You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(323) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(886) |
Feb
(712) |
Mar
(808) |
Apr
(522) |
May
(798) |
Jun
(462) |
Jul
(718) |
Aug
(765) |
Sep
(680) |
Oct
(610) |
Nov
(763) |
Dec
(805) |
| 2003 |
Jan
(907) |
Feb
(960) |
Mar
(757) |
Apr
(1072) |
May
(1084) |
Jun
(934) |
Jul
(839) |
Aug
(587) |
Sep
(644) |
Oct
(824) |
Nov
(653) |
Dec
(611) |
| 2004 |
Jan
(556) |
Feb
(405) |
Mar
(619) |
Apr
(557) |
May
(630) |
Jun
(577) |
Jul
(535) |
Aug
(460) |
Sep
(446) |
Oct
(597) |
Nov
(517) |
Dec
(471) |
| 2005 |
Jan
(474) |
Feb
(573) |
Mar
(438) |
Apr
(508) |
May
(355) |
Jun
(455) |
Jul
(389) |
Aug
(412) |
Sep
(382) |
Oct
(345) |
Nov
(448) |
Dec
(368) |
| 2006 |
Jan
(433) |
Feb
(378) |
Mar
(379) |
Apr
(356) |
May
(265) |
Jun
(334) |
Jul
(305) |
Aug
(273) |
Sep
(292) |
Oct
(192) |
Nov
(240) |
Dec
(263) |
| 2007 |
Jan
(279) |
Feb
(222) |
Mar
(185) |
Apr
(175) |
May
(313) |
Jun
(218) |
Jul
(157) |
Aug
(236) |
Sep
(277) |
Oct
(274) |
Nov
(198) |
Dec
(285) |
| 2008 |
Jan
(251) |
Feb
(188) |
Mar
(185) |
Apr
(152) |
May
(203) |
Jun
(152) |
Jul
(198) |
Aug
(135) |
Sep
(178) |
Oct
(160) |
Nov
(94) |
Dec
(175) |
| 2009 |
Jan
(101) |
Feb
(89) |
Mar
(117) |
Apr
(79) |
May
(130) |
Jun
(148) |
Jul
(157) |
Aug
(98) |
Sep
(117) |
Oct
(96) |
Nov
(112) |
Dec
(129) |
| 2010 |
Jan
(126) |
Feb
(158) |
Mar
(149) |
Apr
(60) |
May
(87) |
Jun
(149) |
Jul
(128) |
Aug
(66) |
Sep
(78) |
Oct
(42) |
Nov
(40) |
Dec
(62) |
| 2011 |
Jan
(53) |
Feb
(68) |
Mar
(39) |
Apr
(66) |
May
(25) |
Jun
(51) |
Jul
(34) |
Aug
(45) |
Sep
(39) |
Oct
(45) |
Nov
(51) |
Dec
(45) |
| 2012 |
Jan
(59) |
Feb
(38) |
Mar
(72) |
Apr
(24) |
May
(36) |
Jun
(44) |
Jul
(55) |
Aug
(48) |
Sep
(25) |
Oct
(39) |
Nov
(27) |
Dec
(21) |
| 2013 |
Jan
(16) |
Feb
(29) |
Mar
(31) |
Apr
(42) |
May
(24) |
Jun
(15) |
Jul
(31) |
Aug
(28) |
Sep
(5) |
Oct
(8) |
Nov
(15) |
Dec
(3) |
| 2014 |
Jan
(5) |
Feb
(14) |
Mar
(22) |
Apr
(32) |
May
(32) |
Jun
(11) |
Jul
(6) |
Aug
(23) |
Sep
(16) |
Oct
(4) |
Nov
(13) |
Dec
(12) |
| 2015 |
Jan
(30) |
Feb
(17) |
Mar
(24) |
Apr
(11) |
May
(3) |
Jun
(25) |
Jul
|
Aug
(8) |
Sep
(45) |
Oct
(4) |
Nov
(5) |
Dec
(8) |
| 2016 |
Jan
(22) |
Feb
(17) |
Mar
(8) |
Apr
(11) |
May
(26) |
Jun
(4) |
Jul
(18) |
Aug
(11) |
Sep
(6) |
Oct
(10) |
Nov
(17) |
Dec
(15) |
| 2017 |
Jan
(33) |
Feb
(1) |
Mar
(4) |
Apr
(2) |
May
(9) |
Jun
(9) |
Jul
(5) |
Aug
(7) |
Sep
(4) |
Oct
(7) |
Nov
|
Dec
(2) |
| 2018 |
Jan
(2) |
Feb
|
Mar
(10) |
Apr
(29) |
May
(13) |
Jun
(4) |
Jul
(3) |
Aug
|
Sep
|
Oct
(14) |
Nov
(6) |
Dec
(2) |
| 2019 |
Jan
(3) |
Feb
|
Mar
(5) |
Apr
(13) |
May
(5) |
Jun
|
Jul
(6) |
Aug
(25) |
Sep
(1) |
Oct
|
Nov
|
Dec
(6) |
| 2020 |
Jan
(10) |
Feb
(8) |
Mar
|
Apr
|
May
(4) |
Jun
(26) |
Jul
(3) |
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
(13) |
| 2021 |
Jan
(12) |
Feb
|
Mar
(10) |
Apr
(2) |
May
(21) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(14) |
Nov
(14) |
Dec
(6) |
| 2022 |
Jan
(20) |
Feb
(1) |
Mar
(3) |
Apr
(21) |
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
(3) |
Oct
|
Nov
(13) |
Dec
(4) |
| 2023 |
Jan
(3) |
Feb
(15) |
Mar
|
Apr
(4) |
May
(5) |
Jun
|
Jul
(11) |
Aug
(6) |
Sep
(3) |
Oct
|
Nov
|
Dec
(11) |
| 2024 |
Jan
(20) |
Feb
|
Mar
(5) |
Apr
|
May
(3) |
Jun
|
Jul
(5) |
Aug
(8) |
Sep
(8) |
Oct
|
Nov
|
Dec
|
| 2025 |
Jan
|
Feb
(2) |
Mar
(1) |
Apr
(11) |
May
|
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
(2) |
Dec
(6) |
| 2026 |
Jan
(4) |
Feb
|
Mar
|
Apr
(2) |
May
(2) |
Jun
|
Jul
(7) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Markus R. K. <man...@di...> - 2026-07-22 11:48:23
|
Hi Paul et al.,
below please find a section that can be added to
plugins/calendar/calendar.php
to have a search field and the needed search algorithm for the web ui.
As mentioned, I moved my new code to a function to be added to above php.
This is for better overview.
The relevant function,
search_engine()
should be called last. So we have this order:
displayPageHeader($color, 'None');
calendar_header();
readcalendardata();
startcalendar();
drawmonthview();
endcalendar();
search_engine();
Since this mailing list's majordomo does not forward emails with
attachments, I add the function here as plain text.
Hope I could help!
Best regards,
Markus
######################################################################
function search_engine() {
// 1. Globale SquirrelMail-Variablen laden
global $data_dir, $username, $default_charset;
// Fallback definieren, falls das Charset nicht gesetzt sein sollte
$charset = !empty($default_charset) ? $default_charset : 'ISO-8859-1';
// ----------------------------------------------------
// 2. Suchformular ausgeben
// ----------------------------------------------------
$search_term_input = isset($_GET['cal_search']) ?
htmlspecialchars($_GET['cal_search'], ENT_COMPAT | ENT_HTML401,
$charset) : '';
$label_search = _("Search");
echo '<br />' . "\n" .
'<form method="GET" action="calendar.php">' . "\n" .
' <table align="center" cellspacing="1" cellpadding="2"
border="0">' . "\n" .
' <tr>' . "\n" .
' <td>' . "\n" .
' <strong>' . $label_search . ':</strong> ' . "\n" .
' <input type="text" name="cal_search" value="' .
$search_term_input . '" size="20" />' . "\n" .
' <input type="submit" value="' . $label_search . '" />' .
"\n" .
' </td>' . "\n" .
' </tr>' . "\n" .
' </table>' . "\n" .
'</form>' . "\n";
// ----------------------------------------------------
// 3. Suche ausführen & Ergebnisse verarbeiten
// ----------------------------------------------------
if (!empty($_GET['cal_search'])) {
$search_term = $_GET['cal_search'];
// Suchbegriff bei Bedarf an das Server-Charset anpassen
if (function_exists('mb_convert_encoding')) {
$search_term_converted = mb_convert_encoding($search_term,
$charset, 'UTF-8');
} else {
$search_term_converted = $search_term;
}
$search_pattern = $data_dir . $username . '.*.cal';
$cal_files = glob($search_pattern);
$results = [];
if (is_array($cal_files)) {
foreach ($cal_files as $file) {
if (!file_exists($file)) continue;
$handle = fopen($file, "r");
if ($handle) {
while (($line = fgets($handle)) !== false) {
$line = trim($line);
if (empty($line)) continue;
// Format: MMDDYYYY|HHMM|0|0|Text||
$fields = explode('|', $line);
// Vergleich inkl. Charset-Anpassung
if (isset($fields[4]) && stripos($fields[4],
$search_term_converted) !== false) {
$date_raw = $fields[0]; // MMDDYYYY
$month = substr($date_raw, 0, 2);
$day = substr($date_raw, 2, 2);
$year = substr($date_raw, 4, 4);
$time_raw = str_pad(trim($fields[1]), 4, '0',
STR_PAD_LEFT);
$sort_key = $year . $month . $day . $time_raw;
$formatted_time = substr($time_raw, 0, 2) .
