Re: Identifying used patches
Erwin Hoffmann <[email protected]>
| Newsgroups | gmane.mail.qmail.general |
|---|---|
| Message-ID | <[email protected]> |
Hi Jens, you may have a look at my qmail follow-up s/qmail (http://fehcom.de/sqmail.html). It does the trick as well (among others). regards. --eh. > Am 26.03.2016 um 11:06 schrieb Jens Bauer <[email protected]>: > > Hi Ed. > > Thank you for the quick answer and suggestions. > > Note: I am already running qmail; I still have the binaries running, but I need to make it work with debian.org. > I do not have the recipe for re-building the exact same version of qmail that I have currently running. > > Can you confirm that John's patch is the *only* patch supporting DENY_TLS and ALLOW_INSECURE_AUTH and REQUIRE_AUTH ? > > If 7.10 is the one I already have installed, then it will not help me installing it again, because it already has the ANY-to-CNAME patch. > -So if that's what I have installed already, then the problem is elsewhere. > > Anyone wanting to test if their qmail works with debian.org and lists.debian.org could try writing a small test e-mail to the debian-user list-bot: > > To: List Bot <[email protected]> > Subject: Hello > Nice weather. I'm just testing my MTA. > > (I get a response if I send the message via telnet, but if I send it through qmail-smtpd, it never leaves my server). > If noone can get a reply from the above mentioned list-bot, I think we might have a bug to find and fix. > > > Love > Jens > > On Sat, 26 Mar 2016 08:52:07 +0000, ed wrote: >> On Sat, Mar 26, 2016 at 03:26:57AM +0100, Jens Bauer wrote: >>> "SMTP Protocol Error: 553 sorry, that domain isn't in my list of >>> allowed rcpthosts; no valid cert for gatewaying (#5.7.1)" >> >>> I am denying any authorization/authentication on port 25. >>> I require secure authorization/authentication on port 587. >> >>> My actual question is: >>> Which patch(es) use "ALLOW_INSECURE_AUTH", "DENY_TLS" and "REQUIRE_AUTH" ? >>> >>> Normally, I would only apply a minimum set of patches, which means >>> I'm not likely to use a "combined patch". >>> Is it *only* the patches from John M. Simpson, or are there others too ? >>> -A lot of arrows point in that direction, which means that I might >>> have stopped rolling my own recipe and used John's patches with my >>> own RCPTCHECK added (I would expect that John's patch would include >>> the "ANY DNS" patch, though). >> >> From what you've said above, I would suggest you get the latest (7.10) >> combined patch[1] and install from his instructions using the various >> run scripts[2]. >> >> 1: <https://qmail.jms1.net/patches/combined-details.shtml> >> 2: <https://qmail.jms1.net/scripts/> >> >> Surprisingly (or not so) that combined set has served me well. The only >> change I've added is some TLS options to prevent SSL2[3]. >> >> 3: <https://www.usenix.org.uk/content/qmail.html> >> >> Using John's patches will at least get you a good stable system with >> minimal effort. >> >> -- >> Best regards, >> Ed http://www.s5h.net/ >> > Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de | PGP Key-Id: EE00CF65
signature.asc
(application/pgp-signature, 842 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJW9nOyAAoJEIP8+SDuAM9lIOMP/RO8L1ZGcdBsG9A6PHMYfcs3 YZbGviwam0Y1gZByEm3567e5BTDC8NbUagicTnQDgvRR7rw/72PTmgIfVb9fE9s0 +nfLqJml0Hw6eZ55gBVuQpyD10L8GPaIZhCQPu9R2giSrYsgyDoAtF5eMvJM6N3/ n0hEYQe6Eck3vvjvUPzKWmXqUE5pIaikA3sNJ1j0tNWaGVO0fNzcGUYH1/PXHOb3 EUdt7TY2KTpAlF3N0xmA2LPbrl9SiiGSCrHLm8sT2Ly81xJ79JGNrIw9SoeEP/8e kQw5ShS/IcD6lnRud6MmxfFPlhxArNDUFb90YV81hZL7aMVV6Ft6Vf1Ki5Z4RO+8 8eh7TcuTWuU4MF4ROzBU8ZYus0y2H6P9JNEgNc6TQQxpaHOHCg90VIbRLxl8Fp7O PCTBzTYrbahL5pPAlDCy18LEsXwOyngdT14fZChN0mry031/wa97bRmwBA80HCNK HIjx4d7MHBHVJccEh5bNm7KygVrmtxpsXwZN/M5J2GXpkuvLT38KU/sEnUmyeRlY sgzbmNJGdtEp5BSD/Ep1fFO6QECWYuRt8m5lagUJgyideVR9/uQ4bZ0NkreVha9F BdJvZX/dTrH8tfsDVYdT7ntC1NymEMpUrUumJlQpzAN/PeJcxKOKvNgStfzHzMZG sZOnWhzYGz6zga0+uCgG =he+h -----END PGP SIGNATURE-----