postfix.sh 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. [[ ! -d /opt/postfix/conf/mta-sts-resolver/ ]] && mkdir -p /opt/postfix/conf/mta-sts-resolver/
  5. # Wait for MySQL to warm-up
  6. while ! mariadb-admin status --ssl=false --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  7. echo "Waiting for database to come up..."
  8. sleep 2
  9. done
  10. until dig +short mailcow.email > /dev/null; do
  11. echo "Waiting for DNS..."
  12. sleep 1
  13. done
  14. cat <<EOF > /etc/aliases
  15. # Autogenerated by mailcow
  16. null: /dev/null
  17. watchdog: /dev/null
  18. ham: "|/usr/local/bin/rspamd-pipe-ham"
  19. spam: "|/usr/local/bin/rspamd-pipe-spam"
  20. EOF
  21. newaliases;
  22. # create sni configuration
  23. if [[ "${SKIP_LETS_ENCRYPT}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  24. echo -n "" > /opt/postfix/conf/sni.map
  25. else
  26. echo -n "" > /opt/postfix/conf/sni.map;
  27. for cert_dir in /etc/ssl/mail/*/ ; do
  28. if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
  29. continue;
  30. fi
  31. IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
  32. for domain in "${domains[@]}"; do
  33. echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
  34. echo "" >> /opt/postfix/conf/sni.map;
  35. done
  36. done
  37. fi
  38. postmap -F hash:/opt/postfix/conf/sni.map;
  39. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_ne.cf
  40. # Autogenerated by mailcow
  41. user = ${DBUSER}
  42. password = ${DBPASS}
  43. hosts = unix:/var/run/mysqld/mysqld.sock
  44. dbname = ${DBNAME}
  45. query = SELECT IF(EXISTS(SELECT address, domain FROM alias
  46. WHERE address = '%s'
  47. AND domain IN (
  48. SELECT domain FROM domain
  49. WHERE backupmx = '1'
  50. AND relay_all_recipients = '1'
  51. AND relay_unknown_only = '1')
  52. ), 'lmtp:inet:dovecot:24', NULL) AS 'transport'
  53. EOF
  54. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  55. # Autogenerated by mailcow
  56. user = ${DBUSER}
  57. password = ${DBPASS}
  58. hosts = unix:/var/run/mysqld/mysqld.sock
  59. dbname = ${DBNAME}
  60. query = SELECT DISTINCT
  61. CASE WHEN '%d' IN (
  62. SELECT domain FROM domain
  63. WHERE relay_all_recipients=1
  64. AND domain='%d'
  65. AND backupmx=1
  66. )
  67. THEN '%s' ELSE (
  68. SELECT goto FROM alias WHERE address='%s' AND active='1'
  69. )
  70. END AS result;
  71. EOF
  72. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  73. # Autogenerated by mailcow
  74. user = ${DBUSER}
  75. password = ${DBPASS}
  76. hosts = unix:/var/run/mysqld/mysqld.sock
  77. dbname = ${DBNAME}
  78. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  79. EOF
  80. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  81. # Autogenerated by mailcow
  82. user = ${DBUSER}
  83. password = ${DBPASS}
  84. hosts = unix:/var/run/mysqld/mysqld.sock
  85. dbname = ${DBNAME}
  86. query = SELECT IF(EXISTS(
  87. SELECT 'TLS_ACTIVE' FROM alias
  88. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  89. WHERE (address='%s'
  90. OR address IN (
  91. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  92. WHERE alias_domain='%d'
  93. )
  94. ) AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_in')) = '1' AND mailbox.active = '1'
  95. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  96. EOF
  97. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  98. # Autogenerated by mailcow
  99. user = ${DBUSER}
  100. password = ${DBPASS}
  101. hosts = unix:/var/run/mysqld/mysqld.sock
  102. dbname = ${DBNAME}
  103. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  104. FROM (
  105. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  106. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  107. WHERE (address = '%s'
  108. OR address IN (
  109. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  110. WHERE alias_domain = '%d'
  111. )
  112. )
  113. AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_out')) = '1'
  114. AND mailbox.active = '1'
  115. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  116. UNION ALL
  117. SELECT COALESCE(
  118. (SELECT hostname FROM relayhosts
