Search results for query "sapiro"
- 6292 messages
[MM3-users] Re: Reg Archive Inactive Status
by Nirmal J
mailman.log :-
File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 388, in _make_request
self._validate_conn(conn)
File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 1050, in _validate_conn
conn.connect()
File "/usr/lib/python3/dist-packages/urllib3/connection.py", line 414, in connect
self.sock = ssl_wrap_socket(
^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/urllib3/util/ssl_.py", line 449, in ssl_wrap_socket
ssl_sock = _ssl_wrap_socket_impl(
^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/urllib3/util/ssl_.py", line 493, in _ssl_wrap_socket_impl
return ssl_context.wrap_socket(sock, server_hostname=server_hostname)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.11/ssl.py", line 517, in wrap_socket
return self.sslsocket_class._create(
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.11/ssl.py", line 1108, in _create
self.do_handshake()
File "/usr/lib/python3.11/ssl.py", line 1379, in do_handshake
self._sslobj.do_handshake()
ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:992)
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/requests/adapters.py", line 489, in send
resp = conn.urlopen(
^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 789, in urlopen
retries = retries.increment(
^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/urllib3/util/retry.py", line 594, in increment
raise MaxRetryError(_pool, url, error or ResponseError(cause))
urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='list1.iitm.ac.in', port=443): Max retries exceeded with url: /hyperkitty/api/mailman/archive (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:992)')))
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "/usr/local/lib/python3.11/dist-packages/mailman_hyperkitty-1.2.0-py3.11.egg/mailman_hyperkitty/__init__.py", line 151, in _archive_message
url = self._send_message(mlist, msg)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/local/lib/python3.11/dist-packages/mailman_hyperkitty-1.2.0-py3.11.egg/mailman_hyperkitty/__init__.py", line 195, in _send_message
result = requests.post(
^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/requests/api.py", line 115, in post
return request("post", url, data=data, json=json, **kwargs)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/requests/api.py", line 59, in request
return session.request(method=method, url=url, **kwargs)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/requests/sessions.py", line 587, in request
resp = self.send(prep, **send_kwargs)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/requests/sessions.py", line 701, in send
r = adapter.send(request, **kwargs)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3/dist-packages/requests/adapters.py", line 563, in send
raise SSLError(e, request=request)
requests.exceptions.SSLError: HTTPSConnectionPool(host='list1.iitm.ac.in', port=443): Max retries exceeded with url: /hyperkitty/api/mailman/archive (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:992)')))
-----Original Message-----
From: Mark <mark(a)msapiro.net>
To: Nirmal <nirmal(a)iitm.ac.in>; MM3 <mailman-users(a)mailman3.org>
Date: Friday, 26 September 2025 9:56 PM IST
Subject: Re: [MM3-users] Re: Reg Archive Inactive Status
On 9/25/25 22:29, Nirmal J wrote:
> I have ensured that the IP Address of list1.iitm.ac.in is in the Mailman_Archiver_From List in settings. But still not working. Please help.
You may also need variuos localhost IPs such as '127.0.0.1', '::1',
'::ffff:127.0.0.1'
What archiving failures do you now see in mailman.log? Do not post the
entire log, just the relevant message(s).
--
Mark Sapiro <mark(a)msapiro.net> The highway is for gamblers,
San Francisco Bay Area, California better use your sense - B. Dylan
11 months, 2 weeks
[MM3-users] Re: Mailman3 without Hyperkitty in docker
by Danil Smirnov
Thank you very much Abhilash!
Could you set up 'latest' tag in postotius repo
<https://hub.docker.com/r/maxking/postorius/tags> please - as it exists for
core/web?
I'd like to have consistent approach across the images...
Also it would be really great to extend image labelling used for
*quay.io/maxking/mailman-*:rolling
<http://quay.io/maxking/mailman-*:rolling>* images to Docker Hub ones...
Version identification is quite hard for Docker...
With my best regards,
Danil
сб, 2 мар. 2019 г. в 03:19, Abhilash Raj <maxking(a)asynchronous.in>:
>
>
> On Thu, Feb 28, 2019, at 10:18 PM, Danil Smirnov wrote:
>
> Hi Abhilash,
>
> Thank you very much - the previous error is fixed now.
>
> But I have another one now, which causes the same 500 Server Error:
>
> bash-4.3# cat /opt/mailman-web-data/logs/uwsgi-error.log
> *** Starting uWSGI 2.0.18 (64bit) on [Fri Mar 1 05:42:09 2019] ***
> compiled with version: 6.3.0 on 01 March 2019 01:52:42
> os: Linux-3.10.0-693.11.1.el7.x86_64 #1 SMP Mon Dec 4 23:52:40 UTC 2017
> nodename: mailman-web
> machine: x86_64
> clock source: unix
> detected number of CPU cores: 2
> current working directory: /opt/mailman-web
> detected binary path: /usr/local/bin/uwsgi
> !!! no internal routing support, rebuild with pcre support !!!
