postfix.sh 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. # Wait for MySQL to warm-up
  5. while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  6. echo "Waiting for database to come up..."
  7. sleep 2
  8. done
  9. while ! dig dns9.quad9.net @unbound +short >/dev/null; do
  10. echo "Waiting for DNS..."
  11. sleep 2
  12. done
  13. cat <<EOF > /etc/aliases
  14. # Autogenerated by mailcow
  15. null: /dev/null
  16. watchdog: /dev/null
  17. ham: "|/usr/local/bin/rspamd-pipe-ham"
  18. spam: "|/usr/local/bin/rspamd-pipe-spam"
  19. EOF
  20. newaliases;
  21. # create sni configuration
  22. echo -n "" > /opt/postfix/conf/sni.map;
  23. for cert_dir in /etc/ssl/mail/*/ ; do
  24. if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
  25. continue;
  26. fi
  27. IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
  28. for domain in "${domains[@]}"; do
  29. echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
  30. echo "" >> /opt/postfix/conf/sni.map;
  31. done
  32. done
  33. postmap -F hash:/opt/postfix/conf/sni.map;
  34. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  35. # Autogenerated by mailcow
  36. user = ${DBUSER}
  37. password = ${DBPASS}
  38. hosts = unix:/var/run/mysqld/mysqld.sock
  39. dbname = ${DBNAME}
  40. query = SELECT DISTINCT
  41. CASE WHEN '%d' IN (
  42. SELECT domain FROM domain
  43. WHERE relay_all_recipients=1
  44. AND domain='%d'
  45. AND backupmx=1
  46. )
  47. THEN '%s' ELSE (
  48. SELECT goto FROM alias WHERE address='%s' AND active='1'
  49. )
  50. END AS result;
  51. EOF
  52. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  53. # Autogenerated by mailcow
  54. user = ${DBUSER}
  55. password = ${DBPASS}
  56. hosts = unix:/var/run/mysqld/mysqld.sock
  57. dbname = ${DBNAME}
  58. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  59. EOF
  60. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  61. # Autogenerated by mailcow
  62. user = ${DBUSER}
  63. password = ${DBPASS}
  64. hosts = unix:/var/run/mysqld/mysqld.sock
  65. dbname = ${DBNAME}
  66. query = SELECT IF(EXISTS(
  67. SELECT 'TLS_ACTIVE' FROM alias
  68. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  69. WHERE (address='%s'
  70. OR address IN (
  71. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  72. WHERE alias_domain='%d'
  73. )
  74. ) AND json_extract(attributes, '$.tls_enforce_in') LIKE '%%1%%' AND mailbox.active = '1'
  75. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  76. EOF
  77. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  78. # Autogenerated by mailcow
  79. user = ${DBUSER}
  80. password = ${DBPASS}
  81. hosts = unix:/var/run/mysqld/mysqld.sock
  82. dbname = ${DBNAME}
  83. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  84. FROM (
  85. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  86. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  87. WHERE (address = '%s'
  88. OR address IN (
  89. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  90. WHERE alias_domain = '%d'
  91. )
  92. )
  93. AND json_extract(attributes, '$.tls_enforce_out') LIKE '%%1%%'
  94. AND mailbox.active = '1'
  95. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  96. UNION ALL
  97. SELECT hostname AS transport FROM relayhosts
  98. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  99. WHERE relayhosts.active = '1'
  100. AND domain = '%d'
  101. OR domain IN (
  102. SELECT target_domain FROM alias_domain
  103. WHERE alias_domain = '%d'
  104. )
  105. )
  106. AS transport_view;
  107. EOF
  108. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  109. # Autogenerated by mailcow
  110. user = ${DBUSER}
  111. password = ${DBPASS}
  112. hosts = unix:/var/run/mysqld/mysqld.sock
  113. dbname = ${DBNAME}
  114. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  115. WHERE active = '1'
  116. AND destination = '%s';
  117. EOF
  118. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  119. # Autogenerated by mailcow
  120. user = ${DBUSER}
  121. password = ${DBPASS}
  122. hosts = unix:/var/run/mysqld/mysqld.sock
  123. dbname = ${DBNAME}
  124. query = SELECT 'null@localhost' FROM mailbox
  125. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  126. EOF
  127. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  128. # Autogenerated by mailcow
  129. user = ${DBUSER}
  130. password = ${DBPASS}
  131. hosts = unix:/var/run/mysqld/mysqld.sock
  132. dbname = ${DBNAME}
  133. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  134. WHERE id IN (
  135. SELECT relayhost FROM domain
  136. WHERE CONCAT('@', domain) = '%s'
  137. OR domain IN (
  138. SELECT target_domain FROM alias_domain WHERE CONCAT('@', alias_domain) = '%s'
  139. )
  140. )
  141. AND active = '1'
  142. AND username != '';
  143. EOF
  144. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  145. # Autogenerated by mailcow
  146. user = ${DBUSER}
  147. password = ${DBPASS}
  148. hosts = unix:/var/run/mysqld/mysqld.sock
  149. dbname = ${DBNAME}
  150. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  151. WHERE nexthop = '%s'
  152. AND active = '1'
  153. AND username != ''
  154. LIMIT 1;
  155. EOF
  156. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  157. # Autogenerated by mailcow
  158. user = ${DBUSER}
  159. password = ${DBPASS}
  160. hosts = unix:/var/run/mysqld/mysqld.sock
  161. dbname = ${DBNAME}
  162. query = SELECT username FROM mailbox, alias_domain
