postfix.sh 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. [[ ! -d /etc/postfix-tlspol ]] && mkdir -p /etc/postfix-tlspol
  5. [[ ! -d /var/lib/postfix-tlspol ]] && mkdir -p /var/lib/postfix-tlspol
  6. # Wait for MySQL to warm-up
  7. while ! mariadb-admin status --ssl=false --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  8. echo "Waiting for database to come up..."
  9. sleep 2
  10. done
  11. until dig +short mailcow.email > /dev/null; do
  12. echo "Waiting for DNS..."
  13. sleep 1
  14. done
  15. cat <<EOF > /etc/aliases
  16. # Autogenerated by mailcow
  17. null: /dev/null
  18. watchdog: /dev/null
  19. ham: "|/usr/local/bin/rspamd-pipe-ham"
  20. spam: "|/usr/local/bin/rspamd-pipe-spam"
  21. EOF
  22. newaliases;
  23. # create sni configuration
  24. if [[ "${SKIP_LETS_ENCRYPT}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  25. echo -n "" > /opt/postfix/conf/sni.map
  26. else
  27. echo -n "" > /opt/postfix/conf/sni.map;
  28. for cert_dir in /etc/ssl/mail/*/ ; do
  29. if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
  30. continue;
  31. fi
  32. IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
  33. for domain in "${domains[@]}"; do
  34. echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
  35. echo "" >> /opt/postfix/conf/sni.map;
  36. done
  37. done
  38. fi
  39. postmap -F hash:/opt/postfix/conf/sni.map;
  40. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_ne.cf
  41. # Autogenerated by mailcow
  42. user = ${DBUSER}
  43. password = ${DBPASS}
  44. hosts = unix:/var/run/mysqld/mysqld.sock
  45. dbname = ${DBNAME}
  46. query = SELECT IF(EXISTS(SELECT address, domain FROM alias
  47. WHERE address = '%s'
  48. AND domain IN (
  49. SELECT domain FROM domain
  50. WHERE backupmx = '1'
  51. AND relay_all_recipients = '1'
  52. AND relay_unknown_only = '1')
  53. ), 'lmtp:inet:dovecot:24', NULL) AS 'transport'
  54. EOF
  55. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  56. # Autogenerated by mailcow
  57. user = ${DBUSER}
  58. password = ${DBPASS}
  59. hosts = unix:/var/run/mysqld/mysqld.sock
  60. dbname = ${DBNAME}
  61. query = SELECT DISTINCT
  62. CASE WHEN '%d' IN (
  63. SELECT domain FROM domain
  64. WHERE relay_all_recipients=1
  65. AND domain='%d'
  66. AND backupmx=1
  67. )
  68. THEN '%s' ELSE (
  69. SELECT goto FROM alias WHERE address='%s' AND active='1'
  70. )
  71. END AS result;
  72. EOF
  73. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  74. # Autogenerated by mailcow
  75. user = ${DBUSER}
  76. password = ${DBPASS}
  77. hosts = unix:/var/run/mysqld/mysqld.sock
  78. dbname = ${DBNAME}
  79. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  80. EOF
  81. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  82. # Autogenerated by mailcow
  83. user = ${DBUSER}
  84. password = ${DBPASS}
  85. hosts = unix:/var/run/mysqld/mysqld.sock
  86. dbname = ${DBNAME}
  87. query = SELECT IF(EXISTS(
  88. SELECT 'TLS_ACTIVE' FROM alias
  89. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  90. WHERE (address='%s'
  91. OR address IN (
  92. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  93. WHERE alias_domain='%d'
  94. )
  95. ) AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_in')) = '1' AND mailbox.active = '1'
  96. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  97. EOF
  98. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  99. # Autogenerated by mailcow
  100. user = ${DBUSER}
  101. password = ${DBPASS}
  102. hosts = unix:/var/run/mysqld/mysqld.sock
  103. dbname = ${DBNAME}
  104. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  105. FROM (
  106. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  107. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  108. WHERE (address = '%s'
  109. OR address IN (
  110. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  111. WHERE alias_domain = '%d'
  112. )
  113. )
  114. AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_out')) = '1'
  115. AND mailbox.active = '1'
  116. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  117. UNION ALL
  118. SELECT COALESCE(
  119. (SELECT hostname FROM relayhosts
