From 6a827cba442a70a28ef444207535763dc8584784 Mon Sep 17 00:00:00 2001 From: Christoph Date: Thu, 8 Jan 2026 13:49:40 +0100 Subject: [PATCH] install_postfix_advanced.sh,install_postfix_base.sh: comment deprecated parameter 'smtpd_tls_dh1024_param_file'. --- DOC/DMARC_Rejections_SOP.md | 36 +++++++++++++++++++++++++++++++++++ DOC/DMARC_Rejections_SOP.pdf | Bin 0 -> 24002 bytes install_postfix_advanced.sh | 4 +++- install_postfix_base.sh | 4 +++- 4 files changed, 42 insertions(+), 2 deletions(-) create mode 100644 DOC/DMARC_Rejections_SOP.md create mode 100644 DOC/DMARC_Rejections_SOP.pdf diff --git a/DOC/DMARC_Rejections_SOP.md b/DOC/DMARC_Rejections_SOP.md new file mode 100644 index 0000000..22c5034 --- /dev/null +++ b/DOC/DMARC_Rejections_SOP.md @@ -0,0 +1,36 @@ +# Analyse und Begründung von DMARC-Rejects +## (Postfix + OpenDMARC 1.4.2) + +### 1. Zweck +Diese SOP beschreibt, wie DMARC-Rejects auf dem Mailserver revisionssicher analysiert und begründet werden, ohne die betroffene E-Mail anzunehmen oder erneut senden zu lassen. + +### 2. Systemkontext +- MTA: Postfix +- DMARC-Filter: OpenDMARC 1.4.2 +- SPF-Prüfung: policyd-spf +- DKIM-Prüfung: OpenDKIM +- Entscheidungspunkt: SMTP END-OF-MESSAGE + +### 3. Grundprinzip +OpenDMARC loggt nur das Endergebnis der DMARC-Evaluation, nicht die Detailursachen. Die Ursache eines Rejects wird durch Log-Korrelation ermittelt. + +### 4. Relevante Logquellen +- Postfix (SMTP-Rejects) +- policyd-spf (SPF-Ergebnis, identity) +- OpenDMARC (pass/fail/none pro Domain) + +### 5. Entscheidungslogik +DMARC besteht nur, wenn mindestens ein Mechanismus DMARC-konform erfolgreich ist: +- SPF(mailfrom) aligned +- DKIM valid + aligned + +SPF über HELO ist für DMARC nicht verwertbar. + +### 6. Ableitungsregel +Wenn SPF nur über HELO erfolgreich war und DMARC fail meldet, muss DKIM fehlgeschlagen sein. + +### 7. Revisionssichere Begründung +Die E-Mail wurde gemäß der DMARC-Policy der Absenderdomain abgelehnt, da keine DMARC-konforme Authentifizierung vorlag. + +### 8. Referenzen +RFC 7489 (DMARC), RFC 7208 (SPF), RFC 6376 (DKIM) diff --git a/DOC/DMARC_Rejections_SOP.pdf b/DOC/DMARC_Rejections_SOP.pdf new file mode 100644 index 0000000000000000000000000000000000000000..4b57178d637e6c422f368452be28347ff973e52d GIT binary patch literal 24002 zcmcG#b99~0+cz2;jjaYvV;hZaHr`=lTa6nuXl&a~W2cR6+cwWm)9(-ObDs6C^T*k1 z?S0>K&E=WQnk(}ea(Q7A-WpbcRzCI%)p21W)ZMrI~vMn-A|#t#e(A3nnI@xd8c z8NPbN^q-!&+87bj3jrJe7S<*}V*nE)dtzoFgW`V(u>21J5f=wBB?q8EIC>=kVh20N z*B2RL208{NIC=vBF(VxVFjj%Lr+|bKu`$5H{tpkp-kg|T*4oPG-~O=vRj&y&@8Do$ zXGKgeY~*BWV5BG}sQr)AZ2!ZDS6^Q}wllJF`0FygkhPTquxU@s`6mQ=MI(D_M>_*x zOpLGNp$JDWU}a?u>}PyU0+8RR_|rD|hahGLaD7!t|F0ze5f@Ve5Wgn+ zPvZZT383OvR#9MFf4D^1iP_&wh;k5f{EJ;(PT$PP;13Is{okqm6XvVGn#BLguCjn0l(o+w0c)yp2EFIUl+0!