Koozali.org: home of the SME Server

Suddenly getting lots of theses reports

Offline Drifting

  • ****
  • 431
  • +0/-0
Re: Suddenly getting lots of theses reports
« Reply #15 on: May 12, 2017, 10:42:39 AM »
Carry on from this, had this come in now? seems I may have missed something to disable. Wish all this was off by default.

Can someone explain what is going on?

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

                   The mail system

<richard@dc.co.uk>: host mail.dc.co.uk[*.*.*.*] said: 552 SPF -
    softfail: uk.co.uk: Sender is not authorized by default to use
    'emma@uk.co.uk' in 'mfrom' identity, however domain is not currently
    prepared for false failures (mechanism '~all' matched) (in reply to end of
    DATA command)

Seem to be getting lots of people telling me the email bounced.

Paul.
« Last Edit: May 15, 2017, 01:44:37 PM by Drifting »
Infamy, Infamy, they all have it in for me!

Offline Drifting

  • ****
  • 431
  • +0/-0
Re: Suddenly getting lots of theses reports
« Reply #16 on: May 12, 2017, 11:13:23 AM »
Carry on from this, had this come in now? seems I may have missed something to disable. Wish all this was off by default.

Can someone explain what is going on?

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

                   The mail system

<richard@dc.co.uk>: host mail.dc.co.uk[*.*.*.*] said: 552 SPF -
    softfail: uk.co.uk: Sender is not authorized by default to use
    'emma@uk.co.uk' in 'mfrom' identity, however domain is not currently
    prepared for false failures (mechanism '~all' matched) (in reply to end of
    DATA command)

Seem to be getting lots of people telling me the email bounced.

Paul.
Think I sussed it, was taking the settings on the docs as standard, so have set :- db configuration setprop qpsmtpd DMARCReject disabled SPFRejectPolicy 0
Assume that is what it was.

Paul
« Last Edit: May 15, 2017, 01:45:14 PM by Drifting »
Infamy, Infamy, they all have it in for me!

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Suddenly getting lots of theses reports
« Reply #17 on: May 13, 2017, 09:57:03 AM »
Drifting

It has NEVER been a good idea to use *.local domain names as external mail servers check for a resolvable domain.
Use a real domain, I suggest you do go through the trouble of changing the domain name & certificates.

Janet,

this is a part my domain configuration:

xxx.local    Primary domain   Primary   Resolve locally   Modify   
xxxyyy.de    Domain fuer email   Primary   Internet DNS servers   Modify   Remove

The xxxyyy.de is hosted by ISP. It's used for email.

I understand you suggest to remove the xxx.local domain. In this case do I have to change the xxxyyy.de to "Primary domain   Primary   Resolve locally" ?

Stefano,

you just need an externally resolvable hostname (like mail.yourdomain.tld) pointing to your SME and the port 80 open and redirected to your SME

that's all

The SME is behind an OPNsense-firewall. No public webpages are hosted on the SME. There's no static IP. The SME is reachable through the firewall with dyndns for horde acivesync. Where/how can I point an externally resolvable hostname (xxxyyy.de) to the SME box? I didn't get that. Or is it already done with the dyndns?

Sorry if I missed something not seeing the wood in front of the trees ;)

Thank's for answering.
stefan
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline Stefano

  • *
  • 10,839
  • +2/-0
Re: Suddenly getting lots of theses reports
« Reply #18 on: May 13, 2017, 02:51:02 PM »
The SME is behind an OPNsense-firewall.

no problem, just forward port 80 to SME

Quote
No public webpages are hosted on the SME.

no problem, again, not needed

Quote
There's no static IP. The SME is reachable through the firewall with dyndns for horde acivesync. Where/how can I point an externally resolvable hostname (xxxyyy.de) to the SME box? I didn't get that. Or is it already done with the dyndns?

your host is available on something like yourhost.dyndns.org.. just create a CNAME record on your domain DNS pointing to  yourhost.dyndns.org

see this example:
Code: [Select]
stefano@stefano-HP ~ $ dig router.emergo.srl

; <<>> DiG 9.9.5-3ubuntu0.14-Ubuntu <<>> router.emergo.srl
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25564
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;router.emergo.srl. IN A

;; ANSWER SECTION:
router.emergo.srl. 1800 IN CNAME router.mysinapsi.net.
router.mysinapsi.net. 600 IN A 83.211.132.11

;; Query time: 565 msec
;; SERVER: 192.168.32.1#53(192.168.32.1)
;; WHEN: Sat May 13 14:49:52 CEST 2017
;; MSG SIZE  rcvd: 96

router.mysinapsi.net is managed on dyndns

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Suddenly getting lots of theses reports
« Reply #19 on: May 13, 2017, 03:11:48 PM »
Quote
no problem, just forward port 80 to SME

I'm too stupid - why should I open the port 80 in my firewall? I don't get it. IMVHO it's got nothing to do with email?? I actually don't want anybody reaching a server from outside through the http-protocol. What is that good for? I don't get it...
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline Stefano

  • *
  • 10,839
  • +2/-0
Re: Suddenly getting lots of theses reports
« Reply #20 on: May 13, 2017, 03:14:01 PM »
letsencrypt need to check your server and so port 80 is needed

nothing harmfull.. if anybody will reach your server on port 80 will see the default white page (index.html you have in /Primary/html folder)

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Suddenly getting lots of theses reports
« Reply #21 on: May 13, 2017, 03:29:09 PM »
I really don't like the idea to open (an unsecured) port 80 on a server. Easy to overload apache and break the server down. I mean we take every effort to secure anything with ssl mechanism and a lot more... Right now the email server from the ISP has to handle the risk. Email I don't want to receive remains on this server. It's not beeing fetched to the SME. Don't know what to think about this...
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline Stefano

