OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
authentication trouble with Exchange 2003 server

From: Alan Diercks (a_diercksyahoo.com)
Date: Mon Nov 20 2006 - 10:06:51 CST


Hi,

I seem to be having authentication issues with postfix
(2.1.5-3.1) sending through a new Exchange 2003 installation. The
most relevant part of the error
message seems to be:

Nov 16 07:55:50 assegai postfix/smtp[23336]: C6B14789F4:
to=,relay=email.systemsbiology.net[10.0.176.62], delay=1,
status=deferred (host email.systemsbiology.net[10.0.176.62] said: 454
5.7.3 Client does not have p ermission to Send As this
sender. (in reply to end of DATA command))

The log files are below (saslfinger, postconf -n, and the mail log)

Mail can be sent successfully through the Exchange
server using clients such as Thunderbird but not
clients which rely on postfix.

Thanks for any help anyone can provide.

-Alan

###########################################################
output of saslfinger -c:

saslfinger - postfix Cyrus sasl configuration Thu Nov 16 08:01:29 PST 2006
version: 1.0
mode: client-side SMTP AUTH

-- basics --
Postfix: 2.1.5
System:
Welcome to SuSE Linux 9.2 (i586) - Kernel \r (\l).

-- smtp is linked to --
        libsasl2.so.2 => /usr/lib/libsasl2.so.2 (0x40087000)

-- active SMTP AUTH and TLS parameters for smtp --
relayhost = email.systemsbiology.net
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options =
smtp_tls_loglevel = 2
smtp_use_tls = yes

-- listing of /usr/lib/sasl2 --
total 256
drwxr-xr-x 2 root root 496 Sep 19 2005 .
drwxr-xr-x 186 root root 60832 Oct 16 07:13 ..
-rwxr-xr-x 1 root root 695 Oct 1 2004 libanonymous.la
-rwxr-xr-x 1 root root 16297 Oct 1 2004 libanonymous.so
-rwxr-xr-x 1 root root 16297 Oct 1 2004 libanonymous.so.2
-rwxr-xr-x 1 root root 16297 Oct 1 2004 libanonymous.so.2.0.19
-rwxr-xr-x 1 root root 679 Oct 1 2004 liblogin.la
-rwxr-xr-x 1 root root 17029 Oct 1 2004 liblogin.so
-rwxr-xr-x 1 root root 17029 Oct 1 2004 liblogin.so.2
-rwxr-xr-x 1 root root 17029 Oct 1 2004 liblogin.so.2.0.19
-rwxr-xr-x 1 root root 704 Oct 1 2004 libsasldb.la
-rwxr-xr-x 1 root root 21736 Oct 1 2004 libsasldb.so
-rwxr-xr-x 1 root root 21736 Oct 1 2004 libsasldb.so.2
-rwxr-xr-x 1 root root 21736 Oct 1 2004 libsasldb.so.2.0.19
-rw------- 1 root root 49 Jul 22 2005 smtpd.conf

-- permissions for /etc/postfix/sasl_passwd --
-rw------- 1 root root 240 Nov 8 07:26 /etc/postfix/sasl_passwd

-- permissions for /etc/postfix/sasl_passwd.db --
-rw------- 1 root root 12288 Nov 8 07:27 /etc/postfix/sasl_passwd.db

/etc/postfix/sasl_passwd.db is up to date.

-- active services in /etc/postfix/master.cf --
# service type private unpriv chroot wakeup maxproc command + args
# (yes) (yes) (yes) (never) (100)
smtp inet n - n - - smtpd
pickup fifo n - n 60 1 pickup
cleanup unix n - n - 0 cleanup
qmgr fifo n - n 300 1 qmgr
rewrite unix - - n - - trivial-rewrite
bounce unix - - n - 0 bounce
defer unix - - n - 0 bounce
trace unix - - n - 0 bounce
verify unix - - n - 1 verify
flush unix n - n 1000? 0 flush
proxymap unix - - n - - proxymap
smtp unix - - n - - smtp
relay unix - - n - - smtp
showq unix n - n - - showq
error unix - - n - - error
local unix - n n - - local
virtual unix - n n - - virtual
lmtp unix - - n - - lmtp
anvil unix - - n - 1 anvil
maildrop unix - n n - - pipe
  flags=DRhu user=vmail argv=/usr/local/bin/maildrop -d ${recipient}
cyrus unix - n n - - pipe
  user=cyrus argv=/usr/lib/cyrus/bin/deliver -e -r ${sender} -m
${extension} ${u
ser}
uucp unix - n n - - pipe
  flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail
($recipient)
ifmail unix - n n - - pipe
  flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)
bsmtp unix - n n - - pipe
  flags=Fq. user=foo argv=/usr/local/sbin/bsmtp -f $sender $nexthop
$recipient
procmail unix - n n - - pipe
  flags=R user=nobody argv=/usr/bin/procmail -t -m /etc/procmailrc
${sender} ${r
ecipient}

