2015年11月4日水曜日

unbound について

4)  unbound
/etc/resolv.conf を nameserver 127.0.0.1 にして /etc/rc.d/unbound -f restart だけで動きます。
http://gihyo.jp/admin/feature/01/unbound/0001  によると以下です。
Unbound は本来はキャシュサーバーなのですが、簡易的なコンテンツサーバとしての機能を持ち,LAN内 のホストの名前の解決などに利用できます。 
なおDNSコ ンテンツサーバは権威サーバとも呼ばれ,自身が権威を持っているゾーンに対する問い合わせのみに回答します。
参考: http://murasaki.cocolog-nifty.com/cloud/2009/07/unbound-1f2d.html




全体の状況は

internet
|
|
|
run0:dhcp
<openbsd(mail+dhcpd server)>
bge0:192.168.11.1
|
|
|
fxp0:dhcp
<PC>

PC send and revieve mail by sylpheed .



サーバーの /etc/dhcpd.intefaces                                       
bge0


サーバーの /etc/dhcpd.conf                                            
option  domain-name-servers 192.168.11.1;
subnet 192.168.11.0 netmask 255.255.255.0 {
        option routers 192.168.11.1;
        range 192.168.11.50 192.168.11.57;
}


サーバーの /etc/resolv.conf                                           
nameserver 127.0.0.1

############# 

以下は不安定ですが 一応ローカルLANでメールの送受信ができます。


/var/unbound/etc/unbound.conf                                        <
-----------------
server:
        interface: 127.0.0.1
        interface: ::1
        access-control: 0.0.0.0/0 refuse
        access-control: 127.0.0.0/8 allow
        access-control: ::0/0 refuse
        access-control: ::1 allow
        hide-identity: yes
        hide-version: yes
###############################--->join name & adress
        interface: 192.168.11.1
        access-control: 192.168.11.0/24 allow
        local-zone: "home." static
        local-data: "server.home.  IN A 192.168.11.1"
        local-data: "kerai.home. IN A 192.168.11.50"
        local-data-ptr: "192.168.11.1   server.home."
        local-data-ptr: "192.168.11.50   kerai.home."
###############################--->to build mail server
 local-data: "home. IN MX 10 server.home."
 local-data-ptr: "192.168.11.1   server.home."



#  /etc/hosts                                                 
-------------------------
127.0.0.1       localhost
::1             localhost
192.168.100.101 aoiyuma.mydns.jp
192.168.11.1    server.home


 
# /etc/myname                                                
-------------------------
aoiyuma.mydns.jp



# /etc/postfix/main.cf                                       
------------------------------------------
myhostname = server.home
mydomain = home
myorigin = $mydomain
inet_interfaces = all
mydestination = $myhostname localhost.$mydomain
home_mailbox = Maildir/
mynetworks = 192.168.11.0/24, 127.0.0.0/8
queue_directory = /var/spool/postfix
command_directory = /usr/local/sbin
daemon_directory = /usr/local/libexec/postfix
data_directory = /var/postfix
mail_owner = _postfix
inet_protocols = all
unknown_local_recipient_reject_code = 550
debug_peer_level = 2
debugger_command =
         PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin
         ddd $daemon_directory/$process_name $process_id & sleep 5
sendmail_path = /usr/local/sbin/sendmail
newaliases_path = /usr/local/sbin/newaliases
mailq_path = /usr/local/sbin/mailq
setgid_group = _postdrop
html_directory = /usr/local/share/doc/postfix/html
manpage_directory = /usr/local/man
sample_directory = /etc/postfix
readme_directory = /usr/local/share/doc/postfix/readme
meta_directory = /etc/postfix
shlib_directory = no





/etc/postfix/master.cf                                        
--------------------------------------
smtp      inet  n       -       -       -       -       smtpd
pickup    unix  n       -       -       60      1       pickup
cleanup   unix  n       -       -       -       0       cleanup
qmgr      unix  n       -       -       300     1       qmgr
tlsmgr    unix  -       -       -       1000?   1       tlsmgr
rewrite   unix  -       -       -       -       -       trivial-rewrite
bounce    unix  -       -       -       -       0       bounce
defer     unix  -       -       -       -       0       bounce
trace     unix  -       -       -       -       0       bounce
verify    unix  -       -       -       -       1       verify
flush     unix  n       -       -       1000?   0       flush
proxymap  unix  -       -       n       -       -       proxymap
proxywrite unix -       -       n       -       1       proxymap
smtp      unix  -       -       -       -       -       smtp
relay     unix  -       -       -       -       -       smtp
showq     unix  n       -       -       -       -       showq
error     unix  -       -       -       -       -       error
retry     unix  -       -       -       -       -       error
discard   unix  -       -       -       -       -       discard
local     unix  -       n       n       -       -       local
virtual   unix  -       n       n       -       -       virtual
lmtp      unix  -       -       -       -       -       lmtp
anvil     unix  -       -       -       -       1       anvil
scache    unix  -       -       -       -       1       scache



/etc/dovecot/dovecot.conf                                        <
protocols = imap
listen = *
!include conf.d/*.conf




/etc/dovecot/conf.d/10-mail.conf  
   mail_location = maildir:~/Maildir
namespace inbox {
  inbox = yes
}
mmap_disable = yes
first_valid_uid = 1000
mail_plugin_dir = /usr/local/lib/dovecot
mbox_write_locks = fcntl





