Postfix 02 - Debian 4 - Postfix + SASL + TLS
Postfix Mail Server Learning · Previous: a basic installation · Next: Debian 4 - A mail server for an ISP
The Slovak original of this document: Postfix 02 - Debian 4 - Postfix + SASL + TLS (slovensky).
|=--------------------------=[ Postfix + SASL + TLS ]=---------------------=| +---------------------------------------------------------------------------+ | | | Installing Postfix with SASL + TLS authentication support | | Debian 4.0 Etch | | | +---------------------------------------------------------------------------+ |=-------------------------------=[ BH 2007 ]=-----------------------------=| Configuring postfix with SASL authentication support. SASL is set up so that the user authenticates through PAM, that is, with their own account password. Since this data travels over the network unencrypted, we will use SSL as well.
Requisites
# apt-get install postfix libsasl2 sasl2-bin libsasl2-modules libdb3-util procmail
Reconfiguring postfix
# dpkg-reconfigure postfix
--------------------------
General type of configuration? <-- Internet Site
Where should mail for root go <-- [empty]
Mail name? <-- server1.example.com
Other destinations to accept mail for? (blank for none) <-- server.domena.sk, localhost.domena.sk, localhost.localdomain, localhost
Force synchronous updates on mail queue? <-- No
Local networks? <-- 127.0.0.0/8
Use procmail for local delivery? <-- Yes
Mailbox size limit <-- 0
Local address extension character? <-- +
Internet protocols to use? <-- allConfiguring postfix SASL
# postconf -e 'smtpd_sasl_local_domain ='
# postconf -e 'smtpd_sasl_auth_enable = yes'
# postconf -e 'smtpd_sasl_security_options = noanonymous'
# postconf -e 'broken_sasl_auth_clients = yes'
# postconf -e 'smtpd_recipient_restrictions = permit_sasl_authenticated,permit_mynetworks,reject_unauth_destination'
# postconf -e 'inet_interfaces = all'
# echo 'pwcheck_method: saslauthd' >> /etc/postfix/sasl/smtpd.conf
# echo 'mech_list: plain login' >> /etc/postfix/sasl/smtpd.conf
Since postfix runs chrooted in /var/spool/postfix, SASL has to go into the jail as well.
----------------------------------------------------------------------------------------
# mkdir -p /var/spool/postfix/var/run/saslauthd
We edit the file /etc/default/saslauthd and thereby turn SASL on. We set the directive
START=yes
and change the line
OPTIONS="-c" to OPTIONS="-c -m /var/spool/postfix/var/run/saslauthd -r"
We restart the SASL daemon
--------------------------
# /etc/init.d/saslauthd startTLS (creating the certificates)
# mkdir /etc/postfix/ssl
# cd /etc/postfix/ssl/
# openssl genrsa -des3 -rand /etc/hosts -out smtpd.key 1024
# chmod 600 smtpd.key
# openssl req -new -key smtpd.key -out smtpd.csr
------------------------------------------------
Country Name (2 letter code) [AU]:SK
State or Province Name (full name) [Some-State]:Slovakia
Locality Name (eg, city) []:Mesto
Organization Name (eg, company) [Internet Widgits Pty Ltd]:domena.sk
Organizational Unit Name (eg, section) []:
Common Name (eg, YOUR name) []:server.domena.sk
Email Address []:postmaster@domena.sk
Please enter the following 'extra' attributes
to be sent with your certificate request
A challenge password []: empty
An optional company name []: empty
------------------------------------------------
# openssl x509 -req -days 3650 -in smtpd.csr -signkey smtpd.key -out smtpd.crt
# openssl rsa -in smtpd.key -out smtpd.key.unencrypted
# mv -f smtpd.key.unencrypted smtpd.key
# openssl req -new -x509 -extensions v3_ca -keyout cakey.pem -out cacert.pem -days 3650Configuring postfix TLS
# postconf -e 'smtpd_tls_auth_only = no'
# postconf -e 'smtp_use_tls = yes'
# postconf -e 'smtpd_use_tls = yes'
# postconf -e 'smtp_tls_note_starttls_offer = yes'
# postconf -e 'smtpd_tls_key_file = /etc/postfix/ssl/smtpd.key'
# postconf -e 'smtpd_tls_cert_file = /etc/postfix/ssl/smtpd.crt'
# postconf -e 'smtpd_tls_CAfile = /etc/postfix/ssl/cacert.pem'
# postconf -e 'smtpd_tls_loglevel = 1'
# postconf -e 'smtpd_tls_received_header = yes'
# postconf -e 'smtpd_tls_session_cache_timeout = 3600s'
# postconf -e 'tls_random_source = dev:/dev/urandom'
# postconf -e 'myhostname = server.domena.sk'Postfix restart
# /etc/init.d/postfix restart
OUTLOOK EXPRESS
tools -> accounts -> mail -> account_name -> servers -> log_on_using_secure_password_authentication = check
tools -> accounts -> mail -> account_name -> servers -> my_server_requires_authentication = check
tools -> accounts -> mail -> account_name -> advanced -> this_server_requires_a_secure_connection(SSL) = check
============================================================================================
Setting postfix up to authenticate using SASL when it connects to another SMTP server
that requires authentication. When postfix wants to connect to the server mail.domena.sk,
the login and password from the file /etc/postfix/sasl_passwd are used
============================================================================================
# touch /etc/postfix/sasl_passwd
# nano /etc/postfix/sasl_passwd
-------------------------------
domena.sk ucet:heslo
# postmap /etc/postfix/sasl_passwd
# nano /etc/postfix/main.cf
---------------------------
smtp_sasl_auth_enable=yes
smtp_sasl_password_maps=hash:/etc/postfix/sasl_passwd
# /etc/init.d/postfix reloadRelaying to an SMTPS server using postfix and stunnel
Install stunnel
---------------
# apt-get install stunnel4
Adding the user and group smtps
-------------------------------
# groupadd smtps
# useradd -d /dev/null -g smtps -s /bin/false smtps
We start stunnel in client mode for the smtp protocol, listening on localhost:465 and
connecting to the remote machine mail.client23.example:465 as the user and group smtps.
------------------------------------------------------------------------------------
# stunnel -c -d 127.0.0.1:465 -o /var/log/SMTPS_tunnel.log -n smtp -s smtps -g smtps -r mail.client23.example:465
# touch /etc/postfix/sasl_passwd
# nano /etc/postfix/sasl_passwd
-------------------------------
localhost ucet@server:HESLO
# postmap /etc/postfix/sasl_passwd
# nano /etc/postfix/main.cf
---------------------------
relayhost = localhost:465
smtp_sasl_auth_enable=yes
smtp_sasl_password_maps=hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options = noanonymous
smtp_use_tls = no
# /etc/init.d/postfix reloadCurrent practice (checked 2026-10)
noteThe article above is kept as it was written in 2008. This section lists what has changed since and what to do instead today.
smtpd_use_tlsandsmtp_use_tls: both have been superseded since Postfix 2.3 and are deprecated as of Postfix 3.9; Postfix logs that support for them will be removed. Usesmtpd_tls_security_level = mayandsmtp_tls_security_level = mayinstead.smtpd_tls_auth_only = no: withmech_list: plain loginthis lets clients send the system (PAM) password over an unencrypted connection, which is what the article set out to avoid. Setsmtpd_tls_auth_only = yes.- AUTH on port 25: today client submission is kept apart from MX traffic: a
submission(587, STARTTLS) orsubmissions(465, implicit TLS) service inmaster.cfwithsmtpd_tls_security_level=encryptandsmtpd_sasl_auth_enable=yes, and no AUTH offered on port 25. RFC 8314 recommends offering both ports and TLS 1.2 or later for clients. - Certificate: a 1024-bit RSA key and a self-signed certificate valid for 3650 days are no longer acceptable;
-rand /etc/hostsadds no entropy and the-des3passphrase is stripped again two commands later. Generate a 2048-bit or larger RSA key or an ECDSA P-256 key (the Postfix TLS_README examples useopenssl genpkeyfor both), and for a server that mail clients connect to get the certificate from a public CA over ACME so that clients can validate it. - saslauthd in the chroot: this still works, but the Postfix SASL_README names Dovecot SASL as the alternative: if Dovecot serves IMAP on the same host,
smtpd_sasl_type = dovecotwithsmtpd_sasl_path = private/authreuses its user database and needs no saslauthd socket inside the jail. broken_sasl_auth_clients = yesand Outlook Express: the parameter exists only for clients with an obsolete AUTH syntax (postconf(5) names Outlook Express 4 and Exchange 5.0). Outlook Express itself is long discontinued; leave the parameter at its defaultnoand configure a current mail client for port 587 or 465.- stunnel for SMTPS relaying: not needed since Postfix 3.0. The SMTP client speaks implicit TLS itself with
smtp_tls_wrappermode = yes, as in the fragment below; the[]around the host suppress MX lookups, and the key insasl_passwdmust be written the same way asrelayhost. sasl_passwd: the file holds a cleartext password, so make it and its indexed file readable by root only (chmod 600).hash:needs Berkeley DB, which some distributions are dropping; current Postfix documentation useslmdb:in the same example.- Init scripts:
/etc/init.d/postfix restartissystemctl restart postfixon a systemd distribution.
relayhost = [mail.client23.example]:submissions smtp_tls_security_level = encrypt smtp_tls_wrappermode = yes smtp_sasl_auth_enable = yes smtp_sasl_password_maps = lmdb:/etc/postfix/sasl_passwd smtp_sasl_security_options = noanonymous
Sources: