postfix.sh 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. [[ ! -d /opt/postfix/conf/postfix-tlspol ]] && mkdir -p /opt/postfix/conf/postfix-tlspol
  5. [[ ! -d /etc/postfix-tlspol ]] && mkdir -p /etc/postfix-tlspol
  6. [[ ! -d /var/lib/postfix-tlspol ]] && mkdir -p /var/lib/postfix-tlspol
  7. # Wait for MySQL to warm-up
  8. while ! mariadb-admin status --ssl=false --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  9. echo "Waiting for database to come up..."
  10. sleep 2
  11. done
  12. until dig +short mailcow.email > /dev/null; do
  13. echo "Waiting for DNS..."
  14. sleep 1
  15. done
  16. cat <<EOF > /etc/aliases
  17. # Autogenerated by mailcow
  18. null: /dev/null
  19. watchdog: /dev/null
  20. ham: "|/usr/local/bin/rspamd-pipe-ham"
  21. spam: "|/usr/local/bin/rspamd-pipe-spam"
  22. EOF
  23. newaliases;
  24. # create sni configuration
  25. if [[ "${SKIP_LETS_ENCRYPT}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  26. echo -n "" > /opt/postfix/conf/sni.map
  27. else
  28. echo -n "" > /opt/postfix/conf/sni.map;
  29. for cert_dir in /etc/ssl/mail/*/ ; do
  30. if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
  31. continue;
  32. fi
  33. IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
  34. for domain in "${domains[@]}"; do
  35. echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
  36. echo "" >> /opt/postfix/conf/sni.map;
  37. done
  38. done
  39. fi
  40. postmap -F hash:/opt/postfix/conf/sni.map;
  41. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_ne.cf
  42. # Autogenerated by mailcow
  43. user = ${DBUSER}
  44. password = ${DBPASS}
  45. hosts = unix:/var/run/mysqld/mysqld.sock
  46. dbname = ${DBNAME}
  47. query = SELECT IF(EXISTS(SELECT address, domain FROM alias
  48. WHERE address = '%s'
  49. AND domain IN (
  50. SELECT domain FROM domain
  51. WHERE backupmx = '1'
  52. AND relay_all_recipients = '1'
  53. AND relay_unknown_only = '1')
  54. ), 'lmtp:inet:dovecot:24', NULL) AS 'transport'
  55. EOF
  56. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  57. # Autogenerated by mailcow
  58. user = ${DBUSER}
  59. password = ${DBPASS}
  60. hosts = unix:/var/run/mysqld/mysqld.sock
  61. dbname = ${DBNAME}
  62. query = SELECT DISTINCT
  63. CASE WHEN '%d' IN (
  64. SELECT domain FROM domain
  65. WHERE relay_all_recipients=1
  66. AND domain='%d'
  67. AND backupmx=1
  68. )
  69. THEN '%s' ELSE (
  70. SELECT goto FROM alias WHERE address='%s' AND active='1'
  71. )
  72. END AS result;
  73. EOF
  74. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  75. # Autogenerated by mailcow
  76. user = ${DBUSER}
  77. password = ${DBPASS}
  78. hosts = unix:/var/run/mysqld/mysqld.sock
  79. dbname = ${DBNAME}
  80. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  81. EOF
  82. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  83. # Autogenerated by mailcow
  84. user = ${DBUSER}
  85. password = ${DBPASS}
  86. hosts = unix:/var/run/mysqld/mysqld.sock
  87. dbname = ${DBNAME}
  88. query = SELECT IF(EXISTS(
  89. SELECT 'TLS_ACTIVE' FROM alias
  90. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  91. WHERE (address='%s'
  92. OR address IN (
  93. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  94. WHERE alias_domain='%d'
  95. )
  96. ) AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_in')) = '1' AND mailbox.active = '1'
  97. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  98. EOF
  99. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  100. # Autogenerated by mailcow
  101. user = ${DBUSER}
  102. password = ${DBPASS}
  103. hosts = unix:/var/run/mysqld/mysqld.sock
  104. dbname = ${DBNAME}
  105. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  106. FROM (
  107. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  108. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  109. WHERE (address = '%s'
  110. OR address IN (
  111. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  112. WHERE alias_domain = '%d'
  113. )
  114. )
  115. AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_out')) = '1'
  116. AND mailbox.active = '1'
  117. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  118. UNION ALL
