среда, 16 мая 2018 г.

Postfix + Dovecot + LetsEncrypt конфигурация


Конфиг для работы SMTP с SSL, самой инструкции по настройке почтового сервера нет и не будет. 😃


Postfix main.cf
########SASL############
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_auth_enable = yes
broken_sasl_atuh_clients = yes


#SSL
smtpd_use_tls=yes
smtpd_tls_security_level = may
smtpd_recipient_restrictions = permit_mynetworks,permit_sasl_authenticated,reject_unauth_pipelining,reject_non_fqdn_recipient,reject_unknown_recipient_domain,reject_unauth_destination
#,check_sender_access
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtpd_tls_session_cache_timeout = 3600s
######################################################################
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.yourdomain/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.yourdomain/privkey.pem


Dovecot

...conf.d/10-master.conf:
service_auth
service auth {
unix_listener /var/spool/postfix/private/auth {
mode = 0660
user = postfix
group = postfix       
}
}

...conf.d/10-auth.conf
auth_mechanisms = plain login

..conf.d/10-ssl.conf
 # SSL protocols to use
ssl_protocols = !SSLv2 !SSLv3

ssl = yes

ssl_cert = </etc/letsencrypt/live/mail.yourdomain/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.yourdomain/privkey.pem

Комментариев нет:

Отправить комментарий