Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 15 Mar 2014 16:35:12 -0700
From:      Drew Tomlinson <drew@mykitchentable.net>
To:        jcv <jv@yeaguy.com>
Cc:        freebsd-questions@FreeBSD.org
Subject:   Re: Help with SMTP AUTH
Message-ID:  <BLU0-SMTP3590B0B871DD2238724B613B3730@phx.gbl>
In-Reply-To: <alpine.BSF.2.00.1403151118060.6557@yeaguy.com>
References:  <BLU0-SMTP4079D728856FBE24B0A93C9B3730@phx.gbl> <alpine.BSF.2.00.1403151118060.6557@yeaguy.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 3/15/2014 11:22 AM, jcv wrote:
>
>
> On Sat, 15 Mar 2014, Drew Tomlinson wrote:
>
>> I'm running FreeBSD 10 with Postfix 2.11, Cyrus SASL 2.1.26, and 
>> saslauthd 2.1.26 .  I've followed various tutorials on the Net and 
>> even checked my current configs against backups from a machine that 
>> died but used to run smtp auth successfully.
>>
>> I've also tested using testsaslauthd and get the OK message:
>>
>> *|testsaslauthd -u/<username>/  -p/<password>/|*
>> 0: OK "Success."
>>
>> I'm wondering if Postfix is even attempting to query saslauthd. I'm 
>> not sure how to tell.  Should I see something in my maillog?  This is 
>> all I see in my log when testing:
>>
>> Mar 15 10:56:38 blacklamb postfix/smtpd[85529]: connect from 
>> unknown[X.X.X.X]
>> Mar 15 10:56:39 blacklamb postfix/smtpd[85529]: Anonymous TLS 
>> connection established from unknown[X.X.X.X]: TLSv1 with cipher 
>> ECDHE-RSA-AES256-SHA (256/256 bits)
>> Mar 15 10:56:39 blacklamb postfix/smtpd[85529]: NOQUEUE: reject: RCPT 
>> from unkno
>> wn[X.X.X.X]: 454 4.7.1 <drew.tomlinson@<removed>.com>: Relay access 
>> denied; from=<drew@mykitchentable.net> 
>> to=<drew.tomlinson@<removed>.com> proto=ESMTP helo=<[127.0.0.1]>
>>
>> Any help on where to begin to solve this would be appreciated.
>>
>> Thanks,
>>
>> Drew
>>
>> -- 
>> Like card tricks?
>>
>> Visit The Alchemist's Warehouse to
>> learn card magic secrets for free!
>>
>> http://alchemistswarehouse.com
>>
>> _______________________________________________
>> freebsd-questions@freebsd.org mailing list
>> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
>> To unsubscribe, send any mail to 
>> "freebsd-questions-unsubscribe@freebsd.org"
>>
>
> does saslauthd bypass postfix main.cf completly??
Thank you for your reply.  That's what I'm trying to figure out.  I 
think it is bypassing because I see nothing about it in my maillog. 
However I am not sure.
>
> whats does your main.cf config look like?
>
> the smtpd part where your getting denied.. Im fooling around with 
> dovecot imap and postfix got it running but.. I see TLS everywhere 
> except when i send to my relayhost..  but im thinking sasl auth 
> encrypting that part.
>
> you have anything like this:
>
> smtpd_sasl_type = dovecot
> smtpd_sasl_path = private/auth
> smtpd_sasl_auth_enable = yes
> smtpd_sasl_security_options = noanonymous
> smtpd_sasl_local_domain = $mydomain
> smtpd_sasl_tls_security_options = noanonymous

These are all the lines that contain "*sasl*" in my config :

  # grep sasl main.cf
smtp_sasl_auth_enable = yes
smtp_sasl_security_options = noanonymous
smtpd_sasl_path = /usr/local/lib/sasl2/smtpd
smtp_sasl_password_maps = hash:/usr/local/etc/postfix/sasl_passwd
smtp_sasl_mechanism_filter = !CRAM-MD5,!DIGEST-MD5, static:all
smtp_sasl_type = cyrus
smtpd_sasl_local_domain =
broken_sasl_auth_clients = yes
smtpd_recipient_restrictions =
    permit_sasl_authenticated,



-- 
Like card tricks?

Visit The Alchemist's Warehouse to
learn card magic secrets for free!

http://alchemistswarehouse.com




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?BLU0-SMTP3590B0B871DD2238724B613B3730>