Re: Posftix/Dovecot deliver

2011-05-19 Thread Jeroen Geilman
On 05/19/2011 01:19 AM, Sahil Tandon wrote: On Wed, 2011-05-18 at 19:05:11 -0300, Gonzalo Rodriguez wrote: May 18 09:49:35 FOOBAR-0010 postfix/local[16584]: 8808D26125: to=, relay=local, delay=0.92, delays=0.91/0.01/0/0, dsn=2.0.0, status=sent (delivered to mailbox) Where is 'foobar.com.ar' li

pitfalls: dbmail-postfix-policyd

2011-05-19 Thread Reindl Harald
i am running the policyd on our main-server since this morning because some users do not realize that it does not solve the quota-problem (daily corn-notifies) to remove 5 messages it works great until now but could be optimized what about writing only warnings to the maillog if db-connection fai

Re: permit_mynetworks doesn't supersede reject_unauth_pipelining

2011-05-19 Thread Wietse Venema
Shawn Heisey: > May 18 18:49:21 nexus2 postfix/smtpd[24852]: > > monitor.example.com[10.2.1.39]: 503 5.5.1 Error: send HELO/EHLO first First, you need to learn to speak SMTP correctly. Second, you need to repeat my examples from yesterday that demonstrate that permit_mynetworks followed by rejec

Re: Posftix/Dovecot deliver

2011-05-19 Thread Gonzalo Rodriguez
2011/5/18 Sahil Tandon : > On Wed, 2011-05-18 at 19:05:11 -0300, Gonzalo Rodriguez wrote: > >> May 18 09:49:35 FOOBAR-0010 postfix/local[16584]: 8808D26125: >> to=, relay=local, delay=0.92, >> delays=0.91/0.01/0/0, dsn=2.0.0, status=sent (delivered to mailbox) > > Where is 'foobar.com.ar' listed in

Re: Posftix/Dovecot deliver

2011-05-19 Thread Gonzalo Rodriguez
that fix it, thank you so much, and all of you. regards 2011/5/19 Grobe, Tony : >> -Original Message- >> From: owner-postfix-us...@postfix.org [mailto:owner-postfix- >> us...@postfix.org] On Behalf Of Gonzalo Rodriguez >> Sent: Thursday, May 19, 2011 8:35 AM >> To: postfix-users@postfix.o

Re: connect to smtp.host.com[1.2.3.4]:25: Permission denied

2011-05-19 Thread Darek M
On Wed, May 18, 2011 at 4:35 PM, Wietse Venema wrote: > Check your SELINUX, APPARMOR, etc. "security" settings. > >        Wietse I'm running FreeBSD 8, and there isn't anything running by default like SELinux on Linux. Do these permissions look ok? -rw--- 1 postfix postfix310 May 1

Re: connect to smtp.host.com[1.2.3.4]:25: Permission denied

2011-05-19 Thread Wietse Venema
Darek M: > On Wed, May 18, 2011 at 4:35 PM, Wietse Venema wrote: > > > Check your SELINUX, APPARMOR, etc. "security" settings. > > > > ? ? ? ?Wietse > > I'm running FreeBSD 8, and there isn't anything running by default > like SELinux on Linux. Do these permissions look ok? File permissions have

Re: permit_mynetworks doesn't supersede reject_unauth_pipelining

2011-05-19 Thread Shawn Heisey
On 5/18/2011 10:30 PM, Noel Jones wrote: On 5/18/2011 8:11 PM, Shawn Heisey wrote: monitor.example.com[10.2.1.39]: 503 5.5.1 Error: send HELO/EHLO first But that's a different error message. For this, you need to set # main.cf smtpd_helo_required = no (which is the default). This setting

Re: permit_mynetworks doesn't supersede reject_unauth_pipelining

2011-05-19 Thread Wietse Venema
Shawn Heisey: > For the world at large, I want to require correct pipelining, but have a > mechanism to bypass it for certain hosts. I might end up using You need to repeat my examples that show that permit_mynetworks and reject_unauth_pipelining work as documented. Wietse

