delegate rejects domains not in the list
  delegate rejects domains not in the list
___ hello yutaka, for example mails from mxpool* i could send you a prepared log file for analysis if you want to. greetz martin papadopoulos Yutaka Sato schrieb:
  08/07-02:34
___ Hi, Your mail including the whole REJECT list was posted to the open forum forwarded via, so I removed it from the spool. Well, your REJECT list includes a line as this: REJECT
  08/07-03:35
___ hello yutaka, works fine now , keep up the good work ! greetz martin papadopoulos Yutaka Sato schrieb:
Is there any way to control&limit user's Session&Connections when use delegate as socks 5 proxy?
  08/07-05:33 . 3454  liword <> [3]
___ Is there any way to control&limit user's Session&Connections when use delegate as socks 5 proxy?For example limit useA can create only 1 session to connect net at a time.
  08/07-08:01
___ There is no SOCKS specific control but a generic parameter to limit the max. number of connection from a host at a time as this: MAXIMA=conpch:1 This limitation can be applied only to a specified ho
  08/07-11:01
___ Hi, Limiting resource usage per user is a feature in the TODO list of DeleGate to be supported from the beginning. Now I feel it might be a time, so I tried to implement it (it will be released in 9
SPAM blocking by DeleGate (Re: delegate rejects domains not in the list)
  08/07-13:36 . 3457 (Yutaka Sato) [143]
___ Hi, By the way, if your intention is to block SPAMs, I don't recommend you to use the REJECT list based on domain name, since it is difficult to identify exaustless spammers by domain spreading over
  08/08-01:31
___ hello yutaka, it would be awesome if you could implement an smtp reject for non mx servers. i mean that if the reverse lookup entry does not contain a valid MX record, or to satisfy scenario of mult
  08/08-12:01
___ Hi, Doing access control based on the (existence of) MX record seems useful and I'll support it in the next release. But "callback" will be useful to be used together with it. Yes, spammers do not t
  08/08-12:26
___ Hi, I tested an extenstion like the enclosed patch with a parameter as follows: RELIABLE="_MX.*" It seems working as I expected to reject hosts without a MX record. It will be able to be extended to
  08/10-01:13
___ Hi, I uploaded 9.2.4-pre14 including SMTP extension as follows which may be useful in your case: <URL:> Cheers, Yutaka 9 9 Yutaka Sato <y.sato@del
  08/10-03:18
___ hello yutaka, its excelent ! best practice to me seems SMTPCONF=reject:nohelo+notmxhelo. greetz from germany ... :-) martin papadopoulos Yutaka Sato schrieb:
  08/11-03:35
___ hello yutaka, unfortunately there is some real bad news ! even companies like *b*y do not follow smtp protocol with ehlo , ehlo-mx and so forth. i don't recommend this setup , not even to your site,
  08/11-05:00
___ Hi, I'm not so surprised about it because I've seen so many broken HELO on SMTP for twenty years. But at least SMTPCONF=reject:nohelo is known practical because it is the default of DeleGate for six
MLSD vs. LIST when proxying
  MLSD vs. LIST when proxying
08/16-23:26
___ Hello, I have a Delegate FTP proxy forwarding requests to a Delegate master. Both DeleGate/9.2.3-pre12 . I connect to the proxy anonymously, then issue: cd //server dir using ncftp I get this result
delegate rewrite
  delegate rewrite
08/17-02:39
___ hello yutaka, is it possible with delegate as an http proxy , to rewrite the user-agent header ? greetz martin papadopoulos
MLSD vs. LIST when proxying
  MLSD vs. LIST when proxying
08/17-19:32
___ DeleGate announces that MLST/MLSD is availabe by default replying to the FEAT command from clients. It can be disabled with: FTPCONF=nomlsx Maybe it should be so by default when DeleGate is not acti
delegate rewrite
  delegate rewrite
08/17-20:41
___ Hi, Unconditional replacement of User-Agent to "xxx" is done as follows: HTTPCONF="kill-qhead:User-Agent" HTTPCONF="add-qhead:User-Agent:xxx" Cheers, Yutaka 9 9 Yutaka Sato <> htt
MLSD vs. LIST when proxying
  MLSD vs. LIST when proxying
08/18-19:11
___ Hello, Works like charme! I also grasp from the suggestion that there is no easy way to tranform LIST <-> MLSD on the fly. Bye, Steffen Kaiser
delegate multiple proxy
  delegate multiple proxy
08/23-03:54
___ hello yutaka, is it possible to have multiple proxies e.g. for different domains routed ? delegate -P8080 SERVER=http PROXY=dom1:8080:domain1 PROXY=dom2:8080 ... ? greetz
  08/23-10:28
___ Hi, Yes. Cheers, Yutaka 9 9 Yutaka Sato <> ( ~ ) National Institute of Advanced Industrial Science and Technology _< >_ 1-1-4 Umezono, Tsukuba, Ibaraki
ftp/sftp service not available
  ftp/sftp service not available
08/25-17:30
___ I have problems running the ftp/sftp gateway. ftp client says: "421 Service not available, remote server has closed connection". Detailed log of delegate below. The connection with command line sftp
Pop3proxy -- Timeout with malformed MimeMessages
  08/30-21:04 . 3473  Gateman <> [92]
___ Hi yutaka, we use delegate(V9.1.1)as a pop3proxy and have problems with some malformed mime messages. Delegate strips of some part of the message so that the client doesn't see the end of the messag
delegate article 3443
  delegate article 3443
08/30-22:13
___ hello yutaka, at least for the scenario authorizing delegate master process , the authorization does not function for the sockmux scenario it does work however . greetinx martin papadopoulos
Pop3proxy -- Timeout with malformed MimeMessages
