postfix.sh 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383
  1. #!/bin/bash
  2. trap "postfix stop" EXIT
  3. [[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
  4. # Wait for MySQL to warm-up
  5. while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
  6. echo "Waiting for database to come up..."
  7. sleep 2
  8. done
  9. until dig +short mailcow.email @unbound > /dev/null; do
  10. echo "Waiting for DNS..."
  11. sleep 1
  12. done
  13. cat <<EOF > /etc/aliases
  14. # Autogenerated by mailcow
  15. null: /dev/null
  16. watchdog: /dev/null
  17. ham: "|/usr/local/bin/rspamd-pipe-ham"
  18. spam: "|/usr/local/bin/rspamd-pipe-spam"
  19. EOF
  20. newaliases;
  21. # create sni configuration
  22. if [[ "${SKIP_LETS_ENCRYPT}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then
  23. echo -n "" > /opt/postfix/conf/sni.map
  24. else
  25. echo -n "" > /opt/postfix/conf/sni.map;
  26. for cert_dir in /etc/ssl/mail/*/ ; do
  27. if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
  28. continue;
  29. fi
  30. IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
  31. for domain in "${domains[@]}"; do
  32. echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
  33. echo "" >> /opt/postfix/conf/sni.map;
  34. done
  35. done
  36. fi
  37. postmap -F hash:/opt/postfix/conf/sni.map;
  38. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_ne.cf
  39. # Autogenerated by mailcow
  40. user = ${DBUSER}
  41. password = ${DBPASS}
  42. hosts = unix:/var/run/mysqld/mysqld.sock
  43. dbname = ${DBNAME}
  44. query = SELECT IF(EXISTS(SELECT address, domain FROM alias
  45. WHERE address = '%s'
  46. AND domain IN (
  47. SELECT domain FROM domain
  48. WHERE backupmx = '1'
  49. AND relay_all_recipients = '1'
  50. AND relay_unknown_only = '1')
  51. ), 'lmtp:inet:dovecot:24', NULL) AS 'transport'
  52. EOF
  53. cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
  54. # Autogenerated by mailcow
  55. user = ${DBUSER}
  56. password = ${DBPASS}
  57. hosts = unix:/var/run/mysqld/mysqld.sock
  58. dbname = ${DBNAME}
  59. query = SELECT DISTINCT
  60. CASE WHEN '%d' IN (
  61. SELECT domain FROM domain
  62. WHERE relay_all_recipients=1
  63. AND domain='%d'
  64. AND backupmx=1
  65. )
  66. THEN '%s' ELSE (
  67. SELECT goto FROM alias WHERE address='%s' AND active='1'
  68. )
  69. END AS result;
  70. EOF
  71. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
  72. # Autogenerated by mailcow
  73. user = ${DBUSER}
  74. password = ${DBPASS}
  75. hosts = unix:/var/run/mysqld/mysqld.sock
  76. dbname = ${DBNAME}
  77. query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
  78. EOF
  79. cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
  80. # Autogenerated by mailcow
  81. user = ${DBUSER}
  82. password = ${DBPASS}
  83. hosts = unix:/var/run/mysqld/mysqld.sock
  84. dbname = ${DBNAME}
  85. query = SELECT IF(EXISTS(
  86. SELECT 'TLS_ACTIVE' FROM alias
  87. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  88. WHERE (address='%s'
  89. OR address IN (
  90. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  91. WHERE alias_domain='%d'
  92. )
  93. ) AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_in')) = '1' AND mailbox.active = '1'
  94. ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
  95. EOF
  96. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
  97. # Autogenerated by mailcow
  98. user = ${DBUSER}
  99. password = ${DBPASS}
  100. hosts = unix:/var/run/mysqld/mysqld.sock
  101. dbname = ${DBNAME}
  102. query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
  103. FROM (
  104. SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
  105. LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
  106. WHERE (address = '%s'
  107. OR address IN (
  108. SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
  109. WHERE alias_domain = '%d'
  110. )
  111. )
  112. AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_out')) = '1'
  113. AND mailbox.active = '1'
  114. ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
  115. UNION ALL
  116. SELECT hostname AS transport FROM relayhosts
  117. LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
  118. WHERE relayhosts.active = '1'
  119. AND domain = '%d'
  120. OR domain IN (
  121. SELECT target_domain FROM alias_domain
  122. WHERE alias_domain = '%d'
  123. )
  124. )
  125. AS transport_view;
  126. EOF
  127. cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
  128. # Autogenerated by mailcow
  129. user = ${DBUSER}
  130. password = ${DBPASS}
  131. hosts = unix:/var/run/mysqld/mysqld.sock
  132. dbname = ${DBNAME}
  133. query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
  134. WHERE active = '1'
  135. AND destination = '%s';
  136. EOF
  137. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
  138. # Autogenerated by mailcow
  139. user = ${DBUSER}
  140. password = ${DBPASS}
  141. hosts = unix:/var/run/mysqld/mysqld.sock
  142. dbname = ${DBNAME}
  143. query = SELECT 'null@localhost' FROM mailbox
  144. WHERE kind REGEXP 'location|thing|group' AND username = '%s';
  145. EOF
  146. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
  147. # Autogenerated by mailcow
  148. user = ${DBUSER}
  149. password = ${DBPASS}
  150. hosts = unix:/var/run/mysqld/mysqld.sock
  151. dbname = ${DBNAME}
  152. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
  153. WHERE id IN (
  154. SELECT relayhost FROM domain
  155. WHERE CONCAT('@', domain) = '%s'
  156. OR domain IN (
  157. SELECT target_domain FROM alias_domain WHERE CONCAT('@', alias_domain) = '%s'
  158. )
  159. )
  160. AND active = '1'
  161. AND username != '';
  162. EOF
  163. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
  164. # Autogenerated by mailcow
  165. user = ${DBUSER}
  166. password = ${DBPASS}
  167. hosts = unix:/var/run/mysqld/mysqld.sock
  168. dbname = ${DBNAME}
  169. query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
  170. WHERE nexthop = '%s'
  171. AND active = '1'
  172. AND username != ''
  173. LIMIT 1;
  174. EOF
  175. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
  176. # Autogenerated by mailcow
  177. user = ${DBUSER}
  178. password = ${DBPASS}
  179. hosts = unix:/var/run/mysqld/mysqld.sock
  180. dbname = ${DBNAME}
  181. query = SELECT username FROM mailbox, alias_domain
  182. WHERE alias_domain.alias_domain = '%d'
  183. AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
  184. AND (mailbox.active = '1' OR mailbox.active = '2')
  185. AND alias_domain.active='1'
  186. EOF
  187. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
  188. # Autogenerated by mailcow
  189. user = ${DBUSER}
  190. password = ${DBPASS}
  191. hosts = unix:/var/run/mysqld/mysqld.sock
  192. dbname = ${DBNAME}
  193. query = SELECT goto FROM alias
  194. WHERE address='%s'
  195. AND (active='1' OR active='2');
  196. EOF
  197. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
  198. # Autogenerated by mailcow
  199. user = ${DBUSER}
  200. password = ${DBPASS}
  201. hosts = unix:/var/run/mysqld/mysqld.sock
  202. dbname = ${DBNAME}
  203. query = SELECT bcc_dest FROM bcc_maps
  204. WHERE local_dest='%s'
  205. AND type='rcpt'
  206. AND active='1';
  207. EOF
  208. cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
  209. # Autogenerated by mailcow
  210. user = ${DBUSER}
  211. password = ${DBPASS}
  212. hosts = unix:/var/run/mysqld/mysqld.sock
  213. dbname = ${DBNAME}
  214. query = SELECT bcc_dest FROM bcc_maps
  215. WHERE local_dest='%s'
  216. AND type='sender'
  217. AND active='1';
  218. EOF
  219. cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
  220. # Autogenerated by mailcow
  221. user = ${DBUSER}
  222. password = ${DBPASS}
  223. hosts = unix:/var/run/mysqld/mysqld.sock
  224. dbname = ${DBNAME}
  225. query = SELECT new_dest FROM recipient_maps
  226. WHERE old_dest='%s'
  227. AND active='1';
  228. EOF
  229. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
  230. # Autogenerated by mailcow
  231. user = ${DBUSER}
  232. password = ${DBPASS}
  233. hosts = unix:/var/run/mysqld/mysqld.sock
  234. dbname = ${DBNAME}
  235. query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
  236. UNION
  237. SELECT domain FROM domain
  238. WHERE domain='%s'
  239. AND active = '1'
  240. AND backupmx = '0'
  241. EOF
  242. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
  243. # Autogenerated by mailcow
  244. user = ${DBUSER}
  245. password = ${DBPASS}
  246. hosts = unix:/var/run/mysqld/mysqld.sock
  247. dbname = ${DBNAME}
  248. query = SELECT CONCAT(JSON_UNQUOTE(JSON_VALUE(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND (active = '1' OR active = '2')
  249. EOF
  250. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
  251. # Autogenerated by mailcow
  252. user = ${DBUSER}
  253. password = ${DBPASS}
  254. hosts = unix:/var/run/mysqld/mysqld.sock
  255. dbname = ${DBNAME}
  256. query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
  257. EOF
  258. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
  259. # Autogenerated by mailcow
  260. user = ${DBUSER}
  261. password = ${DBPASS}
  262. hosts = unix:/var/run/mysqld/mysqld.sock
  263. dbname = ${DBNAME}
  264. # First select queries domain and alias_domain to determine if domains are active.
