Comentario comments on workaround.org
https://workaround.org
Comentario RSS Feed for https://workaround.orgMon, 21 Sep 2026 15:02:10 +0000https://comentario.workaround.org/icon-rss-64px.pngComentario comments on workaround.org
https://workaround.org
6464Stephan | workaround.org | Comentario
https://workaround.org/ispmail-trixie/managing-users-aliases-and-domains/#comentario-f6ca5074-8105-4bcf-bd40-5128914da489
<p>Now I started using postfixadmin for the user management.</p>
<p>I am writing it down here for documentation purposes (also for myself). I did this some time back so hopefully I didn't forget something.</p>
<p>I just installed the latest 4.X version and configured this in config.local.php:</p>
<pre><code>$CONF['database_host'] = '127.0.0.1';
$CONF['database_user'] = 'mailadmin';
$CONF['database_password'] = 'yourdbpassword';
$CONF['database_name'] = 'mailserver';
$CONF['database_prefix'] = 'postfixadmin_';
$CONF['encrypt'] = 'php_crypt:SHA256::{SHA256-CRYPT}';
</code></pre>
<p>Start it and let it create it's tables - they will be prefixed with postfixadmin_</p>
<p>Postfixadmin is using a different database layout, so here is the trick to make it work.</p>
<p>1st thing is to migrate the data to the postfixadmin tables in the format that postfixadmin expects:</p>
<p>Copy Domains</p>
<pre><code>INSERT INTO postfixadmin_domain (domain, description, maxaliases, mailboxes, maxquota, transport, backupmx, active)
SELECT name, 'Migrated from ISPmail', 0, 0, 0, 'virtual', 0, 1 FROM virtual_domains;
</code></pre>
<p>Copy Users/Mailboxes</p>
<pre><code>INSERT INTO postfixadmin_mailbox (username, password, name, maildir, quota, local_part, domain, active)
SELECT
vd.name AS domain,
vu.email AS username,
vu.password AS password,
vu.email AS name,
CONCAT(vd.name, '/', SUBSTRING_INDEX(vu.email, '@', 1), '/') AS maildir,
vu.quota AS quota,
SUBSTRING_INDEX(vu.email, '@', 1) AS local_part,
1 AS active
FROM virtual_users vu
JOIN virtual_domains vd ON vu.domain_id = vd.id;
</code></pre>
<p>Copy Aliases</p>
<pre><code>INSERT INTO postfixadmin_alias (address, goto, domain, active)
SELECT
va.source AS address,
va.destination AS goto,
vd.name AS domain,
1 AS active
FROM virtual_aliases va
JOIN virtual_domains vd ON va.domain_id = vd.id;
</code></pre>
<p>Now, the trick<br>
Move existing tables out of the way:</p>
<pre><code>RENAME TABLE virtual_users TO virtual_users_bak;
RENAME TABLE virtual_aliases TO virtual_aliases_bak;
RENAME TABLE virtual_domains TO virtual_domains_bak;
</code></pre>
<p>..and replace them with the following views:</p>
<pre><code>CREATE VIEW virtual_users AS
SELECT
ROW_NUMBER() OVER (ORDER BY m.username) AS id,
vd.id AS domain_id,
m.password AS password,
m.username AS email,
m.quota AS quota
FROM
postfixadmin_mailbox m
JOIN
virtual_domains vd ON m.domain = vd.name;
</code></pre>
<pre><code>CREATE VIEW virtual_domains AS
SELECT
ROW_NUMBER() OVER (ORDER BY domain) AS id,
domain AS name
FROM
postfixadmin_domain
WHERE
domain != 'ALL';
</code></pre>
<pre><code>CREATE VIEW virtual_aliases AS
SELECT
ROW_NUMBER() OVER (ORDER BY a.address) AS id,
vd.id AS domain_id,
a.address AS source,
a.goto AS destination
FROM postfixadmin_alias a
JOIN virtual_domains vd ON a.domain = vd.name;
</code></pre>
<p>Finally, postfixadmin needs one alias pointing to the mailbox itself - this can be done like this:</p>
<pre><code>INSERT INTO postfixadmin_alias (address, goto, domain, created, modified, active)