':' . substr($time_raw, 2, 2);
// Text unter Berücksichtigung des Charsets
absichern
$clean_text = htmlspecialchars($fields[4],
ENT_COMPAT | ENT_HTML401, $charset);
$results[] = [
'sort_key' => $sort_key,
'link_params' =>
"year=$year&month=$month&day=$day",
'display_date' => "$day.$month.$year",
'time' => $formatted_time,
'text' => $clean_text
];
}
}
fclose($handle);
}
}
// Nach Datum absteigend sortieren (neueste zuerst)
usort($results, function($a, $b) {
return strcmp($b['sort_key'], $a['sort_key']);
});
}
// ----------------------------------------------------
// 4. Ergebnisse als Tabelle ausgeben
// ----------------------------------------------------
$search_term_display = htmlspecialchars($search_term, ENT_COMPAT |
ENT_HTML401, $charset);
echo '<br />' . "\n";
echo '<table align="center" cellspacing="1" cellpadding="4"
border="0" bgcolor="#ababab" width="80%">' . "\n";
echo ' <tr bgcolor="#dcdcdc">' . "\n";
echo ' <td colspan="3"><strong>' . sprintf(_("Search results"),
$search_term_display) . '</strong></td>' . "\n";
echo ' </tr>' . "\n";
if (empty($results)) {
echo ' <tr bgcolor="#ffffff"><td colspan="3">' . _("No
results") . '</td></tr>' . "\n";
} else {
foreach ($results as $res) {
echo ' <tr bgcolor="#ffffff">' . "\n";
echo ' <td width="15%">' . $res['display_date'] .
'</td>' . "\n";
echo ' <td width="10%">' . $res['time'] . '</td>' . "\n";
echo ' <td><a href="day.php?' . $res['link_params'] .
'">' . $res['text'] . '</a></td>' . "\n";
echo ' </tr>' . "\n";
}
}
echo '</table>' . "\n";
}
}
|
|
From: Markus R. K. <man...@di...> - 2026-07-21 04:48:07
|
In the most recent update I added proper processing of special characters, depending on what charset is defined in config.php. I have this version running on my main system. If you like, I can provide calendar.php including the most recent changes. BR, Markus > Hi Paul, > > hope, you remember our talk - meanwhile I created a little addition to > calendar.php, which does exactly what we discussed. > > See video in attachment. > > The code could be moved into a function to make it optically fit better > into the whole project. Anyway, you may find even more things to improve. > > Please let me know, if this is OK so. > > Best regards, > > Markus > > > > > > >> Markus, >>> I am using Squirrelmail 1.4.23[SVN] with calendar plugin enabled. This > works perfectly and so I have hundreds of entries there meanwhile. But > this also means, that it gets harder every day to find events, once > stored. >>> In my understanding, one could try to include one more input field for > a >>> search in the calendar.php page, then grep through the calendar events >>> in >>> the 'data' directory, and in case of one or more matches, create a list >>> of >>> links dynamically in the page to open day.php?... with the appropriate > parameters. >>> Maybe I have just overlooked this and it can be installed somehow? If > not, would this be a possible new feature? >> On paper, that sounds reasonable, though I'm not sure it's something > that >> is likely to be added any time soon, as recent versions of the Advanced > Calendar plugin have a search feature (though I don't remember if the > file >> backend is up to date with that feature; it might only be for the SQL > backend at this time) among a lot of other usability enhancements. Feel > free to contact off list to get ahold of a recent copy of that plugin. > -- >> Paul Lesniewski >> SquirrelMail Team >> Please support Open Source Software by donating to SquirrelMail! > http://squirrelmail.org/donate_paul_lesniewski.php >> ----- >> squirrelmail-users mailing list >> Posting guidelines: http://squirrelmail.org/postingguidelines >> List address: squ...@li... >> List archives: http://news.gmane.org/gmane.mail.squirrelmail.user List > info (subscribe/unsubscribe/change options): >> https://lists.sourceforge.net/lists/listinfo/squirrelmail-users > > |
|
From: Paul L. <pa...@sq...> - 2026-07-17 21:07:24
|
> I am running Squirrelmail version 1.4.23 [SVN] <-- (Thanks Paul for > helping with that) <snip> > So more recently, I got a couple e-mails, eBay and Lufthansa to be > specific, that required clicking on a link - but that URL was entirely > missing. What I have instead is plain text where a link was intended to > be. The href="" field seems to be stripped out entirely, the same as it > would look as if I copied the html directly from a lynx browser in a > terminal, 1990s style. I was able to dig in my spool directory to copy > the > link, but that wasn't too user friendly in my opinion. You can click on "Display Message Details" in the message options and it should give you a pop-up window with the message source where you can find anything you need without going into your message files on the server. > I totally don't remember installing the Unsafe Image Rules plugin in the > past, not in the past 10-15 years at least. Would that plugin fix this > shortcoming in rendering the HTML or is there are mistake in a > configuration file? I thought the "Show Unsafe Images" was already built > in and installed by default. That plugin should not affect URLs. I get eBay messages from time to time that seem ok, though I don't usually check the links (prefer to log in directly rather than click tracking links from email). Are you viewing the plain text or html version of such messages? You can install the "View as HTML" plugin to easily switch back and forth. Otherwise, it's hard to guess why the URL goes missing. Feel free to forward such an email to me personally if you want me to have a look (forward it as an attachment). -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php |
|
From: timothylegg <tim...@gm...> - 2026-07-17 17:01:33
|
Thanks for the help. I located the version number in both strings.php and by executing configtest.php in the CLI. I created a second thread yesterday, but it seems like it was never received. I did a string comparison of squ...@li... between this message and the one in the Sent box on Gmail. Are you aware of any outages at Sourceforge? Between Google and Slashdot, I wouldn't expect there to be any downtime. Timothy D Legg On Thu, Jul 16, 2026 at 1:46 PM Paul Lesniewski <pa...@sq...> wrote: > > > On Thu, July 16, 2026 5:27 pm, timothylegg wrote: > > Hello, > > > > I have a completely separate issue, but before addressing that, I read > the > > documentation section 12.2 "Needed details" first and it was then that I > > realized I am not certain which version I am running and I couldn't find > > any direct way of locating the version. I'm running PHP 8.3.6. Is there > > a > > PHP script for determining the version? Oh yes, I did run > > ./src/configtest.php and I got "Disallowed" so that was useless. > > Open that file and the first two lines should be: > > <?php > echo "Disallowed"; die; > > Change the second line so it starts with two forward slashes: > > // echo "Disallowed"; die; > > Then access it from a web browser. > > Otherwise, you would need to look in src/strings.php, but configtest gives > a lot of other useful information. > > -- > Paul Lesniewski > SquirrelMail Team > Please support Open Source Software by donating to SquirrelMail! > http://squirrelmail.org/donate_paul_lesniewski.php > > > > > ----- > squirrelmail-users mailing list > Posting guidelines: http://squirrelmail.org/postingguidelines > List address: squ...@li... > List archives: http://news.gmane.org/gmane.mail.squirrelmail.user > List info (subscribe/unsubscribe/change options): > https://lists.sourceforge.net/lists/listinfo/squirrelmail-users > |
|
From: timothylegg <tim...@gm...> - 2026-07-16 20:57:18
|
Hello I am running Squirrelmail version 1.4.23 [SVN] <-- (Thanks Paul for helping with that) I've been using Squirrelmail for some 25 years, and in the past, I had to install a few extra plugins to get the extra functionality that I like to have. But the last couple times I installed, I don't recall needing to do that as these features appeared to become included into the default package. It's something I install so rarely because I only use it for myself. So more recently, I got a couple e-mails, eBay and Lufthansa to be specific, that required clicking on a link - but that URL was entirely missing. What I have instead is plain text where a link was intended to be. The href="" field seems to be stripped out entirely, the same as it would look as if I copied the html directly from a lynx browser in a terminal, 1990s style. I was able to dig in my spool directory to copy the link, but that wasn't too user friendly in my opinion. I totally don't remember installing the Unsafe Image Rules plugin in the past, not in the past 10-15 years at least. Would that plugin fix this shortcoming in rendering the HTML or is there are mistake in a configuration file? I thought the "Show Unsafe Images" was already built in and installed by default. Timothy D Legg |
|
From: Paul L. <pa...@sq...> - 2026-07-16 18:44:49
|
On Thu, July 16, 2026 5:27 pm, timothylegg wrote: > Hello, > > I have a completely separate issue, but before addressing that, I read the > documentation section 12.2 "Needed details" first and it was then that I > realized I am not certain which version I am running and I couldn't find > any direct way of locating the version. I'm running PHP 8.3.6. Is there > a > PHP script for determining the version? Oh yes, I did run > ./src/configtest.php and I got "Disallowed" so that was useless. Open that file and the first two lines should be: <?php echo "Disallowed"; die; Change the second line so it starts with two forward slashes: // echo "Disallowed"; die; Then access it from a web browser. Otherwise, you would need to look in src/strings.php, but configtest gives a lot of other useful information. -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php |
|
From: timothylegg <tim...@gm...> - 2026-07-16 17:27:57
|
Hello, I have a completely separate issue, but before addressing that, I read the documentation section 12.2 "Needed details" first and it was then that I realized I am not certain which version I am running and I couldn't find any direct way of locating the version. I'm running PHP 8.3.6. Is there a PHP script for determining the version? Oh yes, I did run ./src/configtest.php and I got "Disallowed" so that was useless. I did find the files in /var/www/html/squirrelmail but I am hesitant to randomly open files up in vi to search for version numbers. Is there a more straightforward way? I did have these in an archive of Downloads matching the keywords searched: 19302400 May 25 2009 all_locales-1.4.18-20090526.tar 3481600 Jan 8 2025 squirrelmail-20250108_0200-SVN.stable.tar 2529280 Jun 27 2007 squirrelmail-decode-1.2.tar 4096 Jan 8 2025 squirrelmail.stable 3225600 Jul 12 2011 squirrelmail-webmail-1.4.22.tar I don't remember exactly which files were used during the installation. The typescript of my installation is lost, so everything is circumstantial evidence. Is there a method for definitively finding a version number or does that come from the name of the tar file? Timothy D Legg |
|
From: Paul L. <pa...@sq...> - 2026-05-28 18:04:10
|
> I need to upgrade from fedora40 to fedora44, running php-8.5.6. > > What is the latest version the latest squirremail-1.4.23 SVN has been > tested on? > > Here are the plugins I'm currently using. > Installed Plugins > 1. squirrelspell > 2. compatibility > 3. squirrel_logger > 4. administrator > 5. calendar > 6. delete_move_next > 7. folder_sizes > 8. local_autorespond_forward > 9. message_details > 10. sent_subfolders > 11. timeout_user > 12. info > 13. lockout > > The last time I upgraded was probably in July, 2024, so I'm hoping there's > a more recent version, as I do see some deprecation warnings when enabling > display mode. SquirrelMail should work fine for your upgrade. Send any deprecation notices to the mailing list and we can take a look to see if any changes need to be considered. Thanks, -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php |
|
From: Alex <mys...@gm...> - 2026-05-27 21:49:08
|
Hi,
I need to upgrade from fedora40 to fedora44, running php-8.5.6.
