You can subscribe to this list here.
2005 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(10) |
Aug
(1) |
Sep
(20) |
Oct
(2) |
Nov
(4) |
Dec
(30) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2006 |
Jan
(2) |
Feb
(12) |
Mar
|
Apr
(6) |
May
|
Jun
(3) |
Jul
(9) |
Aug
(10) |
Sep
(5) |
Oct
(2) |
Nov
(16) |
Dec
(6) |
2007 |
Jan
|
Feb
(5) |
Mar
(39) |
Apr
(60) |
May
(54) |
Jun
(45) |
Jul
(29) |
Aug
(140) |
Sep
(72) |
Oct
(78) |
Nov
(96) |
Dec
(63) |
2008 |
Jan
(141) |
Feb
(59) |
Mar
(89) |
Apr
(121) |
May
(101) |
Jun
(58) |
Jul
(118) |
Aug
(57) |
Sep
(13) |
Oct
(15) |
Nov
(78) |
Dec
(3) |
2009 |
Jan
(30) |
Feb
(51) |
Mar
(31) |
Apr
(15) |
May
(15) |
Jun
(25) |
Jul
(23) |
Aug
(19) |
Sep
(18) |
Oct
(8) |
Nov
(13) |
Dec
(38) |
2010 |
Jan
(21) |
Feb
(18) |
Mar
(5) |
Apr
(16) |
May
(3) |
Jun
(4) |
Jul
(11) |
Aug
|
Sep
(12) |
Oct
(1) |
Nov
(5) |
Dec
(3) |
2011 |
Jan
|
Feb
(4) |
Mar
(5) |
Apr
|
May
(5) |
Jun
|
Jul
|
Aug
(9) |
Sep
|
Oct
|
Nov
|
Dec
|
2012 |
Jan
|
Feb
(2) |
Mar
(4) |
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(3) |
Sep
|
Oct
|
Nov
|
Dec
|
From: Ilyas -- <um...@gm...> - 2012-08-17 23:13:03
|
Dear Scott, Thank you for response. I checked opendkim and it's work fine! On Fri, Aug 17, 2012 at 6:27 PM, Scott Kitterman <iet...@ki...> wrote: > On Friday, August 17, 2012 05:51:18 PM Ilyas -- wrote: > ... >> Somebody known how to fix my problem? > ... > The first thing to try is switching to opendkim (it is a maintained fork of > dkim-milter) because dkim-milter has been unmaintained for years and is known > to be buggy in many respects. See opendkim.org. > > Scott K > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > dkim-milter-discuss mailing list > dki...@li... > https://lists.sourceforge.net/lists/listinfo/dkim-milter-discuss -- GPG Key ID: 6EC5EB27 |
From: Scott K. <iet...@ki...> - 2012-08-17 14:43:41
|
On Friday, August 17, 2012 05:51:18 PM Ilyas -- wrote: ... > Somebody known how to fix my problem? ... The first thing to try is switching to opendkim (it is a maintained fork of dkim-milter) because dkim-milter has been unmaintained for years and is known to be buggy in many respects. See opendkim.org. Scott K |
From: Ilyas -- <um...@gm...> - 2012-08-17 13:51:30
|
Hello, I have problem with dkim-milter (dkim-milter-2.8.3). dkim-milter successfully signing most emails, but some emails (which look normal) pass via relay without signing. My research show that problem occurs when From and To headers follow in some order. There are two cases. Case 1: message does not signed. SMTP session: ================================8<======================= [ro...@ma... /]# telnet 0 25 Trying 0.0.0.0... Connected to 0. Escape character is '^]'. 220 mailrelay.ourdomain.com ESMTP Postfix EHLO localhost 250-mailrelay.ourdomain.com 250-PIPELINING 250-SIZE 10240000 250-VRFY 250-ETRN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250 DSN MAIL FROM: <no...@ou...> 250 2.1.0 Ok RCPT TO: <som...@gm...> 250 2.1.5 Ok DATA 354 End data with <CR><LF>.<CR><LF> From: <no...@ou...> To: <som...@gm...> . 250 2.0.0 Ok: queued as 427862C8819 ================================8<======================= Postfix log: ================================8<======================= 2012-08-17T17:08:29.360923+04:00 mailrelay postfix/smtpd[22226]: connect from localhost.localdomain[127.0.0.1] 2012-08-17T17:08:41.274738+04:00 mailrelay postfix/smtpd[22226]: 427862C8819: client=localhost.localdomain[127.0.0.1] 2012-08-17T17:08:51.217937+04:00 mailrelay postfix/cleanup[21928]: 427862C8819: message-id=<201...@ma...> 2012-08-17T17:08:51.218055+04:00 mailrelay dkim-filter[1425]: (unknown-jobid): no sender header found; accepting 2012-08-17T17:08:51.222046+04:00 mailrelay postfix/qmgr[19619]: 427862C8819: from=<no...@ou...>, size=204, nrcpt=1 (queue active) 2012-08-17T17:08:51.511028+04:00 mailrelay postfix/smtp[22194]: 427862C8819: to=<som...@gm...>, relay=gmail-smtp-in.l.google.com[173.194.70.27]:25, delay=19, delays=19/0/0.05/0.24, dsn=2.0.0, status=sent (250 2.0.0 OK 4145308131 l8si01973873odq.99) 2012-08-17T17:08:51.511150+04:00 mailrelay postfix/qmgr[19619]: 427862C8819: removed ================================8<======================= Case 2: message signed successfully. Sic! I just changes From and To headers in message body (not in envelope). SMTP session: ================================8<======================= [ro...@ma... /]# telnet 0 25 Trying 0.0.0.0... Connected to 0. Escape character is '^]'. 220 mailrelay.ourdomain.com ESMTP Postfix EHLO localhost 250-mailrelay.ourdomain.com 250-PIPELINING 250-SIZE 10240000 250-VRFY 250-ETRN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250 DSN MAIL FROM: <no...@ou...> 250 2.1.0 Ok RCPT TO: <som...@gm...> 250 2.1.5 Ok DATA 354 End data with <CR><LF>.<CR><LF> To: <som...@gm...> From: <no...@ou...> . 250 2.0.0 Ok: queued as 480582C8822 ================================8<======================= Postfix log: ================================8<======================= 2012-08-17T17:14:00.026839+04:00 mailrelay postfix/smtpd[22226]: connect from localhost.localdomain[127.0.0.1] 2012-08-17T17:14:12.295149+04:00 mailrelay postfix/smtpd[22226]: 480582C8822: client=localhost.localdomain[127.0.0.1] 2012-08-17T17:14:19.177684+04:00 mailrelay postfix/cleanup[22399]: 480582C8822: message-id=<201...@ma...> 2012-08-17T17:14:19.177845+04:00 mailrelay dkim-filter[1425]: (unknown-jobid) mode select: signing 2012-08-17T17:14:19.183373+04:00 mailrelay dkim-filter[1425]: 480582C8822 "DKIM-Signature" header added 2012-08-17T17:14:19.193229+04:00 mailrelay postfix/qmgr[19619]: 480582C8822: from=<no...