  163. WHERE alias_domain.alias_domain = '%d'
  164. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  165. AND mailbox.active = '1'
  166. AND alias_domain.active='1'
  167. EOF
  168. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  169. # Autogenerated by mailcow
  170. user = ${DBUSER}
  171. password = ${DBPASS}
  172. hosts = unix:/var/run/mysqld/mysqld.sock
  173. dbname = ${DBNAME}
  174. query = SELECT goto FROM alias
  175. WHERE address='%s'
  176. AND active='1';
  177. EOF
  178. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  179. # Autogenerated by mailcow
  180. user = ${DBUSER}
  181. password = ${DBPASS}
  182. hosts = unix:/var/run/mysqld/mysqld.sock
  183. dbname = ${DBNAME}
  184. query = SELECT bcc_dest FROM bcc_maps
  185. WHERE local_dest='%s'
  186. AND type='rcpt'
  187. AND active='1';
  188. EOF
  189. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  190. # Autogenerated by mailcow
  191. user = ${DBUSER}
  192. password = ${DBPASS}
  193. hosts = unix:/var/run/mysqld/mysqld.sock
  194. dbname = ${DBNAME}
  195. query = SELECT bcc_dest FROM bcc_maps
  196. WHERE local_dest='%s'
  197. AND type='sender'
  198. AND active='1';
  199. EOF
  200. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  201. # Autogenerated by mailcow
  202. user = ${DBUSER}
  203. password = ${DBPASS}
  204. hosts = unix:/var/run/mysqld/mysqld.sock
  205. dbname = ${DBNAME}
  206. query = SELECT new_dest FROM recipient_maps
  207. WHERE old_dest='%s'
  208. AND active='1';
  209. EOF
  210. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  211. # Autogenerated by mailcow
  212. user = ${DBUSER}
  213. password = ${DBPASS}
  214. hosts = unix:/var/run/mysqld/mysqld.sock
  215. dbname = ${DBNAME}
  216. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  217. UNION
  218. SELECT domain FROM domain
  219. WHERE domain='%s'
  220. AND active = '1'
  221. AND backupmx = '0'
  222. EOF
  223. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  224. # Autogenerated by mailcow
  225. user = ${DBUSER}
  226. password = ${DBPASS}
  227. hosts = unix:/var/run/mysqld/mysqld.sock
  228. dbname = ${DBNAME}
  229. query = SELECT CONCAT(JSON_UNQUOTE(JSON_EXTRACT(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND active = '1'
  230. EOF
  231. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  232. # Autogenerated by mailcow
  233. user = ${DBUSER}
  234. password = ${DBPASS}
  235. hosts = unix:/var/run/mysqld/mysqld.sock
  236. dbname = ${DBNAME}
  237. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  238. EOF
  239. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  240. # Autogenerated by mailcow
  241. user = ${DBUSER}
  242. password = ${DBPASS}
  243. hosts = unix:/var/run/mysqld/mysqld.sock
  244. dbname = ${DBNAME}
  245. # First select queries domain and alias_domain to determine if domains are active.
  246. query = SELECT goto FROM alias
  247. WHERE address='%s'
  248. AND active='1'
  249. AND (domain IN
  250. (SELECT domain FROM domain
  251. WHERE domain='%d'
  252. AND active='1')
  253. OR domain in (
  254. SELECT alias_domain FROM alias_domain
  255. WHERE alias_domain='%d'
  256. AND active='1'
  257. )
  258. )
  259. UNION
  260. SELECT logged_in_as FROM sender_acl
  261. WHERE send_as='@%d'
  262. OR send_as='%s'
  263. OR send_as='*'
  264. OR send_as IN (
  265. SELECT CONCAT('@',target_domain) FROM alias_domain
  266. WHERE alias_domain = '%d')
  267. OR send_as IN (
  268. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  269. WHERE alias_domain = '%d')
  270. AND logged_in_as NOT IN (
  271. SELECT goto FROM alias
  272. WHERE address='%s')
  273. UNION
  274. SELECT username FROM mailbox, alias_domain
  275. WHERE alias_domain.alias_domain = '%d'
  276. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  277. AND mailbox.active ='1'
  278. AND alias_domain.active='1'
  279. EOF
  280. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  281. # Autogenerated by mailcow
  282. user = ${DBUSER}
  283. password = ${DBPASS}
  284. hosts = unix:/var/run/mysqld/mysqld.sock
  285. dbname = ${DBNAME}
  286. query = SELECT goto FROM spamalias
  287. WHERE address='%s'
  288. AND validity >= UNIX_TIMESTAMP()
  289. EOF
  290. sed -i '/User overrides/q' /opt/postfix/conf/main.cf
  291. echo >> /opt/postfix/conf/main.cf
  292. if [ -f /opt/postfix/conf/extra.cf ]; then
  293. cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
  294. fi
  295. if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
  296. echo "Creating dummy custom_transport.pcre"
  297. touch /opt/postfix/conf/custom_transport.pcre
  298. fi
  299. if [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then
  300. echo "Creating dummy custom_postscreen_whitelist.cidr"
  301. echo '# Autogenerated by mailcow' > /opt/postfix/conf/custom_postscreen_whitelist.cidr
  302. fi
  303. # Fix Postfix permissions
  304. chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
  305. chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
  306. chgrp -R postdrop /var/spool/postfix/public
  307. chgrp -R postdrop /var/spool/postfix/maildrop
  308. postfix set-permissions
  309. # Check Postfix configuration
  310. postconf -c /opt/postfix/conf > /dev/null
  311. if [[ $? != 0 ]]; then
  312. echo "Postfix configuration error, refusing to start."
  313. exit 1
  314. else
  315. postfix -c /opt/postfix/conf start
  316. sleep 126144000
  317. fi