Email - logrotate rule for the encryption filter
Email Solution · Config document · referenced from Automatic email encryption
The logrotate rule for the log file the encryption filter writes itself. Daily rotation, seven old files kept.
| Item | Value |
|---|---|
| Path on the server | /etc/logrotate.d/bash-postfix-encrypt-filter |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002, identical (diff is empty) |
| Rotates | /var/spool/postfix/bash-postfix-encrypt-filter/log/bash-postfix-encrypt-filter.log |
| Activated with | nothing; the daily logrotate cron job picks it up |
| SELinux | the log directory is labelled like /var/log, and the module postfix-local lets logrotate_t work under the Postfix spool |
The file
/var/spool/postfix/bash-postfix-encrypt-filter/log/bash-postfix-encrypt-filter.log
{
missingok
daily
copytruncate
rotate 7
notifempty
}Reading it today
copytruncateis not needed here. The filter is not a daemon holding the file open; every log line is a separate>>append from a short-lived process, so a plain rename withcreatewould lose nothing.copytruncatedoes no harm either, apart from the small window between copy and truncate in which a line can be lost.- No
compress. The log holds one line per step, five to seven lines per message, with sender and recipient addresses in clear text, for a week. - The same file is on the mailbox server
DC2-A-VCMSX002, where the filter is not enabled inmaster.cf. Withmissingokit does nothing there. - The label is what made it work. The directory was given the context of
/var/logwithsemanage fcontext -a -eandrestorecon; the rules are in SELinux module postfix-local.