SELECT username, username, domain, NOW(), NOW(), active
FROM postfixadmin_mailbox
WHERE username NOT IN (SELECT address FROM postfixadmin_alias);
</code></pre>
<p>Now postfixadmin can be used to manage users, domains and aliases and the views let postfix/dovecot continue to work without changing any configuration.<br>
Alternatively you can also change the postfix/dovecot configuration to use the postfixadmin layout.</p>
Stephanf6ca5074-8105-4bcf-bd40-5128914da489Mon, 21 Sep 2026 15:02:10 +0000Stephan | workaround.org | Comentario
https://workaround.org/ispmail-trixie/upgrading/#comentario-abd6df30-72af-4ec0-9245-24eaaf74d60d
<p>I ignored the advice to start on a fresh machine. I just moved the current dovecot configuration out of the way, did a "full-upgrade" and configured dovecot from scratch as per this tutorial. Much easier than all the other migration steps that would have been necessary otherwise - at least for me.</p>
Stephanabd6df30-72af-4ec0-9245-24eaaf74d60dFri, 18 Sep 2026 09:52:54 +0000Carlos | workaround.org | Comentario
https://workaround.org/ispmail-trixie/going-live/#comentario-cbbc3478-2531-45cc-882d-969fe2a8e599
<p>I think I spotted a little piece missing.</p>
<p>If you have setup that you can send from other aliases in the <a href="https://workaround.org/ispmail-trixie/relaying/#configure-the-submissions-services" rel="nofollow noopener" target="_blank">Sending / Relaying</a> chapter you also have to replace the MAILSERVER-PASSWORD in the <code>/etc/postfix/mariadb-sender-login-maps.cf</code> file.</p>
<pre><code>sed -i "s|MAILSERVER-PASSWORD-HERE|$PW_MAILSERVER|g" \
/etc/postfix/mariadb-sender-login-maps.cf
</code></pre>
Carloscbbc3478-2531-45cc-882d-969fe2a8e599Tue, 15 Sep 2026 09:44:29 +0000Christoph Haas | workaround.org | Comentario
https://workaround.org/ispmail-trixie/anti-spoofing-dkim-spf/#comentario-0c2fa1a0-4910-4974-8a1d-1248db0ebc11
<p>I am very late with my response – sorry for that. Thanks for pointing that out. I have added it to the DKIM chapter. I could verify that without this setting any mismatch between logged-in user and sender-address will rspamd omit a DKIM signature.</p>
Christoph Haas0c2fa1a0-4910-4974-8a1d-1248db0ebc11Sat, 01 Aug 2026 23:44:10 +0000Nuri | workaround.org | Comentario
https://workaround.org/ispmail-trixie/dovecot/#comentario-18b42b1b-ae44-4eb5-8575-e34c0983cd7f
<p>Hello Christoph, compared to what you've done, mine pales in comparison. I should be the one thanking you many times over. I'm very glad that I was able to be of some use, even if it was small :)</p>
Nuri18b42b1b-ae44-4eb5-8575-e34c0983cd7fSat, 01 Aug 2026 17:44:37 +0000Christoph Haas | workaround.org | Comentario
https://workaround.org/ispmail-trixie/dovecot/#comentario-934c1aab-ffa2-443f-a1a9-6d8a8a8e0c51
<p>Hi Nuri. I did not yet thank you for your hint and it's already 7 months ago. But I have added that to <a href="https://workaround.org/ispmail-trixie/dovecot/#99-ispmail-sqlconf" rel="nofollow noopener" target="_blank">https://workaround.org/ispmail-trixie/dovecot/#99-ispmail-sqlconf</a></p>
Christoph Haas934c1aab-ffa2-443f-a1a9-6d8a8a8e0c51Sat, 01 Aug 2026 17:11:31 +0000jkirk | workaround.org | Comentario
https://workaround.org/ispmail-trixie/webmail/#comentario-0b7ff203-5663-468f-bf2c-d2355fd62972
<p>I just checked the default <code>/etc/roundcube/config.inc.php</code> file and the examples does not show an array for the plugins:</p>
<pre><code>// List of active plugins (in plugins/ directory)
