You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Postfix/Dovecot环境下Thunderbird获取Apache默认SSL证书而非mail.domain.cl证书的问题求助

Postfix/Dovecot环境下Thunderbird获取Apache默认SSL证书而非mail.domain.cl证书的问题求助

我已经被这个问题困扰一段时间了。我希望Thunderbird能获取mail.domain.cl的SSL证书,但它总是拿到domain.cl的证书。

经过一系列测试,我发现了这些现象:

  • 邮件客户端获取的是Apache提供的默认证书,而非Postfix/Dovecot应该返回的证书
  • 完全禁用Apache2后问题直接解决;逐个禁用Apache站点时,它会获取下一个站点的证书
  • 为mail.domain.cl创建Apache虚拟主机后,服务器会返回该主机的证书,但Thunderbird仍然提示证书对应错误的域名——即使它自动检测到收发服务器是mail.domain.cl,还是尝试获取domain.cl的证书
  • 其他邮件客户端也有类似问题,只有完全禁用Apache才能拿到正确证书

我的Apache SNI配置看起来没问题,DNS也正常:

  • mail.domain.cl有指向服务器IP的A记录
  • domain.cl的A记录正常工作
  • 还有指向服务器IP的反向DNS记录

我试过为mail.domain.cl创建虚拟主机,配置如下:

<VirtualHost *:443>
ServerName mail.domain.cl
SSLEngine on
SSLCertificateFile /home/domain/.certs/mail.domain.cl/mail.domain.cl.crt
SSLCertificateKeyFile /home/domain/.certs/mail.domain.cl/mail.domain.cl.key
SSLCertificateChainFile /home/domain/.certs/mail.domain.cl/mail.domain.cl.fullchain.crt
Redirect 403 /
ErrorDocument 403 "Acceso Denegado"
</VirtualHost>

但Thunderbird添加邮箱账户时还是尝试从根域名获取证书,这很奇怪。邮件能正常工作,但以后给客户创建新账户时会有问题——它应该从mail.domain.cl获取证书,而不是domain.cl。

查看Apache日志时,我发现Thunderbird尝试获取自动配置文件:

207.248.203.238 - - [29/Jan/2024:02:15:37 +0000] "GET /.well-known/autoconfig/mail/config-v1.1.xml?emailaddress=jairo%40domain.cl HTTP/1.1" 404 491 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Thunderbird/115.7.0"
207.248.203.238 - - [29/Jan/2024:02:16:50 +0000] "GET /.well-known/autoconfig/mail/config-v1.1.xml?emailaddress=jairo%40domain.cl HTTP/1.1" 404 491 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Thunderbird/115.7.0"
207.248.203.238 - - [29/Jan/2024:02:17:49 +0000] "GET /.well-known/autoconfig/mail/config-v1.1.xml?emailaddress=jairo%40domain.cl HTTP/1.1" 404 491 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:115.0) Gecko/20100101 Thunderbird/115.7.0"

它找不到这个自动配置XML文件,不知道这和当前问题有没有关联。

相关配置文件

Postfix main.cf配置

# Debian specific:  Specifying a file name will cause the first
# line of that file to be used as the name.  The Debian default
# is /etc/mailname.
#myorigin = /etc/mailname

smtpd_banner = $myhostname ESMTP $mail_name (Ubuntu)
biff = no

# appending .domain is the MUA's job.
append_dot_mydomain = no

# Uncomment the next line to generate "delayed mail" warnings
#delay_warning_time = 4h

readme_directory = no

# See http://www.postfix.org/COMPATIBILITY_README.html -- default to 3.6 on
# fresh installs.
compatibility_level = 3.6

# TLS parameters
smtpd_tls_cert_file=/etc/ssl/certs/postfix.fullchain.crt
smtpd_tls_key_file=/etc/ssl/private/postfix.key
smtpd_use_tls = yes
smtpd_tls_security_level=may
smtp_tls_CApath=/etc/ssl/certs
smtp_tls_security_level=may
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache

smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_unauth_destination

myhostname = mail.domain.cl
mydomain = domain.cl
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases
myorigin = $mydomain
mydestination = $myhostname, localhost.$mydomain, $mydomain, ubuntu-intelsoft, localhost
relayhost =
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
mailbox_size_limit = 0
recipient_delimiter = +

inet_interfaces = all
inet_protocols = all

smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_auth_enable = yes

smtpd_recipient_restrictions =
permit_mynetworks,
permit_sasl_authenticated,
reject_unauth_destination

mua_client_restrictions = permit_sasl_authenticated, reject
mua_helo_restrictions = permit_sasl_authenticated, reject
mua_sender_restrictions = permit_sasl_authenticated, reject

# Milter configuration for OpenDKIM
milter_protocol = 6
milter_default_action = accept
smtpd_milters = inet:localhost:8891
non_smtpd_milters = $smtpd_milters

Dovecot conf.d/10-ssl.conf配置

##
## SSL settings
##

# SSL/TLS support: yes, no, required. <doc/wiki/SSL.txt>
ssl = yes

# PEM encoded X.509 SSL/TLS certificate and private key. They're opened before
# dropping root privileges, so keep the key file unreadable by anyone but
# root. Included doc/mkcert.sh can be used to easily generate self-signed
# certificate, just make sure to update the domains in dovecot-openssl.cnf
ssl_cert = </etc/ssl/certs/postfix.fullchain.crt
ssl_key = </etc/ssl/private/postfix.key

