Thursday, 3 May 2012

How to create a full backup of my domain in cPanel?


1) Login to the cPanel
2) Go to "Files"
3) Click on "Backup"
4) Under "Full Backup" option
5) Select "Download or Generate a Full Backup Website"
6) Click on "Generate Backup"

Note: It will take some time to complete the full backup of your domain.

Upload file in your account via FTP filezilla in cPanel

How to upload your files via FTP FileZilla in cPanel?


You can upload the file via FTP. Kindly download the FTP client to your local machine and install it. Kindly follow the link below to download the FTP client.
======
http://filezilla-project.org/download.php
======
Then you can upload the files via FTP client. The login details for the FTP is same as cPanel username and password. Make sure that the port number for FTP is 21.

How to create a Parked domain in cPanel?


These are the steps to create a parked domain in cPanel.

1) Login to your cPanel
2) Go to Domains.
3) Click on "Parked Domain" tab
4) Enter the domain name in "Create a Parked Domain"
5) Save it

Enabled "Auto Reload" option to 0 seconds. How to revert it?


Enabled "Auto Reload" option to 0 seconds. How to revert it?

Kindly follow the steps below to disable the "Auto-reload" option in your webmail.


1) login to your "Webmail"
2) You will be auto reloaded to "Horde" login page.
3) Now, click "back to one page", in your browser like Firefox or Google chrome.
4) You will be loaded with "Horde" interface page.
5) There is an option called "Disable Auto Reload" below the "Horde" interface page.
6) Click on "Disable Auto Reload"
7) Then click on "Enable auto-reload"
8) It will prompt for seconds delay for reloading your "Horde", change it accordingly.

Enable Auto reload option in webmail/cPanel


Enable Auto reload option in webmail/cPanel

1) login to your "Webmail"
2) Check for the option "Auto Reload" below the default interface (i.e Horde, Squerrel mail)
3) Click on "Auto Reload" below the default interface
4) Give the seconds to reload that interface by default (e.g 5seconds)



Using For Loop to Rename All Files in a Folder


Using For Loop to Rename All Files in a Folder


This is the batch script for windows to rename all files in a folder on windows. This works well perfectly. This was useful for me. It may help others to do the same. I was worried to change the files name and folder using script, atlast i find my script to fix the issue.



rem: Some testing batch command in Windows XP
setlocal ENABLEDELAYEDEXPANSION
@echo off
rem ***************** Test 1 **********************
rem about variables
set var1= This is a variable VAR1
set var2=’This is a variable VAR2′
set var3=”This is a variable VAR3″
echo %var1%
echo ‘%var2%’
echo “%var3%”
rem ***********************************************
rem Conclusion from test 1 is that assigning text
rem value to variable doesn’t need to be quoted
rem ***********************************************
rem **************** Test 2 **********************
rem about for loop
set count=0
for %%a in (1 2 3) do (
echo !count!
set /A count=!count!+1
echo %%a
)
for %%A in (1 2) do for %%B in (A B) DO ECHO %%A%%B
rem **********************************************
rem Conclusion from test 2 is that variable in
rem the for loop has to be single character like
rem %%a. %%var will not work
rem you don’t have to have
rem setlocal ENABLEDELAYEDEXPANSION for the count
rem to work but you do have to use !count! instead
rem of %count%
rem **********************************************
rem **************** Test 3 **********************
rem use for loop to list all .txt file names
for /f %%a in (’dir /b transaction*.txt’) do (
echo %%a
)
rem **********************************************
rem I don’t know what the switch /f in the for
rem statement and the /A switch in the set
rem statement mean but it works.
rem Can someone explain the switch? =)
rem **********************************************
rem **************** Test 4 **********************
rem rename all .txt file so that all of them
rem starts with “trans” instead of “transaction”
for /f “tokens=1,2 delims=_” %%a in (’dir /b transaction*.txt’) do (
if “%%a”==”transaction” echo yes
echo %%a
echo %%b
ren %%a_%%b tran_%%b
)
rem **********************************************
rem The above script works fine. It renames all
rem files named in partern transaction_XXXX.txt
rem to trans_XXXXX.txt
rem “tokens=1,2 delims=_” tells it to separate
rem whatever returned in dir command in two parts
rem using the first “_” found and put the first
rem token in %%a, the second in %%b.
rem It is very powerful and interesting!
rem **********************************************
goto :eof


One additional remark: if you decide NOT to set ENABLEDELAYEDEXPANSION, then the !variable! syntax fails. Not sure if that means that %variable% would work in that situation instead, but just thought I’d be explicit about where ENABLEDELAYEDEXPANSION had an effect (though obviously it’s relevant in other parts too)



Testing Dovecot in Postfix or Verify Dovecot in Postfix


Testing Dovecot in Postfix or Verify Dovecot in Postfix

One thing that you can do is run this command to verify it is listening on the correct port numbers:
netstat -aunt

This should show that Dovecot is listening on ports 143 and 110 for IMAP and POP3.