What is the latest version the latest squirremail-1.4.23 SVN has been
tested on?
Here are the plugins I'm currently using.
Installed Plugins
1. squirrelspell
2. compatibility
3. squirrel_logger
4. administrator
5. calendar
6. delete_move_next
7. folder_sizes
8. local_autorespond_forward
9. message_details
10. sent_subfolders
11. timeout_user
12. info
13. lockout
The last time I upgraded was probably in July, 2024, so I'm hoping there's
a more recent version, as I do see some deprecation warnings when enabling
display mode.
Thanks,
Alex
|
|
From: Tóth A. <at...@at...> - 2026-04-07 08:27:54
|
Wanted to report back on this: I got to the point where - with some modifications in oath-toolkit - I was able to login using a concatenated password + OTP pair. However squirrelmail seems to initiate reauthentication quite frequently upon reloading page, entering in-and-out of mail directories, refreshing directory list, etc. Since the OTP part of the credentials expire, it fails soon and makes the whole effort/concept not feasible. Is there a good way to reduce the rate of reauthentication triggers and keep the a current session for a prolonged time? php.ini: session.cookie_lifetime = 0 session.gc_maxlifetime = 1440 (24 minutes) While if I'm actively browsing my mails I see reauths sometimes multiple times in a minute. Any ideas appreciated! Thx: Dw. -- dr Tóth Attila, Radiológus, 06-20-825-8057 Attila Toth MD, Radiologist, +36-20-825-8057 2026.Április 3.(P) 23:06 időpontban "Tóth Attila" ezt írta: > I'm using current squirrelmail snapshot, the imap server is dovecot 2.4.3. > I've installed oath-toolkit and totp works for ssh sessions. It would be > good to also enable it for dovecot. It would be easy to add the line to > the dovecot pam file. In case of sshd, it asks for the TOTP and the > password separately. I'm not sure how it would be feasible with > dovecot+squirrelmail. > Anyone ever successfully deployed oath_pam with dovecot+squirrelmail? > Any suggestions or prior experience? > > Thanks: > Dw. > -- > dr Tóth Attila, Radiológus, 06-20-825-8057 > Attila Toth MD, Radiologist, +36-20-825-8057 > > > > ----- > squirrelmail-users mailing list > Posting guidelines: http://squirrelmail.org/postingguidelines > List address: squ...@li... > List archives: http://news.gmane.org/gmane.mail.squirrelmail.user > List info (subscribe/unsubscribe/change options): > https://lists.sourceforge.net/lists/listinfo/squirrelmail-users > |
|
From: Tóth A. <at...@at...> - 2026-04-03 21:19:45
|
I'm using current squirrelmail snapshot, the imap server is dovecot 2.4.3. I've installed oath-toolkit and totp works for ssh sessions. It would be good to also enable it for dovecot. It would be easy to add the line to the dovecot pam file. In case of sshd, it asks for the TOTP and the password separately. I'm not sure how it would be feasible with dovecot+squirrelmail. Anyone ever successfully deployed oath_pam with dovecot+squirrelmail? Any suggestions or prior experience? Thanks: Dw. -- dr Tóth Attila, Radiológus, 06-20-825-8057 Attila Toth MD, Radiologist, +36-20-825-8057 |
|
From: Paul L. <pa...@sq...> - 2026-01-14 22:13:45
|
On Wed, January 14, 2026 3:44 am, Jay Hart wrote: >> >>> ERROR: Error connecting to SMTP server "10.20.30.11:25".Server >>> error: >>> (0) >>> >>> I have enabled enhanced logging for both php-fpm and postfix, Here are >>> some logs entries: >>> >>> [root@kevla postfix]# tail /var/log/php-fpm/www-error.log >>> [09-Jan-2026 21:07:20 America/New_York] PHP Warning: fsockopen(): >>> Failed >>> to enable crypto in /usr/share/squirrelmail/src/configtest.php >>> on line 405 >>> [09-Jan-2026 21:07:20 America/New_York] PHP Warning: fsockopen(): >>> Unable >>> to connect to ssl://x.x.x.x:25 (Unknown error) in >>> /usr/share/squirrelmail/src/configtest.php on line 405 >>> [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): SSL >>> operation failed with code 1. OpenSSL Error messages: >>> error:0A00010B:SSL routines::wrong version number in >>> /usr/share/squirrelmail/src/configtest.php on line 405 >>> [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): >>> Failed >>> to enable crypto in /usr/share/squirrelmail/src/configtest.php >>> on line 405 >>> [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): >>> Unable >>> to connect to ssl://x.x.x.x:25 (Unknown error) in >>> /usr/share/squirrelmail/src/configtest.php on line 405 >>> [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): SSL >>> operation failed with code 1. OpenSSL Error messages: >>> error:0A00010B:SSL routines::wrong version number in >>> /usr/share/squirrelmail/src/configtest.php on line 405 >>> [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): >>> Failed >>> to enable crypto in /usr/share/squirrelmail/src/configtest.php >>> on line 405 >>> [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): >>> Unable >>> to connect to ssl://x.x.x.x:25 (Unknown error) in >>> /usr/share/squirrelmail/src/configtest.php on line 405 >>> >>> more /var/log/maillog |grep warning >>> Jan 10 16:59:57 rocky postfix/smtpd[416626]: dict_lookup: >>> helpful_warnings >>> = (notfound) >>> Jan 10 16:59:57 rocky postfix/smtpd[416626]: dict_update: >>> helpful_warnings >>> = yes >>> Jan 10 16:59:57 rocky postfix/smtpd[416626]: warning: run-time library >>> vs. >>> compile-time header version mismatch: OpenSSL 3.5.0 may not be >>> compatible with OpenSSL 3.2.0 >>> Jan 10 17:05:03 rocky postfix/smtpd[417102]: dict_lookup: >>> helpful_warnings >>> = (notfound) >>> Jan 10 17:05:03 rocky postfix/smtpd[417102]: dict_update: >>> helpful_warnings >>> = yes >>> Jan 10 17:05:03 rocky postfix/smtpd[417105]: dict_lookup: >>> helpful_warnings >>> = (notfound) >>> Jan 10 17:05:03 rocky postfix/smtpd[417105]: dict_update: >>> helpful_warnings >>> = yes >>> Jan 10 17:05:03 rocky postfix/smtpd[417102]: warning: run-time library >>> vs. >>> compile-time header version mismatch: OpenSSL 3.5.0 may not be >>> compatible with OpenSSL 3.2.0 >>> Jan 10 17:05:03 rocky postfix/smtps/smtpd[417105]: warning: run-time >>> library vs. compile-time header version mismatch: OpenSSL 3.5.0 may >>> not be compatible with OpenSSL 3.2.0 >> >> Those errors hint at cert or cipher mismatch, which would require more >> detailed investigation on your part. You can always connect by hand >> using >> openssl s_client and see more details of the exchange. Or sniff it with >> ngrep or the likes. >> >> On the other hand, it is quite possible that you have SquirrelMail set >> to >> connect over TLS immediately, and on port 25, you'll need to use >> STARTTLS. >> See $use_smtp_tls in SquirrelMail's config.php or re-run conf.pl ... >> it's >> still better to run a separate Postfix listener for picking up locally >> submitted mail, because it should be handled differently. >> >> -- >> Paul Lesniewski >> SquirrelMail Team >> Please support Open Source Software by donating to SquirrelMail! >> http://squirrelmail.org/donate_paul_lesniewski.php >> > > Paul, > > Do you think it would be easier to just uninstall and reinstall postfix, > openssl, and dovecot (and whatever else you think would be > needed), then it would be to track this down via troubleshooting? > > I'm going back/forth on that question.. On one hand, if you've been changing configuration parameters without a sense of what they do and it's become a mess, then it can be a good idea to go back to a clean configuration. But you also need to work on the problem and not unrelated things. Dovecot plays no role in any SMTP connections for instance. You'd probably be best served by enabling the TLS/SSL service on port 465 in Postfix's master.cf so you can stop using port 25 for two completely different mail flows and that port is also encrypted from the get-go which is how you might have configured SquirrelMail. -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php |
|
From: Jay H. <jh...@ke...> - 2026-01-14 03:45:03
|
