Qmail Server with Courier IMAP with Master/Slave LDAP for MiraExim
Ensure rpmforge and epel repos are enabled.
- Switch off SELinux
- Flush Iptables rules
Create directory for downloading required packages
- mkdir /downloads
- cd /downloads
Download all required packages for qmail-ldap installation
- wget http://www.qmailrocks.org/downloads/qmailrocks.tar.gz
- wget http://cr.yp.to/software/qmail-1.03.tar.gz
- wget http://cr.yp.to/ucspi-tcp/ucspi-tcp-0.88.tar.gz
- wget http://www.qmailrocks.org/downloads/patches/ucspi-tcp-0.88.errno.patch
- wget http://cr.yp.to/daemontools/daemontools-0.76.tar.gz
- wget http://www.qmail.org/moni.csi.hu/pub/glibc-2.3.1/daemontools-0.76.errno.patch
- wget http://www.nrg4u.com/qmail/qmail-ldap-1.03-20060201.patch.gz
- wget http://lifewithqmail.org/inst_check
- wget https://sourceforge.net/projects/courier/files/maildrop/2.5.4/maildrop-2.5.4.tar.bz2/download --no-check-certificate
- wget http://prdownloads.sourceforge.net/qmail-scanner/qmail-scanner-2.08.tgz?download
- wget http://www.qmailrocks.org/downloads/scripts/finalize/qmailctl
- wget http://packages.sw.be/rpmforge-release/rpmforge-release-0.5.2-2.el5.rf.i386.rpm
Extract all packages :
- tar -xvzf qmailrocks.tar.gz
- tar -xvzf squirrelmail-webmail-1.4.22.tar.gz
- tar -xvjf maildrop-2.5.4.tar.bz2
- tar -xvzf qmail-scanner-2.08.tgz
- tar -xvzf qmailrocks/autorespond-2.0.5.tar.gz
Install all required packages before qmail-ldap installation
yum install vim-enhanced httpd php* php-ldap perl gcc* gcc-c++ gcc44* openssl openssl-devel kernel-headers openssl-devel kernel-headers patch pcre* db4* openldap* glibc* zlib* glib* gdbm* php
Create initial qmail
- mkdir /usr/src/qmail
Creating all needed users and groups
- groupadd nofiles
- useradd -g nofiles -d /var/qmail/alias -s /sbin/nologin -p'*' alias
- useradd -g nofiles -d /var/qmail -s /sbin/nologin -p'*' qmaild
- useradd -g nofiles -d /var/qmail -s /sbin/nologin -p'*' qmaill
- useradd -g nofiles -d /var/qmail -s /sbin/nologin -p'*' qmailp
- groupadd qmail
- useradd -g qmail -d /var/qmail -s /sbin/nologin -p'*' qmailq
- useradd -g qmail -d /var/qmail -s /sbin/nologin -p'*' qmailr
- useradd -g qmail -d /var/qmail -s /sbin/nologin -p'*' qmails
- groupadd vmail
- useradd -g vmail -s /bin/true vmail
Unpack qmail and apply the qmail-ldap patch
- cd /usr/src/qmail
- tar -xvzf /downloads/qmail-1.03.tar.gz
- gunzip /downloads/qmail-ldap-1.03-20060201.patch.gz
- cd qmail-1.03
- patch -p1 < /downloads/qmail-ldap-1.03-20060201.patch
Make changes on "Makefile" to qmail work properly with ldap
Make these entries :
LDAPFLAGS=-DQLDAP_CLUSTER -DEXTERNAL_TODO -DDASH_EXT -DDATA_COMPRESS -DQMQP_COMPRESS -DSMTPEXECCHECK -DALTQUEUE
# ZLIB needed for -DDATA_COMPRESS and -DQMQP_COMPRESS
ZLIB=-lz
# to enable the auto-maildir-make feature
MDIRMAKE=-DAUTOMAILDIRMAKE
# to enable the auto-homedir-make feature
HDIRMAKE=-DAUTOHOMEDIRMAKE
# on most systems we need this to make auth_pop and auth_imap
SHADOWLIBS=-lcrypt
# to enable the possibility to log and debug imap and pop
DEBUG=-DDEBUG
- make man
- make setup check
Creating qmail control files
- cd /var/qmail/control
- echo 100 > concurrencyincoming
- echo 255 > concurrencyremote
- echo ./Maildir/ > defaultdelivery
- echo /var/qmail/bin/dirmaker > dirmaker
- echo 0 > ldapcluster
- id -g vmail > ldapgid
- echo /home/vmail > ldapmessagestore
- echo qmailUser > ldapobjectclass
- echo secret > ldappassword
- echo 127.0.0.1 > ldapserver
- id -u vmail > ldapuid
- echo 80000000 > qmail-smtpd-softlimit
- echo 80000000 > qmail-pop3d-softlimit
- echo 3 > qmail-pop3d-loglevel
- echo 3 > qmail-start-loglevel
- echo groupvama.com > defaultdomain
- echo dc=groupvama,dc=com > ldapbasedn
- echo cn=Manager,dc=groupvama,dc=com > ldaplogin
- echo mail.groupvama.com > me
- echo groupvama.com > rcpthosts
- echo miraexim.com > rcpthosts
- echo vogueserv.com > rcpthosts
- ln -s rcpthosts locals
Unpacking ucspi-tcpi and apply the error patch
- cd /usr/src/qmail
- tar -xvzf /downloads/ucspi-tcp-0.88.tar.gz
- cd ucspi-tcp-0.88
- patch < /downloads/ucspi-tcp-0.88.errno.patch
