Skip to content

Commit fef8248

Browse files
author
Marius Cramer
committed
Merge branch 'master' into 'master'
Master See merge request !119
2 parents c56175b + 1653995 commit fef8248

File tree

2 files changed

+105
-3
lines changed

2 files changed

+105
-3
lines changed

interface/web/mail/mail_domain_edit.php

Lines changed: 94 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -282,6 +282,37 @@ function onAfterInsert() {
282282
unset($tmp_domain);
283283
}
284284
} // endif spamfilter policy
285+
286+
//* create dns-record with dkim-values if the zone exists
287+
if ( (isset($this->dataRecord['dkim']) && $this->dataRecord['dkim'] == 'y') && (isset($this->dataRecord['active']) && $this->dataRecord['active'] == 'y') ) {
288+
$soa_rec = $app->db->queryOneRecord("SELECT id AS zone, sys_userid, sys_groupid, sys_perm_user, sys_perm_group, sys_perm_other, server_id, ttl, serial FROM dns_soa WHERE active = 'Y' AND origin = ?", $this->dataRecord['domain'].'.');
289+
if ( isset($soa_rec) ) {
290+
//* check for a dkim-record in the dns
291+
$dns_data = $app->db->queryOneRecord("SELECT * FROM dns_rr WHERE name = ? AND sys_groupid = ?", $this->dataRecord['dkim_selector'].'._domainkey.'.$this->dataRecord['domain'].'.', $_SESSION["s"]["user"]['sys_groupid']);
292+
if ( isset($dns_data) ) {
293+
$dns_data['data'] = 'v=DKIM1; t=s; p='.str_replace(array('-----BEGIN PUBLIC KEY-----','-----END PUBLIC KEY-----',"\r","\n"), '', $this->dataRecord['dkim_public']);
294+
$dns_data['active'] = 'Y';
295+
$dns_data['stamp'] = date('Y-m-d H:i:s');
296+
$dns_data['serial'] = $app->validate_dns->increase_serial($dns_data['serial']);
297+
$app->db->datalogUpdate('dns_rr', $dns_data, 'id', $dns_data['id']);
298+
$zone = $app->db->queryOneRecord("SELECT id, serial FROM dns_soa WHERE active = 'Y' AND id = ?", $dns_data['zone']);
299+
$new_serial = $app->validate_dns->increase_serial($zone['serial']);
300+
$app->db->datalogUpdate('dns_soa', "serial = '".$new_serial."'", 'id', $zone['id']);
301+
} else { //* no dkim-record found - create new record
302+
$dns_data = $app->db->queryOneRecord("SELECT id AS zone, sys_userid, sys_groupid, sys_perm_user, sys_perm_group, sys_perm_other, server_id, ttl, serial FROM dns_soa WHERE active = 'Y' AND origin = ?", $this->dataRecord['domain'].'.');
303+
$dns_data['name'] = $this->dataRecord['dkim_selector'].'._domainkey.'.$this->dataRecord['domain'].'.';
304+
$dns_data['type'] = 'TXT';
305+
$dns_data['data'] = 'v=DKIM1; t=s; p='.str_replace(array('-----BEGIN PUBLIC KEY-----','-----END PUBLIC KEY-----',"\r","\n"), '', $this->dataRecord['dkim_public']);
306+
$dns_data['aux'] = 0;
307+
$dns_data['active'] = 'Y';
308+
$dns_data['stamp'] = date('Y-m-d H:i:s');
309+
$dns_data['serial'] = $app->validate_dns->increase_serial($dns_data['serial']);
310+
$app->db->datalogInsert('dns_rr', $dns_data, 'id', $dns_data['zone']);
311+
$new_serial = $app->validate_dns->increase_serial($soa_rec['serial']);
312+
$app->db->datalogUpdate('dns_soa', "serial = '".$new_serial."'", 'id', $soa_rec['zone']);
313+
}
314+
}
315+
} //* endif add dns-record
285316
}
286317