Check if Dovecot is Listening
Another test is to connect to Dovecot using telnet on port 143.  Here is an example with the output you want.
telnet localhost 143
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.
* OK dovecot ready.

Check if Dovecot Accepting Passwords
telnet localhost 143
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.
* OK dovecot ready.
1 login hemanth
1 login hemanth password
1 OK Logged in.

Check if Dovecot is Accepting Remote Logins
telnet 21.14.126.132 143
Trying 21.14.26.132…
Connected to 21-14-26-132.static.example.net (21.14.126.132).
Escape character is ‘^]’.
* OK dovecot ready.
1 login hemanth password
1 OK Logged in.

Check if Dovecot is Finding the Mailbox
1 select inbox
* FLAGS (\Answered \Flagged \Deleted \Seen \Draft)
* OK [PERMANENTFLAGS (\Answered \Flagged \Deleted \Seen \Draft \*)] Flags permitted.
* 0 EXISTS
* 0 RECENT
* OK [UIDVALIDITY 1163363765] UIDs valid
* OK [UIDNEXT 1] Predicted next UID
1 OK [READ-WRITE] Select completed.

Linux server settings for high load systems


Linux settings for high load systems


There are a few basic settings you have to adjust for high load systems to make sure the server have enough resources to handle big number of network connections. The main parameter is a maximum number of opened files allowed for the process to keep at the same time. Each network connection uses a file handler therefore if the limit is too low you can quickly run out of handlers and the server can not accept any more connections. 

This limit is set on 2 levels - on the kernel level (fs.file-max) and on the system level (nofile). Another kernel property which can be important in certain configurations (like transports installations or when you use proxy for Bosh connections) is: net.ipv4.ip_local_port_range. This parameter can be set the same way as the fs.file-max property.
fs.file-max

The fs.file-max kernel property is set via sysctl command. You can see current settings executing command:
view source print?
1 # sysctl fs.file-max
2 fs.file-max = 358920


If you plan to run high load service with big number of server connections then this parameter should be at least as twice big as the number of network connections you expect to support. You can change this setting executing command:
view source
print?
1 # sysctl -w fs.file-max=360000
2 fs.file-max = 360000
net.ipv4.ip_local_port_range

You can see current settings executing command:
view source
print?
1 # sysctl net.ipv4.ip_local_port_range
2 net.ipv4.ip_local_port_range = 32768 61000

You can change this setting executing command:
view source
print?
1 # sysctl -w net.ipv4.ip_local_port_range="1024 65000"
2 net.ipv4.ip_local_port_range = 1024 65000
/etc/sysctl.conf

Above commands let the system remember new settings until the next system restart. If you want to make the change permanent you have to edit file: /etc/sysctl.conf and add the property at the end of the file:
view source
print?
1 fs.file-max=360000
2 net.ipv4.ip_local_port_range=1024 65000

It will be automatically loaded next time you start the server. Command:
view source
print?
1 # sysctl -p
Causes the /etc/systcl.conf to be reloaded which is useful when you added more parameters to the file and don't want to restart the server.
nofile

This is the property used by the system limits. For example running the command ulimit -a shows you all limits set for the current user:
view source
print?

01 # ulimit -a
02 core file size (blocks, -c) 0
03 data seg size (kbytes, -d) unlimited
04 file size (blocks, -f) unlimited
05 pending signals (-i) 38912
06 max locked memory (kbytes, -l) 32
07 max memory size (kbytes, -m) unlimited
08 open files (-n) 40960
09 pipe size (512 bytes, -p) 8
10 POSIX message queues (bytes, -q) 819200
11 stack size (kbytes, -s) 8192
12 cpu time (seconds, -t) unlimited
13 max user processes (-u) 38912
14 virtual memory (kbytes, -v) unlimited
15 file locks (-x) unlimited


To make it even more interesting and more complex there are 2 types of system limits: soft limit which can be temporarily exceeded by the user and hard limit which can not be exceeded. To see your hard limit execute command:
view source
print?

