| Linode Forum https://forum.linode.com/ |
|
| can't get smtp auth in postfix https://forum.linode.com/viewtopic.php?f=11&t=8077 |
Page 1 of 1 |
| Author: | kp_mastermind [ Sat Nov 19, 2011 10:35 am ] |
| Post subject: | can't get smtp auth in postfix |
Command: telnet localhost 25 Trying 127.0.0.1... Connected to localhost. Escape character is '^]'. 220 terabug.terabug.com ESMTP Postfix (Ubuntu) ehlo localhost 250-terabug.terabug.com 250-PIPELINING 250-SIZE 30720000 250-VRFY 250-ETRN 250-STARTTLS 250-ENHANCEDSTATUSCODES 250-8BITMIME 250 DSN I have done all sasl setting files as per this guide: http://library.linode.com/email/postfix ... 0.04-lucid Dovecot was having error yesterday, somehow it got fixed. Dovecot is working fine ( I guess because of I installed dovecot-postfix) My sasl files: /etc/default/saslauthd Code: # file:/etc/pam.d/smtp Code: auth required pam_mysql.so user=mail_admin passwd=mail_admin_pass host=127.0.0.1 db=mail table=users usercolumn=email passwdcolumn=password crypt=1 file:/etc/postfix/sasl/smtpd.conf Code: pwcheck_method: saslauthd file:/etc/postfix/master.cf Code: # file:/etc/postfix/main.cf Code: # See /usr/share/postfix/main.cf.dist for a commented, more complete version file:/etc/dovecot/dovecot.conf Code: protocols = imap imaps pop3 pop3s Please let me know steps to get 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN in smtp outgoing mail. Thanks in advance. |
|
| Author: | derfy [ Sat Nov 19, 2011 11:12 am ] |
| Post subject: | |
You *might* be ok; my server won't display SASL options until a remote server tries to STARTTLS, and you've got that handled: Quote: derfy@derfy:~$ openssl s_client -starttls smtp -crlf -connect terabug.terabug.com:25
CONNECTED(00000003) depth=0 /C=IN/ST=Gujarat/L=Ahmedabad/O=TeraBug/OU=Email Services/CN=terabug.terabug.com/emailAddress=<snip for spam> verify error:num=18:self signed certificate verify return:1 depth=0 /C=IN/ST=Gujarat/L=Ahmedabad/O=TeraBug/OU=Email Services/CN=terabug.terabug.com/emailAddress=<snip for spam> verify return:1 --- Certificate chain 0 s:/C=IN/ST=Gujarat/L=Ahmedabad/O=TeraBug/OU=Email Services/CN=terabug.terabug.com/emailAddress=<snip for spam> i:/C=IN/ST=Gujarat/L=Ahmedabad/O=TeraBug/OU=Email Services/CN=terabug.terabug.com/emailAddress=<snip for spam> --- Server certificate -----BEGIN CERTIFICATE----- MIIEETCCAvmgAwIBAgIJALkz1oDOPUbNMA0GCSqGSIb3DQEBBQUAMIGeMQswCQYD VQQGEwJJTjEQMA4GA1UECAwHR3VqYXJhdDESMBAGA1UEBwwJQWhtZWRhYmFkMRAw DgYDVQQKDAdUZXJhQnVnMRcwFQYDVQQLDA5FbWFpbCBTZXJ2aWNlczEcMBoGA1UE AwwTdGVyYWJ1Zy50ZXJhYnVnLmNvbTEgMB4GCSqGSIb3DQEJARYRa3VuYWxAdGVy YWJ1Zy5jb20wHhcNMTExMTE5MTE1NzI5WhcNMTIxMTE4MTE1NzI5WjCBnjELMAkG A1UEBhMCSU4xEDAOBgNVBAgMB0d1amFyYXQxEjAQBgNVBAcMCUFobWVkYWJhZDEQ MA4GA1UECgwHVGVyYUJ1ZzEXMBUGA1UECwwORW1haWwgU2VydmljZXMxHDAaBgNV BAMME3RlcmFidWcudGVyYWJ1Zy5jb20xIDAeBgkqhkiG9w0BCQEWEWt1bmFsQHRl cmFidWcuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0cAyEip1 w7P5f7wuibfzQUsPt5cPTgA0TDXUdlWsgoqunt+cAvQNO5lQCVBkdrhqAu61espb ZZt7MFWkxszz009jZl6Mnce0ljaJYfbOkfxL5q0Gy8SSW4jgZcFnk/sIy6uwmZJv sJc79Ng4i07Xlx2jyVdLA0BXslPUP1rMEbgNzvdb7TjmiQVG8D2BMv1z/sBlyyv2 TILLTLY5Nh+xCRzgCoO2W1/oD6yp8/6NwkstHlS76N/wCXizaTipfu6jjqQWNoVF Nyzpm7/GZihrcsPoXNE325ZRiCPWNsqegMDWcoHASEYx2fckQYz5tvt3Wx7dv4o1 oe8EmynCtcRytwIDAQABo1AwTjAdBgNVHQ4EFgQUyRE2c6SNSLIk2cRC5qCHdZ2L uBAwHwYDVR0jBBgwFoAUyRE2c6SNSLIk2cRC5qCHdZ2LuBAwDAYDVR0TBAUwAwEB /zANBgkqhkiG9w0BAQUFAAOCAQEARpvCZpqsJdOFHsM+3pN57WaEdrWGxSqb8wy8 4NaIMJRxhZ6Fy1ly2Zz3/ItHHqnwACRMKUVsVg380M9fApHBmCKrWc33oz6/syRr uYRwNybzXR+4UJM9JhBd3u7pVsIM6Wbf69I6+1J3P/CZYI7Ok7VBTAG7VwKB0RQz 91icJA8qoEM9ir4cvlURX8lkEbkYbGryqEdyBs/RuW/wOqA4Y19wI5OTXazfKzym