- make && make setup check
Unpacking daemontools and apply daemontools-error patch
- mkdir -p /package
- chmod 1755 /package
- cd /package
- tar -xvzf /downloads/daemontools-0.76.tar.gz
- cd /package/admin/daemontools-0.76/src
- patch < /downloads/daemontools-0.76.errno.patch
- cd /package/admin/daemontools-0.76
- package/install
Creating the supervise script directories
- mkdir /var/qmail/supervise
- cd /var/qmail/supervise
- mkdir -p qmail-smtpd/log qmail-send/log qmail-pop3d/log
- chmod +t qmail-smtpd qmail-send qmail-pop3d
Creating qmail-smtpd run supervise
- vim qmail-smtpd/run
#!/bin/sh
QMAILQUEUE="/var/qmail/bin/qmail-scanner-queue.pl" ; export QMAILQUEUE
QUID=`id -u qmaild`
QGID=`id -g qmaild`
MAXD=`head -1 /var/qmail/control/concurrencyincoming`
HOST=`head -1 /var/qmail/control/me`
SOFT=`head -1 /var/qmail/control/qmail-smtpd-softlimit`
CDBF="/etc/tcp.smtp.cdb"
if [ -z "$QUID" -o -z "$QGID" -o -z "$MAXD" -o -z "$HOST" ]; then
echo QUID, QGID, MAXD, or HOST is unset in
echo /var/qmail/supervise/qmail-smtpd/run
exit 1
fi
exec /usr/local/bin/softlimit -m $SOFT \
/usr/local/bin/tcpserver -v \
-H \
-R \
-l $HOST \
-x $CDBF \
-c $MAXD \
-u $QUID \
-g $QGID \
0 \
smtp \
/var/qmail/bin/qmail-smtpd \
/var/qmail/bin/auth_smtp /usr/bin/true 2>&1
Creating qmail-smtpd log run supervise script
- vim qmail-smtpd/log/run
#!/bin/sh
export PATH=/var/qmail/bin:/usr/local/bin:/usr/bin:/bin
exec /usr/local/bin/setuidgid qmaill /usr/local/bin/multilog t s10000000 n20 /var/log/qmail/qmail-smtpd 2>&1
Creating qmail rc supervise script
- vim /var/qmail/rc
#!/bin/sh
QLOG="`cat /var/qmail/control/qmail-start-loglevel`"
DEFD="`cat /var/qmail/control/defaultdelivery`"
exec env - PATH="/var/qmail/bin:$PATH" LOGLEVEL="$QLOG" qmail-start "$DEFD"
Creating qmail-send run supervise script
- vim qmail-send/run
#!/bin/sh
exec /var/qmail/rc
Creating qmail-send log run supervise script
- vim qmail-send/log/run
#!/bin/sh
exec /usr/local/bin/setuidgid qmaill /usr/local/bin/multilog t s10000000 n20 /var/log/qmail/qmail-send 2>&1
Creating qmail-pop3d run supervise script
- vim qmail-pop3d/run
#!/bin/sh
IP=`head -1 /var/qmail/control/me`
LL=`head -1 /var/qmail/control/qmail-pop3d-loglevel`
SL=`head -1 /var/qmail/control/qmail-pop3d-softlimit`
exec \
env LOGLEVEL=$LL \
softlimit -m $SL \
/usr/local/bin/tcpserver -v -R -H -l 0 0 pop3 \
/var/qmail/bin/qmail-popup $IP \
/var/qmail/bin/tcp-env \
/var/qmail/bin/auth_pop \
/var/qmail/bin/qmail-pop3d Maildir 2>&1
Creating qmail-pop3d log run supervise script
- vim qmail-pop3d/log/run
#!/bin/sh
exec /usr/local/bin/setuidgid qmaill /usr/local/bin/multilog t s10000000 n20 /var/log/qmail/qmail-pop3d 2>&1
Creating auto directory maker script
- vim /var/qmail/bin/dirmaker
#!/bin/sh
echo '----------------------------------------------' >> /tmp/dirmaker
date >> /tmp/dirmaker
echo $1 >> /tmp/dirmaker
id >> /tmp/dirmaker
mkdir --parents -m 700 -p $1/Maildir
mkdir --parents -m 700 -p $1/Maildir/tmp
mkdir --parents -m 700 -p $1/Maildir/cur
mkdir --parents -m 700 -p $1/Maildir/new
chown -R vmail:vmail $1
Set permissions of all qmail supervise run scripts
- chmod 755 qmail-pop3d/run qmail-smtpd/run qmail-send/run
- chmod 755 qmail-pop3d/log/run qmail-smtpd/log/run qmail-send/log/run
- chmod 755 /var/qmail/rc /var/qmail/bin/dirmaker
Create tcp.smtp file to appy tcprules
- vim /etc/tcp.smtp
127.:allow,RELAYCLIENT="",MAXRCPTCOUNT="200"
192.168.:allow,BLOCKRELAYPROBE="",RCPTCHECK="",SENDERCHECK="",AUTHPREPEND="Authenticated user:",SANITYCHECK="",SMTPAUTH="",LOGLEVEL="3",AUTHREQUIRED="",MAXRCPTCOUNT="100"
- allow,BLOCKRELAYPROBE="",RCPTCHECK="",SANITYCHECK="",RETURNMXCHECK="STRICT",RBL="",REJECTEXEC="",LOGLEVEL="3",TARPITCOUNT="10",TARPITDELAY="10",SMTPAUTH="",MAXRCPTCOUNT="25"
Creating qmail logging directories and set permissions
- mkdir /var/log/qmail
- cd /var/log/qmail
- mkdir qmail-send qmail-smtpd qmail-pop3d
- chown -R qmaill:root /var/log/qmail
- chmod -R 750 /var/log/qmail
Creating qmail alias users, links and set permissions
- cd /var/qmail
- cp -p /downloads/qmailctl /var/qmail/bin/.
