Hi zusammen,
ich bin gerade dabei einen Mail-Server aufzusetzen. Mit Dovecot + Postfix ... Nur Postfix funktioniert nicht und ich finde keine Anhaltspunkte warum ?
systemctl status postfix.service ● postfix.service - Postfix Mail Transport Agent Loaded: loaded (/usr/lib/systemd/system/postfix.service; enabled; vendor preset: disabled) Active: active (running) since Mon 2018-01-22 22:12:07 CET; 11h ago Process: 14861 ExecStop=/usr/sbin/postfix stop (code=exited, status=0/SUCCESS) Process: 14878 ExecStart=/usr/sbin/postfix start (code=exited, status=0/SUCCESS) Process: 14876 ExecStartPre=/usr/libexec/postfix/chroot-update (code=exited, status=0/SUCCESS) Process: 14872 ExecStartPre=/usr/libexec/postfix/aliasesdb (code=exited, status=0/SUCCESS) Main PID: 14952 (master) CGroup: /system.slice/postfix.service ├─14952 /usr/libexec/postfix/master -w ├─18008 pickup -l -t unix -u -c └─18059 qmgr -l -t unix -u Jan 23 09:30:44 mail postfix/master[14952]: warning: /usr/libexec/postfix/smtp: bad command startup -- throttling Jan 23 09:31:45 mail postfix/smtp[23008]: fatal: Invalid TLS level "dane" Jan 23 09:31:46 mail postfix/master[14952]: warning: process /usr/libexec/postfix/smtp pid 23008 exit status 1 Jan 23 09:31:46 mail postfix/master[14952]: warning: /usr/libexec/postfix/smtp: bad command startup -- throttling Jan 23 09:32:46 mail postfix/smtp[23066]: fatal: Invalid TLS level "dane"
Aber:
postconf -n append_dot_mydomain = no biff = no bounce_queue_lifetime = 1h config_directory = /etc/postfix inet_interfaces = 127.0.0.1, ::1, 192.168.0.11 local_recipient_maps = $virtual_mailbox_maps mailbox_size_limit = 0 maximal_backoff_time = 15m maximal_queue_lifetime = 1h message_size_limit = 52428800 milter_default_action = accept milter_mail_macros = i {mail_addr} {client_addr} {client_name} {auth_authen} milter_protocol = 6 minimal_backoff_time = 5m mua_client_restrictions = permit_mynetworks,permit_sasl_authenticated,reject mua_relay_restrictions = reject_non_fqdn_recipient,reject_unknown_recipient_domain,permit_mynetworks,permit_sasl_authenticated,reject mua_sender_restrictions = permit_mynetworks,reject_non_fqdn_sender,reject_sender_login_mismatch,permit_sasl_authenticated,reject myhostname = gabel.net mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 non_smtpd_milters = inet:127.0.0.1:11332 postscreen_access_list = permit_mynetworks cidr:/etc/postfix/postscreen_access postscreen_blacklist_action = drop postscreen_dnsbl_action = drop postscreen_dnsbl_sites = ix.dnsbl.manitu.net*2 zen.spamhaus.org*2 postscreen_dnsbl_threshold = 2 postscreen_greet_action = drop queue_run_delay = 5m recipient_delimiter = + smtp_helo_name = smtp.gabel.net smtp_tls_CAfile = /etc/ssl/certs/ca-bundle.crt smtp_tls_ciphers = high smtp_tls_policy_maps = mysql:/etc/postfix/sql/tls-policy.cf smtp_tls_protocols = !SSLv2, !SSLv3 smtp_tls_security_level = dane smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache smtpd_client_restrictions = permit_mynetworks check_client_access hash:/etc/postfix/without_ptr reject_unknown_client_hostname smtpd_data_restrictions = reject_unauth_pipelining smtpd_helo_required = yes smtpd_helo_restrictions = permit_mynetworks reject_invalid_helo_hostname reject_non_fqdn_helo_hostname reject_unknown_helo_hostname smtpd_milters = inet:127.0.0.1:11332 smtpd_recipient_restrictions = check_recipient_access mysql:/etc/postfix/sql/recipient-access.cf smtpd_relay_restrictions = reject_non_fqdn_recipient reject_unknown_recipient_domain permit_mynetworks reject_unauth_destination smtpd_tls_cert_file = /etc/letsencrypt/live/mail.gabel.net/fullchain.pem smtpd_tls_ciphers = high smtpd_tls_key_file = /etc/letsencrypt/live/mail.gabel.net/privkey.pem smtpd_tls_protocols = !SSLv2, !SSLv3 smtpd_tls_security_level = may smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache tls_high_cipherlist = EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA256:EECDH:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!IDEA:!ECDSA:kEDH:CAMELLIA128-SHA:AES128-SHA virtual_alias_maps = mysql:/etc/postfix/sql/aliases.cf virtual_mailbox_domains = mysql:/etc/postfix/sql/domains.cf virtual_mailbox_maps = mysql:/etc/postfix/sql/accounts.cf virtual_transport = lmtp:unix:private/dovecot-lmtp postconf: warning: /etc/postfix/main.cf: unused parameter: smtp_dns_support_level=dnssec
Soweit mir bekannt muss "smtp_dns_support_level=dnssec" aber gesetzt sein damit "dane" überhaupt funktioniert.
Und laut Postfix Doku ist das hier völlig legitim ! "smtp_tls_security_level = dane" ...
Jemand 'ne Idee ?