> setgid() to 101
> setuid() to 100
> chdir() to /opt/mailman-web
> your memory page size is 4096 bytes
> detected max file descriptor number: 1048576
> building mime-types dictionary from file /etc/mime.types...1168 entry found
> lock engine: pthread robust mutexes
> thunder lock: disabled (you can enable it with --thunder-lock)
> uwsgi socket 0 bound to TCP address 0.0.0.0:8080 fd 8
> uwsgi socket 1 bound to TCP address 0.0.0.0:8000 fd 9
> Python version: 3.6.8 (default, Jan 30 2019, 23:58:16) [GCC 6.3.0]
> Python main interpreter initialized at 0x55a2df7f57e0
> python threads support enabled
> your server socket listen backlog is limited to 100 connections
> your mercy for graceful operations on workers is 60 seconds
> mapped 166752 bytes (162 KB) for 2 cores
> *** Operational MODE: threaded ***
> Traceback (most recent call last):
> File
> "/usr/local/lib/python3.6/site-packages/django/utils/module_loading.py",
> line 20, in import_string
> return getattr(module, class_name)
> AttributeError: module 'django.contrib.auth.middleware' has no attribute
> 'SessionAuthenticationMiddleware'
>
> The above exception was the direct cause of the following exception:
>
> Traceback (most recent call last):
> File "wsgi.py", line 38, in <module>
> application = get_wsgi_application()
> File "/usr/local/lib/python3.6/site-packages/django/core/wsgi.py", line
> 13, in get_wsgi_application
> return WSGIHandler()
> File
> "/usr/local/lib/python3.6/site-packages/django/core/handlers/wsgi.py", line
> 136, in __init__
> self.load_middleware()
> File
> "/usr/local/lib/python3.6/site-packages/django/core/handlers/base.py", line
> 34, in load_middleware
> middleware = import_string(middleware_path)
> File
> "/usr/local/lib/python3.6/site-packages/django/utils/module_loading.py",
> line 24, in import_string
> ) from err
> ImportError: Module "django.contrib.auth.middleware" does not define a
> "SessionAuthenticationMiddleware" attribute/class
> unable to load app 0 (mountpoint='') (callable not found or import error)
> *** no app loaded. going in full dynamic mode ***
> *** uWSGI is running in multiple interpreter mode ***
> spawned uWSGI master process (pid: 1)
> spawned uWSGI worker 1 (pid: 37, cores: 2)
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
> --- no python application found, check your startup logs for errors ---
>
> As per my investigation, this error possibly caused by Django upgrade:
>
> *The SessionAuthenticationMiddleware class is removed. It provided no
> functionality since session authentication is unconditionally enabled in
> Django 1.10.*
>
> See https://docs.djangoproject.com/en/2.0/releases/2.0/
>
> After I've removed the line
>
> https://github.com/maxking/docker-mailman/blob/master/postorius/mailman-web…
> from settings.py, the container is finally working.
>
> I've placed PR in github:
> https://github.com/maxking/docker-mailman/pull/314
>
>
> Thank you for your contributions!
>
> I have merged your pull request and it should now be out (hopefully!).
>
>
> Thank you for your help.
>
> Danil
>
>
> пт, 1 мар. 2019 г. в 04:33, Abhilash Raj <maxking(a)asynchronous.in>:
>
>
>
> On Thu, Feb 28, 2019, at 5:19 PM, Abhilash Raj wrote:
> > On February 27, 2019 11:53:34 PM PST, Danil Smirnov <danil(a)smirnov.la>
> wrote:
> > >Hi Mark,
> > >
> > >Actually all this stuff happens inside the container after it's started
> > >and
> > >initialized without errors. I didn't amend the image anyhow.
> > >
> > >Also I have the configuration based on docker-compose.yaml provided in
> > >the
> > >repository which works just fine for mailman-web image.
> > >
> > >The very same config with postorius image (+ UWSGI_STATIC_MAP param)
> > >fails
> > >with 500 error...
> > >
> > >Now answering your questions:
> > >
> > >ср, 27 февр. 2019 г., 22:56 Mark Sapiro <mark(a)msapiro.net>:
> > >
> > >> do you have django-q in INSTALLED_APPS in your Django settings and
> > >what
> > >> is set for Q_CLUSTER?
> > >>
> > >
> > >I've checked settings.py inside the container and I haven't found any
> > >of
> > >the mentioned configurations there.
> > >
> > >Does the manage.py that's being run here point to the right
> > >settings.py?
> > >>
> > >
> > >No clue.
> > >
> > >Also I wonder why we have some Hyperkitty-related cronjobs in non-HK
> > >configured image?