// Debian: install roundcube-plugins first to have any
$config['plugins'] = [
// 'archive',
// 'zipdownload',
];
</code></pre>
<p>Do you mean to replace the list with an array?</p>
<p>And:</p>
<blockquote>
<p>The last two lines make sure that this config file is only accessible to everyone.</p>
</blockquote>
<p>Should this read something like this (s/only/not/)?<br>
"The last two lines make sure that this config file is not accessible to everyone."?</p>
jkirk0b7ff203-5663-468f-bf2c-d2355fd62972Wed, 08 Jul 2026 13:31:46 +0000jkirk | workaround.org | Comentario
https://workaround.org/ispmail-trixie/going-live/#comentario-153b4410-56c8-4a40-ad12-d35f09043c0a
<p>I received <code>ERROR 1046 (3D000) at line 1: No database selected</code></p>
<p>I think you need something like this:</p>
<pre><code># Delete example data
mariadb mailserver <<EOF
DELETE FROM virtual_domains where name='example.org';
EOF
</code></pre>
jkirk153b4410-56c8-4a40-ad12-d35f09043c0aSun, 28 Jun 2026 16:53:42 +0000jkirk | workaround.org | Comentario
https://workaround.org/ispmail-trixie/relaying/#comentario-befeb675-83f8-4fa3-a388-cfb013a04948
<p>I also stumbled over this one (more or less).</p>
<p>I manually installed postfix (postfix-mysql) with <code>apt install postfix-mysql</code> (without <code>DEBIAN_FRONTEND=noninteractive</code> as described in <a href="https://workaround.org/ispmail-trixie/install-the-software-packages/" rel="nofollow noopener" target="_blank">https://workaround.org/ispmail-trixie/install-the-software-packages/</a>) but I accidentally answered the debconf question with "Local only" instead of "Internet configuration" (which seems to be the "noninteractive" default).</p>
<p>This changes the default <code>/etc/postfix/main.cf</code> to</p>
<pre><code>inet_interfaces = loopback-only
default_transport = error
relay_transport = error
</code></pre>
<p>inet_interfaces needs to be changed to <code>inet_interfaces = all</code> and the <code>default_transport</code> + <code>relay_transport</code> lines must be removed to make this guide work.</p>
<p>Took me some hours to figure that out.</p>
<p>Also see the comment from another user: <a href="https://workaround.org/ispmail-trixie/relaying/#comentario-0c252881-ea6e-4bbd-9d3d-eb5611a97af0" rel="nofollow noopener" target="_blank">https://workaround.org/ispmail-trixie/relaying/#comentario-0c252881-ea6e-4bbd-9d3d-eb5611a97af0</a></p>
<p>I can't stress this enough: This is such an awesome guide! Thank you very much, Christoph!</p>
jkirkbefeb675-83f8-4fa3-a388-cfb013a04948Sun, 28 Jun 2026 13:36:50 +0000jkirk | workaround.org | Comentario
https://workaround.org/ispmail-trixie/install-the-software-packages/#comentario-eb93bb31-44a3-4112-8464-cc0091f4efa4
<p>FYI: php-intl php-mbstring are dependencies of roundcube. No need to install them explicitly.</p>
<p>php-xml is not a dependency nor in the list of recommends, see: <a href="https://packages.debian.org/trixie/roundcube-core" rel="nofollow noopener" target="_blank">https://packages.debian.org/trixie/roundcube-core</a><br>
Do we really need it?</p>
<p>(Thx for this cool tutorial. I am following it for over a decade now.)</p>
jkirkeb93bb31-44a3-4112-8464-cc0091f4efa4Sun, 21 Jun 2026 08:12:27 +0000Zeraphim | workaround.org | Comentario
https://workaround.org/ispmail-trixie/managing-users-aliases-and-domains/#comentario-0e68b636-7ed6-4325-a2cb-b121027c0345