^qLjUKfc}>2Q*_#MRByslb@GT*{Ba613kJ@m*5q zb}rs7y3cL*9v{s=4pzk3Hqwl{gEsdr1imTn^v3$Cv`lXP;u3Sj@xxcyX_&-FjM9-^ z-qgA%DziUlQTxu3ZZ9pQ7>7&k@xvmTv`KIWA9`Tb2~K>$7isxB5k6o}DK%S(Jhh>Y zmj@={-hFlhI>GPfCAP{Z8*ce`BGa1%;kG;YKBC&<>dC&GoVY|hN9d3R5CJUR-4(>CURKnbAQN$ zh?|O*po6i?`|CImYvnlTNmwTqd8m+d7Y|7L1VV$7j^=g{UsoT%`+a5F>Mfqg_h#Ow zl<%66q`ML581=qmBr?!2=;_HI$$v_~2PN!gwOp5kAyh)>u;D_Mz6`@>F(OQxzuGxc z$CG!T)(zk6`xcX!cd-ga8?sx61BOPR7{3oMzhLx zhtoI`OWgL8V#VhGjN2+!NeAU^6LAj%`R47XuR+qm!i_vrL!r7!HL|G#C6sNLN9<~R zwOigtp`TMd_{5Xp6vTIgqph1ejny6R>|#|deY&Zso{EgFt}9FvCmpT=Jd4ti(~= z#31c48!737`!MKGE`GIg!d?aZq6gidat-l~7rXZBtU(m?x2qU0 z(Nd;8@GLW88+o7sE09Y1RZx9Pmy}|J|VKN`N;toaR0_RT8p2s*_Js56;`1ZwkMm> zBT1xDlH`Y3%=<(i%~zv**Gp{?sKP#~--BN>J6O(zCm?l~ktcI?F{vc1JPa16OEHhBLA1MAnMVe2N+Ep; z;;iQlHUQ28XJc6kaTvh^{%q-tV1Gns|5ALW3&AG8s!yTUt|zRYC3{MUu}r1^-jjiY zZdUkxJDFVtY@Nkf#p*nRQbh(m3_~ccj=1I7vKBRXnm!HFMg||%Cc?;_`f4Ru-**f{ z!7%J#ExkR)*;>^>l<F`-L0CvY7I& znd6|^`aRg}lBzN;D(Ro31w+iL$R|yE0l)SFrW)=7rYht1)zfe3oUu|Z-SHi-iSwGu z&ZyZJkeOki94dC(u~M~ki<-9(pJlzs>_n=M)e3#!Gbp%B)9bn)bDkd-Sus5jSy7Q7 zVzVIdWT$x@mkPj6)=ACKQ<2!1^ORpw8Q?Ni?P?j&HMYyqU{ zoPeosA()r5e@0Hd-pAFBX8J*JyAv6FvPTO$<99PdJJlYEed^yyGx$oR`$HtPR|o<{ zf&I# zI#SvIzhm>iSa6FC8=${9*v7@*p(5H|6xe)RNJuB910F8%hsKi)_%+%O4p$c|S^qx!EUxmuIktCUSooBFvE$V@(>~!i|Yt zgQ2M}thv;om+X^cm^@8CeSlhnpTR}Fw%qLCp_qDod-JjzK}u&w(Uv^=QN&)>U}t+awBAiaXqTeB%u!R- z0&3^_jr;f0zKgX;EFOMNW&FAq8fcw3;LLap5>5k3>yl0UF&DAHS7GiaAMHWNLd+Qg z%WZ0VKG>$4x7!bVolSmp0Yg(592HN5g{KSo@OZsYITUhuZmhQmPW#Z@%+6qndW{d6 zosb=-s7FuUye&-t%YD0mB1hGEZz)J_%`cm<<8#$tddy{vetR87F=z~C%m+!Q?t&8< z5ZrD^Bh~xlE8v>tZcY%eNG^J8zL0!p1UD$Yt$$mvlU``=Huy8`jQ7;m`$^BtZ?lkJk$6r%wjBad`7nLMQ%JgGY_E zx4%jHMzj!F|5_jfp^}!SR%+-$C7!55`dW?r5&x~{Sz;8b>USwP?WfM8ZSU;5Mq76) zt9Pzxb!baBqPIfiDpW~`9hFAJa5Xzr7G|LevR(pV+x^%H27vIUim;??+?ySw?Nz7n zNb7`sG>d!{_{43EyTD_i$!CVe4rPO5p7(?f{mtLNX2ZXZFLYM0>~$*z4p1gUci}IA z&+`<}|A=g7!iw+UL>imkU!-dPDBMc48H4oP=&b5sK|Al-JgsbC zwL0(GnY1jP8T~nIL#=bXvIa*WZz$zE2C>Fc8$~l#+#B%}i|=5}jMI5n&RcbVt*CAMUTa#TW%v<&E8XN-m z!;m%<0?}*iSG43vAeY>fbreDe>zIx;uEjI-!<%-ooY1_vC!?Kyv(F&WUBKAud9Rx} zf4U~p<5s7TlW!#i;FQoKlqV{vU&Y-<@+2?Tu@ute@i?<@CeKKqq+JkOWAyUyZ0J4u za!6#-#i%YS(ddS$LNGWn+ZQ{wNQ?H&4zqLh%uc6s^+^aeF-Cy@XpLh5P=jS-SnZ(d zSba)L*~^8UpDrGnwYf$le%Jen#>79DFcK%wx8PPT`2UZAgjDmk^7FsqYb~;WbPBsp9 zVp?W)HaZqI77i9>VkQP=W;!-bMivI()}Do(j)Rqvl?_+{&`SX8JW~S!D-&Qj$^cX) zU~lkRJ#jLy(lN0!voNy*X|F!L5^0$j8R=eiurUFtLI4|aBU6(v{|B>@gOR1`s}VX* z4h9xBj=$~!3kf48V#c?6hF(ZQSjotNnDMQ0`H$-4KMTvZQiPG1kr@~QP|ZK3$y<^0 ze=SW)-C;eHr&?Y(nVl)%C4RM5kg>x@ds6&1WP&C0FL@`(G$&*T%O0IP*iHk8>#iv8 z`K5?5ifL2dN~K(^E>DH=_@GtvqztK9TwBXWtx+s@Wbe1R{WSd3gaXaxuI=T;i0@{3 zg?GUE>Dg;1CG>sRJ2=sWNK_J~rZP(Xz-Ol~bI@ut8I}$itTkgGm+mk}XE3);)TP}6@*6QuH27E^KaKef0k^uR!