[pfx] Re: Regarding reject_unlisted_sender and preventing sender address spoofing

2024-01-05 Thread John Fawcett via Postfix-users
On 05/01/2024 19:44, Taco de Wolff via Postfix-users wrote: Hi, I'm trying to understand how the reject_unlisted_sender option works in the smtpd_sender_restrictions option. This is what I understand it to do: For any received mail (it is an smtpd option after all), either for receiving

[pfx] How to spot a competent developer

2024-01-05 Thread Kolusion K via Postfix-users
If you ever want to get an idea of how competent a developer is then I suggest looking no further at the quality of their documentation. My experience is that this is the best way to gauge how disciplined or lazy they are. :) May the good lord bless you all and may we all pray for Trump in

[pfx] Re: CVE-2023-51764

2024-01-05 Thread Wietse Venema via Postfix-users
Gerben Wierda via Postfix-users: > Is > > smtpd_data_restrictions = > reject_unauth_pipelining, > permit_mynetworks, > permit_sasl_authenticated, > reject_multi_recipient_bounce > > enough to stop this small(?) risk (before I manage to upgrade)? Please see

[pfx] Re: Behaviour in case of multiple relay hosts with multiple DNS records

2024-01-05 Thread Wietse Venema via Postfix-users
Peter Wienemann via Postfix-users: > Dear Wietse, > > thanks for your careful review. > > On 2024-01-05 16:11:56 +0100, Wietse Venema via Postfix-users wrote: > > Peter Wienemann via Postfix-users: > >> smtp(8): > >> > >>

[pfx] Regarding reject_unlisted_sender and preventing sender address spoofing

2024-01-05 Thread Taco de Wolff via Postfix-users
Hi, I'm trying to understand how the reject_unlisted_sender option works in the smtpd_sender_restrictions option. This is what I understand it to do: For any received mail (it is an smtpd option after all), either for receiving mail from an external server or for sending mail from a logged in

[pfx] Re: Behaviour in case of multiple relay hosts with multiple DNS records

2024-01-05 Thread Viktor Dukhovni via Postfix-users
On Fri, Jan 05, 2024 at 06:46:01PM +0100, Peter Wienemann via Postfix-users wrote: > > Unfortunately this says that RFC 5321 applies to LMTP deliveries, > > RFC 2033 says: "The LMTP protocol is identical to the SMTP protocol [SMTP] > [HOST-REQ] with its service extensions [ESMTP], except as

[pfx] CVE-2023-51764

2024-01-05 Thread Gerben Wierda via Postfix-users
Is smtpd_data_restrictions = reject_unauth_pipelining, permit_mynetworks, permit_sasl_authenticated, reject_multi_recipient_bounce enough to stop this small(?) risk (before I manage to upgrade)? Gerben Wierda (LinkedIn ,

[pfx] Re: Behaviour in case of multiple relay hosts with multiple DNS records

2024-01-05 Thread Peter Wienemann via Postfix-users
Dear Wietse, thanks for your careful review. On 2024-01-05 16:11:56 +0100, Wietse Venema via Postfix-users wrote: Peter Wienemann via Postfix-users: smtp(8): The Postfix SMTP+LMTP client supports multiple destinations

[pfx] Re: Behaviour in case of multiple relay hosts with multiple DNS records

2024-01-05 Thread Wietse Venema via Postfix-users
Peter Wienemann via Postfix-users: > Hi Viktor, > > On 2024-01-02 18:13:22 +0100, Viktor Dukhovni via Postfix-users wrote: > > That said, indeed the documentation is not explicit on this point, one > > has to read "between the lines". If your technical writing skills are > > adequate, perhaps

[pfx] Re: Behaviour in case of multiple relay hosts with multiple DNS records

2024-01-05 Thread Peter Wienemann via Postfix-users
Hi Viktor, On 2024-01-02 18:13:22 +0100, Viktor Dukhovni via Postfix-users wrote: That said, indeed the documentation is not explicit on this point, one has to read "between the lines". If your technical writing skills are adequate, perhaps you could suggest some concise and clear text