postfix.sh 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. cat <<EOF > /etc/aliases
  5. # Autogenerated by mailcow
  6. null: /dev/null
  7. ham: "|/usr/local/bin/rspamd-pipe-ham"
  8. spam: "|/usr/local/bin/rspamd-pipe-spam"
  9. EOF
  10. newaliases;
  11. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  12. # Autogenerated by mailcow
  13. user = ${DBUSER}
  14. password = ${DBPASS}
  15. hosts = unix:/var/run/mysqld/mysqld.sock
  16. dbname = ${DBNAME}
  17. query = SELECT DISTINCT
  18. CASE WHEN '%d' IN (
  19. SELECT domain FROM domain
  20. WHERE relay_all_recipients=1
  21. AND domain='%d'
  22. AND backupmx=1
  23. )
  24. THEN '%s' ELSE (
  25. SELECT goto FROM alias WHERE address='%s' AND active='1'
  26. )
  27. END AS result;
  28. EOF
  29. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  30. # Autogenerated by mailcow
  31. user = ${DBUSER}
  32. password = ${DBPASS}
  33. hosts = unix:/var/run/mysqld/mysqld.sock
  34. dbname = ${DBNAME}
  35. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  36. EOF
  37. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  38. # Autogenerated by mailcow
  39. user = ${DBUSER}
  40. password = ${DBPASS}
  41. hosts = unix:/var/run/mysqld/mysqld.sock
  42. dbname = ${DBNAME}
  43. query = SELECT IF(EXISTS(
  44. SELECT 'TLS_ACTIVE' FROM alias
  45. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  46. WHERE (address='%s'
  47. OR address IN (
  48. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  49. WHERE alias_domain='%d'
  50. )
  51. ) AND json_extract(attributes, '$.tls_enforce_in') LIKE '%%1%%' AND mailbox.active = '1'
  52. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  53. EOF
  54. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  55. # Autogenerated by mailcow
  56. user = ${DBUSER}
  57. password = ${DBPASS}
  58. hosts = unix:/var/run/mysqld/mysqld.sock
  59. dbname = ${DBNAME}
  60. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  61. FROM (
  62. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  63. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  64. WHERE (address = '%s'
  65. OR address IN (
  66. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  67. WHERE alias_domain = '%d'
  68. )
  69. )
  70. AND json_extract(attributes, '$.tls_enforce_out') LIKE '%%1%%'
  71. AND mailbox.active = '1'
  72. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  73. UNION ALL
  74. SELECT hostname AS transport FROM relayhosts
  75. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  76. WHERE relayhosts.active = '1'
  77. AND domain = '%d'
  78. OR domain IN (
  79. SELECT target_domain FROM alias_domain
  80. WHERE alias_domain = '%d'
  81. )
  82. )
  83. AS transport_view;
  84. EOF
  85. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  86. # Autogenerated by mailcow
  87. user = ${DBUSER}
  88. password = ${DBPASS}
  89. hosts = unix:/var/run/mysqld/mysqld.sock
  90. dbname = ${DBNAME}
  91. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  92. WHERE active = '1'
  93. AND destination = '%s';
  94. EOF
  95. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  96. # Autogenerated by mailcow
  97. user = ${DBUSER}
  98. password = ${DBPASS}
  99. hosts = unix:/var/run/mysqld/mysqld.sock
  100. dbname = ${DBNAME}
  101. query = SELECT 'null@localhost' FROM mailbox
  102. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  103. EOF
  104. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  105. # Autogenerated by mailcow
  106. user = ${DBUSER}
  107. password = ${DBPASS}
  108. hosts = unix:/var/run/mysqld/mysqld.sock
  109. dbname = ${DBNAME}
  110. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  111. WHERE id IN (
  112. SELECT relayhost FROM domain
  113. WHERE CONCAT('@', domain) = '%s'
  114. OR domain IN (
  115. SELECT target_domain FROM alias_domain WHERE CONCAT('@', alias_domain) = '%s'
  116. )
  117. )
  118. AND active = '1'
  119. AND username != '';
  120. EOF
  121. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  122. # Autogenerated by mailcow
  123. user = ${DBUSER}
  124. password = ${DBPASS}
  125. hosts = unix:/var/run/mysqld/mysqld.sock
  126. dbname = ${DBNAME}
  127. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  128. WHERE nexthop = '%s'
  129. AND active = '1'
  130. AND username != ''
  131. LIMIT 1;
  132. EOF
  133. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_catchall_maps.cf
  134. # Autogenerated by mailcow
  135. user = ${DBUSER}
  136. password = ${DBPASS}
  137. hosts = unix:/var/run/mysqld/mysqld.sock
  138. dbname = ${DBNAME}
  139. query = SELECT goto FROM alias, alias_domain
  140. WHERE alias_domain.alias_domain = '%d'
  141. AND alias.address = CONCAT('@', alias_domain.target_domain)
  142. AND alias.active = 1 AND alias_domain.active='1'
  143. EOF
  144. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  145. # Autogenerated by mailcow
  146. user = ${DBUSER}
  147. password = ${DBPASS}
  148. hosts = unix:/var/run/mysqld/mysqld.sock
