
ã€ã³ã¹ããŒã«ããããµãŒããŒã·ã¹ãã ãçµ±åããããã°ã©ã ã®äžç°ãšããŠãã¡ãŒã«ãµãŒããŒã®åäœæãšããã¿ã¹ã¯ãçºçããŸããã ããã¥ã¢ã«ãšããã¥ã¢ã«ã®ææ
®æ·±ãç 究ã«ãããããªãå¥åŠãªäºå®ã瀺ãããŸãããã¡ãŒã©ãŒãå±éããããã®ãã¹ããã©ã¯ãã£ã¹ãšæ確ã«ä¿¡é Œã§ããã¬ã€ããé¡äŒŒç¹ã¯ã©ãã«ããããŸããã§ããã
ãã®ããã¥ã¢ã«ã¯ãäŒç€Ÿã®å
éšææžã«åºã¥ããŠæ®µéçã«èª¬æãããŠãããå®å
šã«æãããªåé¡ã«å¯ŸåŠããŠããŸãã ã°ã«ã¯æéãç¡é§ã«ããªããããããŸããããããã«ã¯ããŠããŠããããŸãã-ããã¥ã¢ã«ã¯å¯ãéãã§ãããã¡ãŒã©ãŒãå±éããããã«èŠã€ãã£ããã¹ãŠã®ããã¥ã¢ã«ããã¯ããŠã®æãæ¹ã®çµµã«äŒŒãŠããããã«ã®ã¿å
¬éãããŠããŸãã
ãã¹ãŠãæåã§åéããããªãå Žåã¯ããããã
iRedMailããã±ãŒãžãæé©ãªãªãã·ã§ã³ã§ãã PostfixãDovecotãApacheãMySQL / PostgreSQLãPolicydãAmavisãFail2banãRoundcubeãAwstatsã®åªãããã«ãã ç°¡åã«ã€ã³ã¹ããŒã«ã§ããå®å®ããŠåäœããŸããçŸãã管çããã«ïŒç¡æïŒãšéåžžã«çŸãã管çããã«ïŒææïŒãããããããã¯æ²æšãªPostfixAdminãšã¯æ¯èŒã§ããŸããã èäœåŽåã®ãã¡ã³ã¯èªã¿ç¶ããããšãã§ããŸãã
å€ããµãŒããŒã¯Gentooã®äžã§åäœããPostfix + VDAããCourierãšãã°ã®ããSASLã®ç±æ žçæãéã³ãæåã®èªèšŒæã«ã®ã¿mysqlã«æ¥ç¶ããããšã«ããŸããã å€æèšç»ã¯ãå
éšæšæºã®CentOSã«ç§»è¡ããããšã§ããã MTAãšMDAã®åœ¹å²ã¯ãPostfixãšDovecotã®æã«å²ãåœãŠãããŠãããè£å©ç ²ãšããŠAmavis + SpamAssassin + ClamAV + Postgrey + Fail2Banãå²ãåœãŠãããŠããŸãã ã¡ãã»ãŒãžã¯ãã¡ã€ã«ã«ä¿åãããã¢ã«ãŠã³ããšãã¡ã€ã³ã¯MySQLã«ä¿åãããŸãã ããã€ãã®ã¡ãŒã«ãã¡ã€ã³ããµãŒããŒäžã§ã¹ãã³ããä»®æ³ã¯ã©ãŒã¿ããµããŒããããŸãã
[*]è¿œå ã®ãªããžããª
ãæ¥ç¶ããŸãã
ãšãã«ãrpmforgeãcentaltãremiããããŸãã ã ãã¹ãŠãåžžã«å¿
èŠãªããã§ã¯ãªããyum-prioritiesãã©ã°ã€ã³ãã€ã³ã¹ããŒã«ã§ããŸãã ãŸãããŸãã¯ããªããç解ããã®ãé¢åãªå Žåã¯ãæã§ãããããªã³ãŸãã¯ãªãã«ããŸãã 次ã«ãã©ã®ãªããžããªãã€ã³ã¹ããŒã«ãããŠãããã説æããŸãã
[*] SELinuxã§ã®äœæ¥ã¯å¥ã®è³æãšããŠäŸ¡å€ããããŸãããããã£ãŠããã®èšäºã®ãã¬ãŒã ã¯ãŒã¯å
ã§ã¯ãselinuxãããå¯å®¹ã«ãããç¡å¹ã«ãããããããšãæ³å®ããŠããŸãã
[*] ntpãå¿ããªãã§ãã ããïŒ
yum install ntp ntpdate < ntp > chkconfig ntpd on && /etc/init.d/ntpd start
ããã«ãããDovecotã§çºçããå¯èœæ§ã®ãããæéã¯åŸæ»ãããŸããããšããåé¡ãåé¿ã§ããŸãã
/ etc / sysconfig / ntpdã§ã¹ã€ããã-Lã«å€æŽããŠãntpdããããã¯ãŒã¯ã§ãªãã¹ã³ããªãããã«ããããšãã§ããŸãã
[*]æºå段éã®æåŸã«ããã¹ããä¿é²ããäœæ¥ãä¿é²ãããŠãŒãã£ãªãã£ãé
眮ããŸãã
yum install wget mlocate bind-utils telnet mailx sharutils