<p>yeah, I have researched it as well, but couldn't find a good setup. Especially in conjunction with the SQL setup. It would be good if I could somehow set in the database to use oauth2 instead of password so I could let the users migrate slowly. There is another bummer: Most clients don't support this, or only support it for special providers.</p>
Zeraphim0e68b636-7ed6-4325-a2cb-b121027c0345Sun, 14 Jun 2026 22:25:17 +0000Pawel | workaround.org | Comentario
https://workaround.org/ispmail-trixie/relaying/#comentario-7a8486bd-d3fe-4a62-bd74-3aca385b6686
<p>Took me a long time to finally migrate my old server to Debian 13. One thing I had problems with was that while sending with swaks worked, neither roundcube nor thunderbird could connect to submissions until I changed inet_interfaces = loopback-only to inet_interfaces = all in main.cf. Just hope that I didn't make the server insecure, but it would not work otherwise.</p>
Pawel7a8486bd-d3fe-4a62-bd74-3aca385b6686Tue, 09 Jun 2026 16:26:06 +0000Jan Schoonderbeek | workaround.org | Comentario
https://workaround.org/ispmail-trixie/catching-spam-with-rspamd/#comentario-4c20bfc1-26df-48aa-9caa-a65f53cef96a
<p>I wrestled with Redis for a while; it wouldn'd start, couldn't find any usable diagnostic information. Then found out something called "valkey" was occupying the port that I tried Redis to start on. Then I discovered Valkey is actually the open source alternative to Redis. My suggestion: install Valkey native instead of Redis (apt install valkey-server) and mention in passing that it replaces Redis. Like you did with MariaDB.</p>
Jan Schoonderbeek4c20bfc1-26df-48aa-9caa-a65f53cef96aSun, 07 Jun 2026 19:40:42 +0000Christoph Haas | workaround.org | Comentario
https://workaround.org/ispmail-trixie/managing-users-aliases-and-domains/#comentario-45ab7d82-44f6-45b7-be93-b3c27f48c4e4
<p>I have researched quite a bit but could not find a good solution yet. Dovecot supports it in general (<a href="https://doc.dovecot.org/main/core/config/auth/databases/oauth2.html)" rel="nofollow noopener" target="_blank">https://doc.dovecot.org/main/core/config/auth/databases/oauth2.html)</a>.</p>
<p>Open-xchange seems to tell Postfix to use the dovecot authentication. (<a href="https://documentation.open-xchange.com/8/middleware/mail/dovecot/oauth_2.0_with_postfix_and_dovecot.html" rel="nofollow noopener" target="_blank">https://documentation.open-xchange.com/8/middleware/mail/dovecot/oauth_2.0_with_postfix_and_dovecot.html</a>) I am not sure if that would make SMTP use oauth2. Worth a try.</p>
Christoph Haas45ab7d82-44f6-45b7-be93-b3c27f48c4e4Wed, 29 Apr 2026 18:38:29 +0000Zeraphim | workaround.org | Comentario
https://workaround.org/ispmail-trixie/managing-users-aliases-and-domains/#comentario-6c9cd204-9d3f-42b4-9ae2-34f80bba8ec5
<p>any idea on how to setup oauth2 in this configuration?</p>
Zeraphim6c9cd204-9d3f-42b4-9ae2-34f80bba8ec5Mon, 27 Apr 2026 22:12:53 +0000Christoph Haas | workaround.org | Comentario
https://workaround.org/ispmail-trixie/relaying/#comentario-1eeb27bb-95b7-49dd-96a6-a29646a8659b
<p>Have you tried setting the "ssl" option in fetchmail? I'm not sure if it supports STARTSSL though.</p>
<p>Alternatively you can add another service to your /etc/postfix/master.cf like:</p>
<pre><code># Dedicated local-only listener with opportunistic TLS
127.0.0.1:10025 inet n - y - - smtpd
-o smtpd_tls_security_level=may
-o smtpd_sasl_auth_enable=no
-o smtpd_client_restrictions=permit_mynetworks,reject
-o smtpd_tls_auth_only=no
-o smtpd_restriction_classes=
