Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

smarthost nimmt mail nicht an - Unauthorized sender address

196 views
Skip to first unread message

Anton Blau

unread,
May 3, 2020, 6:52:00 PM5/3/20
to
Hallo,

ich möchte folgendes Szenario einrichten:

Lokaler User: av...@firstmail.locallan

Dessen E-Mails werden an mail.gmx.net als Smarthost weitergeleitet. Zur
Auslieferung an gmx wird auf den Namen tony.bl...@gmx.de umgeschrieben.


Problem:

Wenn ich mich auf dem Rechner firstmail.locallan als user avmb1
eingeloggt bin funktioniert der Mailversand fehlerfrei (echo "Dies ist
die Testmail" | mail -s "Testmail" test....@gmx.de). gmx nimmt das
E-Mail an.

Wenn ich hingegen per Thunderbird das E-Mail als
av...@firstcloud.locallan an firstcloud.locallan weiterleite scheitert
die Auslieferung.


Log-files:

/var/log/syslog bei Versand über TB -> firstmail.locallan -> mail.gmx.net

May 4 00:25:00 firstmail postfix/smtpd[3101]: connect from
unknown[192.168.1.1]
May 4 00:25:00 firstmail dovecot: auth: Debug: Loading modules from
directory: /usr/lib/dovecot/modules/auth
May 4 00:25:00 firstmail dovecot: auth: Debug: Module loaded:
/usr/lib/dovecot/modules/auth/lib20_auth_var_expand_crypt.so
May 4 00:25:00 firstmail dovecot: auth: Debug: Read auth token secret
from /var/run/dovecot/auth-token-secret.dat
May 4 00:25:00 firstmail dovecot: auth: Debug: passwd-file
/etc/dovecot/users: Read 1 users in 0 secs
May 4 00:25:00 firstmail dovecot: auth: Debug: auth client connected
(pid=0)
May 4 00:25:00 firstmail dovecot: auth: Debug: client in:
AUTH#0111#011PLAIN#011service=smtp#011nologin#011lip=192.168.3.210#011rip=192.168.1.1#011secured#011resp=AGF2bWIxQGZpcnN0bWsfagFpbC5kdWNrAGF2bWIx
(previous base64 data may contain sensitive data)
May 4 00:25:00 firstmail dovecot: auth: Debug:
passwd-file(av...@firstmail.locallan,192.168.1.1): lookup:
user=av...@firstmail.locallan file=/etc/dovecot/users
May 4 00:25:00 firstmail dovecot: auth: Debug: client passdb out:
OK#0111#011user=av...@firstmail.locallan
May 4 00:25:00 firstmail postfix/smtpd[3101]: F18D385FB:
client=unknown[192.168.1.1], sasl_method=PLAIN,
sasl_username=av...@firstmail.locallan
May 4 00:25:00 firstmail postfix/cleanup[3107]: F18D385FB:
message-id=<1484abd2-6bca-0202...@firstmail.locallan>
May 4 00:25:01 firstmail postfix/qmgr[3001]: F18D385FB:
from=<tony.bl...@gmx.de>, size=776, nrcpt=1 (queue active)
May 4 00:25:01 firstmail postfix/smtpd[3101]: disconnect from
unknown[192.168.1.1] ehlo=2 starttls=1 auth=1 mail=1 rcpt=1 data=1
quit=1 commands=8
May 4 00:25:01 firstmail dovecot: imap(av...@firstmail.locallan): save:
box=Sent, uid=4,
msgid=<1484abd2-6bca-0202...@firstmail.locallan>, size=423
May 4 00:25:01 firstmail dovecot: imap(av...@firstmail.locallan):
Connection closed (IDLE running for 0.001 + waiting input for 0.001
secs, 2 B in + 10 B out, state=wait-input) in=1352 out=3556
May 4 00:25:01 firstmail dovecot: auth: Debug: auth client connected
(pid=3111)
May 4 00:25:01 firstmail dovecot: auth: Debug: client in:
AUTH#0111#011PLAIN#011service=imap#011secured#011session=T72j4sWkNNDAqAEB#011lip=192.168.3.210#011rip=192.168.1.1#011lport=143#011rport=53300#011local_name=firstmail.locallan
May 4 00:25:01 firstmail dovecot: auth: Debug: client passdb out: CONT#0111
May 4 00:25:01 firstmail dovecot: auth: Debug: client in:
CONT#0111#011AGF2bWIxQGZpcnN0bWFpbC5kdWNrAGF2bWIx (previous base64 data
may contain sensitive data)
May 4 00:25:01 firstmail dovecot: auth: Debug:
passwd-file(av...@firstmail.locallan,192.168.1.1,<T72j4sWkNNDAqAEB>):
lookup: user=av...@firstmail.locallan file=/etc/dovecot/users
May 4 00:25:01 firstmail dovecot: auth: Debug: client passdb out:
OK#0111#011user=av...@firstmail.locallan
May 4 00:25:01 firstmail dovecot: auth: Debug: master in:
REQUEST#0113129212929#0113111#0111#011a4372b9c9262b5dab150c569f0b0ac51#011session_pid=3113#011request_auth_token
May 4 00:25:01 firstmail dovecot: auth: Debug:
passwd-file(av...@firstmail.locallan,192.168.1.1,<T72j4sWkNNDAqAEB>):
lookup: user=av...@firstmail.locallan file=/etc/dovecot/users
May 4 00:25:01 firstmail dovecot: auth: Debug: master userdb out:
USER#0113129212929#011a...@firstmail.locallan#011uid=5005#011gid=5000#011home=/var/vmail/firstmail.locallan/avmb1#011auth_token=af529ba9aa05b79b556d5eb32826806cbd70d903
May 4 00:25:01 firstmail dovecot: imap-login: Login:
user=<av...@firstmail.locallan>, method=PLAIN, rip=192.168.1.1,
lip=192.168.3.210, mpid=3113, TLS
May 4 00:25:01 firstmail postfix/smtp[3109]: F18D385FB:
to=<test....@gmx.de>, relay=mail.gmx.net[212.227.17.190]:25,
delay=0.63, delays=0.05/0.01/0.46/0.11, dsn=5.0.0, status=bounced (host
mail.gmx.net[212.227.17.190] said: 554-Transaction failed 554
Unauthorized sender address. (in reply to end of DATA command))
May 4 00:25:01 firstmail postfix/cleanup[3107]: 9D3AF8501:
message-id=<202005032225...@firstmail.localdomain>
May 4 00:25:01 firstmail postfix/bounce[3114]: F18D385FB: sender
non-delivery notification: 9D3AF8501
May 4 00:25:01 firstmail postfix/qmgr[3001]: 9D3AF8501: from=<>,
size=2888, nrcpt=1 (queue active)
May 4 00:25:01 firstmail postfix/qmgr[3001]: F18D385FB: removed
May 4 00:25:01 firstmail postfix/smtp[3109]: 9D3AF8501:
to=<tony.bl...@gmx.de>, relay=mail.gmx.net[212.227.17.190]:587,
delay=0.31, delays=0.01/0/0.27/0.02, dsn=5.0.0, status=bounced (host
mail.gmx.net[212.227.17.190] said: 530 Authentication required (in reply
to MAIL FROM command))
May 4 00:25:02 firstmail postfix/qmgr[3001]: 9D3AF8501: removed