  119. SELECT COALESCE(
  120. (SELECT hostname FROM relayhosts
  121. LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id
  122. WHERE relayhosts.active = '1'
  123. AND (
  124. mailbox.username IN (SELECT alias.goto from alias
  125. JOIN mailbox ON mailbox.username = alias.goto
  126. WHERE alias.active = '1'
  127. AND alias.address = '%s'
  128. AND alias.address NOT LIKE '@%%'
  129. )
  130. )
  131. ),
  132. (SELECT hostname FROM relayhosts
  133. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  134. WHERE relayhosts.active = '1'
  135. AND (domain.domain = '%d'
  136. OR domain.domain IN (
  137. SELECT target_domain FROM alias_domain
  138. WHERE alias_domain = '%d'
  139. )
  140. )
  141. )
  142. )
  143. ) AS transport_view;
  144. EOF
  145. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  146. # Autogenerated by mailcow
  147. user = ${DBUSER}
  148. password = ${DBPASS}
  149. hosts = unix:/var/run/mysqld/mysqld.sock
  150. dbname = ${DBNAME}
  151. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  152. WHERE active = '1'
  153. AND destination = '%s';
  154. EOF
  155. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  156. # Autogenerated by mailcow
  157. user = ${DBUSER}
  158. password = ${DBPASS}
  159. hosts = unix:/var/run/mysqld/mysqld.sock
  160. dbname = ${DBNAME}
  161. query = SELECT 'null@localhost' FROM mailbox
  162. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  163. EOF
  164. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  165. # Autogenerated by mailcow
  166. user = ${DBUSER}
  167. password = ${DBPASS}
  168. hosts = unix:/var/run/mysqld/mysqld.sock
  169. dbname = ${DBNAME}
  170. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  171. WHERE id IN (
  172. SELECT COALESCE(
  173. (SELECT id FROM relayhosts
  174. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  175. WHERE relayhosts.active = '1'
  176. AND (domain.domain = '%d'
  177. OR domain.domain IN (
  178. SELECT target_domain FROM alias_domain
  179. WHERE alias_domain = '%d'
  180. )
  181. )
  182. ),
  183. (SELECT id FROM relayhosts
  184. LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id
  185. WHERE relayhosts.active = '1'
  186. AND (
  187. mailbox.username IN (
  188. SELECT alias.goto from alias
  189. JOIN mailbox ON mailbox.username = alias.goto
  190. WHERE alias.active = '1'
  191. AND alias.address = '%s'
  192. AND alias.address NOT LIKE '@%%'
  193. )
  194. )
  195. )
  196. )
  197. )
  198. AND active = '1'
  199. AND username != '';
  200. EOF
  201. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  202. # Autogenerated by mailcow
  203. user = ${DBUSER}
  204. password = ${DBPASS}
  205. hosts = unix:/var/run/mysqld/mysqld.sock
  206. dbname = ${DBNAME}
  207. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  208. WHERE nexthop = '%s'
  209. AND active = '1'
  210. AND username != ''
  211. LIMIT 1;
  212. EOF
  213. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  214. # Autogenerated by mailcow
  215. user = ${DBUSER}
  216. password = ${DBPASS}
  217. hosts = unix:/var/run/mysqld/mysqld.sock
  218. dbname = ${DBNAME}
  219. query = SELECT username FROM mailbox, alias_domain
  220. WHERE alias_domain.alias_domain = '%d'
  221. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  222. AND (mailbox.active = '1' OR mailbox.active = '2')
  223. AND alias_domain.active='1'
  224. EOF
  225. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  226. # Autogenerated by mailcow
  227. user = ${DBUSER}
  228. password = ${DBPASS}
  229. hosts = unix:/var/run/mysqld/mysqld.sock
  230. dbname = ${DBNAME}
  231. query = SELECT goto FROM alias
  232. WHERE address='%s'
  233. AND (active='1' OR active='2');
  234. EOF
  235. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  236. # Autogenerated by mailcow
  237. user = ${DBUSER}
  238. password = ${DBPASS}
  239. hosts = unix:/var/run/mysqld/mysqld.sock
  240. dbname = ${DBNAME}
  241. query = SELECT bcc_dest FROM bcc_maps
  242. WHERE local_dest='%s'
  243. AND type='rcpt'
  244. AND active='1';
  245. EOF
  246. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  247. # Autogenerated by mailcow
