blob: 3b18de40a728b3ea5f3fb27d8ca5f385003fcd5a [file] [log] [blame]
Matthias Andreas Benkardb382b102021-01-02 15:32:21 +01001#!/bin/bash
2
3trap "postfix stop" EXIT
4
5[[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/
6
7# Wait for MySQL to warm-up
8while ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do
9 echo "Waiting for database to come up..."
10 sleep 2
11done
12
13until dig +short mailcow.email @unbound > /dev/null; do
14 echo "Waiting for DNS..."
15 sleep 1
16done
17
18cat <<EOF > /etc/aliases
19# Autogenerated by mailcow
20null: /dev/null
21watchdog: /dev/null
22ham: "|/usr/local/bin/rspamd-pipe-ham"
23spam: "|/usr/local/bin/rspamd-pipe-spam"
24EOF
25newaliases;
26
27# create sni configuration
28echo -n "" > /opt/postfix/conf/sni.map;
29for cert_dir in /etc/ssl/mail/*/ ; do
30 if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then
31 continue;
32 fi
33 IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"
34 for domain in "${domains[@]}"; do
35 echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;
36 echo "" >> /opt/postfix/conf/sni.map;
37 done
38done
39postmap -F hash:/opt/postfix/conf/sni.map;
40
41cat <<EOF > /opt/postfix/conf/sql/mysql_relay_ne.cf
42# Autogenerated by mailcow
43user = ${DBUSER}
44password = ${DBPASS}
45hosts = unix:/var/run/mysqld/mysqld.sock
46dbname = ${DBNAME}
47query = SELECT IF(EXISTS(SELECT address, domain FROM alias
48 WHERE address = '%s'
49 AND domain IN (
50 SELECT domain FROM domain
51 WHERE backupmx = '1'
52 AND relay_all_recipients = '1'
53 AND relay_unknown_only = '1')
54
55 ), 'lmtp:inet:dovecot:24', NULL) AS 'transport'
56EOF
57
58cat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf
59# Autogenerated by mailcow
60user = ${DBUSER}
61password = ${DBPASS}
62hosts = unix:/var/run/mysqld/mysqld.sock
63dbname = ${DBNAME}
64query = SELECT DISTINCT
65 CASE WHEN '%d' IN (
66 SELECT domain FROM domain
67 WHERE relay_all_recipients=1
68 AND domain='%d'
69 AND backupmx=1
70 )
71 THEN '%s' ELSE (
72 SELECT goto FROM alias WHERE address='%s' AND active='1'
73 )
74 END AS result;
75EOF
76
77cat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf
78# Autogenerated by mailcow
79user = ${DBUSER}
80password = ${DBPASS}
81hosts = unix:/var/run/mysqld/mysqld.sock
82dbname = ${DBNAME}
83query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'
84EOF
85
86cat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf
87# Autogenerated by mailcow
88user = ${DBUSER}
89password = ${DBPASS}
90hosts = unix:/var/run/mysqld/mysqld.sock
91dbname = ${DBNAME}
92query = SELECT IF(EXISTS(
93 SELECT 'TLS_ACTIVE' FROM alias
94 LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
95 WHERE (address='%s'
96 OR address IN (
97 SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
98 WHERE alias_domain='%d'
99 )
100 ) AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_in')) = '1' AND mailbox.active = '1'
101 ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';
102EOF
103
104cat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf
105# Autogenerated by mailcow
106user = ${DBUSER}
107password = ${DBPASS}
108hosts = unix:/var/run/mysqld/mysqld.sock
109dbname = ${DBNAME}
110query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps
111 FROM (
112 SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias
113 LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto
114 WHERE (address = '%s'
115 OR address IN (
116 SELECT CONCAT('%u', '@', target_domain) FROM alias_domain
117 WHERE alias_domain = '%d'
118 )
119 )
120 AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_out')) = '1'
121 AND mailbox.active = '1'
122 ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'
123 UNION ALL
124 SELECT hostname AS transport FROM relayhosts
125 LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id
126 WHERE relayhosts.active = '1'
127 AND domain = '%d'
128 OR domain IN (
129 SELECT target_domain FROM alias_domain
130 WHERE alias_domain = '%d'
131 )
132 )
133 AS transport_view;
134EOF
135
136cat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf
137# Autogenerated by mailcow
138user = ${DBUSER}
139password = ${DBPASS}
140hosts = unix:/var/run/mysqld/mysqld.sock
141dbname = ${DBNAME}
142query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports
143 WHERE active = '1'
144 AND destination = '%s';
145EOF
146
147cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf
148# Autogenerated by mailcow
149user = ${DBUSER}
150password = ${DBPASS}
151hosts = unix:/var/run/mysqld/mysqld.sock
152dbname = ${DBNAME}
153query = SELECT 'null@localhost' FROM mailbox
154 WHERE kind REGEXP 'location|thing|group' AND username = '%s';
155EOF
156
157cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf
158# Autogenerated by mailcow
159user = ${DBUSER}
160password = ${DBPASS}
161hosts = unix:/var/run/mysqld/mysqld.sock
162dbname = ${DBNAME}
163query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts
164 WHERE id IN (
165 SELECT relayhost FROM domain
166 WHERE CONCAT('@', domain) = '%s'
167 OR domain IN (
168 SELECT target_domain FROM alias_domain WHERE CONCAT('@', alias_domain) = '%s'
169 )
170 )
171 AND active = '1'
172 AND username != '';
173EOF
174
175cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf
176# Autogenerated by mailcow
177user = ${DBUSER}
178password = ${DBPASS}
179hosts = unix:/var/run/mysqld/mysqld.sock
180dbname = ${DBNAME}
181query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports
182 WHERE nexthop = '%s'
183 AND active = '1'
184 AND username != ''
185 LIMIT 1;
186EOF
187
188cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf
189# Autogenerated by mailcow
190user = ${DBUSER}
191password = ${DBPASS}
192hosts = unix:/var/run/mysqld/mysqld.sock
193dbname = ${DBNAME}
194query = SELECT username FROM mailbox, alias_domain
195 WHERE alias_domain.alias_domain = '%d'
196 AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)
197 AND (mailbox.active = '1' OR mailbox.active = '2')
198 AND alias_domain.active='1'
199EOF
200
201cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf
202# Autogenerated by mailcow
203user = ${DBUSER}
204password = ${DBPASS}
205hosts = unix:/var/run/mysqld/mysqld.sock
206dbname = ${DBNAME}
207query = SELECT goto FROM alias
208 WHERE address='%s'
209 AND (active='1' OR active='2');
210EOF
211
212cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf
213# Autogenerated by mailcow
214user = ${DBUSER}
215password = ${DBPASS}
216hosts = unix:/var/run/mysqld/mysqld.sock
217dbname = ${DBNAME}
218query = SELECT bcc_dest FROM bcc_maps
219 WHERE local_dest='%s'
220 AND type='rcpt'
221 AND active='1';
222EOF
223
224cat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf
225# Autogenerated by mailcow
226user = ${DBUSER}
227password = ${DBPASS}
228hosts = unix:/var/run/mysqld/mysqld.sock
229dbname = ${DBNAME}
230query = SELECT bcc_dest FROM bcc_maps
231 WHERE local_dest='%s'
232 AND type='sender'
233 AND active='1';
234EOF
235
236cat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf
237# Autogenerated by mailcow
238user = ${DBUSER}
239password = ${DBPASS}
240hosts = unix:/var/run/mysqld/mysqld.sock
241dbname = ${DBNAME}
242query = SELECT new_dest FROM recipient_maps
243 WHERE old_dest='%s'
244 AND active='1';
245EOF
246
247cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf
248# Autogenerated by mailcow
249user = ${DBUSER}
250password = ${DBPASS}
251hosts = unix:/var/run/mysqld/mysqld.sock
252dbname = ${DBNAME}
253query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'
254 UNION
255 SELECT domain FROM domain
256 WHERE domain='%s'
257 AND active = '1'
258 AND backupmx = '0'
259EOF
260
261cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf
262# Autogenerated by mailcow
263user = ${DBUSER}
264password = ${DBPASS}
265hosts = unix:/var/run/mysqld/mysqld.sock
266dbname = ${DBNAME}
267query = SELECT CONCAT(JSON_UNQUOTE(JSON_VALUE(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND (active = '1' OR active = '2')
268EOF
269
270cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf
271# Autogenerated by mailcow
272user = ${DBUSER}
273password = ${DBPASS}
274hosts = unix:/var/run/mysqld/mysqld.sock
275dbname = ${DBNAME}
276query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'
277EOF
278
279cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf
280# Autogenerated by mailcow
281user = ${DBUSER}
282password = ${DBPASS}
283hosts = unix:/var/run/mysqld/mysqld.sock
284dbname = ${DBNAME}
285# First select queries domain and alias_domain to determine if domains are active.
