Re: [milter-greylist] curl urlcheck and ldapcheck authentication
2009-05-13 by Emmanuel Dreyfus
... If you specify a ldaps:// URL, you can use x509 authentication. Your ldap.conf will have to contain references to CA, certificate and private key. --
Yahoo Groups archive
Messages
Page 42 of 144 · 7199 messages matched
2009-05-13 by Emmanuel Dreyfus
... If you specify a ldaps:// URL, you can use x509 authentication. Your ldap.conf will have to contain references to CA, certificate and private key. --
2009-05-13 by Piotr Wadas
Hello, what s about authentication to external preferences source, using urlcheck/ldapcheck keywords ? Curl probably supports
2009-05-12 by Petar Bogdanovic
... If you refer to the small patch in this thread, please no. Since it doesn t work with postfix, it s not good yet. The other one I posted in an other
2009-05-12 by manu@netbsd.org
... Shall I commit your change, or hold my breath, after all? -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2009-05-12 by Petar Bogdanovic
... Seems to me like the file is corrupt. ... Right.. I guess you re running spamd without -x. ... Nice. I had always troubles catching this line since it has
2009-05-12 by Petar Bogdanovic
... Cleanup spamd_rcvhdr(), adjust fake Received:-header and make it look like a real one created by Sendmail. This new header will finally trigger the
2009-05-12 by manu@netbsd.org
... What do I add in ChangeLog, after all? -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2009-05-12 by Jim Hermann
... I made the changes manually. It works fine. #cat maillog | grep n4C3DdF2019852 [snip] May 11 22:13:40 host spamd[19237]: spamd: handle_user unable to find
2009-05-12 by Jim Hermann
... I don t know much about running patch. This is the response I got: # patch -p0
2009-05-11 by Petar Bogdanovic
... New patch is attached. Tested, seems to work. Petar Bogdanovic Index: spamd.c =================================================================== RCS
2009-05-11 by Petar Bogdanovic
... At least you can t rely on the value of this header since the only thing which prevents you from providing a bogus value is a correctly compiled spamc or a
2009-05-11 by Petar Bogdanovic
... I m not entirely sure but this (optional) header seems to be pretty useless otherwise. We could add a prefix in order to make it distinguishable from
2009-05-11 by Emmanuel Dreyfus
... Is it reasonable to abuse the User field? -- Emmanuel Dreyfus manu@netbsd.org
2009-05-11 by Petar Bogdanovic
... Pushing the queue-id to spamd requires less work and doesn t make some maillog entries redundant. Could you please test the attached patch? Petar
2009-05-11 by manu@netbsd.org
... Sure we can, the most difficult thing is to find an available % letter ... -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2009-05-11 by Jim Hermann
... That s the only time I want the queue-id, after the DATA stage, when I run spamd. Couldn t we get some FORMAT STRINGS to allow logging some additional
2009-05-11 by manu@netbsd.org
... The message-id is not known before the DATA stage, this why you cannot have it everywhere. -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2009-05-10 by Jim Hermann
... All the maillog entries contain the queue-id. Only a few contain the message-id. It s a two-step process to find the recipient from the spamd report or
2009-05-10 by Petar Bogdanovic
... I assume that s a queue-id. ... We could abuse the `User: spamd protocol header. But I m not sure about the benefit of such a change. What do you want
2009-05-10 by Jim Hermann
milter-greylist community, Is there some way to pass more information to spamd, so that it would log some additional information? Currently, spamd logs only
2009-05-10 by Petar Bogdanovic
... Not [1]spamd but [2]spamd. (man greylist.conf) Petar Bogdanovic [1] http://www.openbsd.org/spamd/ [2]
2009-05-09 by Michael Mansour
Hi, ... Does this mean that you have to be running spamd to take advantage of that code? Michael.
2009-05-09 by Petar Bogdanovic
... Minor correction. Index: spamd.c =================================================================== RCS file: /milter-greylist/milter-greylist/spamd.c,v
2009-05-09 by Petar Bogdanovic
... Ok, I dug through some pieces of the sendmail code and did some tests on an emulated Ubuntu installation: It seems that the way milter-greylist logs
2009-05-09 by manu@netbsd.org
... There are certainly people out of there that made scripts to parse milter-greylist log output. If you change the behaviour, this is nasty for them. IMO the
2009-05-09 by Petar Bogdanovic
... I m not sure if that should be implemented as an option. The injected Received:-header for that specific situation doesn t look like it was generated by
2009-05-09 by manu@netbsd.org
... What about adding an option to enable it, so that we can have in integrated without breaking other user s log parsing scripts? -- Emmanuel Dreyfus
2009-05-09 by Bill Levering
I created a wiki page about this: http://milter-greylist.wikidot.com/postfix
2009-05-08 by Petar Bogdanovic
... Yes, that would be good to know so please report back. Petar Bogdanovic
2009-05-08 by Adam Katz
... Ah, yes. Thanks for reminding me. That s postfix-specific, so since I m on sendmail, I guess a trial to determine if that issue surfaces will be in
2009-05-08 by Petar Bogdanovic
... We use the SA module since it was imported. Runs fine. You should consider [1]this patch when running SA from milter-greylist. Petar Bogdanovic [1]
2009-05-08 by manu@netbsd.org
... Checked in. -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2009-05-08 by manu@netbsd.org
... I have been using geoIP and p0f for months without any problem. I cannot comment on DKIM and SpamAssassin. -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz
2009-05-08 by Adam Katz
Oops, hotmail et al fire on that as their servers are (erroneously?) detected as Windows 2000 SP4, XP SP1+ ... Solution: put this before the p0f stuff: list
2009-05-08 by Adam Katz
reload checks config first (force-reload and restart do not). TODO: abstractions. This is probably easily applied to the other init scripts, too.
2009-05-08 by Adam Katz
I ve become quite the SpamAssassin guru in the last few years; I m quite active in users@spamassassin.apache.org and on irc://irc.freenode.net/#spamassassin
2009-05-08 by Adam Katz
... Perfect! Assuming DKIM works, could I do this: list verified dkim domain { ebay.com gmail.com google.com } dacl whitelist verified dkim dkim verify
2009-05-08 by Jorge García Oncins
Hi, We have been using this method for moths with milter-greylist 4.0 and works very well. It was the way we found to emulate the spf status selections in
2009-05-08 by manu@netbsd.org
... Perhaps something like this will do the trick? list spf domain { gmail.com yahoo.com paypal.com } racl whitelist list spf spf pass racl blacklist list
2009-05-08 by Adam Katz
... Yeah, I realized that soon after writing; the example should have said dacl, or even better, should have stuck to just SPF. ... I have no idea. I just
2009-05-08 by manu@netbsd.org
... I beleive you cannot filter on DKIM at RCPT stage, since the information used by DKIM to decide the message status is in the message headers. But does the
2009-05-07 by Adam Katz
A growing number of spammers are using anti-spam tools like SPF and DKIM (and even DNSWL) these days. Therefore, specifying global rules for behavior in
2009-04-21 by John Thiltges
... I agree on the readability. How about changing fstring_expand() to work like snprintf()? Passing a destination buffer could (hopefully) avoid a
2009-04-20 by manu@netbsd.org
Here is the latest developement version: http://ftp.espci.fr/pub/milter-greylist/milter-greylist-4.3.2.tgz MD5 (milter-greylist-4.3.2.tgz) =
2009-04-17 by manu@netbsd.org
... Well, this gets suddently much less readable :-) -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2009-04-17 by John Thiltges
... Would it be better to make aclstr[] a larger static buffer and not use fstring_expand()? Example: char aclstr[HDRLEN]; if (priv- priv_sr.sr_acl_id)
2009-04-17 by manu@netbsd.org
... What tabout the performance impact of this change? Now we go to fstring_expand() regardless of the existance of an ACL id string, and that function at
2009-04-16 by manu@netbsd.org
Here is our latest developement snapshot. Next snapshot will include Rudy Eschauzier s work on multiple backends.
2009-04-16 by manu@netbsd.org
... I committed it on head, you will have it in 4.3.1 -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2009-04-15 by John Thiltges
Hi all, I recently upgraded to milter-greylist 4.2.2. I was looking forward to using the feature of adding an id string to ACL entries and easily gathering