01 # ulimit -a -H
02 core file size (blocks, -c) unlimited
03 data seg size (kbytes, -d) unlimited
04 file size (blocks, -f) unlimited
05 pending signals (-i) 38912
06 max locked memory (kbytes, -l) 32
07 max memory size (kbytes, -m) unlimited
08 open files (-n) 40960
09 pipe size (512 bytes, -p) 8
10 POSIX message queues (bytes, -q) 819200
11 stack size (kbytes, -s) unlimited
12 cpu time (seconds, -t) unlimited
13 max user processes (-u) 38912
14 virtual memory (kbytes, -v) unlimited
15 file locks (-x) unlimited


The hard limits are usually bigger then the soft limits or sometimes the same. For us the most important parameter is: open files. You can change the property in file: /etc/security/limits.conf. You have to append 2 following lines to the end of the file:
view source
print?
1 jabber soft nofile 350000
2 jabber hard nofile 350000


Where the jabber is the user name of the account running you IM service. You can also set the limits for all users on the machine in a following way:
view source
print?
1 * soft nofile 350000
2 * hard nofile 350000


For those changes to make an effect you have to logout from the modified account and login again. New limits should be applied. 

Retrieve Plesk Admin Pass Windows server

How can Plesk admin password be retrieved?

To Retrieve Plesk Admin Pass Windows server, follow the simple steps below


Resolution

Apart from the password reminder available on the login screen, you can use the plesksrvclient.exe utility located in %plesk_bin% folder to set up a new password or retrieve the old one.

You could set the new passsword by running the following command:
"%plesk_bin%\plesksrvclient" -set <new_password> true

You could also get the current password by running this utility with:
"%plesk_bin%\plesksrvclient" -get

To retrieve password in command line you can use -nogui option:

E.g.
"%plesk_bin%\plesksrvclient" -get -nogui > plesk_password.txt

After that you can see retrieved Plesk password in plesk_password.txt file. 

How to reset/change cPanel password?


How to reset/change cPanel password?

If you like to change/reset your cPanel password, kindly follow the steps below.

=============

1) Go to your cPanel login page.
2) Under "Password Reset"
3) Enter the "Username" of your account.
4) A reset e-mail will reach your registered email account
=============

You can also reset your password by logging into your cPanel.

=============

1) Go to "Preference"
2) Select "Change Password"
3) Enter your "Old Password"
4) Type your "New Password"
5) Click "Change your password now"

=============

Configure email account in Outlook or MS Outlook

How to configure email account in Outlook?

There are many of us who do not use Outlook for send/receive email. But it is the better option to use Outlook to send and receive emails. Configuring email account in Outlook is easier. Just follow the link below to configure Outlook in your local machine.






=============

1. Open Outlook
2. Go to Tools > Email Accounts.
3. This will bring you to the Accounts Configuration Setup.
4. Choose to Add a new E-mail Account.
5. Click Next.
6. Click on Pop3
7.At the next window please enter the following information:
1. Under User Information, enter Your Name and Email Address.
2. For Server Information, enter mail.domain.com for Incoming and mail.domain.com for
Outgoing servers.
3. For Logon Information, enter your login name and password.
Click More Settings... on the lower right hand corner of the screen.

# At the Internet E-Mail Settings, General Tab window enter the following information:
1.Give your account a name,
2.Enter a name for your Organization,
3.Enter your e-mail address or whatever address you want recipients to reply to.

#. At the Outgoing Server Tab:
1.Check the box “My outgoing server (SMTP) requires authentication”.
2.The dial button “Use same settings as my incoming mail server” should be selected.
3.Click on the Advanced Tab.

# Enter the port details
Incoming mail server: 110
outgoing mail server :25

Please uncheck the SSL option.

Click OK.





Thats it the Outlook is configured in your local machine. Now, you can send and receive emails without any issue.

Default email account configuration


Default email account configuration

Kindly follow the steps to configure the email client in the computer so that you can send/receive mails.

================

1. Incoming/Outgoing mailserver: mail.domain.com
2. Username: USERNAME@domain.com
3. Password: password of this email account
4. Outgoing mailserver port: 25 or 26 or 587 or 58700
5. Incoming mailserver port: 110 (for POP)
6. Do not check "Use SSL"
7. Do enable "My Server requires authentication"

================

Configure email account in MAC machine

How to configure email account in MAC machiane?

Configuring the email account in MAC machine is quite easier. Just follow the instructions below to configure the email account in the MAC machine.


1. Open Mac Mail and then click File, Add Account....


2. Enter the POP3 server assigned to you within the Incoming Mail Server field(mail.domain.com). Your User Name is your complete email address. Finally, enter your password and click Continue.


3. On the Incoming Mail Security tab, ensure that Use Secure Sockets Layer (SSL) is unchecked and the Authentication method is Password. Click Continue.


4. On the Outgoing Mail Server tab, enter the SMTP server provided to you within the Outgoing Mail Server option(mail.bwdesigngrp.com). Check the box for Use Authentication, then your complete email address within the User Name field. Enter your password, then click Continue.


