Re: postscreen log scanner script updated

2014-10-08 Thread Marko Weber | ZBF
Hi, Am 2014-09-29 18:18, schrieb Mike.: On 9/29/2014 at 10:44 AM Mike. wrote: |I cleaned up my pslogscan.sh script a bit. Aside from some general |cleanup, I did some re-formatting of the output to make it look a bit |cleaner, and allow for some flexibility in display widths. I also |went

Re: ldap help needed.

2014-06-20 Thread Marko Weber | ZBF
hi wietse, Am 2014-06-17 15:39, schrieb wie...@porcupine.org: Wietse Venema: [] Stopping Postfix Mail Transport Agent: postfix/usr/sbin/postconf: warning: /etc/postfix/main.cf: unused parameter: ldap_transport_result_filter=smtp:%s.24t.loc:25 Apparently, postconf 2.9-2.12 error

ldap help needed.

2014-06-17 Thread Marko Weber | ZBF
hello list, on debian 7.5 i installed postfix 2.9.6 with postfix-ldap package. in the main.cf: ... ldap_transport_result_filter = smtp:%s.24t.loc:25 virtual_mailbox_maps = ldap:ldap_users ## wichtig!! ldap:ldap_users muss hier mit aufgefuehrt werden, sonst werden alle Mails

tls question to viktor,

2014-01-29 Thread Marko Weber | ZBF
hello, viktor or any other. in the postfix tls readme: In order to use TLS, the Postfix SMTP server generally needs a certificate and a private key. Both must be in PEM format. i have setup this way in my main.cf: smtpd_tls_CAfile=

Limitation on outgoing mails

2014-01-17 Thread Marko Weber | ZBF
hi list, sorry to ask, but i CANT remember how the option is named in the main / master cf. theres an option to limit outgoing mails, lets say the mailserver has to send 1000 mails to google.com, u can say with this option not more then 10 mails at once to deliver. does any know what i mean

Re: Puzzling problem

2014-01-09 Thread Marko Weber | ZBF
Hello, Am 2014-01-09 05:26, schrieb Seann: Paul, First thing that caught my eye, is it looks like the reason for the bounce was the filter shell script died: Command died with status 1: /usr/local/bin/filter.sh. Command output: Jan 9 02:49:28.913 [29829] warn: netset: cannot

copy incoming mails to other account and strip out attachements?

2013-12-12 Thread Marko Weber | ZBF
hello list, its me again from hamburg. i googled some time to find a solution for following scene: incoming mails for import...@dingdong.com , should be copied to mob...@dingdong.com AND if Attachements are in the mail, they should be stripped out. Only in the account import...@dingdong.com

LDAP Fallback Question

2013-11-13 Thread Marko Weber | ZBF
hello list, we use LDAP in Postfix for User Management. Now i should setup a second LDAP server and postfix should use the second LDAP server when the first is not longer available. i searched inet but didnt really find a solution. can u help me or guide me? thank you marko

Re: LDAP Fallback Question

2013-11-13 Thread Marko Weber | ZBF
hallo patrick, Am 2013-11-13 10:29, schrieb Patrick Ben Koetter: * Marko Weber | ZBF we...@zackbummfertig.de: hello list, we use LDAP in Postfix for User Management. Now i should setup a second LDAP server and postfix should use the second LDAP server when the first is not longer available

Re: requiring TLS on a pool of servers

2013-10-16 Thread Marko Weber | ZBF
Hello, Am 2013-10-14 14:12, schrieb Dan Langille: I have a group of Postfix servers. I want communications between these servers to be TLS and clients must present a known certificate. These servers are also public-facing and accept incoming mail from servers not under my control. I just

dnsblog dnswl problem ?

