Re: qmail-remote crashed.

Rejaine Silveira Monteiro <[email protected]> Tue, 19 Feb 2019 09:48:38 -0300
Newsgroups gmane.mail.qmail.general
Message-ID <CAMTrDfXfyyY1kWq9dikDab_47FkxVZODPL1jGA3jBPCxDk9Lgw@mail.gmail.com>
well, after  the certificates again, qmail stopped crashing ..

however outlook.com now started to refuse messages with the error below:

104.47.2.36_failed_after_I_sent_the_message./Remote_host_said:_451_4.7.500_=
Server_busy._Please_try_again_later_from_[a.b.c.d]._(AS77712315)_[DB5EUR01F=
T062.eop-EUR01.prod.protection.outlook.com]/

at the moment I have more than 2 thousand messages in the queue giving
this error ... I believe they are blocking the new IP address ... :(

Em seg, 18 de fev de 2019 =C3=A0s 17:18, Rejaine Silveira Monteiro
<[email protected]> escreveu:
>
> I just renamed *.pem only to take a test.
> I created both certificates again and it's working fine now (the cert
> files had been copied from an older server and with an older version
> of OS and openssl)
>
> Em seg, 18 de fev de 2019 =C3=A0s 17:08, John Johnstone
> <[email protected]> escreveu:
> >
> > On 2/18/19 2:12 PM, Rejaine Silveira Monteiro wrote:
> > > Hi , John J.
> > >
> > > I renamed all files * .pem, restart qmail, and all pending emails for
> > > outlook.com were delivered. I'm still trying to understand what
> > > happened ...  I'll going to do a test generating the keys again (I
> > > believe that the ones that were in use were only copied from the
> > > previous server and not generated again)
> > >
> > > thanks!
> >
> > As many have often pointed out as well as John Simpson himself, having =
a
> > publicly facing mail server is a significant effort.  At the time John'=
s
> > patch was maintained that was true and it's even more so today.  Unless
> > you are investing quite a bit of time with it, you'll be likely to have
> > delivery problems at some point.  As Erwin's suggestions may have given
> > the hint to you, TLS today is a moving target for creating
> > interoperability problems.
> >
> > clientcert.pem is for qmail-remote.  servercert.pem is for qmail-smtpd
> > so if that has also been renamed you have disabled TLS for qmail-smtpd =
also.
> >
> > -
> > John J.
> >
> >
> > > Em seg, 18 de fev de 2019 =C3=A0s 15:33, John Johnstone
> > > <[email protected]> escreveu:
> > >>
> > >> On 2/18/19 12:26 PM, Rejaine Silveira Monteiro wrote:
> > >>> Helo Erwin
> > >>>
> > >>> I'm not using TLS and using qmail-1.03-jms1-7.10.patch  (FORCE_TLS=
=3D0
> > >>> and DENY_TLS=3D1)
> > >>
> > >> I can't offer much help with specific ideas for a solution but I can
> > >> offer some advice about where not to look.
> > >>
> > >> In John Simpson's patch FORCE_TLS and DENY_TLS are only used by
> > >> qmail-smtpd.  They are not used elsewhere.
> > >>
> > >>> anyway, I created the tlsdestinations file as you indicated, but it
> > >>> did not work.
> > >>>
> > >>> the only problem is with clients using mail.protection.outlook.com
> > >>>
> > >>> in the link below you can read that there may be problems with new
> > >>> ips, due to some "policy reputation" stuff  (our mta ip was changed
> > >>> last nigth)  and maybe that is why we can not send it there ..
> > >>>
> > >>> https://docs.microsoft.com/pt-br/office365/securitycompliance/remov=
ing-a-user-domain-or-ip-address-from-a-block-list-after-sending-spam-email
> > >>
> > >> If there is a problem with your IP addresses or domain names being
> > >> acceptable to Microsoft you will be seeing 4yz or 5yz SMTP reply err=
ors
> > >> returned by them to you.  Those errors will be in your qmail-send lo=
g
> > >> files.  Those problems wouldn't cause qmail-remote to crash.
> > >>
> > >>> I publish SPF, but not DMARC or DKIM ... so I guess I'll have to wa=
it
> > >>> a little longer ..
> > >>
> > >> Any changes with SPF, DKIM, etc will not make a difference with
> > >> qmail-remote crashing.
> > >>
> > >> If you have /var/qmail/control/clientcert.pem you can rename that fi=
le
> > >> out of the way so that qmail-remote won't use it.  It will effective=
ly
> > >> disable TLS for qmail-remote.  Just be aware that without TLS you ma=
y
> > >> have delivery problems with certain destinations since some will onl=
y
> > >> accept mail transferred with TLS.
> > >>
> > >> -
> > >> John J.
> > >
> >

--=20
*Esta mensagem pode conter informa=C3=A7=C3=B5es confidenciais ou privilegi=
adas,=20
sendo seu sigilo protegido por lei. Se voc=C3=AA n=C3=A3o for o destinat=C3=
=A1rio ou a=20
pessoa autorizada a receber esta mensagem, n=C3=A3o pode usar, copiar ou=20
divulgar as informa=C3=A7=C3=B5es nela contidas ou tomar qualquer a=C3=A7=
=C3=A3o baseada nessas=20
informa=C3=A7=C3=B5es. Se voc=C3=AA recebeu esta mensagem por engano, por f=
avor avise=20
imediatamente ao remetente, respondendo o e-mail e em seguida apague-o.=20
Agradecemos sua coopera=C3=A7=C3=A3o.*