Dear all,
I ponder using Cloudflare for squeak.org for two reasons:
a) Faster site (faster download for files, for example, but website,too)
b) SSL for free, no hassle.
People have expressed interest in that, and I went forth and
created everything necessary at clouflare but one thing:
The master dns server entries have to be changed:
a.ns.squeak.org -> austin.ns.cloudflare.comb.ns.squeak.org -> elsa.ns.cloudflare.com
This has to be changed at the registrar (networksolutions).
Currently, as per whois, Dan is owner of the site but I
don't know wether he's the one turing the knobs for
the domain. If so, we would need him to change those entries,
if not, we would have to find out whom to talk to.
So Iff the board and the admins decide to go for cloudflare we
need networksolutions to change the DNS-NS.
We need:
- a decision
- (mabye) contact Dan/Squeak.org-networksolutions-contact
Best regards
-Tobias
Hi Bradley, GMX has been treating all legitimate emails to
squeak-dev(a)lists.squeakfoundation.org as spam and deleting them, which
is a disruption for a signifcant part of our community.
Tobias has made some calls and determined that, to fix the situation,
we need the PTR-RR updated for bo4.squeak.org, but this must be done
by someone with control over the Gandi instance. Could you help us
out with this? It will be a relief for us to get this fixed.
Regards,
Chris Muller
On Mon, Jan 11, 2016 at 5:42 AM, Tobias Pape <Das.Linux(a)gmx.de> wrote:
> Hi all,
>
> Since GMX is playing three wise monkeys, we have to make sure that our
> PTR-RR for box4.squeak.org is matching. Levente said that our SFC contact
> can change the PTR-RR at Gandi, but we can't .
>
> Hence, I'd call for the board to contact our SFC guy to please change
> the respective entry. If you, want, I can do that, too, btw.
>
> Best regards
> -Tobias
> PS: Please CC me because of GMX.
Hi all,
Since GMX is playing three wise monkeys, we have to make sure that our
PTR-RR for box4.squeak.org is matching. Levente said that our SFC contact
can change the PTR-RR at Gandi, but we can't.
Hence, I'd call for the board to contact our SFC guy to please change
the respective entry. If you, want, I can do that, too, btw.
Best regards
-Tobias
PS: Please CC me because of GMX.
Hi Levente,
Sorry, I had to copy this from the archive (http://lists.squeakfoundation.org/pipermail/box-admins/2016-January/002120.…)
because, as I said, I cannot get mail on my gmx account via the list.
> Hi Tobias,
>
> Only the SFC has access to the admin panel.
> But such record already exists:
> 42.104.246.173.in-addr.arpa. 3600 IN PTR xvm-104-42.ghst.net.
> And it points back to the IP as well:
> xvm-104-42.ghst.net. 1200 IN A 173.246.104.42
> So, unless the servers of gmx are misconfigured, such change shouldn't
> have any effect.
No, that won't work for two reasons.
First, Mailman (via qmail) names itself "box4.squeak.org"[1] in its HELO/EHLO
phase but the PTR-RR says, as you stated, "xvm-104-42.ghst.net".
This violates the SMTP RFC and hence we get blocked.
We _could_ make qmail advertise "xvm-104-42.ghst.net" but this does
not match our mx entries for squeakfoundation.org, and we would get blocked
because of that.
Second, GMX explicitly forbids "hoster-generated PTR-RR records"[2]:
The delivering email server must have a static IP address. Additionally,
it has to be configured correctly and needs to provide a valid HELO,
as well as MX, A, and PTR resource records (reverse DNS entry).
>>The PTR-RR in particular must not correspond to the preset generic
record of the host.<<
(emphasis mine)
So we have to change.
>
> What we could do is to set up a strict SPF record, because we don't want
> any other sources to be considered valid senders by othe mailservers.
> I'm thinking about something like "v=spf1 mx -all".
>
I did this already:
squeakfoundation.org. 86396 IN SPF "v=spf3 mx a ptr ip4:173.246.104.42/32 a:box4.squeakfoundation.orga:box4.squeak.orginclude:squeak.org ~all"
squeakfoundation.org. 86400 IN TXT "v=spf1 mx a ptr ip4:173.246.104.42/32 a:box4.squeakfoundation.orga:box4.squeak.orginclude:squeak.org ~all"
Also I just found a Slack message from November that says:
[22:57] craig @group: Bradley Kuhn from SFC says that box4 could disappear at any time if Gandi doesn't renew the donation, so we should get set up with Tony at Rackspace ASAP.
I don't know what that means in terms of effort or in terms of other service support,
but I can imagine that setting up mailman again will be quite laborious.
Best regards
-Tobias
[1]: that was "box4.squeakfoundation.org" until yesterday.
[2]: http://postmaster.gmx.com/en/email-policy/
> Levente
>
> On Thu, 7 Jan 2016, Tobias Pape wrote:
>
> > Hi all,
> >
> > who of the admins has access to the gandi control panel
> > for box4? we need to set the RR-PTR for box4 so that,
> > finally, GMX allows us to send mail again.
> > I'd suggest putting
> > box4.squeak.org
> > in there.
> >
> > Please reply directly, I cannot get ml-mail via GMX *grml*
> >
> > best regards
> > -Tobias
> >
>
Hi all,
who of the admins has access to the gandi control panel
for box4? we need to set the RR-PTR for box4 so that,
finally, GMX allows us to send mail again.
I'd suggest putting
box4.squeak.org
in there.
Please reply directly, I cannot get ml-mail via GMX *grml*
best regards
-Tobias