-->
ラベル postfix の投稿を表示しています。 すべての投稿を表示
ラベル postfix の投稿を表示しています。 すべての投稿を表示

2011-11-18

メールが届かない(clamdが起動していない)

メールが届いていない。
$ sudo tail -n1 /var/log/mail.err
Nov 18 03:37:59 amdgentoo dovecot: master: Error: service(imap-login): command startup failed, throttling

$ sudo tail -n4500 /var/log/mail.log | lv
...
Nov 18 06:10:17 amdgentoo postfix/pickup[4409]: warning: 7D08E16D908: message has been queued for 1 days
Nov 18 06:10:17 amdgentoo postfix/pickup[4409]: 7D08E16D908: uid=0 from=<root>
Nov 18 06:10:17 amdgentoo postfix/cleanup[18504]: 7D08E16D908: message-id=<20111117211017.7D08E16D908@amdgentoo.localnet>
Nov 18 06:10:17 amdgentoo postfix/cleanup[18504]: 7D08E16D908: milter-reject: END-OF-MESSAGE from localhost[127.0.0.1]: 4.7.1
Service unavailable - try again later; from=<root@amdgentoo.localnet> to=<root@amdgentoo.localnet>
...

大量に下記のエラーが発生している。書き込めなくなっている。
$ sudo tail -f /var/log/clamav/clamav-milter.log
...
ERROR: Failed to initiate streaming/fdpassing
WARNING: No clamd server appears to be available
...

最大値を増やす。
$ rcsdiff /etc/config-archive/etc/clamav-milter.conf,v /etc/clamav-milter.conf
===================================================================
RCS file: /etc/config-archive/etc/clamav-milter.conf,v
retrieving revision 1.7
diff -r1.7 /etc/clamav-milter.conf
231c231
< #LogFileMaxSize 2M
---
> LogFileMaxSize 20M

clamav-milter.logのローテーションの設定は無い。
$ qlist clamav|grep /etc/logrotate.d/
/etc/logrotate.d/clamav

サイズを増やすと同じエラーが書き込まれる。
$ ll -h /var/log/clamav/clamav-milter.log
-rw-r----- 1 clamav clamav 1.4M 2011-11-18 06:10:26 /var/log/clamav/clamav-milter.log

/etc/conf.d/clamdがいつのまにか下記のようになっている。
MILTER_NICELEVEL=19
START_MILTER=yes

戻した。
$ diff -u -U16 /usr/portage/app-antivirus/clamav/files/clamd.conf /etc/conf.d/clamd
--- /usr/portage/app-antivirus/clamav/files/clamd.conf  2008-03-01 08:46:46.000000000 +0900
+++ /etc/conf.d/clamd   2011-11-18 06:22:12.601252509 +0900
@@ -1,9 +1,11 @@
 # Config file for /etc/init.d/clamd

 # NOTICE: Since clamav-0.85-r1, only START_CLAMD and START_FRESHCLAM settings
 #        are used, other are silently ignored

 START_CLAMD=yes
 START_FRESHCLAM=yes
 CLAMD_NICELEVEL=3
 FRESHCLAM_NICELEVEL=19
+MILTER_NICELEVEL=19
+START_MILTER=yes

デフォルト値はyesが無いとclamdなどは起動しない。
$ grep START_CLAMD /etc/init.d/clamd
        if [ "${START_CLAMD}" = "yes" ]; then
        if [ "${START_CLAMD}" = "yes" ]; then
        if [ "${START_CLAMD}" = "yes" ]; then

メールが送れない状態。
$ pstree clamav
clamav-milter───2*[{clamav-milter}]

メールが送れる状態。
$ pstree clamav
clamav-milter───2*[{clamav-milter}]

clamd───{clamd}

freshclam

システム更新時に起動時のデフォルト値が変わりそれに合わせて設定を更新したが、
しかし起動時のデフォルト値は戻った、といった原因かもしれない。
もしくは何かの都合で/etc/conf.d/clamdの設定を手動で減らしたのかもしれない。