  120. LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id
  121. WHERE relayhosts.active = '1'
  122. AND (
  123. mailbox.username IN (SELECT alias.goto from alias
  124. JOIN mailbox ON mailbox.username = alias.goto
  125. WHERE alias.active = '1'
  126. AND alias.address = '%s'
  127. AND alias.address NOT LIKE '@%%'
  128. )
  129. )
  130. ),
  131. (SELECT hostname FROM relayhosts
  132. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  133. WHERE relayhosts.active = '1'
  134. AND (domain.domain = '%d'
  135. OR domain.domain IN (
  136. SELECT target_domain FROM alias_domain
  137. WHERE alias_domain = '%d'
  138. )
  139. )
  140. )
  141. )
  142. ) AS transport_view;
  143. EOF
  144. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  145. # Autogenerated by mailcow
  146. user = ${DBUSER}
  147. password = ${DBPASS}
  148. hosts = unix:/var/run/mysqld/mysqld.sock
  149. dbname = ${DBNAME}
  150. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  151. WHERE active = '1'
  152. AND destination = '%s';
  153. EOF
  154. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  155. # Autogenerated by mailcow
  156. user = ${DBUSER}
  157. password = ${DBPASS}
  158. hosts = unix:/var/run/mysqld/mysqld.sock
  159. dbname = ${DBNAME}
  160. query = SELECT 'null@localhost' FROM mailbox
  161. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  162. EOF
  163. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  164. # Autogenerated by mailcow
  165. user = ${DBUSER}
  166. password = ${DBPASS}
  167. hosts = unix:/var/run/mysqld/mysqld.sock
  168. dbname = ${DBNAME}
  169. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  170. WHERE id IN (
  171. SELECT COALESCE(
  172. (SELECT id FROM relayhosts
  173. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  174. WHERE relayhosts.active = '1'
  175. AND (domain.domain = '%d'
  176. OR domain.domain IN (
  177. SELECT target_domain FROM alias_domain
  178. WHERE alias_domain = '%d'
  179. )
  180. )
  181. ),
  182. (SELECT id FROM relayhosts
  183. LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id
  184. WHERE relayhosts.active = '1'
  185. AND (
  186. mailbox.username IN (
  187. SELECT alias.goto from alias
  188. JOIN mailbox ON mailbox.username = alias.goto
  189. WHERE alias.active = '1'
  190. AND alias.address = '%s'
  191. AND alias.address NOT LIKE '@%%'
  192. )
  193. )
  194. )
  195. )
  196. )
  197. AND active = '1'
  198. AND username != '';
  199. EOF
  200. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  201. # Autogenerated by mailcow
  202. user = ${DBUSER}
  203. password = ${DBPASS}
  204. hosts = unix:/var/run/mysqld/mysqld.sock
  205. dbname = ${DBNAME}
  206. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  207. WHERE nexthop = '%s'
  208. AND active = '1'
  209. AND username != ''
  210. LIMIT 1;
  211. EOF
  212. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  213. # Autogenerated by mailcow
  214. user = ${DBUSER}
  215. password = ${DBPASS}
  216. hosts = unix:/var/run/mysqld/mysqld.sock
  217. dbname = ${DBNAME}
  218. query = SELECT username FROM mailbox, alias_domain
  219. WHERE alias_domain.alias_domain = '%d'
  220. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  221. AND (mailbox.active = '1' OR mailbox.active = '2')
  222. AND alias_domain.active='1'
  223. EOF
  224. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  225. # Autogenerated by mailcow
  226. user = ${DBUSER}
  227. password = ${DBPASS}
  228. hosts = unix:/var/run/mysqld/mysqld.sock
  229. dbname = ${DBNAME}
  230. query = SELECT goto FROM alias
  231. WHERE address='%s'
  232. AND (active='1' OR active='2');
  233. EOF
  234. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  235. # Autogenerated by mailcow
  236. user = ${DBUSER}
  237. password = ${DBPASS}
  238. hosts = unix:/var/run/mysqld/mysqld.sock
  239. dbname = ${DBNAME}
  240. query = SELECT bcc_dest FROM bcc_maps
  241. WHERE local_dest='%s'
  242. AND type='rcpt'
  243. AND active='1';
  244. EOF
  245. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  246. # Autogenerated by mailcow
  247. user = ${DBUSER}
