Re: Authenticated Receive Chain (ARC Sealing) in Postfix?

2023-01-02 Thread Dan Mahoney
> On Jan 2, 2023, at 4:20 PM, raf wrote: > > On Mon, Jan 02, 2023 at 08:32:42PM +, "Cooper, Robert A" > wrote: > >> I have a request from my downstream Exchange admins to look into >> implementing ARC sealing in some postfix relay servers we use for >> address rewriting. From the bit o

Re: Patch: cleanup log

2023-01-02 Thread Phil Biggs
Tuesday, January 3, 2023, 2:47:45 PM, Viktor Dukhovni wrote: > On Mon, Jan 02, 2023 at 07:32:51PM -0500, Wietse Venema wrote: >> > I was just curious what might cause that string of question marks. >> >> This is what a Postfix string looks like after its memory is freed. >> Something to look a

Patch: cleanup log

2023-01-02 Thread Viktor Dukhovni
On Mon, Jan 02, 2023 at 07:32:51PM -0500, Wietse Venema wrote: > > I was just curious what might cause that string of question marks. > > This is what a Postfix string looks like after its memory is freed. > Something to look at in the train tomorrow. Simple patch, the cache dictionary name is

Re: [Devel] OpenSSL 3.0 + TLS 1.3 and FFDHE key exchange

2023-01-02 Thread Viktor Dukhovni
On Mon, Jan 02, 2023 at 01:21:07PM -0500, Viktor Dukhovni wrote: > > Assuming that these finite fields are different than the finite > > fields that elliptic curve cryptography is based on, the proposed > > parameter structure seems sensble to me. > > Yes, indeed the underlying coefficient finite

Re: cleanup log

2023-01-02 Thread Wietse Venema
Phil Biggs: > Hello and happy new year to all, > > My friend is currently running FreeBSD 13.1-RELEASE-p2 GENERIC with the > postfix-sasl-3.7.2_1,1 pkg. > > Today I noticed this in his log: > > 2023-01-02T20:07:39.385545+11:00 postfix.[redacted] postfix/verify 23191 - - > cache ???

Re: Authenticated Receive Chain (ARC Sealing) in Postfix?

2023-01-02 Thread Demi Marie Obenour
On 1/2/23 15:32, Cooper, Robert A wrote: > I have a request from my downstream Exchange admins to look into implementing > ARC sealing in some postfix relay servers we use for address rewriting. From > the bit of research I've done, it looks like this would require being > implemented in an ex

Re: Authenticated Receive Chain (ARC Sealing) in Postfix?

2023-01-02 Thread raf
On Mon, Jan 02, 2023 at 08:32:42PM +, "Cooper, Robert A" wrote: > I have a request from my downstream Exchange admins to look into > implementing ARC sealing in some postfix relay servers we use for > address rewriting. From the bit of research I've done, it looks like > this would require

cleanup log

2023-01-02 Thread Phil Biggs
Hello and happy new year to all, My friend is currently running FreeBSD 13.1-RELEASE-p2 GENERIC with the postfix-sasl-3.7.2_1,1 pkg. Today I noticed this in his log: 2023-01-02T20:07:39.385545+11:00 postfix.[redacted] postfix/verify 23191 - - cache ??? partial c

Re: Authenticated Receive Chain (ARC Sealing) in Postfix?

2023-01-02 Thread Benny Pedersen
Cooper, Robert A skrev den 2023-01-02 21:32: I have a request from my downstream Exchange admins to look into implementing ARC sealing in some postfix relay servers we use for address rewriting. From the bit of research I've done, it looks like this would require being implemented in an externa

Re: Authenticated Receive Chain (ARC Sealing) in Postfix?

2023-01-02 Thread Phil Stracchino
On 1/2/23 15:32, Cooper, Robert A wrote: I have a request from my downstream Exchange admins to look into implementing ARC sealing in some postfix relay servers we use for address rewriting.  From the bit of research I've done,  it looks like this would require being implemented in an external

Authenticated Receive Chain (ARC Sealing) in Postfix?

2023-01-02 Thread Cooper, Robert A
I have a request from my downstream Exchange admins to look into implementing ARC sealing in some postfix relay servers we use for address rewriting. From the bit of research I've done, it looks like this would require being implemented in an external milter. I had not even heard of ARC befor

Re: parent_domain_matches_subdomains && smtpd_access_maps

2023-01-02 Thread Emmanuel Fusté
Le 02/01/2023 à 20:38, Laurent Frigault a écrit : Hi, Is there any way to have some smtpd_access_maps with parent_domain_matches_subdomains and some other without it ? I have : smtpd_recipient_restrictions = permit_mynetworks reject_non_fqdn_sender reject_unknown_sender_domain

Re: parent_domain_matches_subdomains && smtpd_access_maps

2023-01-02 Thread Rob McGee
On 1/2/2023 1:38 PM, Laurent Frigault wrote: Is there any way to have some smtpd_access_maps with parent_domain_matches_subdomains and some other without it ? I have : smtpd_recipient_restrictions = permit_mynetworks reject_non_fqdn_sender reject_unknown_sender_domain reje

Re: parent_domain_matches_subdomains && smtpd_access_maps

2023-01-02 Thread Wietse Venema
Laurent Frigault: > Hi, > > Is there any way to have some smtpd_access_maps with > parent_domain_matches_subdomains and some other without it ? There currently is no syntax to force some lookups with and some without. However, parent_domain_matches_subdomains does not apply to pcre:, regexp:, tc

parent_domain_matches_subdomains && smtpd_access_maps

2023-01-02 Thread Laurent Frigault
Hi, Is there any way to have some smtpd_access_maps with parent_domain_matches_subdomains and some other without it ? I have : smtpd_recipient_restrictions = permit_mynetworks reject_non_fqdn_sender reject_unknown_sender_domain reject_unauth_destination check_sender_access

Re: [Devel] OpenSSL 3.0 + TLS 1.3 and FFDHE key exchange

2023-01-02 Thread Viktor Dukhovni
On Mon, Jan 02, 2023 at 12:57:05PM -0500, Wietse Venema wrote: > > But doing this in a backwards-compatible way, that still works for any > > users who were brave enough to set "tls_eecdh_auto_curves" expecting > > to just limit the EC groups, means that we'll need two parameters with > > the belo

Re: [Devel] OpenSSL 3.0 + TLS 1.3 and FFDHE key exchange

2023-01-02 Thread Wietse Venema
Viktor Dukhovni: > [ The devel list majordomo is not doing too well just now, so please > pardon my use of postfix-users instead. ] > > In TLS 1.3 the key exchange parameters, whether elliptic curve (ECDHE or > ECX, where ECX is one of X25519 or X448) or finite-field (FFDHE), are always > from a

[Devel] OpenSSL 3.0 + TLS 1.3 and FFDHE key exchange

2023-01-02 Thread Viktor Dukhovni
[ The devel list majordomo is not doing too well just now, so please pardon my use of postfix-users instead. ] In TLS 1.3 the key exchange parameters, whether elliptic curve (ECDHE or ECX, where ECX is one of X25519 or X448) or finite-field (FFDHE), are always from a negotiated list of well-know

Re: Issue with Postfix

2023-01-02 Thread Forums
Hello, After checks I noticed that I had "1.1.1.1" in my resolv.conf. And that this DNS was specified in my dhcpcd.conf (certainly a mistake on my side). I deleted this entry in dhcpcd.conf and restarted the service. And no more "1.1.1.1" in resolv.conf. I tested to send an email from anoth