postfix.sh 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. # Wait for MySQL to warm-up
  5. while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  6. echo "Waiting for database to come up..."
  7. sleep 2
  8. done
  9. cat <<EOF > /etc/aliases
  10. # Autogenerated by mailcow
  11. null: /dev/null
  12. watchdog: /dev/null
  13. ham: "|/usr/local/bin/rspamd-pipe-ham"
  14. spam: "|/usr/local/bin/rspamd-pipe-spam"
  15. EOF
  16. newaliases;
  17. # create sni configuration
  18. echo -n "" > /opt/postfix/conf/sni.map;
  19. for cert_dir in /etc/ssl/mail/*/ ; do
  20. if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
  21. continue;
  22. fi
  23. IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
  24. for domain in "${domains[@]}"; do
  25. echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
  26. echo "" >> /opt/postfix/conf/sni.map;
  27. done
  28. done
  29. postmap -F hash:/opt/postfix/conf/sni.map;
  30. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  31. # Autogenerated by mailcow
  32. user = ${DBUSER}
  33. password = ${DBPASS}
  34. hosts = unix:/var/run/mysqld/mysqld.sock
  35. dbname = ${DBNAME}
  36. query = SELECT DISTINCT
  37. CASE WHEN '%d' IN (
  38. SELECT domain FROM domain
  39. WHERE relay_all_recipients=1
  40. AND domain='%d'
  41. AND backupmx=1
  42. )
  43. THEN '%s' ELSE (
  44. SELECT goto FROM alias WHERE address='%s' AND active='1'
  45. )
  46. END AS result;
  47. EOF
  48. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  49. # Autogenerated by mailcow
  50. user = ${DBUSER}
  51. password = ${DBPASS}
  52. hosts = unix:/var/run/mysqld/mysqld.sock
  53. dbname = ${DBNAME}
  54. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  55. EOF
  56. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  57. # Autogenerated by mailcow
  58. user = ${DBUSER}
  59. password = ${DBPASS}
  60. hosts = unix:/var/run/mysqld/mysqld.sock
  61. dbname = ${DBNAME}
  62. query = SELECT IF(EXISTS(
  63. SELECT 'TLS_ACTIVE' FROM alias
  64. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  65. WHERE (address='%s'
  66. OR address IN (
  67. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  68. WHERE alias_domain='%d'
  69. )
  70. ) AND json_extract(attributes, '$.tls_enforce_in') LIKE '%%1%%' AND mailbox.active = '1'
  71. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  72. EOF
  73. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  74. # Autogenerated by mailcow
  75. user = ${DBUSER}
  76. password = ${DBPASS}
  77. hosts = unix:/var/run/mysqld/mysqld.sock
  78. dbname = ${DBNAME}
  79. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  80. FROM (
  81. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  82. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  83. WHERE (address = '%s'
  84. OR address IN (
  85. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  86. WHERE alias_domain = '%d'
  87. )
  88. )
  89. AND json_extract(attributes, '$.tls_enforce_out') LIKE '%%1%%'
  90. AND mailbox.active = '1'
  91. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  92. UNION ALL
  93. SELECT hostname AS transport FROM relayhosts
  94. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  95. WHERE relayhosts.active = '1'
  96. AND domain = '%d'
  97. OR domain IN (
  98. SELECT target_domain FROM alias_domain
  99. WHERE alias_domain = '%d'
  100. )
  101. )
  102. AS transport_view;
  103. EOF
  104. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  105. # Autogenerated by mailcow
  106. user = ${DBUSER}
  107. password = ${DBPASS}
  108. hosts = unix:/var/run/mysqld/mysqld.sock
  109. dbname = ${DBNAME}
  110. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  111. WHERE active = '1'
  112. AND destination = '%s';
  113. EOF
  114. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  115. # Autogenerated by mailcow
  116. user = ${DBUSER}
  117. password = ${DBPASS}
  118. hosts = unix:/var/run/mysqld/mysqld.sock
  119. dbname = ${DBNAME}
  120. query = SELECT 'null@localhost' FROM mailbox
  121. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  122. EOF
  123. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  124. # Autogenerated by mailcow
  125. user = ${DBUSER}
  126. password = ${DBPASS}
  127. hosts = unix:/var/run/mysqld/mysqld.sock
  128. dbname = ${DBNAME}
  129. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  130. WHERE id IN (
  131. SELECT relayhost FROM domain
  132. WHERE CONCAT('@', domain) = '%s'
  133. OR domain IN (
  134. SELECT target_domain FROM alias_domain WHERE CONCAT('@', alias_domain) = '%s'
  135. )
  136. )
  137. AND active = '1'
  138. AND username != '';
  139. EOF
  140. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  141. # Autogenerated by mailcow
  142. user = ${DBUSER}
  143. password = ${DBPASS}
  144. hosts = unix:/var/run/mysqld/mysqld.sock
  145. dbname = ${DBNAME}
  146. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  147. WHERE nexthop = '%s'
  148. AND active = '1'
  149. AND username != ''
  150. LIMIT 1;
  151. EOF
  152. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  153. # Autogenerated by mailcow
  154. user = ${DBUSER}
  155. password = ${DBPASS}
  156. hosts = unix:/var/run/mysqld/mysqld.sock
  157. dbname = ${DBNAME}