2013-09-19 Thread Marko Weber | ZBF
hello, i use list.dnswl.org in postscreen_dnsbl_sites . in the logfiles i see: Sep 19 12:17:18 mail postfix/dnsblog[15318]: warning: dnsblog_query: lookup error for DNS query 35.64.91.217.list.dnswl.org: Host or domain name not found. Name service error for name=35.64.91.217.list.dnswl.org

Re: postscreen postscreen_dnsbl_sites order

2013-09-18 Thread Marko Weber | ZBF
Hi Wietse, Am 2013-09-04 23:45, schrieb wie...@porcupine.org: Marko Weber | ZBF: hello postfix list, maybe an easy quest for you. when i use multiple rbls in 'postscreen_dnsbl_sites' Yes... postscreen_dnsbl_sites = 1.list.org anotherlist.org nsafools.org obamaisadrama.org

postscreen postscreen_dnsbl_sites order

2013-09-04 Thread Marko Weber | ZBF
hello postfix list, maybe an easy quest for you. when i use multiple rbls in 'postscreen_dnsbl_sites' postscreen_dnsbl_sites = 1.list.org anotherlist.org nsafools.org obamaisadrama.org at example. are the entries of 'postscreen_dnsbl_sites' used in order like listed? or is postscreen

Re: How to send more than 1 email per sec per domain?

2013-08-14 Thread Marko Weber | ZBF
Hi, Am 2013-08-13 18:10, schrieb DTNX Postmaster: On Aug 13, 2013, at 17:34, Noel Jones njo...@megan.vbhcs.org wrote: On 8/13/2013 10:26 AM, Philippe Bloix wrote: What i would like is : For example, my postfix relay accepts about 1000 emails (1 shot) from a SMTP client, then the postfix

Re: DSPAM Integration

2013-07-25 Thread Marko Weber | ZBF
hello, Am 2013-07-23 10:19, schrieb Phil Daws: Hello, I would love to integrate DSPAM with AmaViS and read somewhere that the best way for retraining would be to use a custom hook. My thinking is that the custom hook should check the SA score and if that believes it is SPAM then it would pass

Re: ratelimiting outgoing mail

2013-07-11 Thread Marko Weber | ZBF
hi, Am 2013-07-11 12:58, schrieb wie...@porcupine.org: Przemys?aw Orzechowski: Hi I need to setup server that will ratelimit outgoing mail but will accept all messages from authenticated users regardles of ratelimit. I know its somewhat strange approach but ... its higherups decission

Re: postfix munin graphs

2013-06-19 Thread Marko Weber | ZBF
Am 2013-06-19 09:56, schrieb Grant: I think I need to tell munin where my postfix logs are (/var/log/mail/current) since I use metalog. How can I do that? Instead of searching online, use the built-in pod based format, e.g.: $ munindoc postfix_mailstats You just improved my life. You

Re: 2.10 problem

2013-06-04 Thread Marko Weber | ZBF
Am 2013-06-04 15:00, schrieb Benny Pedersen: Grant skrev den 2013-06-04 01:45: The big config change I see referenced with regard to 2.10 is smtpd_relay_restrictions but I don't see how that could be related. My smtpd_relay_restrictions is blank. suggest to make it not in main.cf, but use

Re: postfix need reload after cidr changes?

2013-05-23 Thread Marko Weber | ZBF
hey wietse, Am 2013-05-23 21:33, schrieb wie...@porcupine.org: Marko Weber | ZBF: when i change a cidr map, do i have to reload postfix like on chnages by texthash? i was on http://www.postfix.org/cidr_table.5.html and cant find that info. It is safe to assume that if you change a file

ssl errors in log. error on remote or local side?

2013-05-22 Thread Marko Weber | ZBF
hello list, i find error entries like these in my logs: postfix/smtp[16790]: warning: TLS library problem: 16790:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number:s3_pkt.c:340: does that mean openssl or something is broken on my machine? thanks marko

Re: ssl errors in log. error on remote or local side?

2013-05-22 Thread Marko Weber | ZBF
Am 2013-05-22 17:54, schrieb Viktor Dukhovni: On Wed, May 22, 2013 at 03:57:49PM +0200, Marko Weber | ZBF wrote: I find error entries like these in my logs: postfix/smtp[16790]: warning: TLS library problem: 16790:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number:s3_pkt.c:340

Re: problem, pass bad header thru amavis and dont quarantine them

2013-05-17 Thread Marko Weber | ZBF
Hi Patrick, Am 2013-05-17 00:20, schrieb Patrick Ben Koetter: Marko, * Marko Weber | ZBF we...@zackbummfertig.de: hello, i set in amavid.conf : $final_bad_header_destiny = D_PASS; but in logs i see this lines; May 16 23:22:11 mail amavis[15703]: (15703-13) Passed BAD-HEADER-1

Re: problem, pass bad header thru amavis and dont quarantine them

2013-05-17 Thread Marko Weber | ZBF
, * Marko Weber | ZBF we...@zackbummfertig.de: hello, i set in amavid.conf : $final_bad_header_destiny = D_PASS; but in logs i see this lines; May 16 23:22:11 mail amavis[15703]: (15703-13) Passed BAD-HEADER-1 {RelayedOpenRelay,Quarantined}, [***.***.***.***] apache@***.de - r...@domain.de

postfix ssl errors in log, what does they mean?