> > >
> > >
> https://github.com/maxking/docker-mailman/blob/master/postorius/mailman-web…
> >
> > Because I am a dum dum ;-)
> >
> > Will work on removing those crons and stuff. Would be nice if you
> > opened an issue on Github so that I don't forget.
>
> Should now be fixed in the latest image.
>
> >
> > >Danil
> > >
> > >
> > >
> > >> --
> > >> Mark Sapiro <mark(a)msapiro.net> The highway is for gamblers,
> > >> San Francisco Bay Area, California better use your sense - B.
> > >Dylan
> > >> _______________________________________________
> > >> Mailman-users mailing list -- mailman-users(a)mailman3.org
> > >> To unsubscribe send an email to mailman-users-leave(a)mailman3.org
> > >> https://lists.mailman3.org/mailman3/lists/mailman-users.mailman3.org/
> > >>
> > >_______________________________________________
> > >Mailman-users mailing list -- mailman-users(a)mailman3.org
> > >To unsubscribe send an email to mailman-users-leave(a)mailman3.org
> > >https://lists.mailman3.org/mailman3/lists/mailman-users.mailman3.org/
> >
> >
> > --
> > Sent from my Android device with K-9 Mail. Please excuse my brevity.
>
> --
> thanks,
> Abhilash Raj (maxking)
>
>
> --
> thanks,
> Abhilash Raj (maxking)
>
>
>
7 years, 6 months
[MM3-users] Re: HyperKitty async tasks runner: systemd qcluster service fails eventually
by actionmystique@gmail.com
Mark Sapiro wrote:
> Did you replace <django_project_path>, <user> and <group> with
> appropriate values?
Yes, I did, otherwise qcluster service would not be able to start in the first place because it needs to be able to read settings.py (with the proper permissions) which is located in the django project.
> They should be the same thing. Usually manage.py is just configured to
> run the django-admin command for the particular project.
You're right, running either command manually is successful and lead to the same result:
```
<django_project_path># python3 manage.py qcluster
10:49:41 [Q] INFO Q Cluster-1130205 starting.
10:49:41 [Q] INFO Process-1:1 ready for work at 1130235
10:49:41 [Q] INFO Process-1:2 ready for work at 1130236
10:49:41 [Q] INFO Process-1:3 ready for work at 1130237
10:49:41 [Q] INFO Process-1:4 ready for work at 1130238
10:49:41 [Q] INFO Process-1:5 monitoring at 1130239
10:49:41 [Q] INFO Process-1 guarding cluster at 1130234
10:49:41 [Q] INFO Q Cluster-1130205 running.
10:49:41 [Q] INFO Process-1:6 pushing tasks at 1130240
```
If I replace:
```
ExecStart=/usr/bin/django-admin qcluster --pythonpath <django_project_path>
--settings settings
```
with:
```
WorkingDirectory=<django_project_path>
ExecStart=python3 manage.py qcluster
````
I get the same systemd service issue.
If I remove the ``` remote-fs.target``` from ```After=...```, I get the following error:
```
# systemctl daemon-reload
# systemctl restart qcluster
# systemctl status qcluster
● qcluster.service - HyperKitty async tasks runner
Loaded: loaded (/etc/systemd/system/qcluster.service; enabled; vendor preset: enabled)
Active: active (running) since Thu 2019-12-05 11:08:54 CET; 282ms ago
Main PID: 1132324 (python3)
Tasks: 1 (limit: 9284)
Memory: 22.5M
CGroup: /system.slice/qcluster.service
└─1132324 python3 /usr/bin/django-admin qcluster --pythonpath <django_project_path> --settings settings
Dec 05 11:08:54 samsung4-ubuntu django-admin[1132324]: configure_logging(settings.LOGGING_CONFIG, settings.LOGGING)
Dec 05 11:08:54 samsung4-ubuntu django-admin[1132324]: File "/usr/lib/python3/dist-packages/django/utils/log.py", line 76, in configure_logging
Dec 05 11:08:54 samsung4-ubuntu django-admin[1132324]: logging_config_func(logging_settings)
Dec 05 11:08:54 samsung4-ubuntu django-admin[1132324]: File "/usr/lib/python3.7/logging/config.py", line 800, in dictConfig
Dec 05 11:08:54 samsung4-ubuntu django-admin[1132324]: dictConfigClass(config).configure()
Dec 05 11:08:54 samsung4-ubuntu django-admin[1132324]: File "/usr/lib/python3.7/logging/config.py", line 571, in configure
Dec 05 11:08:54 samsung4-ubuntu django-admin[1132324]: '%r' % name) from e
Dec 05 11:08:54 samsung4-ubuntu django-admin[1132324]: ValueError: Unable to configure handler 'file'
Dec 05 11:08:54 samsung4-ubuntu systemd[1]: qcluster.service: Main process exited, code=exited, status=1/FAILURE
Dec 05 11:08:54 samsung4-ubuntu systemd[1]: qcluster.service: Failed with result 'exit-code'.
