LINUXOR.SK ... open source notes ...

Email - Postfix LDAP map: allow external emails

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Active Directory integration

notebind_pw holds the password of the bind account in clear text; <LDAP_BIND_PASSWORD> is a placeholder. The install notes do not record the owner and mode of this file. It must not be world-readable: ldap_table(5) asks for a file that only the Postfix user can read.

An access table for check_sender_access: it answers OK when the sender address is the userPrincipalName of an account that is a member, directly or through nested groups, of the role group ESMTP_ACCESS. Such a sender may write to any domain; everybody else is held to the own domain by the table that follows it.

ItemValue
Path on the server/etc/postfix/ad_allow_external_emails.cf
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001 and DC2-A-VCMSX002, identical
Referenced bycheck_sender_access ldap:/etc/postfix/ad_allow_external_emails.cf in smtpd_recipient_restrictions
Directory serversDC2-A-VCAD001 and DC2-A-VCAD002, LDAPS on port 636, IPv4 only
SoftwarePostfix 2.10.1, LDAP client of the RHEL 7 package
Activated withpostfix reload; an LDAP table is queried live and needs no postmap

The file

ini
# LDAP Server settings
# Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "server_host") contains only IPv4 addresses.
#
# DC2-A-VCAD001 - 10.12.16.209
# DC2-A-VCAD002 - 10.12.16.210
server_host     = ldaps://10.12.16.209:636, ldaps://10.12.16.210:636
search_base     = DC=ad-dc2,DC=example,DC=net
scope           = sub
version         = 3
start_tls       = no

# LDAP User Binding settings
bind            = yes
bind_dn         = cn=vmail_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net
bind_pw         = <LDAP_BIND_PASSWORD>

# LDAP Filter settings
query_filter    = (&(memberOf:1.2.840.113556.1.4.1941:=CN=ESMTP_ACCESS,OU=APPS,OU=RBAC_ROLES,OU=RBAC,DC=ad-dc2,DC=example,DC=net)(userPrincipalName=%s))
result_attribute= userPrincipalName
result_format   = OK

# Debug settings
debuglevel      = 0

Differences on the other hosts

DC2-B-VCMSX001 and DC2-A-VCMSX002 carry the same file; diff shows node A and DC2-A-VCMSX002 identical, and on node B nothing but a missing empty last line. The first design shows the site 1 variant: DNS names of the domain controllers in server_host instead of IPv4 addresses, and the base DN DC=ad,DC=example,DC=net.

Checked against Postfix 3.11

As builtToday
server_host = ldaps://…:636still valid: LDAP over SSL is requested with an ldaps URL in server_host
version = 3, start_tls = nostill valid; the default version is still 2 and ldaps needs version 3 set explicitly; start_tls must not be set together with an ldaps URL
bind = yes with bind_dn and bind_pwstill valid; bind = sasl exists since 2.8. The file should be readable only by the Postfix user
no tls_require_cert, no tls_ca_cert_filethe default is still no: the trust chain of the server certificate is not checked. yes needs tls_ca_cert_file or tls_ca_cert_dir
simple bind to Active Directory over port 636a domain controller that requires LDAP signing rejects simple binds on clear-text connections; simple binds over TLS are not affected
memberOf:1.2.840.113556.1.4.1941:=still documented by Microsoft as LDAP_MATCHING_RULE_IN_CHAIN; searches with it over a subtree may be more processor intensive
result_attribute with result_format = OKboth still documented with the same meaning

The map would be read unchanged by a current Postfix. What it leaves at the default is the weak point: the connection to the domain controller is encrypted, but the certificate is not verified.

← solutionz