Commit Graph
100 Commits
Author SHA1 Message Date
niten d187b0a555 Sender restrictions apply to ALL messages.
Even incoming.

So permit if there's nothing wrong with the sender address. We still
won't relay.
2023-10-02 14:27:47 -07:00
niten 186589dd5f Nope, imap does need net access 2023-10-02 13:56:50 -07:00
niten 76333c0a7c Permit in the end 2023-10-02 13:16:34 -07:00
niten 9fb588d62c Extra reject on relay is redundant, I think? 2023-10-02 12:41:25 -07:00
niten 8d613f6e57 Works without SSSD!
Now...accept incoming mail if we're the destination
2023-10-02 12:38:56 -07:00
niten 17571822f5 Nevermind...I guess sssd deals with nscd 2023-10-02 12:22:20 -07:00
niten 675e92dd22 Add LDAP network, disable nscd 2023-10-02 12:17:42 -07:00
niten 1dad0af755 Add a couple read-only clauses 2023-10-02 10:56:39 -07:00
niten 5b1df26b89 Need to set LDAP domain 2023-10-02 09:55:27 -07:00
niten 6847ced933 Need to use $ for env vars 2023-10-02 09:40:27 -07:00
niten 04cb0f0eb2 Fixes per errors 2023-10-01 22:21:17 -07:00
niten f2859a40fe Ugh, I'll eventually get this right 2023-10-01 21:56:31 -07:00
niten cc68d1c6a1 Correct env file name 2023-10-01 21:40:30 -07:00
niten 3a1b74863c Missed a reference 2023-10-01 15:01:53 -07:00
niten 393112de4a Add user-ou & group-ou 2023-10-01 14:59:27 -07:00
niten 93569ff4e8 Add .target-file 2023-10-01 14:56:39 -07:00
niten 23e76da29e Oops, shouldn't be nested under systemd 2023-10-01 14:54:08 -07:00
niten 2a46e1bfe3 Try enabling SSSD 2023-10-01 14:51:39 -07:00
niten 66128a5cd2 And this'll be back to failing again... 2023-10-01 14:23:19 -07:00
niten 4d54a95d59 One laaaast try 2023-10-01 13:41:31 -07:00
niten 8092bd4eda Uhh...ldap outpost can only filter on class 2023-10-01 09:11:57 -07:00
niten 8efe768dae This SHOULD WORK damn it 2023-10-01 08:45:31 -07:00
niten f1b38d7524 Move pass_attrs into passdb clause... 2023-10-01 08:30:48 -07:00
niten 6fb4b43428 Alternative way to specify pass_attrs? 2023-10-01 08:09:51 -07:00
niten ab6d2e2244 Try setting pass_attrs instead... 2023-09-30 21:30:46 -07:00
niten c2ad6bf5a1 State directory doesn't need to be modifiable by mail-user 2023-09-30 19:54:46 -07:00
niten 9d3c86a118 Create a mail directory 2023-09-30 18:54:17 -07:00
niten 99e9b6c519 Well what the fuck then 2023-09-30 18:17:24 -07:00
niten 1bcee1c199 Try this again, sigh 2023-09-30 17:37:32 -07:00
niten 02641b1db5 See what this says without user_filter... 2023-09-30 14:50:41 -07:00
niten 907970a86b Try user_attrs in ldap config 2023-09-30 14:45:32 -07:00
niten 41b52ec070 Two userdbs? 2023-09-30 12:47:05 -07:00
niten cea54ef0b0 Try some new settings 2023-09-30 12:20:39 -07:00
niten 915a0f0691 Try specifying username format 2023-09-30 11:48:55 -07:00
niten 6893ce148f Try a different class... 2023-09-30 10:33:39 -07:00
niten 6b31037b23 Change filter 2023-09-30 10:16:22 -07:00
niten 03eb9e16c8 Put user_attrs in the wrong place 2023-09-30 09:38:10 -07:00
niten f29d321673 Try specifying the CN to fetch the user 2023-09-30 08:46:42 -07:00
niten cd9ff40814 Re-add user-db 2023-09-29 18:00:56 -07:00
niten 8860ca23c5 Recipients are recipients... 2023-09-29 17:20:30 -07:00
niten e62d1b8085 It DID say relay... 2023-09-29 16:54:54 -07:00
niten 69b2ed3daf Permit sasl auth recipient before continuing 2023-09-29 16:26:27 -07:00
niten 1c5449a499 Sue cn not uid in the ldap DN 2023-09-29 15:54:07 -07:00
niten 36a9d2a1fa Character snuck in..... 2023-09-29 15:37:20 -07:00
niten 3e2dd06808 with pkgs 2023-09-29 15:01:50 -07:00
niten 601f170c28 Include openldap for testing 2023-09-29 14:59:54 -07:00
niten b81cd98065 Okay, use LDAP bind-dn 2023-09-29 14:51:54 -07:00
niten b51af05f84 Dovecot shouldn't be using PAM 2023-09-29 14:41:59 -07:00
niten 5bf9af1531 Make sure we can delete the sieves 2023-09-29 14:03:02 -07:00