5. On the Outgoing Mail Security tab, ensure that Use Secure Sockets Layer (SSL) is unchecked and the Authentication method is Password. Click Continue.


6. On the Account Summary page, review the values for accuracy, then click Continue.


7. On the Conclusion page, click Done.

Try sending mails now. If you face any issues, then there is a possibility that your ISP is blocking the standard SMTP port 25(to avoid spamming), so try connecting with port 26. The configuration steps are as follows:

* Within the Account tab in Preferences click on the Server Settings... button. In the popup, change the Server port from 25 to 26. Ensure that Use Secure Sockets Layer (SSL) is unchecked and that Authentication is set to Password. Enter your complete email address as the User Name and provide your password within the appropriate field. Click OK.

* When you close the window you will be prompted to Save Changes. Be sure to click Save.

How to upload files in the cPanel?


How to upload files in the cPanel?

You can upload files in the cPanel by two methods, either using File manager or using FTP. I have given the steps below to upload files in the cPanel.
1) Login to the cPanel control panel.
2) Click on File Manager in cPanel and then find the folder or create a folder to upload.
3) Click on the name of the desired folder
4) At the top you can find the option upload. Click on it
5) You can see a browse option, now browse the files and upload it.
Note: By default the file permission should be 644 and directory permission should be 755
++++++++


Also you can upload the file via FTP. Kindly download the FTP client to your local machine and install it. Kindly follow the link below to download the FTP client.
======
http://filezilla-project.org/download.php
======
Then you can upload the files via FTP client. The login details for the FTP is same as cPanel username and password. Make sure that the port number for FTP is 21.

How to install a new cPanel account in the server?

How to install a new  cPAnel account in the server?

Just follow the steps below to install the cPanel in your server or VPS.


#mkdir /home/cpins
#cd /home/cpins
#wget
http://layer1.cpanel.net/latest
#sh latest

Thats it. The cPanel installation will be started. It will take 2-3 hours to install cPanel. Once the cPanel installation is complete, then you can use your new cPanel and set it up by accessing it in the browser

http://IPADDRESS-OF-THE-SERVER:2086


Tuesday, 24 April 2012

Install DKIM in Postfix using openDKIM

1. Install prerequisites

===========
yum install sendmail-devel openssl-devel
===========

2. Install OpenDKIM

Download then extract OpenDKIM. Change to the extracted directory and run configure, make and then, as root, make install.

===========
wget http://downloads.sourceforge.net/project/opendkim/opendkim-2.4.2.tar.gz
tar -zxf opendkim-2.4.2.tar.gz
cd opendkim*
./configure
make && make install
===========

3. Post install steps

Create a Linux user for OpenDKIM, then make some directories to store your keys and config files in.

============
useradd -s /sbin/nologin -b /var/run/opendkim opendkim-milt
mkdir /etc/mail/dkim
mkdir /etc/mail/dkim/keys
chown -R opendkim-milt:opendkim-milt /etc/mail/dkim
chmod -R go-wrx /etc/mail/dkim/keys
============

4.Check for startup script (/etc/init.d/opendkim). If not present, use this:

==============
    #!/bin/bash
    #
    # opendkim    Start and stop opendkim.

    # chkconfig: - 41 61
    # description: opendkim
    # processname: opendkim
    # pidfile: /var/run/opendkim/dkim-milter.pid

    ### BEGIN INIT INFO
    # Provides: opendkim
    # Required-Start: opendkim
    # Required-Stop: opendkim
    # Short-Description: Start and stop OpenDKIM
    # Description: DKIM milter
    ### END INIT INFO

    # Adapted from Andrew Colin Kissa's <topdog-software[dot]com> script for dkim-milter - 28-05-2009

    . /etc/rc.d/init.d/functions

    DAEMON=/usr/local/sbin/opendkim
    RETVAL=0
    PID_FILE=/var/run/opendkim/dkim-milter.pid

    start() {
    echo -n $"Starting DKIM milter: "
    daemon $DAEMON -x /etc/opendkim.conf
    RETVAL=$?
    [ $RETVAL -eq 0 ] && touch /var/lock/subsys/opendkim
    echo
    return $RETVAL
    }

    stop() {
    echo -n $"Stopping DKIM milter: "
    killproc -p $PID_FILE
    RETVAL=$?
    echo
    [ $RETVAL -eq 0 ] && rm -f /var/lock/subsys/opendkim
    return $RETVAL
    }

    restart() {
    stop
    start
    }

    case "$1" in
    start)
    start
    ;;
    stop)
    stop
    ;;
    restart)
    restart
    ;;
    status)
    status -p $PID_FILE
    ;;
    condrestart)
    [ -f /var/lock/subsys/opendkim ] && restart || :
    ;;
    *)
    echo $"Usage: $0 {start|stop|status|reload|restart|condrestart}"
    exit 1
    esac

    exit $?
==============

4. Generating keys for DKIM signing

You will need to generate a pair of keys for each domain you want to sign mail for, a public and a private key. OpenDKIM has a script included that will help do this. Where the keys are kept is up to you but here we create a directory inside /etc/mail/dkim/keys…

