Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - rudiratlos63

#1
Thanks, that's the solution to my problem. I'm already forwarding the ACME HTTP-01 Challenge redirect to my Proxmox Mail Gateway (PMG), and it's working. I'm not sure if the TLS-ALPN-01 works for Caddy itself, since my internet provider doesn't offer IPv6. However, I'm having an issue with my PMG, which sends a spam report via email and provides a link to the same domain for marking spam emails as such. Here, access is routed through the reverse proxy to the PMG website itself, and a certificate for Caddy itself is required for this.
#2
I tried disabling the OpenSense Postfix proxy and generating a certificate via the HTTP-01 challenge using acme.sh on my Proxmox MailGateway (PMG). Caddy forwards the domain (e.g. mail.mydomain.com) to my PMG as a reverse proxy over the HTTP protocol. From the outside, a test web server on the PMG is accessible via HTTP without any issues. However, when I run acme.sh with the standalone option (acme.sh --issue -d mail.mydomain.com --standalone --httpport 80 --log), the certificate issuance fails. I've now run out of options for running Caddy on OpenSense. It would be really handy to use Caddy certificates for the OpenSense Postfix service.
#3
thats a real problem/pitty. therefor caddy is not useable if postfix needs a cert for tls transfer. caddy uses port 80 and if I want to use acme for this specifc domain only. during cert renewal acme ist spinning up port 80 for HTTP-01 challange (my registrar is not offering DNS-01). acme offers an hook after the cert renewal for spinning up caddy and not before for spinning down caddy.
it whould be a very good help if caddy could call a script/action routine after successfull renewal of a specfic cert. with that hook, some adjustments could be made e.g. remap/copy cert file for postfix service an reload/restart postfix.
#4
I've always had trouble using ACME to generate up-to-date certificates for my Postfix service.
The setup was just too complicated to reliably generate a simple certificate and keep
it up to date. Caddy does it better, faster, more reliably, and more easily.
So it would be nice if Postfix allowed you to specify the
two Caddy certificate paths as optional parameters.
#5
How can I use Server certificates generated by Caddy for the Postfix service?
Currently, I can only use certificates generated by ACME for the Postfix service.
All certificates are listed in the `system/trust` directory (ACME and caddy).

my current hack on opensense cli:
postconf -e 'smtpd_tls_cert_file=/var/db/caddy/data/caddy/certificates/acme-v02.api.letsencrypt.org-directory/mydomain.xxx.com/mydomain..xxx.com.crt'
postconf -e 'smtpd_tls_key_file=/var/db/caddy/data/caddy/certificates/acme-v02.api.letsencrypt.org-directory/mydomain.xxx.com/mydomain.xxx.com.key'
service postfix restart

check from other machine:
openssl s_client -connect mydomain.xxx.com:25 -starttls smtp | openssl x509 -noout -dates
#6
I had to disable antispam on my Postfix because rspamd accesses Redis on localhost (IPv4: 127.0.0.1) and ::1 (IPv6). ::1 responds extremely slowly when called multiple times in a row (redis-cli -h ::1 -p 6379 ping). This causes rspamd to time out, which in turn causes Postfix to enter a 300-second timeout. So far, I haven't found a way in the web GUI to configure Redis or rspamd to use only the IPv4 localhost address (127.0.0.1) to work around this problem. However, running `redis-cli -h 127.0.0.1 -p 6379 ping` does not experience any delay.
#7
musste antispam bei meiner postfix abschalten, da rspamd auf redis localhost ip4 (127.0.0.1) und ip6 ::1 zugreift. ::1 antwortet bei mehrfach hintereinander aufrufen ( redis-cli -h ::1 -p 6379 ping ) extrem langsam. das führt dazu, dass rspamd timeouts bekommt und somit postfix in einen 300sek timeout reinläuft. ich habe bisher keine möglichkeit in der webgui gefunden wie redis bzw. rspamd nur auf ip4 localhost 127.0.0.1 benutzt werden kann um das problem zu umgehen. redis-cli -h 127.0.0.1 -p 6379 ping unterliegen hingegen keiner zeitverzögerung.
#8
Hi,
das versuche ich ja erfolglos.
1. Wie kann ich den redirect machen?
#9
Ich denke ich habe es gefunden, unter NetworkTime/Status: de.pool.ntp.org .POOL. 16 sagt, dass die zeit mit diesem pool nicht gesynct werden konnte.
Ein zusätzlicher preferred Eintrag time.cloudflare.com und do not use de.pool.ntp.org bringt den Status mit einem  Active Peer und ein Stratum 3.
Danach war von der MAC OS cli: sntp <myOPNsenseIP> erfolgreich: +0.013941 +/- 0.026170 ....

was mich wundert: sntp de.pool.ntp.org +0.013529 +/- 0.024695 de.pool.ntp.org 85.220.190.246
von der MAC OS cli ist erfolgreich. Anscheinend kommuniziert time.cloudflare.com über einen anderen Port, abweichend von 123
#10
Hello,
in NetworkTime/General I have defined: prefer, de.pool.ntp.org
In Firewall/Rules/INT is defined: pass, INT, direction:in, ip4, UDP, Source: INTnet, Destination: INTaddr, port:123

test on mac os cli: sntp -S de.pool.ntp.org
result: +0.014647 +/- 0.023983 de.pool.ntp.org 162.159.200.123

