Minimal Postfix relay configuration accepting only TLS connections of authenticated users Announcing the arrival of Valued Associate #679: Cesar Manara Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30 pm US/Eastern) Come Celebrate our 10 Year Anniversary!Postfix SASL errorPostfix timing out when trying to send mailIs SASL not supported in Postfix on FreeBSD?What is wrong in my Postfix Dovecot sasl configuration?When does Postfix act like a client?postfix TLS disconnect from unknownPostfix: can't send mail from remote clientProcmail or/and dovecot?Mail infrastructure with dovecot proxyPostfix / Thunderbird / Cyrus SASL2: Username Or Password Invalid
Simulate round-robin tournament draw
Is there a verb for listening stealthily?
Arriving in Atlanta (after US Preclearance in Dublin). Will I go through TSA security in Atlanta to transfer to a connecting flight?
How would it unbalance gameplay to rule that Weapon Master allows for picking a fighting style?
My admission is revoked after accepting the admission offer
Co-worker works way more than he should
Is it accepted to use working hours to read general interest books?
Why doesn't the university give past final exams' answers?
Why is water being consumed when my shutoff valve is closed?
Bright yellow or light yellow?
When does Bran Stark remember Jamie pushing him?
How can I wire a 9-position switch so that each position turns on one more LED than the one before?
What's the difference between using dependency injection with a container and using a service locator?
How long can a nation maintain a technological edge over the rest of the world?
What to do with someone that cheated their way though university and a PhD program?
Is it OK if I do not take the receipt in Germany?
Are there existing rules/lore for MTG planeswalkers?
Will I lose my paid in full property
France's Public Holidays' Puzzle
How was Lagrange appointed professor of mathematics so early?
Will I be more secure with my own router behind my ISP's router?
Has a Nobel Peace laureate ever been accused of war crimes?
What is the numbering system used for the DSN dishes?
Raising a bilingual kid. When should we introduce the majority language?
Minimal Postfix relay configuration accepting only TLS connections of authenticated users
Announcing the arrival of Valued Associate #679: Cesar Manara
Planned maintenance scheduled April 23, 2019 at 23:30 UTC (7:30 pm US/Eastern)
Come Celebrate our 10 Year Anniversary!Postfix SASL errorPostfix timing out when trying to send mailIs SASL not supported in Postfix on FreeBSD?What is wrong in my Postfix Dovecot sasl configuration?When does Postfix act like a client?postfix TLS disconnect from unknownPostfix: can't send mail from remote clientProcmail or/and dovecot?Mail infrastructure with dovecot proxyPostfix / Thunderbird / Cyrus SASL2: Username Or Password Invalid
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I have a mail (and web) server running Debian 7 with Postfix 2.9.
Currently Postfix is essentially used as a mail forwarder; there is only one mailbox (root) which is accessed locally with the "mail" command.
I wish to use this server as an SMTP mail-sending server that can be used, after authentication, by external mail clients (like Thunderbird or Gmail) through a secured connexion (TLS, I suppose).
I do not need POP3 nor IMAP features. I wish to install as few packages, libraries and dependencies as possible (I like the KISS principle).
From my many readings, I understand that I will have to install some Dovecot or Cyrus packages to manage SASL; again, I would like to keep them as scarce as possible, for a minimal setup.
As for TLS, since my server already accepts TLS connexions for serving webpages, I think that I will only have to edit existing mail related configuration files (no extra packages needed).
Many thanks for sharing your advices or thoughts. Eg., if I choose Dovecot for managing SASL, will the "dovecot-core" package be sufficient?
debian ssl postfix debian-wheezy sasl
New contributor
add a comment |
I have a mail (and web) server running Debian 7 with Postfix 2.9.
Currently Postfix is essentially used as a mail forwarder; there is only one mailbox (root) which is accessed locally with the "mail" command.
I wish to use this server as an SMTP mail-sending server that can be used, after authentication, by external mail clients (like Thunderbird or Gmail) through a secured connexion (TLS, I suppose).
I do not need POP3 nor IMAP features. I wish to install as few packages, libraries and dependencies as possible (I like the KISS principle).
From my many readings, I understand that I will have to install some Dovecot or Cyrus packages to manage SASL; again, I would like to keep them as scarce as possible, for a minimal setup.
As for TLS, since my server already accepts TLS connexions for serving webpages, I think that I will only have to edit existing mail related configuration files (no extra packages needed).
Many thanks for sharing your advices or thoughts. Eg., if I choose Dovecot for managing SASL, will the "dovecot-core" package be sufficient?
debian ssl postfix debian-wheezy sasl
New contributor
You can re-use the existing TLS certificate(s) that your webserver uses for Postfix. - As the manual postfix.org/SASL_README.html explains, Dovecot SASL makes most sense when you already (plan to) use Dovecot for POP/IMAP, where Cyrus might be more lightweight when you won't be offering mailboxes but either will work.