  158. query = SELECT username FROM mailbox, alias_domain
  159. WHERE alias_domain.alias_domain = '%d'
  160. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  161. AND mailbox.active = '1'
  162. AND alias_domain.active='1'
  163. EOF
  164. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  165. # Autogenerated by mailcow
  166. user = ${DBUSER}
  167. password = ${DBPASS}
  168. hosts = unix:/var/run/mysqld/mysqld.sock
  169. dbname = ${DBNAME}
  170. query = SELECT goto FROM alias
  171. WHERE address='%s'
  172. AND active='1';
  173. EOF
  174. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  175. # Autogenerated by mailcow
  176. user = ${DBUSER}
  177. password = ${DBPASS}
  178. hosts = unix:/var/run/mysqld/mysqld.sock
  179. dbname = ${DBNAME}
  180. query = SELECT bcc_dest FROM bcc_maps
  181. WHERE local_dest='%s'
  182. AND type='rcpt'
  183. AND active='1';
  184. EOF
  185. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  186. # Autogenerated by mailcow
  187. user = ${DBUSER}
  188. password = ${DBPASS}
  189. hosts = unix:/var/run/mysqld/mysqld.sock
  190. dbname = ${DBNAME}
  191. query = SELECT bcc_dest FROM bcc_maps
  192. WHERE local_dest='%s'
  193. AND type='sender'
  194. AND active='1';
  195. EOF
  196. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  197. # Autogenerated by mailcow
  198. user = ${DBUSER}
  199. password = ${DBPASS}
  200. hosts = unix:/var/run/mysqld/mysqld.sock
  201. dbname = ${DBNAME}
  202. query = SELECT new_dest FROM recipient_maps
  203. WHERE old_dest='%s'
  204. AND active='1';
  205. EOF
  206. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  207. # Autogenerated by mailcow
  208. user = ${DBUSER}
  209. password = ${DBPASS}
  210. hosts = unix:/var/run/mysqld/mysqld.sock
  211. dbname = ${DBNAME}
  212. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  213. UNION
  214. SELECT domain FROM domain
  215. WHERE domain='%s'
  216. AND active = '1'
  217. AND backupmx = '0'
  218. EOF
  219. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  220. # Autogenerated by mailcow
  221. user = ${DBUSER}
  222. password = ${DBPASS}
  223. hosts = unix:/var/run/mysqld/mysqld.sock
  224. dbname = ${DBNAME}
  225. query = SELECT CONCAT(JSON_UNQUOTE(JSON_EXTRACT(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND active = '1'
  226. EOF
  227. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  228. # Autogenerated by mailcow
  229. user = ${DBUSER}
  230. password = ${DBPASS}
  231. hosts = unix:/var/run/mysqld/mysqld.sock
  232. dbname = ${DBNAME}
  233. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  234. EOF
  235. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  236. # Autogenerated by mailcow
  237. user = ${DBUSER}
  238. password = ${DBPASS}
  239. hosts = unix:/var/run/mysqld/mysqld.sock
  240. dbname = ${DBNAME}
  241. # First select queries domain and alias_domain to determine if domains are active.
  242. query = SELECT goto FROM alias
  243. WHERE address='%s'
  244. AND active='1'
  245. AND (domain IN
  246. (SELECT domain FROM domain
  247. WHERE domain='%d'
  248. AND active='1')
  249. OR domain in (
  250. SELECT alias_domain FROM alias_domain
  251. WHERE alias_domain='%d'
  252. AND active='1'
  253. )
  254. )
  255. UNION
  256. SELECT logged_in_as FROM sender_acl
  257. WHERE send_as='@%d'
  258. OR send_as='%s'
  259. OR send_as='*'
  260. OR send_as IN (
  261. SELECT CONCAT('@',target_domain) FROM alias_domain
  262. WHERE alias_domain = '%d')
  263. OR send_as IN (
  264. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  265. WHERE alias_domain = '%d')
  266. AND logged_in_as NOT IN (
  267. SELECT goto FROM alias
  268. WHERE address='%s')
  269. UNION
  270. SELECT username FROM mailbox, alias_domain
  271. WHERE alias_domain.alias_domain = '%d'
  272. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  273. AND mailbox.active ='1'
  274. AND alias_domain.active='1'
  275. EOF
  276. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  277. # Autogenerated by mailcow
  278. user = ${DBUSER}
  279. password = ${DBPASS}
  280. hosts = unix:/var/run/mysqld/mysqld.sock
  281. dbname = ${DBNAME}
  282. query = SELECT goto FROM spamalias
  283. WHERE address='%s'
  284. AND validity >= UNIX_TIMESTAMP()
  285. EOF
  286. sed -i '/User overrides/q' /opt/postfix/conf/main.cf
  287. echo >> /opt/postfix/conf/main.cf
  288. if [ -f /opt/postfix/conf/extra.cf ]; then
  289. cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
  290. fi
  291. if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
  292. echo "Creating dummy custom_transport.pcre"
  293. touch /opt/postfix/conf/custom_transport.pcre
  294. fi
  295. # Fix Postfix permissions
  296. chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
  297. chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
  298. chgrp -R postdrop /var/spool/postfix/public
  299. chgrp -R postdrop /var/spool/postfix/maildrop
  300. postfix set-permissions
  301. # Check Postfix configuration
  302. postconf -c /opt/postfix/conf > /dev/null
  303. if [[ $? != 0 ]]; then
  304. echo "Postfix configuration error, refusing to start."
  305. exit 1
  306. else
  307. postfix -c /opt/postfix/conf start
  308. sleep 126144000
  309. fi