/etc/dovecot/conf.d/10-master.conf                                        
<
service imap-login {
  inet_listener imap {
  }
  inet_listener imaps {
  }
}
service pop3-login {
  inet_listener pop3 {
  }
  inet_listener pop3s {
  }
}
service lmtp {
  unix_listener lmtp {
  }
}
service imap {
}
service pop3 {
}
service auth {
  unix_listener auth-userdb {
  }
}
service auth-worker {
}
service dict {
  unix_listener dict {
  }
}





 /etc/dovecot/conf.d/10-auth.conf 
auth_mechanisms = plain login
!include auth-system.conf.ext
disable_plaintext_auth = no





/etc/dovecot/conf.d/10-ssl.conf                                        <
ssl = yes
ssl_cert = </etc/ssl/dovecotcert.pem
ssl_key = </etc/ssl/private/dovecot.pem






あとは sylpheed で
メールアドレス t@server.home
imap
送受信さーばー ともに server.home
高度な設定でポートを25と143
にするだけです。

intranet で unbound と opensmtpd で mail server をつくる

2) 
intranet で unbound + opensmtpd で作る 
               mail server

    本来の権威ネームサーバ NSD管理の代わりに、 キャシュサーバとして生まれたunboubを 簡易的に権威サーバーとして代用します 
                                     (http://gihyo.jp/admin /feature/01/unbound /0001)



 
全体の状況は

internet
|
|
wifi router
dhcpd|
|
run0:dhcpcd
<openbsd(opensmtpf + dovecot + dhcpd server)>
bge0:192.168.11.1
|
|
fxp0:dhcp
<LINUX thunderbird>



1) setting of openbsd server

a) about dhcpd
/etc/dhcpd.intefaces                                       
bge0


/etc/dhcpd.conf                                            
option  domain-name-servers 192.168.11.1;
subnet 192.168.11.0 netmask 255.255.255.0 {
        option routers 192.168.11.1;
        range 192.168.11.50 192.168.11.57;
}



b) 
/etc/hosts                                                 
-------------------------
127.0.0.1       localhost
::1             localhost
192.168.100.101 aoiyuma.mydns.jp
192.168.11.1    server.home

/etc/myname                                                
-------------------------
aoiyuma.mydns.jp


c)dovecot -n
--------------------------
# 2.2.15: /etc/dovecot/dovecot.conf
# OS: OpenBSD 5.7 i386  
auth_mechanisms = plain login
disable_plaintext_auth = no
first_valid_uid = 1000
imap_client_workarounds = delay-newmail tb-extra-mailbox-sep tb-lsub-flags
listen = *
mail_location = maildir:~/Maildir
mbox_write_locks = fcntl
mmap_disable = yes
namespace inbox {
  inbox = yes
  location = 
  mailbox Drafts {
    special_use = \Drafts
  }
  mailbox Junk {
    special_use = \Junk
  }
  mailbox Sent {
    special_use = \Sent
  }
  mailbox "Sent Messages" {
    special_use = \Sent
  }
  mailbox Trash {
    special_use = \Trash
  }
  prefix = 
}
passdb {
  driver = bsdauth
}
pop3_client_workarounds = outlook-no-nuls oe-ns-eoh
protocols = imap
ssl_cert = </etc/ssl/dovecotcert.pem
ssl_key = </etc/ssl/private/dovecot.pem
userdb {
  driver = passwd


 /etc/dovecot/dovecot.conf                                        <
------------------------
protocols = imap
listen = *
!include conf.d/*.conf


/etc/dovecot/conf.d/10-mail.conf  
-------------------------
   mail_location = maildir:~/Maildir
namespace inbox {
  inbox = yes
}
mmap_disable = yes
first_valid_uid = 1000
mail_plugin_dir = /usr/local/lib/dovecot
mbox_write_locks = fcntl


/etc/dovecot/conf.d/10-master.conf                                        
----------------------------------
service imap-login {
  inet_listener imap {
  }
  inet_listener imaps {
  }
}
service pop3-login {
  inet_listener pop3 {
  }
  inet_listener pop3s {
  }
}
service lmtp {
  unix_listener lmtp {
  }
}
service imap {
}
service pop3 {
}
service auth {
  unix_listener auth-userdb {
  }
}
service auth-worker {
}
service dict {
  unix_listener dict {
  }
}



/etc/dovecot/conf.d/10-auth.conf 
--------------------------------
auth_mechanisms = plain login
!include auth-system.conf.ext
disable_plaintext_auth = no


/etc/dovecot/conf.d/10-ssl.conf                                        <
--------------------------------
ssl = yes
ssl_cert = </etc/ssl/dovecotcert.pem
ssl_key = </etc/ssl/private/dovecot.pem




d)
first openbsd server runs dhcpcd under wifi-router(dhcpd)
so

/etc/hostname.run0                                                                                   
------------------
nwid URoad-662EA0
wpakey 04607271
dhcp

but when i start openbsd as serve , i run the next script .
 mail-server.bat
------------------------------------------------                                                                       
cp /etc/resolv.conf-127    /etc/resolv.conf
cp /etc/hostname.run0-fix  /etc/hostname.run0