*%<@wS!4XLDeYAzK zoUKM2Ytyqcx8q9rCib}5u%9&~$dCyI}| z6T8!gRXD2BZNCE`!zpvqaK!8l==`Nj{%B(srda5vaX(ZSJdr(a9|GAxvr|8^MzI&O ze|S3t=e17YKPKScKxjphBxNjuVPeL_x@Rh|PwWULF7=&y42!%wS{HwYR69I;xSvi_ zqmGyjR4Tr5e_N_JDbC0|%b4ni+&=uy@bCVzA}?vlHI_aiIhh%}q9S(Gp*U%;c2faC zz9Ntn!#HfIFeWi08XiRfJ&JEqas!jtEWN1r%wGxjM!&5oerRVfK(XvwH!PdFf6y)0 zh~kvPLCK4HW+Y`&ugod++LajY^wU(_Y|cV)^J|tKl|sUWtb}W6rcays=Z0m%qmOalB_Y=QI2O*5>wF zmTNA~`-1OC9YM%g$Tdy#tk`ec<-u$E(99>_=t6>E}Z?uCuCmY>5q;$cP0 zOTOc@#a{6j%MLpe(1_xdrvt=+v)x{~<;7;i1G|Ol3x?seY^mUgU@IO6hZ1MjGTr9- ziubgvH8;LI1L%4e?s(N zq#h>ToY!-Lzs!hc)Yk)U_NvGnZ0Wn32zU;u%^KiKhhE$$#un;2CIC z2l;UV%dbKeo|Pqqz@oxDk)5R&DsJ}W%l2}f`n`>siKUEJYo*22aUl6Tn9{+i;@*iO z$FSSB;c->-qH7}JT{(|`_KDr5At0qQp58;j5i@9HavwKYO_Qt1j#=%-3Pr7yF)koT z@0fEBt0=O0v4_=_lLSA_MX`}lHs7*r+;n5TU5?=EBkNaRX^2`T0SuxMW#$6rDJEQy ztiVaiJP$58MV{XHVca?Q>;|fW)&ZR)6uj20MC3cRAf=0e-<#b%Nm}&PzEbMf?Q)nK87cYM~F(rXiJ?BNB532kanYQE>iB1tA!lJSvzn@%KlL~l)2u1Wf_o_^&(Uq(67 zA1t@YQePh6CjS_KnV;k2B#|C1uJBk$2lhN3xgEst4e`F=Qn|sC9lOu_X3pexZKMq= zda)_JgQyY!rF?(~@|4pnV;7Ov=y2PQZzz(2=aQ~Rin)@7wK`*xRrXsPi)tkyBX+QMNrUf{_> z-PoChjcWY*cwRx*`Egi|uWh4jf8SEm+si~uOzeTTZ*3VC6~DDAaAwtLqA3UKX5lAb0+2p1z*gC@h{AB+lSgvDnE;88ANkI>nqC1CbOW3bDIW4IEV+v7e zwJI&@{cw3G18<=Jp45JO7zuVw)<71wZEJrjeu1mDaWx|`y{H1UPjp0b zzVH#u(D{?G3YcVJ&$G(+N|j2MP=#L$&}H)Xlvx$OYU;93)l|xuF%C9tES7fzS3F%V z_`+_Eo^E~na&Ju(G_8hzaXkkd(v#8tF`a$}l_c@jrv;-89PxA||2T`yhC6%i;TOlmEr+Q4K zD@0pBm+sy^4UNY9Wj8$5v8Q3jv`o5y9&^|iF9o#{1pfV?~ zA?=*hnsP1^f^{s?`f+|*msD>0D&yYDvWrqwnY^TTFOK4`?&1akE+J#*tWYg1=itFK zvFozKAl>-7HOolFh1^oCGh^|Wp>f$gJkt+jR-A@&M!4Ayqv4kPSCRURQ3CtQ;+!Q& zl;2m63AHpEnkVcgHX5#9wA!)KqP$3XUDt55{CSVXh#V0C7S3s$%r!c;d*%ED`=8U; zUwW`|v&YYNbUoHwEq+!xKGc;)tFc>mCX46JQO`9jfSy!R`c3}gn439Mh_VnMc|Zt! z*5|~#)~{`CGG9XDt~;5%6P9~IMdM)fvVF>sZ-JSay#8!v1~{-B$6EKRm;78v=yDt)np@eQ3yS+Aw#=b=nf#6C>S3204c5yj#8>-mNU?&Q+YD0b4nQRCADN2 zIQv5SGK}>B^3db62=M`tn$(^D#6&RYK{kx24Z5mD;_XlU34XcsIKEiIjznFm6Fl9g z*vk(hOwWQz0u7ya-{Adz>TwhM-fQ>L7k<1*pkJSCZE<*q#g>LMr+n(oI&j(K9TSHVp)x)t#6N#Eoh{a=>W61j3D`(M?)Eyo;#+L<2$1J( zB%yXEjM4%B`4eWH5IT(>5QJn?^~0*rzz@B@vF@_wr@e8Yf#;cw+{*G;U@@MYWNE}z z*>baO%f!R)11#GPBL0WR;u*fEXY%i8;b(dyob9eKXQ;BQIlXI>4KBI*S<%$^-kP7k zn^2B;JUzSIt1)2q7D$2a0M4oC(s4m{8^rF(!`+?{((ZPpIApm9vlK`0#r$ zH~Pdr-ET?MDT{dbytMuBHur{}VfDIU*1tWq0GCPs<94)$j5`vI_K!h!+_c+~o6P5B zj>mW5OV0Kcm!cLuSuzWF4z9iYEdU%XhBmLW=_AGCwT06Kd#lpI9{2&xtE8|wg+|~` zfM@c%Up8(ALtYOL-{zOn8j$SiD_ll66Fmvwc9BP2o7oQb9IA&6(N<6DW$O1D3X^o8(8 zQ?^(AI5|^OIXTre8?uhCg9$}W2pZ4B!Ww(T$O5vS3)tvM2=jB*)LtC)@h{E5_=lk` zG4EuJmHI$mNQRINi=4>j_#-C+Q*F`05$LJSkLc1P2KwhEah0^Twm8_!0l}>t%1H?- z8sqiGT_^0wI*W^w4c;&2^zD`U&P6@yA;rbh<=W~#8_#7d=)husM_)_5hQiues+!I_ zUWV%^sijektH}hxAOhauFxf-b5lKH4GMpunB|ivTJt!nUfD;@uM_knep!FPZZMTz2 zgBC=(kx)@hBgo~3J?1^Cf)WY#6i8aVzQRXvJzmrbvvzV($Hz z6Cq9q!a#ZbHo-8d&1=9u1kxs~EVfi+d8{QNwwx?wHSnBCEbq5gb33bBC%U*Eu<>x! z&!{)%Jg*XRu$IZFXvMbPiH2I^x^G-Qo2>52+W8!U@?DvDYEdB+C z9S>(S_&Afcn3ftKLyMMtdd!RU;xvK%+#|sgXw7>yTeN)Uy|_3E(_^&aGr!+Yl{G^+ zD@Aynx(aJmAZlou%lQr~8%g>z>!EFZdSivH&5^zZD}>X7DCoGmkxzIc4R zVK;s+^9O~>o%wsUFu47B+;)>@vQXo0yfLhdiVKg|yGgfm#N_aFlK z#{509nGvBM3RCQ!WGIMV(diTwI)#GwfWBqju?x4sxTeVNVVJ+U;z71q?|BZ)GPJM) z#2h|J6CTbucBCz{sl?*hcPmb?g-Kw+4E4CWw8y3Ns1;O6N_MPh8Ic~8qcnLL8*``u zk;xCS+^2Uup7HYw{HV<6bRS6!)RS|2E!e#3yX8+Sa1QJ| zH>3G@wSJzq1@Ephy~WBiC7KcRc%eQ_y(lK2BU9=qLs3t}Qpfhi$WeW0P%KNs+a}z4 z&RSQ_wdo{OSjxN4-A8jQYt*n*T$uVWRbI>wmxL07QA4}CwYsTC;^KZv+tCKE5HyHr z3d>1o_iy8aljlQ`K(Y)ysjM@7;apV1GM;L(tDFM2_YLwI52U?|_Z_jbm`v z=4xaAMc)BJ1IM<b+u3Kb=Q6u;~OA31^b97fyv{+vKQc<+n=h(pE z-F~PO0~dBrcQ-Q^#8l4?1D7(%phxN$vpk?VdJG^=WRvn-*z;Ye zgFw2zAbYNmx`&ZQc)9ezS*$5%D-&&>THe-ee+|BFV%!Gxgx&wrDHx=vYiY=G78^az zoWaYr29wPhlfodn$FLu*6h^^!$1W-M$=$HCIBa_~#os&Mfo#h@WXwN;hcEE{(LfX} z{pI_3rEZEKsXWbU-4~;<2VrD!Oo1h43RG1#yPwBgH5mzpCxz%_B{G` z$VJiku>cc+nIX4-W6@>^nOCM?M9$e*p;I}C3gclF}{ zwXo4C^{2Zqs;p8KhAyZPwghGvE|=XBw$+`$fq=lZWjRNiPwC$dy=1hAv#gJCEgUv5|6r;X$+5G|^E7E)nKwX>^WKKQE zd_w9E;0czME%J+-DYs)vbb1SR|VgPKO~_# z%+ArILolcE59Vkj=H|#5;8b)XUyY^*0|F#;NbQ(0e9_6eYi(7Oj17lD=i? zJE{-3ocq}Jk&rI3I^2|+;U)QFo@=0c`pA9Zp};)V2$2sVbtnmrf#2)^HpxpIFN|l` z-~v-np%&(s5<`d6$sl9nwph_2(LRJRp6IdN3}z!KurbRk($Ju1yw8S*%6PsqoK{wG zzuDRdo$lEJbVgXOdOg2;8dGFP*qtiM-N<$2eVZ0)8mWd@Fm4L~M_=ISY5zW1ZxzCg z{Jl4We_z;{b47w~>#q9ukUX18#HJ4S_ita>M(?Vo{mT=tWl3b>mgQPlg{uuGtpnuP z68QxmAopRhq6O^4ud{-NZ%hw2_=Fh^^I0eJldl^axx6(di%ho;gQn>yeybTt#L@(C zM^t@`E)D?hlQx3?l7Np046= z>w+XmV+|9gj`&{sKMY)YM3{I`;+?4pMj6%bju2s$st~GjLt$UH4e7RqeIP^wZ;)0A zJJ`Bn_CTSz8Ka^xU+R0mp_kG|E0{Q0w3qgy_~ojgL8q!b{71;gQSI*_ik5>5R;uN# zQgw0qD=6|4V&$O$znoZn5=qO^!KS`^bBim{R!y?z$G1-djG@SjdD=-_-zdpxf~(S~ zwU<$k@Xup>T`2VIym1ftVv_&p*@vcE~^{4q;CMElr|r3y2ftKqU{w8AHMGuS4FH`*~YZ6)^f8crOoVA((8A! zwi4bFnR0J!9gs_}XiCqB8*&>Xm&EcR8O9d+PJ0Ne{#H~D3#(u{x1sm1_u#Nc?^5~t zi?a!hwJHj7R1=1`Cyebqua==IEK~cPzm|Vfz_C=|r!*ul(#!nZgNMs7_KE%*?E{ER zGgGJVTU(NHUsYAhU|Gu=!2$Cx%nRn6b98B&`OQBXzeL1}W)K`J9Y6_SaB4>pbiGJh z6A)NKf97g%{}Mo4IX+gKAD<<>EcfM!^u?JxY?SvakLsgt)cV1Mwx1aPN%$Cv?I(uN zM?a4sk*zunxq^6T0R6tHigl>kV@RWzkAcjJE>f6 zGD!jD<_pm$lk<(PX-Yt>A?4s}Dad_t3-K=j)`NODKiP49{Yu{e%rQ0yLfdn{X+RWG zh61JwUV~qK=qh*66hc=(CJD;oE<-4>uv2|3M<|vxgu!8!WeoJf;yXjUH9-A*fjch( zyA{O<0`tA_@&V?9k#)#Hi}2_2#M^Wt8{gmUC}HO=CE)`4jZ*#%?u)Ku(pEM&Jt)od z0RjNODbNy;2u?XCTSJqZzE<^N!qfg85Ue*=?JF#8J8n>NLa!vbPdxe$!