  248. user = ${DBUSER}
  249. password = ${DBPASS}
  250. hosts = unix:/var/run/mysqld/mysqld.sock
  251. dbname = ${DBNAME}
  252. query = SELECT bcc_dest FROM bcc_maps
  253. WHERE local_dest='%s'
  254. AND type='sender'
  255. AND active='1';
  256. EOF
  257. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  258. # Autogenerated by mailcow
  259. user = ${DBUSER}
  260. password = ${DBPASS}
  261. hosts = unix:/var/run/mysqld/mysqld.sock
  262. dbname = ${DBNAME}
  263. query = SELECT new_dest FROM recipient_maps
  264. WHERE old_dest='%s'
  265. AND active='1';
  266. EOF
  267. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  268. # Autogenerated by mailcow
  269. user = ${DBUSER}
  270. password = ${DBPASS}
  271. hosts = unix:/var/run/mysqld/mysqld.sock
  272. dbname = ${DBNAME}
  273. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  274. UNION
  275. SELECT domain FROM domain
  276. WHERE domain='%s'
  277. AND active = '1'
  278. AND backupmx = '0'
  279. EOF
  280. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  281. # Autogenerated by mailcow
  282. user = ${DBUSER}
  283. password = ${DBPASS}
  284. hosts = unix:/var/run/mysqld/mysqld.sock
  285. dbname = ${DBNAME}
  286. query = SELECT CONCAT(JSON_UNQUOTE(JSON_VALUE(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND (active = '1' OR active = '2')
  287. EOF
  288. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  289. # Autogenerated by mailcow
  290. user = ${DBUSER}
  291. password = ${DBPASS}
  292. hosts = unix:/var/run/mysqld/mysqld.sock
  293. dbname = ${DBNAME}
  294. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  295. EOF
  296. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  297. # Autogenerated by mailcow
  298. user = ${DBUSER}
  299. password = ${DBPASS}
  300. hosts = unix:/var/run/mysqld/mysqld.sock
  301. dbname = ${DBNAME}
  302. # First select queries domain and alias_domain to determine if domains are active.
  303. query = SELECT goto FROM alias
  304. WHERE id IN (
  305. SELECT COALESCE (
  306. (
  307. SELECT id FROM alias
  308. WHERE address='%s'
  309. AND (active='1' OR active='2')
  310. ), (
  311. SELECT id FROM alias
  312. WHERE address='@%d'
  313. AND (active='1' OR active='2')
  314. )
  315. )
  316. )
  317. AND active='1'
  318. AND (domain IN
  319. (SELECT domain FROM domain
  320. WHERE domain='%d'
  321. AND active='1')
  322. OR domain in (
  323. SELECT alias_domain FROM alias_domain
  324. WHERE alias_domain='%d'
  325. AND active='1'
  326. )
  327. )
  328. UNION
  329. SELECT logged_in_as FROM sender_acl
  330. WHERE send_as='@%d'
  331. OR send_as='%s'
  332. OR send_as='*'
  333. OR send_as IN (
  334. SELECT CONCAT('@',target_domain) FROM alias_domain
  335. WHERE alias_domain = '%d')
  336. OR send_as IN (
  337. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  338. WHERE alias_domain = '%d')
  339. AND logged_in_as NOT IN (
  340. SELECT goto FROM alias
  341. WHERE address='%s')
  342. UNION
  343. SELECT username FROM mailbox, alias_domain
  344. WHERE alias_domain.alias_domain = '%d'
  345. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  346. AND (mailbox.active = '1' OR mailbox.active ='2')
  347. AND alias_domain.active='1';
  348. EOF
  349. # MX based routing
  350. cat <<EOF > /opt/postfix/conf/sql/mysql_mbr_access_maps.cf
  351. # Autogenerated by mailcow
  352. user = ${DBUSER}
  353. password = ${DBPASS}
  354. hosts = unix:/var/run/mysqld/mysqld.sock
  355. dbname = ${DBNAME}
  356. query = SELECT CONCAT('FILTER smtp_via_transport_maps:', nexthop) as transport FROM transports
  357. WHERE '%s' REGEXP destination
  358. AND active='1'
  359. AND is_mx_based='1';
  360. EOF
  361. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  362. # Autogenerated by mailcow
  363. user = ${DBUSER}
  364. password = ${DBPASS}
  365. hosts = unix:/var/run/mysqld/mysqld.sock
  366. dbname = ${DBNAME}
  367. query = SELECT goto FROM spamalias
  368. WHERE address='%s'
  369. AND validity >= UNIX_TIMESTAMP()
  370. EOF
  371. if [ ! -f /opt/postfix/conf/dns_blocklists.cf ]; then
  372. cat <<EOF > /opt/postfix/conf/dns_blocklists.cf
  373. # This file can be edited.