> >> ERROR: Error connecting to SMTP server "10.20.30.11:25".Server error: >> (0) >> >> I have enabled enhanced logging for both php-fpm and postfix, Here are >> some logs entries: >> >> [root@kevla postfix]# tail /var/log/php-fpm/www-error.log >> [09-Jan-2026 21:07:20 America/New_York] PHP Warning: fsockopen(): Failed >> to enable crypto in /usr/share/squirrelmail/src/configtest.php >> on line 405 >> [09-Jan-2026 21:07:20 America/New_York] PHP Warning: fsockopen(): Unable >> to connect to ssl://x.x.x.x:25 (Unknown error) in >> /usr/share/squirrelmail/src/configtest.php on line 405 >> [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): SSL >> operation failed with code 1. OpenSSL Error messages: >> error:0A00010B:SSL routines::wrong version number in >> /usr/share/squirrelmail/src/configtest.php on line 405 >> [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): Failed >> to enable crypto in /usr/share/squirrelmail/src/configtest.php >> on line 405 >> [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): Unable >> to connect to ssl://x.x.x.x:25 (Unknown error) in >> /usr/share/squirrelmail/src/configtest.php on line 405 >> [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): SSL >> operation failed with code 1. OpenSSL Error messages: >> error:0A00010B:SSL routines::wrong version number in >> /usr/share/squirrelmail/src/configtest.php on line 405 >> [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): Failed >> to enable crypto in /usr/share/squirrelmail/src/configtest.php >> on line 405 >> [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): Unable >> to connect to ssl://x.x.x.x:25 (Unknown error) in >> /usr/share/squirrelmail/src/configtest.php on line 405 >> >> more /var/log/maillog |grep warning >> Jan 10 16:59:57 rocky postfix/smtpd[416626]: dict_lookup: helpful_warnings >> = (notfound) >> Jan 10 16:59:57 rocky postfix/smtpd[416626]: dict_update: helpful_warnings >> = yes >> Jan 10 16:59:57 rocky postfix/smtpd[416626]: warning: run-time library vs. >> compile-time header version mismatch: OpenSSL 3.5.0 may not be >> compatible with OpenSSL 3.2.0 >> Jan 10 17:05:03 rocky postfix/smtpd[417102]: dict_lookup: helpful_warnings >> = (notfound) >> Jan 10 17:05:03 rocky postfix/smtpd[417102]: dict_update: helpful_warnings >> = yes >> Jan 10 17:05:03 rocky postfix/smtpd[417105]: dict_lookup: helpful_warnings >> = (notfound) >> Jan 10 17:05:03 rocky postfix/smtpd[417105]: dict_update: helpful_warnings >> = yes >> Jan 10 17:05:03 rocky postfix/smtpd[417102]: warning: run-time library vs. >> compile-time header version mismatch: OpenSSL 3.5.0 may not be >> compatible with OpenSSL 3.2.0 >> Jan 10 17:05:03 rocky postfix/smtps/smtpd[417105]: warning: run-time >> library vs. compile-time header version mismatch: OpenSSL 3.5.0 may >> not be compatible with OpenSSL 3.2.0 > > Those errors hint at cert or cipher mismatch, which would require more > detailed investigation on your part. You can always connect by hand using > openssl s_client and see more details of the exchange. Or sniff it with > ngrep or the likes. > > On the other hand, it is quite possible that you have SquirrelMail set to > connect over TLS immediately, and on port 25, you'll need to use STARTTLS. > See $use_smtp_tls in SquirrelMail's config.php or re-run conf.pl ... it's > still better to run a separate Postfix listener for picking up locally > submitted mail, because it should be handled differently. > > -- > Paul Lesniewski > SquirrelMail Team > Please support Open Source Software by donating to SquirrelMail! > http://squirrelmail.org/donate_paul_lesniewski.php > Paul, Do you think it would be easier to just uninstall and reinstall postfix, openssl, and dovecot (and whatever else you think would be needed), then it would be to track this down via troubleshooting? I'm going back/forth on that question.. Jay |
|
From: Paul L. <pa...@sq...> - 2026-01-12 21:56:52
|
> ERROR: Error connecting to SMTP server "10.20.30.11:25".Server error: > (0) > > I have enabled enhanced logging for both php-fpm and postfix, Here are > some logs entries: > > [root@kevla postfix]# tail /var/log/php-fpm/www-error.log > [09-Jan-2026 21:07:20 America/New_York] PHP Warning: fsockopen(): Failed > to enable crypto in /usr/share/squirrelmail/src/configtest.php > on line 405 > [09-Jan-2026 21:07:20 America/New_York] PHP Warning: fsockopen(): Unable > to connect to ssl://x.x.x.x:25 (Unknown error) in > /usr/share/squirrelmail/src/configtest.php on line 405 > [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): SSL > operation failed with code 1. OpenSSL Error messages: > error:0A00010B:SSL routines::wrong version number in > /usr/share/squirrelmail/src/configtest.php on line 405 > [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): Failed > to enable crypto in /usr/share/squirrelmail/src/configtest.php > on line 405 > [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): Unable > to connect to ssl://x.x.x.x:25 (Unknown error) in > /usr/share/squirrelmail/src/configtest.php on line 405 > [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): SSL > operation failed with code 1. OpenSSL Error messages: > error:0A00010B:SSL routines::wrong version number in > /usr/share/squirrelmail/src/configtest.php on line 405 > [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): Failed > to enable crypto in /usr/share/squirrelmail/src/configtest.php > on line 405 > [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): Unable > to connect to ssl://x.x.x.x:25 (Unknown error) in > /usr/share/squirrelmail/src/configtest.php on line 405 > > more /var/log/maillog |grep warning > Jan 10 16:59:57 rocky postfix/smtpd[416626]: dict_lookup: helpful_warnings > = (notfound) > Jan 10 16:59:57 rocky postfix/smtpd[416626]: dict_update: helpful_warnings > = yes > Jan 10 16:59:57 rocky postfix/smtpd[416626]: warning: run-time library vs. > compile-time header version mismatch: OpenSSL 3.5.0 may not be > compatible with OpenSSL 3.2.0 > Jan 10 17:05:03 rocky postfix/smtpd[417102]: dict_lookup: helpful_warnings > = (notfound) > Jan 10 17:05:03 rocky postfix/smtpd[417102]: dict_update: helpful_warnings > = yes > Jan 10 17:05:03 rocky postfix/smtpd[417105]: dict_lookup: helpful_warnings > = (notfound) > Jan 10 17:05:03 rocky postfix/smtpd[417105]: dict_update: helpful_warnings > = yes > Jan 10 17:05:03 rocky postfix/smtpd[417102]: warning: run-time library vs. > compile-time header version mismatch: OpenSSL 3.5.0 may not be > compatible with OpenSSL 3.2.0 > Jan 10 17:05:03 rocky postfix/smtps/smtpd[417105]: warning: run-time > library vs. compile-time header version mismatch: OpenSSL 3.5.0 may > not be compatible with OpenSSL 3.2.0 Those errors hint at cert or cipher mismatch, which would require more detailed investigation on your part. You can always connect by hand using openssl s_client and see more details of the exchange. Or sniff it with ngrep or the likes. On the other hand, it is quite possible that you have SquirrelMail set to connect over TLS immediately, and on port 25, you'll need to use STARTTLS. See $use_smtp_tls in SquirrelMail's config.php or re-run conf.pl ... it's still better to run a separate Postfix listener for picking up locally submitted mail, because it should be handled differently. -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php |
|
From: Jay H. <jh...@ke...> - 2026-01-11 00:06:15
|
> > > On Tue, December 30, 2025 9:46 pm, Jay Hart wrote: >>> >>> >>>> >>>>> Checking outgoing mail service.... >>>>> >>>>> ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: >>>>> (111) Connection refused >>>>> >>>>> NOTE: I obfuscated my internal ip network addresses above... >>>>> >>>>> I can't find anything wrong with my postfix config, telnet works just >>>>> fine >>>>> on port 25. >>>>> >>>>> I currently have selinux in 'permissive' mode as in 'Enforcing' mode I >>>>> was >>>>> not able to write to the attachment directory (maybe I have a >>>>> bigger issue here). >>>>> >>>>> Could I need to adjust the firewall rules?? >>>> >>>> Take a look at them and make sure. >>>> >>>> Make sure you are telnetting from the same place SquirrelMail is >>>> running >>>> and that the address is exactly the same. If that works, sudo telnet as >>>> the same user apache is running as, since maybe apache user is >>>> prevented >>>> from connecting on the network. >>>> >>> >>> I have adjusted by firewall rules. How does the following look to you? >>> >>> [root@kevla conf.d]# firewall-cmd --list-all --permanent >>> public >>> target: default >>> icmp-block-inversion: no >>> interfaces: >>> sources: >>> services: cockpit dhcpv6-client http https imap smtp ssh >>> ports: 80/tcp 443/tcp >>> protocols: >>> forward: yes >>> masquerade: no >>> forward-ports: >>> source-ports: >>> icmp-blocks: >>> rich rules: > > You can also turn off the firewall to test. > >>> I am configuring this box 'offline' and no direct connection to an >>> outgoing relay (as of yet). Could that be part of my problem? IOW, is >>> this an internal only issue or could it be related to no forwarding >>> relay server? > > Then are you sure the machine is binding to the IP address you're using if > it is offline? If you are running apache on the same server as the SMTP > service, then why not use 127.0.0.1? It also happens to be a good idea > that you have a different service for accepting local mail which applies > separate policies compared to port 25 that is intended to accept mail from > untrusted external sources. In fact, why not use the submission service? > > >> I've dug a bit deeper here. >> >> Firewall configs are now... >> >> [root@kevla share]# firewall-cmd --list-all --permanent >> public >> target: default >> icmp-block-inversion: no >> interfaces: >> sources: >> services: cockpit dhcpv6-client http https imap imaps smtp ssh >> ports: 80/tcp 443/tcp 25/tcp 993/tcp 143/tcp 587/tcp >> protocols: >> forward: yes >> masquerade: no >> forward-ports: >> source-ports: >> icmp-blocks: >> rich rules: >> >> I've ruled out the firewall being a possibility of the issue. >> >> I think my main problem seems to be shown below from the messages log >> file. I get these every time I run configtest.php and get the SMTP >> server above: >> >> Dec 30 16:04:32 kevla setroubleshoot[37707]: SELinux is preventing >> /usr/sbin/php-fpm from open access on the file >> /usr/share/squirrelmail/plugins/compatibility/functions.php.#012#012***** >> Plugin restorecon (92.2 confidence) suggests >> ************************#012#012If you want to fix the label. >> #012/usr/share/squirrelmail/plugins/compatibility/functions.php default >> label should be usr_t.