OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: postscreen_dnsbl_whitelist_threshold

From: Wietse Venema (wietseporcupine.org)
Date: Mon May 13 2013 - 12:54:02 CDT


/dev/rob0:
> On Mon, May 13, 2013 at 09:12:57AM -0400, Wietse Venema wrote:
> > /dev/rob0:
> > > > I don't see any PASS OLD in there, so I guess the whitelist
> > > > did the trick? Would anything else be logged?
> > >
> > > Hmm, I'm not sure what that was; maybe 66.220.144.151 was due
> > > for retesting in some tests? Here are some from a bit later,
> > > which get "PASS NEW" without any after-220 tests:
> >
> > It may well be that PASS OLD logging has broken.
>
> Not entirely, as I do have numerous PASS OLD in the logs:
>
> $ egrep "^May 13 .* PASS OLD" /var/log/maillog | wc
> 73 584 5947

With whitelisting turned on I see no missing "PASS" logging

PASS NEW New client.
PASS OLD Client reconnects after cached test results expire.
PASS OLD Client reconnects after cached test results expire.

And Postscreen behavior does not change when DNS whitelisting is disabled.

        Wietse