Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
postfix:optimized-configuration [2010/03/08 13:53]
greebo
postfix:optimized-configuration [2013/09/12 15:40] (current)
zagi
Line 1: Line 1:
 **main.cf** **main.cf**
 <code> <code>
-#soft_bounce = yes+#soft_bounce = yes
 smtpd_banner = $myhostname ESMTP (NO UCE)(NO UBE) http://www.rfc.net/rfc2821.html smtpd_banner = $myhostname ESMTP (NO UCE)(NO UBE) http://www.rfc.net/rfc2821.html
 biff = no biff = no
Line 9: Line 9:
  
 # Uncomment the next line to generate "delayed mail" warnings # Uncomment the next line to generate "delayed mail" warnings
-#delay_warning_time = 3h+#delay_warning_time = 3h
  
 readme_directory = no readme_directory = no
Line 46: Line 46:
 <code> <code>
 # TLS parameters # TLS parameters
-tls_random_source dev:/dev/urandom +smtp_tls_security_level=may 
-smtpd_tls_cert_file=/etc/ssl/certs/server.crt +#obsoletes smtp_use_tls smtp_enforce_tls  smtp_tls_enforce_peername 
-smtpd_tls_key_file=/etc/ssl/private/server.key+smtp_tls_note_starttls_offer=yes 
 + 
 +smtp_tls_CApath = /etc/ssl/certs 
 + 
 +smtpd_tls_security_level=may 
 +#obsoletes  smtpd_use_tls smtpd_enforce_tls 
 + 
 +smtp_tls_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem 
 +smtp_tls_key_file=/etc/ssl/private/ssl-cert-snakeoil.key 
 + 
 +smtpd_tls_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem 
 +smtpd_tls_key_file=/etc/ssl/private/ssl-cert-snakeoil.key 
 + 
 +# debuging tls 
 +smtp_tls_loglevel = 0 
 +smtpd_tls_loglevel = 0 
 + 
 +smtpd_tls_auth_only=yes 
 +smtpd_tls_received_header=yes 
 smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
 smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
  
-###smtp_tls_policy_maps hash:/etc/postfix/tls_policy +tls_random_source dev:/dev/urandom
-smtp_tls_security_level = may +
-smtpd_tls_security_level = may+
  
 +###smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
 ###smtpd_tls_ask_ccert = yes ###smtpd_tls_ask_ccert = yes
 ###smtp_tls_verify_cert_match = hostname, nexthop, dot-nexthop ###smtp_tls_verify_cert_match = hostname, nexthop, dot-nexthop
- 
-# debuging tls 
-# smtpd_tls_loglevel = 3 
- 
-#obsolete#smtpd_use_tls=yes 
  
 smtp_tls_note_starttls_offer = yes smtp_tls_note_starttls_offer = yes
Line 74: Line 87:
 smtpd_sasl_exceptions_networks = $mynetworks smtpd_sasl_exceptions_networks = $mynetworks
  
-smtpd_tls_auth_only = yes 
-smtpd_tls_received_header = yes 
  
  smtpd_sasl_authenticated_header = no  smtpd_sasl_authenticated_header = no
Line 177: Line 188:
 address_verify_sender = postar address_verify_sender = postar
 address_verify_map = btree:$(data_directory)/verify address_verify_map = btree:$(data_directory)/verify
 +
  
 home_mailbox = Maildir/ home_mailbox = Maildir/
Line 259: Line 271:
  
 **/etc/postfix/bogon_networks** **/etc/postfix/bogon_networks**
- +<code>
 # http://www.cymru.com/Documents/bogon-bn-agg.txt # http://www.cymru.com/Documents/bogon-bn-agg.txt
 0.0.0.0/      REJECT IP address of MX host is a bogus address 0.0.0.0/      REJECT IP address of MX host is a bogus address
Line 288: Line 300:
 223.0.0.0/    REJECT IP address of MX host is a bogus address 223.0.0.0/    REJECT IP address of MX host is a bogus address
 224.0.0.0/    REJECT IP address of MX host is a bogus address 224.0.0.0/    REJECT IP address of MX host is a bogus address
 +</code>
  
 **/etc/postfix/discard_ehelo_map** **/etc/postfix/discard_ehelo_map**
postfix/optimized-configuration.1268052780.txt.gz · Last modified: 2010/03/08 13:53 by greebo
CC Attribution-Share Alike 4.0 International
Driven by DokuWiki Recent changes RSS feed Valid CSS Valid XHTML 1.0 ipv6 ready