LINUXOR.SK ... open source notes ...

Postfix 03 - Debian 4 - A mail server for an ISP

category: learnz/postfix · date: 2008-06-17 · source: old.linuxor.sk/MAIL/POSTFIX-HOWTOs/BH_Debian4.0_MAIL_SYSTEM_ISP.txt · theme: github

Postfix Mail Server Learning · Previous: Debian 4 - Postfix + SASL + TLS · Next: Postfix + Dovecot + SquirrelMail + MailScanner + ClamAV

The Slovak original of this document: Postfix 03 - Debian 4 - Poštový server pre ISP (slovensky).

asciiart
|=-------------------------------=[ Postfix ]=-----------------------------=|
+---------------------------------------------------------------------------+
|                                                                           |
|                           A mail server for an ISP                        |
|                                Debian 4.0 Etch                            |
|                                                                           |
+---------------------------------------------------------------------------+
|=-------------------------------=[ BH 2008 ]=-----------------------------=|

MailerDeploy = the directory holding the configuration files needed
               for the mail server and all of its components.

System components

asciiart
        MTA - postfix
        MDA - maildrop
        Antivir + Antispam - MailScanner
        Antispam - postgrey
        Antispam - RBL (selected)
        Antispam - DSPAM ( ??? we'll see ??? )
        POP3s + IMAPs - Dovecot
        Webmail - OpenWebmail
        SeLinux - would be VERY COOL ;-)

System features

Setting up the sources for the packaging system

asciiart
        # nano /etc/apt/sources.list
        ----------------------------
        # STABLE
        deb http://ftp.sk.debian.org/debian/ etch main
        deb-src http://ftp.sk.debian.org/debian/ etch main

        # SECURITY
        deb http://security.debian.org/ etch/updates main contrib
        deb-src http://security.debian.org/ etch/updates main contrib

        # DEBIAN VOLATILE (clamav and co.)
        deb http://volatile.debian.org/debian-volatile etch/volatile main contrib non-free
        -------------------------------

Installing the mail server (postfix)

asciiart
-----------------
 Install postfix
-----------------

        We install postfix with the basic parameters for an Internet mail server.
        We will overwrite the postfix config (main.cf) with our own variant anyway (MailerDeploy/postfix/main.cf).

        # apt-get install postfix
        -------------------------
        General type of configuration? [Internet Site]
        Mail name? [mailhost.provider.example]

-------------------------
 Install SASL components
-------------------------

        We install SASL support so that we can authenticate users
        ---------------------------------------------------------
        # apt-get install libsasl2 sasl2-bin libsasl2-modules libdb3-util

----------------
 Config postfix
----------------

        We copy the config from MailerDeploy
        ------------------------------------
        # cp /root/MailerDeploy/postfix/main.cf /etc/postfix/

----------------------------
 Config SASL authentication
----------------------------

        We copy the config from MailerDeploy
        ------------------------------------
        # cp /root/MailerDeploy/postfix/sasl/smtpd.conf /etc/postfix/sasl/

        Since postfix runs chrooted in /var/spool/postfix, we have to add SASL to the jail as well
        ------------------------------------------------------------------------------------------
        # mkdir -p /var/spool/postfix/var/run/saslauthd

        # nano /etc/default/saslauthd
        -----------------------------
        START=yes
        OPTIONS="-m /var/spool/postfix/var/run/saslauthd -r -c"
        -----------------------------END /etc/default/saslauthd

        Restart the saslauthd daemon
        ----------------------------
        # /etc/init.d/saslauthd restart

-----------------------------------------
 TLS (creating self-signed certificates)
-----------------------------------------

        # cd /tmp
        # mkdir config
        # cd config
        # mkdir certs crl newcerts private
        # echo "01" > serial
        # cp /dev/null index.txt
        # cat /etc/ssl/openssl.cnf | sed -e 's/\.\/demoCA/\./' > openssl.cnf

        Creating a new CA
        -----------------
        # openssl req -new -x509 -keyout private/cakey.pem -out cacert.pem -days 365 -config openssl.cnf
        -------------------
        Enter PEM pass phrase: <ca_key_passphrase>
        Country Name (2 letter code) [AU]:SK
        State or Province Name (full name) [Some-State]:Slovakia
        Locality Name (eg, city) []:Mesto
        Organization Name (eg, company) [Internet Widgits Pty Ltd]:Cassovianet s.r.o.
        Organizational Unit Name (eg, section) []:IT
        Common Name (eg, YOUR name) []:CA
        Email Address []:help@provider.example
        -------------------

        Creating a certificate request (cert request)
        ---------------------------------------------
        # openssl req -nodes -new -x509 -keyout newreq.pem -out newreq.pem -days 365 -config openssl.cnf
        -------------------
        Country Name (2 letter code) [AU]:SK
        State or Province Name (full name) [Some-State]:Slovakia
        Locality Name (eg, city) []:Mesto
        Organization Name (eg, company) [Internet Widgits Pty Ltd]:Cassovianet s.r.o.
        Organizational Unit Name (eg, section) []:IT
        Common Name (eg, YOUR name) []:mailhost.provider.example
        Email Address []:help@provider.example
        -------------------

        # openssl x509 -x509toreq -in newreq.pem -signkey newreq.pem -out tmp.pem

        Signing the certificate
        -----------------------
        # openssl ca -config openssl.cnf -policy policy_anything -out newcert.pem -infiles tmp.pem

??? something is off here ??? -> crappy paths !!!

Placing the certificates
------------------------
# cp cacert.pem /usr/share/ssl/certs
# grep -B 100 "END RSA PRIVATE KEY" newreq.pem > /usr/share/ssl/certs/key.pem
# chmod 400 /usr/share/ssl/certs/key.pem
# cp newcert.pem /usr/share/ssl/certs/cert.pem

Linkz

asciiart
        Howto: ISP-style Email Server with Debian-Etch and Postfix 2.3
        --------------------------------------------------------------
        http://workaround.org/articles/ispmail-etch/

        Handling mail for multiple virtual domains with postfix
        -------------------------------------------------------
        http://www.debian-administration.org/articles/243

Current practice (checked 2026-10)

noteThe article above is kept as it was written in 2008. This section lists what has changed since and what to do instead today.

Sources:

← learnz/postfix(EN | SK)