11alias_maps = hash:/etc/aliases, hash:/var/lib/mailman/data/aliases
22alias_database = hash:/etc/aliases, hash:/var/lib/mailman/data/aliases
33virtual_alias_domains = proxy:mysql:{config_dir}/mysql-virtual_alias_domains.cf
4- virtual_alias_maps = hash:/var/lib/mailman/data/virtual-mailman, proxy:mysql:{config_dir}/mysql-virtual_forwardings.cf, proxy:mysql:{config_dir}/mysql-virtual_alias_domains .cf, proxy:mysql:{config_dir}/mysql-virtual_email2email.cf
4+ virtual_alias_maps = hash:/var/lib/mailman/data/virtual-mailman, proxy:mysql:{config_dir}/mysql-virtual_forwardings.cf, proxy:mysql:{config_dir}/mysql-virtual_alias_maps .cf, proxy:mysql:{config_dir}/mysql-virtual_email2email.cf
55virtual_mailbox_domains = proxy:mysql:{config_dir}/mysql-virtual_domains.cf
66virtual_mailbox_maps = proxy:mysql:{config_dir}/mysql-virtual_mailboxes.cf
77virtual_mailbox_base = {vmail_mailbox_base}
@@ -14,7 +14,7 @@ smtpd_sasl_auth_enable = yes
1414broken_sasl_auth_clients = yes
1515smtpd_sasl_authenticated_header = yes
1616smtpd_restriction_classes = greylisting
17- greylisting = check_policy_service inet:127.0.0.1:10023
17+ greylisting = check_policy_service inet:127.0.0.1:10023
1818smtpd_recipient_restrictions = permit_mynetworks, reject_unknown_recipient_domain, check_recipient_access proxy:mysql:{config_dir}/mysql-verify_recipients.cf, permit_sasl_authenticated, reject_non_fqdn_recipient, reject_unauth_destination, check_recipient_access proxy:mysql:{config_dir}/mysql-virtual_recipient.cf{rbl_list}{greylisting}, check_policy_service unix:private/quota-status
1919smtpd_use_tls = yes
2020smtpd_tls_security_level = may
@@ -39,10 +39,13 @@ nested_header_checks = regexp:{config_dir}/nested_header_checks
3939body_checks = regexp:{config_dir}/body_checks
4040owner_request_special = no
4141smtp_tls_security_level = may
42- smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3
43- smtpd_tls_protocols = !SSLv2,!SSLv3
44- smtp_tls_protocols = !SSLv2,!SSLv3
42+ smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
43+ smtpd_tls_protocols = !SSLv2,!SSLv3, !TLSv1, !TLSv1.1
44+ smtp_tls_protocols = !SSLv2,!SSLv3, !TLSv1, !TLSv1.1
4545smtpd_tls_exclude_ciphers = RC4, aNULL
4646smtp_tls_exclude_ciphers = RC4, aNULL
47+ smtpd_tls_mandatory_ciphers = medium
48+ tls_medium_cipherlist = ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
49+ tls_preempt_cipherlist = no
4750# needed for postfix < 3.3 when using reject_unverified_recipient (lmtp):
4851enable_original_recipient = yes
0 commit comments