@ou...>, size=200, nrcpt=1 (queue active) 2012-08-17T17:14:19.428857+04:00 mailrelay postfix/smtp[22308]: 480582C8822: to=<som...@gm...>, relay=gmail-smtp-in.l.google.com[173.194.70.27]:25, delay=9.7, delays=9.4/0/0.04/0.19, dsn=2.0.0, status=sent (250 2.0.0 OK 9201917281 wd2si12002916oiq.90) 2012-08-17T17:14:19.428994+04:00 mailrelay postfix/qmgr[19619]: 480582C8822: removed ================================8<======================= dkim-milter config and keys definition: # cat /etc/mail/dkim-milter/dkim-filter.conf | egrep -v '^$'| egrep -v '^#' ================================8<======================= AutoRestart yes Canonicalization relaxed/simple InternalHosts /etc/postfix/mynetworks KeyList /etc/mail/dkim-milter/keys/keylist LogWhy yes SignatureAlgorithm rsa-sha256 Syslog yes SyslogSuccess yes UMask 007 UserID dkim-milter ================================8<======================= # cat /etc/mail/dkim-milter/keys/keylist ================================8<======================= # sender-pattern:signing-domain:keypath # *:example.com:selector *@ourdomain.com:ourdomain.com:/etc/mail/dkim-milter/keys/climail *@list.ourdomain.com:list.ourdomain.com:/etc/mail/dkim-milter/keys/list *@daily.ourdomain.com:daily.ourdomain.com:/etc/mail/dkim-milter/keys/daily ================================8<======================= Somebody known how to fix my problem? P.S. Some software send emails only as described in Case 2 and I cannot fix this problem in this software. |
From: Scott K. <iet...@ki...> - 2012-06-29 13:55:54
|
On Friday, June 29, 2012 05:44:12 PM Hiren Mistry wrote: > Hi, > > I have configured Zimbra 7.0 mail server with community edition, I have > tried to installed DKIM-Milter. I got "DKIM-Signature" in mail headers > but in "Authentication-Results:" the dkim show as *neutral (bad format)*. > I also observe, when we make communicate with "Gmail", mail goes into > spam in both side (Incoming & Outgoing). > I have copied full mail headers at below. Please any one can help to > resolve this issue. dkim-milter is unmaintained, buggy, and obsolete. Use the more modern fork, opendkim, instead. See opendkim.org. Scott K |
From: Hiren M. <hir...@gm...> - 2012-06-29 12:14:26
|
Hi, I have configured Zimbra 7.0 mail server with community edition, I have tried to installed DKIM-Milter. I got "DKIM-Signature" in mail headers but in "Authentication-Results:" the dkim show as *neutral (bad format)*. I also observe, when we make communicate with "Gmail", mail goes into spam in both side (Incoming & Outgoing). I have copied full mail headers at below. Please any one can help to resolve this issue. ------------------------------------------------------------------------------------------------------------------------- From - Thu Jun 28 23:02:50 2012 X-Account-Key: account1 X-UIDL: GmailId1383426bde652d2b X-Mozilla-Status: 0001 X-Mozilla-Status2: 00000000 X-Mozilla-Keys: Delivered-To: hir...@gm... Received: by 10.143.37.12 with SMTP id p12csp38065wfj; Thu, 28 Jun 2012 10:32:48 -0700 (PDT) Received: by 10.68.221.106 with SMTP id qd10mr10250833pbc.42.1340904750810; Thu, 28 Jun 2012 10:32:30 -0700 (PDT) Return-Path: <hiren.mistry@XXXXXXXXXX.com> Received: from mailsrv.XXXXXXXXXX.com ([14.XX.XX.XX]) by mx.google.com with ESMTP id tj6si4038790pbc.348.2012.06.28.10.32.29; Thu, 28 Jun 2012 10:32:30 -0700 (PDT) Received-SPF: pass (google.com: domain of hiren.mistry@XXXXXXXXXX.com designates 14.XX.XX.XX as permitted sender) client-ip=14.XX.XX.XX; Authentication-Results: mx.google.com; spf=pass (google.com: domain of hiren.mistry@XXXXXXXXXX.com designates 14.XX.XX.XX as permitted sender) smtp.mail=hiren.mistry@XXXXXXXXXX.com; dkim=neutral (bad format) header.i=@XXXXXXXXXX.com Received: from localhost (localhost.localdomain [127.0.0.1]) by mailsrv.XXXXXXXXXX.com (Postfix) with ESMTP id E495422B02F2 for <hir...@gm...>; Thu, 28 Jun 2012 23:02:18 +0530 (IST) X-DKIM: Sendmail DKIM Filter v2.8.3 mailsrv.XXXXXXXXXX.com E495422B02F2 DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=XXXXXXXXXX.com; s=default; t=1340904738; bh=fdkeB/A0FkbVP2k4J4pNPoeWH6vqBm9+b0C3OY87Cw8=; h=Date:From:To:Message-ID:In-Reply-To:Subject:MIME-Version: Content-Type:Content-Transfer-Encoding; b=Pd3ttpME9BX59rL4uaKL3mojyTyeX6uir15MUlc9tw4aRo6hByvaTmajJ95dNXsZH br7P51DYUKGirFDHm9IOPC6rHWXdWim3v4PPBlWClp17+E5Q8iXteL4XEXOLBN7cbq l3kJHPbwjS1+QVqQlQSG+zkIWP/ZfxLzNx957Pmw= X-Virus-Scanned: amavisd-new at mailsrv.XXXXXXXXXX.com Received: from mailsrv.XXXXXXXXXX.com ([127.0.0.1]) by localhost (mailsrv.XXXXXXXXXX.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ESOKx29OOE+V for <hir...@gm...>; Thu, 28 Jun 2012 23:02:13 +0530 (IST) Received: from mailsrv.XXXXXXXXXX.com (mailsrv.XXXXXXXXXX.com [172.16.0.61]) by mailsrv.XXXXXXXXXX.com (Postfix) with ESMTP id 356F422B02F1 for <hir...@gm...>; Thu, 28 Jun 2012 23:02:13 +0530 (IST) Date: Thu, 28 Jun 2012 23:02:13 +0530 (IST) From: hiren.mistry@XXXXXXXXXX.com To: hir...@gm... Message-ID: <78822677.40.1340904733070.JavaMail.root@XXXXXXXXXX.com> In-Reply-To: <1326166907.10.1340865323322.JavaMail.root@XXXXXXXXXX.com> Subject: test mail @ 23:02 PM MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-Originating-IP: [172.16.75.1] X-Mailer: Zimbra 7.2.0_GA_2669 (ZimbraWebClient - FF3.0 (Win)/7.2.0_GA_2669) ------------------------------------------------------------------------------------------------------------------------------------------ ** |
From: Benny B. <Ben...@gm...> - 2012-03-27 22:15:00
|
