Email - Postfix master.cf, internal servers
Email Solution · Config document · referenced from Internal servers: Postfix
smtps service replaces smtpd_recipient_restrictions of main.cf with permit_sasl_authenticated,reject. On port 465 the check for the group ESMTP_ACCESS is therefore not evaluated. Do not copy that line into a setup that separates internal and external senders in the recipient restrictions.The Postfix master process configuration of the internal pair: the two listeners (SMTP on 25, SMTPS on 465), the pipe service that runs the encryption filter, and the pipe service for Dovecot delivery. Stock comments and the commented-out stock services are left out; every active line and my own CFG-ON comments are kept.
| Item | Value |
|---|---|
| Path on the server | /etc/postfix/master.cf |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001, identical; DC2-A-VCMSX002 without the content filter (differences below) |
| Software | Postfix 2.10.1 from the RHEL 7 repository |
| Activated with | postfix reload |
| Filter added | 26 November 2018, the date in the CFG-ON comments |
The file
# Columns: service, type, private, unpriv, chroot, wakeup, maxproc, command + args. # The chroot column is "n" for every service, as in the RHEL 7 package. # CFG-ON (26.11.2018) -> Definition of BASH postfix encrypt filter bash-postfix-encrypt-filter unix - n n - - pipe flags=Rq user=bash-postfix-encrypt-filter null_sender= argv=/usr/local/bin/bash-postfix-encrypt-filter.sh -f ${sender} -- ${recipient} # CFG-ON (26.11.2018) -> Enable BASH postfix encrypt filter for SMTP only smtp inet n - n - - smtpd -o content_filter=bash-postfix-encrypt-filter: # CFG-ON -> Email server accept connections also on SMTPS port (465) # CFG-ON (26.11.2018) -> Enable BASH postfix encrypt filter for SMTPS only smtps inet n - n - - smtpd -o syslog_name=postfix/smtps -o smtpd_tls_wrappermode=yes -o smtpd_sasl_auth_enable=yes -o smtpd_reject_unlisted_recipient=no -o smtpd_recipient_restrictions=permit_sasl_authenticated,reject -o milter_macro_daemon_name=ORIGINATING -o content_filter=bash-postfix-encrypt-filter: # The stock services of the package, unchanged. pickup unix n - n 60 1 pickup cleanup unix n - n - 0 cleanup qmgr unix n - n 300 1 qmgr tlsmgr unix - - n 1000? 1 tlsmgr rewrite unix - - n - - trivial-rewrite bounce unix - - n - 0 bounce defer unix - - n - 0 bounce trace unix - - n - 0 bounce verify unix - - n - 1 verify flush unix n - n 1000? 0 flush proxymap unix - - n - - proxymap proxywrite unix - - n - 1 proxymap smtp unix - - n - - smtp relay unix - - n - - smtp showq unix n - n - - showq error unix - - n - - error retry unix - - n - - error discard unix - - n - - discard local unix - n n - - local virtual unix - n n - - virtual lmtp unix - - n - - lmtp anvil unix - - n - 1 anvil scache unix - - n - 1 scache # CFG-ON -> Dovecot daemon is responsible for local mail delivery # Delivery through the Dovecot LDA. Defined on all three internal servers, but only the # transport table of the mailbox server (DC2-A-VCMSX002) sends mail to it. dovecot unix - n n - - pipe flags=ODRhu user=vmail:vmail argv=/usr/libexec/dovecot/deliver -e -f ${sender} -d ${recipient}
Differences on the other hosts
Against DC2-B-VCMSX001 diff shows a trailing blank after null_sender= on node B and an empty last line that only node A has, and nothing else.
| Host | Line | Value |
|---|---|---|
DC2-A-VCMSX002 | service bash-postfix-encrypt-filter | not present, with its comment |
DC2-A-VCMSX002 | -o content_filter=bash-postfix-encrypt-filter: under smtp | not present |
DC2-A-VCMSX002 | -o content_filter=bash-postfix-encrypt-filter: under smtps | not present |
DC2-A-VCMSX002 | the two comment lines Enable BASH postfix encrypt filter for SMTP only and … for SMTPS only | not present |
DC2-A-VCMSX002 | empty last line | not present |
The script the filter service runs is a Config document: bash-postfix-encrypt-filter.sh.
Checked against Postfix 3.11
| As built | Today |
|---|---|
service smtps on port 465 | the stock master.cf calls it submissions ("formerly called smtps"); its commented template now also carries -o smtpd_forbid_unauth_pipelining=no, -o local_header_rewrite_clients=static:all, -o smtpd_hide_client_session=yes and -o smtpd_relay_restrictions= |
-o smtpd_recipient_restrictions=permit_sasl_authenticated,reject | I expect it is still part of the stock template; not checked. An override like this replaces the list of main.cf for that service |
-o milter_macro_daemon_name=ORIGINATING | still in the stock template |
-o content_filter=bash-postfix-encrypt-filter: on both listeners | still valid: after the message is queued, the entire message goes to the named transport |
pipe service with flags=Rq user=… null_sender= argv=… -f ${sender} -- ${recipient} | identical to the "simple content filter" example in today's FILTER_README |
dovecot pipe service with flags=ODRhu and /usr/libexec/dovecot/deliver | the flags are still valid and deliver is still installed as a link to dovecot-lda; Dovecot now recommends LMTP for delivery |
The file is still the documented shape of a simple content filter. The one line that needs a decision today is the same as then: the recipient restrictions that the 465 service brings with it.