postfix.sh 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. # Wait for MySQL to warm-up
  5. while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  6. echo "Waiting for database to come up..."
  7. sleep 2
  8. done
  9. until dig +short mailcow.email > /dev/null; do
  10. echo "Waiting for DNS..."
  11. sleep 1
  12. done
  13. cat <<EOF > /etc/aliases
  14. # Autogenerated by mailcow
  15. null: /dev/null
  16. watchdog: /dev/null
  17. ham: "|/usr/local/bin/rspamd-pipe-ham"
  18. spam: "|/usr/local/bin/rspamd-pipe-spam"
  19. EOF
  20. newaliases;
  21. # create sni configuration
  22. if [[ "${SKIP_LETS_ENCRYPT}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  23. echo -n "" > /opt/postfix/conf/sni.map
  24. else
  25. echo -n "" > /opt/postfix/conf/sni.map;
  26. for cert_dir in /etc/ssl/mail/*/ ; do
  27. if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
  28. continue;
  29. fi
  30. IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
  31. for domain in "${domains[@]}"; do
  32. echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
  33. echo "" >> /opt/postfix/conf/sni.map;
  34. done
  35. done
  36. fi
  37. postmap -F hash:/opt/postfix/conf/sni.map;
  38. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_ne.cf
  39. # Autogenerated by mailcow
  40. user = ${DBUSER}
  41. password = ${DBPASS}
  42. hosts = unix:/var/run/mysqld/mysqld.sock
  43. dbname = ${DBNAME}
  44. query = SELECT IF(EXISTS(SELECT address, domain FROM alias
  45. WHERE address = '%s'
  46. AND domain IN (
  47. SELECT domain FROM domain
  48. WHERE backupmx = '1'
  49. AND relay_all_recipients = '1'
  50. AND relay_unknown_only = '1')
  51. ), 'lmtp:inet:dovecot:24', NULL) AS 'transport'
  52. EOF
  53. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  54. # Autogenerated by mailcow
  55. user = ${DBUSER}
  56. password = ${DBPASS}
  57. hosts = unix:/var/run/mysqld/mysqld.sock
  58. dbname = ${DBNAME}
  59. query = SELECT DISTINCT
  60. CASE WHEN '%d' IN (
  61. SELECT domain FROM domain
  62. WHERE relay_all_recipients=1
  63. AND domain='%d'
  64. AND backupmx=1
  65. )
  66. THEN '%s' ELSE (
  67. SELECT goto FROM alias WHERE address='%s' AND active='1'
  68. )
  69. END AS result;
  70. EOF
  71. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  72. # Autogenerated by mailcow
  73. user = ${DBUSER}
  74. password = ${DBPASS}
  75. hosts = unix:/var/run/mysqld/mysqld.sock
  76. dbname = ${DBNAME}
  77. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  78. EOF
  79. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  80. # Autogenerated by mailcow
  81. user = ${DBUSER}
  82. password = ${DBPASS}
  83. hosts = unix:/var/run/mysqld/mysqld.sock
  84. dbname = ${DBNAME}
  85. query = SELECT IF(EXISTS(
  86. SELECT 'TLS_ACTIVE' FROM alias
  87. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  88. WHERE (address='%s'
  89. OR address IN (
  90. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  91. WHERE alias_domain='%d'
  92. )
  93. ) AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_in')) = '1' AND mailbox.active = '1'
  94. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  95. EOF
  96. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  97. # Autogenerated by mailcow
  98. user = ${DBUSER}
  99. password = ${DBPASS}
  100. hosts = unix:/var/run/mysqld/mysqld.sock
  101. dbname = ${DBNAME}
  102. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  103. FROM (
  104. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  105. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  106. WHERE (address = '%s'
  107. OR address IN (
  108. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  109. WHERE alias_domain = '%d'
  110. )
  111. )
  112. AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_out')) = '1'
  113. AND mailbox.active = '1'
  114. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  115. UNION ALL
  116. SELECT COALESCE(
  117. (SELECT hostname FROM relayhosts
  118. LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id
  119. WHERE relayhosts.active = '1'
  120. AND (