/var/log/syslog bei Versand als user avmb1 auf dem Rechner
firstmail.locallan per: avmb1@firstmail:/etc/postfix$ echo "Dies ist die
19. Testmail" | mail -s "19. Testmail" test....@gmx.de

May 4 00:37:52 firstmail postfix/pickup[3000]: C906B8503: uid=1001
from=<avmb1>
May 4 00:37:52 firstmail postfix/cleanup[3130]: C906B8503:
message-id=<202005032237...@firstmail.localdomain>
May 4 00:37:52 firstmail postfix/qmgr[3001]: C906B8503:
from=<tony.bl...@gmx.de>, size=436, nrcpt=1 (queue active)
May 4 00:37:53 firstmail postfix/smtp[3134]: C906B8503:
to=<test....@gmx.de>, relay=mail.gmx.net[212.227.17.168]:25,
delay=0.59, delays=0.05/0.01/0.41/0.12, dsn=2.0.0, status=sent (250
Requested mail action okay, completed: id=1Mnpru-1ipDoZ18uI-00pOxV)
May 4 00:37:53 firstmail postfix/qmgr[3001]: C906B8503: removed


/etc/postfix/main.cf
smtpd_banner = $myhostname ESMTP $mail_name (Debian/GNU)
biff = no
append_dot_mydomain = no
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases
mydestination = firstmail.locallan, localhost.locallan, localhost,
*.locallan
relayhost = mail.gmx.net:587
mynetworks = 127.0.0.0/8, 192.168.1.0/24
inet_interfaces = all
recipient_delimiter = +

myorigin = /etc/mailname
mailbox_size_limit = 0
inet_protocols = all

# Der Smarthost mail.gmx.net verlangt zum Versenden einer E-Mail ein
Passwort.
smtp_sender_dependent_authentication = yes
smtp_sasl_auth_enable = yes
smtp_sasl_security_options = noanonymous
smtp_connection_cache_on_demand = no
smtp_sasl_password_maps = hash:/etc/postfix/sasl_password
smtp_tls_security_level = encrypt