2011-06-30

postfixのtransport_maps

参考URL。
http://zsrv.s43.xrea.com/content/view/33/30/
http://d.hatena.ne.jp/matzmura/20080316/1205672821
http://www.eva-01.jp/wiki/pukiwiki.php?Sendmail%2FSTARTTLS
http://www.postfix.org/transport.5.html
http://www.postfix-jp.info/trans-2.3/jhtml/transport.5.html

この例の場合プロバイダのメールサーバーからgmailに送れるので意味はないです。
また認証に使ったユーザー以外のgmailへ送れるかどうか試していないです。

certificate verification failed for smtp.gmail.com ...
$ qfile /etc/ssl/certs/
app-misc/ca-certificates (/etc/ssl/certs)
dev-libs/openssl (/etc/ssl/certs)

plain固定ではなくlogin無効で他は有効にした。
$ rcsdiff /etc/config-archive/etc/postfix/main.cf,v /etc/postfix/main.cf
===================================================================
RCS file: /etc/config-archive/etc/postfix/main.cf,v
retrieving revision 1.12
diff -r1.12 /etc/postfix/main.cf
663c663
< smtp_sasl_mechanism_filter = plain
---
> smtp_sasl_mechanism_filter = !login, static:all
665a666,669
>
> smtp_tls_CApath = /etc/ssl/certs
> smtp_use_tls = yes
> transport_maps = hash:/etc/postfix/transport

デフォルト値。
$ postconf -d|grep -iP "^(transport_maps|smtp_use_tls|smtp_tls_CApath)\s*="
smtp_tls_CApath =
smtp_use_tls = no
transport_maps =

パスワード追加。
$ /usr/bin/sudo /usr/bin/rcsdiff /etc/config-archive/etc/postfix/saslpass,v /etc/postfix/saslpass
===================================================================
RCS file: /etc/config-archive/etc/postfix/saslpass,v
retrieving revision 1.2
diff -r1.2 /etc/postfix/saslpass
3a4
> [smtp.gmail.com]:submission  ユーザー名:パスワード

ドメインが gmail.com の場合 smtp.gmail.com を利用する。
$ sudo cat transport
gmail.com smtp:[smtp.gmail.com]:submission

smtp_sasl_mechanism_filter = !login, !plain, static:all にしたらXOAUTHというのを使うのか?と思ったが、送れなかった。
$ openssl s_client -connect smtp.gmail.com:587 -starttls smtp
...
250-AUTH LOGIN PLAIN XOAUTH
...

クライアント側に対応がない。
# smtp_sasl_mechanism_filter = !login, !plain, static:all
warning: SASL authentication failure: No worthy mechs found

サーバー側に対応がない。
# smtp_sasl_mechanism_filter = gssapi
(SASL authentication failed: server xxx[xxx] offered no compatible authentication mechanisms for this type of connection security)

2011-06-29

サブミッションポート

これはsmtpサーバーではなくsmtpクライアントの設定です。
587番ポートをLISTENしません。

修正: ローカルネットワーク上の他のサーバーから25番ポートでメールを受け取って、
それをプロバイダのメールサーバーの587番ポートにリレーするような感じです。
自身は587番ポートをLISTENしません。
$ sudo netstat -anp|grep -P ":(25|587)\s"
tcp        0      0 0.0.0.0:25              0.0.0.0:*               LISTEN      6807/master