  121. mailbox.username IN (SELECT alias.goto from alias
  122. JOIN mailbox ON mailbox.username = alias.goto
  123. WHERE alias.active = '1'
  124. AND alias.address = '%s'
  125. AND alias.address NOT LIKE '@%%'
  126. )
  127. )
  128. ),
  129. (SELECT hostname FROM relayhosts
  130. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  131. WHERE relayhosts.active = '1'
  132. AND (domain.domain = '%d'
  133. OR domain.domain IN (
  134. SELECT target_domain FROM alias_domain
  135. WHERE alias_domain = '%d'
  136. )
  137. )
  138. )
  139. )
  140. ) AS transport_view;
  141. EOF
  142. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  143. # Autogenerated by mailcow
  144. user = ${DBUSER}
  145. password = ${DBPASS}
  146. hosts = unix:/var/run/mysqld/mysqld.sock
  147. dbname = ${DBNAME}
  148. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  149. WHERE active = '1'
  150. AND destination = '%s';
  151. EOF
  152. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  153. # Autogenerated by mailcow
  154. user = ${DBUSER}
  155. password = ${DBPASS}
  156. hosts = unix:/var/run/mysqld/mysqld.sock
  157. dbname = ${DBNAME}
  158. query = SELECT 'null@localhost' FROM mailbox
  159. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  160. EOF
  161. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  162. # Autogenerated by mailcow
  163. user = ${DBUSER}
  164. password = ${DBPASS}
  165. hosts = unix:/var/run/mysqld/mysqld.sock
  166. dbname = ${DBNAME}
  167. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  168. WHERE id IN (
  169. SELECT COALESCE(
  170. (SELECT id FROM relayhosts
  171. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  172. WHERE relayhosts.active = '1'
  173. AND (domain.domain = '%d'
  174. OR domain.domain IN (
  175. SELECT target_domain FROM alias_domain
  176. WHERE alias_domain = '%d'
  177. )
  178. )
  179. ),
  180. (SELECT id FROM relayhosts
  181. LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id
  182. WHERE relayhosts.active = '1'
  183. AND (
  184. mailbox.username IN (
  185. SELECT alias.goto from alias
  186. JOIN mailbox ON mailbox.username = alias.goto
  187. WHERE alias.active = '1'
  188. AND alias.address = '%s'
  189. AND alias.address NOT LIKE '@%%'
  190. )
  191. )
  192. )
  193. )
  194. )
  195. AND active = '1'
  196. AND username != '';
  197. EOF
  198. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  199. # Autogenerated by mailcow
  200. user = ${DBUSER}
  201. password = ${DBPASS}
  202. hosts = unix:/var/run/mysqld/mysqld.sock
  203. dbname = ${DBNAME}
  204. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  205. WHERE nexthop = '%s'
  206. AND active = '1'
  207. AND username != ''
  208. LIMIT 1;
  209. EOF
  210. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  211. # Autogenerated by mailcow
  212. user = ${DBUSER}
  213. password = ${DBPASS}
  214. hosts = unix:/var/run/mysqld/mysqld.sock
  215. dbname = ${DBNAME}
  216. query = SELECT username FROM mailbox, alias_domain
  217. WHERE alias_domain.alias_domain = '%d'
  218. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  219. AND (mailbox.active = '1' OR mailbox.active = '2')
  220. AND alias_domain.active='1'
  221. EOF
  222. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  223. # Autogenerated by mailcow
  224. user = ${DBUSER}
  225. password = ${DBPASS}
  226. hosts = unix:/var/run/mysqld/mysqld.sock
  227. dbname = ${DBNAME}
  228. query = SELECT goto FROM alias
  229. WHERE address='%s'
  230. AND (active='1' OR active='2');
  231. EOF
  232. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  233. # Autogenerated by mailcow
  234. user = ${DBUSER}
  235. password = ${DBPASS}
  236. hosts = unix:/var/run/mysqld/mysqld.sock
  237. dbname = ${DBNAME}
  238. query = SELECT bcc_dest FROM bcc_maps
  239. WHERE local_dest='%s'
  240. AND type='rcpt'
  241. AND active='1';
  242. EOF
  243. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  244. # Autogenerated by mailcow
  245. user = ${DBUSER}
  246. password = ${DBPASS}
  247. hosts = unix:/var/run/mysqld/mysqld.sock