# If key file is password protected, give the password here. Alternatively
# give it when starting dovecot with -p parameter. Since this file is often
# world-readable, you may want to place this setting instead to a different
# root owned 0600 file by using ssl_key_password = <path.
#ssl_key_password =

# PEM encoded trusted certificate authority. Set this only if you intend to use
# ssl_verify_client_cert=yes. The file should contain the CA certificate(s)
# followed by the matching CRL(s). (e.g. ssl_ca = </etc/ssl/certs/ca.pem)
#ssl_ca =

# Require that CRL check succeeds for client certificates.
#ssl_require_crl = yes

# Directory and/or file for trusted SSL CA certificates. These are used only
# when Dovecot needs to act as an SSL client (e.g. imapc backend or
# submission service). The directory is usually /etc/ssl/certs in
# Debian-based systems and the file is /etc/pki/tls/cert.pem in
# RedHat-based systems. Note that ssl_client_ca_file isn't recommended with
# large CA bundles, because it leads to excessive memory usage.
#ssl_client_ca_dir =
ssl_client_ca_dir = /etc/ssl/certs
#ssl_client_ca_file =

# Require valid cert when connecting to a remote server
#ssl_client_require_valid_cert = yes

# Request client to send a certificate. If you also want to require it, set
# auth_ssl_require_client_cert=yes in auth section.
#ssl_verify_client_cert = no

# Which field from certificate to use for username. commonName and
# x500UniqueIdentifier are the usual choices. You'll also need to set
# auth_ssl_username_from_cert=yes.
#ssl_cert_username_field = commonName

# SSL DH parameters
# Generate new params with `openssl dhparam -out /etc/dovecot/dh.pem 4096`
# Or migrate from old ssl-parameters.dat file with the command dovecot
# gives on startup when ssl_dh is unset.
ssl_dh = </usr/share/dovecot/dh.pem

# Minimum SSL protocol version to use. Potentially recognized values are SSLv3,
# TLSv1, TLSv1.1, TLSv1.2 and TLSv1.3, depending on the OpenSSL version used.
#
# Dovecot also recognizes values ANY and LATEST. ANY matches with any protocol
# version, and LATEST matches with the latest version supported by library.
#ssl_min_protocol = TLSv1.2

# SSL ciphers to use, the default is:
#ssl_cipher_list = ALL:!kRSA:!SRP:!kDHd:!DSS:!aNULL:!eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK:!RC4:!ADH:!LOW@STRENGTH
# To disable non-EC DH, use:
#ssl_cipher_list = ALL:!DH:!kRSA:!SRP:!kDHd:!DSS:!aNULL:!eNULL:!EXPORT:!DES:!3DES:!MD5:!PSK:!RC4:!ADH:!LOW@STRENGTH

# Colon separated list of elliptic curves to use. Empty value (the default)
# means use the defaults from the SSL library. P-521:P-384:P-256 would be an
# example of a valid value.
#ssl_curve_list =

# Prefer the server's order of ciphers over client's.
#ssl_prefer_server_ciphers = no

# SSL crypto device to use, for valid values run "openssl engine"
#ssl_crypto_device =

# SSL extra options. Currently supported options are:
#   compression - Enable compression.
#   no_ticket - Disable SSL session tickets.
#ssl_options =

doveconf -n输出

# 2.3.16 (7e2e900c1a): /etc/dovecot/dovecot.conf
# Pigeonhole version 0.5.16 (09c29328)
# OS: Linux 5.15.0-92-generic x86_64 Ubuntu 22.04.3 LTS
# Hostname: ubuntu-intelsoft
mail_location = mbox:~/mail:INBOX=/var/mail/%u
mail_privileged_group = mail
namespace inbox {
  inbox = yes
  location =
  mailbox Drafts {
    special_use = \Drafts
  }
  mailbox Junk {
    special_use = \Junk
  }
  mailbox Sent {
    special_use = \Sent
  }
  mailbox "Sent Messages" {
    special_use = \Sent
  }
  mailbox Trash {
    special_use = \Trash
  }
  prefix =
}
passdb {
  driver = pam
}
protocols = " imap"
service auth {
  unix_listener /var/spool/postfix/private/auth {
    group = postfix
    mode = 0666
    user = postfix
  }
}
service imap-login {
  inet_listener imaps {
    port = 993
    ssl = yes
  }
}
ssl_cert = </etc/ssl/certs/postfix.fullchain.crt
ssl_client_ca_dir = /etc/ssl/certs
ssl_dh = # hidden, use -P to show it
ssl_key = # hidden, use -P to show it
userdb {
  driver = passwd
}

如前所述,禁用Apache后Thunderbird或其他邮件客户端都能拿到正确证书,没有错误;启用Apache就会显示domain.cl的过期证书。我现在考虑干脆创建另一个服务器,把Apache完全从mail.domain.cl所在的服务器移除。

有没有更好的办法让邮件客户端能获取到正确的证书?

备注:内容来源于stack exchange,提问作者Jairo Alarcón

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 11:13:10