-o smtpd_delay_reject=no
-o smtpd_milters=
-o local_recipient_maps=
-o relay_recipient_maps=
</code></pre>
<p>…and then use localhost:10025 as a target.</p>
Christoph Haas1eeb27bb-95b7-49dd-96a6-a29646a8659bWed, 25 Mar 2026 20:07:57 +0000Martin | workaround.org | Comentario
https://workaround.org/ispmail-trixie/relaying/#comentario-212d05ba-a9e6-43fb-9c82-107ba9600cfe
<p>One thing I had active on my old version of ISPstyle mailserver was fetchmail (for people who change over here and want to receive thier old addresses).<br>
In this version I have to lower smtpd_tls_security_level to "may", or fetchmail would not be able to talk to postfix ("SMTP server requires StartTLS, keeping message").<br>
Is there a better way to accomplish this, by only offering opportunistic encryption for local delivery while keeping it mandatory for external partners?</p>
Martin212d05ba-a9e6-43fb-9c82-107ba9600cfeWed, 25 Mar 2026 19:59:48 +0000Hetass'r El-Balb'r | workaround.org | Comentario
https://workaround.org/ispmail-trixie/lmtp/#comentario-5c1f58cb-ae47-4887-bf13-d3183e68ebea
<p>hmmm apparently restarting the server worked. I must have forgotten to restart a service after modifying the configuration</p>
<p>thanks</p>
Hetass'r El-Balb'r5c1f58cb-ae47-4887-bf13-d3183e68ebeaTue, 24 Mar 2026 09:36:07 +0000Christoph Haas | workaround.org | Comentario
https://workaround.org/ispmail-trixie/lmtp/#comentario-1ee36724-2822-46e9-8c1b-45e801faf6cc
<p>Hi and welcome. The cause is very likely to be found in your logs. Try "journalctl -u postfix" and look for the timestamp when this happened. Or "journalctl -u postfix -f" to follow the logs live.</p>
Christoph Haas1ee36724-2822-46e9-8c1b-45e801faf6ccTue, 24 Mar 2026 09:25:04 +0000Hetass'r El-Balb'r | workaround.org | Comentario
https://workaround.org/ispmail-trixie/lmtp/#comentario-3007c359-c847-4ff6-99a8-41953eb60795
<p>Hi<br>
this is a great tutorial. I used iredmail until recently, but as I migrated my server I decided to install everything by myself.</p>
<p>but I have a problem when testing with swaks :<br>
I use postgresql as a backend, but I adapted the queries and the configuration so the postmap -q tests were OK, as were the doveadm tests, however when I try to send a test email, I get</p>
<p>root@mail:/etc/postfix# swaks --server localhost --to <a href="mailto:[email protected]" rel="nofollow">[email protected]</a><br>
=== Trying localhost:25...<br>
=== Connected to localhost.<br>
<- 220 mail.localdomain ESMTP Postfix (Debian/GNU)<br>
-> EHLO mail.YYYY.fr<br>
<- 250-mail.localdomain<br>
<- 250-PIPELINING<br>
<- 250-SIZE 10240000<br>
<- 250-VRFY<br>
<- 250-ETRN<br>
<- 250-ENHANCEDSTATUSCODES<br>
<- 250-8BITMIME<br>
<- 250-DSN<br>
<- 250-SMTPUTF8<br>
<- 250 CHUNKING<br>
-> MAIL FROM:<a href="mailto:[email protected]" rel="nofollow">[email protected]</a><br>
<- 250 2.1.0 Ok<br>
-> RCPT TO:< <a href="mailto:[email protected]" rel="nofollow">[email protected]</a>><br>
<** 451 4.3.0 < <a href="mailto:[email protected]" rel="nofollow">[email protected]</a>>: Temporary lookup failure<br>
-> QUIT<br>
<- 221 2.0.0 Bye<br>
=== Connection closed with remote host.</p>
<p>my DNS records are OK, I can ping the mail server on both ipv4 and ipv6, both on localhost and "real" hostname<br>
no errror found in syslog</p>
<p>is there something I missed somewhere ?</p>
<p>thanks</p>
Hetass'r El-Balb'r3007c359-c847-4ff6-99a8-41953eb60795Tue, 24 Mar 2026 09:04:51 +0000Martin | workaround.org | Comentario
