11 msgSMTP authentication with saslauthd against PAM

Error in SMTP sequence
\ Rob Sterenborg (13 Apr 2007)
. \ (Wietse Venema) (13 Apr 2007)
. \ (Wietse Venema) (13 Apr 2007)
. . \ (Wietse Venema) (13 Apr 2007)
. . . \ Rob Sterenborg (13 Apr 2007)
. \ Rob Sterenborg (18 Apr 2007)
. . \ (Wietse Venema) (18 Apr 2007)

2 msgdkim-milter on relay server unknown-jobid exter...
11 msgStubborn Cert issue
3 msgProblems with false positives
4 msgreject_unverified_recipient case sensitive?
3 msgdkim=fail (verification error: invalid key gran...
5 msg? Using header checks on (Postini) X-pstn-levels
2 msgCan't find error in my config file. Can you?
1 msgchroot postgresql ssl problem
15 msgWhat cert to buy
3 msgAddress re-writing
9 msgMail Rejected when we relay for a client.
8 msgQueueing up archive messages
2 msgCannot send e-mails from any e-mail clients
1 msgRe: outbound mail failure - need to fix asap -S...
4 msgoutbound mail failure - need to fix asap
3 msgPostfix alias problem
2 msgproblem to send a mail to a command in aliases
3 msgsmtpd_auth
Subject:Re: FW: Error in SMTP sequence
Group:Postfix-users
From:(Wietse Venema)
Date:18 Apr 2007


 
Rob Sterenborg:
> >>> If your sniffer confirms that no "RCPT TO:" is sent, then perhaps
> >>> the cause is a buggy PIPELINING implementation on the sending side.
> >
> > Yes, when I used tcpdump to check (a while ago; don't have
> > the dump anymore), "RCPT TO: " was *NOT* put before the
> > recipient email address.
>
> [...]
>
> > Ok, I'll see what happens when I turn off pipelining for these hosts.
>
> To follow-up on this and for reference: excluding PIPELINGING doesn't
> solve this problem.
>
> Sanitized logs about such session can be found here:
> http://www.sterenborg.info/GW-no-rcptto-pf_log.txt
> http://www.sterenborg.info/GW-no-rcptto-ngrep.txt

Unfortunately, only a packet recording (network-level) with all
the ACK packets, byte offsets, and TCP flags can give deeper insight
why the RCPT TO is not received. It could be a problem of overlapping
data (multiple packets with different data having the same byte
offset in the stream, where the first or last packet is ignored
depending on the receiving system's network stack).

> I guess that since this is doesn't seem to be Postfix related it must be
> GroupWise (or the PIX with smtp-fixup *disabled*, but I haven't heard of
> a PIX sometimes removing "RCPT TO:" commands)..

If the client really does not send "RCPT TO" before the recipient
address, there is no way that the mail would be accepted by any
MTA. In this respect Postfix is no different than other MTAs.

Wietse


© 2004-2008 readlist.com