  08/31-00:37 . 3475 (Yutaka Sato) [126]
___ Hi, Your dump shows it's not 0x20 but 0x00 which is a string terminator of C, and not 0E0D0A but 2E0D0A which is a message terminator of POP (and SMTP, NNTP). The problem is caused because DeleGate
  08/31-01:23
___ Hi, Sorry, I found that the patch is not enough for POP, and encoding a character into multi-bytes might cause another problem on the buffer boundary. So just ignoring '\0' might be the practical wo
  08/31-12:31
___ Hi, I released 9.2.4-pre20 with the workaround. It simply ignores '\0' in a messege by default. You can test to relay '\0' as is with an option MIMECONV="zero:utf8" Cheers, Yutaka 9 9 Yutaka Sato <y
MASTER authentication (Re: delegate article 3443)
  09/01-16:40 . 3478 (Yutaka Sato) [254]
___ Hi, It seems that I forgot not to have implemented the feature because I thoght it must be implemented for long time since the begining ;) Indeed, authentication with master DeleGate (AUTHORIZER + M
ftp/sftp gateway not working
  ftp/sftp gateway not working
09/04-17:39
___ Since there is no answer on my question 3472, I try it again. May be the subject was confusing. If I connect via ftp to delegate, ftp client says: "421 Service not available, remote server has close
DeleGate/9.2.4 (BETA) -- SOCKS over SSL, multiplexed SOCKS, fast MITM, HTTP cache
  09/06-07:28 . 3481 (Yutaka Sato) [149]
___ Dear DeleGate users, I inform you of the new release of DeleGate available as follows: DeleGate/9.2.4 -- SOCKS over SSL, multiplexed SOCKS, fast MITM, HTTP cache + SOCKS over SSL SOCKS has come to b
ftp/sftp gateway not working
  ftp/sftp gateway not working
09/06-12:06
___ Hi, What kind of FTP client are you using? It might be issueing something special command which causes the disconnection. You can see the sequence of commands and responses in the LOGFILE as the enc
  09/06-19:37
___ the It is the command line ftp from krb5-workstation-1.2.2-13 RPM under RedHat 7.2 . Below the -vd log. I cannot see the problem. Regards --Michi 09/06 12:14:11.30 [23612] 0+0: TMPFILE(new_shared) =
  09/06-22:30
___ Hi, Hmm... your login to the SFTP server seems simply rejected with bad password. It is possible that DeleGate fails to relay a password to the server when the password starts with some white space
  09/07-00:49
  09/07-01:02
___ Hmm... your reply is sent in strange format concatenating my message and yours and logs... Then seeing the difference between the logs for SFTP/HTTP and SFTP/FTP (with -dG) will help us to understan
  09/07-01:54
___ By the way, it is strongly recommended to invoke DeleGate by non-privileged users. If you need privilege for some reason, you should install "subin". <URL:
  09/07-17:14
___ and Sorry, hope now it is readable :-) I realize different host key fingerprints in the two dumps. In the http version it is the correct one from the sftp server. Here the failed ftp/sftp: 09/06 17:
  09/07-19:06
___ Hi, I found the problem. FTP-DeleGate is connecting to "sftp://localhost" regardless of the real SFTP server specified in the MOUNT parameter. The enclosed patch is a workaround to make FTP-DeleGate
  09/09-06:54
  09/14-19:18
___ I tried delegate9.2.5-pre2. The connection problem is solved. Thanks. But now the "cd" command seems not to work. After connecting "ls" gives the correct listing of users home. After "cd test" (the
  09/14-21:12
___ Hi, I could reproduce the problem on Linux. On MacOSX (or on BSD Unixes), it is shown as follows: --SFTPGW << [PWD][] --SFTP << pwd^M DeleGate for sftp/SSH gateway uses the sftp command via a Pty wh
  09/14-21:22
___ Yes. If you can do it with the sftp command directly invoked on your terminal, it is also available when the sftp command is indirectly invoked on a pty (pseudo terminal) via DeleGate. Cheers, Yutak
  09/15-17:33
___ The supplied patch works. Thanks for the quick support. Best Regards --Michi
  09/15-18:27
___ Something must be different. When I call sftp interactively the connection succeeds with public-key authentication. Within delegate, called from exactly the terminal where sftp is successful, there
delegate on multiple ips
  delegate on multiple ips
09/16-00:06
___ I have a Windows 2003 server with 5 ip addresses. i would like to set up an HTTP proxy on each ip address. I noticed the command line options to listen on all ports, but how do I configure delegate
ftp/sftp gateway not working
  ftp/sftp gateway not working
09/16-04:32
___ Hi, You invoked your DeleGate under the ownership of "nobody" thus the sftp is also invoked as of nobody. The simplest way to escape the problem is specfying OWNER=root, though I don't recommend it.
delegate on multiple ips
  delegate on multiple ips
09/16-23:13
___ If your "proxy server" means "reverse proxy server" then it can be configured as follows: SERVER=http MOUNT="/* http://server1/* via=" MOUNT="/* http://server2/* via=" Cheers, Yutaka
File download blocking
  File download blocking
09/20-12:21
___ Hi there, I was wondering if someone could help me with a config required to block ..exe and .mp3 files while using delegate. I have tried several configs using the rewrite mount commands in a confi
  09/22-07:30
___ Hi, It depends on the usage of your DeleGate. If you are using DeleGate as a HTTP proxy (with SERVER=http without other MOUNTs), it can be as follows basically: MOUNT="*%S.exe = forbidden" MOUNT="*%
