MESSAGE
DATE | 2022-01-11 |
FROM | raf
|
SUBJECT | Re: [Hangout - NYLXS] Adding Additional domains and outgoing email
|
From hangout-bounces-at-nylxs.com Tue Jan 18 13:16:17 2022 Return-Path: X-Original-To: archive-at-mrbrklyn.com Delivered-To: archive-at-mrbrklyn.com Received: from www2.mrbrklyn.com (www2.mrbrklyn.com [96.57.23.82]) by mrbrklyn.com (Postfix) with ESMTP id 78F06164071; Tue, 18 Jan 2022 13:16:16 -0500 (EST) X-Original-To: hangout-at-nylxs.com Delivered-To: hangout-at-nylxs.com Received: by mrbrklyn.com (Postfix, from userid 1000) id 4821C16402B; Tue, 18 Jan 2022 13:09:14 -0500 (EST) Resent-From: Ruben Safir Resent-Date: Tue, 18 Jan 2022 13:09:13 -0500 Resent-Message-ID: <20220118180913.GY23753-at-www2.mrbrklyn.com> Resent-To: hangout-at-nylxs.com X-Original-To: ruben-at-mrbrklyn.com Delivered-To: ruben-at-mrbrklyn.com Received: from russian-caravan.cloud9.net (russian-caravan.cloud9.net [168.100.1.4]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.cloud9.net", Issuer "Sectigo RSA Domain Validation Secure Server CA" (not verified)) by mrbrklyn.com (Postfix) with ESMTPS id 26EB516400F for ; Tue, 11 Jan 2022 19:15:17 -0500 (EST) Received: by russian-caravan.cloud9.net (Postfix) id 707BA34284D; Tue, 11 Jan 2022 19:14:51 -0500 (EST) Delivered-To: postfix-users-outgoing-at-cloud9.net Received: from localhost (localhost [127.0.0.1]) by russian-caravan.cloud9.net (Postfix) with ESMTP id 6F3243426FE for ; Tue, 11 Jan 2022 19:14:51 -0500 (EST) X-Virus-Scanned: amavisd-new at cloud9.net Received: from russian-caravan.cloud9.net ([127.0.0.1]) by localhost (russian-caravan.cloud9.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AqQmxkeLLwxt for ; Tue, 11 Jan 2022 19:14:51 -0500 (EST) Received: by russian-caravan.cloud9.net (Postfix, from userid 54) id 4F9CB34284F; Tue, 11 Jan 2022 19:14:51 -0500 (EST) Delivered-To: postfix-users-at-cloud9.net Received: from localhost (localhost [127.0.0.1]) by russian-caravan.cloud9.net (Postfix) with ESMTP id 30E1534284D for ; Tue, 11 Jan 2022 19:14:51 -0500 (EST) X-Virus-Scanned: amavisd-new at cloud9.net Received: from russian-caravan.cloud9.net ([127.0.0.1]) by localhost (russian-caravan.cloud9.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xl7owLqI5x8q for ; Tue, 11 Jan 2022 19:14:51 -0500 (EST) Received: from ook.raf.org (ook.raf.org [139.99.156.21]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by russian-caravan.cloud9.net (Postfix) with ESMTPS id 9FE153426FE for ; Tue, 11 Jan 2022 19:14:50 -0500 (EST) Received: from localhost (localhost [127.0.0.1]) by ook.raf.org (Postfix) with ESMTP id 8D1565E268 for ; Wed, 12 Jan 2022 11:14:36 +1100 (AEDT) X-Virus-Scanned: Debian amavisd-new at ook.raf.org Received: from ook.raf.org ([127.0.0.1]) by localhost (ook.raf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wFUBfNPvC_4E for ; Wed, 12 Jan 2022 11:14:34 +1100 (AEDT) Received: by ook.raf.org (Postfix, from userid 1001) id 4E87161C5C; Wed, 12 Jan 2022 11:14:34 +1100 (AEDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=raf.org; s=001; t=1641946474; bh=3rSXSACZLkQ3ewG/LRewnuUDuQErEFq8Vu9NUUQ5QgY=; h=Date:From:To:Subject:References:In-Reply-To:From; b=v7GMs/LUhcfVPeODEbV/QfkHOa98qU2maiTk4RLdsJ3QE3YENpjBfCjqLV7SQwDxU ppsG3TihoLXAj3c1KBcmenZsevzH7u1AJoLobaHFBFzSTvbnLzokfaCgHr9+UNxNIT 4gmI81WqzaogWOdseM2qyyQciM41GxnhTiZpEpNTESe5N3/7Rf4MbSv3VBynuybDom F4LurYALkZ4gn4mB2GJLtX+XKlYLV5NyxqCggu94epAdo44o/0XzEEZ7KM9nhUqTPN 1ji6Fk/h4w6ShnyLqHk2hLbWISD4G7yDs02WCO7Zc6AebixAXhZNxTs44HBzS07ors lFr55vWH6wtRQ== Date: Wed, 12 Jan 2022 11:14:34 +1100 From: raf To: postfix-users-at-postfix.org Message-ID: Mail-Followup-To: postfix-users-at-postfix.org References: <8e8e3633-1574-aea2-ef68-bb6cea73e751-at-mrbrklyn.com> <20211222052031.GA4914-at-www2.mrbrklyn.com> <20220103182959.GA9594-at-www2.mrbrklyn.com> <20220105091026.GA30311-at-www2.mrbrklyn.com> <20220111182049.GA5739-at-www2.mrbrklyn.com> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20220111182049.GA5739-at-www2.mrbrklyn.com> Precedence: bulk Subject: Re: [Hangout - NYLXS] Adding Additional domains and outgoing email X-BeenThere: hangout-at-nylxs.com X-Mailman-Version: 2.1.30rc1 List-Id: NYLXS Tech Talk and Politics List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: hangout-bounces-at-nylxs.com Sender: "Hangout"