  119. LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id
  120. WHERE relayhosts.active = '1'
  121. AND (
  122. mailbox.username IN (SELECT alias.goto from alias
  123. JOIN mailbox ON mailbox.username = alias.goto
  124. WHERE alias.active = '1'
  125. AND alias.address = '%s'
  126. AND alias.address NOT LIKE '@%%'
  127. )
  128. )
  129. ),
  130. (SELECT hostname FROM relayhosts
  131. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  132. WHERE relayhosts.active = '1'
  133. AND (domain.domain = '%d'
  134. OR domain.domain IN (
  135. SELECT target_domain FROM alias_domain
  136. WHERE alias_domain = '%d'
  137. )
  138. )
  139. )
  140. )
  141. ) AS transport_view;
  142. EOF
  143. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  144. # Autogenerated by mailcow
  145. user = ${DBUSER}
  146. password = ${DBPASS}
  147. hosts = unix:/var/run/mysqld/mysqld.sock
  148. dbname = ${DBNAME}
  149. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  150. WHERE active = '1'
  151. AND destination = '%s';
  152. EOF
  153. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  154. # Autogenerated by mailcow
  155. user = ${DBUSER}
  156. password = ${DBPASS}
  157. hosts = unix:/var/run/mysqld/mysqld.sock
  158. dbname = ${DBNAME}
  159. query = SELECT 'null@localhost' FROM mailbox
  160. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  161. EOF
  162. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  163. # Autogenerated by mailcow
  164. user = ${DBUSER}
  165. password = ${DBPASS}
  166. hosts = unix:/var/run/mysqld/mysqld.sock
  167. dbname = ${DBNAME}
  168. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  169. WHERE id IN (
  170. SELECT COALESCE(
  171. (SELECT id FROM relayhosts
  172. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  173. WHERE relayhosts.active = '1'
  174. AND (domain.domain = '%d'
  175. OR domain.domain IN (
  176. SELECT target_domain FROM alias_domain
  177. WHERE alias_domain = '%d'
  178. )
  179. )
  180. ),
  181. (SELECT id FROM relayhosts
  182. LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id
  183. WHERE relayhosts.active = '1'
  184. AND (
  185. mailbox.username IN (
  186. SELECT alias.goto from alias
  187. JOIN mailbox ON mailbox.username = alias.goto
  188. WHERE alias.active = '1'
  189. AND alias.address = '%s'
  190. AND alias.address NOT LIKE '@%%'
  191. )
  192. )
  193. )
  194. )
  195. )
  196. AND active = '1'
  197. AND username != '';
  198. EOF
  199. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  200. # Autogenerated by mailcow
  201. user = ${DBUSER}
  202. password = ${DBPASS}
  203. hosts = unix:/var/run/mysqld/mysqld.sock
  204. dbname = ${DBNAME}
  205. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  206. WHERE nexthop = '%s'
  207. AND active = '1'
  208. AND username != ''
  209. LIMIT 1;
  210. EOF
  211. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  212. # Autogenerated by mailcow
  213. user = ${DBUSER}
  214. password = ${DBPASS}
  215. hosts = unix:/var/run/mysqld/mysqld.sock
  216. dbname = ${DBNAME}
  217. query = SELECT username FROM mailbox, alias_domain
  218. WHERE alias_domain.alias_domain = '%d'
  219. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  220. AND (mailbox.active = '1' OR mailbox.active = '2')
  221. AND alias_domain.active='1'
  222. EOF
  223. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  224. # Autogenerated by mailcow
  225. user = ${DBUSER}
  226. password = ${DBPASS}
  227. hosts = unix:/var/run/mysqld/mysqld.sock
  228. dbname = ${DBNAME}
  229. query = SELECT goto FROM alias
  230. WHERE address='%s'
  231. AND (active='1' OR active='2');
  232. EOF
  233. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  234. # Autogenerated by mailcow
  235. user = ${DBUSER}
  236. password = ${DBPASS}
  237. hosts = unix:/var/run/mysqld/mysqld.sock
  238. dbname = ${DBNAME}
  239. query = SELECT bcc_dest FROM bcc_maps
  240. WHERE local_dest='%s'
  241. AND type='rcpt'
  242. AND active='1';
  243. EOF
  244. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  245. # Autogenerated by mailcow
  246. user = ${DBUSER}
  247. password = ${DBPASS}