– HBruijn
Apr 17 at 9:42
add a comment |
I have a mail (and web) server running Debian 7 with Postfix 2.9.
Currently Postfix is essentially used as a mail forwarder; there is only one mailbox (root) which is accessed locally with the "mail" command.
I wish to use this server as an SMTP mail-sending server that can be used, after authentication, by external mail clients (like Thunderbird or Gmail) through a secured connexion (TLS, I suppose).
I do not need POP3 nor IMAP features. I wish to install as few packages, libraries and dependencies as possible (I like the KISS principle).
From my many readings, I understand that I will have to install some Dovecot or Cyrus packages to manage SASL; again, I would like to keep them as scarce as possible, for a minimal setup.
As for TLS, since my server already accepts TLS connexions for serving webpages, I think that I will only have to edit existing mail related configuration files (no extra packages needed).
Many thanks for sharing your advices or thoughts. Eg., if I choose Dovecot for managing SASL, will the "dovecot-core" package be sufficient?
debian ssl postfix debian-wheezy sasl
New contributor
I have a mail (and web) server running Debian 7 with Postfix 2.9.
Currently Postfix is essentially used as a mail forwarder; there is only one mailbox (root) which is accessed locally with the "mail" command.
I wish to use this server as an SMTP mail-sending server that can be used, after authentication, by external mail clients (like Thunderbird or Gmail) through a secured connexion (TLS, I suppose).
I do not need POP3 nor IMAP features. I wish to install as few packages, libraries and dependencies as possible (I like the KISS principle).
From my many readings, I understand that I will have to install some Dovecot or Cyrus packages to manage SASL; again, I would like to keep them as scarce as possible, for a minimal setup.
As for TLS, since my server already accepts TLS connexions for serving webpages, I think that I will only have to edit existing mail related configuration files (no extra packages needed).
Many thanks for sharing your advices or thoughts. Eg., if I choose Dovecot for managing SASL, will the "dovecot-core" package be sufficient?
debian ssl postfix debian-wheezy sasl
debian ssl postfix debian-wheezy sasl
New contributor
New contributor
edited Apr 17 at 9:29
HBruijn
56.9k1190150
56.9k1190150
New contributor
asked Apr 17 at 8:59
ÉricÉric
11
11
New contributor
New contributor
You can re-use the existing TLS certificate(s) that your webserver uses for Postfix. - As the manual postfix.org/SASL_README.html explains, Dovecot SASL makes most sense when you already (plan to) use Dovecot for POP/IMAP, where Cyrus might be more lightweight when you won't be offering mailboxes but either will work.
– HBruijn
Apr 17 at 9:42
add a comment |
You can re-use the existing TLS certificate(s) that your webserver uses for Postfix. - As the manual postfix.org/SASL_README.html explains, Dovecot SASL makes most sense when you already (plan to) use Dovecot for POP/IMAP, where Cyrus might be more lightweight when you won't be offering mailboxes but either will work.
– HBruijn
Apr 17 at 9:42
You can re-use the existing TLS certificate(s) that your webserver uses for Postfix. - As the manual postfix.org/SASL_README.html explains, Dovecot SASL makes most sense when you already (plan to) use Dovecot for POP/IMAP, where Cyrus might be more lightweight when you won't be offering mailboxes but either will work.
– HBruijn
Apr 17 at 9:42
You can re-use the existing TLS certificate(s) that your webserver uses for Postfix. - As the manual postfix.org/SASL_README.html explains, Dovecot SASL makes most sense when you already (plan to) use Dovecot for POP/IMAP, where Cyrus might be more lightweight when you won't be offering mailboxes but either will work.
– HBruijn
Apr 17 at 9:42
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Éric is a new contributor. Be nice, and check out our Code of Conduct.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f963438%2fminimal-postfix-relay-configuration-accepting-only-tls-connections-of-authentica%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Éric is a new contributor. Be nice, and check out our Code of Conduct.
Éric is a new contributor. Be nice, and check out our Code of Conduct.
Éric is a new contributor. Be nice, and check out our Code of Conduct.
Éric is a new contributor. Be nice, and check out our Code of Conduct.
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f963438%2fminimal-postfix-relay-configuration-accepting-only-tls-connections-of-authentica%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
You can re-use the existing TLS certificate(s) that your webserver uses for Postfix. - As the manual postfix.org/SASL_README.html explains, Dovecot SASL makes most sense when you already (plan to) use Dovecot for POP/IMAP, where Cyrus might be more lightweight when you won't be offering mailboxes but either will work.
– HBruijn
Apr 17 at 9:42