  248. dbname = ${DBNAME}
  249. query = SELECT bcc_dest FROM bcc_maps
  250. WHERE local_dest='%s'
  251. AND type='sender'
  252. AND active='1';
  253. EOF
  254. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  255. # Autogenerated by mailcow
  256. user = ${DBUSER}
  257. password = ${DBPASS}
  258. hosts = unix:/var/run/mysqld/mysqld.sock
  259. dbname = ${DBNAME}
  260. query = SELECT new_dest FROM recipient_maps
  261. WHERE old_dest='%s'
  262. AND active='1';
  263. EOF
  264. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  265. # Autogenerated by mailcow
  266. user = ${DBUSER}
  267. password = ${DBPASS}
  268. hosts = unix:/var/run/mysqld/mysqld.sock
  269. dbname = ${DBNAME}
  270. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  271. UNION
  272. SELECT domain FROM domain
  273. WHERE domain='%s'
  274. AND active = '1'
  275. AND backupmx = '0'
  276. EOF
  277. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  278. # Autogenerated by mailcow
  279. user = ${DBUSER}
  280. password = ${DBPASS}
  281. hosts = unix:/var/run/mysqld/mysqld.sock
  282. dbname = ${DBNAME}
  283. query = SELECT CONCAT(JSON_UNQUOTE(JSON_VALUE(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND (active = '1' OR active = '2')
  284. EOF
  285. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  286. # Autogenerated by mailcow
  287. user = ${DBUSER}
  288. password = ${DBPASS}
  289. hosts = unix:/var/run/mysqld/mysqld.sock
  290. dbname = ${DBNAME}
  291. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  292. EOF
  293. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  294. # Autogenerated by mailcow
  295. user = ${DBUSER}
  296. password = ${DBPASS}
  297. hosts = unix:/var/run/mysqld/mysqld.sock
  298. dbname = ${DBNAME}
  299. # First select queries domain and alias_domain to determine if domains are active.
  300. query = SELECT goto FROM alias
  301. WHERE id IN (
  302. SELECT COALESCE (
  303. (
  304. SELECT id FROM alias
  305. WHERE address='%s'
  306. AND (active='1' OR active='2')
  307. ), (
  308. SELECT id FROM alias
  309. WHERE address='@%d'
  310. AND (active='1' OR active='2')
  311. )
  312. )
  313. )
  314. AND active='1'
  315. AND (domain IN
  316. (SELECT domain FROM domain
  317. WHERE domain='%d'
  318. AND active='1')
  319. OR domain in (
  320. SELECT alias_domain FROM alias_domain
  321. WHERE alias_domain='%d'
  322. AND active='1'
  323. )
  324. )
  325. UNION
  326. SELECT logged_in_as FROM sender_acl
  327. WHERE send_as='@%d'
  328. OR send_as='%s'
  329. OR send_as='*'
  330. OR send_as IN (
  331. SELECT CONCAT('@',target_domain) FROM alias_domain
  332. WHERE alias_domain = '%d')
  333. OR send_as IN (
  334. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  335. WHERE alias_domain = '%d')
  336. AND logged_in_as NOT IN (
  337. SELECT goto FROM alias
  338. WHERE address='%s')
  339. UNION
  340. SELECT username FROM mailbox, alias_domain
  341. WHERE alias_domain.alias_domain = '%d'
  342. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  343. AND (mailbox.active = '1' OR mailbox.active ='2')
  344. AND alias_domain.active='1';
  345. EOF
  346. # MX based routing
  347. cat <<EOF > /opt/postfix/conf/sql/mysql_mbr_access_maps.cf
  348. # Autogenerated by mailcow
  349. user = ${DBUSER}
  350. password = ${DBPASS}
  351. hosts = unix:/var/run/mysqld/mysqld.sock
  352. dbname = ${DBNAME}
  353. query = SELECT CONCAT('FILTER smtp_via_transport_maps:', nexthop) as transport FROM transports
  354. WHERE '%s' REGEXP destination
  355. AND active='1'
  356. AND is_mx_based='1';
  357. EOF
  358. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  359. # Autogenerated by mailcow
  360. user = ${DBUSER}
  361. password = ${DBPASS}
  362. hosts = unix:/var/run/mysqld/mysqld.sock
  363. dbname = ${DBNAME}
  364. query = SELECT goto FROM spamalias
  365. WHERE address='%s'
  366. AND validity >= UNIX_TIMESTAMP()
  367. EOF
  368. if [ ! -f /opt/postfix/conf/dns_blocklists.cf ]; then
  369. cat <<EOF > /opt/postfix/conf/dns_blocklists.cf
  370. # This file can be edited.