- chmod 755 /var/qmail/bin/qmailctl
- ln -s /var/qmail/bin/qmailctl /usr/bin/
- qmailctl cdb
Creating links of supervise scripts
- mkdir -p /service
- cd /service/
- ln -s /var/qmail/supervise/qmail-* .
Creating aliases
- echo qmailadmin@groupvama.com > /var/qmail/alias/.qmail-root
- echo qmailadmin@ groupvama.com > /var/qmail/alias/.qmail-postmaster
- echo qmailadmin@ groupvama.com > /var/qmail/alias/.qmail-mailer-daemon
- ln -s /var/qmail/alias/.qmail-root /var/qmail/alias/.qmail-anonymous
- chmod 644 /var/qmail/alias/.qmail*
Stop sendmail and remove all related files
- /etc/init.d/sendmail stop
- chkconfig sendmail off
- mv /usr/lib/sendmail /usr/lib/sendmail.org
- mv /usr/sbin/sendmail /usr/sbin/sendmail.org
- ln -s /var/qmail/bin/sendmail /usr/lib/sendmail
- ln -s /var/qmail/bin/sendmail /usr/sbin/sendmail
Compile courier-authlib and install
- cd /downloads/qmailrocks/
- tar jxvf courier-authlib-0.55.tar.bz2
- cd courier-authlib-0.55
- ./configure --prefix=/usr/local --exec-prefix=/usr/local --with-authldap --without-authmysql --disable-root-check --with-ssl –with-authchangepwdir=/usr/local/libexec/authlib --with-redhat
- make && make check
- make install-strip && make install-configure
Create IMAP certificate and make changes on configuration files
- vim /usr/local/etc/imapd.cnf
(Change postmaser@example.com an administrative email address)
emailAddress=qmailadmin@groupvama.com
- vim /usr/local/etc/imapd
IMAPDSTART=YES
- vim /usr/local/etc/imapd-ssl
IMAPDSSLSTART=YES
TLS_CERTFILE=/var/qmail/control/clientcert.pem
- vim /usr/local/etc/authlib/authdaemonrc
authmodulelist="authldap"
authmodulelistorig="authldap"
- vim /usr/local/etc/authlib/authldaprc
LDAP_SERVER 127.0.0.1
LDAP_PORT 389
LDAP_BASEDN dc=groupvama,dc=com
LDAP_BINDDN cn=Manager,dc=groupvama,dc=com
LDAP_BINDPW MiraE#1920
LDAP_TIMEOUT 5
LDAP_AUTHBIND 1
LDAP_MAIL uid
LDAP_GLOB_UID vmail
LDAP_GLOB_GID vmail
LDAP_HOMEDIR mailMessageStore
LDAP_MAILROOT /home/vmail
LDAP_MAILDIR mailbox
LDAP_DEFAULTDELIVERY defaultDelivery
LDAP_FULLNAME cn
LDAP_CLEARPW clearPassword
LDAP_CRYPTPW userPassword
LDAP_DEREF never
LDAP_TLS 0
Copy imap and imaps script in init.d directory
cp /usr/local/libexec/imapd.rc /etc/rc.d/init.d/imap
cp /usr/local/libexec/imapd-ssl.rc /etc/rc.d/init.d/imaps
Make imap and imaps services start on boot
- vim /etc/rc.local
/usr/local/sbin/authdaemond start
/etc/rc.d/init.d/imap start
/etc/rc.d/init.d/imaps start
Restart authdaemon and imap services
- /usr/local/sbin/authdaemond stop
- /usr/local/sbin/authdaemond start
- /etc/rc.d/init.d/imap stop
- /etc/rc.d/init.d/imaps stop
- /etc/rc.d/init.d/imap start
- /etc/rc.d/init.d/imaps start
Install autoresponder and maildrop
- cd /downloads/autorespond-2.0.5/
- make && make install
- cd /downloads/maildrop-2.5.4
- ./configure --prefix=/usr/local --exec-prefix=/usr/local --enable-maildrop-uid=root
- make && make install-strip && make install-man
Install all required packages for Qmail-Scanner
- yum perl-suidperl perl-Digest-SHA1 perl-Digest-HMAC perl-Net-DNS perl-Time-HiRes* perl-HTML-Tagset perl-HTML-Parser perl-Pod-Usage* perl-Parse-Syslog perl-Statistics-Distributions spamassassin clamav clamd
Add user "qscand" for scanning
- useradd -c "Qmail-Scanner Account" -s /bin/false -m qscand
Change user clamav to qscand
- vim /etc/logrotate.d/clamav[Change clamav to qscand]