niten 0b1cae5426 Actually set a UID for mail-user 2023-09-29 13:36:54 -07:00
niten 356c284af7 Let imap talk to the network... 2023-09-29 10:31:02 -07:00
niten 2492a479db Tweaks to dovecot 2023-09-29 10:19:09 -07:00
niten 96aa481ad7 Unauth pipelining makes thunderbird break 2023-09-29 09:48:18 -07:00
niten 95305e08f4 lol 2023-09-29 09:32:01 -07:00
niten 98eff8478d Just...use the socket option FFS 2023-09-29 09:19:57 -07:00
niten 7112e4722a Fuck domain-specific keys 2023-09-28 22:34:58 -07:00
niten e3e6305647 Just forget domain-specefic FFS 2023-09-28 22:10:29 -07:00
niten 409d0e6207 WTF is the deal with this selector thing 2023-09-28 22:00:55 -07:00
niten e3fc492961 Oof, need an extra name entry 2023-09-28 20:50:48 -07:00
niten 47b7248dd7 Don't need the sep then 2023-09-28 20:36:48 -07:00
niten 4c8a29a0a2 Maybe we need a newline... 2023-09-28 20:32:35 -07:00
niten efd45dbd0e Don't define a selector then... 2023-09-28 20:08:57 -07:00
niten 0fe2b7863d Define selector for dkim 2023-09-28 19:10:44 -07:00
niten 4a1b3776e9 Oof...was it just an extra space? 2023-09-28 17:41:44 -07:00
niten c4ad7a89a4 Refer to the file in the dir 2023-09-28 17:00:26 -07:00
niten efe6f49c2b Shit...missed one 2023-09-28 16:51:42 -07:00
niten f44d04e16b Specify a directory, I guess 2023-09-28 15:45:43 -07:00
niten 82ed2df2b3 Put dkim tables in directories 2023-09-28 15:27:34 -07:00
niten ad24ed9d2a Need to define key/signing tables earlier 2023-09-28 14:22:47 -07:00
niten db63fc6e2a Give dkim access to config files 2023-09-28 14:18:48 -07:00
niten e132ba1a2a Seems TMPDIR doesn't exist 2023-09-28 13:00:01 -07:00
niten a5ed6cc504 Open firewall ports 2023-09-28 12:31:03 -07:00
niten 41f5cf4c26 rspamd listen on all addresses 2023-09-28 12:05:59 -07:00
niten c99a1d57d6 enabled -> enable 2023-09-27 18:00:08 -07:00
niten 90817bb155 Open firewalls 2023-09-27 17:56:06 -07:00
niten 52524b595f Don't be so strict with clients 2023-09-27 17:28:50 -07:00
niten 713aa646e5 Need to use line...partial apply instead 2023-09-27 17:07:36 -07:00
niten e55d3329f0 Get the brackets right 2023-09-27 17:05:30 -07:00
niten da3d7582e2 Swap spaces for commas in submission 2023-09-27 17:01:48 -07:00
niten 6ecc49bd8e Commas can be spaces (and spaces aren't allowed) 2023-09-27 16:34:20 -07:00
niten d46242a4b6 Submission restrictions ought to be different? 2023-09-27 13:47:38 -07:00
niten 84a80feaf4 Switch back to regular ports 2023-09-27 13:04:51 -07:00
niten 4f3ec6e12e Add opendkim to path for keygen 2023-09-27 13:01:06 -07:00
niten 94e138db2d dovecot user needs x perm on parent dir 2023-09-27 12:57:47 -07:00
niten ade3598355 password -> passwd 2023-09-27 12:13:52 -07:00
niten 8a8d894f00 Just use redis password directly 2023-09-27 12:11:07 -07:00
niten 811f1de248 Forgot mkOption... 2023-09-27 12:08:17 -07:00
niten dd73b0d505 Can I not nest options? 2023-09-27 12:05:07 -07:00
niten c87fb3f639 Set & use Redis password 2023-09-27 12:03:17 -07:00
niten d10830785b Define networks... 2023-09-27 11:39:05 -07:00
niten 4139bcae81 Enable a ton of rspamd checks
And use redis for rspamd
2023-09-27 09:51:26 -07:00
niten 93ca17f907 Try this... 2023-09-27 08:47:24 -07:00
niten 152d76bdb5 Remove extra network 2023-09-27 07:16:39 -07:00
niten 0e543134a8 Just allow access to inet 2023-09-27 06:50:25 -07:00
niten fd683bb7e6 service -> server 2023-09-26 23:16:51 -07:00
niten 1ac5d81fc3 Keep dhparams so we don't have to regenerate 2023-09-26 23:16:00 -07:00
niten d8976486dc Port-forward imap, smtp, submission 2023-09-26 23:11:04 -07:00
niten 6328946703 Another try at building sieves 2023-09-26 15:55:03 -07:00
niten a78e03a374 Add 'with pkgs;' 2023-09-26 15:38:53 -07:00
niten 6ad453e3e0 Fixes to sieve generation 2023-09-26 15:30:38 -07:00