Email - Postfix master.cf, mailbox server
Email Solution · Config document · referenced from Mailbox server
The Postfix service table of the mailbox server. It differs from the stock file in two places: the smtps listener on port 465 and, at the end, the dovecot transport that hands a message to Dovecot's delivery agent. Stock comments and the commented-out stock services are left out; only the column header is kept.
| Item | Value |
|---|---|
| Path on the server | /etc/postfix/master.cf |
| Shown here | DC2-A-VCMSX002 |
| Counterpart | Postfix master.cf, internal servers |
| Activated with | postfix reload |
| Software | Postfix 2.10.1 from the RHEL 7 repository |
The file
# ========================================================================== # service type private unpriv chroot wakeup maxproc command + args # (yes) (yes) (yes) (never) (100) # ========================================================================== smtp inet n - n - - smtpd # CFG-ON -> Email server accept connections also on SMTPS port (465) smtps inet n - n - - smtpd -o syslog_name=postfix/smtps -o smtpd_tls_wrappermode=yes -o smtpd_sasl_auth_enable=yes -o smtpd_reject_unlisted_recipient=no -o smtpd_recipient_restrictions=permit_sasl_authenticated,reject -o milter_macro_daemon_name=ORIGINATING pickup unix n - n 60 1 pickup cleanup unix n - n - 0 cleanup qmgr unix n - n 300 1 qmgr tlsmgr unix - - n 1000? 1 tlsmgr rewrite unix - - n - - trivial-rewrite bounce unix - - n - 0 bounce defer unix - - n - 0 bounce trace unix - - n - 0 bounce verify unix - - n - 1 verify flush unix n - n 1000? 0 flush proxymap unix - - n - - proxymap proxywrite unix - - n - 1 proxymap smtp unix - - n - - smtp relay unix - - n - - smtp showq unix n - n - - showq error unix - - n - - error retry unix - - n - - error discard unix - - n - - discard local unix - n n - - local virtual unix - n n - - virtual lmtp unix - - n - - lmtp anvil unix - - n - 1 anvil scache unix - - n - 1 scache # CFG-ON -> Dovecot daemon is responsible for local mail delivery dovecot unix - n n - - pipe flags=ODRhu user=vmail:vmail argv=/usr/libexec/dovecot/deliver -e -f ${sender} -d ${recipient}
Reading the dovecot transport
| Part | Meaning |
|---|---|
unpriv = n, chroot = n | the pipe daemon must be able to change to another user and to run a program outside the queue directory |
flags=ODRhu | add X-Original-To, Delivered-To and Return-Path headers; fold the next hop and the recipient to lower case |
user=vmail:vmail | run the delivery agent as the owner of the mail store |
/usr/libexec/dovecot/deliver | Dovecot's local delivery agent, the older name of dovecot-lda |
-e | on a rejection, report the reason to Postfix and let Postfix send the bounce |
-f ${sender} | envelope sender |
-d ${recipient} | deliver to this user; the mailbox location is asked from the user database |
The transport is selected by /etc/postfix/transport, and dovecot_destination_recipient_limit = 1 in main.cf makes Postfix call it once per recipient, which -d requires.
Differences from the internal pair
| Line | DC2-A-VCMSX001 and DC2-B-VCMSX001 | DC2-A-VCMSX002 |
|---|---|---|
bash-postfix-encrypt-filter service | defined | absent |
smtp listener | -o content_filter=bash-postfix-encrypt-filter: | no option |
smtps listener | the same options plus -o content_filter=bash-postfix-encrypt-filter: | no content filter |
dovecot transport | defined, not used | defined and used |
Checked against Postfix 3.11.7
| As built | Today |
|---|---|
service name smtps for port 465 | the stock file calls it submissions; smtps is the former name |
-o milter_macro_daemon_name=ORIGINATING | still in the stock template |
pipe with flags=ODRhu | flags still valid; D and O need a recipient limit of 1 |
/usr/libexec/dovecot/deliver | still installed, as a symbolic link to dovecot-lda |
| delivery through the LDA | Dovecot: "These days most people should use LMTP as the MDA instead" |
The stock template for the 465 service today also carries smtpd_forbid_unauth_pipelining=no and smtpd_hide_client_session=yes as examples. In Dovecot 2.4 dovecot-lda no longer uses the HOME environment variable and exits with a temporary failure on an invalid configuration.