2013-05-16 Thread Marko Weber | ZBF
hello , i find many of these in my mail.log: May 16 14:27:33 mail opendkim[2926]: 119CA2FB20: s=dktest d=porcupine.org SSL error:04091068:rsa routines:INT_RSA_VERIFY:bad signature is my openssl broken or something else glitchy? or does this mean the dkim from porcupine.org ist invalid?

Re: Postscreen config

2013-04-29 Thread Marko Weber | ZBF
Am 2013-04-24 15:59, schrieb Tony Nelson: After reading through the recent Postscreen DNSBL threads I decided to give it a try. I used Rob's example from http://rob0.nodns4.us/postscreen.html [1] as a leaping off point, but chose to leave pipelining disabled until I'm sure I understand what I

Re: Graphical stats by domain

2013-04-04 Thread Marko Weber | ZBF
Am 2013-04-04 10:12, schrieb Muzaffer Tolga Özses: On 04/04/2013 10:30 AM, Antoine Nguyen wrote: Muzaffer Tolga Özses to...@ozses.net wrote: Good morning everyone :) Do you guys know of a tool that will act like pflogsumm, only based on domain and graphical? Regards, Hi, take a look

Re: dictionary-attack

2013-03-28 Thread Marko Weber | ZBF
The table was created many years ago over an extended period of time,...:: so, its outdated? i think its better to use postscreen and a regular updated file like DROP from spamhaus. i refresh this DROP every hour. so maybe wrong listed candidates are deleted in the refreshed

TLS Question, untrusted connection

2013-03-26 Thread Marko Weber | ZBF
i sometimes mail with the deutschebank. when i send mails i use a tls_policy_map: db.com secure match=loninmrp23.uk.db.com:nyjinsmp07.us.db.com:loninmrp22.uk.db.com:loninmrp14.uk.db.com:nyginsmp02.us.db.com:nyjinsmp01.us.db.com .db.com secure

Re: Dont add the $myorigin domain to the FROM header field

2013-03-26 Thread Marko Weber | ZBF
Am 2013-03-22 18:50, schrieb Noel Jones: On 3/22/2013 11:44 AM, Victor d'Agostino wrote: Hi all, I use postfix as relay server to several internal domains. xxx is the main one. postconfig | grep domain prints : append_dot_mydomain = no mydomain = xxx myorigin = $mydomain relay_domains =

Re: TLS Question, untrusted connection

2013-03-26 Thread Marko Weber | ZBF
Am 2013-03-26 10:30, schrieb Reindl Harald: Am 26.03.2013 09:44, schrieb Marko Weber|ZBF: Mar 25 14:04:35 mail postfix/smtpd[31103]: Untrusted TLS connection established from loninmrp15.uk.db.com[160.83.44.131]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits) why is on incoming mails

Postscreen dnsblog logentries

2013-03-20 Thread Marko Weber | ZBF
hello, i see alot of entries from postfix/dnsblog in my logs like this: postfix/dnsblog[30381]: warning: dnsblog_query: lookup error for DNS query 140.99.145.217.xx.zen.dq.spamhaus.net: Host or domain name not found. Name service error for

Re: is possible to use different SSL certificates for different domains?

2013-02-25 Thread Marko Weber | ZBF
The one Mailserver, that is doing mailing for N Domains, only need one Certificate. Other thing is with websites, they need each one. connect multiple ip´s to the server for multiple websites ssl certs. but the mailserver only one for himself. the other mailserver dont look what domain sends

Re: is possible to use different SSL certificates for different domains?

2013-02-25 Thread Marko Weber | ZBF
case and not's typical to do, and for this I prefer to comment to this list. If anyone knows how to create this rule, be grateful Thanks On 25/02/2013 10:46, Marko Weber | ZBF wrote: The one Mailserver, that is doing mailing for N Domains, only need one Certificate. Other thing is with websites