postfix.sh 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. # Wait for MySQL to warm-up
  5. while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  6. echo "Waiting for database to come up..."
  7. sleep 2
  8. done
  9. until dig +short mailcow.email @unbound > /dev/null; do
  10. echo "Waiting for DNS..."
  11. sleep 1
  12. done
  13. cat <<EOF > /etc/aliases
  14. # Autogenerated by mailcow
  15. null: /dev/null
  16. watchdog: /dev/null
  17. ham: "|/usr/local/bin/rspamd-pipe-ham"
  18. spam: "|/usr/local/bin/rspamd-pipe-spam"
  19. EOF
  20. newaliases;
  21. # create sni configuration
  22. echo -n "" > /opt/postfix/conf/sni.map;
  23. for cert_dir in /etc/ssl/mail/*/ ; do
  24. if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
  25. continue;
  26. fi
  27. IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
  28. for domain in "${domains[@]}"; do
  29. echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
  30. echo "" >> /opt/postfix/conf/sni.map;
  31. done
  32. done
  33. postmap -F hash:/opt/postfix/conf/sni.map;
  34. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_ne.cf
  35. # Autogenerated by mailcow
  36. user = ${DBUSER}
  37. password = ${DBPASS}
  38. hosts = unix:/var/run/mysqld/mysqld.sock
  39. dbname = ${DBNAME}
  40. query = SELECT IF(EXISTS(SELECT address, domain FROM alias
  41. WHERE address = '%s'
  42. AND domain IN (
  43. SELECT domain FROM domain
  44. WHERE backupmx = '1'
  45. AND relay_all_recipients = '1'
  46. AND relay_unknown_only = '1')
  47. ), 'lmtp:inet:dovecot:24', NULL) AS 'transport'
  48. EOF
  49. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  50. # Autogenerated by mailcow
  51. user = ${DBUSER}
  52. password = ${DBPASS}
  53. hosts = unix:/var/run/mysqld/mysqld.sock
  54. dbname = ${DBNAME}
  55. query = SELECT DISTINCT
  56. CASE WHEN '%d' IN (
  57. SELECT domain FROM domain
  58. WHERE relay_all_recipients=1
  59. AND domain='%d'
  60. AND backupmx=1
  61. )
  62. THEN '%s' ELSE (
  63. SELECT goto FROM alias WHERE address='%s' AND active='1'
  64. )
  65. END AS result;
  66. EOF
  67. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  68. # Autogenerated by mailcow
  69. user = ${DBUSER}
  70. password = ${DBPASS}
  71. hosts = unix:/var/run/mysqld/mysqld.sock
  72. dbname = ${DBNAME}
  73. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  74. EOF
  75. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  76. # Autogenerated by mailcow
  77. user = ${DBUSER}
  78. password = ${DBPASS}
  79. hosts = unix:/var/run/mysqld/mysqld.sock
  80. dbname = ${DBNAME}
  81. query = SELECT IF(EXISTS(
  82. SELECT 'TLS_ACTIVE' FROM alias
  83. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  84. WHERE (address='%s'
  85. OR address IN (
  86. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  87. WHERE alias_domain='%d'
  88. )
  89. ) AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_in')) = '1' AND mailbox.active = '1'
  90. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  91. EOF
  92. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  93. # Autogenerated by mailcow
  94. user = ${DBUSER}
  95. password = ${DBPASS}
  96. hosts = unix:/var/run/mysqld/mysqld.sock
  97. dbname = ${DBNAME}
  98. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  99. FROM (
  100. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  101. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  102. WHERE (address = '%s'
  103. OR address IN (
  104. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  105. WHERE alias_domain = '%d'
  106. )
  107. )
  108. AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_out')) = '1'
  109. AND mailbox.active = '1'
  110. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  111. UNION ALL
  112. SELECT hostname AS transport FROM relayhosts
  113. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  114. WHERE relayhosts.active = '1'
  115. AND domain = '%d'
  116. OR domain IN (
  117. SELECT target_domain FROM alias_domain
  118. WHERE alias_domain = '%d'
  119. )
  120. )
  121. AS transport_view;
  122. EOF
  123. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  124. # Autogenerated by mailcow
  125. user = ${DBUSER}
  126. password = ${DBPASS}
  127. hosts = unix:/var/run/mysqld/mysqld.sock
  128. dbname = ${DBNAME}
  129. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  130. WHERE active = '1'
  131. AND destination = '%s';
  132. EOF