  371. # Delete this file and restart postfix container to revert any changes.
  372. postscreen_dnsbl_sites = wl.mailspike.net=127.0.0.[18;19;20]*-2
  373. hostkarma.junkemailfilter.com=127.0.0.1*-2
  374. list.dnswl.org=127.0.[0..255].0*-2
  375. list.dnswl.org=127.0.[0..255].1*-4
  376. list.dnswl.org=127.0.[0..255].2*-6
  377. list.dnswl.org=127.0.[0..255].3*-8
  378. ix.dnsbl.manitu.net*2
  379. bl.spamcop.net*2
  380. bl.suomispam.net*2
  381. hostkarma.junkemailfilter.com=127.0.0.2*3
  382. hostkarma.junkemailfilter.com=127.0.0.4*2
  383. hostkarma.junkemailfilter.com=127.0.1.2*1
  384. backscatter.spameatingmonkey.net*2
  385. bl.ipv6.spameatingmonkey.net*2
  386. bl.spameatingmonkey.net*2
  387. b.barracudacentral.org=127.0.0.2*7
  388. bl.mailspike.net=127.0.0.2*5
  389. bl.mailspike.net=127.0.0.[10;11;12]*4
  390. dnsbl.sorbs.net=127.0.0.10*8
  391. dnsbl.sorbs.net=127.0.0.5*6
  392. dnsbl.sorbs.net=127.0.0.7*3
  393. dnsbl.sorbs.net=127.0.0.8*2
  394. dnsbl.sorbs.net=127.0.0.6*2
  395. dnsbl.sorbs.net=127.0.0.9*2
  396. EOF
  397. fi
  398. DNSBL_CONFIG=$(grep -v '^#' /opt/postfix/conf/dns_blocklists.cf | grep '\S')
  399. if [ ! -z "$DNSBL_CONFIG" ]; then
  400. echo -e "\e[33mChecking if ASN for your IP is listed for Spamhaus Bad ASN List...\e[0m"
  401. if [ -n "$SPAMHAUS_DQS_KEY" ]; then
  402. echo -e "\e[32mDetected SPAMHAUS_DQS_KEY variable from mailcow.conf...\e[0m"
  403. echo -e "\e[33mUsing DQS Blocklists from Spamhaus!\e[0m"
  404. SPAMHAUS_DNSBL_CONFIG=$(cat <<EOF
  405. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.[4..7]*6
  406. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.[10;11]*8
  407. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.3*4
  408. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.2*3
  409. postscreen_dnsbl_reply_map = texthash:/opt/postfix/conf/dnsbl_reply.map
  410. EOF
  411. cat <<EOF > /opt/postfix/conf/dnsbl_reply.map
  412. # Autogenerated by mailcow, using Spamhaus DQS reply domains
  413. ${SPAMHAUS_DQS_KEY}.sbl.dq.spamhaus.net sbl.spamhaus.org
  414. ${SPAMHAUS_DQS_KEY}.xbl.dq.spamhaus.net xbl.spamhaus.org
  415. ${SPAMHAUS_DQS_KEY}.pbl.dq.spamhaus.net pbl.spamhaus.org
  416. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net zen.spamhaus.org
  417. ${SPAMHAUS_DQS_KEY}.dbl.dq.spamhaus.net dbl.spamhaus.org
  418. ${SPAMHAUS_DQS_KEY}.zrd.dq.spamhaus.net zrd.spamhaus.org
  419. EOF
  420. )
  421. else
  422. if [ -f "/opt/postfix/conf/dnsbl_reply.map" ]; then
  423. rm /opt/postfix/conf/dnsbl_reply.map
  424. fi
  425. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  426. if [ "$response" -eq 503 ]; then
  427. echo -e "\e[31mThe AS of your IP is listed as a banned AS from Spamhaus!\e[0m"
