| >> HOME >> FC5 MENU >> メールサーバー間通信暗号化 (OpenSSL) |
 |
|
|
|
|
|
|
|
|
|
|
| |
|
|
|
|
|
| |
|
|
|
|
|
| |
|
|
| |
[root@linux ~]# vi /etc/postfix/main.cf
smtpd_tls_cert_file = /etc/postfix/server.crt
smtpd_tls_key_file = /etc/postfix/server.key
smtpd_tls_session_cache_database = btree:/etc/postfix/smtpd_scache
smtpd_use_tls = yes
|
|
|
| |
|
|
| |
[root@linux ~]# vi /etc/postfix/master.cf
#
# ==========================================================================
# service type private unpriv chroot wakeup maxproc command + args
# (yes) (yes) (yes) (never) (100)
# ==========================================================================
smtp inet n - n - - smtpd
#submission inet n - n - - smtpd
# -o smtpd_etrn_restrictions=reject
# -o smtpd_client_restrictions=permit_sasl_authenticated,reject
smtps inet n - n - - smtpd
-o smtpd_tls_wrappermode=yes -o smtpd_sasl_auth_enable=yes
#submission inet n - n - - smtpd
# -o smtpd_etrn_restrictions=reject
# -o smtpd_enforce_tls=yes -o smtpd_sasl_auth_enable=yes
#628 inet n - n - - qmqpd
pickup fifo n - n 60 1 pickup
cleanup unix n - n - 0 cleanup
qmgr fifo n - n 300 1 qmgr
#qmgr fifo n - n 300 1 oqmgr
tlsmgr unix - - n 1000? 1 tlsmgr
rewrite unix - - n - - trivial-rewrite
bounce unix - - n - 0 bounce
|
|
|
| |
|
|
| |
[root@linux ~]# ln -s /etc/httpd/conf/server.crt /etc/postfix/server.crt
[root@linux ~]# ln -s /etc/httpd/conf/server.key /etc/postfix/server.key
[root@linux ~]# ls -l /etc/postfix
:
lrwxrwxrwx 1 root root 26 7月 7 14:30 server.crt -> /etc/httpd/conf/server.crt
lrwxrwxrwx 1 root root 26 7月 7 14:30 server.key -> /etc/httpd/conf/server.key
:
|
|
|
|
|
|
| |
|
|
| |
[root@linux ~]# vi /etc/dovecot.conf
# Disable SSL/TLS support.
ssl_disable = no
# PEM encoded X.509 SSL/TLS certificate and private key. They're opened before
# dropping root privileges, so keep the key file unreadable by anyone but
# root. Included doc/mkcert.sh can be used to easily generate self-signed
# certificate, just make sure to update the domains in dovecot-openssl.cnf
#ssl_cert_file = /etc/pki/dovecot/certs/dovecot.pem
#ssl_key_file = /etc/pki/dovecot/private/dovecot.pem
ssl_cert_file = /etc/postfix/server.crt
ssl_key_file = /etc/postfix/server.key
|
|
|
|
|
|
| |
|
|
| |
[root@linux ~]# service postfix restart
Shutting down postfix: [ OK ]
Starting postfix: [ OK ]
|
|
|
| |
|
|
| |
[root@linux ~]# service dovecot restart
Dovecot Imapを停止中: [ OK ]
Dovecot Imap を起動中: [ OK ]
|
|
|
|
|
|
| |
|
|
|
|
|
| |
|
|
 |
|
 |
 |