/var/log/clamav/clamd.log {
missingok
notifempty
create 644 qscand qscand
postrotate
killall -HUP clamd 2>/dev/null || :
endscript
}
- vim /etc/logrotate.d/freshclam[Change clamav to qscand]
/var/log/clamav/freshclam.log {
missingok
notifempty
create 644 qscand qscand
}
- vim /etc/clamd.conf
User qscand
- vim /etc/freshclam.conf
DatabaseOwner qscand
- chown qscand.qscand /var/log/clamav/ -R
- chown -R qscand.qscand /var/run/clamav/
- /etc/init.d/clamd restart
- /etc/init.d/spamassassin restart
Install Qmail-Scanner
- cd /downloads/qmail-scanner-2.08
- ./configure --admin admin --domain groupvama.com
- mkdir -p /var/spool/qscan
- mkdir -p /var/spool/qscan/quarantine/viruses/tmp /var/spool/qscan/quarantine/viruses/cur /var/spool/qscan/quarantine/viruses/new
- mkdir -p /var/spool/qscan/quarantine/spam/tmp /var/spool/qscan/quarantine/spam/cur /var/spool/qscan/quarantine/spam/new
- mkdir -p /var/spool/qscan/quarantine/policy/tmp /var/spool/qscan/quarantine/policy/cur /var/spool/qscan/quarantine/policy/new
- mkdir -p /var/spool/qscan/working/tmp /var/spool/qscan/working/cur /var/spool/qscan/working/new
- mkdir -p /var/spool/qscan/archive/tmp /var/spool/qscan/archive/cur /var/spool/qscan/archive/new
- cp /downloads/qmail-scanner-2.08/quarantine-events.txt /var/spool/qscan/
- chown -R qscand:qscand /var/spool/qscan/
- cp -pv /downloads/qmail-scanner-2.08/qmail-scanner-queue.pl /var/qmail/bin/
- chown qscand.qscand /var/qmail/bin/qmail-scanner-queue.pl
- chmod 4755 /var/qmail/bin/qmail-scanner-queue.pl
- /var/qmail/bin/qmail-scanner-queue.pl -z
- /var/qmail/bin/qmail-scanner-queue.pl -g
- cp -v /downloads/qmail-scanner-2.08/contrib/logrotate.qmail-scanner /etc/logrotate.d/qmail-scanner
- /etc/init.d/syslog restart
Integrate Qmail-scanner with qmail queue
- vim /var/qmail/supervise/qmail-smtpd/run
QMAILQUEUE="/var/qmail/bin/qmail-scanner-queue.pl" ; export QMAILQUEUE
Disclaimer on Qmail is Added to the Second Instance so that only Out going mails to different domains are uploaded with Common Signature / Disclaimer. Here this is used for multiple domains. Also second instance use to copy of all outgoing messages at log@groupvama.com.
- Implement Qmail-2 , i.e Second Qmail Instance
- Define Qmail-send and Qmail-smtpd daemons
- Define 2nd Qmail smtp port ( say 900)
- Install Qmail-qfilter , altermime and bglibs to satisfy the requirement.
- Define Multiple domain's text and HTML disclaimer
- Integrate Qmail's both the instances
Creating directories for installing qmail2
- mkdir -p /var/qmail2
- mkdir /usr/src/qmail2
- cd /usr/src/qmail2
Unpack qmail in /usr/src/qmail2 and apply qmail-ldap patch(this patch contain qmail queue and qmail error patch)
- tar xvzf /downloads/qmailrocks/qmail-1.03.tar.gz ( Assuming that you have downloaded Qmailrocks earlier )
- cd qmail-1.03
- patch -p1 < /downloads/qmail-ldap-1.03-20060201.patch
- echo 255 > /usr/src/qmail2/qmail-1.03/conf-spwan
- echo 211 > /usr/src/qmail2/qmail-1.03/conf-split
Make changes on "Makefile" to qmail work properly with ldap
Make these entries :
LDAPFLAGS=-DQLDAP_CLUSTER -DEXTERNAL_TODO -DDASH_EXT -DDATA_COMPRESS -DQMQP_COMPRESS -DSMTPEXECCHECK -DALTQUEUE
ZLIB=-lz
SHADOWLIBS=-lcrypt
DEBUG=-DDEBUG
- vim conf-qmail
( replace qmail with qmail2 )
Caution: This is very critical Step as, not doing do will cause the main Qmail instance will get over written .
