顯示具有 Program 標籤的文章。 顯示所有文章
顯示具有 Program 標籤的文章。 顯示所有文章

2011年9月5日 星期一

Configure static IPv6 networking under RHEL 5.x / Fedora / CentOS Linux

Red Hat / CentOS / Fedora RHEL support IPv6 out of box. All you have to do is update two files and turn on networking.
You need to update and configure following files for IPv6 configuration:
1.     /etc/sysconfig/network : Turn on networking in this file.
2.     /etc/sysconfig/network-scripts/ifcfg-eth0 : Set default IPv6 router IP and server IP address in this file.
Open /etc/sysconfig/network file, enter:# vi /etc/sysconfig/network
Append following line:
NETWORKING_IPV6=yes
Open /etc/sysconfig/network-scripts/ifcfg-eth0 (1st network config file)# vi /etc/sysconfig/network-scripts/ifcfg-eth0
Append following config directives for IPv6:
IPV6INIT=yes
IPV6ADDR=
IPV6_DEFAULTGW=
Here is my sample file with mix of IPv4 and IPv6 assigned to eth0:
DEVICE=eth0
BOOTPROTO=static
ONBOOT=yes
HWADDR=00:30:48:33:bc:33
IPADDR=202.54.1.5
GATEWAY=202.54.1.3
NETMASK=255.255.255.248
IPV6INIT=yes
IPV6ADDR=2607:f0d0:1002:0011:0000:0000:0000:0002
IPV6_DEFAULTGW=2607:f0d0:1002:0011:0000:0000:0000:0001
Where,
§  NETWORKING_IPV6=yes|no – Enable or disable global IPv6 initialization.
§  IPV6INIT=yes – Enable or disable IPv6 configuration for all interfaces.
§  IPV6ADDR=2607:f0d0:1002:0011:0000:0000:0000:0002 – Specify a primary static IPv6 address here.
§  IPV6_DEFAULTGW=2607:f0d0:1002:0011:0000:0000:0000:0001 – Add a default route through specified gateway.
Save and close the file. Restart networking:# service network restart
Verify your configuration by pinging ipv6 enabled site such as ipv6.google.com:$ ping6 ipv6.google.com
Sample output:
PING ipv6.google.com(2001:4860:b002::68) 56 data bytes
64 bytes from 2001:4860:b002::68: icmp_seq=1 ttl=59 time=93.2 ms
64 bytes from 2001:4860:b002::68: icmp_seq=2 ttl=59 time=95.0 ms
64 bytes from 2001:4860:b002::68: icmp_seq=3 ttl=59 time=94.2 ms
64 bytes from 2001:4860:b002::68: icmp_seq=4 ttl=59 time=95.2 ms
64 bytes from 2001:4860:b002::68: icmp_seq=5 ttl=59 time=94.8 ms
64 bytes from 2001:4860:b002::68: icmp_seq=6 ttl=59 time=95.1 ms
64 bytes from 2001:4860:b002::68: icmp_seq=7 ttl=59 time=93.3 ms
64 bytes from 2001:4860:b002::68: icmp_seq=8 ttl=59 time=93.8 ms

--- ipv6.google.com ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 7010ms
rtt min/avg/max/mdev = 93.268/94.376/95.268/0.799 ms
Traces path to a network host, enter:$ traceroute6 ipv6.google.com

IPv6


4.1 IPv6-ready kernel

現在的Linux發行版的核心都具備了運行IPv6的條件. IPv6功能被編譯成一個可載入模組. 在一般情況下模組不會在開機的時候自動載入.
參照更新的資訊: IPv6+Linux-Status-Distribution

檢察現在的系統是否支持IPv6

注意您的/proc-file-system.必需有如下的結構:


/proc/net/if_inet6


一個簡單的測試:


# test -f /proc/net/if_inet6 && echo "Running kernel is IPv6 ready"
 


如果失敗, 表明模組沒有載入.

試著載入模組

執行載入模組的命令:


# modprobe ipv6
  


如果成功, 模組會在列表中顯示,執行如下命令:


# lsmod |grep -w 'ipv6' && echo "IPv6 module successfully loaded"
 


讓模組自動載入

模組是可以自動載入的,只要在核心模組設定文件( /etc/modules.conf 或 /etc/conf.modules)中加入:


alias net-pf-10 ipv6  # automatically load IPv6 module on demand
 


也可以關掉IPv6模組的自動載入:


alias net-pf-10 off   # disable automatically load of IPv6 module on demand


編譯有 IPv6 功能的核心

如果以上兩個結果都證實了核心不具有IPv6功能, 您可以有如下選擇:
  • 升級成外包裝有IPv6支持說明的Linux發行版(推薦新手使用)再看一下這裡: IPv6+Linux-Status-Distribution
  • 編譯一個新的vanilla核心(如果您知道該怎麼選擇,會比較簡單).
  • 重新編譯您現在擁有的發行版核心(不太容易).
  • 將核心同 USAGI 的擴展一起編譯.
如果您決定編譯一個核心,您必需讀過 Linux Kernel HOWTO. 以及這方面的經驗.
注意:您必需使用核心2.4.x系列或更高. 因為IPv6對2.2.x系列缺少相應的支持. 並且需要ICMPv6 和 6to4 支持的補丁.(補丁可以在 kernel series 2.2.x IPv6 patches找到).

將核心同 USAGI 的擴展一起編譯.

只推薦熟悉核心編譯和IPv6的用戶使用. 參照: USAGI project / FAQ.

IPv6-ready network devices

不是所有的設備都有能力傳輸IPv6數據包, 這裡有一個現狀表: IPv6+Linux-status-kernel.html#transport.

現階段不會支持IPv6的連結

  • Serial Line IP (SLIP, RFC 1055), should be better called now to SLIPv4, device named: slX
  • Parallel Line IP (PLIP), same like SLIP, device names: plipX
  • ISDN with encapsulation rawip, device names: isdnX

在將來都不會支持IPv6的設備

  • ISDN with encapsulation syncppp, device names: ipppX (design issue of the ipppd, will be merged into more general PPP layer in kernel series 2.5.x)

4.2 IPv6-ready 網路設定工具

別扯太遠了, 如果您有一個正在運行IPv6的核心,怎麼會沒有設定的工具呢? 安裝包裡早就有幾個這樣的工具了.

net-tools package

net-tools package 包含一些工具如: ifconfig ,route. 這些可以令您在界面上設定IPv6. 在命令行(shell) 用ifocnig -? 或 route -? 查看諸如IPv6 或 inet6.如果有,則說明具備IPv6設定能力.
輸入以下命令進行檢查:


# /sbin/ifconfig -? 2>& 1|grep -qw 'inet6' && echo "utility 'ifconfig' is
?IPv6-ready"
 


也可以使用route:


# /sbin/route -? 2>& 1|grep -qw 'inet6' && echo "utility 'route' is IPv6-ready"


iproute package

Alexey N. Kuznetsov (Linux 網路代碼現階段的維護者) 寫了一個tool-set可以通過netlink 設備來設定網路.它可以比net-tool提供更多的功能, 但沒有多少文檔並且它不是為膽小的人設計的.


# /sbin/ip 2>&1 |grep -qw 'inet6' && echo "utility 'ip' is IPv6-ready"


如果沒有找到 /sbin/ip 那麼我極力推薦您安裝iproute package.

4.3 IPv6-ready 測試/調式 程式

在為IPv6準備好了系統後,您可以用IPv6進行網路通訊. 首先您必需學習如何用嗅探程式來檢查IPv6數據包. 強烈推薦這樣做,因為在debugging/troubleshooting 中有利於快速診斷.

IPv6 ping

這個程式一般在iputils包裡, 用來測試簡單傳輸發送 ICMPv6 回應請求並等待ICMPv6 回應包.
用法:


# ping6 < hostwithipv6address >
# ping6 < ipv6address >
# ping6 [-I < device >] < link-local-ipv6address > 


例子:


# ping6 -c 1 ::1 
PING ::1(::1) from ::1 : 56 data bytes 
64 bytes from ::1: icmp_seq=0 hops=64 time=292 usec
--- ::1 ping statistics --- 
1 packets transmitted, 1 packets received, 0% packet loss 
round-trip min/avg/max/mdev = 0.292/0.292/0.292/0.000 ms


提示 ping6必需有適當的root權限才能使用, 如果不是root組用戶,使用時可能產生問題:
1.ping6 不在用戶的路徑當中 (probably, because ping6 is generally stored in /usr/sbin -> add path (not really recommended)
2.ping6 不能被正確執行, 通常沒有適當的權限 chmod u+s /usr/sbin/ping6