追記: amdgentooのpostfixとwindowsXPのThunderbird(メールソフト)は、
それぞれプロバイダのメールサーバーの接続情報を持っている。
他のサーバーのpostfixはamdgentooにメールを渡す。
図。
┌──────────┐  ┌──┬─────┐  ┌────┐  ┌───┬─────────────┐
│他のサーバー        ├┬┤25番│amdgentoo ├┬┤ルーター├─┤587番 │プロバイダのメールサーバー│
│relayhost=amdgentoo ││└──┴─────┘│└────┘  └───┴─────────────┘
└──────────┘│                    │
 ...                    │                    │
┌──────────┐│                    │
│他のサーバー        ├┘                    │
│relayhost=amdgentoo │                      │
└──────────┘                      │
                                              │
┌─────┐                                │
│windowsXP ├────────────────┘
└─────┘

追記: 他のサーバーはamdgentooに渡す設定のみ。
$ rcsdiff -r1.6 /etc/config-archive/etc/postfix/main.cf,v /etc/postfix/main.cf
===================================================================
RCS file: /etc/config-archive/etc/postfix/main.cf,v
retrieving revision 1.6
diff -r1.6 /etc/postfix/main.cf
76a77
> myhostname = cogentoo-1.localnet
83a85
> mydomain = localnet
315c317
< relayhost = xxx.xxx.xxx
---
> relayhost = amdgentoo.localnet

プロバイダの説明を探してメールサーバーの設定を修正します。
サブミッションポート, OP25B, ポート587 など。

現在のmain.cf。
/usr/portage/packages/mail-mta/postfix-2.7.4.tbz2のファイルとの差分。(emerge ... -b postfix)
relayhostとsmtp_sasl_auth_enable以下の記述がサブミッションポート用の変更点。
$ diff ./etc/postfix/main.cf /etc/postfix/main.cf
76a77
> myhostname = amdgentoo.localnet
83a85
> mydomain = localnet
262a265
> mynetworks = xxx.xxx.xxx.xxx/8 xxx.xxx.xxx.xxx/24
313a317
> relayhost = プロバイダのメールサーバー:587
652a657,665
>
> smtpd_milters         = unix:/var/run/clamav/clamav-milter.sock
> non_smtpd_milters     = unix:/var/run/clamav/clamav-milter.sock
> milter_default_action = accept
>
> smtp_sasl_auth_enable = yes
> smtp_sasl_mechanism_filter = plain
> smtp_sasl_password_maps = hash:/etc/postfix/saslpass
> smtp_sasl_security_options = noanonymous

デフォルト値。
$ postconf -d|grep -iP "^(smtp_sasl_auth_enable|smtp_sasl_password_maps|smtp_sasl_mechanism_filter|smtp_sasl_security_options)\s*="
smtp_sasl_auth_enable = no
smtp_sasl_mechanism_filter =
smtp_sasl_password_maps =
smtp_sasl_security_options = noplaintext, noanonymous

saslpass修正。
$ sudo vi saslpass
$ /usr/bin/sudo /usr/bin/rcsdiff /etc/config-archive/etc/postfix/saslpass,v /etc/postfix/saslpass
===================================================================
RCS file: /etc/config-archive/etc/postfix/saslpass,v
retrieving revision 1.1
diff -r1.1 /etc/postfix/saslpass
3a4
> プロバイダのメールサーバー ユーザー名:パスワード
$ sudo postmap saslpass

認証方式の確認。
$ telnet プロバイダのメールサーバー 587
Trying xxx.xxx.xxx.xxx...
Connected to プロバイダのメールサーバー.
Escape character is '^]'.
220 xxxxxxxx.example.com ESMTP
EHLO xxx.xxx.xxx.xxx           # EHLO IPアドレス などを入力する。
250-xxxxxxxx.example.com
250-PIPELINING
250-SIZE 20971520
250-ETRN
250-AUTH LOGIN PLAIN
250-AUTH=LOGIN PLAIN
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN
quit                           # 終了。quitを入力する。
221 2.0.0 Bye
Connection closed by foreign host.

この例の場合で smtp_sasl_mechanism_filter 無しの場合、
smtp_sasl_mechanism_filter = login, plain
と同じ。無しで下記を使う。
250-AUTH LOGIN PLAIN
250-AUTH=LOGIN PLAIN
例えば 250-AUTH LOGIN PLAIN XXX とある場合、
smtp_sasl_mechanism_filter = XXX にしても良いです。
もしくは smtp_sasl_security_options に noplaintext を追加します。

他のlinuxは relayhost = amdgentoo.localnet を経由し、windowsは直接同じような指定をしています。

MX検索を無効にする場合。+ポートを文字にする場合。
$ rcsdiff -r1.11 /etc/config-archive/etc/postfix/main.cf,v /etc/postfix/main.cf
===================================================================
RCS file: /etc/config-archive/etc/postfix/main.cf,v
retrieving revision 1.11
diff -r1.11 /etc/postfix/main.cf
317c317
< relayhost = プロバイダのメールサーバー:587
---
> relayhost = [プロバイダのメールサーバー]:submission
$ grep 587 /etc/services
submission      587/tcp                         # mail message submission
submission      587/udp

他。
送信者単位での認証(smtp_sender_dependent_authentication = yes)、
プロバイダごとのsmtpサーバーを直接指定など(/etc/postfix/transport)

参考URL。
http://www.postfix-jp.info/trans-2.2/jhtml/postconf.5.html
http://www.postfix.org/postconf.5.html#smtp_sasl_mechanism_filter
http://kazuizm.com/2006/12/28-072720.php
http://statphys.scphys.kyoto-u.ac.jp/~akihiko/linux/docomo.html
http://www.ecoop.net/memo/2007-03-31-1.html
http://www.aconus.com/~oyaji/mail2/op25b.htm
http://www.geocities.jp/yukke_no_kobeya/kurobako/fe8_130.html
http://www.postfix-jp.info/trans-2.3/jhtml/SASL_README.html#client_sasl
http://www.melnikov.ca/mel/devel/SASL_info.html
http://gmt-24.net/archives/181
http://www.itscom.net/support/security/op25b/submission.html
http://www.itscom.net/support/setup/internet/mailer/sub_smtp_thunderbird2_its.html
http://www.postfix-jp.info/trans-2.3/jhtml/postconf.5.html#smtp_sender_dependent_authentication
http://www.postfix-jp.info/trans-2.3/jhtml/transport.5.html

2010-02-09

Connection lost in middle of processing

この記事は postfix の参考です。

単純なのが良いのでメール送信ソフトをssmtpにしていたが配送に失敗すると再送されません。
$ sudo grep "Connection lost in middle of processing" /var/log/mail.log*
Feb  6 00:15:02 amdgentoo sSMTP[3295]: Connection lost in middle of processing
Feb  9 00:15:05 amdgentoo sSMTP[16511]: Connection lost in middle of processing
Feb  9 02:36:04 amdgentoo sSMTP[2334]: Connection lost in middle of processing

postfixに変更しました。
/etc/postfix/main.cf, /etc/mail/aliases の変更箇所
$ diff /etc/postfix/main.cf.2010-02-09 /etc/postfix/main.cf; echo "==="; diff /etc/mail/aliases.2010-02-09 /etc/mail/aliases
262a263
> mynetworks = 127.0.0.0/8
313a315
> relayhost = プロバイダのsmtpサーバー
===
18a19
> root:自分のメールアドレス

インストールのコマンドの概要
$ sudo emerge -Cav ssmtp
$ sudo emerge -av postfix 
$ cd /etc/postfix
$ sudo cp -i main.cf main.cf.`date +%Y-%m-%d`
$ sudo vi main.cf
$ cd /etc/mail
$ sudo cp -i aliases aliases.`date +%Y-%m-%d`
$ sudo vi aliases
$ sudo newaliases
$ sudo /etc/init.d/postfix restart
$ sudo rc-update add postfix default
$ php -r 'mail("root", "subject", "message to:root ".`hostname`.`date`, "From: username@example.com");'