Keep a copy of all outgoing mail messages
- vim extra.h
QUEUE_EXTRA "Tlog\0"
QUEUE_EXTRALEN 5
- make man
- make setup check
Qmail2 Control Files
- cd /var/qmail2/control/
- echo 100 > concurrencyincoming
- echo 255 > concurrencyremote
- echo ./Maildir/ > defaultdelivery
- echo /var/qmail/bin/dirmaker > dirmaker
- echo 0 > ldapcluster
- id -g vmail > ldapgid
- echo /home/vmail > ldapmessagestore
- echo qmailUser > ldapobjectclass
- echo secret > ldappassword
- echo 127.0.0.1 > ldapserver
- id -u vmail > ldapuid
- echo 80000000 > qmail-smtpd-softlimit
- echo 80000000 > qmail-pop3d-softlimit
- echo 3 > qmail-pop3d-loglevel
- echo 3 > qmail-start-loglevel
- echo groupvama.com > defaultdomain
- echo dc=groupvama,dc=com > ldapbasedn
- echo cn=Manager,dc=groupvama,dc=com > ldaplogin
- echo mail.groupvama.com > me
Qmail2 Daemons
Now create qmail2-smtpd and qmail2-send daemons
- Create /var/qmail2/rc
#!/bin/sh
QLOG="`cat /var/qmail2/control/qmail-start-loglevel`"
DEFD="`cat /var/qmail2/control/defaultdelivery`"
exec env - PATH="/var/qmail2/bin:$PATH" LOGLEVEL="$QLOG" qmail-start "$DEFD"
- chmod 755 /var/qmail2/rc
Create supervise directories for Qmail2-send and Qmail2-smtpd and log directories
- mkdir -p /var/qmail2/supervise/qmail2-smtpd/log
- mkdir -p /var/qmail2/supervise/qmail2-send/log
- mkdir -p /var/log/qmail2/qmail2-smtpd/
- mkdir -p /var/log/qmail2/qmail2-send/
- chown -R qmaill.nofiles /var/log/qmail2/
Daemon for Qmail2-send
- vim /var/qmail2/supervise/qmail2-send/run
#!/bin/sh
exec /var/qmail2/rc
- chmod 755 /var/qmail2/supervise/qmail2-send/run
Log daemon for Qmail2-send
- vim/var/qmail2/supervise/qmail2-send/log/run
#!/bin/sh
exec /usr/local/bin/setuidgid qmaill /usr/local/bin/multilog t s10000000 n20 /var/log/qmail2/qmail2-send 2>&1
Daemon for Qmail2-smtpd
- vim /var/qmail2/supervise/qmail2-smtpd/run
#!/bin/sh
QMAILQUEUE="/var/qmail2/bin/qmail-tail"; export QMAILQUEUE
QUID=`id -u qmaild`
QGID=`id -g qmaild`
MAXD=`head -1 /var/qmail2/control/concurrencyincoming`
HOST=`head -1 /var/qmail2/control/me`
SOFT=`head -1 /var/qmail2/control/qmail-smtpd-softlimit`
CDBF="/etc/tcp.smtp.cdb"
if [ -z "$QUID" -o -z "$QGID" -o -z "$MAXD" -o -z "$HOST" ]; then
echo QUID, QGID, MAXD, or HOST is unset in
echo /var/qmail/supervise/qmail-smtpd/run
exit 1
fi
exec /usr/local/bin/softlimit -m $SOFT \
/usr/local/bin/tcpserver -v \
-H \
-R \
-l $HOST \
-x $CDBF \
-c $MAXD \
-u $QUID \
-g $QGID \
0 \
qmail-second \
/var/qmail2/bin/qmail-smtpd \
/var/qmail2/bin/auth_smtp /usr/bin/true 2>&1
- chmod 755 /var/qmail2/supervise/qmail2-smtpd/run
Log daemon for Qmail2-smtpd
- vim /var/qmail2/supervise/qmail2-smtpd/log/run
#!/bin/sh
exec /usr/local/bin/setuidgid qmaill /usr/local/bin/multilog t s10000000 n20 /var/log/qmail2/qmail2-smtpd 2>&1
- chmod 755 /var/qmail2/supervise/qmail2-smtpd/log/run
Link these file to /service
- ln -s /var/qmail2/supervise/qmail2-smtpd /service/
- ln -s /var/qmail2/supervise/qmail2-send /service/
Restart the Qmail via inttab process
- telnet to port 900 and send the mail .
- check for logs /var/log/qmail2/qmail2-send/current or /var/log/qmail2/qmail2-smtpd/current
Disclaimer Related Implementation
Install bglibs for qmail2
- cd /downloads/
- rpm –Uvh bglibs-1.022-1.i386.rpm ( get it from http://untroubled.org/bglibs/ )
or
- tar -xvfz bglibs-1.022-1.tar.gz
- cd bglibs-1.022-1
- make
- make install
Install altermime for qmail2
- tar xvzf altermime-0.3.6.tar.gz (get it from http://www.pldaniels.com/altermime/ )
- cd altermime-0.3.6
- make
- make install
Install qmail-qfilter for qmail2
- tar xvzf qmail-qfilter-2.1.tar.gz (http://untroubled.org/qmail-qfilter/)
- cd qmail-qfilter-2.1
- vi qmail-qfilter.c
( change qmail into qmail2 )
#ifndef QMAIL_QUEUE
#define QMAIL_QUEUE "/var/qmail2/bin/qmail-queue"
#endif
- make
- make install
- chmod 777 /usr/local/bin/qmail-qfilter
- chown root:qmail /usr/local/bin/qmail-qfilter
Disclaimer Settings
- vi /var/qmail2/bin/qmail-tail
#!/bin/sh
exec /usr/local/bin/qmail-qfilter /var/qmail2/bin/qmail-disclaimer
- chown root:qmail /var/qmail2/bin/qmail-tail
- chmod 777 /var/qmail2/bin/qmail-tail
- mkdir /var/qmail2/control/disclaimer/
- cd /var/qmail2/control/disclaimer
- vim groupvama.com.html
<html>
<body>
DISCLAIMER:
This email message is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorised use or disclosure is prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message.
</body>
</html>
- vim gropvama.com.txt
This email message is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized use or disclosure is prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message.
- chown root:qmail /var/qmail2/control/disclaimer/*
- chmod 777 /var/qmail2/control/disclaimer/*
- mkdir /var/tmp/qmail-qfilter
- chown root:qmail /var/tmp/qmail-qfilter
- chmod 777 /var/tmp/qmail-qfilter
- vi /var/qmail2/bin/qmail-disclaimer
#!/bin/sh
QMAILHOST=groupvama.com
INSPECT_DIR=/var/tmp/qmail-qfilter
if [ ! -f /var/qmail2/control/disclaimer/$QMAILHOST.txt ]
then
cat
exit 0
fi
EX_TEMPFAIL=31
EX_UNAVAILABLE=31
trap "rm -f /var/tmp/qmail-qfilter/in.$$" 0 1 2 3 15
cd $INSPECT_DIR || { echo Error: $INSPECT_DIR does not exist; exit $EX_TEMPFAIL; }
cat >$INSPECT_DIR/in.$$ || { echo Error: Cannot write to disk; exit $EX_TEMPFAIL; }
/usr/local/bin/altermime --input=$INSPECT_DIR/in.$$ \
--xheader="X-Disclaimer: $QMAILHOST" \
--disclaimer=/var/qmail2/control/disclaimer/$QMAILHOST.txt \
--disclaimer-html=/var/qmail2/control/disclaimer/$QMAILHOST.html || { echo Error: message rejected; exit $EX_UNAVAILABLE; }
cat $INSPECT_DIR/in.$$
rm in.$$
exit $?
- chown root:qmail /var/qmail2/bin/qmail-disclaimer
- chmod 777 /var/qmail2/bin/qmail-disclaimer
Activation of Qmail2
Changes on Qmail2-Send run file
- vi /service/qmail2-smtpd/run
( add following line at the top )
#!/bin/sh
QMAILQUEUE="/var/qmail2/bin/qmail-tail"; export QMAILQUEUE
Also Make sure the Qmail-smtpd is running on port 900 by
- vi /etc/services
# Local services
second-qmail 900/tcp
Integrate Qmail with Qmail2
vi /var/qmail/control/smtproutes
- 127.0.0.1:900
Note: Then restart the qmail from /etc/inittab file
Testing
- Telnet and send mail via Qmail-2 , you should get the disclaimer
- Test via offline Client like Evolution , Outlook etc . You should get the mail with
Troubleshooting
- QQ error while sending mails
Check the smtp logs , if find error like
/usr/local/bin/qmail-qfilter: error while loading shared libraries: libbg-sysdeps.so.1: cannot open shared object file: No such file or directory
Then
you have to link libbg-sysdeps.so.1 to /usr/lib
- ln -s /usr/local/bglibs/lib/libbg-sysdeps.so.1 /usr/lib/
This should solve the issue
- 2. Some time the Qmail-1 is not able to deliver mails to Qmail-2 instance due to /var/tmp/qmail-qfilter directory is not there or vanishes. So a script to check and create the directory with cron is created for taking care of this issue.
The script is /usr/bin/check_qmail-qfilter_dir.sh
#!/bin/sh
DIRECTORY=/var/tmp/qmail-qfilter
if [ ! -d "$DIRECTORY" ]; then
mkdir -p $DIRECTORY;
chmod 777 $DIRECTORY;
chown -R root.qmail $Directory
fi
The cron entry is as follows
- crontab -e
*/5 * * * * /usr/bin/check_qmail-qfilter_dir.sh
Openldap master (slapd.conf)