  428. echo -e "\e[33mNo SPAMHAUS_DQS_KEY found... Skipping Spamhaus blocklists entirely!\e[0m"
  429. SPAMHAUS_DNSBL_CONFIG=""
  430. elif [ "$response" -eq 200 ]; then
  431. echo -e "\e[32mThe AS of your IP is NOT listed as a banned AS from Spamhaus!\e[0m"
  432. echo -e "\e[33mUsing the open Spamhaus blocklists.\e[0m"
  433. SPAMHAUS_DNSBL_CONFIG=$(cat <<EOF
  434. zen.spamhaus.org=127.0.0.[10;11]*8
  435. zen.spamhaus.org=127.0.0.[4..7]*6
  436. zen.spamhaus.org=127.0.0.3*4
  437. zen.spamhaus.org=127.0.0.2*3
  438. EOF
  439. )
  440. else
  441. echo -e "\e[31mWe couldn't determine your AS... (maybe DNS/Network issue?) Response Code: $response\e[0m"
  442. echo -e "\e[33mDeactivating Spamhaus DNS Blocklists to be on the safe site!\e[0m"
  443. SPAMHAUS_DNSBL_CONFIG=""
  444. fi
  445. fi
  446. fi
  447. # Reset main.cf
  448. sed -i '/Overrides/q' /opt/postfix/conf/main.cf
  449. echo >> /opt/postfix/conf/main.cf
  450. # Append postscreen dnsbl sites to main.cf
  451. if [ ! -z "$DNSBL_CONFIG" ]; then
  452. echo -e "${DNSBL_CONFIG}\n${SPAMHAUS_DNSBL_CONFIG}" >> /opt/postfix/conf/main.cf
  453. fi
  454. # Append user overrides
  455. echo -e "\n# User Overrides" >> /opt/postfix/conf/main.cf
  456. touch /opt/postfix/conf/extra.cf
  457. sed -i '/\$myhostname/! { /myhostname/d }' /opt/postfix/conf/extra.cf
  458. echo -e "myhostname = ${MAILCOW_HOSTNAME}\n$(cat /opt/postfix/conf/extra.cf)" > /opt/postfix/conf/extra.cf
  459. cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
  460. if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
  461. echo "Creating dummy custom_transport.pcre"
  462. touch /opt/postfix/conf/custom_transport.pcre
  463. fi
  464. if [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then
  465. echo "Creating dummy custom_postscreen_whitelist.cidr"
  466. cat <<EOF > /opt/postfix/conf/custom_postscreen_whitelist.cidr
  467. # Autogenerated by mailcow
  468. # Rules are evaluated in the order as specified.
  469. # Blacklist 192.168.* except 192.168.0.1.
  470. # 192.168.0.1 permit
  471. # 192.168.0.0/16 reject
  472. EOF
  473. fi
  474. # Fix Postfix permissions
  475. chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
  476. chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
  477. chgrp -R postdrop /var/spool/postfix/public
  478. chgrp -R postdrop /var/spool/postfix/maildrop
  479. postfix set-permissions
  480. # Check Postfix configuration
  481. postconf -c /opt/postfix/conf > /dev/null
  482. if [[ $? != 0 ]]; then
  483. echo "Postfix configuration error, refusing to start."
  484. exit 1
  485. else
  486. postfix -c /opt/postfix/conf start
  487. sleep 126144000
  488. fi