ããŒã¿ããŒã¹ã«ã¯
ãRemiã®MySQL 5.5ã䜿çšã
ãŸã ã ãã¡ããmariadbã¯ã§ããŸãããMySQLããŸã çããŠãããã¡ã«ãäžèšã®ã¢ã»ã³ããªã¯å®å
šã«ç§ã«åã£ãŠããŸãã ããŒãžã§ã³ã¯éèŠã§ã Postfixã2.10ã«ã¢ããã°ã¬ãŒããããšãã圌ã¯æ°ããããŒãžã§ã³ãå¿
èŠã«ãªããããŒã¹ãã5.1ã眮ããšãCentALTããpostfixãæŽæ°ãããšMariaDBããã«ãããŸãã PgSQLã®æ¹ã奜ããªäºº-ãããå
¥ããŠãã ããã ãããã€ã¡ã³ãã¯å€ãããŸãããåŸçœ®æ§æãã¡ã€ã«ãå€æŽããã«äœ¿çšããããšãã§ããŸãã postgresqlèªäœã®æ§æãšããŒã¿ããŒã¹ã®äœæã®ã¿ãç°ãªããŸãã
ãããã«äœ¿ããããªãã·ã§ã³ã¯ãèµ·åã«é©ããŠããŸãïŒãããã«æ¡åŒµãããmy.cnfãäžã®ãªããžããªã«è¡šç€ºãããŸãïŒã åãååã®ããŒã¿ããŒã¹ãšããã«å¯Ÿãããã¹ãŠã®æš©éãæã€
postfixãŠãŒã¶ãŒãäœæããŸãã
CREATE USER postfix@localhost IDENTIFIED BY 'mypassword'; CREATE DATABASE postfix; GRANT ALL PRIVILEGES ON postfix.* TO postfix;
ClamAVã¯
ã¢ã³ããŠã€ã«ã¹ãšããŠæ©èœããŸãã ææ°ããŒãžã§ã³ãCentALTã«ããããšã¯æ³šç®ã«å€ããŸããã50 MBã®clamav-dbãããŠã³ããŒãããããšããŠæ»ãã§ããŸãããããã©ã³ã¯ãã€ã³ããããŠã³ããŒãããããããŸããã ãã®ããã
EPELãããã€ããŒããŒãžã§ã³ãå°ãªãããŠã倩æ°äºå ±ãè¡ããŸããã Clamã¯ãœã±ãããä»ããŠæ©èœããããã
/ etc / clamd.confã§æ¬¡ã®è¡
ã«ã€ããŠã³ã¡ã³ãããŸãã
ãŠã€ã«ã¹å¯ŸçããŒã¿ããŒã¹ã®æŽæ°ã¯èªåçã«æ¥ç¶ããã
freshclamãŠãŒãã£ãªãã£ã責任ãè² ããŸãã 察å¿ãããã¡ã€ã«ã
cron.dailyã«ããããšã確èªãããŠã€ã«ã¹å¯ŸçãµãŒãã¹ãå®è¡ããŸã
freshclam chkconfig clamd on && /etc/init.d/clamd start

Webã€ã³ã¿ãŒãã§ãŒã¹ããããã€ãããããªããã¯ã誰ã«ãšã£ãŠãå人çãªåé¡ã§ãã 移è¡ããã»ã¹ãå¶åŸ¡ããããã«å¿
èŠã§ããã ããŒã¿ããŒã¹æ§é ãäœæãããã¡ã€ã³ãã¡ãŒã«ããã¯ã¹ããšã€ãªã¢ã¹ãªã©ã管çããããã«å¿
èŠã«ãªãå ŽåããããŸãã ææ°ã®ã¿ã¹ã¯ã«ã€ããŠã¯ãã»ãšãã©ã®ããã¥ã¢ã«ãç©æ¥µçã«
PostfixAdminãææ¡ããŠã
ãŸãããç§ã¯åŒ·ããããå«ããŸãã ã¡ãŒã«ãµãŒããŒãã¡ãŒã«åŠçãåŠçããWebãµãŒããŒãWebã¢ããªã±ãŒã·ã§ã³ãä¿æããDBãµãŒããŒãããŒã¿ããŒã¹ãåŠçããå¿
èŠããããšããååã«åŸã£ãŠãåé¢ã®ååã«åŸãããšããå§ãããŸãã
Webãµãã·ã¹ãã ãå±éããããªã人ã®ããã«ãç§ã¯ããããå Žåã®ããã«ã¡ãŒã«ãµãŒããŒã®SQLããŒã¿ããŒã¹ãã³ããæ·»ä»ããŠããŸãã 䜿çšãããŠããªãæ©èœããããŸãïŒ
githubã®mysql_dump.sqlPostfixAdminãå¿
èŠãªå Žå-nginx
/ apache + phpãé
眮ã ãå®éã«ã¯
PostfixAdminèªäœã
é
眮ããŸãã ãŸã
ãäžèšã®ãã³ãã®äžã«å±éããããšã¯ã§ããŸãããäžéšã®ãäœåãªãããŒãã«ãæ§é ããåé€ãããŠããŸãã PostfixAdminã¯å°ããã¥ã¢ã³ã¹ãèšå®ããŸãã
config.inc.phpãç·šéããŸãã次ã®ãã©ã¡ãŒã¿ãŒã«æ³šæããŠãã ããã
