Email - bash-postfix-encrypt-filter-sync-smime.service (systemd unit)
Email Solution · Config document · referenced from High availability and key synchronization
The systemd unit that starts the synchronization loop for S/MIME certificates at boot and keeps it in the background.
| Item | Value |
|---|---|
| Path on the server | /etc/systemd/system/bash-postfix-encrypt-filter-sync-smime.service |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001, identical (diff is empty) |
| Starts | /usr/local/bin/bash-postfix-encrypt-filter-sync-smime.sh, as root |
| Activated with | systemctl start and systemctl enable of the unit |
| systemd at the time | the one of RHEL 7 |
The file
[Unit] Description = BASH postfix encrypt filter - SMIME certs synchronization After = network.target [Service] PIDFile = /run/bash-postfix-encrypt-filter-sync-smime.pid User = root Group = root WorkingDirectory = /var/spool/postfix/bash-postfix-encrypt-filter/smime/ ExecStart = /bin/bash /usr/local/bin/bash-postfix-encrypt-filter-sync-smime.sh ExecReload = /bin/kill -s HUP $MAINPID ExecStop = /bin/kill -s TERM $MAINPID PrivateTmp = true [Install] WantedBy = multi-user.target
Reading it today
- There is no
Restart=line. The design says that systemd restarts the service when it is found not running. This unit does not ask for that: the default isRestart=no, so a loop that dies stays dead until somebody starts it. PIDFile=has no effect. WithoutType=the unit is of typesimple, systemd follows the process it started, and nobody writes that file.ExecReloadstops the service. The script has no handler forHUP, so a reload ends the Bash process.After = network.targetorders the unit after the network stack has been brought up; it does not mean that the network is configured, which is whatnetwork-online.targetis for. The loop does not care: the firstrsynchappens at the first change of the directory.- The install notes carry a slip. The heading of this unit there names the file of the PGP unit a second time; the content is the one shown here.
Checked against current systemd
| As built | Today |
|---|---|
PIDFile = without Type= | Still valid, still without function here. systemd recommends PIDFile= only for Type=forking and says PID files should be avoided in new units |
After = network.target | Still valid; network-online.target exists for units that need a configured network |
ExecStart, ExecReload, ExecStop, User, Group, PrivateTmp, WantedBy | All still valid |
The unit loads unchanged on a current system, and is as incomplete there as it was.