Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # postfix config file
- # uncomment for debugging if needed
- soft_bounce=yes
- # postfix main
- mail_owner = postfix
- setgid_group = postdrop
- delay_warning_time = 4
- # postfix paths
- html_directory = no
- command_directory = /usr/sbin
- daemon_directory = /usr/lib/postfix
- queue_directory = /var/spool/postfix
- sendmail_path = /usr/sbin/sendmail.postfix
- newaliases_path = /usr/bin/newaliases.postfix
- mailq_path = /usr/bin/mailq.postfix
- manpage_directory = /usr/share/man
- sample_directory = /usr/share/doc/postfix-2.2.2/samples
- readme_directory = /usr/share/doc/postfix-2.2.2/README_FILES
- # network settings
- inet_interfaces = all
- mydomain = njoror.squashedfly.eu
- myhostname = njoror.squashedfly.eu
- mynetworks = 127.0.0.1, 213.138.113.144
- mydestination = localhost.$mydomain, localhost
- relay_domains = proxy:mysql:/etc/sentora/configs/postfix/mysql-relay_domains_maps.cf
- # mail delivery
- recipient_delimiter = +
- dovecot_destination_recipient_limit = 1
- # mappings
- alias_maps = hash:/etc/aliases
- alias_database = hash:/etc/aliases
- #transport_maps = hash:/etc/postfix/transport
- #local_recipient_maps =
- # virtual setup
- virtual_alias_maps = proxy:mysql:/etc/sentora/configs/postfix/mysql-virtual_alias_maps.cf,
- regexp:/etc/sentora/configs/postfix/virtual_regexp
- virtual_mailbox_base = /var/sentora/vmail
- virtual_mailbox_domains = proxy:mysql:/etc/sentora/configs/postfix/mysql-virtual_domains_maps.cf
- virtual_mailbox_maps = proxy:mysql:/etc/sentora/configs/postfix/mysql-virtual_mailbox_maps.cf
- virtual_minimum_uid = 999
- virtual_uid_maps = static:999
- virtual_gid_maps = static:8
- virtual_transport = dovecot
- dovecot_destination_recipient_limit = 1
- # debugging
- debug_peer_level = 2
- debugger_command =
- PATH=/bin:/usr/bin:/usr/local/bin:/usr/X11R6/bin
- xxgdb $daemon_directory/$process_name $process_id & sleep 5
- # authentication
- smtpd_sasl_auth_enable = yes
- smtpd_sasl_security_options = noanonymous
- smtpd_sasl_local_domain = $myhostname
- broken_sasl_auth_clients = yes
- smtpd_sasl_type = dovecot
- smtpd_sasl_path = private/auth
- # tls config
- # smtp_use_tls = no
- # smtpd_use_tls = no
- #smtp_tls_note_starttls_offer = yes
- #smtpd_tls_loglevel = 1
- #smtpd_tls_received_header = yes
- #smtpd_tls_session_cache_timeout = 3600s
- #tls_random_source = dev:/dev/urandom
- #smtp_tls_session_cache_database = btree:$data_directory/smtp_tls_session_cache
- # Change mail.example.com.* to your host name
- #smtpd_tls_key_file = /etc/pki/tls/private/mail.example.com.key
- #smtpd_tls_cert_file = /etc/pki/tls/certs/mail.example.com.crt
- # smtpd_tls_CAfile = /etc/pki/tls/root.crt
- # rules restrictions
- smtpd_client_restrictions =
- smtpd_helo_restrictions = permit_mynetworks,
- reject_invalid_hostname,
- permit
- smtpd_sender_restrictions = permit_sasl_authenticated,
- permit_mynetworks,
- reject_unknown_sender_domain,
- permit
- smtpd_recipient_restrictions = permit_sasl_authenticated,
- permit_mynetworks,
- permit_inet_interfaces,
- reject_unauth_destination,
- reject_non_fqdn_sender,
- reject_non_fqdn_recipient,
- reject_non_fqdn_hostname,
- permit_sasl_authenticated,
- reject_unknown_recipient_domain,
- reject_unauth_destination,
- reject_invalid_hostname
- # uncomment for realtime black list checks. (Warn: will also reject false positive)
- ,reject_rbl_client zen.spamhaus.org
- ,reject_rbl_client bl.spamcop.net
- ,reject_rbl_client dnsbl.sorbs.net
- #,check_policy_service inet:127.0.0.1:10023
- smtpd_helo_required = yes
- unknown_local_recipient_reject_code = 550
- disable_vrfy_command = yes
- smtpd_data_restrictions = reject_unauth_pipelining
- smtpd_banner = $myhostname ESMTP
- message_size_limit = 20480000
- # Things Philip Changed for SSL
- # Raise log level as default doesn't give much information
- smtpd_tls_loglevel = 1
- # path to the certificate file, should be root:root and 0444
- smtpd_tls_cert_file=/etc/letsencrypt/live/njoror.squashedfly.eu/fullchain.pem
- # path to the private key file, should be root:root and 0400
- smtpd_tls_key_file=/etc/letsencrypt/live/njoror.squashedfly.eu/privkey.pem
- # Allow use of TLS but make it optional
- smtpd_use_tls=yes
- # Cache sessions for speed improvement
- smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
- smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
- # Disable SSLv2/3 as they are vulnerable
- smtpd_tls_protocols = !SSLv2, !SSLv3
- # Insist on stronger ciphers
- smtpd_tls_ciphers = high
- # SASL parameters
- # Don't forget permit_sasl_authenticated in smtpd_relay_restrictions
- smtpd_sasl_type = dovecot
- smtpd_sasl_path = private/auth
- smtpd_sasl_auth_enable = yes
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement