LINUXOR.SK ... open source notes ...

Postfix 02 - Debian 4 - Postfix + SASL + TLS

category: learnz/postfix · date: 2008-03-11 · source: old.linuxor.sk/MAIL/POSTFIX-HOWTOs/BH_Debian4.0_Postfix_SASL_TLS.txt · theme: github

Postfix Mail Server Learning · Previous: a basic installation · Next: Debian 4 - A mail server for an ISP

The Slovak original of this document: Postfix 02 - Debian 4 - Postfix + SASL + TLS (slovensky).

asciiart
|=--------------------------=[ Postfix + SASL + TLS ]=---------------------=|
+---------------------------------------------------------------------------+
|                                                                           |
|       Installing Postfix with SASL + TLS authentication support           |
|                                  Debian 4.0 Etch                          |
|                                                                           |
+---------------------------------------------------------------------------+
|=-------------------------------=[ BH 2007 ]=-----------------------------=|

Configuring postfix with SASL authentication support. SASL is set up so that
the user authenticates through PAM, that is, with their own account password.
Since this data travels over the network unencrypted, we will use SSL as well.

Requisites

asciiart
        # apt-get install postfix libsasl2 sasl2-bin libsasl2-modules libdb3-util procmail

Reconfiguring postfix

asciiart
        # dpkg-reconfigure postfix
        --------------------------
        General type of configuration? <-- Internet Site
        Where should mail for root go <-- [empty]
        Mail name? <-- server1.example.com
        Other destinations to accept mail for? (blank for none) <-- server.domena.sk, localhost.domena.sk, localhost.localdomain, localhost
        Force synchronous updates on mail queue? <-- No
        Local networks? <-- 127.0.0.0/8
        Use procmail for local delivery? <-- Yes
        Mailbox size limit <-- 0
        Local address extension character? <-- +
        Internet protocols to use? <-- all

Configuring postfix SASL

asciiart
        # postconf -e 'smtpd_sasl_local_domain ='
        # postconf -e 'smtpd_sasl_auth_enable = yes'
        # postconf -e 'smtpd_sasl_security_options = noanonymous'
        # postconf -e 'broken_sasl_auth_clients = yes'
        # postconf -e 'smtpd_recipient_restrictions = permit_sasl_authenticated,permit_mynetworks,reject_unauth_destination'
        # postconf -e 'inet_interfaces = all'
        # echo 'pwcheck_method: saslauthd' >> /etc/postfix/sasl/smtpd.conf
        # echo 'mech_list: plain login' >> /etc/postfix/sasl/smtpd.conf

        Since postfix runs chrooted in /var/spool/postfix, SASL has to go into the jail as well.
        ----------------------------------------------------------------------------------------
        # mkdir -p /var/spool/postfix/var/run/saslauthd

        We edit the file /etc/default/saslauthd and thereby turn SASL on. We set the directive
        START=yes
        and change the line
        OPTIONS="-c" to OPTIONS="-c -m /var/spool/postfix/var/run/saslauthd -r"

        We restart the SASL daemon
        --------------------------
        # /etc/init.d/saslauthd start

TLS (creating the certificates)

asciiart
        # mkdir /etc/postfix/ssl
        # cd /etc/postfix/ssl/
        # openssl genrsa -des3 -rand /etc/hosts -out smtpd.key 1024
        # chmod 600 smtpd.key
        # openssl req -new -key smtpd.key -out smtpd.csr
        ------------------------------------------------
        Country Name (2 letter code) [AU]:SK
        State or Province Name (full name) [Some-State]:Slovakia
        Locality Name (eg, city) []:Mesto
        Organization Name (eg, company) [Internet Widgits Pty Ltd]:domena.sk
        Organizational Unit Name (eg, section) []:
        Common Name (eg, YOUR name) []:server.domena.sk
        Email Address []:postmaster@domena.sk

