Email - Postfix LDAP map: sender login maps
Email Solution · Config document · referenced from Active Directory integration
bind_pw holds the password of the bind account in clear text; <LDAP_BIND_PASSWORD> is a placeholder. The install notes do not record the owner and mode of this file. It must not be world-readable: ldap_table(5) asks for a file that only the Postfix user can read.The lookup table behind smtpd_sender_login_maps: for a sender address it returns the SASL login that owns the address. Address and login are the same attribute here, userPrincipalName, so the table says "an address belongs to the account of the same name, as long as that account is a person and is not disabled".
| Item | Value |
|---|---|
| Path on the server | /etc/postfix/ad_sender_login_maps.cf |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002, identical |
| Referenced by | smtpd_sender_login_maps = proxy:ldap:/etc/postfix/ad_sender_login_maps.cf in main.cf |
| Directory servers | DC2-A-VCAD001 and DC2-A-VCAD002, LDAPS on port 636, IPv4 only |
| Software | Postfix 2.10.1, LDAP client of the RHEL 7 package |
| Activated with | postfix reload; an LDAP table is queried live and needs no postmap |
The file
# LDAP Server settings # Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "server_host") contains only IPv4 addresses. # # DC2-A-VCAD001 - 10.12.16.209 # DC2-A-VCAD002 - 10.12.16.210 server_host = ldaps://10.12.16.209:636, ldaps://10.12.16.210:636 search_base = DC=ad-dc2,DC=example,DC=net scope = sub version = 3 start_tls = no # LDAP User Binding settings bind = yes bind_dn = cn=vmail_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net bind_pw = <LDAP_BIND_PASSWORD> # LDAP Filter settings query_filter = (&(userPrincipalName=%s)(objectClass=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) result_attribute= userPrincipalName # LDAP Debug settings debuglevel = 0
Differences on the other hosts
DC2-B-VCMSX001 and DC2-A-VCMSX002 carry the same file; diff shows node A and DC2-A-VCMSX002 identical, and on node B nothing but a missing empty last line. The first design shows the site 1 variant: DNS names of the domain controllers in server_host instead of IPv4 addresses, and the base DN DC=ad,DC=example,DC=net.
Checked against Postfix 3.11
| As built | Today |
|---|---|
server_host = ldaps://…:636 | still valid: LDAP over SSL is requested with an ldaps URL in server_host |
version = 3, start_tls = no | still valid; the default version is still 2 and ldaps needs version 3 set explicitly; start_tls must not be set together with an ldaps URL |
bind = yes with bind_dn and bind_pw | still valid; bind = sasl exists since 2.8. The file should be readable only by the Postfix user |
no tls_require_cert, no tls_ca_cert_file | the default is still no: the trust chain of the server certificate is not checked. yes needs tls_ca_cert_file or tls_ca_cert_dir |
| simple bind to Active Directory over port 636 | a domain controller that requires LDAP signing rejects simple binds on clear-text connections; simple binds over TLS are not affected |
userAccountControl:1.2.840.113556.1.4.803:=2 | still documented by Microsoft as LDAP_MATCHING_RULE_BIT_AND; the value must be decimal |
smtpd_sender_login_maps = proxy:ldap:… | still valid; proxy: tables must be covered by proxy_read_maps, whose default includes the standard parameters |
The map would be read unchanged by a current Postfix. What it leaves at the default is the weak point: the connection to the domain controller is encrypted, but the certificate is not verified.