Email - Postfix LDAP map: allow external emails
Email Solution · Config document · referenced from Active Directory integration
bind_pw holds the password of the bind account in clear text; <LDAP_BIND_PASSWORD> is a placeholder. The install notes do not record the owner and mode of this file. It must not be world-readable: ldap_table(5) asks for a file that only the Postfix user can read.An access table for check_sender_access: it answers OK when the sender address is the userPrincipalName of an account that is a member, directly or through nested groups, of the role group ESMTP_ACCESS. Such a sender may write to any domain; everybody else is held to the own domain by the table that follows it.
| Item | Value |
|---|---|
| Path on the server | /etc/postfix/ad_allow_external_emails.cf |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002, identical |
| Referenced by | check_sender_access ldap:/etc/postfix/ad_allow_external_emails.cf in smtpd_recipient_restrictions |
| Directory servers | DC2-A-VCAD001 and DC2-A-VCAD002, LDAPS on port 636, IPv4 only |
| Software | Postfix 2.10.1, LDAP client of the RHEL 7 package |
| Activated with | postfix reload; an LDAP table is queried live and needs no postmap |
The file
# LDAP Server settings # Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "server_host") contains only IPv4 addresses. # # DC2-A-VCAD001 - 10.12.16.209 # DC2-A-VCAD002 - 10.12.16.210 server_host = ldaps://10.12.16.209:636, ldaps://10.12.16.210:636 search_base = DC=ad-dc2,DC=example,DC=net scope = sub version = 3 start_tls = no # LDAP User Binding settings bind = yes bind_dn = cn=vmail_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net bind_pw = <LDAP_BIND_PASSWORD> # LDAP Filter settings query_filter = (&(memberOf:1.2.840.113556.1.4.1941:=CN=ESMTP_ACCESS,OU=APPS,OU=RBAC_ROLES,OU=RBAC,DC=ad-dc2,DC=example,DC=net)(userPrincipalName=%s)) result_attribute= userPrincipalName result_format = OK # Debug settings debuglevel = 0
Differences on the other hosts
DC2-B-VCMSX001 and DC2-A-VCMSX002 carry the same file; diff shows node A and DC2-A-VCMSX002 identical, and on node B nothing but a missing empty last line. The first design shows the site 1 variant: DNS names of the domain controllers in server_host instead of IPv4 addresses, and the base DN DC=ad,DC=example,DC=net.
Checked against Postfix 3.11
| As built | Today |
|---|---|
server_host = ldaps://…:636 | still valid: LDAP over SSL is requested with an ldaps URL in server_host |
version = 3, start_tls = no | still valid; the default version is still 2 and ldaps needs version 3 set explicitly; start_tls must not be set together with an ldaps URL |
bind = yes with bind_dn and bind_pw | still valid; bind = sasl exists since 2.8. The file should be readable only by the Postfix user |
no tls_require_cert, no tls_ca_cert_file | the default is still no: the trust chain of the server certificate is not checked. yes needs tls_ca_cert_file or tls_ca_cert_dir |
| simple bind to Active Directory over port 636 | a domain controller that requires LDAP signing rejects simple binds on clear-text connections; simple binds over TLS are not affected |
memberOf:1.2.840.113556.1.4.1941:= | still documented by Microsoft as LDAP_MATCHING_RULE_IN_CHAIN; searches with it over a subtree may be more processor intensive |
result_attribute with result_format = OK | both still documented with the same meaning |
The map would be read unchanged by a current Postfix. What it leaves at the default is the weak point: the connection to the domain controller is encrypted, but the certificate is not verified.