Email - Postfix LDAP map: virtual mailbox maps
Email Solution · Config document · referenced from Active Directory integration
bind_pw holds the password of the bind account in clear text; <LDAP_BIND_PASSWORD> is a placeholder. The install notes do not record the owner and mode of this file. It must not be world-readable: ldap_table(5) asks for a file that only the Postfix user can read.The lookup table behind virtual_mailbox_maps: it tells Postfix which addresses of the own domain exist, and returns the mailbox path relative to the mailbox base in the form domain/user/Maildir/.
| Item | Value |
|---|---|
| Path on the server | /etc/postfix/ad_virtual_mailbox_maps.cf |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002, identical |
| Referenced by | virtual_mailbox_maps = proxy:ldap:/etc/postfix/ad_virtual_mailbox_maps.cf in main.cf |
| Directory servers | DC2-A-VCAD001 and DC2-A-VCAD002, LDAPS on port 636, IPv4 only |
| Software | Postfix 2.10.1, LDAP client of the RHEL 7 package |
| Activated with | postfix reload; an LDAP table is queried live and needs no postmap |
The file
# LDAP Server settings # Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "server_host") contains only IPv4 addresses. # # DC2-A-VCAD001 - 10.12.16.209 # DC2-A-VCAD002 - 10.12.16.210 server_host = ldaps://10.12.16.209:636, ldaps://10.12.16.210:636 search_base = DC=ad-dc2,DC=example,DC=net scope = sub version = 3 start_tls = no # LDAP User Binding settings bind = yes bind_dn = cn=vmail_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net bind_pw = <LDAP_BIND_PASSWORD> # LDAP Filter settings query_filter = (&(objectclass=person)(userPrincipalName=%s)) result_attribute= userPrincipalName result_format = %d/%u/Maildir/ # LDAP Debug settings debuglevel = 0
Differences on the other hosts
DC2-B-VCMSX001 and DC2-A-VCMSX002 carry the same file; diff shows node A and DC2-A-VCMSX002 identical, and on node B nothing but a missing empty last line. The first design shows the site 1 variant: DNS names of the domain controllers in server_host instead of IPv4 addresses, and the base DN DC=ad,DC=example,DC=net.
On the internal pair the returned path is never used for a delivery, because the transport table sends the domain on to the mailbox server; the lookup serves to reject unknown recipients at RCPT TO. Unlike the sender login map, this filter does not exclude disabled accounts.
Checked against Postfix 3.11
| As built | Today |
|---|---|
server_host = ldaps://…:636 | still valid: LDAP over SSL is requested with an ldaps URL in server_host |
version = 3, start_tls = no | still valid; the default version is still 2 and ldaps needs version 3 set explicitly; start_tls must not be set together with an ldaps URL |
bind = yes with bind_dn and bind_pw | still valid; bind = sasl exists since 2.8. The file should be readable only by the Postfix user |
no tls_require_cert, no tls_ca_cert_file | the default is still no: the trust chain of the server certificate is not checked. yes needs tls_ca_cert_file or tls_ca_cert_dir |
| simple bind to Active Directory over port 636 | a domain controller that requires LDAP signing rejects simple binds on clear-text connections; simple binds over TLS are not affected |
result_attribute, result_format = %d/%u/Maildir/ | both still documented with the same meaning |
The map would be read unchanged by a current Postfix. What it leaves at the default is the weak point: the connection to the domain controller is encrypted, but the certificate is not verified.