#012Then you can run restorecon. The access attempt >> may have been stopped due to insufficient permissions to access >> a parent directory in which case try to change the following command >> accordingly.#012Do#012# /sbin/restorecon -v >> /usr/share/squirrelmail/plugins/compatibility/functions.php#012#012***** >> Plugin catchall_boolean (7.83 confidence) suggests >> ******************#012#012If you want to allow httpd to read user >> content#012Then you must tell SELinux about this by enabling the >> 'httpd_read_user_content' boolean.#012#012Do#012setsebool -P >> httpd_read_user_content 1#012#012***** Plugin catchall (1.41 confidence) >> suggests **************************#012#012If you believe that php-fpm >> should be allowed open access on the functions.php file by >> default.#012Then you should report this as a bug.#012You can generate a >> local policy module to allow this access.#012Do#012allow this >> access for now by executing:#012# ausearch -c 'php-fpm' --raw | >> audit2allow -M my-phpfpm#012# semodule -X 300 -i my-phpfpm.pp#012 >> >> Here are the permissions for that particular file. >> >> [root@kevla log]# ls -lZ >> /usr/share/squirrelmail/plugins/compatibility/functions.php >> -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 30611 Dec 6 >> 2009 /usr/share/squirrelmail/plugins/compatibility/functions.php >> >> Looking at the plugin directories, and running 'ls -lZ', I see a mixture >> of permissions, such as: >> >> calendar: >> total 76 >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6541 Dec 28 18:51 >> calendar_data.php >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6770 Dec 28 18:51 >> calendar.php >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6128 Dec 28 18:51 >> day.php >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6716 Dec 28 18:51 >> event_create.php >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 5851 Dec 28 18:51 >> event_delete.php >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 12887 Dec 28 18:51 >> event_edit.php >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 5291 Dec 28 18:51 >> functions.php >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 499 Dec 28 18:51 >> index.php >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 887 Dec 28 18:51 >> README >> -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 700 Dec 28 18:51 >> setup.php >> >> compatibility: >> total 68 >> drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 84 Dec 6 >> 2009 docs >> -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 30611 Dec 6 >> 2009 functions.php >> drwxr-xr-x. 31 root root unconfined_u:object_r:user_home_t:s0 4096 Dec 6 >> 2009 includes >> -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 466 Jan 2 >> 2009 index.php >> drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 79 Nov 1 >> 2009 locale >> -rwxr--r--. 1 root root unconfined_u:object_r:user_home_t:s0 5928 Nov 1 >> 2009 make_release.sh >> drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 4096 Nov 1 >> 2009 patches >> drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 4096 Nov 1 >> 2009 patches.old >> -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 53 Nov 1 >> 2009 README >> -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 2096 Dec 6 >> 2009 setup.php >> -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 21 Dec 6 >> 2009 version >> >> I ASSUME I need to change everything /usr/share/squirrelmail to >> ''object_r:usr_t? If not, what SHOULD THEY be? > > Running restorecon -r as the error suggests should reset the files to > whatever the system expects in that directory. What they should be is > different depending on the location and OS. If SELinux is involved, it can > also be blocking PHP from talking over the network to the SMTP service. If > it's on the same machine, you can also try using the sendmail option > instead of using SMTP. > > -- > Paul Lesniewski > SquirrelMail Team > Please support Open Source Software by donating to SquirrelMail! > http://squirrelmail.org/donate_paul_lesniewski.php > Paul, I fixed those issues but have hit a bigger snag, I can't pass a configtest test. Trying to resolve this I have turned off the firewall, just so I can eliminate that as a problem. I get hung up on the SMTP server check with the following error: Checking outgoing mail service.... ERROR: Error connecting to SMTP server "10.20.30.11:25".Server error: (0) I have enabled enhanced logging for both php-fpm and postfix, Here are some logs entries: [root@kevla postfix]# tail /var/log/php-fpm/www-error.log [09-Jan-2026 21:07:20 America/New_York] PHP Warning: fsockopen(): Failed to enable crypto in /usr/share/squirrelmail/src/configtest.php on line 405 [09-Jan-2026 21:07:20 America/New_York] PHP Warning: fsockopen(): Unable to connect to ssl://x.x.x.x:25 (Unknown error) in /usr/share/squirrelmail/src/configtest.php on line 405 [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): SSL operation failed with code 1. OpenSSL Error messages: error:0A00010B:SSL routines::wrong version number in /usr/share/squirrelmail/src/configtest.php on line 405 [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): Failed to enable crypto in /usr/share/squirrelmail/src/configtest.php on line 405 [10-Jan-2026 12:54:20 America/New_York] PHP Warning: fsockopen(): Unable to connect to ssl://x.x.x.x:25 (Unknown error) in /usr/share/squirrelmail/src/configtest.php on line 405 [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): SSL operation failed with code 1. OpenSSL Error messages: error:0A00010B:SSL routines::wrong version number in /usr/share/squirrelmail/src/configtest.php on line 405 [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): Failed to enable crypto in /usr/share/squirrelmail/src/configtest.php on line 405 [10-Jan-2026 13:08:03 America/New_York] PHP Warning: fsockopen(): Unable to connect to ssl://x.x.x.x:25 (Unknown error) in /usr/share/squirrelmail/src/configtest.php on line 405 more /var/log/maillog |grep warning Jan 10 16:59:57 rocky postfix/smtpd[416626]: dict_lookup: helpful_warnings = (notfound) Jan 10 16:59:57 rocky postfix/smtpd[416626]: dict_update: helpful_warnings = yes Jan 10 16:59:57 rocky postfix/smtpd[416626]: warning: run-time library vs. compile-time header version mismatch: OpenSSL 3.5.0 may not be compatible with OpenSSL 3.2.0 Jan 10 17:05:03 rocky postfix/smtpd[417102]: dict_lookup: helpful_warnings = (notfound) Jan 10 17:05:03 rocky postfix/smtpd[417102]: dict_update: helpful_warnings = yes Jan 10 17:05:03 rocky postfix/smtpd[417105]: dict_lookup: helpful_warnings = (notfound) Jan 10 17:05:03 rocky postfix/smtpd[417105]: dict_update: helpful_warnings = yes Jan 10 17:05:03 rocky postfix/smtpd[417102]: warning: run-time library vs. compile-time header version mismatch: OpenSSL 3.5.0 may not be compatible with OpenSSL 3.2.0 Jan 10 17:05:03 rocky postfix/smtps/smtpd[417105]: warning: run-time library vs. compile-time header version mismatch: OpenSSL 3.5.0 may not be compatible with OpenSSL 3.2.0 [root@kevla conf.d]# more /etc/postfix/main.cf |grep -v "#" NOTE: I removed several of standard entries to make this list shorter. compatibility_level = 2 data_directory = /var/lib/postfix mail_owner = postfix myhostname = rocky.$mydomain mydomain = kevla.org myorigin = $mydomain inet_interfaces = all inet_protocols = ipv4 mydestination = $myhostname, localhost.$mydomain, $mydomain, localhost unknown_local_recipient_reject_code = 550 mynetworks = 127.0.0.0/8, 10.20.30.0/24 alias_maps = hash:/etc/aliases alias_database = hash:/etc/aliases home_mailbox = Maildir/ mailbox_transport = lmtp:unix:private/dovecot-lmtp header_checks = regexp:/etc/postfix/header_checks debug_peer_level = 6 debug_peer_list = 127.0.0.1 newaliases_path = /usr/bin/newaliases.postfix disable_vrfy_command = yes smtpd_tls_cert_file = /etc/letsencrypt/live/kevla.org/fullchain.pem smtpd_tls_key_file = /etc/letsencrypt/live/kevla.org/privkey.pem smtpd_tls_security_level = may smtp_tls_CApath = /etc/pki/tls/certs smtp_tls_CAfile = /etc/pki/tls/certs/ca-bundle.crt smtp_tls_security_level = may meta_directory = /etc/postfix shlib_directory = /usr/lib64/postfix smtpd_tls_loglevel = 2 smtp_tls_loglevel = 2 smtpd_discard_ehlo_keywords = chunking, silent-discard smtp_discard_ehlo_keywords = chunking, silent-discard smtpd_tls_mandatory_protocols = TLSv1.3, TLSv1.2, !SSLv2, !SSLv3, !TLSv1, !TLSv1.1 smtpd_tls_protocols = TLSv1.3, TLSv1.2, !SSLv2, !SSLv3, !TLSv1, !TLSv1.1 smtp_tls_mandatory_protocols = TLSv1.3, TLSv1.2, !SSLv2, !SSLv3, !TLSv1, !TLSv1.1 smtp_tls_protocols = TLSv1.3, TLSv1.2, !SSLv2, !SSLv3, !TLSv1, !TLSv1.1 smtputf8_enable = no smtpd_use_tls = yes smtp_use_tls = yes smtpd_client_restrictions = permit_mynetworks, reject_unknown_client, permit smtpd_recipient_restrictions = permit_mynetworks, permit_auth_destination, permit_sasl_authenticated, reject_unauth_destination smtp_sasl_auth_enable = yes smtp_sasl_security_options = noanonymous header_size_limit = 4096000 relayhost = [mail.smtp2go.com]:2525 relay_destination_concurrency_limit = 20 Any pointers on where to look to resolve this?. Do you see anything blatantly worng? I have poured over the postfix, dovecot, and php-fpm configs, and while i have tweaked a few settings, I do not see anything major that stands out. TIA, Jay Hart |
|