/etc/rc.d/unbound restart

/etc/rc.d/smtpd   restart
/etc/rc.d/dovecot  restart


/etc/resolv.conf-127
----------------------------
nameserver 127.0.0.1



/etc/hostname.run0-fix                                                                               
-----------------------
inet 192.168.100.101 255.255.255.0


e)UNBOUND

/var/unbound/etc/unbound.conf
-------------------------------                                      
server:
        interface: 127.0.0.1
        interface: ::1
        access-control: 0.0.0.0/0 refuse
        access-control: 127.0.0.0/8 allow
        access-control: ::0/0 refuse
        access-control: ::1 allow
        hide-identity: yes
        hide-version: yes

        interface: 192.168.11.1
        access-control: 192.168.11.0/24 allow
        local-zone: "home." static
        local-data: "server.home.  IN A 192.168.11.1"
        local-data: "kerai.home. IN A 192.168.11.50"
        local-data-ptr: "192.168.11.1   server.home."
        local-data-ptr: "192.168.11.50   kerai.home."
        local-data: "home. IN MX 10 server.home."
        local-data-ptr: "192.168.11.1   server.home."
/




2) linux thunderbird
smtp
server name : server.home
port 25
authentification method: password, transmitted insecure
conection security     : none


imap
server name : server.home
port 143

authentification method: normal password
conection security     : STARTTLS



X) in this setting

i send mail to X@
server.home and recieve mail from X@server.home .

but
i cannot send mail from   Y@gmx.com      to   
X@server.home
and
i cannot send mail from   X@server.home  to    Y@gmx.com .

this is safe setting considering of virus from internet .
when i want to send or recieve mail with Z@gmail.com , i use Y@gmx.com .

さらに
/etc /pf.confを 以下のようにすると 

ext_if="run0"
int_if="bge0"
tcp_services="{ 22, 80 }"
icmp_types="echoreq"
set block-policy return
set loginterface $ext_if
set skip on lo
match out on $ext_if inet from ($int_if:network) to any nat-to ($ext_if:0)
set reassemble yes no-df
block in log
pass out quick
antispoof quick for { lo $int_if }
pass in  on  $ext_if   inet proto tcp from any to  ( $ext_if:0 ) port  $tcp_services
pass in inet proto icmp all icmp-type $icmp_types
pass in on $int_if
外からのメールはgmx.comを利用しても入ってこなくなります。
ただ
 gmx.comを利用して @internet.com に秘密をおくれます。

もちろん
ext_if="run0"
int_if="bge0"
tcp_services="{ 22, 80 }"
icmp_types="echoreq"
set block-policy return
set loginterface $ext_if
set skip on lo

###  match out on $ext_if inet from ($int_if:network) to any nat-to ($ext_if:0)
set reassemble yes no-df
block in log
pass out quick
antispoof quick for { lo $int_if }
pass in  on  $ext_if   inet proto tcp from any to  ( $ext_if:0 ) port  $tcp_services
pass in inet proto icmp all icmp-type $icmp_types
pass in on $int_if

とすれば intraネット内からメールも遅れなくなりますが、wwwも見れなくなります。
でも web mailの存在を考えると ここまでしなくてはいけないかもしれません。






opensmtpd と  dovecot  で mail server をつくる

1)レンタルサーバーで無料の mydns.jpを利用し opensmtpd +   dovecot  で mail server




  1)全体の状況は以下です。

openbsd:mailserverは いわゆるレンタルサーバーで す。                 mailserver is build on called rental server .
ここにメールサーバーを立ち上げて 
linux : thunderbird から使います。i use this server on linux's thunderbird .

linux : thunderbird
1.2.3.4
|
|
|
internet-----em0:openbsd:mailserver( opensmtpd + dovecot)




2)MXを設定するために                                                              i set mx by the following procedure

mydns



きちんと設定できれば以下となります
host aoiyuma.mydns.jp
then
aoiyuma.mydns.jp has address 157.7.208.141
aoiyuma.mydns.jp mail is handled by 10 mail.aoiyuma.mydns.jp.



3)dovecot -n の 結果は、
# 2.2.15: /etc/dovecot/dovecot.conf
# OS: OpenBSD 5.7 amd64 
auth_mechanisms = plain login
disable_plaintext_auth = no
first_valid_uid = 1000
imap_client_workarounds = delay-newmail tb-extra-mailbox-sep tb-lsub-flags
listen = *
mail_location = maildir:~/Maildir
mbox_write_locks = fcntl
mmap_disable = yes
namespace inbox {
  inbox = yes
  location =
  mailbox Drafts {
    special_use = \Drafts
  }
  mailbox Junk {
    special_use = \Junk
  }
  mailbox Sent {
    special_use = \Sent
  }
  mailbox "Sent Messages" {
    special_use = \Sent
  }
  mailbox Trash {
    special_use = \Trash
  }
  prefix =
}
passdb {
  driver = bsdauth
}
pop3_client_workarounds = outlook-no-nuls oe-ns-eoh
protocols = imap
ssl_cert = </etc/ssl/dovecotcert.pem
ssl_key = </etc/ssl/private/dovecot.pem
userdb {
  driver = passwd
}

こうなるためには


/etc/dovecot/dovecot.conf          
protocols = imap imaps
listen = *
!include conf.d/*.conf





/etc/dovecot/conf.d/10-master.conf 
service imap-login {
  inet_listener imap {
  }
  inet_listener imaps {
    port = 993
    ssl = yes
  }
}
service pop3-login {
  inet_listener pop3 {
  }
  inet_listener pop3s {
  }
}
service lmtp {
  unix_listener lmtp {
  }
}
service imap {
}
service pop3 {
}
service auth {
  unix_listener auth-userdb {
  }
}
service auth-worker {
}
service dict {
  unix_listener dict {
  }
}




/etc/dovecot/conf.d/10-mail.conf                                        <
   mail_location = maildir:~/Maildir
namespace inbox {
  inbox = yes
}
mmap_disable = yes
first_valid_uid = 1000
mail_plugin_dir = /usr/local/lib/dovecot
mbox_write_locks = fcntl