- Vim /etc/openldap/ldap.conf
BASE dc=groupvama,dc=com
URI ldap://127.0.0.1/
- Vim /etc/openldap/slapd.conf
#
# See slapd.conf(5) for details on configuration options.
# This file should NOT be world readable.
#
include /etc/openldap/schema/core.schema
include /etc/openldap/schema/cosine.schema
include /etc/openldap/schema/inetorgperson.schema
include /etc/openldap/schema/nis.schema
include /etc/openldap/schema/qmail.schema
include /etc/openldap/schema/dnszone.schema
# Allow LDAPv2 client connections. This is NOT the default.
allow bind_v2
# Do not enable referrals until AFTER you have a working directory
# service AND an understanding of referrals.
#referral ldap://root.openldap.org
pidfile /var/run/openldap/slapd.pid
argsfile /var/run/openldap/slapd.args
# Load dynamic backend modules:
# modulepath /usr/lib64/openldap
# Modules available in openldap-servers-overlays RPM package
# Module syncprov.la is now statically linked with slapd and there
# is no need to load it here
# moduleload accesslog.la
# moduleload auditlog.la
# moduleload denyop.la
# moduleload dyngroup.la
# moduleload dynlist.la
# moduleload lastmod.la
# moduleload pcache.la
# moduleload ppolicy.la
# moduleload refint.la
# moduleload retcode.la
# moduleload rwm.la
# moduleload smbk5pwd.la
# moduleload translucent.la
# moduleload unique.la
# moduleload valsort.la
# modules available in openldap-servers-sql RPM package:
# moduleload back_sql.la
# The next three lines allow use of TLS for encrypting connections using a
# dummy test certificate which you can generate by changing to
# /etc/pki/tls/certs, running "make slapd.pem", and fixing permissions on
# slapd.pem so that the ldap user or group can read it. Your client software
# may balk at self-signed certificates, however.
# TLSCACertificateFile /etc/pki/tls/certs/ca-bundle.crt
# TLSCertificateFile /etc/pki/tls/certs/slapd.pem
# TLSCertificateKeyFile /etc/pki/tls/certs/slapd.pem
# Sample security restrictions
# Require integrity protection (prevent hijacking)
# Require 112-bit (3DES or better) encryption for updates
# Require 63-bit encryption for simple bind
# security ssf=1 update_ssf=112 simple_bind=64
# Sample access control policy:
# Root DSE: allow anyone to read it
# Subschema (sub)entry DSE: allow anyone to read it
# Other DSEs:
# Allow self write access
# Allow authenticated users read access
# Allow anonymous users to authenticate
# Directives needed to implement policy:
# access to dn.base="" by * read
# access to dn.base="cn=Subschema" by * read
# access to *
# by self write
# by users read
# by anonymous auth
#
#access to *
# by dn.exact="cn=Manager,dc=groupvama,dc=com" read
# by * none
# if no access controls are present, the default policy
# allows anyone and everyone to read anything but restricts
# updates to rootdn. (e.g., "access to * by * read")
# modules available in openldap-servers-sql RPM package:
# moduleload back_sql.la
# The next three lines allow use of TLS for encrypting connections using a
# dummy test certificate which you can generate by changing to
# /etc/pki/tls/certs, running "make slapd.pem", and fixing permissions on
# slapd.pem so that the ldap user or group can read it. Your client software
# may balk at self-signed certificates, however.
# TLSCACertificateFile /etc/pki/tls/certs/ca-bundle.crt
# TLSCertificateFile /etc/pki/tls/certs/slapd.pem
# TLSCertificateKeyFile /etc/pki/tls/certs/slapd.pem
# Sample security restrictions
# Require integrity protection (prevent hijacking)
# Require 112-bit (3DES or better) encryption for updates
# Require 63-bit encryption for simple bind
# security ssf=1 update_ssf=112 simple_bind=64
# Sample access control policy:
# Root DSE: allow anyone to read it
# Subschema (sub)entry DSE: allow anyone to read it
# Other DSEs:
# Allow self write access
# Allow authenticated users read access
# Allow anonymous users to authenticate
# Directives needed to implement policy:
# access to dn.base="" by * read
# access to dn.base="cn=Subschema" by * read
# access to *
# by self write
# by users read
# by anonymous auth
#
#access to *
# by dn.exact="cn=Manager,dc=groupvama,dc=com" read
# by * none
# if no access controls are present, the default policy
# allows anyone and everyone to read anything but restricts
# updates to rootdn. (e.g., "access to * by * read")
#
# rootdn can always read and write EVERYTHING!
#######################################################################
# ldbm and/or bdb database definitions
#######################################################################
serverID 001
database bdb
suffix "dc=groupvama,dc=com"
rootdn "cn=Manager,dc=groupvama,dc=com"
# Cleartext passwords, especially for the rootdn, should
# be avoided. See slappasswd(8) and slapd.conf(5) for details.
# Use of strong authentication encouraged.
rootpw MiraE#1920
# rootpw {crypt}ijFYNcSNctBYg
# The database directory MUST exist prior to running slapd AND
# should only be accessible by the slapd and slap tools.
# Mode 700 recommended.
directory /var/lib/ldap
# Indices to maintain for this database
index objectClass eq,pres
index ou,cn,mail,surname,givenname eq,pres,sub
index uidNumber,gidNumber,loginShell eq,pres
index uid,memberUid eq,pres,sub
index nisMapName,nisMapEntry eq,pres,sub
# Replicas of this database
#replogfile /var/lib/ldap/openldap-master-replog
#replica host=ldap-1.example.com:389 starttls=critical
# bindmethod=sasl saslmech=GSSAPI
# authcId=host/ldap-master.example.com@EXAMPLE.COM
overlay syncprov
syncprov-checkpoint 100 10
syncprov-sessionlog 100
replica uri=ldap://182.71.29.139:389
binddn="cn=Manager,dc=groupvama,dc=com"
bindmethod=simple credentials=MiraE#1920
Openldap slave (slapd.conf)