Hi, and thanks for the quick reply! Am 27.03.2012 23:49, schrieb Murray S. Kucherawy: >> -----Original Message----- >> From: Scott Kitterman [mailto:iet...@ki...] >> Sent: Tuesday, March 27, 2012 1:05 PM >> To: dki...@li... >> Subject: Re: [dkim-milter-discuss] internal error from libdkim: ar_addquery() failed >> >> On Tuesday, March 27, 2012 09:00:40 PM Benny Baumann wrote: >>> I'm having some trouble with the dkim-milter package. Currently I'm >>> using the package from Debian Testing (2.8.2). >> >> Switch to opendkim. dkim-milter is dead. The opendkim package in >> Testing (which I co-maintain) has the current release. If you find >> that fixes your problems, please file a bug against dkim-milter. It'll >> help me get it removed so it doesn't get released with Wheezy. > > +1. And if you find it doesn't fix your problem, please report it via the SourceForge bug tracker for opendkim and we'll take a look. > Just checked by updating my server configuration to use opendkim instead of dkim-milter and it seems to work just fine (couldn't test all the detail yet, but looks good so far). Had to manually port some settings from dkim-milter to opendkim (basically the socket in the start script config and the used keys for the daemon config) but that was yet another finger exercise at getting it work. > The dkim-milter package's last release was v2.8.3 in 2009, and it has been unmaintained since then. I guessed having a look at the SF.net project page. Will file a bug with the Debian package when I get around to it. > > -MSK BenBE. > > ------------------------------------------------------------------------------ > This SF email is sponsosred by: > Try Windows Azure free for 90 days Click Here > http://p.sf.net/sfu/sfd2d-msazure > _______________________________________________ > dkim-milter-discuss mailing list > dki...@li... > https://lists.sourceforge.net/lists/listinfo/dkim-milter-discuss > |
From: Murray S. K. <ms...@cl...> - 2012-03-27 22:01:41
|
> -----Original Message----- > From: Scott Kitterman [mailto:iet...@ki...] > Sent: Tuesday, March 27, 2012 1:05 PM > To: dki...@li... > Subject: Re: [dkim-milter-discuss] internal error from libdkim: ar_addquery() failed > > On Tuesday, March 27, 2012 09:00:40 PM Benny Baumann wrote: > > I'm having some trouble with the dkim-milter package. Currently I'm > > using the package from Debian Testing (2.8.2). > > Switch to opendkim. dkim-milter is dead. The opendkim package in > Testing (which I co-maintain) has the current release. If you find > that fixes your problems, please file a bug against dkim-milter. It'll > help me get it removed so it doesn't get released with Wheezy. +1. And if you find it doesn't fix your problem, please report it via the SourceForge bug tracker for opendkim and we'll take a look. The dkim-milter package's last release was v2.8.3 in 2009, and it has been unmaintained since then. -MSK |
From: Scott K. <iet...@ki...> - 2012-03-27 20:30:32
|
On Tuesday, March 27, 2012 09:00:40 PM Benny Baumann wrote: > I'm having some trouble with the dkim-milter package. Currently I'm > using the package from Debian Testing (2.8.2). Switch to opendkim. dkim-milter is dead. The opendkim package in Testing (which I co-maintain) has the current release. If you find that fixes your problems, please file a bug against dkim-milter. It'll help me get it removed so it doesn't get released with Wheezy. Scott K |
From: Benny B. <Ben...@gm...> - 2012-03-27 19:00:53
|
Hi, I'm having some trouble with the dkim-milter package. Currently I'm using the package from Debian Testing (2.8.2). I repeatedly get the following error in my logs: Mar 25 23:00:42 server dkim-filter[1337]: FEDCBA987654: dkim_eoh(): internal error from libdkim: ar_addquery() for `20120113._domainkey.gmail.com' failed Looking up this domain using dig shows the result get's truncated: $ dig in txt 20120113._domainkey.gmail.com ;; Truncated, retrying in TCP mode. ; <<>> DiG 9.8.1-P1 <<>> in txt 20120113._domainkey.gmail.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 31318 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 4, ADDITIONAL: 4 ;; QUESTION SECTION: ;20120113._domainkey.gmail.com. IN TXT ;; ANSWER SECTION: 20120113._domainkey.gmail.com. 258 IN TXT "k=rsa\; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1Kd87/UeJjenpabgbFwh+eBCsSTrqmwIYYvywlbhbqoo2DymndFkbjOVIPIldNs/m40KF+yzMn1skyoxcTUGCQs8g3FgD2Ap3ZB5DekAo5wMmk4wimDO+U8QzI3SD0" "7y2+07wlNWwIt8svnxgdxGkVbbhzY8i+RQ9DpSVpPbF7ykQxtKXkv/ahW3KjViiAH+ghvvIhkx4xYSIc9oSwVmAl5OctMEeWUwg8Istjqz8BZeTWbf41fbNhte7Y+YqZOwq1Sd0DbvYAD9NOZK9vlfuac0598HY+vtSBczUiKERHv1yRbcaQtZFh5wtiRrN04BLUTD21MycBX5jYchHjPY/wIDAQAB" ;; AUTHORITY SECTION: gmail.com. 80381 IN NS ns2.google.com. gmail.com. 80381 IN NS ns4.google.com. gmail.com. 80381 IN NS ns3.google.com. gmail.com. 80381 IN NS ns1.google.com. ;; ADDITIONAL SECTION: ns1.google.com. 79281 IN A 216.239.32.10 ns2.google.com. 79281 IN A 216.239.34.10 ns3.google.com. 79281 IN A 216.239.36.10 ns4.google.com. 79281 IN A 216.239.38.10 ;; Query time: 0 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Tue Mar 27 20:53:50 2012 ;; MSG SIZE rcvd: 605 When doing a dump with tcpdump the full response needed in the request is recieved in the UDP response. As discussed in http://permalink.gmane.org/gmane.mail.sendmail.dkim-milter.general/203 no TCP fallback is necessary (and none is tried) but also this packet is dropped as invalid (as I found while I tried to debug the issue. Is there any known solution or work around for this problem? Best regards, BenBE. |
From: Murray S. K. <ms...@cl...> - 2012-02-17 18:56:43
|
