OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
RE: setup postfix whitout mynetworks, just with permit_sasl_authenticated

From: Dan Blejan (dansdn.ro)
Date: Mon Dec 03 2007 - 04:24:44 CST


Sorry for the mess.

Dec 3 11:41:26 www pop3d: Connection, ip=[::ffff: xxx.yyy.zzz.www]
Dec 3 11:41:26 www authdaemond: received auth request, service=pop3, authtype=login
Dec 3 11:41:26 www authdaemond: authmysql: trying this module
Dec 3 11:41:26 www authdaemond: SQL query: SELECT username, password, "", '1001', '1001', '/usr/local/virtual', maildir, quota, name, "" FROM mailbox WHERE username = "localuserlocaldomain"
Dec 3 11:41:26 www authdaemond: password matches successfully
Dec 3 11:41:26 www authdaemond: authmysql: sysusername=<null>, sysuserid=1001, sysgroupid=1001, homedir=/usr/local/virtual, address=localuserlocaldomain, fullname=Dan Blejan, maildir=localuserlocaldomain/, quota=0, options=<null>
Dec 3 11:41:26 www authdaemond: authmysql: clearpasswd=<null>, passwd=<passwdhash>
Dec 3 11:41:26 www authdaemond: Authenticated: sysusername=<null>, sysuserid=1001, sysgroupid=1001, homedir=/usr/local/virtual, address=localuserlocaldomain, fullname=Dan Blejan, maildir=localuserlocaldomain/, quota=0, options=<null>
Dec 3 11:41:26 www authdaemond: Authenticated: clearpasswd=<password>, passwd=<passwdhash>
Dec 3 11:41:26 www pop3d: LOGIN, user=localuserlocaldomain, ip=[::ffff: xxx.yyy.zzz.www], port=[1215]
Dec 3 11:41:26 www pop3d: LOGOUT, user=localuserlocaldomain, ip=[::ffff: xxx.yyy.zzz.www], port=[1215], top=0, retr=0, rcvd=6, sent=30, time=0
Dec 3 11:41:26 www postfix/smtpd[908]: warning: dict_nis_init: NIS domain name not set - NIS lookups disabled
Dec 3 11:41:28 www postfix/smtpd[908]: warning: xxx.yyy.zzz.www: hostname client200-sebastian.sdn.ro verification failed: Name or service not known
Dec 3 11:41:28 www postfix/smtpd[908]: connect from unknown[xxx.yyy.zzz.www]
Dec 3 11:41:28 www postfix/smtpd[908]: NOQUEUE: reject: RCPT from unknown[xxx.yyy.zzz.www]: 554 5.7.1 < someuseryahoo.com >: Relay access denied; from=<localuserlocaldomain> to=< someuseryahoo.com > proto=ESMTP helo=<ko>

-----Original Message-----
From: owner-postfix-userspostfix.org [mailto:owner-postfix-userspostfix.org] On Behalf Of Ralf Hildebrandt
Sent: Monday, December 03, 2007 11:59 AM
To: postfix-userspostfix.org
Subject: Re: setup postfix whitout mynetworks, just with permit_sasl_authenticated

* Dan Blejan <dansdn.ro>:
> I know it's not postfix, but in first place I had to see if authentication was properly done.
>
> With:
>
> smtpd_recipient_restrictions =
> permit_sasl_authenticated,
> reject_unauth_destination,
> ...
>
> same result:
>
> NOQUEUE: reject: RCPT from unknown[xxx.yyy.zzz.www]: 554 5.7.1 <someuseryahoo.com>: Relay access denied; from=< localuserlocaldomain > to=<someuseryahoo.com> proto=ESMTP helo=<ko>
>
> I don't know where or what to check further...

Did the client authenticate?
Show the complete logs for that incident.

--
Ralf Hildebrandt (Ralf.Hildebrandtcharite.de) plonkcharite.de
Postfix - Einrichtung, Betrieb und Wartung Tel. +49 (0)30-450 570-155
http://www.arschkrebs.de
"Never trust a computer you can't throw out a window."
-- Steve Wozniak