LINUXOR.SK ... open source notes ...

Email - Postfix LDAP map: virtual mailbox maps

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Active Directory integration

notebind_pw holds the password of the bind account in clear text; <LDAP_BIND_PASSWORD> is a placeholder. The install notes do not record the owner and mode of this file. It must not be world-readable: ldap_table(5) asks for a file that only the Postfix user can read.

The lookup table behind virtual_mailbox_maps: it tells Postfix which addresses of the own domain exist, and returns the mailbox path relative to the mailbox base in the form domain/user/Maildir/.

ItemValue
Path on the server/etc/postfix/ad_virtual_mailbox_maps.cf
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001 and DC2-A-VCMSX002, identical
Referenced byvirtual_mailbox_maps = proxy:ldap:/etc/postfix/ad_virtual_mailbox_maps.cf in main.cf
Directory serversDC2-A-VCAD001 and DC2-A-VCAD002, LDAPS on port 636, IPv4 only
SoftwarePostfix 2.10.1, LDAP client of the RHEL 7 package
Activated withpostfix reload; an LDAP table is queried live and needs no postmap

The file

ini
# LDAP Server settings
# Due to problems in LDAP clients/LDAP libraries in dual IP stacks (IPv4, IPv6) environments, this configuration (parameter "server_host") contains only IPv4 addresses.
#
# DC2-A-VCAD001 - 10.12.16.209
# DC2-A-VCAD002 - 10.12.16.210
server_host     = ldaps://10.12.16.209:636, ldaps://10.12.16.210:636
search_base     = DC=ad-dc2,DC=example,DC=net
scope           = sub
version         = 3
start_tls       = no

# LDAP User Binding settings
bind            = yes
bind_dn         = cn=vmail_svc,ou=users_svc,DC=ad-dc2,DC=example,DC=net
bind_pw         = <LDAP_BIND_PASSWORD>

# LDAP Filter settings
query_filter    = (&(objectclass=person)(userPrincipalName=%s))
result_attribute= userPrincipalName
result_format   = %d/%u/Maildir/

# LDAP Debug settings
debuglevel      = 0

Differences on the other hosts

DC2-B-VCMSX001 and DC2-A-VCMSX002 carry the same file; diff shows node A and DC2-A-VCMSX002 identical, and on node B nothing but a missing empty last line. The first design shows the site 1 variant: DNS names of the domain controllers in server_host instead of IPv4 addresses, and the base DN DC=ad,DC=example,DC=net.

On the internal pair the returned path is never used for a delivery, because the transport table sends the domain on to the mailbox server; the lookup serves to reject unknown recipients at RCPT TO. Unlike the sender login map, this filter does not exclude disabled accounts.

Checked against Postfix 3.11

As builtToday
server_host = ldaps://…:636still valid: LDAP over SSL is requested with an ldaps URL in server_host
version = 3, start_tls = nostill valid; the default version is still 2 and ldaps needs version 3 set explicitly; start_tls must not be set together with an ldaps URL
bind = yes with bind_dn and bind_pwstill valid; bind = sasl exists since 2.8. The file should be readable only by the Postfix user
no tls_require_cert, no tls_ca_cert_filethe default is still no: the trust chain of the server certificate is not checked. yes needs tls_ca_cert_file or tls_ca_cert_dir
simple bind to Active Directory over port 636a domain controller that requires LDAP signing rejects simple binds on clear-text connections; simple binds over TLS are not affected
result_attribute, result_format = %d/%u/Maildir/both still documented with the same meaning

The map would be read unchanged by a current Postfix. What it leaves at the default is the weak point: the connection to the domain controller is encrypted, but the certificate is not verified.

← solutionz