ãã®åŸã
domain.tld / postfixadmin / setup.phpã«ã¢ã¯ã»ã¹ã㊠ããã¹ã¯ãŒããçæããã¹ãŒããŒç®¡çè
ã¢ã«ãŠã³ããäœæã§ããŸãã çæãããããã·ã¥ãconfig.inc.phpãã¡ã€ã«ã«è¿œå ããã¹ããŒã¿ã¹ãå€æŽããå¿
èŠããããŸãã
$CONF['configured'] = true; $CONF['setup_password'] = 't8h9i9s2i7s7m2y4l9o8g9i4n:a0n9d5p2a5s2s9w5o4r7d';
[ïŒ] Postfixadminèªäœã¯ãsetup.phpã®å®è¡æã«mysqlãšpostgresqlã®äž¡æ¹ã«åºæ¬æ§é ãäœæããŸãã 䜿çšããå Žåã¯ã空ã®ããŒã¹ã§ã€ã³ã¹ããŒã«ãå®è¡ããå¿
èŠããããŸãã

ããã©ã«ãæ§é å
šäœãpostfixããŒã¿ããŒã¹ã«äœæãããŠããããšã確èªããMTAãšMDAã®ã€ã³ã¹ããŒã«ã«é²ã¿ãŸãã
Postfixã¯ãã§ã«CentOSã«ãã³ãã«ãããŠããŸãããææ°ã®ãã®ã§ã¯ãããŸããã
CentALTããæŽæ°ãã
ããããDovecotãé
眮ããŸãã
yum update postfix yum install dovecot dovecot-mysql
ãã¹ãŠã®äž»èŠãªè¹è¶ã·ã¹ãã ã¯ãå¥ã®ãŠãŒã¶ãŒã®äžã§
/ var / vmailã®ãã¡ã€ã«ã§åäœããŸãã
groupadd -g 1000 vmail useradd -d /var/vmail/ -g 1000 -u 1000 vmail chown vmail:vmail /var/vmail
èªå·±çœ²åSSLãäœæããŸããã
mkdir /etc/postfix/certs openssl req -new -x509 -days 3650 -nodes -out /etc/postfix/certs/cert.pem -keyout /etc/postfix/certs/key.pem
æãåä»ãªãã«ãã¹ãããã¯ãPostfixãããŒã¿ããŒã¹ã§åäœãããããšã§ãã
mkdir /etc/postfix/mysql
ãã®ãã£ã¬ã¯ããªã«ã次ã®å
容ã®ãã¡ã€ã«ãäœæããŸãã
MySQLåŸçœ®æ§ærelay_domains.cf hosts = localhost user = postfix password = mypassword dbname = postfix query = SELECT domain FROM domain WHERE domain='%s' and backupmx = '1'
virtual_alias_domain_maps.cf hosts = localhost user = postfix password = mypassword dbname = postfix query = SELECT goto FROM alias,alias_domain WHERE alias_domain.alias_domain = '%d' and alias.address = CONCAT('%u', '@', alias_domain.target_domain) AND alias.active = 1
virtual_alias_maps.cf hosts = localhost user = postfix password = mypassword dbname = postfix query = SELECT goto FROM alias WHERE address='%s' AND active = '1'
virtual_mailbox_domains.cf hosts = localhost user = postfix password = mypassword dbname = postfix query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '0' AND active = '1'
