Can someone confirm (or disprove) that the current version of Sendmail from ports (8.15.2_5), explicitly compiled with the blacklistd flag, has stopped feeding offending IPs (e.g. those failing do_auth) to blacklistd since Jan 3?
I ran
The poll() did pick up sshd and ftpd activity, but all quiet on the Sendmail front, since Jan 3.
I ran
So it appears to be something working not quite right, or maybe a combination of compile options. Before I file a bug report, I just want to check for confirmation or lack thereof.
Using compile options:
Relevant part of blacklistd.conf:
Output of
Poudriere build info available at https://pastebin.com/wBCdXunK
I ran
blacklistd -d
to check, but the poll() revealed nothing while do_auth failures were coming in.The poll() did pick up sshd and ftpd activity, but all quiet on the Sendmail front, since Jan 3.
I ran
strings
on the Sendmail binary, and the expected output was there:
Code:
libblacklist.so.0
blacklist_r
blacklist_open
Using compile options:
Code:
OPTIONS_FILE_SET+=SHMEM
OPTIONS_FILE_SET+=SEM
OPTIONS_FILE_SET+=LA
OPTIONS_FILE_SET+=NIS
OPTIONS_FILE_SET+=IPV6
OPTIONS_FILE_SET+=TLS
OPTIONS_FILE_SET+=SASL
OPTIONS_FILE_SET+=SASLAUTHD
OPTIONS_FILE_UNSET+=LDAP
OPTIONS_FILE_UNSET+=BDB
OPTIONS_FILE_UNSET+=GDBM
OPTIONS_FILE_UNSET+=SOCKETMAP
OPTIONS_FILE_UNSET+=CYRUSLOOKUP
OPTIONS_FILE_SET+=BLACKLISTD
OPTIONS_FILE_UNSET+=SMTPUTF8
OPTIONS_FILE_SET+=PICKY_HELO_CHECK
OPTIONS_FILE_SET+=MILTER
OPTIONS_FILE_SET+=DOCS
Code:
[local]
smtp stream * * * 3 30d
smtps stream * * * 3 30d
submission stream * * * 3 30d
blacklistctl dump -nb
shows nothing after 2018/01/03 (on seven different installations).Poudriere build info available at https://pastebin.com/wBCdXunK