dkim-milter support has been discontinued. You should instead switch to OpenDKIM, http://www.opendkim.org. That said, the error means you're getting mail from someone that's signed by a key that can't be found in the DNS. The error is legitimate, and there's not much you can do about it other than ignore it or filter mail from that source. -MSK From: Admin [mailto:he...@pc...] Sent: Friday, February 17, 2012 10:09 AM To: dki...@li... Subject: [dkim-milter-discuss] error on DKIM one inbound domain Hello. can someone help me get this error and continuing server errors with DKIM? The problem is that i am getting this in my OSSEC logs my the thousands from this ONE domain. Postfix, mailman. I have no other problems with DKIM ever, but for the last few weeks with this error. Received From: www->/var/log/maillog Rule: 1002 fired (level 2) -> "Unknown problem somewhere in the system." Portion of the log(s): Feb 16 20:42:47 www dkim-filter[1305]: 560704ACD3D: key retrieval failed (s=k1, d=monobestoffers.info<http://monobestoffers.info/>): res_query(): `k1._domainkey.monobestoffers.info<http://domainkey.monobestoffers.info/>' Unknown host IT would not bother me, except i have blocked the ip from the firewall and continue to recieve the errors and am worried about the load on the mailsystem and server. How can I stop it and what is going on, any help would be appreciated. Thanks, |
From: Admin <he...@pc...> - 2012-02-17 18:41:49
|
Hello. can someone help me get this error and continuing server errors with DKIM? The problem is that i am getting this in my OSSEC logs my the thousands from this ONE domain. Postfix, mailman. I have no other problems with DKIM ever, but for the last few weeks with this error. Received From: www->/var/log/maillog Rule: 1002 fired (level 2) -> "Unknown problem somewhere in the system." Portion of the log(s): Feb 16 20:42:47 www dkim-filter[1305]: 560704ACD3D: key retrieval failed (s=k1, d=monobestoffers.info <http://monobestoffers.info/>): res_query(): `k1._domainkey.monobestoffers.info <http://domainkey.monobestoffers.info/>' Unknown host IT would not bother me, except i have blocked the ip from the firewall and continue to recieve the errors and am worried about the load on the mailsystem and server. How can I stop it and what is going on, any help would be appreciated. Thanks, |
From: Rolf E. S. <R.E...@so...> - 2011-08-23 08:10:32
|
On 8/23/11 2:10 AM, Subscribe wrote: > Hello List, > > I have just found this mailing list in my search for help to get my > emails signed using DKIM. I followed a few examples and can now see this: > > Authentication-Results: mx.elandsys.com; dkim=permerror > (verification error: signature timestamp in the future) > header.i=@sakafete.com header.b=benCvdNW; dkim-adsp=none > Received: from [127.0.0.1] (d24-36-134-162.home1.cgocable.net [24.36.134.162]) > by cakafeteinc.propagation.net (Postfix) with ESMTPA id 433D0238D2F > for<aut...@dk...>; Wed, 17 Aug 2011 21:33:33 -0500 (CDT) > DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=sakafete.com; > s=default.private; t=1313634813; bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN > /XKdLCPjaYaY=; h=Message-ID:Date:From:MIME-Version:To:Subject: > Content-Type:Content-Transfer-Encoding; b=benCvdNWqqvUbMyDm0lj93hn > q0J1CGo3xu4jARU4YoCmj9luh13qxUA6elCmJgzIwZUUZpEmbhPjezN0Bk+c0lhRFV7 > rxGZfFDPG58VV4Pn80n64E7IZ/BDQu99b5CN0LAl9RvakW6P/n2kC+p/vHmADhCjezK > MxwpVcBz96rq8= > > but if I do # host -t txt mail._domainkey.upsda.com I get this error message: > Host mail._domainkey.upsda.com not found: 3(NXDOMAIN) Not sure why you do a lookup on mail._domainkey.upsda.com?? As you use s=default.private and d=sakafete.com, you should check your DNS TXT record with: default.private._domainkey.sakafete.com If I check, I get a NXDOMAIN result. That explains the dkim=permerror. See RFC4871 for the way to publish your TXT record in DNS. > Can I be pointed to a tutorial for getting openDkim working on Linux/Debian with ispCP Omega and is opendkim the present version that I should be using. OpenDKIM is the version to use; I cc this mail to the opendkim users list, so any further replies can go there. /rolf |
From: Subscribe <sub...@ca...> - 2011-08-23 00:27:56
|
Hello List, I have just found this mailing list in my search for help to get my emails signed using DKIM. I followed a few examples and can now see this: Authentication-Results: mx.elandsys.com; dkim=permerror (verification error: signature timestamp in the future) header.i=@sakafete.com header.b=benCvdNW; dkim-adsp=none Received: from [127.0.0.1] (d24-36-134-162.home1.cgocable.net [24.36.134.162]) by cakafeteinc.propagation.net (Postfix) with ESMTPA id 433D0238D2F for<aut...@dk...>; Wed, 17 Aug 2011 21:33:33 -0500 (CDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=sakafete.com; s=default.private; t=1313634813; bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN /XKdLCPjaYaY=; h=Message-ID:Date:From:MIME-Version:To:Subject: Content-Type:Content-Transfer-Encoding; b=benCvdNWqqvUbMyDm0lj93hn q0J1CGo3xu4jARU4YoCmj9luh13qxUA6elCmJgzIwZUUZpEmbhPjezN0Bk+c0lhRFV7 rxGZfFDPG58VV4Pn80n64E7IZ/BDQu99b5CN0LAl9RvakW6P/n2kC+p/vHmADhCjezK MxwpVcBz96rq8= but if I do # host -t txt mail._domainkey.upsda.com I get this error message: Host mail._domainkey.upsda.com not found: 3(NXDOMAIN) Can I be pointed to a tutorial for getting openDkim working on Linux/Debian with ispCP Omega and is opendkim the present version that I should be using. Many Thanks. |
From: Willem K. <w.k...@gm...> - 2011-08-09 13:16:31
|