virtual_mailbox_maps.cf hosts = localhost user = postfix password = mypassword dbname = postfix query = SELECT maildir FROM mailbox WHERE username='%s' AND active = '1'
ãã¡ã€ã«
/etc/postfix/main.cfãç·šéããæ°ãã«äœæããããã¡ã€ã«ã䜿çšããŠããŒã¿ããŒã¹ãæäœããããã«Postfixã«
æ瀺ããŸãã
åªããã¡ãŒã«ãµãŒããŒã¯ç¬èªã®ãµãŒããŒãã¹ãããããèŠç¥ãã¬äººãèªèšŒããŸãã èªèšŒãæ£ããæ©èœããããã«ããã«ã¯ãããŒã587ã§SMTPãµãŒãã¹ãããã«äžããŠéä¿¡ãå®è¡ããŸãã ããã©ã«ãã§èªèšŒä»ãã®smtpãµãŒããŒã«å
¥ããšãã«æ°ããã¢ã«ãŠã³ããäœæãããšãã®ã¹ããŒããã©ã³ã¯587ããŒããæäŸããŸãã mail.domain.tldãå
¥åããã ãã§ã¯äžååã§ããããšãã¯ã©ã€ã¢ã³ãã«èª¬æãããã¯ãããŸããããŸããããã€ãã®ããŒããç»é²ããå¿
èŠããããŸãã äžè¬çã«ã/
etc / postfix / master.cfã§ã
éä¿¡ãæ
åœããã»ã¯ã·ã§ã³
ãç·šéããŸãã
submission inet n - n - - smtpd -o syslog_name=postfix/submission -o smtpd_tls_wrappermode=no -o smtpd_tls_security_level=encrypt -o smtpd_sasl_auth_enable=yes -o smtpd_recipient_restrictions=permit_mynetworks,permit_sasl_authenticated,reject -o smtpd_relay_restrictions=permit_mynetworks,permit_sasl_authenticated,defer_unauth_destination -o milter_macro_daemon_name=ORIGINATING
[ïŒ] -oããŒã®åã®ã¹ããŒã¹ã«æ³šæããŠãã ãã-ãããããªããšãèšå®ã¯ç¡å¹ã«ãªããŸãã
ãšããããmaster.cfãèã«çœ®ããåŸã§æ»ã£ãŠ
/etc/postfix/main.cfã«é²ã¿ãŸã
soft_bounce = no myhostname = mail.domain.tld mydomain = domain.tld myorigin = $myhostname
ãããã¯ããã©ã«ãã®è¡ã®å€æŽã§ããã 次ã«ãèšå®ã®ããã€ãã®ã»ã¯ã·ã§ã³ãè¿œå ããŸãã éè€ã確èªãããã€ãã£ãæ§æããèŠã€ãã£ãå Žåã¯ããããåé€ããŸãã
/etc/postfix/main.cfãã¡ã€ã«ã®äžéšã«ããæ§é åãããã¯ã«èšå®ã
å
¥åããããšããå§ãããŸãã
[ïŒ]ãã©ãã¯ãªã¹ãã䜿çšãããã©ãã-ããªãã®éžæã
ããªããŒãçæããªãããã«ã察å¿ãã
reject_rbl_clientãã£ã¬ã¯ãã£ããã³ã¡ã³ãåããŸããã å€ãã®å Žåãã°ã¬ãŒãªã¹ãã¯ååã§ãããSpamhausãšãã®ä»ã®ããªã·ãŒã¯æ··åããªã·ãŒã«åŸããŸãããå®éã«ã¯ãæ£çŽãªäººãã¯ãã©ãã¯ãªã¹ãã«ç»é²ãããŠãããã誀æ€ç¥ã¯ãããŸããã§ããã ã©ãããŒãç§ã¯æšæž¬ããŸãã ãããã£ãŠãRBLãã£ã¬ã¯ãã£ããå«ãããã©ããã¯å¥œã¿ã®åé¡ã§ãã æ
å ±æäŸã®ç®çã§ãããã瀺ãããšèããŠãã ããã
[ïŒ]ãã©ã¡ãŒã¿ãŒã¯ã°ã«ãŒãã«åããããŸã-æ
éã«æ€èšããå¿
èŠã«å¿ããŠèª¿æŽããŠãã ããã ç·šéããã«ä»äººã®èšå®ãç²ç®çã«è²Œãä»ãããããæªããªãã·ã§ã³ã¯ãããŸããã
[ïŒ] Malamutã¯ãpermit_mynetworksãªãã·ã§ã³ãéåžžã«çãããå±éºã§ããããšãæ£ããææããŸããã ãããåé€ããèªèšŒããããŠãŒã¶ãŒã«ã®ã¿éä¿¡ãéä¿¡ã§ããããã«ããæ¹ãã¯ããã«è¯ãã§ãããã
