LINUXOR.SK ... open source notes ...

Email - bash-postfix-encrypt-filter-sync-smime.sh (S/MIME certificate synchronization)

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from High availability and key synchronization

noteThe script runs as root and is owned by, and readable for, the unprivileged filter account (mode 550). Do not copy that: whoever becomes that account can change what root runs.

The loop that keeps the directory of S/MIME certificates the same on both internal servers. It waits for any change in the directory with inotifywait, fixes owner and mode of the files, and pushes the whole directory to the other node with rsync over ssh, deleting there what is not here. The other node runs the mirror image.

ItemValue
Path on the server/usr/local/bin/bash-postfix-encrypt-filter-sync-smime.sh
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001, pointing back at node A
Owner and modebash-postfix-encrypt-filter:bash-postfix-encrypt-filter, 550
Runs asroot, from the systemd unit bash-postfix-encrypt-filter-sync-smime.service
Directory/var/spool/postfix/bash-postfix-encrypt-filter/smime
Needsrsync, inotify-tools, an ssh key of the filter account accepted on the other node

The script

bash
#!/bin/bash
#
# Supposed to run on DC2-A-VCMSX001
#
SMIME_KEYS_DIR=/var/spool/postfix/bash-postfix-encrypt-filter/smime/
USER=bash-postfix-encrypt-filter
HOST=dc2-b-vcmsx001.adm.example.net

# Synchronization of SMIME public certificates
while true; do
    inotifywait -r -e modify,attrib,close_write,move,create,delete $SMIME_KEYS_DIR
    chown bash-postfix-encrypt-filter:bash-postfix-encrypt-filter $SMIME_KEYS_DIR/*
    chmod 400 $SMIME_KEYS_DIR/*
    rsync -avz -e "ssh -o StrictHostKeyChecking=no -i /home/bash-postfix-encrypt-filter/.ssh/id_rsa" $SMIME_KEYS_DIR/ $USER@$HOST:$SMIME_KEYS_DIR/ --delete
done

Differences between the hosts

HostLineValue
DC2-A-VCMSX001comment# Supposed to run on DC2-A-VCMSX001
DC2-B-VCMSX001comment# Supposed to run on DC2-B-VCMSX001
DC2-A-VCMSX001HOST=dc2-b-vcmsx001.adm.example.net
DC2-B-VCMSX001HOST=dc2-a-vcmsx001.adm.example.net
DC2-A-VCMSX001SMIME_KEYS_DIR=/var/spool/postfix/bash-postfix-encrypt-filter/smime/ (trailing slash)
DC2-B-VCMSX001SMIME_KEYS_DIR=/var/spool/postfix/bash-postfix-encrypt-filter/smime

That is the whole difference. The trailing slash on node A only produces a double slash in the paths, which changes nothing. The install notes show it on both nodes; the archived file of node B does not have it.

Reading it today

Checked against inotify-tools 4 and rsync 3.4

As builtToday
inotifywait from inotify-toolsUpstream is active (4.26.262, September 2026). The package is not in RHEL 10; EPEL 10 has 4.23
rsync -avz --delete over sshrsync 3.4 is in RHEL 10

The event names of inotifywait 4.x, the rsync options and the policy of current OpenSSH towards an RSA key made with ssh-keygen -t rsa in 2019 were not re-checked.

← solutionz