  248. hosts = unix:/var/run/mysqld/mysqld.sock
  249. dbname = ${DBNAME}
  250. query = SELECT bcc_dest FROM bcc_maps
  251. WHERE local_dest='%s'
  252. AND type='sender'
  253. AND active='1';
  254. EOF
  255. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  256. # Autogenerated by mailcow
  257. user = ${DBUSER}
  258. password = ${DBPASS}
  259. hosts = unix:/var/run/mysqld/mysqld.sock
  260. dbname = ${DBNAME}
  261. query = SELECT new_dest FROM recipient_maps
  262. WHERE old_dest='%s'
  263. AND active='1';
  264. EOF
  265. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  266. # Autogenerated by mailcow
  267. user = ${DBUSER}
  268. password = ${DBPASS}
  269. hosts = unix:/var/run/mysqld/mysqld.sock
  270. dbname = ${DBNAME}
  271. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  272. UNION
  273. SELECT domain FROM domain
  274. WHERE domain='%s'
  275. AND active = '1'
  276. AND backupmx = '0'
  277. EOF
  278. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  279. # Autogenerated by mailcow
  280. user = ${DBUSER}
  281. password = ${DBPASS}
  282. hosts = unix:/var/run/mysqld/mysqld.sock
  283. dbname = ${DBNAME}
  284. query = SELECT CONCAT(JSON_UNQUOTE(JSON_VALUE(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND (active = '1' OR active = '2')
  285. EOF
  286. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  287. # Autogenerated by mailcow
  288. user = ${DBUSER}
  289. password = ${DBPASS}
  290. hosts = unix:/var/run/mysqld/mysqld.sock
  291. dbname = ${DBNAME}
  292. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  293. EOF
  294. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  295. # Autogenerated by mailcow
  296. user = ${DBUSER}
  297. password = ${DBPASS}
  298. hosts = unix:/var/run/mysqld/mysqld.sock
  299. dbname = ${DBNAME}
  300. # First select queries domain and alias_domain to determine if domains are active.
  301. query = SELECT goto FROM alias
  302. WHERE id IN (
  303. SELECT COALESCE (
  304. (
  305. SELECT id FROM alias
  306. WHERE address='%s'
  307. AND (active='1' OR active='2')
  308. ), (
  309. SELECT id FROM alias
  310. WHERE address='@%d'
  311. AND (active='1' OR active='2')
  312. )
  313. )
  314. )
  315. AND active='1'
  316. AND (domain IN
  317. (SELECT domain FROM domain
  318. WHERE domain='%d'
  319. AND active='1')
  320. OR domain in (
  321. SELECT alias_domain FROM alias_domain
  322. WHERE alias_domain='%d'
  323. AND active='1'
  324. )
  325. )
  326. UNION
  327. SELECT logged_in_as FROM sender_acl
  328. WHERE send_as='@%d'
  329. OR send_as='%s'
  330. OR send_as='*'
  331. OR send_as IN (
  332. SELECT CONCAT('@',target_domain) FROM alias_domain
  333. WHERE alias_domain = '%d')
  334. OR send_as IN (
  335. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  336. WHERE alias_domain = '%d')
  337. AND logged_in_as NOT IN (
  338. SELECT goto FROM alias
  339. WHERE address='%s')
  340. UNION
  341. SELECT username FROM mailbox, alias_domain
  342. WHERE alias_domain.alias_domain = '%d'
  343. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  344. AND (mailbox.active = '1' OR mailbox.active ='2')
  345. AND alias_domain.active='1';
  346. EOF
  347. # MX based routing
  348. cat <<EOF > /opt/postfix/conf/sql/mysql_mbr_access_maps.cf
  349. # Autogenerated by mailcow
  350. user = ${DBUSER}
  351. password = ${DBPASS}
  352. hosts = unix:/var/run/mysqld/mysqld.sock
  353. dbname = ${DBNAME}
  354. query = SELECT CONCAT('FILTER smtp_via_transport_maps:', nexthop) as transport FROM transports
  355. WHERE '%s' REGEXP destination
  356. AND active='1'
  357. AND is_mx_based='1';
  358. EOF
  359. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  360. # Autogenerated by mailcow
  361. user = ${DBUSER}
  362. password = ${DBPASS}
  363. hosts = unix:/var/run/mysqld/mysqld.sock
  364. dbname = ${DBNAME}
  365. query = SELECT goto FROM spamalias
  366. WHERE address='%s'
  367. AND validity >= UNIX_TIMESTAMP()
  368. EOF
  369. if [ ! -f /opt/postfix/conf/dns_blocklists.cf ]; then
  370. cat <<EOF > /opt/postfix/conf/dns_blocklists.cf
  371. # This file can be edited.
  372. # Delete this file and restart postfix container to revert any changes.
  373. postscreen_dnsbl_sites = wl.mailspike.net=127.0.0.[18;19;20]*-2
  374. hostkarma.junkemailfilter.com=127.0.0.1*-2
  375. list.dnswl.org=127.0.[0..255].0*-2
  376. list.dnswl.org=127.0.[0..255].1*-4
  377. list.dnswl.org=127.0.[0..255].2*-6
  378. list.dnswl.org=127.0.[0..255].3*-8
  379. bl.spamcop.net*2
  380. bl.suomispam.net*2
  381. hostkarma.junkemailfilter.com=127.0.0.2*3
  382. hostkarma.junkemailfilter.com=127.0.0.4*2
  383. hostkarma.junkemailfilter.com=127.0.1.2*1
  384. backscatter.spameatingmonkey.net*2
  385. bl.ipv6.spameatingmonkey.net*2
  386. bl.spameatingmonkey.net*2
  387. b.barracudacentral.org=127.0.0.2*7
  388. bl.mailspike.net=127.0.0.2*5
  389. bl.mailspike.net=127.0.0.[10;11;12]*4
  390. EOF
  391. fi
  392. # Remove discontinued DNSBLs from existing dns_blocklists.cf
  393. sed -i '/ix\.dnsbl\.manitu\.net\*2/d' /opt/postfix/conf/dns_blocklists.cf # Nixspam
  394. DNSBL_CONFIG=$(grep -v '^#' /opt/postfix/conf/dns_blocklists.cf | grep '\S')
  395. if [ ! -z "$DNSBL_CONFIG" ]; then
  396. echo -e "\e[33mChecking if ASN for your IP is listed for Spamhaus Bad ASN List...\e[0m"
  397. if [ -n "$SPAMHAUS_DQS_KEY" ]; then
  398. echo -e "\e[32mDetected SPAMHAUS_DQS_KEY variable from mailcow.conf...\e[0m"
  399. echo -e "\e[33mUsing DQS Blocklists from Spamhaus!\e[0m"
  400. SPAMHAUS_DNSBL_CONFIG=$(cat <<EOF
  401. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.[4..7]*6
  402. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.[10;11]*8
  403. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.3*4
  404. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net=127.0.0.2*3
  405. postscreen_dnsbl_reply_map = texthash:/opt/postfix/conf/dnsbl_reply.map
  406. EOF
  407. cat <<EOF > /opt/postfix/conf/dnsbl_reply.map
  408. # Autogenerated by mailcow, using Spamhaus DQS reply domains
  409. ${SPAMHAUS_DQS_KEY}.sbl.dq.spamhaus.net sbl.spamhaus.org
  410. ${SPAMHAUS_DQS_KEY}.xbl.dq.spamhaus.net xbl.spamhaus.org
  411. ${SPAMHAUS_DQS_KEY}.pbl.dq.spamhaus.net pbl.spamhaus.org
  412. ${SPAMHAUS_DQS_KEY}.zen.dq.spamhaus.net zen.spamhaus.org
  413. ${SPAMHAUS_DQS_KEY}.dbl.dq.spamhaus.net dbl.spamhaus.org
  414. ${SPAMHAUS_DQS_KEY}.zrd.dq.spamhaus.net zrd.spamhaus.org
  415. EOF
  416. )
  417. else
  418. if [ -f "/opt/postfix/conf/dnsbl_reply.map" ]; then
  419. rm /opt/postfix/conf/dnsbl_reply.map
  420. fi
  421. response=$(curl --connect-timeout 15 --max-time 30 -s -o /dev/null -w "%{http_code}" "https://asn-check.mailcow.email")
  422. if [ "$response" -eq 503 ]; then
  423. echo -e "\e[31mThe AS of your IP is listed as a banned AS from Spamhaus!\e[0m"
  424. echo -e "\e[33mNo SPAMHAUS_DQS_KEY found... Skipping Spamhaus blocklists entirely!\e[0m"
  425. SPAMHAUS_DNSBL_CONFIG=""
  426. elif [ "$response" -eq 200 ]; then
  427. echo -e "\e[32mThe AS of your IP is NOT listed as a banned AS from Spamhaus!\e[0m"
  428. echo -e "\e[33mUsing the open Spamhaus blocklists.\e[0m"
  429. SPAMHAUS_DNSBL_CONFIG=$(cat <<EOF
  430. zen.spamhaus.org=127.0.0.[10;11]*8
  431. zen.spamhaus.org=127.0.0.[4..7]*6
