[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Scott Techlist via Postfix-users
Noel: As I understand from your explanation, if I keep my parent_domain_matches_subdomains = smtpd_access_maps Then the preceding dot format is moot/not needed. Only outbound.protection.outlook.com OK Check. >The reason it doesn't work is you're confusing sender and client.

[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Scott Techlist via Postfix-users
>>Depending on whether omain is client or sender or ... >> >>... >>reject_unauth_destination >>... >>check_client_access hash:/pathname >>reject_rbl_client example.com >>... >> >>Or >> >>... >>reject_unauth_destination >>... >>check_sender_access

[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Scott Techlist via Postfix-users
>> check_sender_access hash:/etc/postfix/sender_checks, > >That directive checks the email address which is used in the SMTP MAIL >FROM command. > >I believe you need to use check_client_access to check the verified >client hostname instead of check_sender_access. > > Bill & Noel, thank you both

[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Scott Techlist via Postfix-users
>Scott Techlist via Postfix-users: >> I need to allow a domain to bypass my RBL checks. I'm doing something >> wrong, or I'm >misunderstanding what I'm checking from my logs. I'd be grateful for an >assist to remedy. >> > >Depending on whether omain is client or sender or ... > >... >

[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Scott Techlist via Postfix-users
>I can tell you there is significant spam from that Microsoft IP space. That >spamcop doesn't have false positives, but rather due to >the sharing of IP >space, senders that aren't spammers get tarred with the same brush as the >spammers. I did a grep on the maillog >files and that is a

[pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Viktor Dukhovni via Postfix-users
On Wed, Feb 28, 2024 at 08:55:04AM -0500, Scott Hollenbeck via Postfix-users wrote: > Would someone please describe the configuration settings needed to support > TLS 1.2 and 1.3 with no weak ciphers? Here's what I currently have in my > configuration files: This is not the right question.

[pfx] postfix check_sender_access and subdomain test

2024-02-28 Thread lists--- via Postfix-users
I can tell you there is significant spam from that Microsoft IP space. That spamcop doesn't have false positives, but rather due to the sharing of IP space, senders that aren't spammers get tarred with the same brush as the spammers.  I did a grep on the maillog files and that is a firehose of

[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Noel Jones via Postfix-users
On 2/28/2024 1:38 PM, Scott Techlist via Postfix-users wrote: I need to allow a domain to bypass my RBL checks.  I’m doing something wrong, or I’m misunderstanding what I’m checking from my logs.  I’d be grateful for an assist to remedy. This box is an old postfix install Postfix version

[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Bill Cole via Postfix-users
On 2024-02-28 at 14:38:41 UTC-0500 (Wed, 28 Feb 2024 13:38:41 -0600) Scott Techlist via Postfix-users is rumored to have said: I need to allow a domain to bypass my RBL checks. I'm doing something wrong, or I'm misunderstanding what I'm checking from my logs. I'd be grateful for an assist

[pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Scott Hollenbeck via Postfix-users
> -Original Message- > From: Wietse Venema via Postfix-users > Sent: Wednesday, February 28, 2024 3:11 PM > To: Postfix users > Subject: [pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak > Ciphers > > Scott Hollenbeck via Postfix-users: > > Right, but that page says "You

[pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Wietse Venema via Postfix-users
Scott Hollenbeck via Postfix-users: > Right, but that page says "You are strongly encouraged not to change this > setting". I'm also unsure why I'm not seeing any TLS 1.3 ciphers when > "smtpd_tls_protocols = >=TLSv1.2". Doesn't that setting include TLS 1.3? tls_high_cipherlist and

[pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Scott Hollenbeck via Postfix-users
Right, but that page says "You are strongly encouraged not to change this setting". I'm also unsure why I'm not seeing any TLS 1.3 ciphers when "smtpd_tls_protocols = >=TLSv1.2". Doesn't that setting include TLS 1.3? Scott > -Original Message- > From: Wietse Venema via Postfix-users >

[pfx] Re: postfix check_sender_access and subdomain test

2024-02-28 Thread Wietse Venema via Postfix-users
Scott Techlist via Postfix-users: > I need to allow a domain to bypass my RBL checks. I'm doing something wrong, > or I'm misunderstanding what I'm checking from my logs. I'd be grateful for > an assist to remedy. > Depending on whether omain is client or sender or ... ...