  265. query = SELECT goto FROM alias
  266. WHERE address='%s'
  267. AND active='1'
  268. AND (domain IN
  269. (SELECT domain FROM domain
  270. WHERE domain='%d'
  271. AND active='1')
  272. OR domain in (
  273. SELECT alias_domain FROM alias_domain
  274. WHERE alias_domain='%d'
  275. AND active='1'
  276. )
  277. )
  278. UNION
  279. SELECT logged_in_as FROM sender_acl
  280. WHERE send_as='@%d'
  281. OR send_as='%s'
  282. OR send_as='*'
  283. OR send_as IN (
  284. SELECT CONCAT('@',target_domain) FROM alias_domain
  285. WHERE alias_domain = '%d')
  286. OR send_as IN (
  287. SELECT CONCAT('%u','@',target_domain) FROM alias_domain
  288. WHERE alias_domain = '%d')
  289. AND logged_in_as NOT IN (
  290. SELECT goto FROM alias
  291. WHERE address='%s')
  292. UNION
  293. SELECT username FROM mailbox, alias_domain
  294. WHERE alias_domain.alias_domain = '%d'
  295. AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
  296. AND (mailbox.active = '1' OR mailbox.active ='2')
  297. AND alias_domain.active='1'
  298. EOF
  299. # Reject sasl usernames with smtp disabled
  300. cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_access_maps.cf
  301. # Autogenerated by mailcow
  302. user = ${DBUSER}
  303. password = ${DBPASS}
  304. hosts = unix:/var/run/mysqld/mysqld.sock
  305. dbname = ${DBNAME}
  306. query = SELECT 'REJECT' FROM mailbox WHERE username = '%u' AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.smtp_access')) = '0';
  307. EOF
  308. cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
  309. # Autogenerated by mailcow
  310. user = ${DBUSER}
  311. password = ${DBPASS}
  312. hosts = unix:/var/run/mysqld/mysqld.sock
  313. dbname = ${DBNAME}
  314. query = SELECT goto FROM spamalias
  315. WHERE address='%s'
  316. AND validity >= UNIX_TIMESTAMP()
  317. EOF
  318. sed -i '/User overrides/q' /opt/postfix/conf/main.cf
  319. echo >> /opt/postfix/conf/main.cf
  320. touch /opt/postfix/conf/extra.cf
  321. sed -i '/myhostname/d' /opt/postfix/conf/extra.cf
  322. echo -e "myhostname = ${MAILCOW_HOSTNAME}\n$(cat /opt/postfix/conf/extra.cf)" > /opt/postfix/conf/extra.cf
  323. cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
  324. if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
  325. echo "Creating dummy custom_transport.pcre"
  326. touch /opt/postfix/conf/custom_transport.pcre
  327. fi
  328. if [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then
  329. echo "Creating dummy custom_postscreen_whitelist.cidr"
  330. echo '# Autogenerated by mailcow' > /opt/postfix/conf/custom_postscreen_whitelist.cidr
  331. fi
  332. # Fix SMTP last login on slaves
  333. sed -i "s/__REDIS_SLAVEOF_IP__/${REDIS_SLAVEOF_IP}/g" /usr/local/bin/smtpd_last_login.sh
  334. # Fix Postfix permissions
  335. chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
  336. chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
  337. chgrp -R postdrop /var/spool/postfix/public
  338. chgrp -R postdrop /var/spool/postfix/maildrop
  339. postfix set-permissions
  340. # Check Postfix configuration
  341. postconf -c /opt/postfix/conf > /dev/null
  342. if [[ $? != 0 ]]; then
  343. echo "Postfix configuration error, refusing to start."
  344. exit 1
  345. else
  346. postfix -c /opt/postfix/conf start
  347. sleep 126144000
  348. fi