-- mechanisms on email.systemsbiology.net --
250-AUTH LOGIN
250-AUTH=LOGIN

-- end of saslfinger output --

Output of postconf -n:

alias_maps = hash:/etc/aliases
biff = no
canonical_maps = hash:/etc/postfix/canonical
command_directory = /usr/sbin
config_directory = /etc/postfix
daemon_directory = /usr/lib/postfix
debug_peer_level = 2
defer_transports =
disable_dns_lookups = no
html_directory = /usr/share/doc/packages/postfix/html
inet_interfaces = 127.0.0.1 ::1
mail_owner = postfix
mail_spool_directory = /var/mail
mailbox_command =
mailbox_size_limit = 0
mailbox_transport =
mailq_path = /usr/bin/mailq
manpage_directory = /usr/share/man
masquerade_classes = envelope_sender, header_sender, header_recipient
masquerade_domains = systemsbiology.org
masquerade_exceptions = root
message_size_limit = 10240000
mydomain = systemsbiology.net
myhostname = assegai.systemsbiology.net
myorigin = $mydomain
newaliases_path = /usr/bin/newaliases
queue_directory = /var/spool/postfix
readme_directory = /usr/share/doc/packages/postfix/README_FILES
relayhost = email.systemsbiology.net
relocated_maps = hash:/etc/postfix/relocated
sample_directory = /usr/share/doc/packages/postfix/samples
sender_canonical_maps = hash:/etc/postfix/sender_canonical
sendmail_path = /usr/sbin/sendmail
setgid_group = maildrop
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options =
smtp_tls_loglevel = 2
smtp_use_tls = yes
smtpd_client_restrictions =
smtpd_helo_required = no
smtpd_helo_restrictions =
smtpd_recipient_restrictions = permit_mynetworks,reject_unauth_destination
smtpd_sasl_auth_enable = yes
smtpd_sender_restrictions = hash:/etc/postfix/access
smtpd_use_tls = yes
strict_rfc821_envelopes = no
transport_maps = hash:/etc/postfix/transport
unknown_local_recipient_reject_code = 550

Mail log:

Nov 16 07:55:49 assegai postfix/pickup[22952]: C6B14789F4: uid=51015
from= Nov 16 07:55:49 assegai postfix/cleanup[23334]:
C6B14789F4:message-id=<20061116155549.GB22956assegai.systemsbiology.net>
Nov 16 07:55:49 assegai postfix/qmgr[22953]: C6B14789F4:
from=<AAAAAAAsystemsbiology.org>, size=778, nrcpt=1 (queue active)
Nov 16 07:55:49 assegai postfix/smtp[23336]: starting TLS engine
Nov 16 07:55:50 assegai postfix/smtp[23336]:SSL_connect:before/connect
initialization
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv2/v3
write client hello A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:error in
SSLv2/v3 read server hello A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:error in
SSLv3 read server hello A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:error in
SSLv3 read server hello A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv3 read
server hello A
Nov 16 07:55:50 assegai postfix/smtp[23336]: Peer cert verify depth=1
/C=US/ST=Arizona/L=Scottsdale/O=Starfield Technologies,
Inc./OU=http://www.starfieldtech.com/repository/CN=Starfield Secure
Certification Authority/emailAddress=practicesstarfieldtech.com
Nov 16 07:55:50 assegai postfix/smtp[23336]: verify
error:num=20:unable to get local issuer certificate
Nov 16 07:55:50 assegai postfix/smtp[23336]: verify return:0
Nov 16 07:55:50 assegai postfix/smtp[23336]: Peer cert verify depth=1
/C=US/ST=Arizona/L=Scottsdale/O=Starfield Technologies,
Inc./OU=http://www.starfieldtech.com/repository/CN=Starfield Secure
Certification Authority/emailAddress=practicesstarfieldtech.com
Nov 16 07:55:50 assegai postfix/smtp[23336]: verify
error:num=27:certificate not trusted
Nov 16 07:55:50 assegai postfix/smtp[23336]: verify return:0
Nov 16 07:55:50 assegai postfix/smtp[23336]: Peer cert verify depth=0
/O=email.systemsbiology.net/OU=Domain Control
Validated/CN=email.systemsbiology.net
Nov 16 07:55:50 assegai postfix/smtp[23336]: verify return:1
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv3 read
server certificate A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv3 read
server done A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv3 write
client key exchange A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv3 write
change cipher spec A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv3 write
finished A
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv3 flush data
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:error in
SSLv3 read finished A
Nov 16 07:55:50 assegai last message repeated 3 times
Nov 16 07:55:50 assegai postfix/smtp[23336]: SSL_connect:SSLv3 read
finished A
Nov 16 07:55:50 assegai postfix/smtp[23336]: Unverified:
subject_CN=email.systemsbiology.net, issuer=Starfield Secure
Certification Authority
Nov 16 07:55:50 assegai postfix/smtp[23336]: TLS connection
established to email.systemsbiology.net: TLSv1 with cipher RC4-MD5
(128/128 bits)
Nov 16 07:55:50 assegai postfix/smtp[23336]: Peer certficate could not
be verified
Nov 16 07:55:50 assegai postfix/smtp[23336]: C6B14789F4:
to=<AAAA.AAAAAAAcomcast.net>,
relay=email.systemsbiology.net[10.0.176.62], delay=1, status=deferred
(host email.systemsbiology.net[10.0.176.62] said: 454 5.7.3 Client
does not have permission to Send As this sender. (in reply to end of
DATA command))

 
____________________________________________________________________________________
Sponsored Link

Mortgage rates near 39yr lows.
$510k for $1,698/mo. Calculate new payment!
www.LowerMyBills.com/lre