From: Paul L. <pa...@sq...> - 2025-12-31 03:12:48
|
On Tue, December 30, 2025 9:46 pm, Jay Hart wrote: >> >> >>> >>>> Checking outgoing mail service.... >>>> >>>> ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: >>>> (111) Connection refused >>>> >>>> NOTE: I obfuscated my internal ip network addresses above... >>>> >>>> I can't find anything wrong with my postfix config, telnet works just >>>> fine >>>> on port 25. >>>> >>>> I currently have selinux in 'permissive' mode as in 'Enforcing' mode I >>>> was >>>> not able to write to the attachment directory (maybe I have a >>>> bigger issue here). >>>> >>>> Could I need to adjust the firewall rules?? >>> >>> Take a look at them and make sure. >>> >>> Make sure you are telnetting from the same place SquirrelMail is >>> running >>> and that the address is exactly the same. If that works, sudo telnet as >>> the same user apache is running as, since maybe apache user is >>> prevented >>> from connecting on the network. >>> >> >> I have adjusted by firewall rules. How does the following look to you? >> >> [root@kevla conf.d]# firewall-cmd --list-all --permanent >> public >> target: default >> icmp-block-inversion: no >> interfaces: >> sources: >> services: cockpit dhcpv6-client http https imap smtp ssh >> ports: 80/tcp 443/tcp >> protocols: >> forward: yes >> masquerade: no >> forward-ports: >> source-ports: >> icmp-blocks: >> rich rules: You can also turn off the firewall to test. >> I am configuring this box 'offline' and no direct connection to an >> outgoing relay (as of yet). Could that be part of my problem? IOW, is >> this an internal only issue or could it be related to no forwarding >> relay server? Then are you sure the machine is binding to the IP address you're using if it is offline? If you are running apache on the same server as the SMTP service, then why not use 127.0.0.1? It also happens to be a good idea that you have a different service for accepting local mail which applies separate policies compared to port 25 that is intended to accept mail from untrusted external sources. In fact, why not use the submission service? > I've dug a bit deeper here. > > Firewall configs are now... > > [root@kevla share]# firewall-cmd --list-all --permanent > public > target: default > icmp-block-inversion: no > interfaces: > sources: > services: cockpit dhcpv6-client http https imap imaps smtp ssh > ports: 80/tcp 443/tcp 25/tcp 993/tcp 143/tcp 587/tcp > protocols: > forward: yes > masquerade: no > forward-ports: > source-ports: > icmp-blocks: > rich rules: > > I've ruled out the firewall being a possibility of the issue. > > I think my main problem seems to be shown below from the messages log > file. I get these every time I run configtest.php and get the SMTP > server above: > > Dec 30 16:04:32 kevla setroubleshoot[37707]: SELinux is preventing > /usr/sbin/php-fpm from open access on the file > /usr/share/squirrelmail/plugins/compatibility/functions.php.#012#012***** > Plugin restorecon (92.2 confidence) suggests > ************************#012#012If you want to fix the label. > #012/usr/share/squirrelmail/plugins/compatibility/functions.php default > label should be usr_t.#012Then you can run restorecon. The access attempt > may have been stopped due to insufficient permissions to access > a parent directory in which case try to change the following command > accordingly.#012Do#012# /sbin/restorecon -v > /usr/share/squirrelmail/plugins/compatibility/functions.php#012#012***** > Plugin catchall_boolean (7.83 confidence) suggests > ******************#012#012If you want to allow httpd to read user > content#012Then you must tell SELinux about this by enabling the > 'httpd_read_user_content' boolean.#012#012Do#012setsebool -P > httpd_read_user_content 1#012#012***** Plugin catchall (1.41 confidence) > suggests **************************#012#012If you believe that php-fpm > should be allowed open access on the functions.php file by > default.#012Then you should report this as a bug.#012You can generate a > local policy module to allow this access.#012Do#012allow this > access for now by executing:#012# ausearch -c 'php-fpm' --raw | > audit2allow -M my-phpfpm#012# semodule -X 300 -i my-phpfpm.pp#012 > > Here are the permissions for that particular file. > > [root@kevla log]# ls -lZ > /usr/share/squirrelmail/plugins/compatibility/functions.php > -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 30611 Dec 6 > 2009 /usr/share/squirrelmail/plugins/compatibility/functions.php > > Looking at the plugin directories, and running 'ls -lZ', I see a mixture > of permissions, such as: > > calendar: > total 76 > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6541 Dec 28 18:51 > calendar_data.php > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6770 Dec 28 18:51 > calendar.php > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6128 Dec 28 18:51 > day.php > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6716 Dec 28 18:51 > event_create.php > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 5851 Dec 28 18:51 > event_delete.php > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 12887 Dec 28 18:51 > event_edit.php > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 5291 Dec 28 18:51 > functions.php > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 499 Dec 28 18:51 > index.php > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 887 Dec 28 18:51 > README > -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 700 Dec 28 18:51 > setup.php > > compatibility: > total 68 > drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 84 Dec 6 > 2009 docs > -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 30611 Dec 6 > 2009 functions.php > drwxr-xr-x. 31 root root unconfined_u:object_r:user_home_t:s0 4096 Dec 6 > 2009 includes > -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 466 Jan 2 > 2009 index.php > drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 79 Nov 1 > 2009 locale > -rwxr--r--. 1 root root unconfined_u:object_r:user_home_t:s0 5928 Nov 1 > 2009 make_release.sh > drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 4096 Nov 1 > 2009 patches > drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 4096 Nov 1 > 2009 patches.old > -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 53 Nov 1 > 2009 README > -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 2096 Dec 6 > 2009 setup.php > -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 21 Dec 6 > 2009 version > > I ASSUME I need to change everything /usr/share/squirrelmail to > ''object_r:usr_t? If not, what SHOULD THEY be? Running restorecon -r as the error suggests should reset the files to whatever the system expects in that directory. What they should be is different depending on the location and OS. If SELinux is involved, it can also be blocking PHP from talking over the network to the SMTP service. If it's on the same machine, you can also try using the sendmail option instead of using SMTP. -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php |
|
From: Jay H. <jh...@ke...> - 2025-12-30 21:50:35
|
> > >> >>> Checking outgoing mail service.... >>> >>> ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: >>> (111) Connection refused >>> >>> NOTE: I obfuscated my internal ip network addresses above... >>> >>> I can't find anything wrong with my postfix config, telnet works just fine on port 25. >>> >>> I currently have selinux in 'permissive' mode as in 'Enforcing' mode I was not able to write to the attachment directory (maybe I have a >>> bigger issue here). >>> >>> Could I need to adjust the firewall rules?? >> >> Take a look at them and make sure. >> >> Make sure you are telnetting from the same place SquirrelMail is running and that the address is exactly the same. If that works, sudo telnet as the same user apache is running as, since maybe apache user is prevented from connecting on the network. >> >> -- >> Paul Lesniewski >> SquirrelMail Team >> Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php >> > > Paul, > > I have adjusted by firewall rules. How does the following look to you? > > [root@kevla conf.d]# firewall-cmd --list-all --permanent > public > target: default > icmp-block-inversion: no > interfaces: > sources: > services: cockpit dhcpv6-client http https imap smtp ssh > ports: 80/tcp 443/tcp > protocols: > forward: yes > masquerade: no > forward-ports: > source-ports: > icmp-blocks: > rich rules: > > If I need to adjust something, please let me know what, and how to go about it... > > About this error: > ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: > > I am configuring this box 'offline' and no direct connection to an outgoing relay (as of yet). Could that be part of my problem? IOW, is this an internal only issue or could it be related to no forwarding relay server? > > Jay > Paul, I've dug a bit deeper here. Firewall configs are now... [root@kevla share]# firewall-cmd --list-all --permanent public target: default icmp-block-inversion: no interfaces: sources: services: cockpit dhcpv6-client http https imap imaps smtp ssh ports: 80/tcp 443/tcp 25/tcp 993/tcp 143/tcp 587/tcp protocols: forward: yes masquerade: no forward-ports: source-ports: icmp-blocks: rich rules: I've ruled out the firewall being a possibility of the issue. I think my main problem seems to be shown below from the messages log file. I get these every time I run configtest.php and get the SMTP server above: Dec 30 16:04:32 kevla setroubleshoot[37707]: SELinux is preventing /usr/sbin/php-fpm from open access on the file /usr/share/squirrelmail/plugins/compatibility/functions.php.