Postfix 03 - Debian 4 - A mail server for an ISP
Postfix Mail Server Learning · Previous: Debian 4 - Postfix + SASL + TLS · Next: Postfix + Dovecot + SquirrelMail + MailScanner + ClamAV
The Slovak original of this document: Postfix 03 - Debian 4 - Poštový server pre ISP (slovensky).
|=-------------------------------=[ Postfix ]=-----------------------------=|
+---------------------------------------------------------------------------+
| |
| A mail server for an ISP |
| Debian 4.0 Etch |
| |
+---------------------------------------------------------------------------+
|=-------------------------------=[ BH 2008 ]=-----------------------------=|
MailerDeploy = the directory holding the configuration files needed
for the mail server and all of its components.System components
MTA - postfix
MDA - maildrop
Antivir + Antispam - MailScanner
Antispam - postgrey
Antispam - RBL (selected)
Antispam - DSPAM ( ??? we'll see ??? )
POP3s + IMAPs - Dovecot
Webmail - OpenWebmail
SeLinux - would be VERY COOL ;-)System features
Setting up the sources for the packaging system
# nano /etc/apt/sources.list
----------------------------
# STABLE
deb http://ftp.sk.debian.org/debian/ etch main
deb-src http://ftp.sk.debian.org/debian/ etch main
# SECURITY
deb http://security.debian.org/ etch/updates main contrib
deb-src http://security.debian.org/ etch/updates main contrib
# DEBIAN VOLATILE (clamav and co.)
deb http://volatile.debian.org/debian-volatile etch/volatile main contrib non-free
-------------------------------Installing the mail server (postfix)
-----------------
Install postfix
-----------------
We install postfix with the basic parameters for an Internet mail server.
We will overwrite the postfix config (main.cf) with our own variant anyway (MailerDeploy/postfix/main.cf).
# apt-get install postfix
-------------------------
General type of configuration? [Internet Site]
Mail name? [mailhost.provider.example]
-------------------------
Install SASL components
-------------------------
We install SASL support so that we can authenticate users
---------------------------------------------------------
# apt-get install libsasl2 sasl2-bin libsasl2-modules libdb3-util
----------------
Config postfix
----------------
We copy the config from MailerDeploy
------------------------------------
# cp /root/MailerDeploy/postfix/main.cf /etc/postfix/
----------------------------
Config SASL authentication
----------------------------
We copy the config from MailerDeploy
------------------------------------
# cp /root/MailerDeploy/postfix/sasl/smtpd.conf /etc/postfix/sasl/
Since postfix runs chrooted in /var/spool/postfix, we have to add SASL to the jail as well
------------------------------------------------------------------------------------------
# mkdir -p /var/spool/postfix/var/run/saslauthd
# nano /etc/default/saslauthd
-----------------------------
START=yes
OPTIONS="-m /var/spool/postfix/var/run/saslauthd -r -c"
-----------------------------END /etc/default/saslauthd
Restart the saslauthd daemon
----------------------------
# /etc/init.d/saslauthd restart
-----------------------------------------
TLS (creating self-signed certificates)
-----------------------------------------
# cd /tmp
# mkdir config
# cd config
# mkdir certs crl newcerts private
# echo "01" > serial
# cp /dev/null index.txt
# cat /etc/ssl/openssl.cnf | sed -e 's/\.\/demoCA/\./' > openssl.cnf
Creating a new CA
-----------------
# openssl req -new -x509 -keyout private/cakey.pem -out cacert.pem -days 365 -config openssl.cnf
-------------------
Enter PEM pass phrase: <ca_key_passphrase>
Country Name (2 letter code) [AU]:SK
State or Province Name (full name) [Some-State]:Slovakia
Locality Name (eg, city) []:Mesto
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Cassovianet s.r.o.
Organizational Unit Name (eg, section) []:IT
Common Name (eg, YOUR name) []:CA
Email Address []:help@provider.example
-------------------
Creating a certificate request (cert request)
---------------------------------------------
# openssl req -nodes -new -x509 -keyout newreq.pem -out newreq.pem -days 365 -config openssl.cnf
-------------------
Country Name (2 letter code) [AU]:SK
State or Province Name (full name) [Some-State]:Slovakia
Locality Name (eg, city) []:Mesto
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Cassovianet s.r.o.
Organizational Unit Name (eg, section) []:IT
Common Name (eg, YOUR name) []:mailhost.provider.example
Email Address []:help@provider.example
-------------------
# openssl x509 -x509toreq -in newreq.pem -signkey newreq.pem -out tmp.pem
Signing the certificate
-----------------------
# openssl ca -config openssl.cnf -policy policy_anything -out newcert.pem -infiles tmp.pem
??? something is off here ??? -> crappy paths !!!
Placing the certificates
------------------------
# cp cacert.pem /usr/share/ssl/certs
# grep -B 100 "END RSA PRIVATE KEY" newreq.pem > /usr/share/ssl/certs/key.pem
# chmod 400 /usr/share/ssl/certs/key.pem
# cp newcert.pem /usr/share/ssl/certs/cert.pemLinkz
Howto: ISP-style Email Server with Debian-Etch and Postfix 2.3
--------------------------------------------------------------
http://workaround.org/articles/ispmail-etch/
Handling mail for multiple virtual domains with postfix
-------------------------------------------------------
http://www.debian-administration.org/articles/243Current practice (checked 2026-10)
noteThe article above is kept as it was written in 2008. This section lists what has changed since and what to do instead today.
- Unfinished article: the notes stop after the certificate step and the author marks that step as broken himself. The points below cover only what is written.
- Package sources: Debian 4.0 (etch) is long out of support and its repositories are gone from the mirrors. The
debian-volatilesuite was replaced bystable-updatesstarting with Debian squeeze. - SASL through saslauthd in the chroot: the component list already contains Dovecot, and Postfix can use it directly for SMTP AUTH (
smtpd_sasl_type = dovecot,smtpd_sasl_path = private/auth). That gives one user database for IMAP, POP3 and SMTP and removes the saslauthd socket from the Postfix jail. - Own CA and 365-day self-signed certificates: customers of an ISP connect with ordinary mail clients, which must be able to validate the server certificate (RFC 8314). Use a certificate from a public CA, renewed automatically over ACME, instead of a private CA whose root every customer would have to import.
- Submission: customers should send through an authenticated service on port 587 (STARTTLS) or 465 (implicit TLS) with
smtpd_tls_security_level=encrypt, separate from the MX service on port 25 (RFC 6409, RFC 8314). - RBL and greylisting (postgrey): since Postfix 2.8
postscreendoes the DNSBL and pregreet tests in front of the SMTP server processes, so that spambots do not occupysmtpdprocesses. It is the usual first layer today; RBL checks no longer need to sit insmtpd_recipient_restrictions. - SPF, DKIM and DMARC: the article predates them as an operational requirement. An ISP mail server today publishes SPF and DMARC records, signs outgoing mail with DKIM and checks all three on incoming mail; with Postfix this is done through Milter applications (the Postfix MILTER_README names OpenDKIM and OpenDMARC).
Sources:
- Postfix SASL Howto (SASL_README)
- Postfix Postscreen Howto (POSTSCREEN_README)
- Postfix before-queue Milter support (MILTER_README)
- RFC 8314: Cleartext Considered Obsolete: Use of TLS for Email Submission and Access
- RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
- Debian wiki: StableUpdates