sender_dependent_relayhost_maps = hash:/etc/postfix/sender_dependent
sender_canonical_maps = hash:/etc/postfix/sender_canonical

smtpd_sasl_auth_enable = yes
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/dovecot-auth
smtpd_sasl_authenticated_header = yes
smtpd_sasl_security_options = noanonymous
smtpd_sasl_local_domain = $myhostname
broken_sasl_auth_clients = yes
smtpd_recipient_restrictions = reject_unknown_sender_domain,
reject_unknown_recipient_domain, reject_unauth_pipelining,
permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination
smtpd_sender_restrictions = reject_unknown_sender_domain
mailbox_command = /usr/lib/dovecot/deliver -c /etc/dovecot/dovecot.conf
-m "${EXTENSION}"
smtpd_tls_cert_file = /etc/dovecot/private/dovecot.pem
smtpd_tls_key_file = /etc/dovecot/private/dovecot.key
smtpd_use_tls = yes
smtp_use_tls = yes
smtpd_tls_received_header = yes
smtpd_tls_auth_only = yes
tls_random_source = dev:/dev/urandom


Woran kann das liegen?


Vielen Dank!


Tony

Anton Blau

unread,
May 5, 2020, 4:50:09 PM5/5/20
to
Am 04.05.2020 um 00:51 schrieb Anton Blau:

Ich konnte das Problem zwischenzeitlich eingrenzen. Das Problem tritt
immer auf, wenn ein E-Mail von einem (nichtvirtuellen) lokalen user
versendet wird, der in der /etc/passwd eingetragen ist.

Auch wenn ich diesen in der Gruppe vmail hinzufüge kommt die
Fehlermeldung: User initialization failed: Namespace '':
stat(/var/vmail/mail/dad) failed: Permission denied (euid=1000(dad)
egid=1000(dad) missing +x perm: /var/vmail, we're not in group
5000(vmail), dir owned by 5000:5000 mode=0770)

Offensichtlich kann dovecot mit den lokalen user nicht im Verzeicnis
/var/vmail schreiben.

Wie könnte ich denn das lösen?

Vielen Dank!

Tony

P. S. hier die vollständige /var/log/syslog

May 5 22:46:16 firstmail postfix/pickup[1633]: 32C29CA34: uid=1000
from=<dad>
May 5 22:46:16 firstmail postfix/cleanup[1722]: 32C29CA34:
message-id=<202005052046...@firstmail.localdomain>
May 5 22:46:16 firstmail postfix/qmgr[1634]: 32C29CA34:
from=<d...@firstmail.locallan>, size=421, nrcpt=1 (queue active)
May 5 22:46:16 firstmail postfix/smtp[1726]: 32C29CA34:
to=<test....@gmx.de>, relay=mail.gmx.net[212.227.17.190]:587,
delay=0.36, delays=0.07/0.01/0.26/0.02, dsn=5.0.0, status=bounced (host
mail.gmx.net[212.227.17.190] said: 530 Authentication required (in reply
to MAIL FROM command))
May 5 22:46:16 firstmail postfix/cleanup[1722]: 95EC4CA35:
message-id=<202005052046...@firstmail.localdomain>
May 5 22:46:16 firstmail postfix/bounce[1729]: 32C29CA34: sender
non-delivery notification: 95EC4CA35
May 5 22:46:16 firstmail postfix/qmgr[1634]: 95EC4CA35: from=<>,
size=2443, nrcpt=1 (queue active)
May 5 22:46:16 firstmail postfix/qmgr[1634]: 32C29CA34: removed
May 5 22:46:16 firstmail dovecot: lda(dad): Error: User initialization
failed: Namespace '': stat(/var/vmail/mail/dad) failed: Permission
denied (euid=1000(dad) egid=1000(dad) missing +x perm: /var/vmail, we're
not in group 5000(vmail), dir owned by 5000:5000 mode=0770)
May 5 22:46:16 firstmail dovecot: lda: Fatal: Invalid user settings.
Refer to server log for more information.
May 5 22:46:16 firstmail postfix/local[1730]: 95EC4CA35:
to=<d...@firstmail.locallan>, relay=local, delay=0.06,
delays=0.04/0/0/0.02, dsn=4.3.0, status=deferred (temporary failure)
May 5 22:46:16 firstmail postfix/local[1730]: using
backwards-compatible default setting relay_domains=$mydestination to
update fast-flush logfile for domain "firstmail.locallan"
0 new messages