[ïŒ] main.cfãã¡ã€ã«ã«
æ»ã ã
postgrey ã
amavisããã³
dovecotãè¿œå ããŸããã
ããã§ã¯
MDAã«é²ã¿ãŸãããã

ããã¯äœã§ããïŒ
- ããã¯ã¡ãŒã«é
ä¿¡ãšãŒãžã§ã³ããããŒã«ã«ãã©ã³ã¹ããŒãã§ã
- Postfixãæ©èœãããã€ãã£ãSASL
- ã¯ã©ãŒã¿ãæäœãã
- ãŠãŒã¶ãŒimapãšpop3ã®æäŸ
/etc/dovecot/dovecot.confã«å¯Ÿããããã€ãã®å€æŽïŒ
protocols = imap pop3 login_greeting = Hello there.
æ§æãã¡ã€ã«ã®æ®ãã®éšåã¯ã䟿å©ãªããã«ã³ã³ããŒãã³ãã«åå²ãããååã«ææžåãããŠããŸãã
10-auth.conf disable_plaintext_auth = no auth_realms = domain.tld domain2.tld auth_default_realm = domain.tld auth_mechanisms = plain login
10-logging.confåå¥ã®ãªã¹ãã¯ãããŸãã-å¿
èŠãªãªãã·ã§ã³ãèªç±ã«å«ããããšãã§ããŸãã
10-mail.confmail_location = maildirïŒ/ var / vmail /ïŒ
d /ïŒ
n
mail_uid = 1000
mail_gid = 1000
mail_plugins =ã¯ã©ãŒã¿
10-ssl.confssl =ã¯ã
ssl_cert = </etc/postfix/certs/cert.pem
ssl_key = </etc/postfix/certs/key.pem
15-lda.confquota_full_tempfail = no
lda_mailbox_autocreate = yes
lda_mailbox_autosubscribe = yes
ãããã³ã«lda {
mail_plugins = $ mail_plugins autocreate
}
20-imap.confãããã³ã«imap {
mail_plugins = $ mail_plugins autocreate quota imap_quota
}
auth-sql.conf.extpassdb {
ãã©ã€ããŒ= sql
args = /etc/dovecot/dovecot-sql.conf.ext
}
userdb {
ãã©ã€ããŒ= sql
args = /etc/dovecot/dovecot-sql.conf.ext
}
/etc/dovecot/dovecot-sql.conf.extãäœæããŸãã
dovecot-sql.conf.extãã©ã€ããŒ= mysql
connect = host = localhost dbname = postfix user = postfix password = mypassword
default_pass_scheme = MD5-CRYPT
user_query = SELECT '/ var / vmail /ïŒ
d /ïŒ
n' as homeã 'maildirïŒ/ var / vmail /ïŒ
d /ïŒ
n'as mailã1000 AS uidã1000 AS gidãconcatïŒ' *ïŒãã€ã= 'ãquotaïŒAS quota_rule FROM FROM mailbox WHERE username ='ïŒ
u 'AND active =' 1 '
password_query =ãŠãŒã¶ãŒãšããŠãŠãŒã¶ãŒåãéžæããã¹ã¯ãŒããuserdb_homeãšããŠã/ var / vmail /ïŒ
d /ïŒ
nããuserdb_mailãšããŠãmaildirïŒ/ var / vmail /ïŒ
d /ïŒ
nããuserdb_uidãšããŠ1000ãuserdb_gidãšããŠ1000ãconcat ïŒ '*ïŒãã€ã='ãã¯ã©ãŒã¿ïŒAS userdb_quota_rule FROM FROMã¡ãŒã«ããã¯ã¹WHER
EãŠãŒã¶ãŒå= 'ïŒ