  248. password = ${DBPASS}
  249. hosts = unix:/var/run/mysqld/mysqld.sock
  250. dbname = ${DBNAME}
  251. query = SELECT bcc_dest FROM bcc_maps
  252. WHERE local_dest='%s'
  253. AND type='sender'
  254. AND active='1';
  255. EOF
  256. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  257. # Autogenerated by mailcow
  258. user = ${DBUSER}
  259. password = ${DBPASS}
  260. hosts = unix:/var/run/mysqld/mysqld.sock
  261. dbname = ${DBNAME}
  262. query = SELECT new_dest FROM recipient_maps
  263. WHERE old_dest='%s'
  264. AND active='1';
  265. EOF
  266. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  267. # Autogenerated by mailcow
  268. user = ${DBUSER}
  269. password = ${DBPASS}
  270. hosts = unix:/var/run/mysqld/mysqld.sock
  271. dbname = ${DBNAME}
  272. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  273. UNION
  274. SELECT domain FROM domain
  275. WHERE domain='%s'
  276. AND active = '1'
  277. AND backupmx = '0'
  278. EOF
  279. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  280. # Autogenerated by mailcow
  281. user = ${DBUSER}
  282. password = ${DBPASS}
  283. hosts = unix:/var/run/mysqld/mysqld.sock
  284. dbname = ${DBNAME}
  285. query = SELECT CONCAT(JSON_UNQUOTE(JSON_VALUE(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND (active = '1' OR active = '2')
  286. EOF
  287. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  288. # Autogenerated by mailcow
  289. user = ${DBUSER}
  290. password = ${DBPASS}
  291. hosts = unix:/var/run/mysqld/mysqld.sock
  292. dbname = ${DBNAME}
  293. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  294. EOF
  295. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  296. # Autogenerated by mailcow
  297. user = ${DBUSER}
  298. password = ${DBPASS}
  299. hosts = unix:/var/run/mysqld/mysqld.sock
  300. dbname = ${DBNAME}
  301. # First select queries domain and alias_domain to determine if domains are active.
  302. query = SELECT goto FROM alias
  303. WHERE id IN (
  304. SELECT COALESCE (
  305. (
  306. SELECT id FROM alias
  307. WHERE address='%s'
  308. AND (active='1' OR active='2')
  309. ), (
  310. SELECT id FROM alias
  311. WHERE address='@%d'
  312. AND (active='1' OR active='2')
  313. )
  314. )
  315. )
  316. AND active='1'
  317. AND (domain IN
  318. (SELECT domain FROM domain
  319. WHERE domain='%d'
  320. AND active='1')
  321. OR domain in (
  322. SELECT alias_domain FROM alias_domain
  323. WHERE alias_domain='%d'
  324. AND active='1'
  325. )
  326. )
  327. UNION
  328. SELECT logged_in_as FROM sender_acl
  329. WHERE send_as='@%d'
  330. OR send_as='%s'
  331. OR send_as='*'
  332. OR send_as IN (
  333. SELECT CONCAT('@',target_domain) FROM alias_domain
  334. WHERE alias_domain = '%d')
  335. OR send_as IN (
  336. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  337. WHERE alias_domain = '%d')
  338. AND logged_in_as NOT IN (
  339. SELECT goto FROM alias
  340. WHERE address='%s')
  341. UNION
  342. SELECT username FROM mailbox, alias_domain
  343. WHERE alias_domain.alias_domain = '%d'
  344. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  345. AND (mailbox.active = '1' OR mailbox.active ='2')
  346. AND alias_domain.active='1';
  347. EOF
  348. # MX based routing
  349. cat <<EOF > /opt/postfix/conf/sql/mysql_mbr_access_maps.cf
  350. # Autogenerated by mailcow
  351. user = ${DBUSER}
  352. password = ${DBPASS}
  353. hosts = unix:/var/run/mysqld/mysqld.sock
  354. dbname = ${DBNAME}
  355. query = SELECT CONCAT('FILTER smtp_via_transport_maps:', nexthop) as transport FROM transports
  356. WHERE '%s' REGEXP destination
  357. AND active='1'
  358. AND is_mx_based='1';
  359. EOF
  360. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  361. # Autogenerated by mailcow
  362. user = ${DBUSER}
  363. password = ${DBPASS}
  364. hosts = unix:/var/run/mysqld/mysqld.sock
  365. dbname = ${DBNAME}
  366. query = SELECT goto FROM spamalias
  367. WHERE address='%s'
  368. AND validity >= UNIX_TIMESTAMP()
  369. EOF
  370. if [ ! -f /opt/postfix/conf/dns_blocklists.cf ]; then
  371. cat <<EOF > /opt/postfix/conf/dns_blocklists.cf
  372. # This file can be edited.