*9FdPBtR z@(|q$${nM_POT!Rr?{=z!R&|#Ukc5#hG@gp^%CmlCdcGgtpH3%0}`-75OR694c2$w%t7e6u>T*AqP+gH|tJ%1hq2Fi&eCAifS=Kyb} z4oZHS*=9kaRYe={GB6YKJ6ULv`+^a;ieO0SAA+k(LRoWMdaSzEoX9#3@?k%I3VOH2 zc4Jp;WaUyvurw7|o60nZeoUUSB8T#M$7R*Mr?C^4DWf2bmrD8-$2xszzwRApyOdKs z!7AdtP(h%mE6(|#&;+D{Hw%I^j+oi9TlsFDeuhSpNW9N+3hlF+ znB(1ixfq>WY5^-m(-^`KAP7o;VOGqa&Fqde_uLYG9#f072`o;Gp=(|v)tp*w8KsH1ANQ@ zkymu%`Q1GDL*s5(dmQ;Cr!;Ni@G9LEWw9M)jOr7#yut*bT_p`B+b%29s8^!}Fg<{Xl@UqrSr%+*(5T_3-}{2EYVIF9@(V`h)MK|L+6; z*Hd#>d*J!Hgq5*15d2FFL^GS10|AQX>H_`xj!VaXrf|MnMm951jgk=Cgu<}3haP(@gSZGal zRt92rCMIGwAmo`92p(W!=lJt{egCKZ+V}eXhmVqCXx7MFu151F-pEUn}7)KQ$rT;mE#D+%3Kt;fTdIO038GhP-hKv>{^KXtn;1ZxO zKncb-XI^34_OCE?JAf4sGSBl0aOWfD5e0t!+zI$U`kCIO^o{?U{jb!Y#~&SxKphMW z%xrwbn!qQ^Ta!)X50&k2OXyFFo%8L%{MN_%=fUuo_|{@$`9ox3dShY#^I(5#iT>3B zv;;K7Ci=$tS3vkri}j6@<;?=q8<9=mP2i2l{wBc0@h0$^0id$KI{*6e*2g6Hr;p{$ z5c?Y^^IJqrZ}Bm|DPw*!%k(DB`eu*)&3U#rEv$coeshWWt;O;;zBd7uzw!M|=vzWq z{^sS)rPnOKy8C92`AwV|*!Kt3|IbhX0Z4zQ+`lG@fur5)?TA0~^3U{noff86M*o_+ zHr6(;%hsRo|6JbwS>68Eh3s{%0WW&|Z!4IH6>w_3u1^12U1-Js!50|2Oucz4!B#wW&@z4;JYYvREc&@rhOwiC)HBCqu~}$sWCT7V%JPnV;I&h1{&Y zZfM%B9v)IxWHkLz1Sdw>$OH@ONXU6_voEc%=fKsJ;tO?O1{$`JGQ2}a7xBUK$M)h? zXhgpd!W$$)VJCQT-D0>{`Ru6s&5hMpn0S5UK_>RkPb|?GGFPD&A!YH#-gZu4_2ezU zpL&l@fG|=bVz8~#sr~ab1!hLtUxf75i%dZLyh0chKkLqV%rVErST34@8LS)O4vn|c1m9a@>^<3Wb;vBS4g|ZqcUh`bab=>qEJ}OyWaQc-y&J0aWSFU!@9rt zVzh855DRR4!)Sw{9*g=dA(3o|5Ri@Sj}92W{6%>yJP3=h%74yb+DOH$6kFIIIj~uU zy@&ExpWeJ;rkh3^zq1uzzK+n92G8-}6UY_MgQTYFJd<|z7-UG(BI$lQN*#fSRFteZ zzBAlslD*TEa^1(b&}_Q*K9UP;dfQjINVh=|g#=E?|9e# zJ#G!Bx~vamOve$VZW$fpNiPkykS60L*(gmGPS-u$=rg8OzH~reySBn>dUy?Klnk~% z)W1M%+(Y?~h5V)$!TMxJ_$B|nU^}#AqSkEzlX5pn;$F9kf=@RsG0*$2JRzRPr2S?3g0Zy+yj@6a!#(-jepKz2WfuIzWeb93Z*((8G%y}gi%+*W2URV*xje zb7_uQjmMkQ1%}@ahTg?&=UN5hW?AeUf}|4f9XC8}hAXN>izEYVA!Ni?WNTjrSY$0N zm8cqojb*-(gEW-pz486|&6uJ~k`cP!*v1p+N9NM;^@xBQ9F*Rz+=cm2`1dBhVFb~- z-?03`I4Lo!*q{_U@zQ=3$hRwf)q=oQ5;?ae6J5{g6Sc%*DIJ=l+S6~g-+`wuF{w~& zDX%X?`FiNU$|ljf_|k$kfYwjtkg{|!wAF*p8lN|H%Ek_Y^55^{D2A&w#ahXL|?BtH`ReA=Ar+SJ>Wt z(q238;d(uT+0QQka;UT~Yo?fqHPyOpW-J&U{@Y-xd|E4n`3{P=Y$7fSrjS0iP^g^n z?C=;Z{WTl=z`Cft-Ap+hwQdaz!u>U9N{Zsj={I)*dk+&Y!f;*HI=gmHSQo3HAJSqxgt9gI{N^(OeU8f~L2yFt#Z2^MZ}~+}HK(38Od2E5$62o%Ng#H`5bxe+UU@ zHxzs&M^^(dN{S@Fx%Bu$3Zw2YXI>N|n;46VuC1-*r@KN0i494pyF7luZc>kO`Z0Fg z;X^Uf;=cHznu?C^%V^`-X^)1SX$~_C0;$Xerok!EY*OCyfh8A+aSAQdUXa%yRO4mm zH9{;w{yP7Zq8?}r4ps4sQ-|4ld3 z4QU&qr(b0Qk=q7tHc?v#0uS>U=GnOr4CEjfeURehy0~6Y?y3R4Ul(C#Wdkp{SsH42 z*AJ<*Jo_}v-?O*%5B=su7&0De6kY~eAD>-PL{mV zt#eJBugNV&;J<*p?8*Oh05lpNHZgh3DRtJYfsfoQxg+a6aM*Cb<6~w)Jf~!KP$*FB zB1NFUs(hpf9HCI55b(L=sD8lUg=U<#wN@i9DE{zrV5Vd|J>E@by7l4q_PSs4XLHrP z{|6N&3b|1`&!CxP%wPIuDQSotmIciYYrZ%>R{7#SSU{|!XH^dNV}}6kUO<1sst6Y? zk>nh$`iH`vuGDg>^|9i+pa`$)AZTResnzLiv_75ZDF@_fCNT!