============
mkdir /etc/mail/dkim/keys/example.com
opendkim-genkey.sh -D /etc/mail/dkim/keys/example.com/ -d example.com -s default
chown -R opendkim-milt:opendkim-milt /etc/mail/dkim/example.com
mv /etc/mail/dkim/keys/example.com/default.private /etc/mail/dkim/keys/example.com/default
============



    * Reply with quote
    * Report this post

OpenDKIM with Postfix

Postby Bimlendu on Thu Oct 06, 2011 10:11 am
Reference ticket: DPZ-639288

1. Install prerequisites

===========
    yum install sendmail-devel openssl-devel
===========


2. Install OpenDKIM

Download then extract OpenDKIM. Change to the extracted directory and run configure, make and then, as root, make install

============
    wget http://downloads.sourceforge.net/project/opendkim/opendkim-2.4.2.tar.gz
    tar -zxf opendkim-2.4.2.tar.gz
    cd opendkim*
    ./configure
    make && make install
============


3. Post install steps

Create a Linux user for OpenDKIM, then make some directories to store your keys and config files in.

==========
    useradd -s /sbin/nologin -b /var/run/opendkim opendkim-milt
    mkdir /etc/mail/dkim
    mkdir /etc/mail/dkim/keys
    chown -R opendkim-milt:opendkim-milt /etc/mail/dkim
    chmod -R go-wrx /etc/mail/dkim/keys
==========



Check for startup script (/etc/init.d/opendkim). If not present, use this:

============
    #!/bin/bash
    #
    # opendkim    Start and stop opendkim.

    # chkconfig: - 41 61
    # description: opendkim
    # processname: opendkim
    # pidfile: /var/run/opendkim/dkim-milter.pid

    ### BEGIN INIT INFO
    # Provides: opendkim
    # Required-Start: opendkim
    # Required-Stop: opendkim
    # Short-Description: Start and stop OpenDKIM
    # Description: DKIM milter
    ### END INIT INFO

    # Adapted from Andrew Colin Kissa's <topdog-software[dot]com> script for dkim-milter - 28-05-2009

    . /etc/rc.d/init.d/functions

    DAEMON=/usr/local/sbin/opendkim
    RETVAL=0
    PID_FILE=/var/run/opendkim/dkim-milter.pid

    start() {
    echo -n $"Starting DKIM milter: "
    daemon $DAEMON -x /etc/opendkim.conf
    RETVAL=$?
    [ $RETVAL -eq 0 ] && touch /var/lock/subsys/opendkim
    echo
    return $RETVAL
    }

    stop() {
    echo -n $"Stopping DKIM milter: "
    killproc -p $PID_FILE
    RETVAL=$?
    echo
    [ $RETVAL -eq 0 ] && rm -f /var/lock/subsys/opendkim
    return $RETVAL
    }

    restart() {
    stop
    start
    }

    case "$1" in
    start)
    start
    ;;
    stop)
    stop
    ;;
    restart)
    restart
    ;;
    status)
    status -p $PID_FILE
    ;;
    condrestart)
    [ -f /var/lock/subsys/opendkim ] && restart || :
    ;;
    *)
    echo $"Usage: $0 {start|stop|status|reload|restart|condrestart}"
    exit 1
    esac

    exit $?
============


4. Generating keys for DKIM signing

You will need to generate a pair of keys for each domain you want to sign mail for, a public and a private key. OpenDKIM has a script included that will help do this. Where the keys are kept is up to you but here we create a directory inside /etc/mail/dkim/keys…

===========
mkdir /etc/mail/dkim/keys/example.com
opendkim-genkey.sh -D /etc/mail/dkim/keys/example.com/ -d example.com -s default
chown -R opendkim-milt:opendkim-milt /etc/mail/dkim/example.com
mv /etc/mail/dkim/keys/example.com/default.private /etc/mail/dkim/keys/example.com/default
===========

‘-s’ is the selector, here I have used default, you can use anything like mail or dk or dkim or sample.

5. OpenDKIM configuration

We need to edit one config file and create two ‘table’ files that the OpenDKIM milter will use to know what to do with the mails.