[pfx] postfix check_sender_access and subdomain test

2024-02-28 Thread Scott Techlist via Postfix-users
I need to allow a domain to bypass my RBL checks. I'm doing something wrong, or I'm misunderstanding what I'm checking from my logs. I'd be grateful for an assist to remedy. This box is an old postfix install Postfix version 2.2.10. (I know, working on migrating) main.cf: (full

[pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Wietse Venema via Postfix-users
Scott Hollenbeck via Postfix-users: > Thanks, here's the output: > > $ postconf -H | grep -E 'high|medium' > tls_high_cipherlist > tls_medium_cipherlist > $ > No, a hint to study the postconf(5) manpage. https://www.postfix.org/postconf.5.html#tls_high_cipherlist

[pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Scott Hollenbeck via Postfix-users
Thanks, here's the output: $ postconf -H | grep -E 'high|medium' tls_high_cipherlist tls_medium_cipherlist $ Empty cipher lists? Scott > -Original Message- > From: Wietse Venema via Postfix-users > Sent: Wednesday, February 28, 2024 2:18 PM > To: Postfix users > Subject: [pfx] Re:

[pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Wietse Venema via Postfix-users
Scott Hollenbeck via Postfix-users: > Sorry, I should note that this is for postfix 3.6.4. > postconf -H | grep -E 'high|medium' Wietse > > > -Original Message- > > From: Scott Hollenbeck via Postfix-users > > Sent: Wednesday, February 28, 2024 8:55 AM > > To:

[pfx] Re: userid for file delivery ?

2024-02-28 Thread Markus Schönhaber via Postfix-users
28.02.24, 19:09 +0100, John Levine via Postfix-users: > Here's another question that might be answered in the documentation > but I can't find it. If I have a file delivery like this in > the /etc/aliases file > > foo: /a/b/somefile > > what userid writes to the file? postfix? nobody? > > I

[pfx] Re: userid for file delivery ?

2024-02-28 Thread Wietse Venema via Postfix-users
John Levine via Postfix-users: > Here's another question that might be answered in the documentation > but I can't find it. If I have a file delivery like this in > the /etc/aliases file > > foo: /a/b/somefile > > what userid writes to the file? postfix? nobody? > > I realize that for user

[pfx] Re: Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Scott Hollenbeck via Postfix-users
Sorry, I should note that this is for postfix 3.6.4. Scott > -Original Message- > From: Scott Hollenbeck via Postfix-users > Sent: Wednesday, February 28, 2024 8:55 AM > To: postfix-users@postfix.org > Subject: [pfx] Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers > >

[pfx] userid for file delivery ?

2024-02-28 Thread John Levine via Postfix-users
Here's another question that might be answered in the documentation but I can't find it. If I have a file delivery like this in the /etc/aliases file foo: /a/b/somefile what userid writes to the file? postfix? nobody? I realize that for user mailboxes it's the user, but in this case, there's

[pfx] Re: Postfix gmail relay SASL authentication failed invalid parameter supplied

2024-02-28 Thread Nuno Catarino via Postfix-users
Solved Many thanks to *Wietse Venema* The solution could be as simple as: /etc/postfix/main.cf: smtp_sasl_mechanism_filter = login plain Nuno Catarino escreveu (quarta, 28/02/2024 à(s) 15:04): > Hi there, i'm using leap 15.5, trying to send emails thru gmail relay and > getting crazy. >

[pfx] Re: Postfix gmail relay SASL authentication failed invalid parameter supplied

2024-02-28 Thread Wietse Venema via Postfix-users
Nuno Catarino via Postfix-users: > postfix/smtp[31278]: CFC982C034E: to=, > relay=smtp.gmail.com[64.233.167.109]:587, > delay=5.5, delays=0.05/0/5.4/0, dsn=4.7.0, status=deferred (SASL > authentication failed; cannot authenticate to server > smtp.gmail.com[64.233.167.109]: > invalid parameter