I checked, the keys seem to validate (although I don't really understand how) I used the autoresponder checking e-mail addresses on some sites. I don't think I have feature masquerade activated in sendmail, but I'll check. In fact it is a bit of a problem to tell daemons on ux to not use localhost.localdomain. I solved that for squirrelmail by editing the userprofile to show the correct reply-to address. On Mon, Aug 8, 2011 at 7:34 PM, Murray S. Kucherawy <ms...@cl...>wrote: > (Since you installed OpenDKIM instead, I’ll Cc: that list and we should > move this discussion over there.)**** > > ** ** > > There are rewrite rules in the sendmail configuration that change the From: > field (features called “masquerade” and “genericstable”). That’s why it > appears to be delivered with the From: field you expect. The problem is > that those changes are made only after the filter has seen them, which is > why you have to tell opendkim to sign for “localhost.localdomain” because > that’s what the filter sees.**** > > ** ** > > In fact, you might want to check that the signatures are being validated, > because they probably are failing since the data are essentially being > changed in transit.**** > > ** ** > > You will probably need either the “replace rules” feature to deal with > this, or you’ll need to arrange that your mail is generated with the final > domain name in there and not “localhost.localdomain” to get it verifying > properly.**** > > ** ** > > *From:* Willem Kossen [mailto:w.k...@gm...] > *Sent:* Monday, August 08, 2011 5:16 AM > *To:* dkim-milter general discussion > *Subject:* Re: [dkim-milter-discuss] sendmail non-smtpd possible?**** > > ** ** > > Ah, I think i figured it out...**** > > what happens in many cases is that mail originates from > user@localhost.localdomain. I didn't tell opendkim to sign mail from that > domain. Still the mail ends up as @wkossen.nl in the recipients mailbox, > but sendmail didn't know that at the time the mail was delivered to it. > during input, it was localhost.localdomain. therefor no signing. Now I told > opendkim in the config file that the domain localhost.localdomain should be > signed and it worked.**** > > ** ** > > and squirrelmail delivered mail as user@localhost (no localdomain) I added > that domain too. this is far from ideal, a bit of a hack, but I guess it > works.**** > > ** ** > > thanks for the help**** > > On Sat, Aug 6, 2011 at 9:27 AM, Murray S. Kucherawy <ms...@cl...> > wrote:**** > > First, as Rolf said, you should switch to opendkim. This package has been > unmaintained for over two years.**** > > **** > > I just tried it with sendmail 8.14.4 and opendkim 2.4.2 (just released!), > and it signed a message I sent using the sendmail shell interface rather > than SMTP. Since that means sendmail does provide milter service to mail > that’s piped in, you should be able to get dkim-milter to do it too unless > there was a bug in it in this regard.**** > > **** > > You can always use LogWhy to track down why your mail isn’t being signed. > It might have something to do with a domain name mismatch in the mail you’re > feeding.**** > > **** > > Good luck,**** > > -MSK**** > > **** > > *From:* Willem Kossen [mailto:w.k...@gm...] > *Sent:* Friday, August 05, 2011 5:57 AM > *To:* dki...@li... > *Subject:* [dkim-milter-discuss] sendmail non-smtpd possible?**** > > **** > > Hi there,**** > > **** > > I have succesfully implemented dkim signing in my mailserver, but it only > works when mail is delivered to it via smtp. A lot of mail however comes in > via sendmail executable for instance because of websites, webmail or > applications sending out notices. I want that mail to be signed as well. Is > it possible at all (like in postfix non-smtpd filters) or in any other way? > in fact, i would like all outgoing mail to be signed.**** > > **** > > Thanks**** > > > -- > ------------ > Willem Kossen**** > > > > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > dkim-milter-discuss mailing list > dki...@li... > https://lists.sourceforge.net/lists/listinfo/dkim-milter-discuss**** > > > > > -- > ------------ > Willem Kossen > w.k...@gm...**** > > > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > dkim-milter-discuss mailing list > dki...@li... > https://lists.sourceforge.net/lists/listinfo/dkim-milter-discuss > > -- ------------ Willem Kossen w.k...@gm... |
From: Murray S. K. <ms...@cl...> - 2011-08-08 17:34:51
|
(Since you installed OpenDKIM instead, I'll Cc: that list and we should move this discussion over there.) There are rewrite rules in the sendmail configuration that change the From: field (features called "masquerade" and "genericstable"). That's why it appears to be delivered with the From: field you expect. The problem is that those changes are made only after the filter has seen them, which is why you have to tell opendkim to sign for "localhost.localdomain" because that's what the filter sees. In fact, you might want to check that the signatures are being validated, because they probably are failing since the data are essentially being changed in transit. You will probably need either the "replace rules" feature to deal with this, or you'll need to arrange that your mail is generated with the final domain name in there and not "localhost.localdomain" to get it verifying properly. From: Willem Kossen [mailto:w.k...