Solved

Configuring SSL for Postfix without TLS support

Posted on 2009-07-07
3
456 Views
Last Modified: 2013-11-10
I am tying to configure Postfix server to answer email request on any specific port with SSL enable. So far I have gathere that we can configure postfix to use TLS support which requires email client to issue STATRTLS command.

Here are the master.cf of postfix that i am working with

smtp      inet  n       -       -       -       -       smtpd
submission inet n       -       -       -       -       smtpd
#  -o smtpd_enforce_tls=yes
#  -o smtpd_sasl_auth_enable=yes
#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
smtps     inet  n       -       -       -       -       smtpd
#  -o smtpd_tls_wrappermode=yes
  -o smtpd_sasl_auth_enable=yes
#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
#628      inet  n       -       -       -       -       qmqpd
pickup    fifo  n       -       -       60      1       pickup
cleanup   unix  n       -       -       -       0       cleanup
qmgr      fifo  n       -       n       300     1       qmgr
#qmgr     fifo  n       -       -       300     1       oqmgr
tlsmgr    unix  -       -       -       1000?   1       tlsmgr
rewrite   unix  -       -       -       -       -       trivial-rewrite
bounce    unix  -       -       -       -       0       bounce
defer     unix  -       -       -       -       0       bounce
trace     unix  -       -       -       -       0       bounce
verify    unix  -       -       -       -       1       verify
flush     unix  n       -       -       1000?   0       flush
proxymap  unix  -       -       n       -       -       proxymap
smtp      unix  -       -       -       -       -       smtp
# When relaying mail as backup MX, disable fallback_relay to avoid MX loops
relay     unix  -       -       -       -       -       smtp
0
Comment
Question by:binarykuki
  • 2
3 Comments
 
LVL 30

Expert Comment

by:Kerem ERSOY
ID: 24799277
Hi,

the settings you've got here is only to ensure that SMTPD to listen on port 587 (submission too). But in order it to establish TLS sessions you also need settins in your main.cf too. Here are the settings. The commented out commands are may be useful for you. Try them too if you need. You can find a tutorial at http://www.postfix.org. You also need to create a self-signed SSL certificate with OpenSSL and put the certificate in your tursted root certificate store if you don't want your email client to nag about it. Or just get a regular one it will cost you between 15 -30 USD.

If you have further questions don't hsitate to ask.

Cheers,
K
# TLS parameters

# smtp_use_tls = yes

# smtp_tls_security_level = may

smtpd_use_tls=yes

# smtpd_tls_security_level = may

# smtpd_tls_auth_only = no

smtp_tls_note_starttls_offer = yes

smtpd_tls_loglevel = 2

smtpd_tls_received_header = yes

smtpd_tls_session_cache_timeout = 3600s

tls_random_source = dev:/dev/urandom

smtpd_tls_cert_file=/usr/share/ssl/certs/postfix.crt

smtpd_tls_key_file=/usr/share/ssl/private/postfix.pem

#smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache

#smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache

# TLS end

Open in new window

0
 
LVL 2

Accepted Solution

by:
binarykuki earned 0 total points
ID: 25030059
This did not solve the issue. Email client still had to issue STARTLS command to get a secure channel.
0
 
LVL 30

Expert Comment

by:Kerem ERSOY
ID: 25057999
STARTLS is the required command to start TLS anyway. There's no other way to start encrypted communication. So this is obvious. This renders the way you close the question unacceptable.

I've corectly pointed you out how to enable the use of TLS that you had missing in oyour configuration but as you know there are standards for communication. You can not break them.

0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

New-MailboxSearch Powershell Command and step by step approach to Search and Extract Emails form Exchange 2013 Journaling server.
Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now