```
This issue seems related to logging; I configured the following in ```/etc/mailman3/mailman.cfg```:
```
[logging.debian]
format: %(asctime)s (%(process)d) %(message)s
datefmt: %b %d %H:%M:%S %Y
propagate: no
level: debug
path: mailman.log
[logging.root]
level: debug
[logging.archiver]
level: debug
[logging.bounce]
level: debug
[logging.config]
level: debug
[logging.database]
level: debug
[logging.debug]
level: debug
[logging.error]
level: debug
[logging.fromusenet]
level: debug
[logging.http]
level: debug
[logging.locks]
level: debug
[logging.mischief]
level: debug
[logging.plugins]
level: debug
[logging.runner]
level: debug
[logging.smtp]
level: debug
[logging.subscribe]
level: debug
[logging.vette]
level: debug
```
6 years, 9 months
[MM3-users] Re: Confirmation emails to Users has wrong domain name (example.com!)
by Odhiambo Washington
On Thu, Sep 30, 2021 at 1:59 AM Abhilash Raj <maxking(a)asynchronous.in>
wrote:
>
>
> > On Sep 29, 2021, at 2:34 PM, Odhiambo Washington <odhiambo(a)gmail.com>
> wrote:
> >
> > On Wed, Sep 29, 2021 at 8:31 PM Mark Sapiro <mark(a)msapiro.net> wrote:
> >
> >> On 9/29/21 9:50 AM, Odhiambo Washington wrote:
> >>> 1. Confirmation emails to Users has wrong domain name (example.com!)
> >>> <https://docs.mailman3.org/en/latest/faq.html#id1>
> >>> <
> >>
> https://docs.mailman3.org/en/latest/faq.html#confirmation-emails-to-users-h…
> >>>
> >>>
> >>> This happens when your reverse (SSL) proxy isn’t setting up the correct
> >>> headers when proxying requests. Fix this by setting the right
> >>> proxy_set_header directives:
> >> ...
> >>> How is this supposed to be mitigated in Apache when using WSGI?
> >>>
> >>> My config:
> >>>
> >>> WSGIDaemonProcess hyperkitty threads=25 python-path=/usr/local/mailman
> >>> user=mailman group=mailman
> >>> WSGIPythonHome "/usr/local"
> >>> WSGIProcessGroup hyperkitty
> >>
> >>
> >> You are using mod_wsgi and not proxying at all, so this is not relevant
> >> in your case.
> >>
> >> Are you actually seeing this issue? If so, it might be related to
> >>
> >>
> https://docs.mailman3.org/en/latest/faq.html#the-domain-name-displayed-in-h…
> >>
> >
> > My issue is related to this, but the documentation referred to is not for
> > the faint-hearted!
> > I can't make head or tails of it.
>
> Click on “Domain” in Postorius from the top bar, which should take you to
> the Domains page.
>
> For your domain (in the “Mail Host” column), see the corresponding “Web
> Host” column, it should look something like:
>
> lists.mailman3.org (lists.mailman3.org)
> (Edit)
> SITE_ID = 1
>
Mine looks different, slightly. But there is no example.com at all.
[image: Abhilash.png]
>
> on a new-ish version of Postorius.
>
I have the newest versions of everything, having installed only yesterday.
>
> If it doesn’t show the right values and instead shows “example.com” for
> you, click on the “Edit” link, which will take
> you to a page that will allow you to edit both the values.
>
It shows the right values, but with "SITE_ID = 2". In my settings_local.py
I have SITE_ID = 1.
I suppose the example.com is the one tied to SITE_ID = 1 and that is what I
have in my settings_local.py.
Should I edit my settings_local.py?
I am still confused.
--
Best regards,
Odhiambo WASHINGTON,
Nairobi,KE
+254 7 3200 0004/+254 7 2274 3223
"Oh, the cruft.", egrep -v '^$|^.*#' :-)
4 years, 11 months
[MM3-users] Re: possible backscatter attack using Mailman3 servers
by Odhiambo Washington
On Sat, Jan 4, 2025 at 5:30 AM David Newman <dnewman(a)networktest.com> wrote:
>
>
> On 1/3/25 5:44 PM, Mark Sapiro wrote:
>
> >> Greetings. On a system running Mailman 3.3.9 and Postfix, I'm seeing
> >> about 20-30 entries per day in the Postfix queue where it appears a
> >> Gmail user signs up for a mailing list that requires confirmation, and
> >> Gmail responds that the user is too busy to handle requests.
> >>
> >> There are no publicly advertised email lists on this server, and I
> >> don't ever see anything in the Mailman logs indicating the user ever
> >> tried signing up.
