Mail relaying with Jamm
"buzz lightyear" <[email protected]>
| Newsgroups | gmane.mail.jamm.user |
|---|---|
| Message-ID | <[email protected]> |
Howto on postfix/tls for jamm users ----------------------------------- Five days of frustration finally paid off. The following steps have been assimulated from all over. So thanks to everyone, especially Chris Holleman Steps needed to get both tls/postfix up and running and getting connections with email clients: 1. configure cyrus sasl2, something like this should work --with-rc4 --with-dblib=berkeley --enable-anon --enable-cram --enable-digest --enable-plain --enable-login --enable-ntlm --with-ldap=/usr/local 2. get the tls patch from ftp://ftp.aet.tu-cottbus.de/pub/postfix_tls and patch postfix patch -p1 < ../pfixtls-0.8.16-2.0.18-0.9.7c/pfixtls.diff .... if your postfix isn't this version, ftp.aet.tu-cottbus.de contains various versions in one of the subdirs 3. recompile postfix make tidy make makefiles CCARGS="-DUSE_SSL -I/usr/local/ssl/include -DUSE_SASL_AUTH -I/usr/include/sasl -DHAS_LDAP -I/usr/local/include" AUXLIBS="-L/usr/local/lib -lldap -llber -L/usr/local/ssl/lib -lssl -lcrypto -L/usr/lib/sasl2 -lsasl2" make make upgrade 4. update the sasl2 smtpd.conf <edit /usr/lib/sasl2/smtpd.conf and replace the contents (if any) with> pwcheck_method: saslauthd mech_list: LOGIN PLAIN DIGEST-MD5 CRAM-MD5 5. update the saslauthd.conf <edit /etc/saslauthd.conf and replace the contents with> ldap_servers: ldap://192.168.1.3 ldap_filter: mail=%u note: depending on the version of sasl2 libs either use mail=%u or if you sasl2 libs are newer then 2.1.17 use mail=%u@%r in your ldap_filter note2: you might also make your ldap filter to read something like ldap_filter: (&(ObjectClass=JammMailAccount)(mail=%u@%r)(accountactive=TRUE)) 6. update main.cf <edit /etc/postfix/main.cf> smtpd_sasl_auth_enable = yes #smtpd_sasl_local_domain = $myhostname broken_sasl_auth_clients = yes smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, check_relay_domains smtpd_sasl_security_options = noanonymous note: smtpd_recipient_restrictions = permit_mynetworks, permit_sasl_authenticated, check_relay_domains is on one line 7. start saslauthd /usr/local/sbin/saslauthd -a ldap -O /etc/saslauthd.conf 8. restart postfix restart postfix 9. Set your mail client to send an email via your postfix server (port 25) with username/password authentication. This should work as smtpd_sasl_auth_enable = yes 10. Generate an SSL certificate: mkdir /etc/postfix/ssl cd /etc/postfix/ssl openssl req -new -x509 -nodes -out smtpd.pem -keyout smtpd.pem -days 3650 note: I'm not too sure if this command self-signs the certificate. I originally used the following howto to generate my certificates - http://postfix.state-of-mind.de/patrick.koetter/smtpauth/postfix_tls_support.html note2: I will come back with a command for this a little later 11. Add the tls stuff to the /etc/postfix/main.cf # tls config smtp_use_tls = yes smtpd_use_tls = yes smtp_tls_note_starttls_offer = yes smtpd_tls_key_file = /etc/postfix/ssl/smtpd.pem smtpd_tls_cert_file = /etc/postfix/ssl/smtpd.pem smtpd_tls_CAfile = /etc/postfix/ssl/smtpd.pem smtpd_tls_loglevel = 1 smtpd_tls_received_header = yes smtpd_tls_session_cache_timeout = 3600s tls_random_source = dev:/dev/urandom 12. restart postfix 13. Test to ensure that the server is actually able to accept TLS connections and SASL auth: telnet localhost 25 EHLO example.com You should see several lines of text, including these three: 250-STARTTLS 250-AUTH LOGIN PLAIN OTP DIGEST-MD5 CRAM-MD5 250-AUTH=LOGIN PLAIN OTP DIGEST-MD5 CRAM-MD5 14. Use openssl to create a connection with the postfix using tls openssl s_client -starttls smtp -connect localhost:25 This command contacts postfix and sets up tls. I should get as the lastline before "---" and the server's 220: "Verify return code: 19 (self signed certificate in certificate chain)". If you get anything else, your certs are bad or can't be read. The exact text should tell you what. You can also use the 'openssl s_server' utility for testing, instead of PostfixPostfix. 15. Update master.cf <edit /etc/postfix/master.cf and add> smtps inet n - n - - smtpd -o smtpd_tls_wrappermode=yes -o smtpd_sasl_auth_enable=yes 16. Update /etc/services <edit /etc/services and add> smtps 465/tcp # secure smtp note, if port 465 is already being used, then add an alias - use this instead urd 465/tcp smtps # URL Rendesvous Directory for SSM 17. restart the server reboot .. or whatever is the correct sequence for your machine 18. Set the firewall within your environment to allow port 465 to get to your mailserver 19. set you mail client to use ssl or tls and send a mail Most of the above should be straight forward and obvious. Items 15 and 16 are to allow mail clients like outlook express and mozilla to come in over ssl and then be forced to use tls - without these steps, no matter what you do, the connection will always fail. I have aged considerably over the last past five days. I will shortly have to set up another linux box (the above was for a solaris box) and will follow the above steps just to make sure everything works as detailed. I will then take the plunge and try and set up a fail safe environment for postfix and imap. I don't think that this should affect the jamm frontend though. Best Buzz _________________________________________________________________ It's fast, it's easy and it's free. Get MSN Messenger today! http://www.msn.co.uk/messenger ------------------------------------------------------- This SF.Net email is sponsored by: Oracle 10g Get certified on the hottest thing ever to hit the market... Oracle 10g. Take an Oracle 10g class now, and we'll give you the exam FREE. http://ads.osdn.com/?ad_id=3149&alloc_id=8166&op=click