Jump to content

Roll Out Done in Pahwa

From TetraWiki
Revision as of 14:51, 2 December 2014 by Biswajit (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)


Objective[edit]

  • SSL Certicate was implemented on the Pahwa mail server ( postfix , trend Micro and Qmail )
  • Now all the NON - Secure ports needs to disabled or modified
  • Identified Ports / Services were POP3 (Qmail-pop) , IMAP (Courier) , HTTP (Apache) and SMTP (postfix) without Auth ( SMTP service cannot be disabled )

Solution[edit]

  • POP3 - disabled on Qmail by removing (qmail-pop3d ) the Link to /service
  • IMAP - Disable by binding it to localhost ( 127.0.0.1) in imapd.conf files
  • HTTP - Redirect hhtp to HTTPS .
  • SMTP - Disable Authentication on postfix so that relay mails cannot come on port 25 . Also allowed few designated IP to relay ( As that was customer requirement )


Technical Roll Out Process In Pahwa qmail + postfix + Apache


  • For the Apache done the below in httpd.conf
RewriteEngine On
RewriteRule ^(.*)$ https://%{HTTP_HOST}$1 [R=301,L]
  • For the Non secure Pop port disablement done below

unlink /services/qmail-pop3d

  • For the Postfix done below in main.cf
mynetworks = 127.0.0.0/8, 192.168.0.2, 192.168.0.16, 192.168.0.49, 182.71.174.125
smtpd_sasl_auth_enable = no