#1  
Old 20th July 2009, 21:02
madmerlin madmerlin is offline
Junior Member
 
Join Date: Jun 2009
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default relay denied

I'm trying to use thunderbird to send email from an external location. Receiving email works perfectly via IMAp.
For the SMTP server settings I'm using the server via port:25, and have Security and Authentication, Use name and password checked... using the user's name as his email address. I have TLS, if available enabled as well.

/var/log/mail.info:
Code:
554 5.7.1 <user@hisdomain.com>: Relay access denied; from=<me@mydomain.ca> to=<user@hisdomain.com> proto=SMTP helo=<[192.168.1.133]>
snipet from main.cf
Code:
relayhost =
smtpd_sasl_authenticated_header = yes
smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, check_recipient_access mysql:/etc/postfix/mysql-virtual_recipient.cf, reject_unauth_destination
smtpd_tls_security_level = may
transport_maps = proxy:mysql:/etc/postfix/mysql-virtual_transports.cf
relay_domains = mysql:/etc/postfix/mysql-virtual_relaydomains.cf
maildrop snipet from master.cf:
Code:
maildrop  unix  -       n       n       -       -       pipe
  flags=R user=vmail argv=/usr/bin/maildrop -d vmail ${extension} ${recipient} ${user} ${nexthop} ${sender}
Used the perfect server ubuntu 9.04 + ISPconfig3 as my guide.

Thanks much,
MM
Reply With Quote
Sponsored Links
  #2  
Old 20th July 2009, 23:18
till till is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 35,976
Thanks: 825
Thanked 5,369 Times in 4,216 Posts
Default

Your mail client did not authenticate itself with smtp-auth. Please enable smtp authentication in the email client.
__________________
Till Brehm
--
Get ISPConfig support and the ISPConfig 3 manual from ispconfig.org.
Reply With Quote
  #3  
Old 20th July 2009, 23:33
madmerlin madmerlin is offline
Junior Member
 
Join Date: Jun 2009
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by till View Post
Your mail client did not authenticate itself with smtp-auth. Please enable smtp authentication in the email client.
Using Thunderbird I've tried all 4 authentication options...

Security and Authentication
Use name and password is enabled. (using email address as user)
Use secure connection has 4 options and I've tried all 4.
No
TLS if available
TLS
SSL

TLS option gives "Unable to connect to SMTP server myserver via STARTTLS since it doesn't support EHLO.

using TLS if available or NO gives the relay error I quoted above.
Reply With Quote
  #4  
Old 21st July 2009, 08:18
till till is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 35,976
Thanks: 825
Thanked 5,369 Times in 4,216 Posts
Default

Please post all messages that appear in the mail log when you try to send a meial. There must be more lines then just the line you posted.
__________________
Till Brehm
--
Get ISPConfig support and the ISPConfig 3 manual from ispconfig.org.
Reply With Quote
  #5  
Old 21st July 2009, 17:53
madmerlin madmerlin is offline
Junior Member
 
Join Date: Jun 2009
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by till View Post
Please post all messages that appear in the mail log when you try to send a meial. There must be more lines then just the line you posted.
From /var/log/mail.log:
Code:
Jul 21 08:47:42 dbl postfix/smtpd[25947]: NOQUEUE: reject: RCPT from externalserver.domain.com[x.x.x.x]: 554 5.7.1 <user@hisdomain.com>: Relay access denied; from=<me@mydomain.ca> to=<user@hisdomain.com> proto=SMTP helo=<[192.168.1.133]>
Jul 21 08:47:43 dbl postfix/smtpd[25947]: disconnect from externalserver.domain.com[x.x.x.x]
where externalserver.domain.com is the remote location I'm currently at.

I'm using "use name and password" authentication with the secure connection option of "TLS, if available"

Thanks for the help. Really appreciate it.
Reply With Quote
  #6  
Old 22nd July 2009, 18:02
madmerlin madmerlin is offline
Junior Member
 
Join Date: Jun 2009
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default

Any other insight into why sending from an external location might be failing? There's really not much more in the log files.

Is there a table in MySQL I could check for the right relay authentication information?... or a config file on my Ubuntu 9.04 server?

A test I could try locally on the machine?
Reply With Quote
  #7  
Old 22nd July 2009, 19:35
dzudzu dzudzu is offline
Member
 
Join Date: Jun 2009
Location: Serbia
Posts: 64
Thanks: 1
Thanked 6 Times in 6 Posts
Default

can u post complete main.cf and master.cf files,

and pls send and try to recive mail 1 more time and post all changes in the log that heapen when u do that.

thx
__________________
EonTek.rs - System Engineering

dzudzu
Reply With Quote
  #8  
Old 22nd July 2009, 21:00
madmerlin madmerlin is offline
Junior Member
 
Join Date: Jun 2009
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
Default

Quote:
Originally Posted by dzudzu View Post
can u post complete main.cf and master.cf files,

and pls send and try to recive mail 1 more time and post all changes in the log that heapen when u do that.

thx
main.cf
Code:
# See /usr/share/postfix/main.cf.dist for a commented, more complete version


# Debian specific:  Specifying a file name will cause the first
# line of that file to be used as the name.  The Debian default
# is /etc/mailname.
#myorigin = /etc/mailname

smtpd_banner = $myhostname ESMTP $mail_name (Ubuntu)
biff = no

# appending .domain is the MUA's job.
append_dot_mydomain = no

# Uncomment the next line to generate "delayed mail" warnings
#delay_warning_time = 4h

readme_directory = /usr/share/doc/postfix

# TLS parameters
smtpd_tls_cert_file = /etc/postfix/smtpd.cert
smtpd_tls_key_file = /etc/postfix/smtpd.key
smtpd_use_tls = yes
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache

# See /usr/share/doc/postfix/TLS_README.gz in the postfix-doc package for
# information on enabling SSL in the smtp client.