&fb zl*Q3522*eRSzm7MH1}hy^ruY+O{tNOp^_ZXN&G4aYY?svF%8^dV@&=^(>3Knw*-O)%Qe3Q0a!~p^0#<{lcQ7 z;KZU7sNpZ1&ETt~{af=hW&CYU1mW6MJnlw;d*I;5cyo0;-W_)ZG_jfHH^UT;zC0Fg zHu8g80a2;t>d{Ku!z2AHPE#|#F;_G5$Qfn!30MOl?e0<%NiNp)O%j^Usy5Sp@^0l; zaWp5$$drrQKG`-Gkf{Y&QwRqIh;{ee!xkJ zKui;+W^1dqa`dACOoxr_(x_-_yUwjcx?GNp%_h)n?IS=}k33zrc%H#ZZBX|+G0u&e z>g{^Ht45SZ5vhR1DUUg`fr&xE7mhsi-rrS7QPx^5(m+e)rTN}r-9ql>G7@-|j2b`0 zhwmTX?ci{nI2s*ZWN{8ZCibpPoNR-23uU`FFM|~Gu?SrGGtmX8i^X9sL56&Hk@ZJyX-iaWIO_CMM%+Rsv{w_bWd--V}hK z3}U3fBwGGHQE8DfU15pGkFkD9B9{!IMBcQ#vJ)rOa((tT+lIn3Q+zINPI7CZo+5>2 z8U?kMtS=pcl@{JIW=yhD)`aF(p1rgtNXd%PShVd8S^GH;#23oCR#qN@Dp%mg$l@iR za4>opN{@uHbKbY#dMI9y1PXXqhUWAjZhYX)OMhmI`!4zTBoYB>HdoOxzN#-u%(6Oy z`l%{q+Tr7-5M_jlZV(2a7)-0)=ih};2R(B z_cxgHY;iexI%X#*^A+UC5G>ofbbGo|YjnU43A3T|L^|Jw=Tn9etFU4EZN#)+i8hSP zy>AA3CXkI1g_9V6Fr`1&VK1exGN%#(TAw-x81DCH{;5BOcRbLpvj3U(9*PFKZ0%g! z8uQ-c-6!+0X->}G+1Ud5pB%FWt@mr=2_nI5I9Ca9co(WHRJ_{xpd4$qV@uVTAsb6U zDSpXX(l@swBmAgs=xA~nZu`P*;6nxqP=X4hy=M}c2$A%ORJKtHHffNH$2_@TA)kI` z==6OuJ!?)Zvv1o!==w}$FtaR`>=ibFZah#)9ljidw_lG?Fx60*+a_0Pm8d(Dk~Uq& z)do$(>2a~Tq`9`r-(ac#q}zn>^QVm2Sk(am0fDo&`{!avmylb8xMl<#8WCIm$R2Ds z-LRNu91m}Xj#)EGHDFW02rh zXOafGPA`RnT644r1-|M}#rz$(b|D5O#2-r)K_Ll1(*lBcgZMZTYitq^_ilKQSKaxV zqc-kBg8S0iV)HRS_VRWdv!4~Ij%ci2aO_qSTqYi$g!YLL$$IprIG0m+{o*{xQ?bbJ zql^QK+eVG>zo-@d1<`s$5e1KSw-!XUGORRLOoc!iST=}|QoYy+FmRvi->e99QzJ4J z$2$t&R*g_N?>uhwzpXl_^@El}M2d|w_`GO$)37_4oFv6-PtnhbfZfn)meHXVFG(+R$GR=g5&DAACopmp9Y}G}#rf zjgcCH61!fm_lvU$cb&b++?@1*Af!GV#_E+N#H!U&Eqs_Nka$}ZMaAbR`LuYLAhOa- zrIQ|?^>$c{>Sh4z@>D@t(K3s&wjcfQGLOyEkxa7w#y*}dS5!*X>EWEO0Rch7C}5(z zyriITj^H`3XY-JEqR2|4>3Fj&=2AJ*1B5Hvjh+wmRuSO^B9Ne=zc~VYDJY@oL(~Jk zw|^bGkL$?OX1CDbPTR#dzzT-VSVnoT&QGdIb(ea~r>O`cAJ|hooE|xktp{&l53BDjp2*nvu&a`Mr;yocq$Ot(7PjW_S|J z0<7L6EsKSQm^l;N&5ha!ko4|-{LF#iz=Om^2kM?BAeOlbEBQllLxn);rmGCeg*PWxTc>t`Opqy1V}Q;;fqdm(q#lXKR5aDG`$sf0{lgOcA4F`wCbZo6)$ z`)6FxvwKM4)e)25hZJ%I6QG2?9z9HJDv|<{9?F!xL`Nq~tNV2Wet3>jsEj(>g-x4j z?IbIUHW9inm+e~vX(EIlPqE**v^Pn+Ai(XcEMjyvWw^hi?-|gy+jxMcuT@*4^UFu_ z_UCV5anf^MpzmE`Z$0ziUZY6L_)VW+u?j{ROf1jg*_LmVwt2HMx@VUwdA(is@_5Q$M)oY*XVri=Q80712L?YX+ zRGO1omzhf_++o0!y{8GU$Ix~}6Snj|WUm-cvd#mgQ>z(N`27;SnE@u5=W|t`-S3M) z9viEMofQ%UYC^Zu1NAYP8;_Bb7mtyGT?vr2dH0snXqon)k7M`IAa=QXhguEq`Rgt&p?4u|3T=#W?>AQuJdG9^jG+YUO zkUS2fIZ>J>R+{gI$#UaqwBU4bm?5$2PveDKwG@-yMX`v?+Za>m;Ez2g(0~R(P)~FT zGFQ(__mF4Nr%jkusbI6SEubeB%{TT~OzWEp97Nj6<=5pDxNptRs-Noqqyj9%X*xNT z(FiQh|7a*7rNzO*cybezJRJSB`<^@^>X7(^FXsgjCTuM`7lqgU5Jj>sw3{@5B%1vD%9Mz61L825-4-h zTm8=B@RJ@lb#AqkT&<0$(4PmV5yh@zr_LmjhNH0Rtne1^$CrnZO4!gbFfbgxNQH!k zEG!