postfix.sh 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. cat <<EOF > /etc/aliases
  5. null: /dev/null
  6. ham: "|/usr/local/bin/rspamd-pipe-ham"
  7. spam: "|/usr/local/bin/rspamd-pipe-spam"
  8. EOF
  9. newaliases;
  10. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  11. user = ${DBUSER}
  12. password = ${DBPASS}
  13. hosts = unix:/var/run/mysqld/mysqld.sock
  14. dbname = ${DBNAME}
  15. query = SELECT DISTINCT
  16. CASE WHEN '%d' IN (
  17. SELECT domain FROM domain
  18. WHERE relay_all_recipients=1
  19. AND domain='%d'
  20. AND backupmx=1
  21. )
  22. THEN '%s' ELSE (
  23. SELECT goto FROM alias WHERE address='%s' AND active='1'
  24. )
  25. END AS result;
  26. EOF
  27. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  28. user = ${DBUSER}
  29. password = ${DBPASS}
  30. hosts = unix:/var/run/mysqld/mysqld.sock
  31. dbname = ${DBNAME}
  32. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  33. EOF
  34. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  35. user = ${DBUSER}
  36. password = ${DBPASS}
  37. hosts = unix:/var/run/mysqld/mysqld.sock
  38. dbname = ${DBNAME}
  39. query = SELECT IF(EXISTS(
  40. SELECT 'TLS_ACTIVE' FROM alias
  41. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  42. WHERE (address='%s'
  43. OR address IN (
  44. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  45. WHERE alias_domain='%d'
  46. )
  47. ) AND json_extract(attributes, '$.tls_enforce_in') LIKE '%%1%%' AND mailbox.active = '1'
  48. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  49. EOF
  50. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  51. user = ${DBUSER}
  52. password = ${DBPASS}
  53. hosts = unix:/var/run/mysqld/mysqld.sock
  54. dbname = ${DBNAME}
  55. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  56. FROM (
  57. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  58. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  59. WHERE (address = '%s'
  60. OR address IN (
  61. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  62. WHERE alias_domain = '%d'
  63. )
  64. )
  65. AND json_extract(attributes, '$.tls_enforce_out') LIKE '%%1%%'
  66. AND mailbox.active = '1'
  67. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  68. UNION ALL
  69. SELECT hostname AS transport FROM relayhosts
  70. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  71. WHERE relayhosts.active = '1'
  72. AND domain = '%d'
  73. OR domain IN (
  74. SELECT target_domain FROM alias_domain
  75. WHERE alias_domain = '%d'
  76. )
  77. )
  78. AS transport_view;
  79. EOF
  80. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  81. user = ${DBUSER}
  82. password = ${DBPASS}
  83. hosts = unix:/var/run/mysqld/mysqld.sock
  84. dbname = ${DBNAME}
  85. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  86. WHERE active = '1'
  87. AND destination = '%s';
  88. EOF
  89. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  90. user = ${DBUSER}
  91. password = ${DBPASS}
  92. hosts = unix:/var/run/mysqld/mysqld.sock
  93. dbname = ${DBNAME}
  94. query = SELECT 'null@localhost' FROM mailbox
  95. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  96. EOF
  97. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  98. user = ${DBUSER}
  99. password = ${DBPASS}
  100. hosts = unix:/var/run/mysqld/mysqld.sock
  101. dbname = ${DBNAME}
  102. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  103. WHERE id IN (
  104. SELECT relayhost FROM domain
  105. WHERE CONCAT('@', domain) = '%s'
  106. OR domain IN (
  107. SELECT target_domain FROM alias_domain WHERE CONCAT('@', alias_domain) = '%s'
  108. )
  109. )
  110. AND active = '1'
  111. AND username != '';
  112. EOF
  113. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  114. user = ${DBUSER}
  115. password = ${DBPASS}
  116. hosts = unix:/var/run/mysqld/mysqld.sock
  117. dbname = ${DBNAME}
  118. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  119. WHERE nexthop = '%s'
  120. AND active = '1'
  121. AND username != ''
  122. LIMIT 1;
  123. EOF
  124. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_catchall_maps.cf
  125. user = ${DBUSER}
  126. password = ${DBPASS}
  127. hosts = unix:/var/run/mysqld/mysqld.sock
  128. dbname = ${DBNAME}
  129. query = SELECT goto FROM alias, alias_domain
  130. WHERE alias_domain.alias_domain = '%d'
  131. AND alias.address = CONCAT('@', alias_domain.target_domain)
  132. AND alias.active = 1 AND alias_domain.active='1'
  133. EOF
  134. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  135. user = ${DBUSER}
  136. password = ${DBPASS}
  137. hosts = unix:/var/run/mysqld/mysqld.sock
  138. dbname = ${DBNAME}
