postfix.sh 6.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. cat <<EOF > /etc/aliases
  5. null: /dev/null
  6. ham: "|/usr/local/bin/rspamd-pipe-ham"
  7. spam: "|/usr/local/bin/rspamd-pipe-spam"
  8. EOF
  9. newaliases;
  10. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  11. user = ${DBUSER}
  12. password = ${DBPASS}
  13. hosts = mysql
  14. dbname = ${DBNAME}
  15. query = SELECT DISTINCT
  16. CASE WHEN '%d' IN (
  17. SELECT domain FROM domain
  18. WHERE relay_all_recipients=1
  19. AND domain='%d'
  20. AND backupmx=1
  21. )
  22. THEN '%s' ELSE (
  23. SELECT goto FROM alias WHERE address='%s' AND active='1'
  24. )
  25. END AS result;
  26. EOF
  27. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  28. user = ${DBUSER}
  29. password = ${DBPASS}
  30. hosts = mysql
  31. dbname = ${DBNAME}
  32. query = SELECT IF(EXISTS(
  33. SELECT 'TLS_ACTIVE' FROM alias
  34. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  35. WHERE (address='%s'
  36. OR address IN (
  37. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  38. WHERE alias_domain='%d'
  39. )
  40. ) AND json_extract(attributes, '$.tls_enforce_in') LIKE '%%1%%' AND mailbox.active = '1'
  41. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  42. EOF
  43. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  44. user = ${DBUSER}
  45. password = ${DBPASS}
  46. hosts = mysql
  47. dbname = ${DBNAME}
  48. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  49. FROM (
  50. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  51. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  52. WHERE (address = '%s'
  53. OR address IN (
  54. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  55. WHERE alias_domain = '%d'
  56. )
  57. )
  58. AND json_extract(attributes, '$.tls_enforce_out') LIKE '%%1%%'
  59. AND mailbox.active = '1'
  60. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  61. UNION ALL
  62. SELECT hostname AS transport FROM relayhosts
  63. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  64. WHERE relayhosts.active = '1'
  65. AND domain = '%d'
  66. OR domain IN (
  67. SELECT target_domain FROM alias_domain
  68. WHERE alias_domain = '%d'
  69. )
  70. )
  71. AS transport_view;
  72. EOF
  73. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps.cf
  74. user = ${DBUSER}
  75. password = ${DBPASS}
  76. hosts = mysql
  77. dbname = ${DBNAME}
  78. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  79. WHERE id IN (
  80. SELECT relayhost FROM domain
  81. WHERE CONCAT('@', domain) = '%s'
  82. OR '%s' IN (
  83. SELECT CONCAT('@', alias_domain) FROM alias_domain
  84. )
  85. )
  86. AND username != '';
  87. EOF
  88. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_catchall_maps.cf
  89. user = ${DBUSER}
  90. password = ${DBPASS}
  91. hosts = mysql
  92. dbname = ${DBNAME}
  93. query = SELECT goto FROM alias, alias_domain
  94. WHERE alias_domain.alias_domain = '%d'
  95. AND alias.address = CONCAT('@', alias_domain.target_domain)
  96. AND alias.active = 1 AND alias_domain.active='1'
  97. EOF
  98. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  99. user = ${DBUSER}
  100. password = ${DBPASS}
  101. hosts = mysql
  102. dbname = ${DBNAME}
  103. query = SELECT username FROM mailbox, alias_domain
  104. WHERE alias_domain.alias_domain = '%d'
  105. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  106. AND mailbox.active = '1'
  107. AND alias_domain.active='1'
  108. EOF
  109. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  110. user = ${DBUSER}
  111. password = ${DBPASS}
  112. hosts = mysql
  113. dbname = ${DBNAME}
  114. query = SELECT goto FROM alias
  115. WHERE address='%s'
  116. AND active='1';
  117. EOF