u' ANDã¢ã¯ãã£ã= '1'
Dovecot㧠Postfixã®åéãäœããŸãããã
/etc/postfix/main.cfã«2ã€ã®ã»ã¯ã·ã§ã³ãè¿œå ããŸãã
ãŸããDovecotãã¡ãŒã«ã®é
ä¿¡ã«é¢äžããŠãããšããäºå®ã®åã«
Postfixãé
眮ããŸãã
/etc/postfix/master.cf㧠ïŒ
次ã«ãã¯ã©ãŒã¿ã®è¶
éã«é¢ããèŠåã¹ã¯ãªãã
/usr/local/bin/quota-warning.shãæ£ããå®è¡ãããããšã確èªããå¿
èŠããããŸãã ç§ã®å ŽåãCentOSã§ã¯ããã®ãã¹ã誀ã£ãŠæå®ãããŠãããæåã§ç·šéããå¿
èŠããããŸããã ãããã«ããŠããããã©ã«ãã§
postmaster@domain.tldãšããŠæå®ãããŠããéä¿¡è
ã¢ãã¬ã¹ãç·šéããŠãæåã§ä¿®æ£ããŸãã ç®çã®ãã€ããªãèŠã€ãã
updatedb locate dovecot-lda chmod 755 /usr/local/bin/quota-warning.sh
ãŸãã/
usr / local / bin / quota-warning.shèªäœã®ãã¹ãä¿®æ£ããå¿
èŠã«å¿ããŠããæå³ã®ããããããŒãã¹ã¯ãªããã«è¿œå ããŸãã
Amavisã¯ã¡ãŒã«ãšãŒãžã§ã³ããšã¢ã³ããŠã€ã«ã¹ããã³ã¢ã³ãã¹ãã ã·ã¹ãã ã®éã«ãã
ç§ãã¡ã®ããã«
æ©èœãããããspamdãåå¥ã«å®è¡ããå¿
èŠã¯ãããŸãã-å¿
èŠã«å¿ããŠããŒããããã¢ãžã¥ãŒã«ãšããŠæ©èœããŸãã SAãææ°ã®ç¶æ
ã«ä¿ã€ã«ã¯ããã€ãã£ãã®
sa-updateãŠãŒãã£ãªãã£ã䜿çšãããŸãã
etc / cron.dã«ãã¢ããããŒã¿ãŒã®ã¹ã±ãžã¥ãŒã«ãããèµ·åãå«ã
sa-updateãã¡ã€ã«ãããããšã確èªããŸãã
[ïŒ] rpmforge-extrasãã
spamassassin 3.3.2ãã€ã³ã¹ããŒã«ããŠ
ãã ããã EPELããŒãžã§ã³3.3.1ããã®çªåºã¯ãsa-updateã«å
倩çãªæ¬ é¥ããããŸãã ææ°ããŒãžã§ã³
3.3.2ã¯ãã§ã«ãã®åé¡ãã解æŸãããŠãããæ£ããæŽæ°ãããŠããŸã
yum install spamassassin amavisd-new
/etc/mail/spamassassin/local.cfãå°ãä¿®æ£ã
ãŸãlocal.cf required_hits 6 report_safe 0 rewrite_header Subject ***SPAM***
ãããã
Amavisæ§æãã¡ã€ã«ã¯ãç§ãè³è³ããDovecotã®æ§æãšã¯æ£å察ã§ãã ããã¯éåžžã®perlã¹ã¯ãªããã§ããããã©ãŒããããäžååã§ãã å€æŽãå ããã ãã§ãããã¡ã€ã«ã®ååã.plã«å€æŽããæ§æã匷調ããŠç·šéããŸãã ç掻ãå°ã楜ã«ãªããŸãã
次ã«ãã¡ãŒã«ã®ãã§ãã¯ã«
Amavisã䜿çšããŠããããšã
Postfixã«ç¥ãããŸãã é©åãªãããã¯ã
/etc/postfix/master.cfã«è¿œå ããŸã
/etc/postfix/main.cfã«è¿œå ããŸã
ãµãŒãã¹ãäœæããŸãã
chkconfig amavisd on && /etc/init.d/amavisd start /etc/init.d/postfix restart telnet 127.0.0.1 10024

ã°ã¬ãŒãªã¹ãã®å¹çã¯è€æ°åèšè¿°ãããŠãããããéãã«
yum install postgrey
è¿œå ã®èšå®ã¯å¿
èŠãããŸãã-/
etc/postfix/main.cfã§èšå®ããŸã
smtpd_recipient_restrictions = ... reject_unauth_destination, check_policy_service unix:/var/spool/postfix/postgrey/socket, ...
