mailcow: Confirmed A record with IP xxx.xxx.xxx.xxx, but HTTP validation failed

Found this happening in my new mailcow installation and could reproduce following the steps here https://docs.mailcow.email/post_installation/firststeps-ssl/#lets-encrypt-out-of-the-box to re-run the ACME plugin. Found lots of others complaining about this and recommendations to disable IP and HTTP checks. Don’t do that! Instead fix your NAT reflection rules so that your containers can talk to your external IP […]

Changing USG-3P WAN static IP aka “There was an error saving the Primary (WAN1) network. IP xxx.xxx.xxx.xxx is used as NAT outband at configuration Default.”

Not sure why this is an issue that Ubiquiti has left out there, but if you try and change the static IP address the UniFi controller will puke with the above error. Apparently there are a bunch of different workarounds, but the simplest (to me at least) seems to be logging into the USG directly […]

Don’t be a fuckup; fuckup (that’s not where check_sender_access goes!)

So recently some Russian cunt(s) started relaying email through my postfix server. I finally figured out I had a check_sender_access in my smtpd_helo_restrictions AND smtpd_sender_restrictions. With entire domains listed spammers found one of the domains to send from and then used my server as an open relay. -Don’t put entire domains in sender_access as OK. […]

Watchdawg

Proxmox VMs I got tired of interrupting calls from the trouble and strife (and the rest of the family) that something wasn’t working. Seems to normally be weird edge cases between hardware and software and virtualization, but at least once the virtualized Ubuntu 20.04.4 running Plex has died and the OPNsense router died once too. […]