Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Outgoing smtp connections, to local Exim

Discussion in 'E-mail Discussions' started by mikelsanz, Nov 20, 2017.

  1. mikelsanz

    mikelsanz Member

    Joined:
    May 23, 2013
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Reseller Owner
    Hello! We have some hosts with Wordpress installs, with a plugin to change mail() function, to external SMTP gateway. From last upgrade to v.68, we can't use this, and all the outgoing smtp attempts, goes to local Exim, and not outside...

    Connection: opening to ssl://externalgateway:465, timeout=300, options=array ()
    Connection: Failed to connect to server. Error number 2. "Error notice: stream_socket_client(): Peer certificate CN=s3.localnameserver.xxx' did not match expected CN=mail.externalgateway.xxx'
    Connection: Failed to connect to server. Error number 2. "Error notice: stream_socket_client(): Failed to enable crypto
    Connection: Failed to connect to server. Error number 2. "Error notice: stream_socket_client(): unable to connect to ssl://externalgateway.xxx:465 (Unknown error)
    SMTP ERROR: Failed to connect to server: (0)

    -----------------------------

    smtp:none:plain://mail.externalgateway.xxx':587 <--- Calling to external gateway

    220-s3.gestiondeservidor.com ESMTP Exim 4.89 #1 Mon, 20 Nov 2017 13:00:52 +0100
    220-We do not authorize the use of this system to transport unsolicited,
    220 and/or bulk e-mail.
    EHLO 185.162.171.12
    250-s3.localnameserver.xxx Hello XYZ.XYZ.XYZ.XYZ [XYZ.XYZ.XYZ.XYZ] <--- But connected to local Exim...
    250-SIZE 52428800
    250-8BITMIME
    250-PIPELINING
    250-AUTH PLAIN LOGIN
    250-STARTTLS
    250 HELP
    AUTH PLAIN
    334
    AHdlYnNAZW52aW9zLjIwY29tdW5pY2FjaW9uLm5ldABzbXRwMjAxNCs=
    535 Incorrect authentication data
     
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    41,494
    Likes Received:
    1,612
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    Can you verify if the "WHM Home » Security Center » SMTP Restrictions" feature is enabled on this system? If so, does disabling it solve the issue?

    Thank you.
     
  3. Anas Ashfaq

    Anas Ashfaq Registered

    Joined:
    Jan 15, 2018
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Finland
    cPanel Access Level:
    Root Administrator
    Hello,

    Disabling the restrictions solves the issue but is that a recommended solution?

    Is there a way to enable the smtp restrictions and add an exception to the trust mail sending providers e.g. mailgun

    Thank you
     
  4. cPWilliamL

    cPWilliamL cP Technical Analyst II
    Staff Member

    Joined:
    May 15, 2017
    Messages:
    257
    Likes Received:
    27
    Trophy Points:
    103
    Location:
    America
    cPanel Access Level:
    Root Administrator
    We don't provide a method at this time to make this option specific to users or outbound hosts; however, this is simply implemented through iptables UID/GID matches:
    Code:
    # iptables -nL|grep match
    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            multiport dports 25,465,587 owner GID match 992
    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            multiport dports 25,465,587 owner GID match 12
    ACCEPT     tcp  --  0.0.0.0/0            127.0.0.1            multiport dports 25,465,587 owner UID match 202
    ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0            multiport dports 25,465,587 owner UID match 0
    
    It shouldn't be difficult to apply manually, but this would also make a good feature request. I also believe CSF(ConfigServer Security and Firewall) provides this functionality.
     
Loading...

Share This Page