Edit /etc/opendkim.conf

These options should work:

==================
##
## opendkim.conf -- configuration file for OpenDKIM filter
##
## $Id: opendkim.conf.sample,v 1.5 2010/03/05 03:32:12 mmarkley Exp $
##
#ADSPDiscard             Yes
ADSPNoSuchDomain        Yes
AutoRestart             Yes
AutoRestartRate         10/1h
Canonicalization        relaxed/relaxed
KeyTable                refile:/etc/mail/opendkim/keyTable
LogWhy                  Yes
On-Default              reject
On-BadSignature         reject
On-DNSError             tempfail
On-InternalError        accept
On-NoSignature          accept
On-Security             discard
PidFile                 /var/run/opendkim/dkim-milter.pid
SignatureAlgorithm      rsa-sha256
SigningTable            refile:/etc/mail/opendkim/signingTable
Socket                  inet:20209@localhost
Syslog                  Yes
SyslogSuccess           Yes
TemporaryDirectory      /var/tmp
UMask                   022
UserID                  opendkim-milt:opendkim-milt
X-Header                Yes
==================

ii) /etc/mail/opendkim/signingTable

This table is used to select one or more signatures to apply to a message based on the address found in the From: header field. Keys in this table vary depending on the type of table used; values in this data set should include one field that contains a name found in the KeyTable that identifies which key should be used in generating the signature, and an optional second field naming the signer of the message that will be included in the "i=" tag in the generated signature.

If the first field contains only a "%" character, it will be replaced by the domain found in the From: header field. Similarly, within the optional second field, any "%" character will be replaced by the domain found in the From: header field.

If this table specifies a regular expression file ("refile"), then the keys are wildcard patterns that are matched against the address found in the From: header field. Entries are checked in the order in which they appear in the file.

For all other database types, the full user@host is checked first, then simply host, then user@.domain (with all superdomains checked in sequence, so "foo.example.com" would first check "user@foo.example.com", then "user@.example.com", then "user@.com"), then .domain, then user@*, and finally *.

In any case, only the first match is applied, unless MultipleSignatures is enabled in which case all matches are applied.

A working signingTable will look like this:

--------------
$ cat /etc/mail/opendkim/signingTable
*@espserv.com mail._domainkey.example.com
*@joseairosa.com mail._domainkey.example1.com
*@porvocacao.com mail._domainkey.example2.com
--------------

6. Postfix configuration

Add these to postfix's main.cf file:

============
smtpd_milters           = inet:localhost:20209
non_smtpd_milters       = inet:localhost:20209
milter_protocol         = 2
milter_default_action   = accept
============

You can change the port if required. Reload postfix.

7. DKIM DNS entries

When you created the keys few steps back, you should have got two files, one the private key and the other a public key. Open the public key file and add the contents to your domain's DNS.

=============
$ cat mail.txt
mail._domainkey IN TXT "v=DKIM1; r=postmaster; g=*; k=rsa; t=y; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNSFbbde/56vjZfTYRXe0w8J44fPmBwZgoIZsGfYFgQxCFKJ50NL2EVWGey9pWw+YrJEfec3nTlbcquxnmm92y7vsWM9B7sCyoYQIweepJBdkJ3boJXBlm3eXMqrOMJfYmqjn51Y5B0kuErgu/N41S1Cr3/BtQU3/QZL0qnXi+6wIDAQAB"
=============

While adding make sure that you remove the "r=postmaster" tag. This tag is still experimental and is not supported globally.

Finally add a DKIM ADSP record which should look something like this:

----------
_adsp._domainkey.example.com    IN    TXT    "dkim=unknown"
----------

8. Start OpenDKIM

=======
service opendkim start
=======

9. Add it to chkconfig so that openDKIM starts automatically on boot.

=======
chkconfig --level 2345 opendkim on
=======

10. Test. Send a mail to check-auth-username=gmail.com@verifier.port25.com. You will get the authentication results in username@gmail's inbox.

Use the following command to test and check if opendkim is being called by postfix or not.

==========
echo Test | mail -s test check-auth-username=gmail.com@verifier.port25.com ;tail -fn0 /var/log/maillog
==========