*OQLFW%*$6$Y>M3PwAnvGS>-|=YA$?TLm%Q;+rTdhqtU_1=$XsqkG`aP%Cvz;> zu`u+~G4T}85%h3i8P;kVzC4Vh?Q(9bt1oBgr>9@3J-huJ9dH-nR@>5+i^0xnL0C}U zgP4h@^4aDVvy8#f8YXQaC5n^h@p(v_w4uoD#52vBSNHL@a(g?xNw_~~rl#wmC)+(q zld<{f$MGjbw;-Qog-fiT^7QDYI*dv~SMY(;kncJ<#Eq-_-Y6`}yQ+CD}!mC`&{el1Q1d zEAifAMo;vA-{bl6|Mt$8>vmq(eVx~R&+T$J<~L_4N3o@=uiq%z0=@etuCoJB+yVKCbPPPC3TDVzfSE0DZOj#)J$s3e^ zWk-vMoUue>=RQH$OfEY;o!PGZ@!U(O_;jRYInj~niApMn{s-_ zUM1tRAPR0+K~cNx26a64k%guCzALg%Z+fD`%5zO>9^?sL>9?9&X{-%|9NCv8MD@@+ zmaAg8xBI92gthGJ1?{Vu*Sa?uwk#9ALi|CCO2`6Pwm_f0Z0gUssT*5SAe)m5F!}4& z8vM2j_u2R>uXlw@=hEP5I0f_<9mtMkgx2SPU1s?Dr3e5VF;xM$vb z%${##YC>HB4L`WuHXMd8Zk!ZBY0H(@#owQoYXy5i}PIl$+Ed z#x22S;IpxSppd zqer57S+F^|XKLAl9+Kk;*L=W@2M#dYrE&p7K#Y`)+-nyz zoW|;%j}21gTP3YbR_f)S&Wq5qMm1chv->`xR;4za;p3RoSNhBs>6^(kci0&Gv4E*X zVYB-L^2Ubck%f<$KFn5Jp^KC$YJ7LFATf0xioPr8&ox@tr*#^cXZEqNl%C80_lrs;)&A{yAii^s_ zz#~Iq9sdrP%vqS3jvUGi2j4 zPVM5cd`#&(U+SucjY(odC_>hPbO9N})! z5d94QL8DEllVjK!6RtBrTaS=vB_ND$J_dm=xaS>=m3W^~L~jiJR;O{xCLiiDdk%uD z(HEb>&e-S5b5dIR9d*yTo#^6_KhSx=q9prW{id#PY%a@2m6YKoLsHFiCyoynnQ|_- zqD4Nm_pIE+9(9ixXBJcZmi90Z2ln+G646?lzTz6jEVPV>Okfl+g>i5%7evkzC0$aO z)j1k;U6a`@7dBCW%k?sW=bpFew8ru-ufI6zJ0fgun=^-7>f$g_&@7I0S^b&x)$wLv zH&n_gZzDj_4W4iL+?0RK`m|&(ZSCs!GujS5{RUT?=p19z4|Ks;AE!OJ!9H&#F(TrN z{W#v^Kp)E<$B_74U*x5Gj)8PPQVH?Q7lEG9eajMr;m*I+-Wrh3#3lVA+$KH_Yt?B# zc=wRw_bH8%_tk!OO})x^cy_#}hoRow-z|a>sOH)cK+=sJqg!TsCEBjayNt(8_Nis} zBiX&O6w(Pt?y=;TcZp{_HH%xbkdD1Ubus716+Df#7;c#__TGc+x1TaC22>ov%uu6* ztVP%-8Z10yiiw~Jc|&;dvZo=!w)2c@fmzKI@V{c8m;wLtgXqch6EcuG#dB#j!*|fh zls?dQun-HFyBDGy$FkvT0)7yvr)QY@Dzsk4X#S0nxiy1-QE_vs=d#Stx8 zM)MhCB%)DDxCAy|1-I0@J-5u+l85tq1@|}|-dGMDHp`HzjcPfpKGJ%0)S7BlSpFO> zKfQ;LoIb-j(J(zEk4bj&lFw_nORhm@+pA~#1lbZv-iL?ysvFPN4ytSzDt)^eOyY^Uu}w9_*LLcB#A^ z)>XAeX}ZlEEuKR7=K5iry1gjqBO&@$D%z_kf2})6NO=D4XMAQ3+U0_FHbtRe%Pa3p z)1OMCU2H#~O@42Kv_)kzvEQB@+`Ri-Ki03nsq3Lb&iYE5q!Xnmdc&o_OuXwV&vIoy zp|X74>ujV^(Z#E^%gfYTFO5zpNPi%-CoDs+io>@4hW)kWGKp_%OfWU?8Q~IImYr}< zDvucH;eF$n>AAT1vEsgVb3{q&yQs_{``e7X>_aOG{2#x3>m2Q%!NJ|>-Q-NJm6GVzeJ-gS3_Px)EF_mXQoDR&W#N(Z&H9=ETv_5my>wgy z^Wf`g*PmNDmg)BhcRgIKFBNH}J{MCM4_)$v=bzz=5#;kkIc6TnxxRQS%payG(DFlz z>TKbS`pc*+o%0UDPxD&NgsT?a0*RN4upXOuL&S8!D@T;z$0?P?zn{u;`hn*v$xR>- zaIB%inWM8Qt&~BuurQa?nEUzcDJmMSp~^kNn6F1v*5ik?oMI3ldXH5c_kNS9-l!#- zErkZ789(Vxo#00yrqnD&Y0a3l2v!KdBBmkGTqZ}ikQY-&_`R!JK|cn{ zD~#gD6VskTQ_i?Gl=Y04RxGFDDwaL#Y>V1kl4)2iRa{4!1vzCtS@1Z?cw4ZHs$&i8 zY^zFj>_Sgfyyz&S%D1qS9OEe-&M0%PWO!-g!&&7$eEzw)dD5H{-fx)N(9bRP=Aftd zqZf`&NGMMc#ilMk7)e_k109~I^eFC`k!bd2(89}?W1kDscV7Dm)9+B2_P7L%xE=BW z4NtA!v`?&iJk~Rcut{s{a6agmbeOwRSE64xbQJHWAAdi?C*_Q)p_N+wD6M)76gN1Z zkvGQkQ?TzH>k(P+!(kQ4vCz6!$1haXu;^GKJNDB z@|UZ-re)EV(#%tw41Q-3gEoIKJ3G-F3l)Q?