> >
> >
> > This is an attack mail bombing the user. The requests that result in the
> > can come via web or email. Mailman's logging of subscribes has been
> > missing most events through Mailman 3.3.10. See https://gitlab.com/
> > mailman/mailman/-/issues/1143 which will be fixed in 3.3.11, but
> > subscribes waiting user confirmation still won't be logged.
> >
> > However, the message with subject "Please Confirm Your Email Address"
> > comes from Django allauth so it isn't actually Mailman sending it but
> > rather Django allauth as a result of a request to sign up for a Django
> > account at https://mail.example3.com/accounts/signup/. You can probably
> > find that request in your web server logs, and you may find the user
> > and/or email in the Django admin UI.
>
> Thanks VERY much for this.
>
> No such users in the Django UI, but the web server logs have 252
> attempts from 132 unique IPv4 addresses registered to different ISPs
> throughout Europe.
>
> So, even though Mailman support for more detailed logging of sub and
> unsub requests would be useful, it likely would not have helped with
> attacks from many source IP addresses.
>
> >
> > Since django-mailman3 1.3.6, you can disable these signups by putting
> >
> > ACCOUNT_ADAPTER =
> 'django_mailman3.views.user_adapter.DisableSignupAdapter'
> >
> > in your Django settings, but then your users won't be able to sign up
> > for web accounts.
>
> I have made this change. As for not having web accounts, this just means
> new users cannot sign up to manage their Mailman settings, correct? I
> presume existing web accounts will continue to work.
>
You could also try this:
https://lists.mailman3.org/archives/list/mailman-users@mailman3.org/message…
It really helped in many cases, although with the change you already made,
it becomes a useless effort.
--
Best regards,
Odhiambo WASHINGTON,
Nairobi,KE
+254 7 3200 0004/+254 7 2274 3223
In an Internet failure case, the #1 suspect is a constant: DNS.
"Oh, the cruft.", egrep -v '^$|^.*#' ¯\_(ツ)_/¯ :-)
[How to ask smart questions:
http://www.catb.org/~esr/faqs/smart-questions.html]
1 year, 8 months
[MM3-users] Re: [NON-INTERNAL] Re: Missing Archived emails - Hyperkitty - CERT Issue
by Willie Castillo
Odhiambo, long time no hear from you. Hope you are doing well.
The last archived post for that specific list is July 3rd. 2025. We do not see the one for July 25th. Also, I just noticed something else in the logs, apparently the server is still having "SSLCertVerificationError" issues even after updating the DigiCert, CA-Certificate,etc. I must be missing something else.
Based on that, looks like the archiving is failing still due to the "SSLCertVerificationError".
The spool directory now has 8 *.pck files in it. However, I do not see the original ones from 7/25
~# ll -t /opt/mailman/mm/var/archives/hyperkitty/spool/
-rw-rw---- 1 mailman mailman 14725 Jul 29 08:07 1753790859.2498085+320096cb9852779b55a4cbb1e4f9603736ebd78d.pck
-rw-rw---- 1 mailman mailman 15122 Jul 29 08:07 1753790859.2437658+7fddf881d592f27be60e32aa5b3c34c7077b9988.pck
-rw-rw---- 1 mailman mailman 6399 Jul 29 08:07 1753790859.2370558+ee410eb31691bf2854cca46c64e80e3bf61c3523.pck
-rw-rw---- 1 mailman mailman 26619 Jul 29 08:07 1753790859.230345+b2e70f5b65900731895bbee5a3d83401f1500567.pck
-rw-rw---- 1 mailman mailman 15676 Jul 29 08:07 1753790859.2225533+82371c8a0202d62eaa046dd3633a23d6837d7a80.pck
-rw-rw---- 1 mailman mailman 98273 Jul 29 08:07 1753790859.2136636+8ee9273fbbaf4352d482e69d177e2eb2824078a5.pck
-rw-rw---- 1 mailman mailman 98109 Jul 29 08:07 1753790859.2026713+49d82ecd57eda7eaa582ba925449e2343bea5c56.pck
-rw-rw---- 1 mailman mailman 88479 Jul 29 08:07 1753790859.191489+162aa89dcac50ca6f5463ce1098c828728af12d1.pck
________________________________
From: Odhiambo Washington <odhiambo(a)gmail.com>
Sent: Tuesday, July 29, 2025 7:59 AM
To: mailman-users(a)mailman3.org <mailman-users(a)mailman3.org>; Mark Sapiro <mark(a)msapiro.net>
Cc: Willie Castillo <Willie.Castillo(a)caemilusa.com>
Subject: Re: [MM3-users] Re: [NON-INTERNAL] Re: Missing Archived emails - Hyperkitty - CERT Issue
CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and know the content is safe.
On Tue, Jul 29, 2025 at 2:25 PM Willie Castillo <Willie.Castillo(a)caemilusa.com<mailto:Willie.Castillo@caemilusa.com>> wrote:
The issue started right after the site's CERT expired. The CERT expired on 7/8/25. This is what's in the log...
