Email - bash-postfix-encrypt-filter-sync-smime.sh (S/MIME certificate synchronization)
Email Solution · Config document · referenced from High availability and key synchronization
550). Do not copy that: whoever becomes that account can change what root runs.The loop that keeps the directory of S/MIME certificates the same on both internal servers. It waits for any change in the directory with inotifywait, fixes owner and mode of the files, and pushes the whole directory to the other node with rsync over ssh, deleting there what is not here. The other node runs the mirror image.
| Item | Value |
|---|---|
| Path on the server | /usr/local/bin/bash-postfix-encrypt-filter-sync-smime.sh |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001, pointing back at node A |
| Owner and mode | bash-postfix-encrypt-filter:bash-postfix-encrypt-filter, 550 |
| Runs as | root, from the systemd unit bash-postfix-encrypt-filter-sync-smime.service |
| Directory | /var/spool/postfix/bash-postfix-encrypt-filter/smime |
| Needs | rsync, inotify-tools, an ssh key of the filter account accepted on the other node |
The script
#!/bin/bash # # Supposed to run on DC2-A-VCMSX001 # SMIME_KEYS_DIR=/var/spool/postfix/bash-postfix-encrypt-filter/smime/ USER=bash-postfix-encrypt-filter HOST=dc2-b-vcmsx001.adm.example.net # Synchronization of SMIME public certificates while true; do inotifywait -r -e modify,attrib,close_write,move,create,delete $SMIME_KEYS_DIR chown bash-postfix-encrypt-filter:bash-postfix-encrypt-filter $SMIME_KEYS_DIR/* chmod 400 $SMIME_KEYS_DIR/* rsync -avz -e "ssh -o StrictHostKeyChecking=no -i /home/bash-postfix-encrypt-filter/.ssh/id_rsa" $SMIME_KEYS_DIR/ $USER@$HOST:$SMIME_KEYS_DIR/ --delete done
Differences between the hosts
| Host | Line | Value |
|---|---|---|
DC2-A-VCMSX001 | comment | # Supposed to run on DC2-A-VCMSX001 |
DC2-B-VCMSX001 | comment | # Supposed to run on DC2-B-VCMSX001 |
DC2-A-VCMSX001 | HOST= | dc2-b-vcmsx001.adm.example.net |
DC2-B-VCMSX001 | HOST= | dc2-a-vcmsx001.adm.example.net |
DC2-A-VCMSX001 | SMIME_KEYS_DIR= | /var/spool/postfix/bash-postfix-encrypt-filter/smime/ (trailing slash) |
DC2-B-VCMSX001 | SMIME_KEYS_DIR= | /var/spool/postfix/bash-postfix-encrypt-filter/smime |
That is the whole difference. The trailing slash on node A only produces a double slash in the paths, which changes nothing. The install notes show it on both nodes; the archived file of node B does not have it.
Reading it today
- Push with
--delete, from both sides. Whichever node sees an event first makes the other node equal to itself. What that means when both sides changed is worked through in High availability and key synchronization. - Events are only seen while
inotifywaitruns. A change that lands whilechown,chmodorrsyncare running is not noticed until the next event. StrictHostKeyChecking=noaccepts whatever host key the peer presents.- *
chmod 400 $SMIME_KEYS_DIR/** fails with a message when the directory is empty; the loop carries on.
Checked against inotify-tools 4 and rsync 3.4
| As built | Today |
|---|---|
inotifywait from inotify-tools | Upstream is active (4.26.262, September 2026). The package is not in RHEL 10; EPEL 10 has 4.23 |
rsync -avz --delete over ssh | rsync 3.4 is in RHEL 10 |
The event names of inotifywait 4.x, the rsync options and the policy of current OpenSSH towards an RSA key made with ssh-keygen -t rsa in 2019 were not re-checked.