Email - exceptions_encrypt_from.txt (senders never encrypted)
Email Solution · Config document · referenced from Automatic email encryption
The list of envelope sender addresses (MAIL FROM) whose mail the encryption filter sends on as it is. These are the notification mailboxes of the platforms, the second-level support mailboxes and the monitoring sender.
| Item | Value |
|---|---|
| Path on the server | /var/spool/postfix/bash-postfix-encrypt-filter/exceptions_encrypt_from.txt |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001, identical (diff is empty) |
| Owner and mode | bash-postfix-encrypt-filter:root, 400 |
| Read by | bash-postfix-encrypt-filter.sh, on every message; no reload needed |
| Format | one address per line, lowercase, compared as a whole string |
The file
mailer-daemon@ad-dc2.example.net notification@ad-dc2.example.net notification.env3@ad-dc2.example.net notification.env3-test@ad-dc2.example.net notification_ad@ad-dc2.example.net notification.env1@ad-dc2.example.net notification.env1-test@ad-dc2.example.net notification.env2@ad-dc2.example.net notification.env2-test@ad-dc2.example.net notification-test@ad-dc2.example.net p1.secondlevel@ad-dc2.example.net p2.secondlevel@ad-dc2.example.net p3.secondlevel@ad-dc2.example.net training.secondlevel@ad-dc2.example.net sensu_mail@ad-dc2.example.net
Differences between the hosts and the sites
The two servers of site 2 have the same file. It is not covered by the synchronization services, so nothing synchronizes it between them. The site 1 list is known only from the example in the header of the script, and differs like this.
| Where | Line | Value |
|---|---|---|
| Site 2, as archived | domain | ad-dc2.example.net |
| Site 1, script header | domain | ad.example.net |
| Site 2, as archived | extra entries | notification@… and sensu_mail@… |
| Site 1, script header | test mailboxes | spelled notification.env1-tes@…, notification.env2-tes@…, notification.env3-tes@… (without the final t) |
Reading it today
- No comments, no blank-line tricks. The script splits the file on whitespace and treats every word as an address. A
#comment line would become a list of harmless but useless entries, so I add none here. - The comparison is exact and case-sensitive. A client that sends
MAIL FROM:<Notification@…>is not on the list. - The envelope sender is what the client says it is. The design intended
reject_sender_login_mismatchwith the login map from Active Directory to stop a client from borrowing one of these addresses. As archived, the order of the sender restrictions defeats it, and nothing stops it: any authenticated account inSMTP_ACCESScan send as a listed address and so bypass encryption. See Internal servers: Postfix.