  139. query = SELECT username FROM mailbox, alias_domain
  140. WHERE alias_domain.alias_domain = '%d'
  141. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  142. AND mailbox.active = '1'
  143. AND alias_domain.active='1'
  144. EOF
  145. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  146. user = ${DBUSER}
  147. password = ${DBPASS}
  148. hosts = unix:/var/run/mysqld/mysqld.sock
  149. dbname = ${DBNAME}
  150. query = SELECT goto FROM alias
  151. WHERE address='%s'
  152. AND active='1';
  153. EOF
  154. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  155. user = ${DBUSER}
  156. password = ${DBPASS}
  157. hosts = unix:/var/run/mysqld/mysqld.sock
  158. dbname = ${DBNAME}
  159. query = SELECT bcc_dest FROM bcc_maps
  160. WHERE local_dest='%s'
  161. AND type='rcpt'
  162. AND active='1';
  163. EOF
  164. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  165. user = ${DBUSER}
  166. password = ${DBPASS}
  167. hosts = unix:/var/run/mysqld/mysqld.sock
  168. dbname = ${DBNAME}
  169. query = SELECT bcc_dest FROM bcc_maps
  170. WHERE local_dest='%s'
  171. AND type='sender'
  172. AND active='1';
  173. EOF
  174. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  175. user = ${DBUSER}
  176. password = ${DBPASS}
  177. hosts = unix:/var/run/mysqld/mysqld.sock
  178. dbname = ${DBNAME}
  179. query = SELECT new_dest FROM recipient_maps
  180. WHERE old_dest='%s'
  181. AND active='1';
  182. EOF
  183. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  184. user = ${DBUSER}
  185. password = ${DBPASS}
  186. hosts = unix:/var/run/mysqld/mysqld.sock
  187. dbname = ${DBNAME}
  188. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  189. UNION
  190. SELECT domain FROM domain
  191. WHERE domain='%s'
  192. AND active = '1'
  193. AND backupmx = '0'
  194. EOF
  195. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  196. user = ${DBUSER}
  197. password = ${DBPASS}
  198. hosts = unix:/var/run/mysqld/mysqld.sock
  199. dbname = ${DBNAME}
  200. query = SELECT CONCAT(JSON_UNQUOTE(JSON_EXTRACT(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND active = '1'
  201. EOF
  202. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  203. user = ${DBUSER}
  204. password = ${DBPASS}
  205. hosts = unix:/var/run/mysqld/mysqld.sock
  206. dbname = ${DBNAME}
  207. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  208. EOF
  209. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  210. user = ${DBUSER}
  211. password = ${DBPASS}
  212. hosts = unix:/var/run/mysqld/mysqld.sock
  213. dbname = ${DBNAME}
  214. # First select queries domain and alias_domain to determine if domains are active.
  215. query = SELECT goto FROM alias
  216. WHERE address='%s'
  217. AND active='1'
  218. AND (domain IN
  219. (SELECT domain FROM domain
  220. WHERE domain='%d'
  221. AND active='1')
  222. OR domain in (
  223. SELECT alias_domain FROM alias_domain
  224. WHERE alias_domain='%d'
  225. AND active='1'
  226. )
  227. )
  228. UNION
  229. SELECT logged_in_as FROM sender_acl
  230. WHERE send_as='@%d'
  231. OR send_as='%s'
  232. OR send_as='*'
  233. OR send_as IN (
  234. SELECT CONCAT('@',target_domain) FROM alias_domain
  235. WHERE alias_domain = '%d')
  236. OR send_as IN (
  237. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  238. WHERE alias_domain = '%d')
  239. AND logged_in_as NOT IN (
  240. SELECT goto FROM alias
  241. WHERE address='%s')
  242. UNION
  243. SELECT username FROM mailbox, alias_domain
  244. WHERE alias_domain.alias_domain = '%d'
  245. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  246. AND mailbox.active ='1'
  247. AND alias_domain.active='1'
  248. EOF
  249. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  250. user = ${DBUSER}
  251. password = ${DBPASS}
  252. hosts = unix:/var/run/mysqld/mysqld.sock
  253. dbname = ${DBNAME}
  254. query = SELECT goto FROM spamalias
  255. WHERE address='%s'
  256. AND validity >= UNIX_TIMESTAMP()
  257. EOF
  258. # Reset GPG key permissions
  259. mkdir -p /var/lib/zeyple/keys
  260. chmod 700 /var/lib/zeyple/keys
  261. chown -R 600:600 /var/lib/zeyple/keys
  262. # Fix Postfix permissions
  263. chown -R root:postfix /opt/postfix/conf/sql/
  264. chmod 640 /opt/postfix/conf/sql/*.cf
  265. chgrp -R postdrop /var/spool/postfix/public
  266. chgrp -R postdrop /var/spool/postfix/maildrop
  267. postfix set-permissions
  268. # Check Postfix configuration
  269. postconf -c /opt/postfix/conf
  270. if [[ $? != 0 ]]; then
  271. echo "Postfix configuration error, refusing to start."
  272. exit 1
  273. else
  274. postfix -c /opt/postfix/conf start
  275. sleep 126144000
  276. fi