@gm...] Sent: Monday, August 08, 2011 5:16 AM To: dkim-milter general discussion Subject: Re: [dkim-milter-discuss] sendmail non-smtpd possible? Ah, I think i figured it out... what happens in many cases is that mail originates from user@localhost.localdomain. I didn't tell opendkim to sign mail from that domain. Still the mail ends up as @wkossen.nl<http://wkossen.nl> in the recipients mailbox, but sendmail didn't know that at the time the mail was delivered to it. during input, it was localhost.localdomain. therefor no signing. Now I told opendkim in the config file that the domain localhost.localdomain should be signed and it worked. and squirrelmail delivered mail as user@localhost (no localdomain) I added that domain too. this is far from ideal, a bit of a hack, but I guess it works. thanks for the help On Sat, Aug 6, 2011 at 9:27 AM, Murray S. Kucherawy <ms...@cl...<mailto:ms...@cl...>> wrote: First, as Rolf said, you should switch to opendkim. This package has been unmaintained for over two years. I just tried it with sendmail 8.14.4 and opendkim 2.4.2 (just released!), and it signed a message I sent using the sendmail shell interface rather than SMTP. Since that means sendmail does provide milter service to mail that's piped in, you should be able to get dkim-milter to do it too unless there was a bug in it in this regard. You can always use LogWhy to track down why your mail isn't being signed. It might have something to do with a domain name mismatch in the mail you're feeding. Good luck, -MSK From: Willem Kossen [mailto:w.k...@gm...<mailto:w.k...@gm...>] Sent: Friday, August 05, 2011 5:57 AM To: dki...@li...<mailto:dki...@li...> Subject: [dkim-milter-discuss] sendmail non-smtpd possible? Hi there, I have succesfully implemented dkim signing in my mailserver, but it only works when mail is delivered to it via smtp. A lot of mail however comes in via sendmail executable for instance because of websites, webmail or applications sending out notices. I want that mail to be signed as well. Is it possible at all (like in postfix non-smtpd filters) or in any other way? in fact, i would like all outgoing mail to be signed. Thanks -- ------------ Willem Kossen ------------------------------------------------------------------------------ BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA The must-attend event for mobile developers. Connect with experts. Get tools for creating Super Apps. See the latest technologies. Sessions, hands-on labs, demos & much more. Register early & save! http://p.sf.net/sfu/rim-blackberry-1 _______________________________________________ dkim-milter-discuss mailing list dki...@li...<mailto:dki...@li...> https://lists.sourceforge.net/lists/listinfo/dkim-milter-discuss -- ------------ Willem Kossen w.k...@gm...<mailto:w.k...@gm...> |
From: Willem K. <w.k...@gm...> - 2011-08-08 12:15:57
|
Ah, I think i figured it out... what happens in many cases is that mail originates from user@localhost.localdomain. I didn't tell opendkim to sign mail from that domain. Still the mail ends up as @wkossen.nl in the recipients mailbox, but sendmail didn't know that at the time the mail was delivered to it. during input, it was localhost.localdomain. therefor no signing. Now I told opendkim in the config file that the domain localhost.localdomain should be signed and it worked. and squirrelmail delivered mail as user@localhost (no localdomain) I added that domain too. this is far from ideal, a bit of a hack, but I guess it works. thanks for the help On Sat, Aug 6, 2011 at 9:27 AM, Murray S. Kucherawy <ms...@cl...>wrote: > First, as Rolf said, you should switch to opendkim. This package has been > unmaintained for over two years.**** > > ** ** > > I just tried it with sendmail 8.14.4 and opendkim 2.4.2 (just released!), > and it signed a message I sent using the sendmail shell interface rather > than SMTP. Since that means sendmail does provide milter service to mail > that’s piped in, you should be able to get dkim-milter to do it too unless > there was a bug in it in this regard.**** > > ** ** > > You can always use LogWhy to track down why your mail isn’t being signed. > It might have something to do with a domain name mismatch in the mail you’re > feeding.**** > > ** ** > > Good luck,**** > > -MSK**** > > ** ** > > *From:* Willem Kossen [mailto:w.k...@gm...] > *Sent:* Friday, August 05, 2011 5:57 AM > *To:* dki...@li... > *Subject:* [dkim-milter-discuss] sendmail non-smtpd possible?**** > > ** ** > > Hi there,**** > > ** ** > > I have succesfully implemented dkim signing in my mailserver, but it only > works when mail is delivered to it via smtp. A lot of mail however comes in > via sendmail executable for instance because of websites, webmail or > applications sending out notices. I want that mail to be signed as well. Is > it possible at all (like in postfix non-smtpd filters) or in any other way? > in fact, i would like all outgoing mail to be signed.**** > > ** ** > > Thanks**** > > > -- > ------------ > Willem Kossen**** > > > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > dkim-milter-discuss mailing list > dki...@li... > https://lists.sourceforge.net/lists/listinfo/dkim-milter-discuss > > -- ------------ Willem Kossen w.k...@gm... |
From: Willem K. <w.k...@gm...> - 2011-08-08 11:09:11
|
Thanks for both your responses. I made the switch, which was next to painless, but that didn't solve my problem, in fact, it seems stranger than I thought at first. echo test | mail so...@ex... --> no signing echo test | sendmail so...@ex... --> no signing squirrelmail on same host sending a mail --> no signing changed squirrelmail config to use smtp, --> no signing (?) telnet to mailserver from other host on smtp port --> no signing??? telnet from server itself on smtp --> no signing ??? and now thunderbird using this server as smtp --> no signing /?????? sendEmail -s localhost -f bl...@ex... -t so...@ex... -u test -m test -v --> yes, signed now i can understand that the from addresses are different in some cases, but even with direct telnet to smtp, when i use from-domains listed in opendkim.conf Domain statement, no luck. It's probably something simple I'm missing, but I'm sure missing it... any pointers? (sendEmail is a commandline tool for sending mail over smtp which I use a lot) Kind regards, Willem Kossen On Sat, Aug 6, 2011 at 9:27 AM, Murray S. Kucherawy <ms...@cl...>wrote: > First, as Rolf said, you should switch to opendkim. This package has been > unmaintained for over two years.**** > > ** ** > > I just tried it with sendmail 8.14.4 and opendkim 2.4.2 (just released!), > and it signed a message I sent using the sendmail shell interface rather > than SMTP. Since that means sendmail does provide milter service to mail > that’s piped in, you should be able to get dkim-milter to do it too unless > there was a bug in it in this regard.**** > > ** ** > > You can always use LogWhy to track down why your mail isn’t being signed. > It might have something to do with a domain name mismatch in the mail you’re > feeding.**** > > ** ** > > Good luck,**** > > -MSK**** > > ** ** > > *From:* Willem Kossen [mailto:w.k...@gm...] > *Sent:* Friday, August 05, 2011 5:57 AM > *To:* dki...@li... > *Subject:* [dkim-milter-discuss] sendmail non-smtpd possible?**** > > ** ** > > Hi there,**** > > ** ** > > I have succesfully implemented dkim signing in my mailserver, but it only > works when mail is delivered to it via smtp. A lot of mail however comes in > via sendmail executable for instance because of websites, webmail or > applications sending out notices. I want that mail to be signed as well. Is > it possible at all (like in postfix non-smtpd filters) or in any other way? > in fact, i would like all outgoing mail to be signed.**** > > ** ** > > Thanks**** > > > -- > ------------ > Willem Kossen**** > > > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > dkim-milter-discuss mailing list > dki...@li... > https://lists.sourceforge.net/lists/listinfo/dkim-milter-discuss > > -- ------------ Willem Kossen w.k...@gm... |
From: Murray S. K. <ms...@cl...> - 2011-08-06 07:40:37
|
First, as Rolf said, you should switch to opendkim. This package has been unmaintained for over two years. I just tried it with sendmail 8.14.4 and opendkim 2.4.2 (just released!), and it signed a message I sent using the sendmail shell interface rather than SMTP. Since that means sendmail does provide milter service to mail that's piped in, you should be able to get dkim-milter to do it too unless there was a bug in it in this regard. You can always use LogWhy to track down why your mail isn't being signed. It might have something to do with a domain name mismatch in the mail you're feeding. Good luck, -MSK From: Willem Kossen [mailto:w.k...@gm...] Sent: Friday, August 05, 2011 5:57 AM To: dki...@li... Subject: [dkim-milter-discuss] sendmail non-smtpd possible? Hi there, I have succesfully implemented dkim signing in my mailserver, but it only works when mail is delivered to it via smtp. A lot of mail however comes in via sendmail executable for instance because of websites, webmail or applications sending out notices. I want that mail to be signed as well. Is it possible at all (like in postfix non-smtpd filters) or in any other way? in fact, i would like all outgoing mail to be signed. Thanks -- ------------ Willem Kossen |
From: Rolf E. S. <R.E...@so...> - 2011-08-05 20:53:26
|
Hi, Willem, On 8/5/11 2:57 PM, Willem Kossen wrote: > Hi there, > > I have succesfully implemented dkim signing in my mailserver, but it > only works when mail is delivered to it via smtp. A lot of mail > however comes in via sendmail executable for instance because of > websites, webmail or applications sending out notices. I want that > mail to be signed as well. Is it possible at all (like in postfix > non-smtpd filters) or in any other way? in fact, i would like all > outgoing mail to be signed. I'm not sure about the exact Sendmail configuration options you will need, but in general the following is important to keep in mind. To minimize DKIM signature corruption, it is important to sign at the final step before delivery of the mail to a remote SMTP server. This is true for both mail that is to be signed and originates locally (via a web application or a command line script), as well as for mail you receive via SMTP which you have to sign before delivering it to its destination (e.g. the Internet). Having said that, you will want to look for a Sendmail configuration that allows you to invoke the milter right before (or from within) the _outbound_ SMTP connection. You may have to define the milter in your ClientPortOptions setting, I'm not sure. Or switch to Postfix ;-) BTW: I wonder whether you implemented DKIM signing using the dkim-milter milter software or using OpenDKIM? As you post your question on the dkim-milter-discuss list I suppose the former is true. I'd recommend to forget about dkim-milter and start using openDKIM (http://www.opendkim.org/) as dkim-milter is no longer maintained and it's author dropped dkim-milter development and continued the dkim-milter work as the opendkim project. Regards, /rolf |
From: Willem K. <w.k...@gm...> - 2011-08-05 12:57:07
|