- Vim /etc/openldap/slapd.conf
#
# See slapd.conf(5) for details on configuration options.
# This file should NOT be world readable.
#
include /etc/openldap/schema/core.schema
include /etc/openldap/schema/cosine.schema
include /etc/openldap/schema/inetorgperson.schema
include /etc/openldap/schema/nis.schema
include /etc/openldap/schema/qmail.schema
# Allow LDAPv2 client connections. This is NOT the default.
allow bind_v2
# Do not enable referrals until AFTER you have a working directory
# service AND an understanding of referrals.
#referral ldap://root.openldap.org
pidfile /var/run/openldap/slapd.pid
argsfile /var/run/openldap/slapd.args
# Load dynamic backend modules:
# modulepath /usr/lib/openldap
# Modules available in openldap-servers-overlays RPM package
# Module syncprov.la is now statically linked with slapd and there
# is no need to load it here
# moduleload accesslog.la
# moduleload auditlog.la
# moduleload denyop.la
# moduleload dyngroup.la
# moduleload dynlist.la
# moduleload lastmod.la
# moduleload pcache.la
# moduleload ppolicy.la
# moduleload refint.la
# moduleload retcode.la
# moduleload rwm.la
# moduleload smbk5pwd.la
# moduleload translucent.la
# moduleload unique.la
# moduleload valsort.la
# modules available in openldap-servers-sql RPM package:
# moduleload back_sql.la
# The next three lines allow use of TLS for encrypting connections using a
# dummy test certificate which you can generate by changing to
# /etc/pki/tls/certs, running "make slapd.pem", and fixing permissions on
# slapd.pem so that the ldap user or group can read it. Your client software
# may balk at self-signed certificates, however.
# TLSCACertificateFile /etc/pki/tls/certs/ca-bundle.crt
# TLSCertificateFile /etc/pki/tls/certs/slapd.pem
# TLSCertificateKeyFile /etc/pki/tls/certs/slapd.pem
# Sample security restrictions
# Require integrity protection (prevent hijacking)
# Require 112-bit (3DES or better) encryption for updates
# Require 63-bit encryption for simple bind
# security ssf=1 update_ssf=112 simple_bind=64
# Sample access control policy:
# Root DSE: allow anyone to read it
# Subschema (sub)entry DSE: allow anyone to read it
# Other DSEs:
# Allow self write access
# Allow authenticated users read access
# Allow anonymous users to authenticate
# Directives needed to implement policy:
# access to dn.base="" by * read
# access to dn.base="cn=Subschema" by * read
# access to *
# by self write
# by users read
# by anonymous auth
#
# if no access controls are present, the default policy
# allows anyone and everyone to read anything but restricts
# updates to rootdn. (e.g., "access to * by * read")
#
# rootdn can always read and write EVERYTHING!
#access to *
# by dn.exact="cn=Manager,dc=groupvama,dc=com" read
# by * none
#######################################################################
# ldbm and/or bdb database definitions
#######################################################################
serverID 002
database bdb
#suffix "dc=my-domain,dc=com"
#rootdn "cn=Manager,dc=my-domain,dc=com"
suffix "dc=groupvama,dc=com"
rootdn "cn=Manager,dc=groupvama,dc=com"
# Cleartext passwords, especially for the rootdn, should
# be avoided. See slappasswd(8) and slapd.conf(5) for details.
# Use of strong authentication encouraged.
# rootpw secret
# rootpw {crypt}ijFYNcSNctBYg
rootpw MiraE#1920
# The database directory MUST exist prior to running slapd AND
# should only be accessible by the slapd and slap tools.
# Mode 700 recommended.
directory /var/lib/ldap
# Indices to maintain for this database
index objectClass eq,pres
index ou,cn,mail,surname,givenname eq,pres,sub
index uidNumber,gidNumber,loginShell eq,pres
index uid,memberUid eq,pres,sub
index nisMapName,nisMapEntry eq,pres,sub
# Replicas of this database
#replogfile /var/lib/ldap/openldap-master-replog
#replica host=ldap-1.example.com:389 starttls=critical
# bindmethod=sasl saslmech=GSSAPI
# authcId=host/ldap-master.example.com@EXAMPLE.COM
#syncrepl rid=001
#provider=ldap://182.71.29.139
#type=refreshAndPersist
#searchbase="dc=groupvama,dc=com"
#filter="(objectClass=*)"
#scope=sub
#attrs="*"
#bindmethod=simple
#binddn="cn=Manager,dc=groupvama,dc=com"
#credentials=MiraE#1920
syncrepl rid=001
provider=ldap://182.71.29.139
type=refreshAndPersist
retry="60 +"
searchbase="dc=groupvama,dc=com"
scope=sub
schemachecking=on
bindmethod=simple
binddn="cn=Manager,dc=groupvama,dc=com"
credentials=MiraE#1920
mirrormode on
Then restart ldap on both automatically master slave synchronize.