Re: [exim] Still having localhost sending problems

Top Page
Delete this message
Reply to this message
Author: The Doctor, 3328-138 Ave Edmonton AB T5Y 1M4, 669-2000, 473-4587
Date:  
To: Jeremy Harris
CC: exim-users
Subject: Re: [exim] Still having localhost sending problems
> On 24/05/14 06:18, The Doctor, 3328-138 Ave Edmonton AB T5Y 1M4,
> 669-2000, 473-4587 wrote:
>> When trying to send from mutt I get
> [...]
>> Any way of bypassing TLS on localhost?
>
> You've not shown TLS being used, and you've not shown your config.
> I'm not sure how we can help you.
> --
> Jeremy


Config below














primary_hostname = doctor.nl2k.ab.ca

local_interfaces = 0.0.0.0.25 : 0.0.0.0.465 : 0.0.0.0.587



domainlist local_domains = @:@[]:localhost:secure.nl2k.ab.ca:mail.nl2k.ab.ca:mail.nk.ca:nk.ca:nl2k.ca:nl2k.ab.ca:doctor.nl2k.ab.ca:doctor.nk.ca:netknow.ca:partial-lsearch;/usr/exim/vdom3


domainlist relay_to_domains =
hostlist relay_from_hosts = 204.209.81.0/24 : 127.0.0.1 : 208.118.93.0/24: 208.118.94.0/24

hostlist hosts_avoid_tls = 127.0.0.1 : 204.209.81.0/24

trusted_users = exim : majordomo






acl_smtp_rcpt = acl_check_rcpt
acl_smtp_data = acl_check_data




av_scanner = clamd:127.0.0.1 3310



spamd_address = 204.209.81.3 783




tls_advertise_hosts = *


tls_certificate = /usr/exim/ca.crt
tls_privatekey = /usr/exim/ca.key


daemon_smtp_ports = 25 : 465 : 587
tls_on_connect_ports = 465


tls_require_ciphers = ALL : !SSLv2 : !LOW : !aNULL : !eNULL : !3DES : @STRENGTH












never_users = root



host_lookup = *



rfc1413_hosts = *
rfc1413_query_timeout = 5s








ignore_bounce_errors_after = 2h


timeout_frozen_after = 6h

auto_thaw = 1m



message_size_limit = 50M



spool_directory = /var/spool/exim




smtp_receive_timeout = 5m
smtp_accept_max = 25



begin acl


acl_check_smtp:
accept hosts = :
accept hosts = +relay_hosts
deny hosts = +block_hosts
accept



acl_check_rcpt:

  deny    message       = rejected because $sender_host_address is in a black list at $dnslist_domain\n$dnslist_text 
     dnslists = sbl-xbl.spamhaus.org : zen.spamhaus.org : dev.null.dk : relays.visi.com : bl.spamcop.net : hostkarma.junkemailfilter.com=127.0.0.2
           log_message   = found in $dnslist_domain




  accept  hosts = :
          control = dkim_disable_verify



  deny    message       = Restricted characters in address
          domains       = +local_domains
          local_parts   = ^[.] : ^.*[@%!/|]



  deny    message       = Restricted characters in address
          domains       = !+local_domains
          local_parts   = ^[./|] : ^.*[@%!] : ^.*/\\.\\./



  accept  local_parts   = postmaster
          domains       = +local_domains



  require verify        = sender





























drop    message = Legitimate bounces are never sent to more than one recipient.
        senders = : postmaster@*
        condition = ${if >{$recipients_count}{0}{true}{false}}









  accept  hosts         = +relay_from_hosts
          control       = submission
          control       = dkim_disable_verify



  accept  authenticated = *
          control       = submission/sender_retain
          control       = dkim_disable_verify



  require message = relay not permitted
          domains = +local_domains : +relay_to_domains



require verify = recipient




  deny    message       = Rejected sender
          domains       = dhl.com
          local_parts   = adminsu*


  deny    message       = Rejected sender
          domains       = *.com
          local_parts   = postmail-*


  deny    message       = Rejected sender
          domains       = usa.com
          local_parts   = express.deli*


  deny    message       = Rejected sender
          domains       = gmail.com
          local_parts   = emarketing2*


  deny    message       = Rejected sender
          domains       = gmail.com
          local_parts   = emarketing2sofsol*


  deny    message       = Rejected sender
          domains       = gmail.com
          local_parts   = umair*


  deny    message       = Rejected sender
          domains       = gmail.com
          local_parts   = umairpbl


  deny    message       = Rejected sender
          domains       = gmail.com
          local_parts   = edusa102


  deny      message    = Rejected sender
          domains    = doctor.nl2k.ab.ca
          local_parts    = OWA-Erro*



  deny      message    = Rejected recipient
          domains    = localhost.com
          local_parts    = root



  deny      message    = Rejected recipient
          domains    = freeshell.org
          local_parts    = dino



deny hosts = /usr/exim/blockhosts






accept



acl_check_data:


  accept authenticated = *
     set acl_m_authenticated = 1  


accept hosts = :

   deny    malware    = *
           message    = This message contains a virus ($malware_name).