Re: permit_mynetworks doesn't supersede reject_unauth_pipelining

2011-05-19 Thread martijn.list
On 05/19/2011 05:44 PM, Shawn Heisey wrote: > > On 5/18/2011 10:30 PM, Noel Jones wrote: >> On 5/18/2011 8:11 PM, Shawn Heisey wrote: >>> monitor.example.com[10.2.1.39]: 503 5.5.1 Error: send >>> HELO/EHLO first >> >> But that's a different error message. For this, you need to set >> >> # main.cf

Re: permit_mynetworks doesn't supersede reject_unauth_pipelining

2011-05-19 Thread Wietse Venema
Shawn Heisey: > helo mcp.example.com > mail from: postmas...@mcp.example.com > quit > > Here's what this looks like in context: > > mcp:/usr/src# telnet ns2 25 > Trying 10.8.0.22... > Connected to ns2.example.com. > Escape character is '^]'. > 220 nexus2.example.com ESMTP Postfix (Debian/GNU) > h

Re: Posftix/Dovecot deliver

2011-05-19 Thread Jeroen Geilman
On 05/19/2011 02:28 PM, Gonzalo Rodriguez wrote: foobar is a example domain, is ofuscated That's what example.com is for. RFC 2606, section 3: 3. Reserved Example Second Level Domain Names The Internet Assigned Numbers Authority (IANA) also currently has the following second level doma

Re: permit_mynetworks doesn't supersede reject_unauth_pipelining

2011-05-19 Thread Shawn Heisey
On 5/19/2011 10:13 AM, Wietse Venema wrote: Shawn Heisey: helo mcp.example.com mail from: postmas...@mcp.example.com quit Here's what this looks like in context: mcp:/usr/src# telnet ns2 25 Trying 10.8.0.22... Connected to ns2.example.com. Escape character is '^]'. 220 nexus2.example.com ESMTP

Re: permit_mynetworks doesn't supersede reject_unauth_pipelining

2011-05-19 Thread Wietse Venema
Shawn Heisey: > On 5/19/2011 10:13 AM, Wietse Venema wrote: > > Shawn Heisey: > >> helo mcp.example.com > >> mail from: postmas...@mcp.example.com > >> quit > >> > >> Here's what this looks like in context: > >> > >> mcp:/usr/src# telnet ns2 25 > >> Trying 10.8.0.22... > >> Connected to ns2.example

Patched Postfix?

2011-05-19 Thread Patrick Ben Koetter
Today I've come across a Sophos PureMesssage server that puts "ignore_policy_error" as restriction option: smtpd_client_restrictions = ignore_policy_error, check_policy_service inet:localhost:4466 I've looked up the postconf man page, but couldn't find that option. Sophos OTOH ha

Re: Patched Postfix?

2011-05-19 Thread Wietse Venema
Patrick Ben Koetter: > Today I've come across a Sophos PureMesssage server that puts > "ignore_policy_error" as restriction option: > > smtpd_client_restrictions = > ignore_policy_error, > check_policy_service inet:localhost:4466 > > I've looked up the postconf man page, but coul

fatal: parameter "smtpd_recipient_restrictions"

2011-05-19 Thread Reindl Harald
hi how do i get "check_policy_service unix:/var/spool/postfix/dbmail-postfix-policyd/socket" on port 10026 to activate quota-checks before lmtp for messages from the spam-appliance with a minimum or bette rno other checks than verify rcpt? i tried directly before "permit_mynetworks" but get the

Re: fatal: parameter "smtpd_recipient_restrictions"

2011-05-19 Thread Wietse Venema
Reindl Harald: Checking application/pgp-signature: FAILURE -- Start of PGP signed section. [ Charset ISO-8859-1 unsupported, converting... ] > hi > > how do i get "check_policy_service > unix:/var/spool/postfix/dbmail-postfix-policyd/socket" > on port 10026 to activate quota-checks before lmtp f