FreeBSD ➔ Dovecot


Writing Icon

Lizenz: Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0)
Letzte Aktualisierung:
Veröffentlicht:
Verfasser: Markus Kohlmeyer
Beitragender: Jesco Freund


Zu den Voraussetzungen für dieses HowTo siehe bitte: FreeBSD ➔ WebHosting System ➔ Voraussetzungen

Einleitung

Unser WebHosting System wird um folgende Dienste erweitert.

  • Dovecot 2.3.1 (IMAP only, 1GB Quota)

Installation

Wir installieren mail/dovecot und dessen Abhängigkeiten.

mkdir -p /var/db/ports/mail_dovecot
cat > /var/db/ports/mail_dovecot/options << "EOF"
_OPTIONS_READ=dovecot-2.3.1
_FILE_COMPLETE_OPTIONS_LIST=LIBWRAP LUA LZ4 VPOPMAIL CDB LDAP MYSQL PGSQL SQLITE ICU LUCENE SOLR TEXTCAT
OPTIONS_FILE_UNSET+=LIBWRAP
OPTIONS_FILE_UNSET+=LUA
OPTIONS_FILE_SET+=LZ4
OPTIONS_FILE_UNSET+=VPOPMAIL
OPTIONS_FILE_UNSET+=CDB
OPTIONS_FILE_UNSET+=LDAP
OPTIONS_FILE_UNSET+=MYSQL
OPTIONS_FILE_UNSET+=PGSQL
OPTIONS_FILE_UNSET+=SQLITE
OPTIONS_FILE_SET+=ICU
OPTIONS_FILE_UNSET+=LUCENE
OPTIONS_FILE_UNSET+=SOLR
OPTIONS_FILE_SET+=TEXTCAT
"EOF"

cd /usr/ports/mail/dovecot
make config-recursive all install clean-depends clean

echo 'dovecot_enable="YES"' >> /etc/rc.conf

Konfiguration

dovecot.conf einrichten.

cat > /usr/local/etc/dovecot/dovecot.conf << "EOF"
auth_mechanisms = plain login
auth_verbose = yes
first_valid_gid = 5000
first_valid_uid = 5000
hostname = mail.example.com
imap_client_workarounds = delay-newmail tb-extra-mailbox-sep tb-lsub-flags
last_valid_gid = 5000
last_valid_uid = 5000
lda_mailbox_autocreate = yes
lda_mailbox_autosubscribe = yes
lda_original_recipient_header = X-Original-To
listen = * [::]
login_log_format_elements = user=<%u> method=%m rip=%r lip=%l mpid=%e %c %k session=<%{session}>
mail_location = maildir:/data/vmail/%d/%n
namespace inbox {
  inbox = yes
  mailbox Archives {
    auto = subscribe
    special_use = \Archive
  }
  mailbox Drafts {
    auto = subscribe
    special_use = \Drafts
  }
  mailbox Junk {
    auto = subscribe
    special_use = \Junk
  }
  mailbox Sent {
    auto = subscribe
    special_use = \Sent
  }
  mailbox Trash {
    auto = subscribe
    special_use = \Trash
  }
}
passdb {
  args = scheme=ssha512 username_format=%u /usr/local/etc/dovecot/passwd
  default_fields = uid=5000 gid=5000 home=/data/vmail/%d/%n
  driver = passwd-file
  override_fields = uid=5000 gid=5000 home=/data/vmail/%d/%n
}
plugin {
  quota = maildir:User quota
  quota_rule = *:storage=1G
  quota_rule2 = Archive:storage=+1G
}
pop3_client_workarounds = outlook-no-nuls oe-ns-eoh
postmaster_address = postmaster@example.com
protocol imap {
  mail_plugins = quota imap_quota
}
protocol pop3 {
  mail_plugins = quota
}
protocols = imap lmtp
quota_full_tempfail = yes
service auth {
  unix_listener /var/spool/postfix/private/auth {
    group = postfix
    mode = 0660
    user = postfix
  }
}
service imap-login {
  inet_listener imap {
    port = 0
  }
  inet_listener imaps {
    port = 993
  }
  process_min_avail = 2
}
service pop3-login {
  inet_listener pop3 {
    port = 0
  }
  inet_listener pop3s {
    port = 0
  }
}
ssl = required
ssl_cert = </data/pki/certs/mail.example.com.crt
ssl_cipher_list = EECDH+ECDSA+CHACHA20 EECDH+CHACHA20 EECDH+ECDSA+AESGCM+AES256 EECDH+AESGCM+AES256 EECDH+ECDSA+AESGCM+AES128 EECDH+AESGCM+AES128 EECDH+ECDSA+AES256+SHA384 EECDH+AES256+SHA384 EECDH+ECDSA+AES128+SHA256 EECDH+AES128+SHA256 EECDH+ECDSA+AES256+SHA1 EECDH+AES256+SHA1 EECDH+ECDSA+AES128+SHA1 EECDH+AES128+SHA1 EDH+CHACHA20 EDH+AESGCM+AES256 EDH+AESGCM+AES128 EDH+AES256+SHA256 EDH+AES128+SHA256 EDH+AES256+SHA1 EDH+AES128+SHA1 !CAMELLIA !SEED !IDEA !RC2 !RC4 !3DES !DES !kRSA !kSRP !kPSK !kGOST !kECDHr !kECDHe !kDHr !kDHd !aDSS !aNULL !eNULL !MEDIUM !LOW !EXPORT
ssl_dh = </usr/local/etc/dovecot/dh.pem
ssl_key = </data/pki/private/mail.example.com.key
ssl_min_protocol = TLSv1.2
ssl_prefer_server_ciphers = yes
userdb {
  args = username_format=%u /usr/local/etc/dovecot/passwd
  default_fields = uid=5000 gid=5000 home=/data/vmail/%d/%n
  driver = passwd-file
  override_fields = uid=5000 gid=5000 home=/data/vmail/%d/%n
}
"EOF"

/usr/local/etc/dovecot/dh.pem erzeugen.

/usr/local/bin/openssl dhparam 4096 > /usr/local/etc/dovecot/dh.pem

/usr/local/etc/dovecot/passwd einrichten.

Das Anlegen neuer Mailuser wird mittels Script automatisiert.

cat > /usr/local/etc/dovecot/create_mailuser.sh << "EOF"
#!/bin/sh

dovecot_user="${1}"
dovecot_pass="`openssl rand -hex 64 | openssl passwd -1 -stdin | tr -cd '[[:alnum:]]' | cut -c 2-13`"
dovecot_hash="`echo ${dovecot_pass} | xargs -I % doveadm pw -s SSHA512 -p %`"
echo "Password for ${dovecot_user} is: ${dovecot_pass}"
echo "${dovecot_user}:${dovecot_hash}:5000:5000::/data/vmail/%d/%n::" >> /usr/local/etc/dovecot/passwd
"EOF"

chmod 0755 /usr/local/etc/dovecot/create_mailuser.sh

# admin@example.com anlegen
/usr/local/etc/dovecot/create_mailuser.sh admin@example.com

Abschluss

Dovecot kann nun gestartet werden.

service dovecot start

Über den Autor