為ping6指定界面

用local-addresses 作為ping6 目標必需指定一個界面. 否則核心將不知道數據包發往哪個設備. 在沒有指定的情況下會有這樣的輸出:


# ping6 fe80::212:34ff:fe12:3456 
connect: Invalid argument


為ping6指定界面的結果:


# ping6 -I eth0 -c 1 fe80::2e0:18ff:fe90:9205 
PING fe80::212:23ff:fe12:3456(fe80::212:23ff:fe12:3456) from
?fe80::212:34ff:fe12:3478 eth0: 56 data bytes 
64 bytes from fe80::212:23ff:fe12:3456: icmp_seq=0 hops=64 time=445 usec
--- fe80::2e0:18ff:fe90:9205 ping statistics --- 
1 packets transmitted, 1 packets received, 0% packet loss round-trip
?min/avg/max/mdev = 0.445/0.445/0.445/0.000 ms


Ping6 to multicast addresses(多播地址)

一個發現IPv6-active hosts 的比較有趣的機制:


# ping6 -I eth0 ff02::1 PING ff02::1(ff02::1) from fe80:::2ab:cdff:feef:0123 eth0: 56 data bytes
64 bytes from ::1: icmp_seq=1 ttl=64 time=0.104 ms
64 bytes from fe80::212:34ff:fe12:3450: icmp_seq=1 ttl=64 time=0.549 ms (DUP!) 


與IPv4不同的是, ping 的回應在廣播地址中是可以屏蔽的,目前只有IPv6防火牆可以做到.

IPv6 traceroute6

這個程式一般在iputils包裡, 和IPv4的traceroute程式相似, 但與當前版本不同的是IPv6不能正確地使用ICMP echo-request. 看下面這個例子:


# traceroute6 www.6bone.net 
traceroute to 6bone.net (3ffe:b00:c18:1::10) from 3ffe:ffff:0000:f101::2, 30
?hops max, 16 byte packets 
 1 localipv6gateway (3ffe:ffff:0000:f101::1) 1.354 ms 1.566 ms 0.407 ms 
 2 swi6T1-T0.ipv6.switch.ch (3ffe:2000:0:400::1) 90.431 ms 91.956 ms 92.377 ms 
 3 3ffe:2000:0:1::132 (3ffe:2000:0:1::132) 118.945 ms 107.982 ms 114.557 ms 
 4 3ffe:c00:8023:2b::2 (3ffe:c00:8023:2b::2) 968.468 ms 993.392 ms 973.441 ms 
 5 3ffe:2e00:e:c::3 (3ffe:2e00:e:c::3) 507.784 ms 505.549 ms 508.928 ms 
 6 www.6bone.net (3ffe:b00:c18:1::10) 1265.85 ms * 1304.74 ms


IPv6 tracepath6

這個程式一般在iputils包裡, 它用來追蹤MTU的路徑.看下面的例子:


# tracepath6 www.6bone.net 
 1?: [LOCALHOST] pmtu 1480 
 1: 3ffe:401::2c0:33ff:fe02:14 150.705ms 
 2: 3ffe:b00:c18::5 267.864ms 
 3: 3ffe:b00:c18::5 asymm 2 266.145ms pmtu 1280 
 3: 3ffe:3900:5::2 asymm 4 346.632ms 
 4: 3ffe:28ff:ffff:4::3 asymm 5 365.965ms 
 5: 3ffe:1cff:0:ee::2 asymm 4 534.704ms 
 6: 3ffe:3800::1:1 asymm 4 578.126ms !N 
Resume: pmtu 1280


IPv6 tcpdump

在Linux作業系統中 tcpdump 是主要的數據包捕獲工具.IPv6支持 3.6 的版本.
tcpdump用於降低數據包雜訊的參數:
  • icmp6: 過濾本地ICMPv6通訊.
  • ip6: 過濾本地IPv6通訊.(包括 ICMPv6)
  • proto ipv6: filters tunneled IPv6-in-IPv4 traffic
  • not port ssh: 在遠程SSH會話中禁止SSH數據包的顯示. to suppress displaying SSH packets for running tcpdump in a remote SSH session
使用命令行參數也可以從一個數據包中捕獲/列印資訊.
  • "-s 512": 增加捕獲限定為512 bytes.
  • "-vv": 詳細列印.
  • "-n": 不將地址轉換成名稱,在名稱服務有問題時可以用到.