  149. dbname = ${DBNAME}
  150. query = SELECT username FROM mailbox, alias_domain
  151. WHERE alias_domain.alias_domain = '%d'
  152. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  153. AND mailbox.active = '1'
  154. AND alias_domain.active='1'
  155. EOF
  156. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  157. # Autogenerated by mailcow
  158. user = ${DBUSER}
  159. password = ${DBPASS}
  160. hosts = unix:/var/run/mysqld/mysqld.sock
  161. dbname = ${DBNAME}
  162. query = SELECT goto FROM alias
  163. WHERE address='%s'
  164. AND active='1';
  165. EOF
  166. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  167. # Autogenerated by mailcow
  168. user = ${DBUSER}
  169. password = ${DBPASS}
  170. hosts = unix:/var/run/mysqld/mysqld.sock
  171. dbname = ${DBNAME}
  172. query = SELECT bcc_dest FROM bcc_maps
  173. WHERE local_dest='%s'
  174. AND type='rcpt'
  175. AND active='1';
  176. EOF
  177. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  178. # Autogenerated by mailcow
  179. user = ${DBUSER}
  180. password = ${DBPASS}
  181. hosts = unix:/var/run/mysqld/mysqld.sock
  182. dbname = ${DBNAME}
  183. query = SELECT bcc_dest FROM bcc_maps
  184. WHERE local_dest='%s'
  185. AND type='sender'
  186. AND active='1';
  187. EOF
  188. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  189. # Autogenerated by mailcow
  190. user = ${DBUSER}
  191. password = ${DBPASS}
  192. hosts = unix:/var/run/mysqld/mysqld.sock
  193. dbname = ${DBNAME}
  194. query = SELECT new_dest FROM recipient_maps
  195. WHERE old_dest='%s'
  196. AND active='1';
  197. EOF
  198. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  199. # Autogenerated by mailcow
  200. user = ${DBUSER}
  201. password = ${DBPASS}
  202. hosts = unix:/var/run/mysqld/mysqld.sock
  203. dbname = ${DBNAME}
  204. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  205. UNION
  206. SELECT domain FROM domain
  207. WHERE domain='%s'
  208. AND active = '1'
  209. AND backupmx = '0'
  210. EOF
  211. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  212. # Autogenerated by mailcow
  213. user = ${DBUSER}
  214. password = ${DBPASS}
  215. hosts = unix:/var/run/mysqld/mysqld.sock
  216. dbname = ${DBNAME}
  217. query = SELECT CONCAT(JSON_UNQUOTE(JSON_EXTRACT(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND active = '1'
  218. EOF
  219. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  220. # Autogenerated by mailcow
  221. user = ${DBUSER}
  222. password = ${DBPASS}
  223. hosts = unix:/var/run/mysqld/mysqld.sock
  224. dbname = ${DBNAME}
  225. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  226. EOF
  227. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  228. # Autogenerated by mailcow
  229. user = ${DBUSER}
  230. password = ${DBPASS}
  231. hosts = unix:/var/run/mysqld/mysqld.sock
  232. dbname = ${DBNAME}
  233. # First select queries domain and alias_domain to determine if domains are active.
  234. query = SELECT goto FROM alias
  235. WHERE address='%s'
  236. AND active='1'
  237. AND (domain IN
  238. (SELECT domain FROM domain
  239. WHERE domain='%d'
  240. AND active='1')
  241. OR domain in (
  242. SELECT alias_domain FROM alias_domain
  243. WHERE alias_domain='%d'
  244. AND active='1'
  245. )
  246. )
  247. UNION
  248. SELECT logged_in_as FROM sender_acl
  249. WHERE send_as='@%d'
  250. OR send_as='%s'
  251. OR send_as='*'
  252. OR send_as IN (
  253. SELECT CONCAT('@',target_domain) FROM alias_domain
  254. WHERE alias_domain = '%d')
  255. OR send_as IN (
  256. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  257. WHERE alias_domain = '%d')
  258. AND logged_in_as NOT IN (
  259. SELECT goto FROM alias
  260. WHERE address='%s')
  261. UNION
  262. SELECT username FROM mailbox, alias_domain
  263. WHERE alias_domain.alias_domain = '%d'
  264. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  265. AND mailbox.active ='1'
  266. AND alias_domain.active='1'
  267. EOF
  268. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  269. # Autogenerated by mailcow
  270. user = ${DBUSER}
  271. password = ${DBPASS}
  272. hosts = unix:/var/run/mysqld/mysqld.sock
  273. dbname = ${DBNAME}
  274. query = SELECT goto FROM spamalias
  275. WHERE address='%s'
  276. AND validity >= UNIX_TIMESTAMP()
  277. EOF
  278. # Reset GPG key permissions
  279. mkdir -p /var/lib/zeyple/keys
  280. chmod 700 /var/lib/zeyple/keys
  281. chown -R 600:600 /var/lib/zeyple/keys
  282. # Fix Postfix permissions
  283. chown -R root:postfix /opt/postfix/conf/sql/
  284. chmod 640 /opt/postfix/conf/sql/*.cf
  285. chgrp -R postdrop /var/spool/postfix/public
  286. chgrp -R postdrop /var/spool/postfix/maildrop
  287. postfix set-permissions
  288. # Check Postfix configuration
  289. postconf -c /opt/postfix/conf
  290. if [[ $? != 0 ]]; then
  291. echo "Postfix configuration error, refusing to start."
  292. exit 1
  293. else
  294. postfix -c /opt/postfix/conf start
  295. sleep 126144000
  296. fi