myhostname = <my FQDN server>
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases
myorigin = /etc/mailname
mydestination = <my FQDN server>, localhost, localhost.localdomain
relayhost =
mynetworks = 127.0.0.0/8 [::1]/128
mailbox_size_limit = 0
recipient_delimiter = +
inet_interfaces = all
html_directory = /usr/share/doc/postfix/html
virtual_alias_domains =
virtual_alias_maps = proxy:mysql:/etc/postfix/mysql-virtual_forwardings.cf, mysql:/etc/postfix/mysql-virtual_email2email.cf
virtual_mailbox_domains = proxy:mysql:/etc/postfix/mysql-virtual_domains.cf
virtual_mailbox_maps = proxy:mysql:/etc/postfix/mysql-virtual_mailboxes.cf
virtual_mailbox_base = /var/vmail
virtual_uid_maps = static:5000
virtual_gid_maps = static:5000
smtpd_sasl_auth_enable = yes
broken_sasl_auth_clients = yes
smtpd_sasl_authenticated_header = yes
smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, check_recipient_access mysql:/etc/postfix/mysql-virtual_recipient.cf, reject_unauth_destination
smtpd_tls_security_level = may
transport_maps = proxy:mysql:/etc/postfix/mysql-virtual_transports.cf
relay_domains = mysql:/etc/postfix/mysql-virtual_relaydomains.cf
virtual_create_maildirsize = yes
virtual_maildir_extended = yes
virtual_mailbox_limit_maps = proxy:mysql:/etc/postfix/mysql-virtual_mailbox_limit_maps.cf
virtual_mailbox_limit_override = yes
virtual_maildir_limit_message = "The user you are trying to reach is over quota."
virtual_overquota_bounce = yes
proxy_read_maps = $local_recipient_maps $mydestination $virtual_alias_maps $virtual_alias_domains $virtual_mailbox_maps $virtual_mailbox_domains $relay_recipient_maps $relay_domains $canonical_maps $sender_canonical_maps $recipient_canonical_maps $relocated_maps $transport_maps $mynetworks $virtual_mailbox_limit_maps
smtpd_sender_restrictions = check_sender_access mysql:/etc/postfix/mysql-virtual_sender.cf
smtpd_client_restrictions = check_client_access mysql:/etc/postfix/mysql-virtual_client.cf
maildrop_destination_concurrency_limit = 1
maildrop_destination_recipient_limit = 1
virtual_transport = maildrop
header_checks = regexp:/etc/postfix/header_checks
mime_header_checks = regexp:/etc/postfix/mime_header_checks
nested_header_checks = regexp:/etc/postfix/nested_header_checks
body_checks = regexp:/etc/postfix/body_checks
content_filter = amavis:[127.0.0.1]:10024
receive_override_options = no_address_mappings
message_size_limit = 0
master.cf
Code:
#
# Postfix master process configuration file.  For details on the format
# of the file, see the master(5) manual page (command: "man 5 master").
#
# Do not forget to execute "postfix reload" after editing this file.
#
# ==========================================================================
# service type  private unpriv  chroot  wakeup  maxproc command + args
#               (yes)   (yes)   (yes)   (never) (100)
# ==========================================================================
smtp      inet  n       -       -       -       -       smtpd
#submission inet n       -       -       -       -       smtpd
#  -o smtpd_tls_security_level=encrypt
#  -o smtpd_sasl_auth_enable=yes
#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
#  -o milter_macro_daemon_name=ORIGINATING
#smtps     inet  n       -       -       -       -       smtpd
#  -o smtpd_tls_wrappermode=yes
#  -o smtpd_sasl_auth_enable=yes
#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
#  -o milter_macro_daemon_name=ORIGINATING
#628      inet  n       -       -       -       -       qmqpd
pickup    fifo  n       -       -       60      1       pickup
cleanup   unix  n       -       -       -       0       cleanup
qmgr      fifo  n       -       n       300     1       qmgr
#qmgr     fifo  n       -       -       300     1       oqmgr
tlsmgr    unix  -       -       -       1000?   1       tlsmgr
rewrite   unix  -       -       -       -       -       trivial-rewrite
bounce    unix  -       -       -       -       0       bounce
defer     unix  -       -       -       -       0       bounce
trace     unix  -       -       -       -       0       bounce
verify    unix  -       -       -       -       1       verify
flush     unix  n       -       -       1000?   0       flush
proxymap  unix  -       -       n       -       -       proxymap
proxywrite unix -       -       n       -       1       proxymap
smtp      unix  -       -       -       -       -       smtp
# When relaying mail as backup MX, disable fallback_relay to avoid MX loops
relay     unix  -       -       -       -       -       smtp
        -o smtp_fallback_relay=
#       -o smtp_helo_timeout=5 -o smtp_connect_timeout=5
showq     unix  n       -       -       -       -       showq
error     unix  -       -       -       -       -       error
retry     unix  -       -       -       -       -       error
discard   unix  -       -       -       -       -       discard
local     unix  -       n       n       -       -       local
virtual   unix  -       n       n       -       -       virtual
lmtp      unix  -       -       -       -       -       lmtp
anvil     unix  -       -       -       -       1       anvil
scache    unix  -       -       -       -       1       scache
#
# ====================================================================
# Interfaces to non-Postfix software. Be sure to examine the manual
# pages of the non-Postfix software to find out what options it wants.
#
# Many of the following services use the Postfix pipe(8) delivery
# agent.  See the pipe(8) man page for information about ${recipient}
# and other message envelope options.
# ====================================================================
#
# maildrop. See the Postfix MAILDROP_README file for details.
# Also specify in main.cf: maildrop_destination_recipient_limit=1
#
maildrop  unix  -       n       n       -       -       pipe
  flags=R user=vmail argv=/usr/bin/maildrop -d vmail ${extension} ${recipient} ${user} ${nexthop} ${sender}
#
# See the Postfix UUCP_README file for configuration details.
#
uucp      unix  -       n       n       -       -       pipe
  flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail ($recipient)
#
# Other external delivery methods.
#
ifmail    unix  -       n       n       -       -       pipe
  flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)
bsmtp     unix  -       n       n       -       -       pipe
  flags=Fq. user=bsmtp argv=/usr/lib/bsmtp/bsmtp -t$nexthop -f$sender $recipient
scalemail-backend unix  -       n       n       -       2       pipe
  flags=R user=scalemail argv=/usr/lib/scalemail/bin/scalemail-store ${nexthop} ${user} ${extension}
mailman   unix  -       n       n       -       -       pipe
  flags=FR user=list argv=/usr/lib/mailman/bin/postfix-to-mailman.py
  ${nexthop} ${user}


amavis unix - - - - 2 smtp
        -o smtp_data_done_timeout=1200
        -o smtp_send_xforward_command=yes