Jul 16 15:19:45 2025 (3777209) Connection to HyperKitty failed: HTTPSConnectionPool(host='XXX.com', port=443): Max retries exceeded with url: /hyperkitty/api/mailman/urls?mlist=jmats-versions%40XXX.com (Caused by SSLError(SSLCertVerificatio
nError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate has expired (_ssl.c:1000)')))
The CERT has been updated but the 7/25 message is not archived still.
While at it, also edit your /etc/mailman3/mailman-hyperkitty.cfg to what is documented so that the issue doesn't recur:
```
[general]
base_url: http://127.0.0.1:8000/archives/<https://urldefense.us/v3/__http://127.0.0.1:8000/archives/__;!!E8b8mVbrrfWV…>
api_key: Secret_Hyperkitty_API_Key
```
PS: I haven't seen your responses to @Mark Sapiro<mailto:mark@msapiro.net>'s questions quoted below:
```
Did the new post get archived? If so, why is last post at still July 25,
2025? If no, why not. The post must go to the archiver to cause the
queue to be processed.
If the post was archived and the July 25 messages are still queued,
what's in Mailman's mailman.log. There should be error messages and
tracebacks indicating the issue.
```
--
Best regards,
Odhiambo WASHINGTON,
Nairobi,KE
+254 7 3200 0004/+254 7 2274 3223
In an Internet failure case, the #1 suspect is a constant: DNS.
"Oh, the cruft.", egrep -v '^$|^.*#' ¯\_(ツ)_/¯ :-)
[How to ask smart questions: http://www.catb.org/~esr/faqs/smart-questions.html<https://urldefense.us/v3/__http://www.catb.org/*esr/faqs/smart-questions.ht…>]
1 year, 1 month
[MM3-users] Re: Splitting hosts: mta&core vs postorius
by Ruth Ivimey-Cook
Mark,
Thank you for your thoughts so far.
On 6/23/20 3:22 PM, Mark Sapiro wrote:
> I have done further testing. See my comment at
> <https://gitlab.com/mailman/mailman/-/issues/735#note_366074014>.
>
> You need to set hostname: in mailman.cfg to the actual external IP
> address of the Mailman host machine or to a name which resolves to that
> IP both internally and externally, and also set that host name/IP in the
> MAILMAN_REST_API_URL setting on the Postorius machine.
I've done that, but there is no observed change in the browser (still
get same 404 error).
Specifically, I reset hostname to be a newly-added CNAME of the actual
host address, and ensured that the 0.0.0.0 addresses were no longer there.
>
>> However I then get another issue. From the mailman.log file I now see in
>> the last few lines. For clarity I've numbered them like this "{1}":
>>
>> {1} [22/Jun/2020:00:58:24 +0000] "GET /3.1/domains HTTP/1.1" 200 320 "-"
>> "GNU Mailman REST client v3.3.1"
>> {2} [22/Jun/2020:00:58:24 +0000] "GET /3.1/domains/ch-bc.org.uk
>> HTTP/1.1" 200 215 "-" "GNU Mailman REST client v3.3.1"
>> {3} [22/Jun/2020:00:58:24 +0000] "GET
>> /3.1/domains/greyarea-web1.cam.ivimey.org/lists?advertised=true&count=0&page=1
>> HTTP/1.1" 404 26 "-" "GNU Mailman REST client v3.3.1"
>>
>> At this point the browser screen reports "Something went wrong" and the
>> message "HTTP Error 404: {"title": "404 Not Found"}"
> Make the above changes and see if that solves this. If not, let us know
> and we'll try to help.
A tcpdump now shows the GET of
/3.1/domains/mailman-web.ivimey.org/lists&advertised=true&count=0&page=1
directed at mailman-core and the reply being 404 not found.
The extract from core's mailman.log is now:
[24/Jun/2020:20:41:11 +0000] "GET
/3.1/domains/mailman-web.ivimey.org/lists?advertised=true&count=0&page=1
HTTP/1.1" 404 26 "-" "GNU Mailman REST client v3.3.1"
And the entry for postorius in mailmansuite.log:
ERROR 2020-06-24 21:41:11,191 13310 postorius Un-handled exception:
HTTP Error 404: {"title": "404 Not Found"}
Traceback (most recent call last):
File
"/opt/mailman3/lib/python3.6/site-packages/django/core/handlers/base.py",
line 113, in _get_response
response = wrapped_callback(request, *callback_args,
**callback_kwargs)
[snip]
File
"/opt/mailman3/lib/python3.6/site-packages/mailmanclient/restbase/page.py",
line 37, in __init__
self._create_page()
File
"/opt/mailman3/lib/python3.6/site-packages/mailmanclient/restbase/page.py",
line 62, in _create_page
response, content = self._connection.call(self._build_url())
File
"/opt/mailman3/lib/python3.6/site-packages/mailmanclient/restbase/connection.py",
line 116, in call
error_msg, response, None)
urllib.error.HTTPError: HTTP Error 404: {"title": "404 Not Found"}
Note that the mailman-web.ivimey.org address is the newly-added CNAME of
greyarea-web1, mailman-core is likewise the CNAME of greyarea-post.