#012#012***** Plugin restorecon (92.2 confidence) suggests ************************#012#012If you want to fix the label. #012/usr/share/squirrelmail/plugins/compatibility/functions.php default label should be usr_t.#012Then you can run restorecon. The access attempt may have been stopped due to insufficient permissions to access a parent directory in which case try to change the following command accordingly.#012Do#012# /sbin/restorecon -v /usr/share/squirrelmail/plugins/compatibility/functions.php#012#012***** Plugin catchall_boolean (7.83 confidence) suggests ******************#012#012If you want to allow httpd to read user content#012Then you must tell SELinux about this by enabling the 'httpd_read_user_content' boolean.#012#012Do#012setsebool -P httpd_read_user_content 1#012#012***** Plugin catchall (1.41 confidence) suggests **************************#012#012If you believe that php-fpm should be allowed open access on the functions.php file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'php-fpm' --raw | audit2allow -M my-phpfpm#012# semodule -X 300 -i my-phpfpm.pp#012 Here are the permissions for that particular file. [root@kevla log]# ls -lZ /usr/share/squirrelmail/plugins/compatibility/functions.php -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 30611 Dec 6 2009 /usr/share/squirrelmail/plugins/compatibility/functions.php Looking at the plugin directories, and running 'ls -lZ', I see a mixture of permissions, such as: calendar: total 76 -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6541 Dec 28 18:51 calendar_data.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6770 Dec 28 18:51 calendar.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6128 Dec 28 18:51 day.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6716 Dec 28 18:51 event_create.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 5851 Dec 28 18:51 event_delete.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 12887 Dec 28 18:51 event_edit.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 5291 Dec 28 18:51 functions.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 499 Dec 28 18:51 index.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 887 Dec 28 18:51 README -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 700 Dec 28 18:51 setup.php compatibility: total 68 drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 84 Dec 6 2009 docs -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 30611 Dec 6 2009 functions.php drwxr-xr-x. 31 root root unconfined_u:object_r:user_home_t:s0 4096 Dec 6 2009 includes -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 466 Jan 2 2009 index.php drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 79 Nov 1 2009 locale -rwxr--r--. 1 root root unconfined_u:object_r:user_home_t:s0 5928 Nov 1 2009 make_release.sh drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 4096 Nov 1 2009 patches drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 4096 Nov 1 2009 patches.old -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 53 Nov 1 2009 README -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 2096 Dec 6 2009 setup.php -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 21 Dec 6 2009 version I ASSUME I need to change everything in /usr/share/squirrelmail to ''object_r:usr_t? If not, what SHOULD THEY be? Jay |
|
From: Jay H. <jh...@ke...> - 2025-12-30 21:47:06
|
> > >> >>> Checking outgoing mail service.... >>> >>> ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: >>> (111) Connection refused >>> >>> NOTE: I obfuscated my internal ip network addresses above... >>> >>> I can't find anything wrong with my postfix config, telnet works just fine >>> on port 25. >>> >>> I currently have selinux in 'permissive' mode as in 'Enforcing' mode I was >>> not able to write to the attachment directory (maybe I have a >>> bigger issue here). >>> >>> Could I need to adjust the firewall rules?? >> >> Take a look at them and make sure. >> >> Make sure you are telnetting from the same place SquirrelMail is running >> and that the address is exactly the same. If that works, sudo telnet as >> the same user apache is running as, since maybe apache user is prevented >> from connecting on the network. >> >> -- >> Paul Lesniewski >> SquirrelMail Team >> Please support Open Source Software by donating to SquirrelMail! >> http://squirrelmail.org/donate_paul_lesniewski.php >> > > Paul, > > I have adjusted by firewall rules. How does the following look to you? > > [root@kevla conf.d]# firewall-cmd --list-all --permanent > public > target: default > icmp-block-inversion: no > interfaces: > sources: > services: cockpit dhcpv6-client http https imap smtp ssh > ports: 80/tcp 443/tcp > protocols: > forward: yes > masquerade: no > forward-ports: > source-ports: > icmp-blocks: > rich rules: > > If I need to adjust something, please let me know what, and how to go about it... > > About this error: > ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: > > I am configuring this box 'offline' and no direct connection to an outgoing relay (as of yet). Could that be part of my problem? IOW, is > this an internal only issue or could it be related to no forwarding relay server? > > Jay > Paul, I've dug a bit deeper here. Firewall configs are now... [root@kevla share]# firewall-cmd --list-all --permanent public target: default icmp-block-inversion: no interfaces: sources: services: cockpit dhcpv6-client http https imap imaps smtp ssh ports: 80/tcp 443/tcp 25/tcp 993/tcp 143/tcp 587/tcp protocols: forward: yes masquerade: no forward-ports: source-ports: icmp-blocks: rich rules: I've ruled out the firewall being a possibility of the issue. I think my main problem seems to be shown below from the messages log file. I get these every time I run configtest.php and get the SMTP server above: Dec 30 16:04:32 kevla setroubleshoot[37707]: SELinux is preventing /usr/sbin/php-fpm from open access on the file /usr/share/squirrelmail/plugins/compatibility/functions.php.#012#012***** Plugin restorecon (92.2 confidence) suggests ************************#012#012If you want to fix the label. #012/usr/share/squirrelmail/plugins/compatibility/functions.php default label should be usr_t.#012Then you can run restorecon. The access attempt may have been stopped due to insufficient permissions to access a parent directory in which case try to change the following command accordingly.#012Do#012# /sbin/restorecon -v /usr/share/squirrelmail/plugins/compatibility/functions.php#012#012***** Plugin catchall_boolean (7.83 confidence) suggests ******************#012#012If you want to allow httpd to read user content#012Then you must tell SELinux about this by enabling the 'httpd_read_user_content' boolean.#012#012Do#012setsebool -P httpd_read_user_content 1#012#012***** Plugin catchall (1.41 confidence) suggests **************************#012#012If you believe that php-fpm should be allowed open access on the functions.php file by default.#012Then you should report this as a bug.#012You can generate a local policy module to allow this access.#012Do#012allow this access for now by executing:#012# ausearch -c 'php-fpm' --raw | audit2allow -M my-phpfpm#012# semodule -X 300 -i my-phpfpm.pp#012 Here are the permissions for that particular file. [root@kevla log]# ls -lZ /usr/share/squirrelmail/plugins/compatibility/functions.php -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 30611 Dec 6 2009 /usr/share/squirrelmail/plugins/compatibility/functions.php Looking at the plugin directories, and running 'ls -lZ', I see a mixture of permissions, such as: calendar: total 76 -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6541 Dec 28 18:51 calendar_data.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6770 Dec 28 18:51 calendar.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6128 Dec 28 18:51 day.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 6716 Dec 28 18:51 event_create.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 5851 Dec 28 18:51 event_delete.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 12887 Dec 28 18:51 event_edit.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 5291 Dec 28 18:51 functions.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 499 Dec 28 18:51 index.php -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 887 Dec 28 18:51 README -rw-r--r--. 1 root root unconfined_u:object_r:usr_t:s0 700 Dec 28 18:51 setup.php compatibility: total 68 drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 84 Dec 6 2009 docs -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 30611 Dec 6 2009 functions.php drwxr-xr-x. 31 root root unconfined_u:object_r:user_home_t:s0 4096 Dec 6 2009 includes -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 466 Jan 2 2009 index.php drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 79 Nov 1 2009 locale -rwxr--r--. 1 root root unconfined_u:object_r:user_home_t:s0 5928 Nov 1 2009 make_release.sh drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 4096 Nov 1 2009 patches drwxr-xr-x. 2 root root unconfined_u:object_r:user_home_t:s0 4096 Nov 1 2009 patches.old -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 53 Nov 1 2009 README -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 2096 Dec 6 2009 setup.php -rw-r--r--. 1 root root unconfined_u:object_r:user_home_t:s0 21 Dec 6 2009 version I ASSUME I need to change everything /usr/share/squirrelmail to ''object_r:usr_t? If not, what SHOULD THEY be? Jay |