 /etc/dovecot/conf.d/10-ssl.conf                                        <
ssl = yes
ssl_cert = </etc/ssl/dovecotcert.pem
ssl_key = </etc/ssl/private/dovecot.pem


4) /etc/login.conf                                                                              
auth-defaults:auth=passwd,skey:
auth-ftp-defaults:auth-ftp=passwd:
default:\
        :path=/usr/bin /bin /usr/sbin /sbin /usr/X11R6/bin /usr/local/bin /usr/local/sbin:\
        :umask=022:\
        :datasize-max=512M:\
        :datasize-cur=512M:\
        :maxproc-max=256:\
        :maxproc-cur=128:\
        :openfiles-cur=512:\
        :stacksize-cur=4M:\
        :localcipher=blowfish,8:\
        :ypcipher=old:\
        :tc=auth-defaults:\
        :tc=auth-ftp-defaults:
daemon:\
        :ignorenologin:\
        :datasize=infinity:\
        :maxproc=infinity:\
        :openfiles-cur=128:\
        :stacksize-cur=8M:\
        :localcipher=blowfish,9:\
        :tc=default:
staff:\
        :datasize-cur=1536M:\
        :datasize-max=infinity:\
        :maxproc-max=512:\
        :maxproc-cur=256:\
        :ignorenologin:\
        :requirehome@:\
        :tc=default:
authpf:\
        :welcome=/etc/motd.authpf:\
        :shell=/usr/sbin/authpf:\
        :tc=default:
bgpd:\
        :openfiles-cur=512:\
        :tc=daemon:
unbound:\
        :openfiles-cur=512:\
        :tc=daemon:
dovecot:\
        :openfiles-cur=2048:\
        :openfiles-max=4096:\
        :tc=daemon:



http://cvsweb.openbsd.org/cgi-bin/cvsweb/~checkout~/ports/mail/dovecot/pkg/README-server?rev=1.2
では
dovecot:\
    :openfiles-cur=512:\
    :openfiles-max=2048:\
    :tc=daemon:

5)/etc/pf.conf                                                                    
ext_if="em0"
tcp_services="{ 22, 25, 80, 110, 143, 465, 587 }"
icmp_types="echoreq"
set block-policy return
set loginterface $ext_if
set skip on lo
set reassemble yes no-df
block in log
pass out quick
antispoof quick for { lo }
pass in  on  $ext_if   inet proto tcp from any to  ( $ext_if:0 ) port  $tcp_services
pass in inet proto icmp all icmp-type $icmp_types
pass in on $ext_if proto tcp to port 21
pass in on $ext_if proto tcp to port > 4915




6)/etc/mail/smtpd.conf
 send mail to anything but your local domains.

鎖国?
A@openbsd.link と B@openbsd.link の間の送受信は可能。
しかし X@gmail.comとの送受信は不可能。

だから 安全 
開 国

X@gmail.comとの送受信は可能
でも ウィルスメールがはいってもこれます。
listen on lo0
listen on em0 port 587

table aliases db:/etc/mail/aliases.db

accept  from any for domain "aoiyuma.mydns.jp" alias <aliases> deliver to maildir
accept from any for domain "aoiyuma.mydns.jp"        deliver to maildir

accept for local alias <aliases> deliver to maildir
accept for local deliver to maildir

reject from any for any



gmailは sendingに465を使っている。
587にしたのでgmailからのが受信できないとも考えられる。
じゃあ 465にしたらどうかというと 
こうしてもgmailからのは受信できないし、
更に悪いことにはaoiyuma.mydns.jpか らのも受信できなくなってしまった。

で  587にした。
ただし
送信に587を使うメールサーバーから実際に受信できないかは未確認
なので、心配は残るが、 gmail 465のことを考えると大丈夫かな?


listen on lo0
listen on em0 port 25 
listen on em0 port 465
listen on em0 port 587

table aliases db:/etc/mail/aliases.db

accept      from any           for domain "aoiyuma.mydns.jp"      alias <aliases>      deliver to maildir

accept from any   for domain "aoiyuma.mydns.jp"   deliver to maildir

accept for local           alias <aliases>   deliver to maildir
accept for local                              deliver to maildir


mynetwork1 = "14.22.25.247/32"
mynetwork2 = "6.2.6.2/32"
accept from source $mynetwork1 for any relay
accept from source $mynetwork2 for any relay
accept from local for any relay
d

# nano /etc/mail/aliases
# makemap /etc/mail/aliases
  は newaliasesに相当。

 STARTTLS にする。
openssl genrsa -out /etc/ssl/private/mail.aoiyuma.mydns.jp.key 4096
openssl req -new -x509 -key /etc/ssl/private/mail.aoiyuma.mydns.jp.key -out /etc/ssl/mail.aoiyuma.mydns.jp.crt -days 365
chmod 600 /etc/ssl/mail.aoiyuma.mydns.jp.crt
chmod 600 /etc/ssl/private/mail.aoiyuma.mydns.jp.key


cat jp3
6.2.6.2/32 114.22.25.247/32

makemap jp3

from http://technoquarter.blogspot.jp/2015/02/openbsd-mail-server-part-2-opensmtpd.html

so it listens
on egress with tls (for incoming mail) and
egress port 587 (submission) with tls and authentication (for outgoing mail),
accepts mail for virtual users and virtual domains, and delivers this mail to Maildir.