There is nothing I can see in the other logs that looks out of the ordinary.
I guess this indicates that my earlier wondering if I had something left
over from a past install is dispelled, as that name didn't exist until
today.
6 years, 2 months
[MM3-users] Re: hyperkitty_import Unicode Errors
by kdhall@binghamton.edu
Stephen J Turnbull wrote:
> On 2023-05-07 07:39 Mark Sapiro writes:
> > On 5/6/23 11:27, Dave Hall via Mailman-users wrote:
> > > django.db.utils.OperationalError: (1366, "Incorrect string value:
> > '\xE1\x90\xA7\x0A\x0AO...' for column
> > mailman3web.hyperkitty_email.content at row 1")
> > Is there a known cause for this?
> > Almost always nonconforming user clients. You write "frequently", but
> I'm
> guessing it's maybe 1% or 2% of all the messages, right? I suspect it's
> a
> particular author or institution using such a client.
> > Is it fixed in some release more recent than 0+20180916?
> > This is almost surely not something we can fix. Based on the error,
> it's in third
> party code (Django) that we import. It's possible we could provide a
> more explanatory message, but the only thing we can sensibly do is hold
> the
> message for an admin to edit it by hand. As long as the text in
> question and the
> Content-Type header aren't too sensitive, we can help with identifying
> charset
> (often UTF-8 as Mark suggests but why someone would be encoding FINAL
> MIDDLE DOT is a mystery to me).
> > I'm not sure what's going on here. My first thought is the database is
> > MySQL or MariaDB and this is a 4-byte UTF-8 encoding and the database
> > column charset definition is utf8 and not utf8mb4, but
> > '\xE1\x90\xA7\x0A\x0A' is the 3-byte UTF-8 encoding for CANADIAN
> > SYLLABICS FINAL MIDDLE DOT ('\xE1\x90\xA7') followed by two
> > newlines. so I'm not sure what the issue is.
> > I'm guessing home-made client, possibly Asian or a spammer, which
> provides no
> content-type header. Even today I see raw 8-bit encoded text without an
> encoding
> spec from legitimate Japanese and Chinese sources, and of course with
> spammers
> all bets are off -- they might even do it deliberately to crash filters.
I have located an email with a similar error in a V2.1 .mbox file. The post was by a faculty member in my organization using Thunderbird 60.2.1 on a Mac - OSX 10.13. The list was used to correspond with students taking a programming course.
The message body is multi-part MIME with two sections:
This is a multi-part message in MIME format.
--------------4BAB6CD38F4927471D366565
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
and
--------------4BAB6CD38F4927471D366565
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit
The hexadecimal sting \\xEF\\xBB\\xBF\\xEF\\xBB\\xBF appears one place in each section.
I'm not sure exactly what this means. I did check my MariaDB (as Mark hinted) and found that it set for utf8 rather than utf8mb4. I'd be willing to change this, but would I also have to do something to update the Mailman databases since those tables are already created?
Thanks.
-Dave
3 years, 4 months
[MM3-users] Re: mail loops back to myself
by Florian Sukup
On 6/13/25 01:58, Mark Sapiro wrote:
> On 6/12/25 15:05, Florian Sukup wrote:
>>
>> I always restart mailman3 after changing main.cf
>
> I asked if you restarted/reloaded Postfix. I would assume that you had,
Sorry, I meant postfix which I restart after changing main.cf or master.cf.
