瀏覽代碼

use mail as dkim selector. explicitely give keysize. add localhost to sasl exceptions.

Thomas Buck 5 年之前
父節點
當前提交
f17f41b536

+ 4
- 1
roles/mailserver/files/etc_rspamd_override.d_dkim_signing.conf 查看文件

@@ -2,4 +2,7 @@
2 2
 path = "/var/lib/rspamd/dkim/$domain.$selector.key";
3 3
   
4 4
 # Default selector to use
5
-selector = "default";
5
+selector = "mail";
6
+
7
+# Enable DKIM signing for alias sender addresses
8
+allow_username_mismatch = true;

+ 3
- 2
roles/mailserver/tasks/rspamd.yml 查看文件

@@ -60,11 +60,12 @@
60 60
     group=_rspamd
61 61
 
62 62
 - name: Generate DKIM keys
63
-  shell: rspamadm dkim_keygen -s default -d {{ item.name }} -k {{ item.name }}.default.key > {{ item.name }}.default.txt
63
+  shell: rspamadm dkim_keygen -b 1024 -s mail -d {{ item.name }} -k {{ item.name }}.mail.key > {{ item.name }}.mail.txt
64 64
   args:
65
-    creates: /var/lib/rspamd/dkim/{{ item.name }}.default.key
65
+    creates: /var/lib/rspamd/dkim/{{ item.name }}.mail.key
66 66
     chdir: /var/lib/rspamd/dkim/
67 67
   with_items: "{{ virtual_domains }}"
68
+  notify: restart rspamd
68 69
 
69 70
 - name: Start redis
70 71
   service:

+ 1
- 0
roles/mailserver/templates/etc_postfix_main.cf.j2 查看文件

@@ -84,6 +84,7 @@ alias_database = hash:/etc/aliases
84 84
 mydestination = localhost
85 85
 relayhost =
86 86
 mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 {{ ' '.join(friendly_networks) }}
87
+smtpd_sasl_exceptions_networks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 {{ ' '.join(friendly_networks) }}
87 88
 #mailbox_command = procmail -a "$EXTENSION"
88 89
 mailbox_size_limit = 0
89 90
 recipient_delimiter = +

Loading…
取消
儲存