  432. zen.spamhaus.org=127.0.0.3*4
  433. zen.spamhaus.org=127.0.0.2*3
  434. EOF
  435. )
  436. else
  437. echo -e "\e[31mWe couldn't determine your AS... (maybe DNS/Network issue?) Response Code: $response\e[0m"
  438. echo -e "\e[33mDeactivating Spamhaus DNS Blocklists to be on the safe site!\e[0m"
  439. SPAMHAUS_DNSBL_CONFIG=""
  440. fi
  441. fi
  442. fi
  443. # Reset main.cf
  444. sed -i '/Overrides/q' /opt/postfix/conf/main.cf
  445. echo >> /opt/postfix/conf/main.cf
  446. # Append postscreen dnsbl sites to main.cf
  447. if [ ! -z "$DNSBL_CONFIG" ]; then
  448. echo -e "${DNSBL_CONFIG}\n${SPAMHAUS_DNSBL_CONFIG}" >> /opt/postfix/conf/main.cf
  449. fi
  450. # Append user overrides
  451. echo -e "\n# User Overrides" >> /opt/postfix/conf/main.cf
  452. touch /opt/postfix/conf/extra.cf
  453. sed -i '/\$myhostname/! { /myhostname/d }' /opt/postfix/conf/extra.cf
  454. echo -e "myhostname = ${MAILCOW_HOSTNAME}\n$(cat /opt/postfix/conf/extra.cf)" > /opt/postfix/conf/extra.cf
  455. cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
  456. if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
  457. echo "Creating dummy custom_transport.pcre"
  458. touch /opt/postfix/conf/custom_transport.pcre
  459. fi
  460. if [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then
  461. echo "Creating dummy custom_postscreen_whitelist.cidr"
  462. cat <<EOF > /opt/postfix/conf/custom_postscreen_whitelist.cidr
  463. # Autogenerated by mailcow
  464. # Rules are evaluated in the order as specified.
  465. # Blacklist 192.168.* except 192.168.0.1.
  466. # 192.168.0.1 permit
  467. # 192.168.0.0/16 reject
  468. EOF
  469. fi
  470. cat <<EOF > /opt/postfix/conf/mta-sts-resolver/daemon.yml
  471. # Autogenerated by mailcow | DO NOT TOUCH!
  472. host: 127.0.0.1
  473. port: 8461
  474. reuse_port: true
  475. shutdown_timeout: 20
  476. cache:
  477. type: redis
  478. options:
  479. url: "redis://redis/1" # Use seperate Redis Database for mta-sts keys
  480. max_connections: 25
  481. socket_timeout: 1.0
  482. socket_connect_timeout: 1.0
  483. password: ${REDISPASS}
  484. proactive_policy_fetching:
  485. enabled: true
  486. interval: 86400
  487. default_zone:
  488. strict_testing: false
  489. timeout: 4
  490. tlsrpt: false # TODO for Postfix Deb 13
  491. zones:
  492. myzone:
  493. strict_testing: false
  494. timeout: 4
  495. EOF
  496. # Fix Postfix permissions
  497. chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
  498. chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
  499. chgrp -R postdrop /var/spool/postfix/public
  500. chgrp -R postdrop /var/spool/postfix/maildrop
  501. postfix set-permissions
  502. # Checking if there is a leftover of a crashed postfix container before starting a new one
  503. if [ -e /var/spool/postfix/pid/master.pid ]; then
  504. rm -rf /var/spool/postfix/pid/master.pid
  505. fi
  506. # Check Postfix configuration
  507. postconf -c /opt/postfix/conf > /dev/null
  508. if [[ $? != 0 ]]; then
  509. echo "Postfix configuration error, refusing to start."
  510. exit 1
  511. else
  512. postfix -c /opt/postfix/conf start
  513. sleep 126144000
  514. fi