smtpd.conf
は以下です

pki mail.aoiyuma.mydns.jp certificate "/etc/ssl/mail.aoiyuma.mydns.jp.crt"
pki mail.aoiyuma.mydns.jp key "/etc/ssl/private/mail.aoiyuma.mydns.jp.key"

listen on em0                 tls          pki   mail.aoiyuma.mydns.jp   auth-optional
listen on em0 port submission tls-require pki   mail.aoiyuma.mydns.jp   auth

table aliases db:/etc/mail/aliases.db
table jp3 db:/etc/mail/jp3.db

accept from any         for domain "aoiyuma.mydns.jp"   alias <aliases> deliver to maildir
accept from any         for domain "aoiyuma.mydns.jp"                   deliver to maildir

accept for local                                        alias <aliases> deliver to maildir
accept for local                                                        deliver to maildir

accept from source <jp3>        for any relay
accept from local               for any relay


あと /home/fogeがあったとしたら それのshellがたとえfalse でも
mkdir -p /home/foge/Mairdir/{new,cur,tmp}
chown -R foge.foge /home/foge/Mairdir/
chmod -R 400 /home/foge/Mairdir/
して fogeがメールを利用できないようにした。
https://ipv4.fetus.jp/
tr '\n' ' ' <jp.tx

STARTTLS + spamd です,しかし不安定。
mail+nginx-server.bat-openSMTPD-spam   を実行するだけです。                                                                 
pfctl -f /etc/mail/black.pf
pfctl -sr
/etc/rc.d/smtpd         restart
/etc/rc.d/dovecot       restart
echo '----------------'
echo '----------------'
echo '----------------'
echo '----------------'
/etc/rc.d/spamd         -f restart                                                                                                           
ps ax| grep spam
/etc/rc.d/spamlogd      -f restart
ps ax| grep spam
/usr/libexec/spamd-setup


ここは http://technoquarter.blogspot.jp にすっかりお世話になりました。
また opensmtpのmailing listからもたくさんの助言をいただきました。


Incoming mail:
pf -> relay to spamd -> send to opensmtpd on lo0 -> deliver to maildir

Outoing mail:
opensmtpd on lo0 -> relay out
とあるので

openssl genrsa -out /etc/ssl/private/mail.aoiyuma.mydns.jp.key 4096
openssl req -new -x509 -key /etc/ssl/private/mail.aoiyuma.mydns.jp.key -out /etc/ssl/mail.aoiyuma.mydns.jp.crt -days 365
chmod 600 /etc/ssl/mail.aoiyuma.mydns.jp.crt
chmod 600 /etc/ssl/private/mail.aoiyuma.mydns.jp.key
してから
                                                         
smtpd.conf  
pki mail.aoiyuma.mydns.jp certificate "/etc/ssl/mail.aoiyuma.mydns.jp.crt"
pki mail.aoiyuma.mydns.jp key "/etc/ssl/private/mail.aoiyuma.mydns.jp.key"
listen on lo0
listen on em0                 tls         pki   mail.aoiyuma.mydns.jp   auth-optional
listen on em0 port submission tls-require pki   mail.aoiyuma.mydns.jp   auth
table aliases db:/etc/mail/aliases.db
accept from any         for domain "aoiyuma.mydns.jp"                   deliver to maildir
accept for local                                        alias <aliases> deliver to maildir
accept from local



 /etc/mail/black.pf 
ext_if="em0"
tcp_services="{  22,     80,      143 }"
icmp_types="echoreq"
set block-policy return
set loginterface $ext_if
set skip on lo
set reassemble yes no-df
block in log
pass out quick
antispoof quick for { lo }
pass in on $ext_if proto tcp to any port submission
table <spamd-white> persist
table <nospamd> persist file "/etc/mail/nospamd"
pass in         on $ext_if proto tcp from any to any port smtp rdr-to 127.0.0.1 port spamd
pass in on $ext_if proto tcp from <nospamd> to any port  smtp
pass in log     on $ext_if proto tcp from any to any port smtp
pass out log on $ext_if proto tcp to any port smtp
pass in  on  $ext_if   inet proto tcp from any to  ( $ext_if:0 ) port  $tcp_services
pass in inet proto icmp all icmp-type $icmp_types
pass in on $ext_if proto tcp to port 21
pass in on $ext_if proto tcp to port > 4915




/etc/rc.conf.local                                                                                      
ftpd_flags="-llUSA"
smtpd_flags=""
pf=YES                  # Packet filter / NAT
pf_rules=/etc/pf.conf           # Packet filter rules file



cat /etc/mail/nospamd                                                                                                     
157.7.208.141   #自分自身




一応
Return to RBL.JP home page は以下のように合格。

Relay test 19

>>> RSET
relay NOT accepted!!
Closing connection ...

>>> QUIT

Relay test result

All tests performed, no relays accepted.

http://www.noroi.jp/?date=20070415
で は
spamd の運用では、pf <spamd> と pf <spamd-white> を維持する必要がある。
前者は spamd-setup を定期的に実行して、 最近のブラックリストをネットから持ってくる。
後者は spamd 自身が /var/db/spamdb の WHITE データで定期的に置き替える。
 netstat -na -f inet
/usr/libexec/spamd-setup


# ls -l /var/db/spamd
-rw-r--r--  1 _spamd  _spamd  65536 Aug  1 15:03 /var/db/spamd




7) thunderbird setting of google mail
arch linux's thunderbird automatically detect them (openbsd's one cannot).