  133. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  134. # Autogenerated by mailcow
  135. user = ${DBUSER}
  136. password = ${DBPASS}
  137. hosts = unix:/var/run/mysqld/mysqld.sock
  138. dbname = ${DBNAME}
  139. query = SELECT 'null@localhost' FROM mailbox
  140. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  141. EOF
  142. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  143. # Autogenerated by mailcow
  144. user = ${DBUSER}
  145. password = ${DBPASS}
  146. hosts = unix:/var/run/mysqld/mysqld.sock
  147. dbname = ${DBNAME}
  148. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  149. WHERE id IN (
  150. SELECT relayhost FROM domain
  151. WHERE CONCAT('@', domain) = '%s'
  152. OR domain IN (
  153. SELECT target_domain FROM alias_domain WHERE CONCAT('@', alias_domain) = '%s'
  154. )
  155. )
  156. AND active = '1'
  157. AND username != '';
  158. EOF
  159. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  160. # Autogenerated by mailcow
  161. user = ${DBUSER}
  162. password = ${DBPASS}
  163. hosts = unix:/var/run/mysqld/mysqld.sock
  164. dbname = ${DBNAME}
  165. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  166. WHERE nexthop = '%s'
  167. AND active = '1'
  168. AND username != ''
  169. LIMIT 1;
  170. EOF
  171. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  172. # Autogenerated by mailcow
  173. user = ${DBUSER}
  174. password = ${DBPASS}
  175. hosts = unix:/var/run/mysqld/mysqld.sock
  176. dbname = ${DBNAME}
  177. query = SELECT username FROM mailbox, alias_domain
  178. WHERE alias_domain.alias_domain = '%d'
  179. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  180. AND (mailbox.active = '1' OR mailbox.active = '2')
  181. AND alias_domain.active='1'
  182. EOF
  183. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  184. # Autogenerated by mailcow
  185. user = ${DBUSER}
  186. password = ${DBPASS}
  187. hosts = unix:/var/run/mysqld/mysqld.sock
  188. dbname = ${DBNAME}
  189. query = SELECT goto FROM alias
  190. WHERE address='%s'
  191. AND (active='1' OR active='2');
  192. EOF
  193. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  194. # Autogenerated by mailcow
  195. user = ${DBUSER}
  196. password = ${DBPASS}
  197. hosts = unix:/var/run/mysqld/mysqld.sock
  198. dbname = ${DBNAME}
  199. query = SELECT bcc_dest FROM bcc_maps
  200. WHERE local_dest='%s'
  201. AND type='rcpt'
  202. AND active='1';
  203. EOF
  204. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  205. # Autogenerated by mailcow
  206. user = ${DBUSER}
  207. password = ${DBPASS}
  208. hosts = unix:/var/run/mysqld/mysqld.sock
  209. dbname = ${DBNAME}
  210. query = SELECT bcc_dest FROM bcc_maps
  211. WHERE local_dest='%s'
  212. AND type='sender'
  213. AND active='1';
  214. EOF
  215. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  216. # Autogenerated by mailcow
  217. user = ${DBUSER}
  218. password = ${DBPASS}
  219. hosts = unix:/var/run/mysqld/mysqld.sock
  220. dbname = ${DBNAME}
  221. query = SELECT new_dest FROM recipient_maps
  222. WHERE old_dest='%s'
  223. AND active='1';
  224. EOF
  225. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  226. # Autogenerated by mailcow
  227. user = ${DBUSER}
  228. password = ${DBPASS}
  229. hosts = unix:/var/run/mysqld/mysqld.sock
  230. dbname = ${DBNAME}
  231. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  232. UNION
  233. SELECT domain FROM domain
  234. WHERE domain='%s'
  235. AND active = '1'
  236. AND backupmx = '0'
  237. EOF
  238. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  239. # Autogenerated by mailcow
  240. user = ${DBUSER}
  241. password = ${DBPASS}
  242. hosts = unix:/var/run/mysqld/mysqld.sock
  243. dbname = ${DBNAME}
  244. query = SELECT CONCAT(JSON_UNQUOTE(JSON_VALUE(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND (active = '1' OR active = '2')
  245. EOF
  246. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  247. # Autogenerated by mailcow
  248. user = ${DBUSER}
  249. password = ${DBPASS}
  250. hosts = unix:/var/run/mysqld/mysqld.sock
  251. dbname = ${DBNAME}
  252. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  253. EOF
  254. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  255. # Autogenerated by mailcow
  256. user = ${DBUSER}
  257. password = ${DBPASS}
  258. hosts = unix:/var/run/mysqld/mysqld.sock
  259. dbname = ${DBNAME}
  260. # First select queries domain and alias_domain to determine if domains are active.