287318
function onBeforeUpdate() {
@@ -308,6 +339,69 @@ function onBeforeUpdate() {
308339
}
309340
unset($rec);
310341
}
342+
343+
//* update dns-record when the dkim record was changed
344+
// NOTE: only if the domain-name was not changed
345+
346+
//* get domain-data from the db
347+
$mail_data = $app->db->queryOneRecord("SELECT * FROM mail_domain WHERE domain = ?", $this->dataRecord['domain']);
348+
349+
if ( isset($mail_data) ) {
350+
$post_data = $mail_data;
351+
$post_data['dkim_selector'] = $this->dataRecord['dkim_selector'];
352+
$post_data['dkim_public'] = $this->dataRecord['dkim_public'];
353+
$post_data['dkim_private'] = $this->dataRecord['dkim_private'];
354+
if ( isset($this->dataRecord['dkim']) ) $post_data['dkim'] = 'y'; else $post_data['dkim'] = 'n';
355+
if ( isset($this->dataRecord['active']) ) $post_data['active'] = 'y'; else $post_data['active'] = 'n';
356+
}
357+
358+
//* dkim-value changed
359+
if ( $mail_data != $post_data ) {
360+
//* get the dns-record for the public from the db
361+
$dns_data = $app->db->queryOneRecord("SELECT * FROM dns_rr WHERE name = ? AND sys_groupid = ?'", $mail_data['dkim_selector'].'._domainkey.'.$mail_data['domain'].'.', $mail_data['sys_groupid']);
362+
363+
//* we modify dkim dns-values for active mail-domains only
364+
if ( $post_data['active'] == 'y' ) {
365+
if ( $post_data['dkim'] == 'n' ) {
366+
$new_dns_data['active'] = 'N';
367+
} else {
368+
if ( $post_data['dkim_selector'] != $mail_data['dkim_selector'] )
369+
$new_dns_data['name'] = $post_data['dkim_selector'].'._domainkey.'.$post_data['domain'].'.';
370+
if ( $post_data['dkim'] != $mail_data['dkim'] )
371+
$new_dns_data['active'] = 'Y';
372+
if ( $post_data['active'] != $mail_data['active'] && $post_data['active'] == 'y' )
373+
$new_dns_data['active'] = 'Y';
374+
if ( $post_data['dkim_public'] != $mail_data['dkim_public'] )
375+
$new_dns_data['data'] = 'v=DKIM1; t=s; p='.str_replace(array('-----BEGIN PUBLIC KEY-----','-----END PUBLIC KEY-----',"\r","\n"), '', $post_data['dkim_public']);
376+
}
377+
} else $new_dns_data['active'] = 'N';
378+
379+
if ( isset($dns_data) && isset($new_dns_data) ) {
380+
//* update dns-record
381+
$new_dns_data['serial'] = $app->validate_dns->increase_serial($dns_data['serial']);
382+
$app->db->datalogUpdate('dns_rr', $new_dns_data, 'id', $dns_data['id']);
383+
$zone = $app->db->queryOneRecord("SELECT id, serial FROM dns_soa WHERE active = 'Y' AND id = ?", $dns_data['zone']);
384+
$new_serial = $app->validate_dns->increase_serial($zone['serial']);
385+
$app->db->datalogUpdate('dns_soa', "serial = '".$new_serial."'", 'id', $zone['id']);
386+
} else {
387+
//* create a new dns-record
388+
$new_dns_data = $app->db->queryOneRecord("SELECT id AS zone, sys_userid, sys_groupid, sys_perm_user, sys_perm_group, sys_perm_other, server_id, ttl, serial FROM dns_soa WHERE active = 'Y' AND origin = ?", $mail_data['domain'].'.');
389+
//* create a new record only if the dns-zone exists
390+
if ( isset($new_dns_data) && $post_data['dkim'] == 'y' ) {
391+
$new_dns_data['name'] = $post_data['dkim_selector'].'._domainkey.'.$post_data['domain'].'.';
392+
$new_dns_data['type'] = 'TXT';
393+
$new_dns_data['data'] = 'v=DKIM1; t=s; p='.str_replace(array('-----BEGIN PUBLIC KEY-----','-----END PUBLIC KEY-----',"\r","\n"), '', $post_data['dkim_public']);
394+
$new_dns_data['aux'] = 0;
395+
$new_dns_data['active'] = 'Y';
396+
$new_dns_data['stamp'] = date('Y-m-d H:i:s');
397+
$new_dns_data['serial'] = $app->validate_dns->increase_serial($new_dns_data['serial']);
398+
$app->db->datalogInsert('dns_rr', $new_dns_data, 'id', $new_dns_data['zone']);
399+
$zone = $app->db->queryOneRecord("SELECT id, serial FROM dns_soa WHERE active = 'Y' AND id = ?", $new_dns_data['zone']);
400+
$new_serial = $app->validate_dns->increase_serial($zone['serial']);
401+
$app->db->datalogUpdate('dns_soa', "serial = '".$new_serial."'", 'id', $zone['id']);
402+
}
403+
}
404+
} //* endif $mail_data != $post_data
311405
}
312406

313407
function onAfterUpdate() {

server/plugins-available/mail_plugin_dkim.inc.php

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -119,8 +119,12 @@ function check_system($data) {
119119
}
120120
/* dir for dkim-keys writeable? */
121121
$mail_config = $app->getconf->get_server_config($conf['server_id'], 'mail');
122-
if (isset($mail_config['dkim_path']) && (!empty($mail_config['dkim_path'])) && isset($data['new']['dkim_private']) && !empty($data['new']['dkim_private'])) {
123-
122+
if ( isset($mail_config['dkim_path']) &&
123+
!empty($mail_config['dkim_path']) &&
124+
isset($data['new']['dkim_private']) &&
125+
!empty($data['new']['dkim_private']) &&
126+
$mail_config['dkim_path'] != '/'
127+
) {
124128
if (!is_dir($mail_config['dkim_path'])) {
125129
$app->log('DKIM Path '.$mail_config['dkim_path'].' not found - (re)created.', LOGLEVEL_DEBUG);
126130
if($app->system->is_user('amavis')) {
@@ -133,10 +137,12 @@ function check_system($data) {
133137
}
134138
if(!empty($amavis_user)) {
135139
mkdir($mail_config['dkim_path'], 0750, true);
136-
exec('chown '.$amavis_user.' /var/lib/amavis/dkim');
140+
exec('chown '.$amavis_user.' '.escapeshellarg($mail_config['dkim_path']));
137141
unset($amavis_user);
138142
} else {
139143
mkdir($mail_config['dkim_path'], 0755, true);
144+
$app->log('No user amavis or vscan found - using root for '.$mail_config['dkim_path']
145+
, LOGLEVEL_WARNING);
140146
}
141147
}
142148

@@ -194,6 +200,8 @@ function write_dkim_key($key_file, $key_value, $key_domain) {
194200
if (!file_put_contents($key_file.'.public', $public_key) === false)
195201
$app->log('Saved DKIM Public to '.$key_domain.'.', LOGLEVEL_DEBUG);
196202
else $app->log('Unable to save DKIM Public to '.$key_domain.'.', LOGLEVEL_DEBUG);
203+
} else {
204+
$app->log('Unable to save DKIM Privte-key to '.$key_file.'.private', LOGLEVEL_ERROR);
197205
}
198206
return $success;
199207
}

0 commit comments

Comments
 (0)