IPv6 ping to 3ffe:ffff:100:f101::1 native over a local link



 # tcpdump -t -n -i eth0 -s 512 -vv ip6 or proto ipv6 
tcpdump: listening on eth0 
3ffe:ffff:100:f101:2e0:18ff:fe90:9205 > 3ffe:ffff:100:f101::1: icmp6: echo
?request (len 64, hlim 64) 
3ffe:ffff:100:f101::1 > 3ffe:ffff:100:f101:2e0:18ff:fe90:9205: icmp6: echo
?reply (len 64, hlim 64)


IPv6 ping to 3ffe:ffff:100::1 routed through an IPv6-in-IPv4-tunnel

1.2.3.4和5.6.7.8是遂道的終點(這些都是例子).


# tcpdump -t -n -i ppp0 -s 512 -vv ip6 or proto ipv6 
tcpdump: listening on ppp0 
1.2.3.4 > 5.6.7.8: 2002:ffff:f5f8::1 > 3ffe:ffff:100::1: icmp6: echo request
?(len 64, hlim 64) (DF) (ttl 64, id 0, len 124) 
5.6.7.8 > 1.2.3.4: 3ffe:ffff:100::1 > 2002:ffff:f5f8::1: icmp6: echo reply (len
?64, hlim 61) (ttl 23, id 29887, len 124) 
1.2.3.4 > 5.6.7.8: 2002:ffff:f5f8::1 > 3ffe:ffff:100::1: icmp6: echo request
?(len 64, hlim 64) (DF) (ttl 64, id 0, len 124) 
5.6.7.8 > 1.2.3.4: 3ffe:ffff:100::1 > 2002:ffff:f5f8::1: icmp6: echo reply (len
?64, hlim 61) (ttl 23, id 29919, len 124)


4.4 IPv6-ready programs(能和IPv6協同工作的程式)

在當前的發行版中已經包含了能和IPv6協同工作的程式(服務端/客戶端)參照: IPv6+Linux-Status-Distribution.或者檢查 http://www.bieringer.de/linux/IPv6/status/IPv6+Linux-status-apps.html一些可用程式的線索: IPv6 & Linux - HowTo - Part 3或 IPv6 & Linux - HowTo - Part 4.

4.5 IPv6-ready 客戶端程式 (selection)

想要進行下面的測試, 您的作業系統必需擁有IPv6能力. 有些例子是真實地連結了6bone的情況下做的.

檢查DNS對IPv6地址的解析能力

因為這幾年Domain Name System (DNS)安全的不斷升級, 它們中的大部份都具備了對IPv6 地址類型AAAA的解析能力. (新的類型A6 只有BIND9和更高的版本支持)檢查DNS對IPv6地址的解析能力:


# host -t AAAA www.join.uni-muenster.de


將得到下面的結果:


www.join.uni-muenster.de. is an alias for ns.join.uni-muenster.de. 
ns.join.uni-muenster.de. has AAAA address 3ffe:400:10:100:201:2ff:feb5:3806


IPv6-ready telnet clients

IPv6-ready telnet 客戶端. 對它進行一個簡單的測試:


$ telnet 3ffe:400:100::1 80
Trying 3ffe:400:100::1... 
Connected to 3ffe:400:100::1. 
Escape character is '^]'. 
HEAD / HTTP/1.0
HTTP/1.1 200 OK 
Date: Sun, 16 Dec 2001 16:07:21 
GMT Server: Apache/2.0.28 (Unix) 
Last-Modified: Wed, 01 Aug 2001 21:34:42 GMT 
ETag: "3f02-a4d-b1b3e080" 
Accept-Ranges: bytes 
Content-Length: 2637 
Connection: close 
Content-Type: text/html; charset=ISO-8859-1
Connection closed by foreign host.


如果telnet只出現"cannot resolve hostname", 說明作業系統的IPv6還未激活.

openssh

openssh已經支持IPv6, 但必需對它用以下的參數進行編譯後才能使用:
  • --without-ipv4-default: the client tries an IPv6 connect first automatically and fall back to IPv4 if not working
  • --with-ipv4-default: default connection is IPv4, IPv6 connection must be force like following example shows:


$ ssh -6 ::1 
user@::1's password: ****** 
[user@ipv6host user]$


如果您的ssh不能對 -6 進行反應, 可能作業系統的IPv6還未激活,或ssh的版本太低.

ssh.com

他們的客戶/服務端程式是免費的.