  • *
  • 10,839
  • +2/-0
Re: Suddenly getting lots of theses reports
« Reply #22 on: May 13, 2017, 03:39:07 PM »
there are thousands of exposed SME servers out there.. ATM and AFAIR there was no issues..

if you want, you can edit the html file to redirect a surfer to your site (or anywhere you decide)

Letsencrypt will not see/use your page.. it works on an hidden dir .well-known (almost empty)

Offline DanB35

  • ****
  • 764
  • +0/-0
    • http://www.familybrown.org
Re: Suddenly getting lots of theses reports
« Reply #23 on: May 13, 2017, 03:56:32 PM »
I really don't like the idea to open (an unsecured) port 80 on a server.
In order to receive a certificate from Let's Encrypt, you must demonstrate control over the host for which you're seeking the certificate.  There are three ways you can do that:
  • Serve a small file from http://$HOSTNAME/.well-known/acme-challenge
  • Serve a TLS certificate from https://$HOSTNAME
  • Add a DNS TXT record relating to $HOSTNAME
Dehydrated, the client described on the wiki page, supports the first and third methods, but the contrib doesn't support DNS authentication for two reasons: (1) for most SME installations, the first method is much simpler to implement, and (2) everybody's DNS is different.  But if you refuse to open ports 80 or 443 to your SME box, and you can't obtain the cert directly on your firewall (which you could if you were running pfsense, for example), DNS validation is your only remaining option.

Here's some information on using the DNS challenge with dehydrated:
https://github.com/lukas2511/dehydrated/blob/master/docs/dns-verification.md
https://github.com/lukas2511/dehydrated/wiki/Examples-for-DNS-01-hooks

Edit: The OPNSense homepage (https://opnsense.org/) indicates that it's able to obtain Let's Encrypt certs, so you might want to investigate the possibility of obtaining the cert on your firewall and deploying it from there to your SME box.  The deployment could be scripted pretty easily on either the firewall side or the SME side.  In short, it would need to copy the cert, the private key, and the intermediate CA cert to your SME server, set the SSL properties correctly (which would only need to be done once, and thus could be done manually), and then signal the ssl-update event.
« Last Edit: May 13, 2017, 06:11:20 PM by DanB35 »
......

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Suddenly getting lots of theses reports
« Reply #24 on: May 13, 2017, 10:45:22 PM »
there are thousands of exposed SME servers out there.. ATM and AFAIR there was no issues..

if you want, you can edit the html file to redirect a surfer to your site (or anywhere you decide)

Letsencrypt will not see/use your page.. it works on an hidden dir .well-known (almost empty)

Creating/altering the index.htm in /home/e-smith/files/ibays/Primary/html with a re-direction to an external domain hosted by my ISP results in not beeing able to access the server-manager. I assume also horde (not tested). Content of index.htm:

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">

<html>

<head>
  <meta http-equiv="refresh" content="1; URL=http://www.externaldoamin.de"
</head>

</html>

What's wrong with that?

@DanB35:

Thank you for your reply. I'l think about this. Thank you so far.

stefan

And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Suddenly getting lots of theses reports
« Reply #25 on: May 13, 2017, 11:34:54 PM »
if you use letsencrypt certs you won't have any issue, never..

I followed the https://wiki.contribs.org/Letsencrypt#Installation. Opened the port 80 on my firewall and forwarded to the SME. Removed the domain.local and set up as primary domian a ISP hosted one.

No errors occured,  but it's not working.

These are generated:
/etc/dehydrated/config
/etc/dehydrated/domains.txt

This is empty:
/etc/dehydrated/certs/
rm /etc/dehydrated/accounts/

Do I have to whitelist (in my firewall)
Quote
You can now run dehydrated for the first time, and make sure it's able to connect to the Let's Encrypt servers,

Not working out-of-the-box for me.

Some help would be nice.

stefan
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

Offline DanB35

  • ****
  • 764
  • +0/-0
    • http://www.familybrown.org
Re: Suddenly getting lots of theses reports
« Reply #26 on: May 13, 2017, 11:36:48 PM »
"it's not working" is not very helpful.  What happens when you run "dehydrated -c"?
......

guest22

Re: Suddenly getting lots of theses reports
« Reply #27 on: May 14, 2017, 07:55:05 AM »
No errors occured,  but it's not working.

I had this too a few days back on a new server. 'not working' was after issuing 'dehydrated -c' there was no feedback to the console and after a little bit, the prompt was back.

I ended up removing the contrib and go for a manual install. That worked for me and gave me the nice progress report on screen, so I knew exactly what dehydrated was doing.


HTH

Offline SchulzStefan

  • *
  • 620
  • +0/-0
Re: Suddenly getting lots of theses reports
« Reply #28 on: May 14, 2017, 09:59:09 AM »
"it's not working" is not very helpful.  What happens when you run "dehydrated -c"?

I know. But if there's nothing to report and nothing in a log, what should I report?

RequestedDeletion was faster - same with me. I'll try the manual installation and will report.

regards,
stefan
And then one day you find ten years have got behind you.

Time, 1973
(Mason, Waters, Wright, Gilmour)

guest22

Re: Suddenly getting lots of theses reports
« Reply #29 on: May 14, 2017, 10:01:41 AM »
I'll try the manual installation and will report.


Please make sure you remove everything. Uninstalling the contrib does not remove e.g. db config info e.g. 'config show letsencrypt'