Enable Tls Postfix di debian 8 dan 9 dengan letsencrypt
Baru sempet mendokumentasikan lagi
Mengatur Postfix untuk mengenkripsi semua lalu lintas saat berkomunikasi dengan mailserver lainnya, untuk meng Enable Tls Postfix hanya menambahkan trust positive ssl dan beberapa line tambahan di bagian Tls file main.cf di /etc/posfix/main.cf
# TLS parameters
smtpd_tls_cert_file=/etc/letsencrypt/live/sudom.domain.com/fullchain.pem
smtpd_tls_key_file=/etc/letsencrypt/live/sudom.domain.com/privkey.pem
smtpd_use_tls=yes
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
##################################
##outgoing
smtp_tls_security_level = may
smtp_tls_note_starttls_offer = yes
smtp_tls_CApath = /etc/ssl/certs
smtp_tls_CAfile = /etc/ssl/certs/ca-certificates.crt
smtp_tls_loglevel = 1
##incoming
smtpd_tls_security_level = may
smtpd_tls_received_header = yes
smtpd_tls_auth_only = yes
smtpd_tls_CApath = /etc/ssl/certs
smtpd_tls_loglevel = 1
##################################
Note
postfix/smtpd - Ini biasanya adalah proses daemon SMTP untuk menangani email masuk dan routing ke lokasi internal yang sesuai.
postfix/smtp - Ini biasanya adalah proses daemon SMTP untuk mengirim email ke keluar / ke mail server lain.
sumber
http://www.postfix.org/TLS_README.html
https://serverfault.com/questions/696936/whats-the-difference-between-postfix-smtp-and-postfix-smtpd
adapaun log nya menjadi seperti ini
Nov 9 10:06:18 mail postfix/smtpd[8726]: connect from mail.domain.com[36.xx.xx.xx]
Nov 9 10:06:19 mail postfix/smtpd[8726]: Trusted TLS connection established from mail.domain.com[36.xx.xx.xx]: TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)
Nov 9 10:06:19 mail postfix/smtpd[8726]: 327DB22EC8: client=mail.domain.com[36.xx.xx.xx], sasl_method=DIGEST-MD5, [email protected]
Nov 9 10:06:19 mail postfix/cleanup[8732]: 327DB22EC8: message-id=<[email protected]>
Nov 9 10:06:19 mail postfix/qmgr[17172]: 327DB22EC8: from=<[email protected]>, size=33597, nrcpt=1 (queue active)
Nov 9 10:06:19 mail postfix/smtpd[8726]: disconnect from mail.domain.com[36.xx.xx.xx] ehlo=2 starttls=1 auth=1 mail=1 rcpt=1 data=1 quit=1 commands=8
Nov 9 10:06:19 mail postfix/smtp[8734]: Trusted TLS connection established to gmail-smtp-in.l.google.com[74.125.24.26]:25: TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)
Nov 9 10:06:20 mail postfix/smtp[8734]: 327DB22EC8: to=<[email protected]>, relay=gmail-smtp-in.l.google.com[74.125.24.26]:25, delay=1.6, delays=0.07/0/0.67/0.85, dsn=2.0.0, status=sent (250 2.0.0 OK 1541732780 w3-v6si5961460plb.421 - gsmtp)
Nov 9 10:06:20 mail postfix/qmgr[17172]: 327DB22EC8: removed
Salam
Mengatur Postfix untuk mengenkripsi semua lalu lintas saat berkomunikasi dengan mailserver lainnya, untuk meng Enable Tls Postfix hanya menambahkan trust positive ssl dan beberapa line tambahan di bagian Tls file main.cf di /etc/posfix/main.cf
# TLS parameters
smtpd_tls_cert_file=/etc/letsencrypt/live/sudom.domain.com/fullchain.pem
smtpd_tls_key_file=/etc/letsencrypt/live/sudom.domain.com/privkey.pem
smtpd_use_tls=yes
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
##################################
##outgoing
smtp_tls_security_level = may
smtp_tls_note_starttls_offer = yes
smtp_tls_CApath = /etc/ssl/certs
smtp_tls_CAfile = /etc/ssl/certs/ca-certificates.crt
smtp_tls_loglevel = 1
##incoming
smtpd_tls_security_level = may
smtpd_tls_received_header = yes
smtpd_tls_auth_only = yes
smtpd_tls_CApath = /etc/ssl/certs
smtpd_tls_loglevel = 1
##################################
Note
postfix/smtpd - Ini biasanya adalah proses daemon SMTP untuk menangani email masuk dan routing ke lokasi internal yang sesuai.
postfix/smtp - Ini biasanya adalah proses daemon SMTP untuk mengirim email ke keluar / ke mail server lain.
sumber
http://www.postfix.org/TLS_README.html
https://serverfault.com/questions/696936/whats-the-difference-between-postfix-smtp-and-postfix-smtpd
adapaun log nya menjadi seperti ini
Nov 9 10:06:18 mail postfix/smtpd[8726]: connect from mail.domain.com[36.xx.xx.xx]
Nov 9 10:06:19 mail postfix/smtpd[8726]: Trusted TLS connection established from mail.domain.com[36.xx.xx.xx]: TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)
Nov 9 10:06:19 mail postfix/smtpd[8726]: 327DB22EC8: client=mail.domain.com[36.xx.xx.xx], sasl_method=DIGEST-MD5, [email protected]
Nov 9 10:06:19 mail postfix/cleanup[8732]: 327DB22EC8: message-id=<[email protected]>
Nov 9 10:06:19 mail postfix/qmgr[17172]: 327DB22EC8: from=<[email protected]>, size=33597, nrcpt=1 (queue active)
Nov 9 10:06:19 mail postfix/smtpd[8726]: disconnect from mail.domain.com[36.xx.xx.xx] ehlo=2 starttls=1 auth=1 mail=1 rcpt=1 data=1 quit=1 commands=8
Nov 9 10:06:19 mail postfix/smtp[8734]: Trusted TLS connection established to gmail-smtp-in.l.google.com[74.125.24.26]:25: TLSv1.2 with cipher ECDHE-RSA-CHACHA20-POLY1305 (256/256 bits)
Nov 9 10:06:20 mail postfix/smtp[8734]: 327DB22EC8: to=<[email protected]>, relay=gmail-smtp-in.l.google.com[74.125.24.26]:25, delay=1.6, delays=0.07/0/0.67/0.85, dsn=2.0.0, status=sent (250 2.0.0 OK 1541732780 w3-v6si5961460plb.421 - gsmtp)
Nov 9 10:06:20 mail postfix/qmgr[17172]: 327DB22EC8: removed
Salam
Komentar
Posting Komentar