  373. # Delete this file and restart postfix container to revert any changes.
  374. postscreen_dnsbl_sites = wl.mailspike.net=127.0.0.[18;19;20]*-2
  375. hostkarma.junkemailfilter.com=127.0.0.1*-2
  376. list.dnswl.org=127.0.[0..255].0*-2
  377. list.dnswl.org=127.0.[0..255].1*-4
  378. list.dnswl.org=127.0.[0..255].2*-6
  379. list.dnswl.org=127.0.[0..255].3*-8
  380. bl.spamcop.net*2
  381. bl.suomispam.net*2
  382. hostkarma.junkemailfilter.com=127.0.0.2*3
  383. hostkarma.junkemailfilter.com=127.0.0.4*2
  384. hostkarma.junkemailfilter.com=127.0.1.2*1
  385. backscatter.spameatingmonkey.net*2
  386. bl.ipv6.spameatingmonkey.net*2
  387. bl.spameatingmonkey.net*2
  388. b.barracudacentral.org=127.0.0.2*7
  389. bl.mailspike.net=127.0.0.2*5
  390. bl.mailspike.net=127.0.0.[10;11;12]*4
  391. EOF
  392. fi
  393. # Remove discontinued DNSBLs from existing dns_blocklists.cf
  394. sed -i '/ix\.dnsbl\.manitu\.net\*2/d' /opt/postfix/conf/dns_blocklists.cf # Nixspam
  395. DNSBL_CONFIG=$(grep -v '^#' /opt/postfix/conf/dns_blocklists.cf | grep '\S')
  396. if [ ! -z "$DNSBL_CONFIG" ]; then
  397. echo -e "\e[33mChecking if ASN for your IP is listed for Spamhaus Bad ASN List...\e[0m"
  398. if [ -n "$SPAMHAUS_DQS_KEY" ]; then
  399. echo -e "\e[32mDetected SPAMHAUS_DQS_KEY variable from mailcow.conf...\e[0m"
  400. echo -e "\e[33mUsing DQS Blocklists from Spamhaus!\e[0m"
  401. SPAMHAUS_DNSBL_CONFIG=$(cat <<EOF
  402. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.[4..7]*6
  403. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.[10;11]*8
  404. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.3*4
  405. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.2*3
  406. postscreen_dnsbl_reply_map = texthash:/opt/postfix/conf/dnsbl_reply.map
  407. EOF
  408. cat <<EOF > /opt/postfix/conf/dnsbl_reply.map
  409. # Autogenerated by mailcow, using Spamhaus DQS reply domains
  410. ${SPAMHAUS_DQS_KEY}.sbl.dq.spamhaus.net sbl.spamhaus.org
  411. ${SPAMHAUS_DQS_KEY}.xbl.dq.spamhaus.net xbl.spamhaus.org
  412. ${SPAMHAUS_DQS_KEY}.pbl.dq.spamhaus.net pbl.spamhaus.org
  413. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net zen.spamhaus.org
  414. ${SPAMHAUS_DQS_KEY}.dbl.dq.spamhaus.net dbl.spamhaus.org
  415. ${SPAMHAUS_DQS_KEY}.zrd.dq.spamhaus.net zrd.spamhaus.org
  416. EOF
  417. )
  418. else
  419. if [ -f "/opt/postfix/conf/dnsbl_reply.map" ]; then
  420. rm /opt/postfix/conf/dnsbl_reply.map
  421. fi
  422. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  423. if [ "$response" -eq 503 ]; then
  424. echo -e "\e[31mThe AS of your IP is listed as a banned AS from Spamhaus!\e[0m"
  425. echo -e "\e[33mNo SPAMHAUS_DQS_KEY found... Skipping Spamhaus blocklists entirely!\e[0m"
  426. SPAMHAUS_DNSBL_CONFIG=""
  427. elif [ "$response" -eq 200 ]; then
  428. echo -e "\e[32mThe AS of your IP is NOT listed as a banned AS from Spamhaus!\e[0m"
  429. echo -e "\e[33mUsing the open Spamhaus blocklists.\e[0m"
  430. SPAMHAUS_DNSBL_CONFIG=$(cat <<EOF
  431. zen.spamhaus.org=127.0.0.[10;11]*8