127.0.0.1:10025 inet n - - - - smtpd
        -o content_filter=
        -o local_recipient_maps=
        -o relay_recipient_maps=
        -o smtpd_restriction_classes=
        -o smtpd_client_restrictions=
        -o smtpd_helo_restrictions=
        -o smtpd_sender_restrictions=
        -o smtpd_recipient_restrictions=permit_mynetworks,reject
        -o mynetworks=127.0.0.0/8
        -o strict_rfc821_envelopes=yes
        -o receive_override_options=no_unknown_recipient_checks,no_header_body_checks
        -o smtpd_bind_address=127.0.0.1
tail from /var/log/mail.info while trying to send via Thunderbird while using user authentication and "use TLS if available"
Code:
Jul 22 11:54:32 dbl postfix/smtpd[27195]: connect from <my external location>[external IP]
Jul 22 11:54:33 dbl postfix/smtpd[27195]: NOQUEUE: reject: RCPT from <my external location>[external IP]: 554 5.7.1 <user@hisdomain.com>: Relay access denied; from=<me@mydomain.ca> to=<user@hisdomain.com> proto=SMTP helo=<[192.168.1.133]>
Jul 22 11:54:34 dbl postfix/smtpd[27195]: disconnect from <my external location>[external IP]
Thanks for having a look. Appreciate it.
Reply With Quote
  #9  
Old 23rd July 2009, 00:03
dzudzu dzudzu is offline
Member
 
Join Date: Jun 2009
Location: Serbia
Posts: 64
Thanks: 1
Thanked 6 Times in 6 Posts
Default

Ok i came up with few things so try it out:

first try making in master.cf like this:

smtp inet n - n - - smtpd

and try if it is working, after that try setting:

smtps inet n - n - - smtpd

and try again

after try like this:

open up main.cf and go throu following

smtpd_sasl_auth_enable = yes
smtpd_sasl_security_options = noanonymous
smtpd_sasl_local_domain = $myhostname - you defined this right?
broken_sasl_auth_clients = yes

at the type in console postconf and check if these match:

smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, check_recipient_access mysql:/etc/postfix/mysql-virtual_recipient.cf, reject_unauth_destination
smtpd_reject_unlisted_recipient = yes
smtpd_reject_unlisted_sender = no
smtpd_restriction_classes =
smtpd_sasl_auth_enable = yes
smtpd_sasl_authenticated_header = yes
smtpd_sasl_exceptions_networks =
smtpd_sasl_local_domain =
smtpd_sasl_path = smtpd
smtpd_sasl_security_options = noanonymous
smtpd_sasl_tls_security_options = $smtpd_sasl_security_options
smtpd_sasl_type = cyrus
smtpd_sender_login_maps =
smtpd_sender_restrictions = check_sender_access mysql:/etc/postfix/mysql-virtual_sender.cf

lets see if it worked out
__________________
EonTek.rs - System Engineering

dzudzu
Reply With Quote
  #10  
Old 23rd July 2009, 19:19
madmerlin madmerlin is offline
Junior Member
 
Join Date: Jun 2009
Posts: 21
Thanks: 2
Thanked 0 Times in 0 Posts
 
Default

unfortunately those changes in the master.cf file didn't help.

I also made sure all my settings matched the ones you listed with postconf.

Frustrating. Thanks for the help appreciate it. Any other ideas?
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Postfix: 554 5.7.1 Relay access denied Crog Server Operation 4 26th March 2010 14:19
ISP Config hesitation when opening web pages frankb Installation/Configuration 7 15th December 2008 13:06
postfix 554 Relay access denied ratcateme Server Operation 1 29th May 2008 18:52
Apache Ownership cybereatl General 2 26th March 2008 12:25
Questions in regards to ISP-Server Setup - Ubuntu 5.10 "Breezy Badger" rbrantley HOWTO-Related Questions 16 10th April 2006 18:26


All times are GMT +2. The time now is 17:34.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.