  118. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  119. user = ${DBUSER}
  120. password = ${DBPASS}
  121. hosts = mysql
  122. dbname = ${DBNAME}
  123. query = SELECT bcc_dest FROM bcc_maps
  124. WHERE local_dest='%s'
  125. AND type='rcpt'
  126. AND active='1';
  127. EOF
  128. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  129. user = ${DBUSER}
  130. password = ${DBPASS}
  131. hosts = mysql
  132. dbname = ${DBNAME}
  133. query = SELECT bcc_dest FROM bcc_maps
  134. WHERE local_dest='%s'
  135. AND type='sender'
  136. AND active='1';
  137. EOF
  138. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  139. user = ${DBUSER}
  140. password = ${DBPASS}
  141. hosts = mysql
  142. dbname = ${DBNAME}
  143. query = SELECT new_dest FROM recipient_maps
  144. WHERE old_dest='%s'
  145. AND active='1';
  146. EOF
  147. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  148. user = ${DBUSER}
  149. password = ${DBPASS}
  150. hosts = mysql
  151. dbname = ${DBNAME}
  152. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  153. UNION
  154. SELECT domain FROM domain
  155. WHERE domain='%s'
  156. AND active = '1'
  157. AND backupmx = '0'
  158. EOF
  159. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  160. user = ${DBUSER}
  161. password = ${DBPASS}
  162. hosts = mysql
  163. dbname = ${DBNAME}
  164. query = SELECT maildir FROM mailbox WHERE username='%s' AND active = '1'
  165. EOF
  166. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  167. user = ${DBUSER}
  168. password = ${DBPASS}
  169. hosts = mysql
  170. dbname = ${DBNAME}
  171. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  172. EOF
  173. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  174. user = ${DBUSER}
  175. password = ${DBPASS}
  176. hosts = mysql
  177. dbname = ${DBNAME}
  178. # First select queries domain and alias_domain to determine if domains are active.
  179. query = SELECT goto FROM alias
  180. WHERE address='%s'
  181. AND active='1'
  182. AND (domain IN
  183. (SELECT domain FROM domain
  184. WHERE domain='%d'
  185. AND active='1')
  186. OR domain in (
  187. SELECT alias_domain FROM alias_domain
  188. WHERE alias_domain='%d'
  189. AND active='1'
  190. )
  191. )
  192. UNION
  193. SELECT logged_in_as FROM sender_acl
  194. WHERE send_as='@%d'
  195. OR send_as='%s'
  196. OR send_as IN (
  197. SELECT CONCAT('@',target_domain) FROM alias_domain
  198. WHERE alias_domain = '%d')
  199. OR send_as IN (
  200. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  201. WHERE alias_domain = '%d')
  202. AND logged_in_as NOT IN (
  203. SELECT goto FROM alias
  204. WHERE address='%s')
  205. UNION
  206. SELECT username FROM mailbox, alias_domain
  207. WHERE alias_domain.alias_domain = '%d'
  208. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  209. AND mailbox.active ='1'
  210. AND alias_domain.active='1'
  211. EOF
  212. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  213. user = ${DBUSER}
  214. password = ${DBPASS}
  215. hosts = mysql
  216. dbname = ${DBNAME}
  217. query = SELECT goto FROM spamalias
  218. WHERE address='%s'
  219. AND validity >= UNIX_TIMESTAMP()
  220. EOF
  221. # Reset GPG key permissions
  222. mkdir -p /var/lib/zeyple/keys
  223. chmod 700 /var/lib/zeyple/keys
  224. chown -R 600:600 /var/lib/zeyple/keys
  225. # Fix Postfix permissions
  226. chgrp -R postdrop /var/spool/postfix/public
  227. chgrp -R postdrop /var/spool/postfix/maildrop
  228. postfix set-permissions
  229. # Check Postfix configuration
  230. postconf -c /opt/postfix/conf
  231. if [[ $? != 0 ]]; then
  232. echo "Postfix configuration error, refusing to start."
  233. exit 1
  234. else
  235. postfix -c /opt/postfix/conf start
  236. sleep 126144000
  237. fi