        Please enter the following 'extra' attributes
        to be sent with your certificate request
        A challenge password []: empty
        An optional company name []: empty
        ------------------------------------------------
        # openssl x509 -req -days 3650 -in smtpd.csr -signkey smtpd.key -out smtpd.crt
        # openssl rsa -in smtpd.key -out smtpd.key.unencrypted
        # mv -f smtpd.key.unencrypted smtpd.key
        # openssl req -new -x509 -extensions v3_ca -keyout cakey.pem -out cacert.pem -days 3650

Configuring postfix TLS

asciiart
        # postconf -e 'smtpd_tls_auth_only = no'
        # postconf -e 'smtp_use_tls = yes'
        # postconf -e 'smtpd_use_tls = yes'
        # postconf -e 'smtp_tls_note_starttls_offer = yes'
        # postconf -e 'smtpd_tls_key_file = /etc/postfix/ssl/smtpd.key'
        # postconf -e 'smtpd_tls_cert_file = /etc/postfix/ssl/smtpd.crt'
        # postconf -e 'smtpd_tls_CAfile = /etc/postfix/ssl/cacert.pem'
        # postconf -e 'smtpd_tls_loglevel = 1'
        # postconf -e 'smtpd_tls_received_header = yes'
        # postconf -e 'smtpd_tls_session_cache_timeout = 3600s'
        # postconf -e 'tls_random_source = dev:/dev/urandom'
        # postconf -e 'myhostname = server.domena.sk'

Postfix restart

asciiart
        # /etc/init.d/postfix restart

OUTLOOK EXPRESS

asciiart
        tools -> accounts -> mail -> account_name -> servers -> log_on_using_secure_password_authentication = check
        tools -> accounts -> mail -> account_name -> servers -> my_server_requires_authentication = check
        tools -> accounts -> mail -> account_name -> advanced -> this_server_requires_a_secure_connection(SSL) = check

============================================================================================
 Setting postfix up to authenticate using SASL when it connects to another SMTP server
 that requires authentication. When postfix wants to connect to the server mail.domena.sk,
 the login and password from the file /etc/postfix/sasl_passwd are used
============================================================================================

        # touch /etc/postfix/sasl_passwd
        # nano /etc/postfix/sasl_passwd
        -------------------------------
        domena.sk       ucet:heslo

        # postmap /etc/postfix/sasl_passwd
        # nano /etc/postfix/main.cf
        ---------------------------
        smtp_sasl_auth_enable=yes
        smtp_sasl_password_maps=hash:/etc/postfix/sasl_passwd

        # /etc/init.d/postfix reload

Relaying to an SMTPS server using postfix and stunnel

asciiart
        Install stunnel
        ---------------
        # apt-get install stunnel4

        Adding the user and group smtps
        -------------------------------
        # groupadd smtps
        # useradd -d /dev/null -g smtps -s /bin/false smtps

        We start stunnel in client mode for the smtp protocol, listening on localhost:465 and
        connecting to the remote machine mail.client23.example:465 as the user and group smtps.
        ------------------------------------------------------------------------------------
        # stunnel -c -d 127.0.0.1:465 -o /var/log/SMTPS_tunnel.log -n smtp -s smtps -g smtps -r mail.client23.example:465

        # touch /etc/postfix/sasl_passwd
        # nano /etc/postfix/sasl_passwd
        -------------------------------
        localhost       ucet@server:HESLO

        # postmap /etc/postfix/sasl_passwd
        # nano /etc/postfix/main.cf
        ---------------------------
        relayhost = localhost:465
        smtp_sasl_auth_enable=yes
        smtp_sasl_password_maps=hash:/etc/postfix/sasl_passwd
        smtp_sasl_security_options = noanonymous
        smtp_use_tls = no

        # /etc/init.d/postfix reload

Current practice (checked 2026-10)

noteThe article above is kept as it was written in 2008. This section lists what has changed since and what to do instead today.
ini
relayhost = [mail.client23.example]:submissions
smtp_tls_security_level = encrypt
smtp_tls_wrappermode = yes
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = lmdb:/etc/postfix/sasl_passwd
smtp_sasl_security_options = noanonymous

Sources:

← learnz/postfix(EN | SK)