IPv6-ready web 流覽器

目前支持IPv6的web 流覽器列表: IPv6+Linux-status-apps.html#HTTP.
這些流覽器大部份都存在問題:
  • 如果 proxy(代理)只支持IPv4, IPv6的請求將會失敗. 方法: 升級proxy
  • Automatic proxy settings (*.pac) 不能對IPv6的不同請求進行適當的處理 (written in Java-script and well hard coded in source like to be seen in Maxilla source code).
一些早期的版本不能對IPv6地址進行正確的操作, 如: http://[3ffe:400:100::1]/
一個小測試,顯示在沒有代理的情況下的 URL 和 流覽器.

URLs for testing

測試IPv6最方便的方法是訪問: http://www.kame.net/. 如果海龜是活動的, 說明連接是通過IPv6進行的, 它不動的話, 說明連接是通過IPv4進行的.

4.6 IPv6-ready server 程式

包括:sshd, httpd, telnetd,

2011年6月23日 星期四

Removing the WMI Provider

To remove the WMI Provider
1.      Launch wbemtest.exe.
2.      Click Connect.
3.      Type root\default as the namespace, and then click Connect.
4.      Click Delete Class.
5.      Enter the class name and follow the prompts to delete the class.
6.      Remove the following registry keys created by the WMI provider:

2011年4月27日 星期三

System — UUID

System — UUID

A UUID is an identifier that is designed to be unique across both time and space, and requires no central registration
process. The UUID is 128 bits long. Its format is described in RFC 4122, but the actual field contents are opaque
and not significant to the SMBIOS specification, which is only concerned with the byte order. The following field
names, particularly for multiplexed fields, follow historical practice:
Offset
RFC 4122  Name
Length
Value
Description

00h
time_low
DWORD
Varies
The low field of the timestamp

04h
time_mid
WORD
Varies
The middle field of the timestamp
06h
time_hi_and_version
WORD
Varies
The high field of the timestamp multiplexed with the version number

08h
clock_seq_hi_and_reserved
BYTE
Varies
The high field of the clock sequence multiplexed with the variant
09h
clock_seq_low
BYTE
Varies
The low field of the clock sequence
0Ah
Node
6 BYTEs
Varies
The spatially unique node identifier


Although RFC 4122 recommends network byte order for all fields, the PC industry (including the ACPI, UEFI, and
Microsoft specifications) has consistently used little-endian byte encoding for the first three fields: time_low,
time_mid, time_hi_and_version. The same encoding, also known as wire format, should also be used for the
SMBIOS representation of the UUID.
The UUID {00112233-4455-6677-8899-AABBCCDDEEFF} would thus be represented as 33 22 11 00 55 44 77 66
88 99 AA BB CC DD EE FF.
If the value is all FFh, the ID is not currently present in the system, but can be set. If the value is all 00h, the ID is
not present in the system.

2011年4月7日 星期四

FRU (Field Replaceable Unit)

FRU (Field Replaceable Unit)
        A Field Replaceable Unit or FRU is a circuit board, part or assembly that can be quickly and easily removed from a personal computer or other piece of electronic equipment, and replaced by the user or a technician without having to send the entire product or system to a repair facility. FRUs allow a technician lacking in-depth product knowledge to fault isolate and replace faulty components.
       
        A typical desktop computer is composed almost entirely of FRUs, including:
        - Power supply units
        - Motherboards
        - socketed microprocessors
        - primary storage modules
                - RAM
        - secondary storage devices
                - hard drives
                - optical drives
                - floppy drives
        - Bus devices
                - video cards
                - sound cards
        - Cooling fans
        - Peripherals
                - keyboards
                - mice
                - printers
                -connecting cabless

2011年3月28日 星期一

New Features Included with IntelR AMT 7.0 SDK:

Host-Based Setup and Configuration
• This key Intel® AMT 7.0 platform feature is fully documented and includes samples, use cases and snippets (see below) that demonstrate the feature.
• The SDK also supports the related User Consent feature with samples, a GUI-based tool, and extensive documentation.

Snippets Added to Intel AMT Feature Use Cases
• Nearly 300 snippets – short samples of code that demonstrate a step or sequence of steps in a use case – were added to the SDK documentation.
• The snippets are written using PowerShell 2.0. They depend on a framework called the IntelvProModule located at <SDK_root>\Windows\Common\WS-Management\Scripting Framework.
• You can exercise a snippet opposite a configured Intel AMT platform by copying the snippet into a supplied template.
• The snippets support backward compatibility and demonstrate, where necessary, the difference between Intel AMT versions, back to Release 3.2. They were validated against Releases 3.2, 4, 5, 5.1, 6, 6.1 and 7.0.

Change From Traversal to Selectors Using a Key
• The Use Case flows now, in most cases, locate the instance of a class using one or more key properties, rather than starting with an instance of CIM_ComputerSystem and traversing associations to locate the pertinent object. The snippets use this approach in their implementation.

KVM
• Update to the RealVNC Library 
1. A new version of the RealVNC library was added to the SDK. This solves some open issues and makes several protocol features available for Intel AMT applications.
2. The SDK documentation includes a spreadsheet showing the features in the RealVNC library that Intel AMT supports.
• The samples and library support screen rotation.
• The Digest authentication mechanism was upgraded.
• The KVM library error reporting was improved.

Redirection Library
• The Windows Redirection library now supports DVDs. The DVD feature is compatible with Intel AMT Releases 7.0 and later releases. The library is compatible with all versions of Intel AMT.
• The library supports the link preference feature, including an option for legacy behavior, used with earlier releases that do not support link preference.
• The Digest authentication mechanism was upgraded.

Intel(R) vPro(TM) Gateway, also known as the Management Presence Server (MPS)
• The SDK contains a new version of the MPS and, for the first time, includes the MPS source code.
• Documentation of the Intel(R) vPro(TM) Gateway reflects the latest MPS API.
• A new sample, the MPSInterFaceClient, demonstrates the API.

Other Documentation Changes
• The Setup and Configuration documentation was reorganized. 
• Documentation for Local Call for Help (also known as Client Initiated Local Access, or CILA) was added to the Remote Access Configuration section.
• The documentation describes the Digest Master Password concept, with snippets. It demonstrates how to implement a master password that is used to create a unique admin password for each Intel AMT platform.
• The documentation provides a flow that shows how to use the Release 7.0 certificate enrollment feature, used to create a server certificate request for Intel AMT that does not expose the private key. 
• The documentation contains a list of deprecated and deleted features across all versions.

Deprecated EOI (SOAP) Samples Moved
• The SOAP samples, documentation, Storage library, Crypt32Api and most associated files were moved to a ZIP archive in the SDK root directory.
• The SDK general documentation was modified to reflect this change. Most references to SOAP commands were removed.
• Certain samples that use SOAP (the sample setup and configuration application, the MPS notification sample, the redirection GUI sample and the AMTRedirection sample) remain in their respective directories.
• The WSDLs and other common files remain in place in support of these samples.

Other Updates
• The SDK includes an Event ID-to-string library that supports notifications from the event log. Go to <SDK_Root>\DOCS\Scripts\Alert Messages to see the XML file and a sample script.
• The Access Monitor sample now supports the new bulk load of audit log event definitions.
• The SDK recognizes that Intel AMT Release 7.0 can support a wireless interface on a desktop platform.
• The USBFile sample supports host-based setup and also a "scramble" mode.
• The Setup and Configuration Application, the MPS Notification sample, and the Audit Log sample have been updated to use OpenSSL version 1.0.0.

2011年3月22日 星期二

SMTP Command


Part 1:
 
Basic SMTP Commands
 
Below are the basic SMTP commands described. All SMTP servers that follows the SMTP protocol specification must support these basic commands.
 
HELO 
(Hello)
The client sends this command to the SMTP server to identify itself and initiate the SMTP conversation. The domain name or IP address of the SMTP client is usually sent as an argument together with the command (e.g. "HELO client.example.com"). If a domain name is used as an argument with the HELO command, it must be a fully qualified domain name (also called FQDN).
 