  374. # Delete this file and restart postfix container to revert any changes.
  375. postscreen_dnsbl_sites = wl.mailspike.net=127.0.0.[18;19;20]*-2
  376. hostkarma.junkemailfilter.com=127.0.0.1*-2
  377. list.dnswl.org=127.0.[0..255].0*-2
  378. list.dnswl.org=127.0.[0..255].1*-4
  379. list.dnswl.org=127.0.[0..255].2*-6
  380. list.dnswl.org=127.0.[0..255].3*-8
  381. bl.spamcop.net*2
  382. bl.suomispam.net*2
  383. hostkarma.junkemailfilter.com=127.0.0.2*3
  384. hostkarma.junkemailfilter.com=127.0.0.4*2
  385. hostkarma.junkemailfilter.com=127.0.1.2*1
  386. backscatter.spameatingmonkey.net*2
  387. bl.ipv6.spameatingmonkey.net*2
  388. bl.spameatingmonkey.net*2
  389. b.barracudacentral.org=127.0.0.2*7
  390. bl.mailspike.net=127.0.0.2*5
  391. bl.mailspike.net=127.0.0.[10;11;12]*4
  392. EOF
  393. fi
  394. # Remove discontinued DNSBLs from existing dns_blocklists.cf
  395. sed -i '/ix\.dnsbl\.manitu\.net\*2/d' /opt/postfix/conf/dns_blocklists.cf # Nixspam
  396. DNSBL_CONFIG=$(grep -v '^#' /opt/postfix/conf/dns_blocklists.cf | grep '\S')
  397. if [ ! -z "$DNSBL_CONFIG" ]; then
  398. echo -e "\e[33mChecking if ASN for your IP is listed for Spamhaus Bad ASN List...\e[0m"
  399. if [ -n "$SPAMHAUS_DQS_KEY" ]; then
  400. echo -e "\e[32mDetected SPAMHAUS_DQS_KEY variable from mailcow.conf...\e[0m"
  401. echo -e "\e[33mUsing DQS Blocklists from Spamhaus!\e[0m"
  402. SPAMHAUS_DNSBL_CONFIG=$(cat <<EOF
  403. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.[4..7]*6
  404. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.[10;11]*8
  405. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.3*4
  406. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.2*3
  407. postscreen_dnsbl_reply_map = texthash:/opt/postfix/conf/dnsbl_reply.map
  408. EOF
  409. cat <<EOF > /opt/postfix/conf/dnsbl_reply.map
  410. # Autogenerated by mailcow, using Spamhaus DQS reply domains
  411. ${SPAMHAUS_DQS_KEY}.sbl.dq.spamhaus.net sbl.spamhaus.org
  412. ${SPAMHAUS_DQS_KEY}.xbl.dq.spamhaus.net xbl.spamhaus.org
  413. ${SPAMHAUS_DQS_KEY}.pbl.dq.spamhaus.net pbl.spamhaus.org
  414. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net zen.spamhaus.org
  415. ${SPAMHAUS_DQS_KEY}.dbl.dq.spamhaus.net dbl.spamhaus.org
  416. ${SPAMHAUS_DQS_KEY}.zrd.dq.spamhaus.net zrd.spamhaus.org
  417. EOF
  418. )
  419. else
  420. if [ -f "/opt/postfix/conf/dnsbl_reply.map" ]; then
  421. rm /opt/postfix/conf/dnsbl_reply.map
  422. fi
  423. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  424. if [ "$response" -eq 503 ]; then
  425. echo -e "\e[31mThe AS of your IP is listed as a banned AS from Spamhaus!\e[0m"
  426. echo -e "\e[33mNo SPAMHAUS_DQS_KEY found... Skipping Spamhaus blocklists entirely!\e[0m"
  427. SPAMHAUS_DNSBL_CONFIG=""
  428. elif [ "$response" -eq 200 ]; then
  429. echo -e "\e[32mThe AS of your IP is NOT listed as a banned AS from Spamhaus!\e[0m"
  430. echo -e "\e[33mUsing the open Spamhaus blocklists.\e[0m"
  431. SPAMHAUS_DNSBL_CONFIG=$(cat <<EOF
  432. zen.spamhaus.org=127.0.0.[10;11]*8