`}%N4R+v9vjFG&YcNOYZp>gZ4(1_6s zS@T}hwPkb*m8IG7b~ta{C;suT#*cK%S3TY;eoHF|)|Tj=kU-bnm_-5KRxA~|BQe_I zz^486!Z5}e1ruvdxqN~3N`8wsuK%swz!EF7eNEWqQGbL|228X+IEo<~Cn4D5?`B$& z;CXt*78xOfPn+{hK~$#-zSP#orlltIb(nEip+q7LKvpLBJnOg$7w*Szi_5%NqqmqB zS`x+g@j-mEldk8+(tmb|4M`~b8CUd*mY zIO?=3OlP!p;rqbArvcdV(~M*_7jS6noHGlwl`{rh#DkzU`mQ={@yIRZkcLWvMzh|= z(CD)jOPqavA{;2~g2u1~UZdH^){eAkrM?jUAw`_~3Gml*Eb zJZ5(0q9C<{KN9$`gH^w<419mXN2nqe8nt+}gxw~d>EKBkdRM|krB;K1fBpwi-+pyw zofQ|1Jb$Dl{D~Hw*d}fY%<+XyP628AJ4P|IGyoKV8`vKnwGB7Le7E&be|)$Xeo`~V7qt73+Dj} zQ~%i1=;N1slJthvj>r|jxH-$}PY&TsYVy*FhlHF(*$q{jE7oNTIVc7ng_GG2>!kqh$QkG%kA&SwBxh!?WUM z<)hrb_!pnkSr1y;4%Xf{4yRN*Hg4?xCG-G3IK?3hlz#HgkmC>x=@t?`9nPa$T)foO zrqDhvfi--}un@$ToAhN4k)wMgzGdqfy?EdL?AMI$e0s;O^Uk_l2rphjCL!R^v6)s8 zcp6Q_x}Wc6R5j@BI@Oryox~dmG5P+sEV?X?6K3OeM`5hEZ|`$6V}n=MS-Y{1G@(9p zGTnN>C&7Xb*zQFyj;GNVA(z+0y^gSpKC*1KTx!C3d zL}DN-DJMtlCLT-uQx5fahw*Pw98qKZ_dFcASm?jWbt8@;+Bc$u+a3!X|FUp9a{=RboEvf6b`D_v?fJ;Lc8-a2{K^fOw(axC?rmqx zPD>oS(@)GvTqm(5_V4(+?S7)U1LATB#CG3~ncJD?_jb3P15Vm;Ilt^2@V5WIo%>gI zj%en#?Hoyyp-7AjMUr1KBq~N`a%4tEHfcz*UL$cZ6q%Tjs2CZ|?Ql1;EhC9B1WBQh zt=|8M=13S#hOE%Y{EWO#GOznjERXE}$l?!0N=pWOWYQ)>Qg38Qha^invYjJc1A>%q zH@(|!?hs_8N4{s|pGZ27%{I8UB&2o)ii9?NC2bS|n+?nxrM2APxBq+W`Vk znv_qPi~>pPB&xpuD#ZIozx^+p=YNKH#9i}W8ocfO*>IP^+y34D&ERcYvfXqHF87DQ z+uCaW^H0J*#m@lbw@sk83r*7=KkaOP8BS|SyUqOol?xPb_5#?lg+8GL zT(yHQz;91o1ZqC3lUt475wEW&;9Y?o8A(e7s-zbjg+xjt;g0ZMF`_gizTkiViby~a04iCcT7?msL;J92JlYVKVs5I zIbe(3lY>|wZEp;P`tw}WpX&pN_TF)lk}`kHCn+UGB$&JM0#||9dk=tfQG4$JP literal 0 HcmV?d00001 diff --git a/install_postfix_advanced.sh b/install_postfix_advanced.sh index d7d0c89..00ba8d4 100755 --- a/install_postfix_advanced.sh +++ b/install_postfix_advanced.sh @@ -2126,7 +2126,9 @@ smtpd_tls_key_file = $_TLS_KEY_FILE #smtpd_tls_dh1024_param_file = /etc/postfix/ssl/dh_1024.pem ## - also possible to use 2048 key with that parameter ## - -smtpd_tls_dh1024_param_file = /etc/postfix/ssl/dh_2048.pem +## - DEPRECATED parameter- +## - +#smtpd_tls_dh1024_param_file = /etc/postfix/ssl/dh_2048.pem ## - File with DH parameters that the Postfix SMTP server should use with EDH ciphers. ## - diff --git a/install_postfix_base.sh b/install_postfix_base.sh index 2286054..787778c 100755 --- a/install_postfix_base.sh +++ b/install_postfix_base.sh @@ -929,7 +929,9 @@ smtpd_tls_key_file = $_TLS_KEY_FILE #smtpd_tls_dh1024_param_file = /etc/postfix/ssl/dh_1024.pem ## - also possible to use 2048 key with that parameter ## - -smtpd_tls_dh1024_param_file = /etc/postfix/ssl/dh_2048.pem +## - DEPRECATED parameter- +## - +#smtpd_tls_dh1024_param_file = /etc/postfix/ssl/dh_2048.pem ## - File with DH parameters that the Postfix SMTP server should use with EDH ciphers. ## -