<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Stefano Rivera (Posts about postfix)</title><link>https://stefanorivera.com/</link><description></description><atom:link href="https://stefanorivera.com/categories/postfix.xml" rel="self" type="application/rss+xml"></atom:link><language>en</language><copyright>Contents © 2026 &lt;a href="mailto:stefano@rivera.za.net"&gt;Stefano Rivera&lt;/a&gt; 
&lt;a rel="license" href="https://creativecommons.org/licenses/by-sa/4.0/"&gt;
&lt;img alt="Creative Commons License BY-SA"
     class="cc-license-button"
     src="/assets/img/cc-by-sa-4.0.svg"&gt;&lt;/a&gt;</copyright><lastBuildDate>Fri, 01 May 2026 14:29:42 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>s_client's R "feature"</title><link>https://stefanorivera.com/posts/2007/07/17/sclients-r-feature/</link><dc:creator>Stefano Rivera</dc:creator><description>&lt;p&gt;I've just spent a few hours brain-haemorrhaging over why my new Postfix server wasn't allowing me to enter "RCPT TO:" over a STARTTLS connection. Instead it would renegotiate the TLS.&lt;/p&gt;
&lt;p&gt;Eventually I found &lt;a href="http://archives.neohapsis.com/archives/postfix/2007-01/1334.html"&gt;an e-mail by Wietse Venema&lt;/a&gt; saying:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;Victor Duchovni:
&lt;span class="k"&gt;&amp;gt; &lt;/span&gt;&lt;span class="ge"&gt;On Mon, Jan 22, 2007 at 04:31:12PM -0500, Wietse Venema wrote: &lt;/span&gt;
&lt;span class="k"&gt;&amp;gt; &lt;/span&gt;&lt;span class="ge"&gt;&amp;gt; RCPT TO:&amp;lt;postmaster&amp;gt;&lt;/span&gt;
&lt;span class="k"&gt;&amp;gt; &lt;/span&gt;&lt;span class="ge"&gt;&amp;gt; RENEGOTIATING&lt;/span&gt;
&lt;span class="k"&gt;&amp;gt;&lt;/span&gt;
&lt;span class="ge"&gt;&amp;gt; You got bit by the "s_client" "R" feature... try "rcpt to:" lower case,&lt;/span&gt;
&lt;span class="k"&gt;&amp;gt; &lt;/span&gt;&lt;span class="ge"&gt;then it hangs up.&lt;/span&gt;

What utter brain damage, a non-transparent SSL client program.
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Read this and be warned -- we are all stupid, in the eyes of the truly mad &lt;code&gt;s_client&lt;/code&gt;&lt;/p&gt;</description><category>debian</category><category>postfix</category><category>ubuntu</category><guid>http://tumbleweed.org.za/2007/07/17/sclients-r-feature</guid><pubDate>Tue, 17 Jul 2007 12:28:50 GMT</pubDate></item><item><title>Postfix + SMTP-AUTH</title><link>https://stefanorivera.com/posts/2007/02/23/postfix-smtp-auth/</link><dc:creator>Stefano Rivera</dc:creator><description>&lt;p&gt;I finally found a &lt;a href="http://www.jimmy.co.at/weblog/?p=52"&gt;good blog post&lt;/a&gt; on the subject of getting Postfix to do SMTP-AUTH via SASL.&lt;/p&gt;
&lt;p&gt;I went one step further, and instead of moving &lt;code&gt;/var/run/saslauthd/&lt;/code&gt; to the Postfix chroot, I did a bind mount:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;/etc/fstab&lt;/code&gt;:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;run&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;saslauthd&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;spool&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;postfix&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;run&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;saslauthd&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;none&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;bind&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="w"&gt;     &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Postfix was announcing methods like CRAM-MD5 which can't be supported by the PAM backend, so I restricted them down to PLAIN and LOGIN (over TLS only, obviously):&lt;/p&gt;
&lt;p&gt;&lt;code&gt;/etc/postfix/sasl/smtpd.conf&lt;/code&gt;:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;&lt;span class="n"&gt;pwcheck_method&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;saslauthd&lt;/span&gt;
&lt;span class="n"&gt;mech_list&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;plain&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;login&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;Now, it's working nicely, and I can IMAPS and SMTP-AUTH-TLS to my mail server from anywhere.&lt;/p&gt;</description><category>debian</category><category>postfix</category><category>sasl</category><category>software</category><guid>http://tumbleweed.org.za/2007/02/23/postfix-smtp-auth</guid><pubDate>Fri, 23 Feb 2007 15:18:12 GMT</pubDate></item></channel></rss>