Jamie L. Penman-Smithson
2004-Jul-13 01:20 UTC
[Logcheck-devel] Bug#259094: logcheck-database: correction to cyrus rules
package: logcheck-database version: 1.2.23 severity: wishlist If you use policy-spf with postfix it generates alot of spurious log messages, all of which can safely be ignored. --- logcheck-postfix.orig 2004-07-09 04:03:11.000000000 +0100 +++ logcheck-postfix 2004-07-13 02:18:28.000000000 +0100 @@ -6,3 +6,5 @@ ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtpd\[[0-9]+\]: warning: smtpd_peer_init: [0-9]+\.[0-9]+\.[0-9]+\.[0-9]+: hostname [^[:space:]]+ verification failed: (Temporary failure in name resolution|Name or service not known|No address associated with hostname)$ ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtp\[[0-9]+\]: Peer verification: CommonName in certificate does not match: [._[:alnum:]-]+ != [._[:alnum:]-]+$ ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtp\[[0-9]+\]: [A-Z0-9]+: host [^[:space:]]+ said: [45][0-9][0-9] .* \(in reply to (HELO|EHLO|MAIL FROM|RCPT TO|end of DATA) command\)$ +^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/policy-spf\[[0-9]+\]: handler sender_permitted_from: DUNNO$ +^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/policy-spf\[[0-9]+\]: : SPF none: smtp_comment=SPF: domain of sender [^[:space:]]+ does not designate mailers, header_comment=[a-z\.]+: domain of [^[:space:]]+ does not designate permitted sender hosts$ -j -- -jamie <jamie at silverdream.org> | spamtrap: spam at silverdream.org w: http://www.silverdream.org | p: sms at silverdream.org pgp key @ http://silverdream.org/~jps/pub.key 01:30:01 up 13 days, 3:46, 13 users, load average: 0.20, 0.35, 0.40 -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: This is a digitally signed message part Url : http://lists.alioth.debian.org/pipermail/logcheck-devel/attachments/20040713/9e9e16b1/attachment.pgp
maks attems
2004-Jul-13 12:43 UTC
Bug#259094: [Logcheck-devel] Bug#259094: logcheck-database: correction to cyrus rules
tags 259094 moreinfo thanks On Tue, 13 Jul 2004, Jamie L. Penman-Smithson wrote:> package: logcheck-database > version: 1.2.23 > severity: wishlist > > If you use policy-spf with postfix it generates alot of spurious log > messages, all of which can safely be ignored. > > --- logcheck-postfix.orig 2004-07-09 04:03:11.000000000 +0100 > +++ logcheck-postfix 2004-07-13 02:18:28.000000000 +0100 > @@ -6,3 +6,5 @@ > ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtpd\[[0-9]+\]: warning: smtpd_peer_init: [0-9]+\.[0-9]+\.[0-9]+\.[0-9]+: hostname [^[:space:]]+ verification failed: (Temporary failure in name resolution|Name or service not known|No address associated with hostname)$ > ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtp\[[0-9]+\]: Peer verification: CommonName in certificate does not match: [._[:alnum:]-]+ != [._[:alnum:]-]+$ > ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtp\[[0-9]+\]: [A-Z0-9]+: host [^[:space:]]+ said: [45][0-9][0-9] .* \(in reply to (HELO|EHLO|MAIL FROM|RCPT TO|end of DATA) command\)$ > +^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/policy-spf\[[0-9]+\]: handler sender_permitted_from: DUNNO$ > +^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/policy-spf\[[0-9]+\]: : SPF none: smtp_comment=SPF: domain of sender [^[:space:]]+ does not designate mailers, header_comment=[a-z\.]+: domain of [^[:space:]]+ does not designate permitted sender hosts$hmm are these really need inside of violations.ignore.d/logcheck-postfix? shouldn't they go to ignore.d.server/postfix? could you post some offending messages and which layer they were shown from logcheck ("Security Events" or "System Events")? a++ maks -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: Digital signature Url : http://lists.alioth.debian.org/pipermail/logcheck-devel/attachments/20040713/82bdf59d/attachment.pgp
Debian Bug Tracking System
2004-Jul-15 07:33 UTC
Processed: Re: [Logcheck-devel] Bug#259094: logcheck-database: correction to cyrus rules
Processing commands for control at bugs.debian.org:> tags 259094 pendingBug#259094: logcheck-database: correction to cyrus rules There were no tags set. Tags added: pending> tags 259092 pendingBug#259092: logcheck-database: correction to cyrus rules There were no tags set. Tags added: pending> thanksStopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator, Debian Bugs database)
