Install the following packages:
- cyrus-sasl
- cyrus-sasl-crammd5
- cyrus-sasl-digestmd5
- cyrus-sasl-gssapi
- cyrus-sasl-otp
- cyrus-sasl-plain
- cyrus-sasl-saslauthd
Start the saslauthd service:
- chkconfig --add saslauthd
- /etc/init.d/saslauthd start
Now create our certificates for secure authentication:
- mkdir /etc/postfix/ssl
- cd /etc/postfix/ssl/
- openssl genrsa -des3 -rand /etc/hosts -out smtpd.key 1024
- chmod 600 smtpd.key
- openssl req -new -key smtpd.key -out smtpd.csr
- openssl x509 -req -days 3650 -in smtpd.csr -signkey smtpd.key -out smtpd.crt
- openssl rsa -in smtpd.key -out smtpd.key.unencrypted
- mv -f smtpd.key.unencrypted smtpd.key
- openssl req -new -x509 -extensions v3_ca -keyout cakey.pem -out cacert.pem -days 3650
Setup postfix, the easiest way to do this is with the postconf command:
- postconf -e 'mydomain = example.com'
- postconf -e 'myhostname = server1.$mydomain'
- postconf -e 'mynetworks = 127.0.0.0/8'
- postconf -e 'smtpd_sasl_local_domain ='
- postconf -e 'smtpd_sasl_auth_enable = yes'
- postconf -e 'smtpd_sasl_security_options = noanonymous'
- postconf -e 'broken_sasl_auth_clients = yes'
- postconf -e 'smtpd_recipient_restrictions = permit_sasl_authenticated,permit_mynetworks,check_relay_domains'
- postconf -e 'inet_interfaces = all'
- postconf -e 'alias_maps = hash:/etc/aliases'
- postconf -e 'smtpd_tls_auth_only = no'
- postconf -e 'smtp_use_tls = yes'
- postconf -e 'smtpd_use_tls = yes'
- postconf -e 'smtp_tls_note_starttls_offer = yes'
- postconf -e 'smtpd_tls_key_file = /etc/postfix/ssl/smtpd.key'
- postconf -e 'smtpd_tls_cert_file = /etc/postfix/ssl/smtpd.crt'
- postconf -e 'smtpd_tls_CAfile = /etc/postfix/ssl/cacert.pem'
- postconf -e 'smtpd_tls_loglevel = 1'
- postconf -e 'smtpd_tls_received_header = yes'
- postconf -e 'smtpd_tls_session_cache_timeout = 3600s'
- postconf -e 'tls_random_source = dev:/dev/urandom'
To Enable TLS edit the /etc/postfix/master.cf file and uncomment the following line:
Use Yast->Security & Users->Firewall and Allow the following services:
- IMAP
- IMAPS
- Mail Server
- POP3
- POP3S