smtp.googlemail.com
465
auth              : Oauht2
conectio security : SSK/TLS
imap.googlemail.com
993
auth              : Oauht2
conectio security : SSK/TLS


smtp mail.aoiyuma.mydns.jp 587
auth              : normal password
conectio security : STARTTLS          
imap mail.aoiyuma.mydns.jp 143
auth              : normal password
conectio security : STARTTLS
abobe is the same setting of gmx.com



付録1)開国していて カフェにはいったと きの対処方法

カフェで
shllscript
curl ifconfig.me > ifconfigme.txt
scp  ifconfigme.txt tu@aoiyuma.mydns.jp:/home/tu






aoiyuma.mydns.jp にsshで入って
shllscript
y=`cat ./ifconfigme.txt`
cp /etc/mail/smtpd.conf /etc/mail/smtpd.conf-back
sed "s/xxx/$y\/32/g" kt  > /etc/mail/smtpd.conf
/etc/rc.d/smtpd restart




ただし ktは以下です

listen on lo0
listen on em0 port 25 
listen on em0 port 465
listen on em0 port 587
table aliases db:/etc/mail/aliases.db
accept from any         for domain "aoiyuma.mydns.jp"   alias <aliases> deliver to maildir
accept from any         for domain "aoiyuma.mydns.jp"                   deliver to maildir
accept for local                                        alias <aliases> deliver to maildir
accept for local                                                        deliver to maildir
mynetwork = "xxx"
accept from source $mynetwork for any relay
reject from any for any





2015年10月19日月曜日

★★★ make world ; openbsd follow current 

私見; 釈迦は 縁起に言及したと思うが 、空はどうかと思う。
さらに 日本に伝わった中国仏教は 中国の道教の思想(例えば無)に修飾されている。
したがって サンスクリット(文語)でかかれた経典 あるいは パーリ(口語)でかかれたものに 原点復帰しないといけないと思う

https://ja.wikipedia.org/wiki/%E9%BE%8D%E6%A8%B9 より
「空」の理論の大成は龍樹の『中論』などの著作によって果たされた。

龍樹は、存在という現象も含めて、あらゆる現象はそれぞれの因果関係の上に成り立っていることを論証している。
さらに、因果関係によって現象が現れているのであるから、それ自身で存在するという「独立した不変の実体」(=自性)はないことを明かしている。
これによって、すべての存在は無自性であり、「空」であると論証しているのである。

哲学者の梅原猛は、龍樹は釈迦の仏教を否定し、大乗仏教を創始したとしている

とにかく 仏教の空 は 無ではない。


follow current では
  全てをソースから作り直します。

いわば 古い工作機械が新設計図にのっとって 新しい部品を 全部設計図から古い工作機械でつくりなおし それを組み立てて 新しい工作機械をつくるんですね。 


なれたら 以下のように linuxの上で できます。
つまり 上の画面の赤で囲んだ部分だけが arch で
    それ以外は           qemu上のOpenbsdです。

しかし 初心のうちは openbsdでしましょう。 
なれたら linux のkvmの上で立ち上げたOpenBSDに linuxから sshではいってします。
下の図のごとくです
このこと自体は新しいことでもなんでもなく
 https://markshroyer.com/2013/01/debugging-openbsd-via-qemu/
に書かれてます。 
詳しくは
http://openbsd-akita.blogspot.jp/2015/11/export-kvms-image-to-real-machine.html に書いてます


ともかくとして 混乱するといけないので 初心者は この背景が青の部分はよみとばして下さい。


A) まず概観です

openbsdのサポートするアーキテクチャー
は以下です



drwxr-xr-x   2 0  0       1024 Aug 16 10:28   alpha
drwxr-xr-x   2 0  0        512 Aug 16 03:33   amd64
drwxr-xr-x   2 0  0        512 Aug 14 13:10   armish
drwxr-xr-x   2 0  0       1024 Aug 15 10:19   armv7
drwxr-xr-x   2 0  0        512 Aug 16 10:08   hppa
drwxr-xr-x   2 0  0        512 Aug 16 03:35   i386
drwxr-xr-x   2 0  0        512 Aug 16 06:33   landisk
drwxr-xr-x   2 0  0        512 Aug  7 07:43   loongson
drwxr-xr-x   2 0  0        512 Aug 22 07:17   luna88k
drwxr-xr-x   2 0  0        512 Aug 16 08:18   macppc
drwxr-xr-x   2 0  0        512 Aug 12 01:00   octeon

drwxr-xr-x   2 0  0       1024 Aug  7 00:32     sgi
drwxr-xr-x   2 0  0        512 Aug 16 13:56   socppc
drwxr-xr-x   2 0  0        512 Aug 15 06:23    sparc
drwxr-xr-x   2 0  0        512 Aug 16 09:58   sparc64
drwxr-xr-x   2 0  0        512 Aug 16 09:28     vax
drwxr-xr-x   2 0  0        512 Aug 16 08:01   zaurus





そして  
上の全アーキテクチャーにソースは共通です。
これは驚くべきことです。


-rw-r--r--   1 0  0   24847048 Aug 10 13:50 ports.tar.gz  firefoxなどアプリのソース
-rw-r--r--   1 0  0  126534216 Oct 13 19:12 src.tar.gz      根本的ソース
-rw-r--r--   1 0  0  120351877 Aug 10 13:50 xenocara.tar.gz     Xのソース