> but I'm at a loss to understand the issue, unless your
> /etc/postfix/master.cf is missing an uncommented entry for lmtp like
> ```
> lmtp unix - - y - - lmtp
> ```
>
I found it there, here is my master.cf:
vvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
smtp inet n - y - - smtpd
submission inet n - y - - smtpd
-o syslog_name=postfix/submission
-o smtpd_tls_security_level=encrypt
-o smtpd_sasl_auth_enable=yes
-o smtpd_sasl_type=dovecot
-o smtpd_sasl_path=private/auth
-o smtpd_tls_auth_only=yes
-o smtpd_reject_unlisted_recipient=no
pickup unix n - y 60 1 pickup
cleanup unix n - y - 0 cleanup
qmgr unix n - n 300 1 qmgr
tlsmgr unix - - y 1000? 1 tlsmgr
rewrite unix - - y - - trivial-rewrite
bounce unix - - y - 0 bounce
defer unix - - y - 0 bounce
trace unix - - y - 0 bounce
verify unix - - y - 1 verify
flush unix n - y 1000? 0 flush
proxymap unix - - n - - proxymap
proxywrite unix - - n - 1 proxymap
smtp unix - - y - - smtp
relay unix - - y - - smtp
-o syslog_name=postfix/$service_name
showq unix n - y - - showq
error unix - - y - - error
retry unix - - y - - error
discard unix - - y - - discard
local unix - n n - - local
virtual unix - n n - - virtual
lmtp unix - - y - - lmtp
anvil unix - - y - 1 anvil
scache unix - - y - 1 scache
postlog unix-dgram n - n - 1 postlogd
maildrop unix - n n - - pipe
flags=DRXhu user=vmail argv=/usr/bin/maildrop -d ${recipient}
uucp unix - n n - - pipe
flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail
($recipient)
ifmail unix - n n - - pipe
flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)
bsmtp unix - n n - - pipe
flags=Fq. user=bsmtp argv=/usr/lib/bsmtp/bsmtp -t$nexthop -f$sender
$recipient
scalemail-backend unix - n n - 2 pipe
flags=R user=scalemail argv=/usr/lib/scalemail/bin/scalemail-store
${nexthop} ${user} ${extension}
mailman unix - n n - - pipe
flags=FRX user=list argv=/usr/lib/mailman/bin/postfix-to-mailman.py
${nexthop} ${user}
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
Is the last line a problem? It seems to be from mailman2.
Is there a possibility to debug in more detail? To find out when and
where it takes the wrong turn?
The system running has grown over many years and even if the hardware
changed the configuration was kept. So there may a flaw outside the
postfix/mailman configuration which causes the error, ie. network
configuration.
Another thing I can do is to upgrade from bullseye to bookworm. Which I
haven't done yet because I was with mailman2/sendmail. That's the reason
to change to mailman3/postfix. Since, mailman2 doesn't work anymore I
could do it and hope for a miracle ... . This would mean postfix 3.5.25
-> 3.7.11 and mailman3 3.3.3 -> 3.3.8 . That's more an act of desperation.
Thanks for your help,
Florian.
1 year, 3 months
[MM3-users] Re: Docker, Mailman 3, templates and list user accounts
by Abhilash Raj
Hi,
On Mon, Aug 7, 2017, at 06:06 AM, Henrik Rasmussen wrote:
> I used Docker to installed Mailman 3.
>
> The top header of the web interface says "Example.Com" while linking to
> the correct site URL (I believe coming from SERVE_FROM_DOMAIN). In a
> post[1], Mark Sapiro referred to the template system in Mailman 3 by
> pointing out that "a custom template can be put in
> var/templates/site/en/welcome.txt or
> var/templates/domains/example.com/en/welcome.txt<http://var/templates/domains/example.com/en/welcome.txt>
> or
> var/templates/lists/listname.example.com/en/welcome.txt<http://var/templates/lists/listname.example.com/en/welcome.txt>
> where var is Mailman's configured var_dir". I believe this refers to the
> mail templates.
Yes, these are email templates.
>
> 1) Where do I change the similar template system, for the web
> interface, without breaking a laver upgrade?
I am not sure if you can do that for now without tinkering with the
source code.
> 2) How do I change the site name in the top of the web interface on
> Mailman 3 to my subside and ?
When you deploy the web interface, the domain it is being served from is
used at the top of the web interface. It is defined by SITE_ID in the
settings.py file for Django (or settings_local.py if you are using the
container images). The default value is set to 1 and points to
example.com.
In the newer versions of Container Images, the SERVE_FROM_DOMAIN
environment variable's value will replace the `example.com` domain and
you will be able to see that instead of example.com.
For now, you should just login into the admin interface at /admin/ and
just create a new Site model. And then use the id of that Site in your
Django's settings.py. Each domain that you add gets their own id and
depending on which domain you are serving from, you can set the SITE_ID
in the settings. Mailman 3 supports multiple domains at the same time.
> [1]
> https://lists.mailman3.org/archives/list/mailman-users@mailman3.org/thread/…
>
>
>
> The Mailman command in Mailman Core doesn't seem to have a command for
> listing the accounts users have created by using Sign up in the web
> interface, so I believe that accounts may be created in the webinterface.
The Core and and Web frontend handle users separately. Ideally, a user
shouldn't have to worry about the Core ever and only interact with the
Web Interface.
> Is there similar commands for the web interface like the mailman commands
> for the Mailman core?
You can interact with the Django shell to get almost any internal data
structure. But you can go to the admin interface at /admin/ and you will
find the list of users there along with a whole lot of other
information.
>
> Regards, Henrik Rasmussen
> _______________________________________________
> Mailman-users mailing list
> mailman-users(a)mailman3.org
> https://lists.mailman3.org/mailman3/lists/mailman-users.mailman3.org/
--
thanks,
Abhilash Raj
9 years, 1 month