<feed xmlns='http://www.w3.org/2005/Atom'>
<title>fripost-ansible/roles/common/files/etc/postfix, branch master</title>
<subtitle>Fripost ansible scripts</subtitle>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/'/>
<entry>
<title>Postfix: don't share the master.cf between the instances.</title>
<updated>2016-07-10T02:53:37+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-07-10T02:53:37+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=1b744e0e6320dabaa62bc369addf7f0b89cdc107'/>
<id>1b744e0e6320dabaa62bc369addf7f0b89cdc107</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>postfix: master.cf wibble</title>
<updated>2016-05-18T19:14:14+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-05-18T19:14:14+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=1bdc6a1202f9cabea5f907c4213f2a6f902443b6'/>
<id>1bdc6a1202f9cabea5f907c4213f2a6f902443b6</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>postfix: Update to recommended TLS settings.</title>
<updated>2016-05-18T19:13:46+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2016-05-18T17:25:20+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=8fc53ecddfe875be30501a89fd24f226de7575d9'/>
<id>8fc53ecddfe875be30501a89fd24f226de7575d9</id>
<content type='text'>
Following Viktor Dukhovni's 2015-08-06 recommendation

    http://article.gmane.org/gmane.mail.postfix.user/251935

(We're using stronger ciphers and protocols in our own infrastructure.)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Following Viktor Dukhovni's 2015-08-06 recommendation

    http://article.gmane.org/gmane.mail.postfix.user/251935

(We're using stronger ciphers and protocols in our own infrastructure.)
</pre>
</div>
</content>
</entry>
<entry>
<title>Make the webmail connect directly to the outgoing SMTP proxy.</title>
<updated>2015-06-07T00:54:26+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-06-04T18:26:53+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=2c925ea17fcb6f71826e5c0f30f99c5daba10e14'/>
<id>2c925ea17fcb6f71826e5c0f30f99c5daba10e14</id>
<content type='text'>
(Hence delete the 'webmail' Postfix instance.)  This shortens the delay
caused by the recipient verification probes.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
(Hence delete the 'webmail' Postfix instance.)  This shortens the delay
caused by the recipient verification probes.
</pre>
</div>
</content>
</entry>
<entry>
<title>Upgrade the MX configuration from Wheezy to Jessie.</title>
<updated>2015-06-07T00:53:53+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-05-30T11:23:19+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=fa82a617a0c50b7478cd2b7189aa5f7d14449954'/>
<id>fa82a617a0c50b7478cd2b7189aa5f7d14449954</id>
<content type='text'>
In particular, since Postfix is now able to perform LDAP lookups using
SASL, previous hacks with simble binds on cn=postfix,ou=services,… can
now be removed.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
In particular, since Postfix is now able to perform LDAP lookups using
SASL, previous hacks with simble binds on cn=postfix,ou=services,… can
now be removed.
</pre>
</div>
</content>
</entry>
<entry>
<title>Upgrade amavis config to Jessie.</title>
<updated>2015-06-07T00:53:33+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-05-14T21:26:10+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=d87fefa9d38e6b8c99eafa16ea75dc8c879c41df'/>
<id>d87fefa9d38e6b8c99eafa16ea75dc8c879c41df</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Configure the list manager (Sympa).</title>
<updated>2015-06-07T00:53:27+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2015-05-14T20:00:36+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=166804e99e33c8ec5760e88ba1f52d4fc301334c'/>
<id>166804e99e33c8ec5760e88ba1f52d4fc301334c</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Replace Postgrey with postscreen.</title>
<updated>2015-06-07T00:53:05+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2014-07-12T23:39:45+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=4fb4be4d279dd94cab33fc778cfa318b93d6926f'/>
<id>4fb4be4d279dd94cab33fc778cfa318b93d6926f</id>
<content type='text'>
See http://www.postfix.org/POSTSCREEN_README.html and
    http://rob0.nodns4.us/postscreen.html

It's infortunate that smtpd(8) cannot be chrooted any longer, which
means that we have to un-chroot cleanup(8) as well.  Indeed, currently
smtpd(8) uses $virtual_alias_maps for recipient validation; later
cleanup(8) uses it again for rewriting.  So these processes need to be
both chrooted, or both not.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
See http://www.postfix.org/POSTSCREEN_README.html and
    http://rob0.nodns4.us/postscreen.html

It's infortunate that smtpd(8) cannot be chrooted any longer, which
means that we have to un-chroot cleanup(8) as well.  Indeed, currently
smtpd(8) uses $virtual_alias_maps for recipient validation; later
cleanup(8) uses it again for rewriting.  So these processes need to be
both chrooted, or both not.
</pre>
</div>
</content>
</entry>
<entry>
<title>More logcheck-database tweaks.</title>
<updated>2015-06-07T00:53:02+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2014-07-11T20:39:09+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=1422d37b350428b1524016026290ad80724b016d'/>
<id>1422d37b350428b1524016026290ad80724b016d</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Increase the timeout in the smtpd waiting for the reinjection from amavis.</title>
<updated>2015-06-07T00:52:30+00:00</updated>
<author>
<name>Guilhem Moulin</name>
<email>guilhem@fripost.org</email>
</author>
<published>2014-07-04T21:06:41+00:00</published>
<link rel='alternate' type='text/html' href='http://git.fripost.org/fripost-ansible/commit/?id=85e90fece41e0dadb19087a44c4eec8b76c9d5dd'/>
<id>85e90fece41e0dadb19087a44c4eec8b76c9d5dd</id>
<content type='text'>
SMTP client connection caching was introduced in 2.6.0: the SMTP session is
held for the next task (in adaptative mode, only when there was a delay of only
5s between the two previous mails), but Postfix will terminate it if the next
mail doesn't come soon enough, or if amavis does't terminate it itself (usually
after 15s).
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
SMTP client connection caching was introduced in 2.6.0: the SMTP session is
held for the next task (in adaptative mode, only when there was a delay of only
5s between the two previous mails), but Postfix will terminate it if the next
mail doesn't come soon enough, or if amavis does't terminate it itself (usually
after 15s).
</pre>
</div>
</content>
</entry>
</feed>