---------------------------------
Oct  6 00:31:59 smtp01 sendmail[4579]: p964Vw7R004579: from=root, size=82, class=0, nrcpts=1, msgid=<201110060431.p964Vw7R004579@servername.com>, relay=root@localhost
Oct  6 00:31:59 smtp01 postfix/smtpd[4581]: connect from localhost.localdomain[127.0.0.1]
Oct  6 00:31:59 smtp01 postfix/smtpd[4581]: setting up TLS connection from localhost.localdomain[127.0.0.1]
Oct  6 00:31:59 smtp01 postfix/smtpd[4581]: Anonymous TLS connection established from localhost.localdomain[127.0.0.1]: TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)
Oct  6 00:31:59 smtp01 sendmail[4579]: STARTTLS=client, relay=[127.0.0.1], version=TLSv1/SSLv3, verify=FAIL, cipher=DHE-RSA-AES256-SHA, bits=256/256
Oct  6 00:31:59 smtp01 postfix/smtpd[4581]: 36AD1B103: client=localhost.localdomain[127.0.0.1], sasl_sender=root@servername.com
Oct  6 00:31:59 smtp01 postfix/cleanup[4584]: 36AD1B103: message-id=<201110060431.p964Vw7R004579@servername.com>
[b]Oct  6 00:31:59 smtp01 opendkim[4486]: 36AD1B103: DKIM-Signature header added (s=mail, d=domainname.com)[/b]
Oct  6 00:31:59 smtp01 postfix/qmgr[3136]: 36AD1B103: from=<root@servername.com>, size=788, nrcpt=1 (queue active)
Oct  6 00:31:59 smtp01 sendmail[4579]: p964Vw7R004579: to=check-auth-username=gmail.com@verifier.port25.com, ctladdr=root (0/0), delay=00:00:01, xdelay=00:00:00, mailer=relay, pri=30082, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (Ok: queued as 36AD1B103)
Oct  6 00:31:59 smtp01 postfix/smtpd[4581]: disconnect from localhost.localdomain[127.0.0.1]
Oct  6 00:32:01 smtp01 postfix/smtp[4585]: 36AD1B103: to=<check-auth-username=gmail.com@verifier.port25.com>, relay=verifier.port25.com[96.244.219.19]:25, delay=2, delays=0.09/0.01/1.5/0.3, dsn=2.6.0, status=sent (250 2.6.0 message received)
Oct  6 00:32:01 smtp01 postfix/qmgr[3136]: 36AD1B103: removed
---------------------------------

Check you inbox for the authentication results. You should get the following:

==========================================================
Summary of Results
==========================================================
...
DKIM check:         pass
...
==========================================================
Details:
==========================================================
...
----------------------------------------------------------
DKIM check details:
----------------------------------------------------------
Result:         pass (signature verifies; identity doesn't match any headers)
ID(s) verified: header.d=domainname.com
Canonicalized Headers:
   date:Thu,'20'6'20'Oct'20'2011'20'00:31:58'20'-0400'0D''0A'
   from:root'20'<root@servername.com>'0D''0A'
   message-id:<201110060431.p964Vw7R004579@servername.com>'0D''0A'
   to:check-auth-username=gmail.com@verifier.port25.com'0D''0A'
   subject:test'0D''0A'
   dkim-signature:v=1;'20'a=rsa-sha256;'20'c=relaxed/relaxed;'20'd=domainname.com;'20's=mail;'20't=1317875519;'20'bh=fdkeB/A0FkbVP2k4J4pNPoeWH6vqBm9+b0C3OY87Cw8=;'20'h=Date:From:Message-Id:To:Subject;'20'b=

Canonicalized Body:
   Test'0D''0A'


DNS record(s):
   mail._domainkey.domainname.com. 1800 IN TXT "v=DKIM1; g=*; k=rsa; t=y; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDA1X6GKfaUhV3jthv32C5lo/V3/4yOys9CsZZByYId2NJnfRWiZroEozl6/4XyQhdb2JPNMRT8xcWd+RqSRfyszb9DzlEhfk4q0PpP7QFhtEzpUVSGrsNiSutkY56JkoQRblrrbrKUNgu5U0GTaFuNUnpj2/kHmEeIGcCk9we9eQIDAQAB"

NOTE: DKIM checking has been performed based on the latest DKIM specs
(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for
older versions.  If you are using Port25's PowerMTA, you need to use
version 3.2r11 or later to get a compatible version of DKIM.

----------------------------------------------------------

If you receive the above results, all is good.

11. You can automate the key generation and setting up permissions on keys using this script.

==================
    #!/bin/bash
    read -p "Enter your domain name : " domain_name
    if [ -f $domain_name ];
    then
    echo "Enter valid domain name"
    else
    if [ -d /etc/mail/opendkim/keys/$domain_name ];
    then
       echo "Domain already added"
    else
    mkdir /etc/mail/opendkim/keys/$domain_name
    echo -e "Generating key......\n"


    opendkim-genkey -d $domain_name -s mail -t -D /etc/mail/opendkim/keys/$domain_name/
    chown -R opendkim-milt /etc/mail/opendkim/keys/$domain_name
    cp /etc/mail/opendkim/keyTable /etc/mail/opendkim/keyTable_bak_before_$domain_name
    echo "mail._domainkey.$domain_name $domain_name:mail:/etc/mail/opendkim/keys/$domain_name/mail.private" >> /etc/mail/opendkim/keyTable
    echo "*@$domain_name mail._domainkey.$domain_name" >> /etc/mail/opendkim/signingTable
    echo -e "Restarting opendkim.........\n"
    /etc/init.d/opendkim restart
    echo -e "\nAdd the following public key in the domains DNS zone file \n"
    echo -e "\n============================="
    echo `cat /etc/mail/opendkim/keys/$domain_name/mail.txt|sed 's/r\=postmaster\;//g'`
    echo "============================="
    fi
    fi
==================