Hi there, I have succesfully implemented dkim signing in my mailserver, but it only works when mail is delivered to it via smtp. A lot of mail however comes in via sendmail executable for instance because of websites, webmail or applications sending out notices. I want that mail to be signed as well. Is it possible at all (like in postfix non-smtpd filters) or in any other way? in fact, i would like all outgoing mail to be signed. Thanks -- ------------ Willem Kossen |
From: Murray S. K. <ms...@cl...> - 2011-05-20 20:15:56
|
> -----Original Message----- > From: mi...@co... [mailto:mi...@co...] > Sent: Friday, May 20, 2011 1:02 PM > To: dki...@li... > Subject: [dkim-milter-discuss] Majordomo > > Is there any way to get opendkim to work with majordomo? Wrong list for opendkim; try ope...@li.... -MSK |
From: <mi...@co...> - 2011-05-20 20:01:56
|
Is there any way to get opendkim to work with majordomo? Bob |
From: Sharma, A. <ash...@hp...> - 2011-05-16 14:00:12
|
Adding DKIM mailing list guys to suggest some help. -----Original Message----- From: Sharma, Ashish Sent: Wednesday, May 11, 2011 5:31 PM To: sid...@li... Cc: Varghese, Daniel Subject: [sid-milter-discuss] Sender-ID validation via Blackberry failing Hi, I have a Postfix mail receiving server, on this I am using sid-milter (found at http://sourceforge.net/projects/sid-milter/ got from http://www.postfix.org/addon.html) tool to validate senderID and SPF. Here the problem is for mail servers that implement Sender-ID, mail servers that are implementing sender-ID and having their mails sent via Blackberry are having their sender-ID (sender-id=neutral) not getting verified on my postfix end. Following are the mail headers that I am receiving: >From SRS0=nRLNv7=UW=aol.com=xx...@sr... Mon Jan 24 11:05:10 2011 Return-Path: <SRS0=nRLNv7=UW=aol.com=xxx...@sr...> X-Original-To: cp...@de... Delivered-To: cp...@de... Received: from localhost (localhost [127.0.0.1]) by dev1.cpgtest.ostinet.net (Postfix) with ESMTP id C94AA2828C for <cp...@de...>; Mon, 24 Jan 2011 11:05:10 -0500 (EST) Authentication-Results: dev1.cpgtest.ostinet.net; sender-id=neutral header.from=xxx...@ao...; spf=pass smtp.mfrom=SRS0=nRLNv7=UW=aol.com=xxx...@sr... X-DKIM: OpenDKIM Filter v2.1.3 dev1.cpgtest.ostinet.net D5DEA2815D Authentication-Results: dev1.cpgtest.ostinet.net; dkim=none (no signature); dkim-adsp=none Received: from b27.c7.bise7.blackberry ([192.168.0.127]) by srs.bis7.eu.blackberry.com (8.13.7 TEAMON/8.13.7) with ESMTP id p0OFtGaw021900 for cp...@de...; Mon, 24 Jan 2011 16:05:09 GMT X-rim-org-msg-ref-id: 300123690 Message-ID: <300...@b2...se7.blackberry> Content-Transfer-Encoding: base64 Reply-To: xxx...@ao... X-Priority: Normal References: <160...@b2...se7.blackberry> In-Reply-To: <160...@b2...se7.blackberry> Sensitivity: Normal Importance: Normal Subject: Re: Test from aol To: cp...@de... From: xxx...@ao... Date: Mon, 24 Jan 2011 16:05:51 +0000 Content-Type: text/plain; charset="Windows-1252" MIME-Version: 1.0 Status: RO Can anybody tell me what needs to be done at my end to get sender-ID for mails sent via Blackberry to be verified and passed correctly. Also as can be seen Blackberry implements SRS (Sender Rewrite Scheme): Authentication-Results: dev1.cpgtest.ostinet.net; sender-id=neutral header.from=xxx...@ao...; spf=pass smtp.mfrom=SRS0=nRLNv7=UW=aol.com=xxx...@sr... so as per my understanding Sender-ID validation should in this case work flawless as Sender Rewrite Scheme(SRS) makes sure SPF passes if a mail forwarder has implemented SRS as per information available at the links http://www.openspf.org/SRS and http://www.libsrs2.org/srs/srs.pdf If the above information is correct, then why sid-milter is behaving as experienced, is it a bug? Thanks Ashish Sharma ------------------------------------------------------------------------------ Achieve unprecedented app performance and reliability What every C/C++ and Fortran developer should know. Learn how Intel has extended the reach of its next-generation tools to help boost performance applications - inlcuding clusters. http://p.sf.net/sfu/intel-dev2devmay _______________________________________________ sid-milter-discuss mailing list sid...@li... https://lists.sourceforge.net/lists/listinfo/sid-milter-discuss |
From: Rolf E. S. <R.E...@so...> - 2011-05-14 21:34:16
|
Hi, Peter, On 5/12/11 8:03 PM, st...@in... wrote: > Hello folks! > > I have trouble compiling dkim-milter on AIX6.1 using IBM xlc. > > I got this error, how do I solve this ? : > > Making dependencies > in /home/steen/dkim-milter-2.8.3/obj.AIX.6.1.6.PPC/libdkim > make: 1254-002 Cannot find a rule to create target depend from > dependencies. > Stop. > Making in /home/steen/dkim-milter-2.8.3/obj.AIX.6.1.6.PPC/libdkim > make: 1254-002 Cannot find a rule to create target sm_os.h from > dependencies. > Stop. > make: 1254-004 The error code from the last command is 2. > > > Stop. > > > Regards // > // Peter Steen I have no solution to your problem. But I'd recommend to use OpenDKIM instead of dkim-milter: afaik dkim-milter is no longer maintained / developed and opendkim is the successor of it. See www.opendkim.org for more information. Regards, /rolf |
From: <st...@in...> - 2011-05-12 18:04:11
|
Hello folks! I have trouble compiling dkim-milter on AIX6.1 using IBM xlc. I got this error, how do I solve this ? : Making dependencies in /home/steen/dkim-milter-2.8.3/obj.AIX.6.1.6.PPC/libdkim make: 1254-002 Cannot find a rule to create target depend from dependencies. Stop. Making in /home/steen/dkim-milter-2.8.3/obj.AIX.6.1.6.PPC/libdkim make: 1254-002 Cannot find a rule to create target sm_os.h from dependencies. Stop. make: 1254-004 The error code from the last command is 2. Stop. Regards // // Peter Steen McAfee check. |