  drop message = This message is denied by policy : $spam_score spam points
       spam = nobody:true
       condition = ${if > {$spam_score_int}{409}{1}{0}}



   warn    spam       = nobody
           message = Subject: {SPAM?} $rh_subject:
           add_header = X-Spam_score: $spam_score\n\
                        X-Spam_score_int: $spam_score_int\n\
                        X-Spam_bar: $spam_bar\n\
                        X-Spam_report: $spam_report



deny
    !hosts = +relay_from_hosts
    message = This message was considered to be spam
    spam = www:true
    condition = ${if >{$spam_score_int}{409}{1}{0}} 


deny senders = /usr/exim/deny_senders


accept





begin routers








check_dnslookup:
driver = dnslookup
domains = ! +local_domains
ignore_target_hosts = 0.0.0.0 : 127.0.0.0/8
verify_only
no_more




check_system_aliases:
driver = redirect
allow_fail
allow_defer
data = ${lookup{$local_part}lsearch{/etc/aliases}}
verify_only





check_localuser:
driver = accept
check_local_user
verify_only







virtuals:
  driver = redirect
  allow_defer
  allow_fail
  domains       = partial-lsearch;/usr/exim/vdom3
  data = ${lookup{$local_part@$domain}lsearch*@{/usr/exim/virtualaliases}}
  retry_use_local_part
  pipe_transport = address_pipe
  file_transport = address_file
  no_more



















dnslookup:
driver = dnslookup
domains = ! +local_domains
transport = remote_smtp
ignore_target_hosts = 0.0.0.0 : 127.0.0.0/8
no_more





system_aliases:
driver = redirect
allow_fail
allow_defer
data = ${lookup{$local_part}lsearch{/etc/aliases}}
file_transport = address_file
pipe_transport = address_pipe








userforward:
driver = redirect
check_local_user
local_part_prefix = +* : -*
local_part_prefix_optional
file = $home/.forward
allow_filter
no_verify
no_expn
check_ancestor
file_transport = address_file
pipe_transport = address_pipe
reply_transport = address_reply





localuser:
driver = accept
check_local_user
local_part_prefix = +* : -*
local_part_prefix_optional
transport = local_delivery
cannot_route_message = Unknown user

procmail:
driver = accept
check_local_user
require_files = $home/.procmailrc
transport = procmail_pipe







lists:
driver = redirect
file = /usr/home/majordomo/lists/$local_part
forbid_pipe
forbid_file
errors_to = $local_part-request@???
user = majordomo
no_more








begin transports



remote_smtp:
driver = smtp
connect_timeout = 15m
data_timeout = 15m
hosts_avoid_tls = 127.0.0.1

procmail_pipe:
driver = pipe
command = /usr/bin/procmail -d $local_part
return_path_add
delivery_date_add
envelope_to_add
check_string = "From "
escape_string = ">From "
umask = 077
user = $local_part
group = mail






local_delivery:
driver = appendfile
file = /var/mail/$local_part
delivery_date_add
envelope_to_add
return_path_add
group = mail
mode = 0600



address_pipe:
driver = pipe
return_output



address_file:
driver = appendfile
delivery_date_add
envelope_to_add
return_path_add



address_reply:
driver = autoreply




begin retry




*                      *           F,1h,15m; G,10h,1h,1.5; F,7d,1h
127.0.0.1              *           F,1h,1m; G,2h,10m,1.5; F,5h,10m
204.209.81.1              *           F,1h,1m; G,2h,10m,1.5; F,3h,10m
204.209.81.3              *           F,1h,1m; G,2h,10m,1.5; F,5h,10m






begin rewrite






begin authenticators


PLAIN:
  driver                     = plaintext
  public_name                = PLAIN
  server_set_id              = $auth2
  server_prompts             = :
  server_condition           = ${if saslauthd{{$2}{$3}}{1}{0}}
  server_advertise_condition = ${if def:tls_cipher }



LOGIN:
  driver                     = plaintext
  public_name                = LOGIN
  server_set_id              = $auth1
 server_prompts             = <| Username: | Password:
 server_condition           = ${if saslauthd{{$1}{$2}}{1}{0}}
  server_advertise_condition = ${if def:tls_cipher }