[pfx] Re: Postfix gmail relay SASL authentication failed invalid parameter supplied

2024-02-28 Thread Bill Cole via Postfix-users
On 2024-02-28 at 10:04:05 UTC-0500 (Wed, 28 Feb 2024 15:04:05 +) Nuno Catarino via Postfix-users is rumored to have said: > Hi there, i'm using leap 15.5, trying to send emails thru gmail relay and > getting crazy. > Send my configuration for someone to help me > when i'm trying to send the

[pfx] Re: postfix and smtpd_proxy_timeout

2024-02-28 Thread natan via Postfix-users
W dniu 28.02.2024 o 16:14, Wietse Venema via Postfix-users pisze: natan via Postfix-users: for"us...@domain.ltd" Feb 27 16:02:28 smtp1v postfix/cleanup[23476]: warning: proxy:mysql:/etc/postfix/mysql_sender_bcc_maps_user.cf-new lookup error for"us...@domain.ltd" Feb 27 16:02:29 smtp1v

[pfx] Re: postfix and smtpd_proxy_timeout

2024-02-28 Thread Wietse Venema via Postfix-users
natan via Postfix-users: > for "us...@domain.ltd" > Feb 27 16:02:28 smtp1v postfix/cleanup[23476]: warning: > proxy:mysql:/etc/postfix/mysql_sender_bcc_maps_user.cf-new lookup error > for "us...@domain.ltd" > Feb 27 16:02:29 smtp1v postfix/cleanup[23476]: warning: >

[pfx] Postfix gmail relay SASL authentication failed invalid parameter supplied

2024-02-28 Thread Nuno Catarino via Postfix-users
Hi there, i'm using leap 15.5, trying to send emails thru gmail relay and getting crazy. Send my configuration for someone to help me when i'm trying to send the email the error is: postfix/pickup[30145]: CFC982C034E: uid=0 from= postfix/cleanup[30149]: CFC982C034E:

[pfx] Re: rbl bounces email that has both rbl_override and client_checks whitelisting

2024-02-28 Thread Bill Cole via Postfix-users
On 2024-02-27 at 16:39:54 UTC-0500 (Tue, 27 Feb 2024 13:39:54 -0800 (PST)) lists--- via Postfix-users is rumored to have said: I have a sender_checks file but I don't see that on the postfix.org website. Is that a deprecated parameter? The names of Postfix map files are up to you. Their

[pfx] Configuration Settings for TLS 1.2 and 1.3 with No Weak Ciphers

2024-02-28 Thread Scott Hollenbeck via Postfix-users
Would someone please describe the configuration settings needed to support TLS 1.2 and 1.3 with no weak ciphers? Here's what I currently have in my configuration files: main.cf: smtpd_tls_cert_file=/etc/letsencrypt/live/mysite.net/fullchain.pem

[pfx] Re: postfix and smtpd_proxy_timeout

2024-02-28 Thread natan via Postfix-users
Hi In log i get: Feb 27 15:57:28 smtp1v postfix/cleanup[23476]: warning: proxy:mysql:/etc/postfix/mysql_sender_bcc_maps_user.cf-new lookup error for "us...@domain.ltd" Feb 27 16:02:28 smtp1v postfix/cleanup[23476]: warning: proxy:mysql:/etc/postfix/mysql_sender_bcc_maps_user.cf-new lookup

[pfx] Re: question regarding postmap -q test

2024-02-28 Thread Markus Schönhaber via Postfix-users
28.02.24, 09:20 +0100, lists--- via Postfix-users: > My sender_access file contains > > charity.donation.jp REJECT > > postmap -q charity.donation.jp hash:sender_access > REJECT > > So it returns REJECT as expected. However testing some random users at > the domain: > > postmap -q

[pfx] question regarding postmap -q test

2024-02-28 Thread lists--- via Postfix-users
My sender_access file contains charity.donation.jp REJECT postmap -q charity.donation.jp hash:sender_access REJECT So it returns REJECT as expected. However testing some random users at the domain: postmap -q m...@charity.donation.jp hash:sender_access returns nothing. Is the domain being