Debian Bug Tracking System
2004-Jul-24 02:18 UTC
[Logcheck-devel] Bug#259094: marked as done (logcheck-database: correction to cyrus rules)
Your message dated Fri, 23 Jul 2004 22:02:12 -0400 with message-id <E1BoBrY-0003x8-00 at newraff.debian.org> and subject line Bug#259094: fixed in logcheck 1.2.24 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Debian bug tracking system administrator (administrator, Debian Bugs database) -------------------------------------- Received: (at submit) by bugs.debian.org; 13 Jul 2004 01:20:40 +0000>From jamie at silverdream.org Mon Jul 12 18:20:40 2004Return-path: <jamie at silverdream.org> Received: from lorien.silverdream.org [62.3.218.19] by spohr.debian.org with esmtp (Exim 3.35 1 (Debian)) id 1BkByJ-0004iK-00; Mon, 12 Jul 2004 18:20:39 -0700 Received: from localhost (localhost [127.0.0.1]) by lorien.silverdream.org (Postfix) with ESMTP id 03FD54800088 for <submit at bugs.debian.org>; Tue, 13 Jul 2004 02:20:09 +0100 (BST) Received: from lorien.silverdream.org ([127.0.0.1]) by localhost (lorien.silverdream.org [127.0.0.1]) (amavisd-new, port 10024) with LMTP id 24540-06 for <submit at bugs.debian.org>; Tue, 13 Jul 2004 02:20:06 +0100 (BST) Received: from oasis.silverdream.hq (pegasus.pinklemon.net [62.3.218.17]) (using SSLv3 with cipher RC4-MD5 (128/128 bits)) (No client certificate requested) by lorien.silverdream.org (Postfix) with ESMTP id 0D5894800087 for <submit at bugs.debian.org>; Tue, 13 Jul 2004 02:20:06 +0100 (BST) Subject: logcheck-database: correction to cyrus rules From: "Jamie L. Penman-Smithson" <jamie at silverdream.org> Reply-To: jamie at silverdream.org To: submit at bugs.debian.org Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-OANRKfWLTOxwS7NV5uVL" Organization: PinkLemon Internet Services Message-Id: <1089681605.14096.668.camel at oasis.silverdream.hq> Mime-Version: 1.0 X-Mailer: Ximian Evolution 1.4.6 Date: Tue, 13 Jul 2004 02:20:05 +0100 X-Virus-Scanned: by amavisd-new-20030616-p10 (Debian) at silverdream.org Delivered-To: submit at bugs.debian.org X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE autolearn=no version=2.60-bugs.debian.org_2004_03_25 X-Spam-Level: --=-OANRKfWLTOxwS7NV5uVL Content-Type: text/plain Content-Transfer-Encoding: quoted-printable package: logcheck-database version: 1.2.23 severity: wishlist If you use policy-spf with postfix it generates alot of spurious log messages, all of which can safely be ignored. =20 --- logcheck-postfix.orig 2004-07-09 04:03:11.000000000 +0100 +++ logcheck-postfix 2004-07-13 02:18:28.000000000 +0100 @@ -6,3 +6,5 @@ ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtpd\[[0-9]+\]: warning: smtpd_peer_init: [0-9]+\.[0-9]+\.[0-9]+\.[0-9]+: hostname [^[:space:]]+ verification failed: (Temporary failure in name resolution|Name or service not known|No address associated with hostname)$ ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtp\[[0-9]+\]: Peer verification: CommonName in certificate does not match: [._[:alnum:]-]+ !=3D [._[:alnum:]-]+$ ^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/smtp\[[0-9]+\]: [A-Z0-9]+: host [^[:space:]]+ said: [45][0-9][0-9] .* \(in reply to (HELO|EHLO|MAIL FROM|RCPT TO|end of DATA) command\)$ +^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/policy-spf\[[0-9]+\]: handler sender_permitted_from: DUNNO$ +^\w{3} [ :0-9]{11} [._[:alnum:]-]+ postfix/policy-spf\[[0-9]+\]: : SPF none: smtp_comment=3DSPF: domain of sender [^[:space:]]+ does not designate mailers, header_comment=3D[a-z\.]+: domain of [^[:space:]]+ does not designate permitted sender hosts$ -j --=20 -jamie <jamie at silverdream.org> | spamtrap: spam at silverdream.org w: http://www.silverdream.org | p: sms at silverdream.org pgp key @ http://silverdream.org/~jps/pub.key 01:30:01 up 13 days, 3:46, 13 users, load average: 0.20, 0.35, 0.40 --=-OANRKfWLTOxwS7NV5uVL Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQBA8zjF0mxM1DK1CAsRArR0AJ4zTzxtUysdG5IfkBp9myr/CuziKgCgho33 H0T+eQj8N6CcBhO07puthG8=DZ+w -----END PGP SIGNATURE----- --=-OANRKfWLTOxwS7NV5uVL-- --------------------------------------- Received: (at 259094-close) by bugs.debian.org; 24 Jul 2004 02:08:08 +0000>From katie at ftp-master.debian.org Fri Jul 23 19:08:08 2004Return-path: <katie at ftp-master.debian.org> Received: from newraff.debian.org [208.185.25.31] (mail) by spohr.debian.org with esmtp (Exim 3.35 1 (Debian)) id 1BoBxH-0000fG-00; Fri, 23 Jul 2004 19:08:07 -0700 Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian)) id 1BoBrY-0003x8-00; Fri, 23 Jul 2004 22:02:12 -0400 From: Todd Troxell <ttroxell at debian.org> To: 259094-close at bugs.debian.org X-Katie: $Revision: 1.51 $ Subject: Bug#259094: fixed in logcheck 1.2.24 Message-Id: <E1BoBrY-0003x8-00 at newraff.debian.org> Sender: Archive Administrator <katie at ftp-master.debian.org> Date: Fri, 23 Jul 2004 22:02:12 -0400 Delivered-To: 259094-close at bugs.debian.org X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER autolearn=no version=2.60-bugs.debian.org_2004_03_25 X-Spam-Level: X-CrossAssassin-Score: 7 Source: logcheck Source-Version: 1.2.24 We believe that the bug you reported is fixed in the latest version of logcheck, which is due to be installed in the Debian FTP archive: logcheck-database_1.2.24_all.deb to pool/main/l/logcheck/logcheck-database_1.2.24_all.deb logcheck_1.2.24.dsc to pool/main/l/logcheck/logcheck_1.2.24.dsc logcheck_1.2.24.tar.gz to pool/main/l/logcheck/logcheck_1.2.24.tar.gz logcheck_1.2.24_all.deb to pool/main/l/logcheck/logcheck_1.2.24_all.deb logtail_1.2.24_all.deb to pool/main/l/logcheck/logtail_1.2.24_all.deb A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 259094 at bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Todd Troxell <ttroxell at debian.org> (supplier of updated logcheck package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster at debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Friday, 23 Jul 2004 21:39:19 -0500 Source: logcheck Binary: logcheck logtail logcheck-database Architecture: source all Version: 1.2.24 Distribution: unstable Urgency: low Maintainer: Debian logcheck Team <logcheck-devel at lists.alioth.debian.org> Changed-By: Todd Troxell <ttroxell at debian.org> Description: logcheck - Mails anomalies in the system logfiles to the administrator logcheck-database - A database of system log rules for the use of log checkers logtail - Print log file lines that have not been read Closes: 206495 213711 257874 258735 258759 259092 259094 259371 259466 260096 260102 260103 260105 260330 260382 260810 Changes: logcheck (1.2.24) unstable; urgency=low . eevans: * Added violations ignore rule for squid (Closes: #257874) maks * Added dhcpd-client, kernel, ntp, postfix rules. (Closes: #259094) * Added lots of postfix rules at level workstation for those, who wants to include /var/log/mail.log. (Closes: #206495) * Generalize "nobody" to "[_[:alnum:]-]+" for su rule. * Update rules ignore.d.paranoid/cron, ignore.d.paranoid/postfix. New courier rules merged and simplified from imap, impd-ssl and pop3d-ssl. thanks to Bastian Blank <waldi at debian.org>. (Closes: #258759) * Fix pid regex in cyrus rules. (Closes: #259092) * Added cyrus rules for notifyd. (Closes: #259466) * Make sure logtail gets a logfile to read, if not exit soon. Documented -o switch in logtail(8). (Closes: #259371) * Added logcheck-devel mail to logtail(8) and copyright. * Added userv rules. (Closes: #260105) * Generalize user match in spamd rule. (Closes: #260103) * Added a ippl rule at level workstation. (Closes: #260102) * Updated logcheck help message to all existent switches. Corrected logcheck command line parsing, -T needs no args. Use 6 'X' for mktemp(1) template. Better lock handling. (Closes: #260330) * Do not create unused /var/state/logcheck and really get rid of it. (Closes: #260096) * Added cs Translation. thanks Jan Outrata. (Closes: #260382) * Remove duplicate postfix rules, fix for remote string add lmtp rule. (Closes: #260810) todd: * Added 2 kernel rules for sparc workstations. * Added nearly 50 squid rules. (Closes: #213711) * Fix anacron Normal exit rule. * Move adduser from preinst to postinst (Closes: #258735) * Update pump and dhclient rules. Files: b12f7f6e9f7ee1c1ab93c11d06197436 670 admin optional logcheck_1.2.24.dsc fac761afff4056f62d05e0b0a49a8941 78439 admin optional logcheck_1.2.24.tar.gz b42736deefef2c9cbb27e596fe3453ca 38306 admin optional logcheck_1.2.24_all.deb 544fe294c31535dae713ca94746030c4 45540 admin optional logcheck-database_1.2.24_all.deb ab277c25932c9ef600581ebb1aa8f68c 22412 admin optional logtail_1.2.24_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBAb4/4u3oQ3FHP2YRAteqAKDC5u2SOudNtfjaZvMM1gFdFIE1AQCfXBAm nUk8s8a4rlxDrmTdK7SD5XI=XQO7 -----END PGP SIGNATURE-----