https://workaround.org/ispmail-trixie/database/#comentario-c4f4ad28-7949-4275-99d4-9772c726c490
<p>Thank you Christoph for this super-fast reply! I guess that's out of my reach then.<br>
And yes... I was and am aware of the security risk of still running Wheezy, but compared to earlier times family and children became important factors in my life taking their time. :-)</p>
Martinc4f4ad28-7949-4275-99d4-9772c726c490Thu, 19 Mar 2026 15:30:45 +0000Christoph Haas | workaround.org | Comentario
https://workaround.org/ispmail-trixie/database/#comentario-2700b2f1-4f5a-440f-a6ee-e81b29651c3e
<p>Hi Martin. Wheezy 2014 might not be the best choice nowadays without the security support. :) But I'm sure you are aware of that. Yeah, thanks for the report. Glad that you followed the guide for so long.</p>
<p>I have given your question to my least mistrusted AI chat. It said that it may be possible. You may be able to do some trickery and lete baikal query the virtual_users table. However the final catch is the storage of the passwords. I am using what Dovecot is defaulting to. But Baikal (according to AI) only supports either plaintext passwords in the database or a special format of MD5 hashing. The AI told me to "just" alter the code of Baikal… yeah, right.</p>
<p>I am using Nextcloud with CalDAV and CardDAV myself. And the accounts are not synced. I have considered using some OIDC server for single-sign-on. But that is another beast.</p>
<p>So… no easy solution I'm afraid.</p>
<p>Cheers, Christoph</p>
Christoph Haas2700b2f1-4f5a-440f-a6ee-e81b29651c3eThu, 19 Mar 2026 09:33:17 +0000Martin | workaround.org | Comentario
https://workaround.org/ispmail-trixie/database/#comentario-11deac72-46b9-44b1-80f8-31efaaa0fc75
<p>Hi Christoph,</p>
<p>I've been following your guides from around 2008 when I first set up my mailserver in Debian Etch. I got a bit lazy lately, so the Wheezy version from 2014 is still running... which I'm upgrading to Trixie these days.<br>
Thank you so much for your guidance!</p>
<p>There's one thing I want to ask, although it's not part of your tutorials really:<br>
Some years ago I had added <a href="https://sabre.io/baikal/" rel="nofollow noopener" target="_blank">baikal</a> to extend my server with CalDAV/CardDAV for (only two) users who want to have synced contacts/calendars without sharing those with big companies. Baikal is using MariaDB as well. I have a seperate database called "baikal" which contains a table calles "users".<br>
I'm not good with databases ... is there a chance that I drop this table and somehow create a link to the "virtual_users" table in our "mailserver" database, so that each account on our mailserver can automatically login to baikal too?</p>
<p>Thanks and best regards,<br>
Martin</p>
Martin11deac72-46b9-44b1-80f8-31efaaa0fc75Thu, 19 Mar 2026 09:14:53 +0000Caio Olivera | workaround.org | Comentario
https://workaround.org/ispmail-trixie/database/#comentario-b67d119a-618a-42d7-a545-6ebfa952026c
<p>Can I send the setup using PostgreSQL too?</p>
Caio Oliverab67d119a-618a-42d7-a545-6ebfa952026cSat, 28 Feb 2026 02:42:02 +0000Caio Olivera | workaround.org | Comentario
https://workaround.org/ispmail-trixie/relaying/#comentario-0c252881-ea6e-4bbd-9d3d-eb5611a97af0
<p>Can you please add this:</p>
<blockquote>
<p>postconf inet_protocols=all</p>
</blockquote>
<p>This fixes SMTP not connecting in some cases</p>
Caio Olivera0c252881-ea6e-4bbd-9d3d-eb5611a97af0Sat, 28 Feb 2026 02:37:20 +0000