286query = SELECT goto FROM alias
287 WHERE address='%s'
288 AND active='1'
289 AND (domain IN
290 (SELECT domain FROM domain
291 WHERE domain='%d'
292 AND active='1')
293 OR domain in (
294 SELECT alias_domain FROM alias_domain
295 WHERE alias_domain='%d'
296 AND active='1'
297 )
298 )
299 UNION
300 SELECT logged_in_as FROM sender_acl
301 WHERE send_as='@%d'
302 OR send_as='%s'
303 OR send_as='*'
304 OR send_as IN (
305 SELECT CONCAT('@',target_domain) FROM alias_domain
306 WHERE alias_domain = '%d')
307 OR send_as IN (
308 SELECT CONCAT('%u','@',target_domain) FROM alias_domain
309 WHERE alias_domain = '%d')
310 AND logged_in_as NOT IN (
311 SELECT goto FROM alias
312 WHERE address='%s')
313 UNION
314 SELECT username FROM mailbox, alias_domain
315 WHERE alias_domain.alias_domain = '%d'
316 AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)
317 AND (mailbox.active = '1' OR mailbox.active ='2')
318 AND alias_domain.active='1'
319EOF
320
321# Reject sasl usernames with smtp disabled
322cat <<EOF > /opt/postfix/conf/sql/mysql_sasl_access_maps.cf
323# Autogenerated by mailcow
324user = ${DBUSER}
325password = ${DBPASS}
326hosts = unix:/var/run/mysqld/mysqld.sock
327dbname = ${DBNAME}
328query = SELECT 'REJECT' FROM mailbox WHERE username = '%u' AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.smtp_access')) = '0';
329EOF
330
331cat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf
332# Autogenerated by mailcow
333user = ${DBUSER}
334password = ${DBPASS}
335hosts = unix:/var/run/mysqld/mysqld.sock
336dbname = ${DBNAME}
337query = SELECT goto FROM spamalias
338 WHERE address='%s'
339 AND validity >= UNIX_TIMESTAMP()
340EOF
341
342sed -i '/User overrides/q' /opt/postfix/conf/main.cf
343echo >> /opt/postfix/conf/main.cf
344touch /opt/postfix/conf/extra.cf
345sed -i '/myhostname/d' /opt/postfix/conf/extra.cf
346echo -e "myhostname = ${MAILCOW_HOSTNAME}\n$(cat /opt/postfix/conf/extra.cf)" > /opt/postfix/conf/extra.cf
347
348cat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cf
349
350if [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then
351 echo "Creating dummy custom_transport.pcre"
352 touch /opt/postfix/conf/custom_transport.pcre
353fi
354
355if [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then
356 echo "Creating dummy custom_postscreen_whitelist.cidr"
357 echo '# Autogenerated by mailcow' > /opt/postfix/conf/custom_postscreen_whitelist.cidr
358fi
359
360# Fix SMTP last login on slaves
361sed -i "s/__REDIS_SLAVEOF_IP__/${REDIS_SLAVEOF_IP}/g" /usr/local/bin/smtpd_last_login.sh
362
363# Fix Postfix permissions
364chown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcre
365chmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcre
366chgrp -R postdrop /var/spool/postfix/public
367chgrp -R postdrop /var/spool/postfix/maildrop
368postfix set-permissions
369
370# Check Postfix configuration
371postconf -c /opt/postfix/conf > /dev/null
372
373if [[ $? != 0 ]]; then
374 echo "Postfix configuration error, refusing to start."
375 exit 1
376else
377 postfix -c /opt/postfix/conf start
378 sleep 126144000
379fi