|
From: Jay H. <jh...@ke...> - 2025-12-30 17:14:07
|
> >> Checking outgoing mail service.... >> >> ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: >> (111) Connection refused >> >> NOTE: I obfuscated my internal ip network addresses above... >> >> I can't find anything wrong with my postfix config, telnet works just fine >> on port 25. >> >> I currently have selinux in 'permissive' mode as in 'Enforcing' mode I was >> not able to write to the attachment directory (maybe I have a >> bigger issue here). >> >> Could I need to adjust the firewall rules?? > > Take a look at them and make sure. > > Make sure you are telnetting from the same place SquirrelMail is running > and that the address is exactly the same. If that works, sudo telnet as > the same user apache is running as, since maybe apache user is prevented > from connecting on the network. > > -- > Paul Lesniewski > SquirrelMail Team > Please support Open Source Software by donating to SquirrelMail! > http://squirrelmail.org/donate_paul_lesniewski.php > Paul, I have adjusted by firewall rules. How does the following look to you? [root@kevla conf.d]# firewall-cmd --list-all --permanent public target: default icmp-block-inversion: no interfaces: sources: services: cockpit dhcpv6-client http https imap smtp ssh ports: 80/tcp 443/tcp protocols: forward: yes masquerade: no forward-ports: source-ports: icmp-blocks: rich rules: If I need to adjust something, please let me know what, and how to go about it... About this error: ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: I am configuring this box 'offline' and no direct connection to an outgoing relay (as of yet). Could that be part of my problem? IOW, is this an internal only issue or could it be related to no forwarding relay server? Jay |
|
From: Paul L. <pa...@sq...> - 2025-12-30 10:36:57
|
> Checking outgoing mail service.... > > ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: > (111) Connection refused > > NOTE: I obfuscated my internal ip network addresses above... > > I can't find anything wrong with my postfix config, telnet works just fine > on port 25. > > I currently have selinux in 'permissive' mode as in 'Enforcing' mode I was > not able to write to the attachment directory (maybe I have a > bigger issue here). > > Could I need to adjust the firewall rules?? Take a look at them and make sure. Make sure you are telnetting from the same place SquirrelMail is running and that the address is exactly the same. If that works, sudo telnet as the same user apache is running as, since maybe apache user is prevented from connecting on the network. -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php |
|
From: Jay H. <jh...@ke...> - 2025-12-30 01:40:41
|
Good Evening Paul,
I am setting up a new web/email server. Rocky Linux 9 using apache, postfix, dovecot, and rspamd.
Grabbed the latest Stable version snapshots (1.4.23-svn) yesterday.
I am trying to complete the squirrelmail install but right now I'm stuck here:
SquirrelMail configtest
This script will try to check some aspects of your SquirrelMail configuration and point you to errors whereever it can find them. You need
to go run conf.pl in the config/ directory first before you run this script.
SquirrelMail version: 1.4.23 [SVN]
Config file version: 1.4.0
Config file last modified: 30 December 2025 00:36:57
Checking PHP configuration...
PHP version 8.3.29 OK.
Running as N/A(N/A) / N/A(N/A)
display_errors:
error_reporting: 22527
variables_order OK: GPCS.
PHP extensions OK. Dynamic loading is disabled.
Checking paths...
Data dir OK.
Attachment dir OK.
Plugins are not correctly enabled in the configuration file.
Themes OK.
Default language OK.
Base URL detected as: https://10.20.30.11/webmail/src (location base autodetected)
Checking outgoing mail service....
ERROR: Error connecting to SMTP server "A.B.C.D:25".Server error: (111) Connection refused
NOTE: I obfuscated my internal ip network addresses above...
I can't find anything wrong with my postfix config, telnet works just fine on port 25.
I currently have selinux in 'permissive' mode as in 'Enforcing' mode I was not able to write to the attachment directory (maybe I have a
bigger issue here).
Could I need to adjust the firewall rules??
Any assistance very much appreciated.
Jay Hart
|
|
From: Paul L. <pa...@sq...> - 2025-11-10 20:28:53
|
Markus, > I am using Squirrelmail 1.4.23[SVN] with calendar plugin enabled. > > This works perfectly and so I have hundreds of entries there meanwhile. > But this also means, that it gets harder every day to find events, once > stored. > > In my understanding, one could try to include one more input field for a > search in the calendar.php page, then grep through the calendar events in > the 'data' directory, and in case of one or more matches, create a list of > links dynamically in the page to open day.php?... with the appropriate > parameters. > > Maybe I have just overlooked this and it can be installed somehow? > > If not, would this be a possible new feature? On paper, that sounds reasonable, though I'm not sure it's something that is likely to be added any time soon, as recent versions of the Advanced Calendar plugin have a search feature (though I don't remember if the file backend is up to date with that feature; it might only be for the SQL backend at this time) among a lot of other usability enhancements. Feel free to contact off list to get ahold of a recent copy of that plugin. -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php |
|
From: Markus R. K. <man...@di...> - 2025-11-09 18:54:12
|
Hi Paul, hi all! I am using Squirrelmail 1.4.23[SVN] with calendar plugin enabled. This works perfectly and so I have hundreds of entries there meanwhile. But this also means, that it gets harder every day to find events, once stored. In my understanding, one could try to include one more input field for a search in the calendar.php page, then grep through the calendar events in the 'data' directory, and in case of one or more matches, create a list of links dynamically in the page to open day.php?... with the appropriate parameters. Maybe I have just overlooked this and it can be installed somehow? If not, would this be a possible new feature? Thanks, best regards, Markus |
|
From: Tóth A. <at...@at...> - 2025-07-05 07:13:05
|
2025.Július 5.(Szo) 06:40 időpontban Harold Hallikainen via squirrelmail-users ezt írta: > Never mind! It looks like fail2ban already has something for this. I just > have to figure out how to configure it. It depends on the IMAP server and the type of authentication. In my case dovecot performs local authentication and it gets logged into auth.log via syslog-ng. You have to study your use case to figure it out where the failed login information goes. BR: Dw. > > Thanks! > > Harold > > On Fri, July 4, 2025 4:59 pm, Harold Hallikainen via squirrelmail-users > wrote: >> Is this possible? I get several hundered ssh login failures each day >> that >> I pass to fail2ban to block those IP addresses. It seems like there >> MIGHT >> similarly be SM login failures that would be nice to block. >> >> Harold >> >> >> >> >> >> -- >> Not sent from an iPhone. >> >> >> >> ----- >> squirrelmail-users mailing list Posting guidelines: >> http://squirrelmail.org/postingguidelines >> List address: squ...@li... >> List archives: http://news.gmane.org/gmane.mail.squirrelmail.user >> List info (subscribe/unsubscribe/change options): >> https://lists.sourceforge.net/lists/listinfo/squirrelmail-users >> >> > > > -- > Not sent from an iPhone. > > > ----- > squirrelmail-users mailing list > Posting guidelines: http://squirrelmail.org/postingguidelines > List address: squ...@li... > List archives: http://news.gmane.org/gmane.mail.squirrelmail.user > List info (subscribe/unsubscribe/change options): > https://lists.sourceforge.net/lists/listinfo/squirrelmail-users > |
|
From: Harold H. <ha...@ha...> - 2025-07-05 04:40:28
|
Never mind! It looks like fail2ban already has something for this. I just have to figure out how to configure it. Thanks! Harold On Fri, July 4, 2025 4:59 pm, Harold Hallikainen via squirrelmail-users wrote: > Is this possible? I get several hundered ssh login failures each day that > I pass to fail2ban to block those IP addresses. It seems like there > MIGHT > similarly be SM login failures that would be nice to block. > > Harold > > > > > > -- > Not sent from an iPhone. > > > > ----- > squirrelmail-users mailing list Posting guidelines: > http://squirrelmail.org/postingguidelines > List address: squ...@li... > List archives: http://news.gmane.org/gmane.mail.squirrelmail.user > List info (subscribe/unsubscribe/change options): > https://lists.sourceforge.net/lists/listinfo/squirrelmail-users > > -- Not sent from an iPhone. |