Postfix中针对特定外发域禁用TLS的实现方法咨询
问题描述
Is there a way we can disable TLS for a particular domain, the global setting for outgoing SMTP is encrypt.
We have an ipsec tunnel to the destination and they dont have TLS enabled at their end.
Postfix server tls settings:
smtp_tls_security_level = encryptThe destination is configured in Transport file:
example.com smtp:[10.1.1.100]:25
解决方案
当然可以实现!Postfix提供了smtp_tls_policy_maps配置项,允许你针对特定域名或目标IP覆盖全局的TLS安全策略,具体操作步骤如下:
步骤1:创建TLS策略映射文件
在Postfix配置目录下新建一个映射文件(比如/etc/postfix/tls_policy),添加针对目标的TLS禁用规则,两种方式可选:- 直接针对域名
example.com设置:example.com none - 针对Transport中指定的IP地址(更精准,避免域名解析变动影响):
[10.1.1.100]:25 none
这里的
none表示强制禁用TLS加密,Postfix不会尝试与对方建立TLS连接。- 直接针对域名
步骤2:更新Postfix主配置文件
编辑/etc/postfix/main.cf,添加或修改以下配置项:smtp_tls_policy_maps = hash:/etc/postfix/tls_policy步骤3:生成哈希数据库文件
Postfix需要读取哈希格式的映射文件,执行命令生成:postmap /etc/postfix/tls_policy步骤4:重启Postfix服务生效
根据你的操作系统选择对应命令重启服务:# 适用于systemd架构系统(如Ubuntu 18.04+、CentOS 7+) systemctl restart postfix # 适用于SysVinit架构系统 service postfix restart
原理说明
全局配置smtp_tls_security_level = encrypt要求所有外发SMTP连接必须使用TLS加密,而smtp_tls_policy_maps定义的规则优先级高于全局设置,这样既能保证其他域名的加密要求不受影响,又能让通过IPsec隧道通信的目标域正常收发邮件。
备注:内容来源于stack exchange,提问作者sunny_hkhk

