
Configuring Mail Securely with Postfix, POP3, and IMAP
|
27
get some sense of where you’re going by looking back at the paragraphs that laid out
our tasks at the beginning of this section.
The postconf command lives in the /usr/sbin directory. You’ll use it to print the value
of a Postfix parameter in the Postfix main.cf configuration file.
Since you already installed Postfix and Debian set it up as a service, you need to tell
Postfix what to do about secure authentication. Use the following commands:
# postconf -e 'smtpd_sasl_local_domain ='
# postconf -e 'smtpd_sasl_auth_enable = yes'
# postconf -e 'smtpd_sasl_security_options = noanonymous'
# postconf -e 'broken_sasl_auth_clients = yes'
# postconf -e 'smtpd_recipient_restrictions = \
permit_sasl_authenticated,permit_mynetworks,reject_unauth_destination'
# postconf -e 'inet_interfaces = all'
These commands write text to the smtpd.conf file:
# echo 'pwcheck_method: saslauthd' >> /etc/postfix/sasl/smtpd.conf
# echo 'mech_list: plain login' >> /etc/postfix/sasl/smtpd.conf
Now create a directory for your SSL certificates and generate both the certificates and
the encryption keys:
# mkdir /etc/postfix/ssl
# cd /etc/postfix/ssl/
# openssl genrsa -des3 -rand /etc/hosts -out smtpd.key 1024
293 semi-random bytes loaded
Generating RSA private key, 1024 bit long modulus
..........................................++++++
.......................................++++++ ...