[ïŒ] check_policy_serviceãã£ã¬ã¯ãã£ãã¯ãreject_unauth_destinationã®åŸã«æå®ããå¿
èŠããããŸãã
ã¹ãã£ã³ãããµãŒããŒãé€å€ããå¿
èŠãããå Žåã¯ã
/etc/postfix/postgrey_whitelist_clients.localãç·šéããããŒã«ã«ãµãŒããŒããç¹å®ã®ã¡ãŒã«ã¢ãã¬ã¹ãã¹ãã£ã³ããé€å€ããã«ã¯ã
postgrey_whitelist_recipientsãç·šéã
ãŸã ã å
æ¬çãªæ
å ±ã¯wikiã§å
¥æã§ããŸãïŒ
wiki.centos.org/HowTos/postgreyFail2banã«ã€ããŠãå¥ã®è°è«ã ãã®æå¹æ§ãå®èšŒããããã«ããŠãŒãã£ãªãã£ãã€ã³ã¹ããŒã«ããååŸã®ã¡ãŒã«ãµãŒããŒã®çµ±èšã瀺ãåçã瀺ããŸãã ãã£ãŒãã®èµ€ãç·ã¯ããªãŒãã³ãªã¬ãŒãæ€çŽ¢ããäžæ£ãªã¹ã¯ã€ãã§ãã ãã¡ãããæåã¯éåããŠããã倧ããªè² è·ã«ã¯ãªããŸãããããªããã®ãŽããèãã®ã§ããããã ãããã£ãŠã3ã€ã®ã«ãŒã«ã§fail2banãã€ã³ã¹ããŒã«ãããšãã°ã©ãã®å€èŠ³ã倧å¹
ã«æ¹åãããŸãã
yum install fail2ban
ã¡ãŒã«ãµãŒããŒ/etc/fail2ban/jail.confã®ã«ãŒã« SSHãå
éšãããã¯ãŒã¯ã«å¯ŸããŠã®ã¿éããŠããå Žåãæåã®ã«ãŒã«ãåé€ã§ããŸãã ãŸã ãè¿œå ã®ãžã§ã¹ãã£ãŒã¯ãããŸãã-ã«ãŒã«ã¯ãã®ãŸãŸäœ¿çšã§ããŸãã smtpã®ãã«ãŒããã©ãŒã¹ä¿è·ãæãåºãããŠããã
urbainã«æè¬ããŸãã
chkconfig fail2ban on && /etc/init.d/fail2ban start
Dovecotã«
autocreateãã©ã°ã€ã³ã
å«ããã®ã§ããã¡ã€ã³ãšã¡ãŒã«ããã¯ã¹ãäœæããããã«ãPostfixadminãä»ããŠããŸãã¯ã³ã³ãœãŒã«ã§INSERT INTOãå®è¡ããããšã«ãããããããããŒã¿ããŒã¹ã«å
¥åããã ãã§ãã æåã®èªèšŒãŸãã¯åä¿¡ããæåã®æåã§ããã£ã¬ã¯ããªæ§é ãèªåçã«äœæãããŸãã
ããŸããŸãªããŒãºã§pop3ãimapãsmtpããã¹ããã- POP3ãã°ã€ã³ã®ãã¹ã
telnet 127.0.0.1 110 user test pass testpassword UIDL
- IMAPãã°ã€ã³ã®ãã¹ã
telnet 127.0.0.1 143 1 LOGIN test testpassword 1 SELECT INBOX
- èªèšŒãªãã§SMTPããã¹ããã
telnet 127.0.0.1 25
- SSLã䜿çšããã«èªèšŒã䜿çšããŠSMTPã
ãã¹ãããAUTH LOGINã®åŸã«é 次éä¿¡ãããbase64ãã¹ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããããªã³ãŒãããŸããã³ãŒã334ã®çä¿¡èŠä»¶ãbase64ã§ãšã³ã³ãŒããããŸãã
telnet 127.0.0.1 25
- SSLã䜿çšããSMTPã®ãã¹ã
ãŠã€ã«ã¹å¯Ÿçä¿è·ã®ãã¹ã- amavis . , . , . :
cd /usr/share/doc/amavisd-new-2.8.0/test-messages perl -pe 's/./chr(ord($&)^255)/sge' <sample.tar.gz.compl | zcat | tar xvf -
- :
sendmail -i your-address@example.com < sample-virus-simple.txt sendmail -i your-address@example.com < sample-spam-GTUBE-junk.txt
( /var/log/maillog). , verbose /etc/dovecot/conf.d/10-logging.conf log-level /etc/amavisd/amavisd.conf .