  261. query = SELECT goto FROM alias
  262. WHERE address='%s'
  263. AND active='1'
  264. AND (domain IN
  265. (SELECT domain FROM domain
  266. WHERE domain='%d'
  267. AND active='1')
  268. OR domain in (
  269. SELECT alias_domain FROM alias_domain
  270. WHERE alias_domain='%d'
  271. AND active='1'
  272. )
  273. )
  274. UNION
  275. SELECT logged_in_as FROM sender_acl
  276. WHERE send_as='@%d'
  277. OR send_as='%s'
  278. OR send_as='*'
  279. OR send_as IN (
  280. SELECT CONCAT('@',target_domain) FROM alias_domain
  281. WHERE alias_domain = '%d')
  282. OR send_as IN (
  283. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  284. WHERE alias_domain = '%d')
  285. AND logged_in_as NOT IN (
  286. SELECT goto FROM alias
  287. WHERE address='%s')
  288. UNION
  289. SELECT username FROM mailbox, alias_domain
  290. WHERE alias_domain.alias_domain = '%d'
  291. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  292. AND (mailbox.active = '1' OR mailbox.active ='2')
  293. AND alias_domain.active='1'
  294. EOF
  295. # Reject sasl usernames with smtp disabled
  296. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_access_maps.cf
  297. # Autogenerated by mailcow
  298. user = ${DBUSER}
  299. password = ${DBPASS}
  300. hosts = unix:/var/run/mysqld/mysqld.sock
  301. dbname = ${DBNAME}
  302. query = SELECT 'REJECT' FROM mailbox WHERE username = '%u' AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.smtp_access')) = '0';
  303. EOF
  304. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  305. # Autogenerated by mailcow
  306. user = ${DBUSER}
  307. password = ${DBPASS}
  308. hosts = unix:/var/run/mysqld/mysqld.sock
  309. dbname = ${DBNAME}
  310. query = SELECT goto FROM spamalias
  311. WHERE address='%s'
  312. AND validity >= UNIX_TIMESTAMP()
  313. EOF
  314. sed -i '/User overrides/q' /opt/postfix/conf/main.cf
  315. echo >> /opt/postfix/conf/main.cf
  316. if [ -f /opt/postfix/conf/extra.cf ]; then
  317. cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
  318. fi
  319. if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
  320. echo "Creating dummy custom_transport.pcre"
  321. touch /opt/postfix/conf/custom_transport.pcre
  322. fi
  323. if [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then
  324. echo "Creating dummy custom_postscreen_whitelist.cidr"
  325. echo '# Autogenerated by mailcow' > /opt/postfix/conf/custom_postscreen_whitelist.cidr
  326. fi
  327. # Fix SMTP last login on slaves
  328. sed -i "s/__REDIS_SLAVEOF_IP__/${REDIS_SLAVEOF_IP}/g" /usr/local/bin/smtpd_last_login.sh
  329. # Fix Postfix permissions
  330. chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
  331. chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
  332. chgrp -R postdrop /var/spool/postfix/public
  333. chgrp -R postdrop /var/spool/postfix/maildrop
  334. postfix set-permissions
  335. # Check Postfix configuration
  336. postconf -c /opt/postfix/conf > /dev/null
  337. if [[ $? != 0 ]]; then
  338. echo "Postfix configuration error, refusing to start."
  339. exit 1
  340. else
  341. postfix -c /opt/postfix/conf start
  342. sleep 126144000
  343. fi