  432. zen.spamhaus.org=127.0.0.[4..7]*6
  433. zen.spamhaus.org=127.0.0.3*4
  434. zen.spamhaus.org=127.0.0.2*3
  435. EOF
  436. )
  437. else
  438. echo -e "\e[31mWe couldn't determine your AS... (maybe DNS/Network issue?) Response Code: $response\e[0m"
  439. echo -e "\e[33mDeactivating Spamhaus DNS Blocklists to be on the safe site!\e[0m"
  440. SPAMHAUS_DNSBL_CONFIG=""
  441. fi
  442. fi
  443. fi
  444. # Reset main.cf
  445. sed -i '/Overrides/q' /opt/postfix/conf/main.cf
  446. echo >> /opt/postfix/conf/main.cf
  447. # Append postscreen dnsbl sites to main.cf
  448. if [ ! -z "$DNSBL_CONFIG" ]; then
  449. echo -e "${DNSBL_CONFIG}\n${SPAMHAUS_DNSBL_CONFIG}" >> /opt/postfix/conf/main.cf
  450. fi
  451. # Append user overrides
  452. echo -e "\n# User Overrides" >> /opt/postfix/conf/main.cf
  453. touch /opt/postfix/conf/extra.cf
  454. sed -i '/\$myhostname/! { /myhostname/d }' /opt/postfix/conf/extra.cf
  455. echo -e "myhostname = ${MAILCOW_HOSTNAME}\n$(cat /opt/postfix/conf/extra.cf)" > /opt/postfix/conf/extra.cf
  456. cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
  457. if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
  458. echo "Creating dummy custom_transport.pcre"
  459. touch /opt/postfix/conf/custom_transport.pcre
  460. fi
  461. if [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then
  462. echo "Creating dummy custom_postscreen_whitelist.cidr"
  463. cat <<EOF > /opt/postfix/conf/custom_postscreen_whitelist.cidr
  464. # Autogenerated by mailcow
  465. # Rules are evaluated in the order as specified.
  466. # Blacklist 192.168.* except 192.168.0.1.
  467. # 192.168.0.1 permit
  468. # 192.168.0.0/16 reject
  469. EOF
  470. fi
  471. cat <<EOF > /opt/postfix/conf/postfix-tlspol/config.yaml
  472. server:
  473. address: 127.0.0.1:8642
  474. log-level: info
  475. prefetch: true
  476. cache-file: /var/lib/postfix-tlspol/cache.db
  477. dns:
  478. # must support DNSSEC
  479. address: 127.0.0.11:53
  480. EOF
  481. # Fixing local command execution of postfix-tlspol with symlink to config
  482. if [ ! -L /etc/postfix-tlspol/config.yaml ]; then
  483. ln -s /opt/postfix/conf/postfix-tlspol/config.yaml /etc/postfix-tlspol/config.yaml
  484. fi
  485. # Fix Postfix permissions
  486. chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
  487. chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
  488. chgrp -R postdrop /var/spool/postfix/public
  489. chgrp -R postdrop /var/spool/postfix/maildrop
  490. postfix set-permissions
  491. # Checking if there is a leftover of a crashed postfix container before starting a new one
  492. if [ -e /var/spool/postfix/pid/master.pid ]; then
  493. rm -rf /var/spool/postfix/pid/master.pid
  494. fi
  495. # Check Postfix configuration
  496. postconf -c /opt/postfix/conf > /dev/null
  497. if [[ $? != 0 ]]; then
  498. echo "Postfix configuration error, refusing to start."
  499. exit 1
  500. else
  501. postfix -c /opt/postfix/conf start
  502. sleep 126144000
  503. fi