ããã§ãã³ã³ãã¥ãŒã¿ãŒã®é»æºããªãã«ããŠãã¡ãŒã«ãµãŒããŒã§ã®äœæ¥ãéå§ãããããã¡ã€ã³ããŠãŒã¶ãŒããšã€ãªã¢ã¹ãªã©ãäœæãããã§ããŸããæåŸã«ãããã€ãã®äžè¬çãªãã€ã³ããšæšå¥šäºé
ïŒ- æ§æãã¡ã€ã«ãæäœããã«ã¯ãgitã䜿çšããŠã/ etcãã£ã¬ã¯ããªãŒããªããžããªãŒã«ããŸãããã®ã¢ãããŒãã«ãããæè¡éšéã®åŸæ¥å¡éã§æ§æãç°¡åã«ãããããšãã§ããæ§æããã»ã¹ã段éçã«å¶åŸ¡ã§ããŸãããã®ãããªçµ±åãããã·ã¹ãã ãã¡ãŒã«ãµãŒããŒãšããŠäœ¿çšããå Žåããã®æ¹æ³ã¯éåžžã«äŸ¿å©ã§ãã
- c courier dovecot. , . wiki2.dovecot.org/Migration/Courier . POP3 UIDL , . , .
find . -name "courier*" -delete
- iptables â .
- CentOS rsyslog , syslog-ng EPEL. , syslog-ng â .
- vacation , dovecot Sieve «» . â « ». .
æ§æãã¡ã€ã«ã®ã»ãŒå®å
šãªã¢ã»ã³ããªãgithubã«é
眮ããŠãå¿
èŠã«å¿ããŠãæ§æãã¡ã€ã«ã«åå²ããŠã§ã¯ãªãå
šäœãšããŠã¢ã¯ã»ã¹ã§ããããã«ããŸããããã®èšäºã§ã¯ããã¹ãŠã®ã·ã¹ãã ã®åã段éçãªã»ããã¢ãããã·ãã¥ã¬ãŒãããŠããã¡ã€ã«ãåŸã
ã«ç·šéããŸãããã»ãšãã©ã®ããã¥ã¢ã«ã§ã¯ããã¡ã€ã«ã¯ããã«æäŸãããèªè
ã¯èªåãäœããã©ããŒããŠããŠã©ã®ããã«ãªã³ã¯ãããŠããããç¥ãããšãã§ããŸããã§ãããç§ã¯ãããåãé€ãã段éçãªã»ããã¢ãããèŠããããšããŸãããããããããã¯èª°ãã«åœ¹ç«ã€ã§ãããããããã€ã³ã¹ããŒã«ã®åæ段éã§ããããšãããäžåºŠåŒ·èª¿ããŸããã¡ãŒã«ãµãŒããŒã§éåžžã«æãŸããç£èŠæ¥ç¶ãèæ
®ããªããŠããäœæ¥ãçµäºããããšã¯ã§ããŸãããã¹ãã 察çããªã·ãŒã培åºçã«èª¿æŽããå¿
èŠããããŸããè¿œå ã®ãªã¬ãŒã䜿çšããäºå®ãããå Žåã¯ãèŠæ±ã確å®ããå¿
èŠããããŸããå¶éãªã©ã®ãã©ã¡ãŒã¿ã確èªããå¿
èŠããããŸãããããã倧èŠæš¡ãªã¬ã€ããäœæããéã®ãã®ãã¹ããã³ã®æ®ãã®éšåã¯å®å
šã§ãããšèããããšãã§ããŸããã¡ãŒã«ãµãŒããŒã§ã¯ãªãããåå¿è
ãåãã§ã¯ãªãè³æãå
¬éããäºå®ã§ãããç«ã«ã€ããŠãã¬ãŒãã³ã°ããããšã«ããŸããã誰ããã®å Žæãèªã¿ãŸããã...ããŒãš...ããªãã®å¿èãããããŸããã§ãããåºçç©ãããã€ãã®éšåã«åããã®ã¯äžé©åã ãšæãããŸããã