  433. zen.spamhaus.org=127.0.0.[4..7]*6
  434. zen.spamhaus.org=127.0.0.3*4
  435. zen.spamhaus.org=127.0.0.2*3
  436. EOF
  437. )
  438. else
  439. echo -e "\e[31mWe couldn't determine your AS... (maybe DNS/Network issue?) Response Code: $response\e[0m"
  440. echo -e "\e[33mDeactivating Spamhaus DNS Blocklists to be on the safe site!\e[0m"
  441. SPAMHAUS_DNSBL_CONFIG=""
  442. fi
  443. fi
  444. fi
  445. # Reset main.cf
  446. sed -i '/Overrides/q' /opt/postfix/conf/main.cf
  447. echo >> /opt/postfix/conf/main.cf
  448. # Append postscreen dnsbl sites to main.cf
  449. if [ ! -z "$DNSBL_CONFIG" ]; then
  450. echo -e "${DNSBL_CONFIG}\n${SPAMHAUS_DNSBL_CONFIG}" >> /opt/postfix/conf/main.cf
  451. fi
  452. # Append user overrides
  453. echo -e "\n# User Overrides" >> /opt/postfix/conf/main.cf
  454. touch /opt/postfix/conf/extra.cf
  455. sed -i '/\$myhostname/! { /myhostname/d }' /opt/postfix/conf/extra.cf
  456. echo -e "myhostname = ${MAILCOW_HOSTNAME}\n$(cat /opt/postfix/conf/extra.cf)" > /opt/postfix/conf/extra.cf
  457. cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
  458. if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
  459. echo "Creating dummy custom_transport.pcre"
  460. touch /opt/postfix/conf/custom_transport.pcre
  461. fi
  462. if [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then
  463. echo "Creating dummy custom_postscreen_whitelist.cidr"
  464. cat <<EOF > /opt/postfix/conf/custom_postscreen_whitelist.cidr
  465. # Autogenerated by mailcow
  466. # Rules are evaluated in the order as specified.
  467. # Blacklist 192.168.* except 192.168.0.1.
  468. # 192.168.0.1 permit
  469. # 192.168.0.0/16 reject
  470. EOF
  471. fi
  472. cat <<EOF > /opt/postfix/conf/postfix-tlspol/config.yaml
  473. server:
  474. address: 127.0.0.1:8642
  475. log-level: info
  476. prefetch: true
  477. cache-file: /var/lib/postfix-tlspol/cache.db
  478. dns:
  479. # must support DNSSEC
  480. address: 127.0.0.11:53
  481. EOF
  482. # Fixing local command execution of postfix-tlspol with symlink to config
  483. if [ ! -L /etc/postfix-tlspol/config.yaml ]; then
  484. ln -s /opt/postfix/conf/postfix-tlspol/config.yaml /etc/postfix-tlspol/config.yaml
  485. fi
  486. # Fix Postfix permissions
  487. chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
  488. chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
  489. chgrp -R postdrop /var/spool/postfix/public
  490. chgrp -R postdrop /var/spool/postfix/maildrop
  491. postfix set-permissions
  492. # Checking if there is a leftover of a crashed postfix container before starting a new one
  493. if [ -e /var/spool/postfix/pid/master.pid ]; then
  494. rm -rf /var/spool/postfix/pid/master.pid
  495. fi
  496. # Check Postfix configuration
  497. postconf -c /opt/postfix/conf > /dev/null
  498. if [[ $? != 0 ]]; then
  499. echo "Postfix configuration error, refusing to start."
  500. exit 1
  501. else
  502. postfix -c /opt/postfix/conf start
  503. sleep 126144000
  504. fi