例えばインストール 時になにがはいってくるかというと

 1 1007  5000   10171090 Oct 20 09:44 bsd シングルプロセサ用のカーネル
 1 1007  5000   10215954 Oct 20 09:44 bsd.mp マルチプロセサの
カーネル
 1 1007  5000    7680667 Oct 20 09:50 bsd.rd    ブートローダー
1 1007  5000   55006525 Oct 20 09:44 base58.tgz ユーザーランド(後述)
-rw-r--r--  1 1007  5000   51727023 Oct 20 09:45 comp58.tgz
コンパイラ
-rw-r--r--  1 1007  5000    2790358 Oct 20 09:45 game58.tgz ゲーム
-rw-r--r--  1 1007  5000    8990754 Oct 20 09:45 man58.tgz マニュアル
-rw-r--r--  1 1007  5000   20926145 Oct 20 10:29 xbase58.tgz  X関係
-rw-r--r--  1 1007  5000   40008468 Oct 20 10:29 xfont58.tgz
  X関係
-rw-r--r--  1 1007  5000   19446067 Oct 20 10:30 xserv58.tgz  X関係
-rw-r--r--  1 1007  5000    4497260 Oct 20 10:30 xshare58.tgz X関係
です。


を頭に入れておいてください。

つまり 全アーキテクチャでソースは共通で 各アーキテクチャを それぞれのコンパイラがうまくコンパイルしてくれるのです。 まったくもって驚嘆すべき構造です。




B)まず最新のソースをつれてくる

# cd /usr
# export CVSROOT=anoncvs@anoncvs3.usa.openbsd.org:/cvs
#  cvs checkout -P src



          cvs -d$CVSROOT checkout -P sys 
      一応通るけど 必要ないらしい    確かに /usr/src/sys/は黄色だけで できていた。

Once you have a tree,
you can update it at a later time:
 # cd /usr/src
 # export CVSROOT=anoncvs@anoncvs3.usa.openbsd.org:/cvs
 # cvs -d$CVSROOT up -Pd


http://unosodoku638kam.hatenablog.com/entry/2013/12/27/192223  も参考に

 

C)ソースからカーネルをビルドする。


cp /bsd /bsd-1
とバックアップをとっときます。
立ち上がらないときは /bsd-1で立ち上げます

# cd /usr/src/sys/arch/amd64/conf
# config GENERIC
# cd ../compile/GENERIC
# make clean && make                <ー15分かかった:linuxで遊んでいよう
# make clean && make depend && make   <ー15分かかった:linuxで遊んでいよう
# make install

ls -l /bsd*

インストールが終わったら再起動させます。
# reboot

 

openbsdではこの青背景の部分は またもや無視してください。
kvm hostは archlinux です(もちろん guestはopenbsd)。
archlinuxで topで負荷をみると

top - 00:51:44 up 44 min,  0 users,  load average: 2.61, 2.46, 1.99

Tasks: 112 total,   3 running, 109 sleeping,   0 stopped,   0 zombie
%Cpu0  :   8.9/4.1    13[|||||||                                              ]
%Cpu1  :  90.1/9.3    99[|||||||||||||||||||||||||||||||||||||||||||||||||||||]
GiB Mem : 61.1/1.857   
GiB Swap:  0.0/4.000   

な感じで、swapは発生してません。 意外と軽い。

 

D)ソースからユーザランドbaseをビルド
Linux
ディストリビューションでいうところの
   coreutilsやBusyBoxに当たる部分

 

次にカーネル以外の部分を最新にします。
Clear your /usr/obj directory and rebuild symbolic links:
# rm -rf /usr/obj/*
# cd /usr/src
# make obj



  • # cd /usr/src/etc && env DESTDIR=/ make distrib-dirs
    
    
  • Build the system:
    # cd /usr/src

    # make build   <ー2時間ぐらいかかる:おでかけtime
    

 

細かな変更の適用

ビルドが終了したら「 Following -current 」 を確認し、
必要な変更を行います。



例えば 2013/12/04 には、 2013/12/08 に libcompat が廃止されたので、 以下のコマンドを実行し、 必要のないファイルを削除するように書かれています。
# rm -f /usr/lib/libcompat.a /usr/lib/libcompat_p.a
# rm -f /usr/include/{re_comp,regexp,sgtty,sys/timeb}.h
# rm -f /usr/share/man/man3/{re_comp,re_exec,rexec,regexp}.3
# rm -f /usr/share/man/man3/{cuserid,ftime,gtty,setrgid,setruid,stty}.3
これ以外にも様々な指示があるので、 よく内容を読んで実行してください。


openbsd do not  security support of X and aplications of ports .
X's security is xorg .
Firefox(a part of ports)  security is  firefox.org .



E) xenocara つまり X




 http://www.openbsd.org/faq/faq5.html#Xbld の通りである

$ cd /usr


# cvs -qdanoncvs@anoncvs3.usa.openbsd.org:/cvs checkout -P xenocara

       cvs -qdanoncvs@anoncvs2.usa.openbsd.org:/cvs checkout -P xenocara  でもいいかな

# cd /usr/xenocara

# rm -rf /usr/xobj/*

# make bootstrap

# make obj

# make build




F)portsつまり アプリレベル

firefox等のアプリをそのソースからコンパイル

私はこれはしません。

openbsd本体では 500をこえるpkgをつくるので 
         これには余程はやいコンピューターがいると思われます。

( vlc をmakeしようとすると 10時間立っても終わりません。  
cpu: Intel(R) Celeron(R) CPU J1800 @ 2.41GHz, 2417.11 MHz
では オソーイ. Cleaning for gcc-4.9.3p3が出たのでおそらくgccもコンパイルして遅くなったのだろう )


export PKG_PATH=http://ftp.openbsd.org/pub/OpenBSD/snapshots/packages/amd64
pkg_add firefox
で充分です。
ただし packages にないときはしょうがない。