MAIL FROM
Specifies the e-mail address of the sender. This command also tells the SMTP server that a new mail transaction is starting and makes the server to reset all its state tables and buffers etc. This command is usually sent as the first command after the identifying and login process. If the senders e-mail address is accepted the server will reply with a 250 OK reply code. Example:
 
C: MAIL FROM:<mail@samlogic.com>
S: 250 OK
 
RCPT TO 
(Recipient To)
Specifies the e-mail address of the recipient. This command can be repeated multiple times for a given e-mail message in order to deliver a single e-mail message to multiple recipients. The example below shows how this command can be used to send same e-mail message to two recipients:
 
C: MAIL FROM:<mail@samlogic.com>
S: 250 OK
C: RCPT TO:<john@mail.com>
S: 250 OK
C: RCPT TO:<peggy@mail.com>
S: 250 OK
 
DATA
The DATA command starts the transfer of the message contents (body text, attachments etc). After that the DATA command has been sent to the server from the client, the server will respond with a 354 reply code. After that, the message contents can be transferred to the server. When all message contents have been sent, a single dot (".") must be sent in a line by itself. If the message is accepted for delivery, the SMTP server will response with a 250 reply code. Example (the message contents is set to italic in the example below):
 
C: DATA
S: 354 Send message content; end with <CRLF>.<CRLF>
C: Date: Thu, 21 May 2008 05:33:29 -0700
C: From: SamLogic <mail@samlogic.com>
C: Subject: The Next Meeting
C: To: john@mail.com
C:
C: Hi John,
C: The next meeting will be on Friday.
C: /Anna.
C: .
S: 250 OK
 
RSET 
(Reset)
If the RSET command is sent to the e-mail server the current mail transaction will be aborted. The connection will not be closed (this is reserved for the QUIT command, see below) but all information about the sender, recipients and e-mail data will be removed and buffers and state tables will be cleared.
 
VRFY 
(Verify)
This command asks the server to confirm that a specified user name or mailbox is valid (exists). If the user name is asked, the full name of the user and the fully specified mailbox are returned. In some e-mail servers the VRFY command is ignored because it can be a security hole. The command can be used to probe for login names on servers. Servers that ignore the VRFY command will usually send some kind of reply, but they will not send the information that the client asked for.
 
NOOP 
(No operation)
The NOOP command does nothing else than makes the receiver to send an OK reply. The main purpose is to check that the server is still connected and is able to communicate with the client. 
 
QUIT
Asks the server to close the connection. If the connection can be closed the servers replies with a 221 numerical code and then is the session closed.
 
 
Example - How To Use Basic SMTP Commands
 
The example below shows how some of the basic SMTP commands described in this page can be used to send an e-mail message trough an SMTP server to a recipient.
 
S: 220 smtp.server.com Simple Mail Transfer Service Ready
C: HELO client.example.com
S: 250 Hello client.example.com
C: MAIL FROM:<mail@samlogic.com>
S: 250 OK
C: RCPT TO:<john@mail.com>
S: 250 OK
C: DATA
S: 354 Send message content; end with <CRLF>.<CRLF>
C: <The message data (body text, subject, e-mail header, attachments etc) is sent>
C: .
S: 250 OK, message accepted for delivery: queued as 12345
C: QUIT
S: 221 Bye
 
In the example above an e-mail message is sent from mail@samlogic.com to john@mail.com. The senders e-mail address is specified by the MAIL FROM command and the recipients e-mail address is specified by the RCPT TO command. The DATA command informs the server that now will the message data be sent (e-mail header, body text etc). The single dot below the message contents informs the SMTP server when the message data ends. After a single dot has been sent to the server and the server has responded, a QUIT command is sent to terminate the session.
 
 
Part 2:
 
Extended SMTP (ESMTP) Commands
 
If a client initiates the SMTP communication using an EHLO (Extended Hello) command instead of the HELO command some additional SMTP commands are often available. They are often referred to as Extended SMTP (ESMTP) commands or SMTP service extensions. Every server can have its own set of extended SMTP commands. After the client has sent the EHLO command to the server, the server often sends a list of available ESMTP commands back to the client.
 
EHLO 
(Extended Hello)
Same as HELO but tells the server that the client may want to use the Extended SMTP (ESMTP) protocol instead. EHLO can be used although you will not use any ESMTP command. And servers that do not offer any additional ESMTP commands will normally at least recognize the EHLO command and reply in a proper way.
 
