LINUXOR.SK ... open source notes ...

Email - Postfix LDAP map: sender login maps

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Active Directory integration

notebind_pw holds the password of the bind account in clear text; <LDAP_BIND_PASSWORD> is a placeholder. The install notes do not record the owner and mode of this file. It must not be world-readable: ldap_table(5) asks for a file that only the Postfix user can read.

The lookup table behind smtpd_sender_login_maps: for a sender address it returns the SASL login that owns the address. Address and login are the same attribute here, userPrincipalName, so the table says "an address belongs to the account of the same name, as long as that account is a person and is not disabled".

ItemValue
Path on the server/etc/postfix/ad_sender_login_maps.cf
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001 and DC2-A-VCMSX002, identical
Referenced bysmtpd_sender_login_maps = proxy:ldap:/etc/postfix/ad_sender_login_maps.cf in main.cf
Directory serversDC2-A-VCAD001 and DC2-A-VCAD002, LDAPS on port 636, IPv4 only
SoftwarePostfix 2.10.1, LDAP client of the RHEL 7 package
Activated withpostfix reload; an LDAP table is queried live and needs no postmap

The file

ini
# LDAP Server settings
# Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "server_host") contains only IPv4 addresses.
#
# DC2-A-VCAD001 - 10.12.16.209
# DC2-A-VCAD002 - 10.12.16.210
server_host     = ldaps://10.12.16.209:636, ldaps://10.12.16.210:636
search_base     = DC=ad-dc2,DC=example,DC=net
scope           = sub
version         = 3
start_tls       = no

# LDAP User Binding settings
bind            = yes
bind_dn         = cn=vmail_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net
bind_pw         = <LDAP_BIND_PASSWORD>

# LDAP Filter settings
query_filter    = (&(userPrincipalName=%s)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
result_attribute= userPrincipalName

# LDAP Debug settings
debuglevel      = 0

Differences on the other hosts

DC2-B-VCMSX001 and DC2-A-VCMSX002 carry the same file; diff shows node A and DC2-A-VCMSX002 identical, and on node B nothing but a missing empty last line. The first design shows the site 1 variant: DNS names of the domain controllers in server_host instead of IPv4 addresses, and the base DN DC=ad,DC=example,DC=net.

Checked against Postfix 3.11

As builtToday
server_host = ldaps://…:636still valid: LDAP over SSL is requested with an ldaps URL in server_host
version = 3, start_tls = nostill valid; the default version is still 2 and ldaps needs version 3 set explicitly; start_tls must not be set together with an ldaps URL
bind = yes with bind_dn and bind_pwstill valid; bind = sasl exists since 2.8. The file should be readable only by the Postfix user
no tls_require_cert, no tls_ca_cert_filethe default is still no: the trust chain of the server certificate is not checked. yes needs tls_ca_cert_file or tls_ca_cert_dir
simple bind to Active Directory over port 636a domain controller that requires LDAP signing rejects simple binds on clear-text connections; simple binds over TLS are not affected
userAccountControl:1.2.840.113556.1.4.803:=2still documented by Microsoft as LDAP_MATCHING_RULE_BIT_AND; the value must be decimal
smtpd_sender_login_maps = proxy:ldap:…still valid; proxy: tables must be covered by proxy_read_maps, whose default includes the standard parameters

The map would be read unchanged by a current Postfix. What it leaves at the default is the weak point: the connection to the domain controller is encrypted, but the certificate is not verified.

← solutionz