一応書きます


# cd /usr
# cvs -qd anoncvs@anoncvs.ca.openbsd.org:/cvs get -P ports



Any time afterwards, to update this tree:
If you are following -current:
    # cd /usr/ports
    # cvs -q up -Pd



 make search key=rsnapshot


ここ

「 /etc/mk.conf 」に以下を追加します。
SUDO=/usr/bin/sudo
USE_SYSTRACE=Yes
WRKOBJDIR=/usr/obj/ports
DISTDIR=/usr/distfiles
PACKAGE_REPOSITORY=/usr/packages

アクセス権を修正します。
$ sudo chgrp -R wsrc /usr/ports
$ sudo find /usr/ports -type d -exec chmod g+w {} \;

フォルダを作成します。
$ sudo mkdir /usr/obj/ports
$ sudo mkdir /usr/distfiles
$ sudo mkdir /usr/packages

 

 

  • 検索
    $ cd /usr/ports
    $ make search key=rsnapshot
必要なものが見つかったら、 そのディレクトリに移動し、 以下のコマンドを使用して、 インストールを行います。
  • インストール
    $ sudo make install
  •  
  • フレーバーの表示
    $ make show=FLAVORS
  •  
  • フレーバーの設定してインストール。
    $ sudo env FLAVOR=no_x11 make install
  •  
  • サブパッケージの表示
    $ make show=MULTI_PACKAGES
  •  
  • サブパッケージを指定してインストール
    $ env SUBPACKAGE="-server" make install


15.3.6 - Cleaning up after a port build

You probably want to clean the port's default working directory after you have built the package and installed it.
$ make clean
===>  Cleaning for rsnapshot-1.2.9
In addition, you can also clean the working directories of all dependencies of the port with this make target:
$ make clean=depends
===>  Cleaning for rsync-2.6.9
===>  Cleaning for rsnapshot-1.2.9
If you wish to remove the source distribution set(s) of the port, you would use
$ make clean=dist
===>  Cleaning for rsnapshot-1.2.9
===>  Dist cleaning for rsnapshot-1.2.9
In case you have been compiling multiple flavors of the same port, you can clear the working directories of all these flavors at once using
$ make clean=flavors
You can also clean things up as they get built, by setting a special variable. Work directories will automatically be cleaned after packages have been created:
$ make package BULK=Yes

雑感
QEMUの技術は大事だ!
おそらく i386は おそらくamd64 マルチCPUな 高速コンピュータの上で ソースからコンパイルされている。

というのは openbsdに たとえ古いi386マシンがあったとしても 昔は1G超えのメモリを積むことはあり得なかった。 しかもCPUが i386では1000近いpackageを作ることは恐ろしい時間がかかり耐えられない。






ともかくとして snapshotについていくには
kenel
userland
X
をコンパイルして、


さらに portsの日本語`入力(scim-anthy)はコンパイルしないとうまくいかない。





NHKの神の数式(theory of everything) より抜粋

素粒子はすごく軽いので 通常は重力は無視できるので 
微細な世界では標準理論(素粒子の数式)だけでOK
しかし 宇宙の始まりとブラックホールの中では重力が無視できないので標準理論は破綻する。

そのために超弦理論がでてきた。
恐ろしい事に 数学力があれば  超弦理論から 一般相対性理論も 標準理論(素粒子の数式)も 導きだされてしまう。



で superstring theoryが theory of every thing の最有力候補だ。 
superstring theoryは 超微細な世界では 11次元という。
(一本のロープは 人間には前か後かにしか進めない一次元の世界であるが 小さなアリにとっては前後左右に進める2次元の世界だ。 でなんとなく感覚的に微細な世界では 11次元は納得できる)

なお 数学は神の領域で nが3以上なら 神様でもフェルマーの式を満たす数はつくれない。
そして 今 整数論、位相幾何、関数論が相互乗り入れになり 数学の第統一がなされようとしている(フェルマーの定理という整数論の問題が 楕円関数で解決された)。

さらにペレルマンがポアンカレ予想をといたときに 物理の概念をたくさんいれている。

で 数学と物理とが融合していっており 大大統一論がスタートしてるかのようである。
 でも これらは天才の世界の出来事であり
通常の人間は いくら努力をしても 100m 10秒は切れないように ワカンナイ。

なお
https://www.youtube.com/watch?v=7y_BlA3ZTeQ
の 5分50秒くらいのところに 超弦理論の元は
200年前の 数学者オイラーのオイラーの関数だったとでてます。



2015年10月18日日曜日

boot openbsd in UEFI pc preparing by only OpenBSD

0)i wii install openbsd to USB HDD (sd1).

1) boot PC by openbsd 5.8 snapshot CD.

2) install but Partway

3) when 'Use (W)hole disk .....' appear , push ! and go to shell .

4) fdisk -i -b 960 sd1 
 
 
 
 
 5) exit

6) when # appear ,

newfs_msdos /dev/rsd1i

mount /dev/sd1i  /mnt2

mkdir -p /mnt2/efi/boot

cp /mnt/usr/mdec/BOO* /mnt2/efi/boot

7) reboot PC 
 
 
 
8)the next comes up .

 
 
 
 
 
 
in BIOS
openbsd's sd1i is captured as UEFI Generic Boot
          sd1a             as Maxter 

 
 
 
 
 
 
 
<expieriemnt> 
 
and then 
i install openbsd58 into openbsd area  .
but
snapshot's UEFI cannot boot openbsd58 .
it is natural because of diffrense of virsion .