AUTH 
(Authentication)
The AUTH command is used to authenticate the client to the server. The AUTH command sends the clients username and password to the e-mail server. AUTH can be combined with some other keywords as PLAIN, LOGIN and CRAM-MD5 (e.g. AUTH LOGIN) to use different login methods and different levels of security. 
 
The example below shows how AUTH LOGIN can be used to make an authenticated login:
 
S: 220 smtp.server.com Simple Mail Transfer Service Ready
C: EHLO client.example.com
S: 250-smtp.server.com Hello client.example.com
S: 250-SIZE 1000000
S: 250 AUTH LOGIN PLAIN CRAM-MD5
C: AUTH LOGIN
S: 334 VXNlcm5hbWU6
C: adlxdkej
S: 334 UGFzc3dvcmQ6
C: lkujsefxlj
S: 235 2.7.0 Authentication successful
 
After that the AUTH LOGIN command has been sent to the server, the server asks for username and password by sending BASE64 encoded text (questions) to the client. "VXNlcm5hbWU6" is the BASE64 encoded text for the word "Username" and "UGFzc3dvcmQ6" is the BASE64 encoded text for the word "Password" in the example above. The client sends username and password also using BASE64 encoding. "adlxdkej", in the example above, is a BASE64 encoded username and "lkujsefxlj" is a BASE64 encoded password.
 
More detailed information about the AUTH command is available on this reference page: The AUTH Command. 
 
STARTTLS 
(Start Transport Layer Security)
E-mail servers and clients that uses the SMTP protocol normally communicate using plain text over the Internet. The communication often goes through one or more routers that is not controlled or trusted by the server and client. This communication can be monitored and it is also possible to alter the messages that are sent via the routers.
 
To improve security, an encrypted TLS (Transport Layer Security) connection can be used when communicating between the e-mail server and the client. TLS is most useful when a login username and password (sent by the AUTH command) needs to be encrypted. TLS can be used to encrypt the whole e-mail message, but the command does not guarantee that the whole message will stay encrypted the whole way to the receiver; some e-mail servers can decide to send the e-mail message with no encryption. But at least the username and password used with the AUTH command will stay encrypted. Using the STARTTLS command together with the AUTH command is a very secure way to authenticate users.
 
The example below shows how to combine the STARTTLS and AUTH LOGIN command to make a secure login to an e-mail server (S = Server, C = Client):
 
S: 220 smtp.server.com Simple Mail Transfer Service Ready
C: EHLO client.example.com
S: 250-smtp.server.com Hello client.example.com
S: 250-SIZE 1000000
S: 250-AUTH LOGIN PLAIN CRAM-MD5
S: 250-STARTTLS
S: 250 HELP
C: STARTTLS
S: 220 TLS go ahead
C: EHLO client.example.com *
S: 250-smtp.server.com Hello client.example.com
S: 250-SIZE 1000000
S: 250-AUTH LOGIN PLAIN CRAM-MD5
S: 250 HELP
C: AUTH LOGIN
S: 334 VXNlcm5hbWU6
C: adlxdkej
S: 334 UGFzc3dvcmQ6
C: lkujsefxlj
S: 235 2.7.0 Authentication successful
C: MAIL FROM:<mail@samlogic.com>
S: 250 OK
C: RCPT TO:<john@mail.com>
S: 250 OK
C: DATA
S: 354 Send message, end with a "." on a line by itself
C: <The message data (body text, subject, e-mail header, attachments etc) is sent>
S .
S: 250 OK, message accepted for delivery: queued as 12345
C: QUIT
S: 221 Bye
  
*) The client sends the EHLO command again to the e-mail server and starts the communication from the beginning, but this time the communication will be encrypted until the QUIT command is sent.
 
SIZE
The SIZE command has two purposes. The SMTP server can inform the client what is the maximum message size and the client can inform the SMTP server the (estimated) size of the e-mail message that will be sent. The client should not send an e-mail message that is larger than the size reported by the server, but normally it is no problem if the message is somewhat larger than the size informed by the client to the server.
 
The example below shows how a server (S) and client (C) reports size to each other:
 
S: 250 SIZE 1000000
C: MAIL FROM:<mail@samlogic.com> SIZE=500000
 
The client sends the SIZE command, and size information, together with the MAIL FROM command. The server sends the command and size information alone. The size is always specified in bytes.
 
HELP
This command causes the server to send helpful information to the client, for example a list of commands that are supported by the SMTP server.