then again, we come back to "what would be generic control grammar?" > which is not a simple problem. > I think this would lead to embedding a full scripting language, like some applications embed lua... Not sure it woud be a good thing. -- Erwan

Re: Tip: Restricting mail reception using a remote service's SPF records

2009-06-26 Thread Ville Walveranta
On Fri, Jun 26, 2009 at 5:17 PM, mouss wrote: > so you would block mail from me? Yes, in fact, the local "cache" mail server would refuse mail from everyone but the servers mentioned in the external service's SPF record hence creating sort of an unprotected, IP-based "tunnel" between the external

Send to relay?

2009-06-26 Thread Ville Walveranta
Is it possible for Postfix to relay mail through another SMTP server? In other words: [sender client] -LAN-> [Postfix SMTP] -slow-> [some other SMTP] -> [recipient's SMTP] -> [recipient's client] .. where "Postfix SMTP" would relay via "some other SMTP" all outbound email it accepts to queue? Th