On Tue, Jan 11, 2022 at 01:20:49PM -0500, Ruben Safir wrote:
> On Thu, Jan 06, 2022 at 02:09:45PM +1100, raf wrote: > > On Wed, Jan 05, 2022 at 04:10:26AM -0500, Ruben Safir wrote: > > > > > > > > /etc/postfix/main.cf: > > > > > > smtpd_sasl_type = dovecot > > > > > > smtpd_sasl_path = private/auth > > > > > > > > > > Can't this be done with tls withouth dovecot or sasl? > > > > > > > > Authentication is needed by Dovecot for IMAP access > > > > to read email. So it should be available for use by > > > > Postfix as well. > > > > > > It is not working anyway. The reason is that > > A) It won't relay > B) The IP addresses are mmarked in spamhoause as not valid for email > service > > Outbound Email policy of Cablevision/OptimumOnline for this IP range > > (Jan 2007) Email sent from this IP block via port 25 (SMTP) should only > be sent via the designated outbound mail server for Optimum Online > customers: mail.optimum.net The use of port 25 is obsolete, you should > use port 465/TLS (SMTPS) or port 587 (SMTP-Submit /w STARTTLS) to send > mail, whether you are using Optimum's server or a third-party ISP's > server. > > See OOL's support site at > http://optimum.custhelp.com/cgi-bin/optimum.cfg/php/enduser/std_adp.php?p_faqid=39 > > Standard-tier OOL customers are blocked from sending/receiving mail via > port 25 (SMTP) to any other servers since 2004. See OOL support site: > http://optimum.custhelp.com/cgi-bin/optimum.cfg/php/enduser/std_adp.php?p_faqid=876 > > You may send mail via another ISP by using SMTP-Submit (port 587) or > SMTPS (port 465/TLS) service, if your third-party ISP's mail server > supports this service. > > It is hiting on port 587 so I don't know a way around this that is > satisfactory. it is BS and annoying > http://optimum.custhelp.com/cgi-bin/optimum.cfg/php/enduser/std_adp.php?p_faqid=876http://optimum.custhelp.com/cgi-bin/optimum.cfg/php/enduser/std_adp.php?p_faqid=876
The above sounds very different to what I thought you were talking about. I thought you were saying that *your* Postfix server wasn't relaying email for your users, and that some form of user authentication (Dovecot SASL or TLS client certificates) was needed locally to be able to allow relaying *by* your Postfix server.
The above sounds like your problem is that your Postfix server needs to send all outgoing mail via a specific *remote* mail server (Cablevision/OptimumOnline), and that *it* won't relay your email unless your Postfix server authenticates itself to that remote server, so that that remote server will be willing to relay mail that comes out of your Postfix server. That's a very different problem.
If that's the case, your Postfix doesn't need access to Dovecot's SASL abilities, or to TLS client certificates. It just needs to connect to the remote mail server in the way that that server requires, by sypplying a username and password to it.
I think it could look something like this:
/etc/postfix/main.cf: transport_maps = hash:/etc/postfix/transport smtp_sasl_auth_enable = yes smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
/etc/postfix/transport: * relay:[mail.optimum.net]:587
/etc/postfix/sasl_password: USER-at-mail.optimum.net:PASSWORD
But a transport map is probably overkill if it applies to all outgoing mail. I think that the transport_maps parameter and the transport file can be replaced by the relayhost parameter:
relayhost = [mail.optimum.net]:587
But you'd still need the smtp_sasl_auth_enable and smtp_sasl_password_maps parameters, and the sasl_password file.
I hope that makes some sense. But I still don't understand your statement that "It is hitting on port 587" I'm not sure what you mean by "It". Is "It" your Postfix server connecting to the remote ISP mail server on port 587, and failing to authenticate there? If so, the above should help. But if you are referring to something connecting to your Postfix server on port 587, then I'm probably still misundertanding the nature of your problem.
cheers, raf
P.S. The URLs above are inaccessible. Perhaps they only exist for their customers. The optimum.custhelp.com domain doesn't even resolve to an address for me. _______________________________________________ Hangout mailing list Hangout-at-nylxs.com http://lists.mrbrklyn.com/mailman/listinfo/hangout
|
|