Sunday, 22 April 2012

Identfy spamming accounts in cPanel servers

For detailed troubleshooting on Spamming issue in cPanel servers, refer the following link.

http://linux-bloggers.blogspot.in/2011/12/exim-message-transfer-agent-mta.html

In this post, we have provided the script to identify accounts that is senting more mails in a day.

==============
awk -v dt=$(date +"%Y-%m-%d" --date "$(date +"%F %T") 1 days ago") '$1~dt && $0~/ [UA]=/ &&  $0!~/U=(mailnull)/ {printf("%s %s",$1,$2); for (i=1;i<=NF;i++) if ($i ~ /\<[UA]=/) printf(" %s\n",$i)}' /var/log/exim_mainlog | sed -r 's/(:..:..|\<U=|\<A=|courier_login:|courier_plain:)//g'| sort -f | uniq -c | awk '$1>50 {print}'
==============

If you execute this script then, you will get the account that is senting more mails in a day with number of emails.

Courtesy: Madhan Kumar(Collegue)



 

Thursday, 12 April 2012

Bacth script to take backup of all the database MSSQL

Here, is the script that we used to take backup of all the MSSQL database present in the windows server. You would need to get the "Sa" password from any website web.config file.

===============================
@ECHO OFF
SETLOCAL
REM Created By Dhanasekaran
for /F "tokens=2-4 delims=/ " %%A in ('Date /T') DO SET NowDate=%%A-%%B-%%C
echo %NowDate%
SET DBList=%SystemDrive%SQLDBList.txt
SqlCmd -S  .\SQLEXPRESS -U sa -P Password -Q "SET NoCount ON; SELECT Name FROM master.dbo.sysDatabases WHERE [Name] NOT IN ('master','model','msdb','tempdb')"> "%DBList%"
cd D:\Backup
mkdir D:\Backup\%NowDate%
FOR /F "tokens=*" %%I IN (%DBList%) DO (ECHO Backing up database: %%I
SqlCmd -S  .\SQLEXPRESS -U sa -P 27facil?ent -Q "BACKUP DATABASE [%%I] TO DISK='D:\Backup\%NowDate%\%%I.bak'"
ECHO.
)
IF EXIST "%DBList%" DEL /F /Q "%DBList%"
ENDLOCAL
 ===============================

Open notepad and save this file as "backup.bat" and then execute this file. The database backup will be stored in D:\Backup\Date.

Wednesday, 11 April 2012

login webmail Internal Server Error User is over quota

Hello,

My customer said his webmail login page shows over quota error. When I checked his account, it was over quota. I have increased his cPanel user quota. However, the over quota issue still appears in the cPanel account and in webmail accounts.

----------------------------------
Internal Server Error

User 'useraccount' is over quota.
----------------------------------


What should I do?? For one cPanel user running /script/upcp is ridiculous still I have made it. However the  "User 'useraccount' is over quota" still appears in the cPanel and webmail.

--------

Solution:

1) First check if the user quota is available. I mean, check if the user has enough diskspace and still if the issue appears follow the steps below.

2) First run  /scripts/fixquotas or  /scripts/fixquotas --force
    Check if this fix this issue.

3) If not, then
# cd /var/cpanel/overquota/
# ll |grep username
-rw-------  1 root root    41 Mar 27 17:26 username
#
# mv username username_bak
#
#/etc/init.d/cpanel restart

This will fix the issue 100%. Ask the user to clear the browser cache and verify the same from your end.

4) If you still have this issue go for /scripts/upcp --force



Thats it...... :)

Please let us know your comments if it is useful to you.



Saturday, 7 April 2012

Plesk Panel redirecting to URL: hostname:11444

At times, when we access the Plesk panel by accessing the following URL:

========
https://hostname:8443
========

It will be redirecting to the following URL:

========
http://hostname:11444
========

In this case, you will not be able to access the Plesk panel.

Fix:

Execute the following command as a root user.

========
 /usr/local/psa/bin/sso -d
 ========

You can access the Plesk panel without any problem.