Solved

Configuring SSL for Postfix without TLS support

Posted on 2009-07-07
3
462 Views
Last Modified: 2013-11-10
I am tying to configure Postfix server to answer email request on any specific port with SSL enable. So far I have gathere that we can configure postfix to use TLS support which requires email client to issue STATRTLS command.

Here are the master.cf of postfix that i am working with

smtp      inet  n       -       -       -       -       smtpd
submission inet n       -       -       -       -       smtpd
#  -o smtpd_enforce_tls=yes
#  -o smtpd_sasl_auth_enable=yes
#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
smtps     inet  n       -       -       -       -       smtpd
#  -o smtpd_tls_wrappermode=yes
  -o smtpd_sasl_auth_enable=yes
#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
#628      inet  n       -       -       -       -       qmqpd
pickup    fifo  n       -       -       60      1       pickup
cleanup   unix  n       -       -       -       0       cleanup
qmgr      fifo  n       -       n       300     1       qmgr
#qmgr     fifo  n       -       -       300     1       oqmgr
tlsmgr    unix  -       -       -       1000?   1       tlsmgr
rewrite   unix  -       -       -       -       -       trivial-rewrite
bounce    unix  -       -       -       -       0       bounce
defer     unix  -       -       -       -       0       bounce
trace     unix  -       -       -       -       0       bounce
verify    unix  -       -       -       -       1       verify
flush     unix  n       -       -       1000?   0       flush
proxymap  unix  -       -       n       -       -       proxymap
smtp      unix  -       -       -       -       -       smtp
# When relaying mail as backup MX, disable fallback_relay to avoid MX loops
relay     unix  -       -       -       -       -       smtp
0
Comment
Question by:binarykuki
  • 2
3 Comments
 
LVL 30

Expert Comment

by:Kerem ERSOY
ID: 24799277
Hi,

the settings you've got here is only to ensure that SMTPD to listen on port 587 (submission too). But in order it to establish TLS sessions you also need settins in your main.cf too. Here are the settings. The commented out commands are may be useful for you. Try them too if you need. You can find a tutorial at http://www.postfix.org. You also need to create a self-signed SSL certificate with OpenSSL and put the certificate in your tursted root certificate store if you don't want your email client to nag about it. Or just get a regular one it will cost you between 15 -30 USD.

If you have further questions don't hsitate to ask.

Cheers,
K
# TLS parameters

# smtp_use_tls = yes

# smtp_tls_security_level = may

smtpd_use_tls=yes

# smtpd_tls_security_level = may

# smtpd_tls_auth_only = no

smtp_tls_note_starttls_offer = yes

smtpd_tls_loglevel = 2

smtpd_tls_received_header = yes

smtpd_tls_session_cache_timeout = 3600s

tls_random_source = dev:/dev/urandom

smtpd_tls_cert_file=/usr/share/ssl/certs/postfix.crt

smtpd_tls_key_file=/usr/share/ssl/private/postfix.pem

#smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache

#smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache

# TLS end

Open in new window

0
 
LVL 2

Accepted Solution

by:
binarykuki earned 0 total points
ID: 25030059
This did not solve the issue. Email client still had to issue STARTLS command to get a secure channel.
0
 
LVL 30

Expert Comment

by:Kerem ERSOY
ID: 25057999
STARTLS is the required command to start TLS anyway. There's no other way to start encrypted communication. So this is obvious. This renders the way you close the question unacceptable.

I've corectly pointed you out how to enable the use of TLS that you had missing in oyour configuration but as you know there are standards for communication. You can not break them.

0

Featured Post

Promote certifications in your email signature

Has your company recently won an award or achieved a certification? They'll no doubt want to show it off. Email signature images used to promote certifications & awards can instantly establish credibility with a recipient and provide you with numerous benefits.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Email signatures have numerous marketing benefits. Here are 8 top reasons to turn your email signature into a marketing channel.
Resolve DNS query failed errors for Exchange
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now