pm62MPcS0odGXWj7mCf9oXJ5z0k53RJLLE5sL2H3QhZ4DC8Z9gs9xxO7WqF1oPu8 qp8MPtXRKrG1+pQIt1bx0J908MlYf4z+EvGGQmSRxva/gNnZyA== -----END CERTIFICATE----- subject=/C=IN/ST=Gujarat/L=Ahmedabad/O=TeraBug/OU=Email Services/CN=terabug.terabug.com/emailAddress=<snip for spam> issuer=/C=IN/ST=Gujarat/L=Ahmedabad/O=TeraBug/OU=Email Services/CN=terabug.terabug.com/emailAddress=<snip for spam> --- No client certificate CA names sent --- SSL handshake has read 1964 bytes and written 354 bytes --- New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE SSL-Session: Protocol : TLSv1 Cipher : DHE-RSA-AES256-SHA Session-ID: 254552E12B923EA82F9AD59F505E096A3A02B5A54F1B081E9F20C3BAC3022E64 Session-ID-ctx: Master-Key: EBA91626733D04272F74601CAD8FD47CAE3739816AA51BC5F98A9F5C1159BB4FFEDBC02F80A982035F4DC45D0879085B Key-Arg : None Start Time: 1321715217 Timeout : 300 (sec) Verify return code: 18 (self signed certificate) --- 250 DSN ehread:errno=0 derfy@derfy:~$ However, you'll probably want to wait until someone more qualified can help. :) |
|
| Author: | kp_mastermind [ Sat Nov 19, 2011 11:19 am ] |
| Post subject: | |
Is this means anyone can send mail from my server? When I send a mail from windows live mail it does not ask/promote from login id password. It gives me following relay error Code: The message could not be sent. The setting for your outgoing email [SMTP] server might need to be configured. To find the server settings for 'a***d@k**s**ts.com', please contact your email service provider. |
|
| Author: | derfy [ Sat Nov 19, 2011 11:30 am ] |
| Post subject: | |
Try setting it to use port 465 and/or TLS on port 25 in Windows Live Mail (I do not use it so have no idea how). From the log you posted, it looks like it's not even trying to STARTTLS. |
|
| Author: | kp_mastermind [ Sat Nov 19, 2011 11:36 am ] |
| Post subject: | |
Tried to set Secured connection. Connection got rejected. Tried to change port. Connection got rejected. ehlo localhost is not showing 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN so sasl is not set. Also tell me is this mean anyone can send mail using my server? |
|
| Author: | derfy [ Sat Nov 19, 2011 4:01 pm ] |
| Post subject: | |
http://www.postfix.org/TLS_README.html wrote: Supporting AUTH over TLS only
Sending AUTH data over an unencrypted channel poses a security risk. When TLS layer encryption is required ("smtpd_tls_security_level = encrypt" or the obsolete "smtpd_enforce_tls = yes"), the Postfix SMTP server will announce and accept AUTH only after the TLS layer has been activated with STARTTLS. When TLS layer encryption is optional ("smtpd_tls_security_level = may" or the obsolete "smtpd_enforce_tls = no"), it may however still be useful to only offer AUTH when TLS is active. To maintain compatibility with non-TLS clients, the default is to accept AUTH without encryption. In order to change this behavior, set "smtpd_tls_auth_only = yes". By your first post, you do have this set and as such, the postfix server will not announce 250 AUTH... without a STARTTLS. Your master.cf shows that submission/smtps is functional; however you may need to open these ports in your firewall. Also no, your server cannot be used to relay (unless of course you or your users have easily crackable username/passwords) |
|
| Author: | kp_mastermind [ Sun Nov 20, 2011 9:03 am ] |
| Post subject: | |
Someone please help me. Tried everything but didn't help. Can't send mail from Live mail client. Please go through all posts. |
|
| Page 1 of 1 | All times are UTC-04:00 |
| Powered by phpBB® Forum Software © phpBB Group http://www.phpbb.com/ |
|