test on mac os cli: sntp -S <myInternalOPNsenseIP>
result:   
sntp: Exchange failed: Server not synchronized
sntp_exchange {
        result: 9 (Server not synchronized)
        header: E4 (li:3 vn:4 mode:4)
       stratum: 00 (0)
          poll: 03 (8)
     precision: 00 (1.000000e+00)
         delay: 0000.0000 (0.000000000)
    dispersion: 0000.0000 (0.000000000)
           ref: 52415445 ("RATE")
         t_ref: 00000000.00000000 (0.000000000)
            t1: ED5669AC.E574D594 (3981863340.896313999)
            t2: ED5669AC.E574D594 (3981863340.896313999)
            t3: ED5669AC.E574D594 (3981863340.896313999)
            t4: ED5669AC.E5F7B5AE (3981863340.898310999)
        offset: FFFFFFFFFFFFFFFF.FFBE8FF300000000 (-0.000998500)
         delay: 0000000000000000.0082E01A00000000 (0.001997000)
          mean: 00000000ED5669AC.E574D59400000000 (3981863340.896314144)
         error: 0000000000000000.0000000000000000 (0.000000000)
          addr: 10.8.81.1
}
sntp: Exchange failed: Timeout
sntp_exchange {
        result: 6 (Timeout)
        header: 00 (li:0 vn:0 mode:0)
       stratum: 00 (0)
          poll: 00 (1)
     precision: 00 (1.000000e+00)
         delay: 0000.0000 (0.000000000)
    dispersion: 0000.0000 (0.000000000)
           ref: 00000000 ("    ")
         t_ref: 00000000.00000000 (0.000000000)
            t1: ED5669AC.E60A84BE (3981863340.898597999)
            t2: 00000000.00000000 (0.000000000)
            t3: 00000000.00000000 (0.000000000)
            t4: 00000000.00000000 (0.000000000)
        offset: FFFFFFFF8954CB29.8CFABDA100000000 (-1990931670.449299097)
         delay: FFFFFFFF12A99653.19F57B4200000000 (-3981863340.898598194)
          mean: 0000000000000000.0000000000000000 (0.000000000)
         error: 0000000000000000.0000000000000000 (0.000000000)
          addr: 10.8.81.1
}
sntp: Exchange failed: Timeout
sntp_exchange {
        result: 6 (Timeout)
        header: 00 (li:0 vn:0 mode:0)
       stratum: 00 (0)
          poll: 00 (1)
     precision: 00 (1.000000e+00)
         delay: 0000.0000 (0.000000000)
    dispersion: 0000.0000 (0.000000000)
           ref: 00000000 ("    ")
         t_ref: 00000000.00000000 (0.000000000)
            t1: ED5669AD.E77D1FE6 (3981863341.904252999)
            t2: 00000000.00000000 (0.000000000)
            t3: 00000000.00000000 (0.000000000)
            t4: 00000000.00000000 (0.000000000)
        offset: FFFFFFFF8954CB29.0C41700D00000000 (-1990931670.952126503)
         delay: FFFFFFFF12A99652.1882E01A00000000 (-3981863341.904253006)
          mean: 0000000000000000.0000000000000000 (0.000000000)
         error: 0000000000000000.0000000000000000 (0.000000000)
          addr: 10.8.81.1
}
sntp: Exchange failed: Timeout
sntp_exchange {
        result: 6 (Timeout)
        header: 00 (li:0 vn:0 mode:0)
       stratum: 00 (0)
          poll: 00 (1)
     precision: 00 (1.000000e+00)
         delay: 0000.0000 (0.000000000)
    dispersion: 0000.0000 (0.000000000)
           ref: 00000000 ("    ")
         t_ref: 00000000.00000000 (0.000000000)
            t1: ED5669AE.E8ED1BF7 (3981863342.909867999)
            t2: 00000000.00000000 (0.000000000)
            t3: 00000000.00000000 (0.000000000)
            t4: 00000000.00000000 (0.000000000)
        offset: FFFFFFFF8954CB28.8B89720480000000 (-1990931671.454933882)
         delay: FFFFFFFF12A99651.1712E40900000000 (-3981863342.909867764)
          mean: 0000000000000000.0000000000000000 (0.000000000)
         error: 0000000000000000.0000000000000000 (0.000000000)
          addr: 10.8.81.1
}
+0.015877 +/- 0.032075 10.8.81.1 10.8.81.1
#11
High availability / Master not taking over CARP IP
February 08, 2026, 04:41:09 PM
My HA is working, but the Master will not be promoted to Master after a reboot.
My CARP IPs have the folowing VirtualIP CARP settings:
Backup Server: Advbase set to 1 and Advskew set to 100, Disable preempt: off
Master Server: Advbase set to 1 and Advskew set to 0,   Disable preempt: on
#12
High availability / Re: CARP and Unbound DNS response
February 07, 2026, 06:00:17 PM
thank you for your patience. Now it works.
#13
High availability / Re: CARP and Unbound DNS response
February 06, 2026, 06:46:09 PM
I#ve got the following error:

There were error(s) loading the rules: /tmp/rules.debug:187: no translation address with matching address family found. - The line in question reads [187]: rdr on vtnet1 inet6 proto {tcp udp} from {(vtnet1:network)} to $CARP_DMZ_IP port {53} -> 127.0.0.1 port 53 # CARP DNS forwarding
#14
High availability / Re: CARP and Unbound DNS response
February 05, 2026, 07:01:03 PM
Where should I do this?
I have Adguard running on DNS Port 53. Unbound runs on Port 5354
#15
High availability / Re: CARP and Unbound DNS response
February 05, 2026, 03:55:05 PM
Hello Patrick,
this is not working. same result. pls. see attached screenshots. I've defined the nat rule you suggested.