|
@@ -11,6 +11,7 @@ address_verify_map = btree:$data_directory/verify_cache
|
11
|
11
|
address_verify_negative_cache = yes
|
12
|
12
|
address_verify_negative_expire_time = 3d
|
13
|
13
|
address_verify_negative_refresh_time = 3h
|
|
14
|
+address_verify_pending_request_limit = 5000
|
14
|
15
|
address_verify_poll_count = ${stress?{1}:{3}}
|
15
|
16
|
address_verify_poll_delay = 3s
|
16
|
17
|
address_verify_positive_expire_time = 31d
|
|
@@ -92,6 +93,7 @@ default_recipient_limit = 20000
|
92
|
93
|
default_recipient_refill_delay = 5s
|
93
|
94
|
default_recipient_refill_limit = 100
|
94
|
95
|
default_transport = smtp
|
|
96
|
+default_transport_rate_delay = 0s
|
95
|
97
|
default_verp_delimiters = +=
|
96
|
98
|
defer_code = 450
|
97
|
99
|
defer_service_name = defer
|
|
@@ -108,6 +110,7 @@ disable_mime_input_processing = no
|
108
|
110
|
disable_mime_output_conversion = no
|
109
|
111
|
disable_verp_bounces = no
|
110
|
112
|
disable_vrfy_command = no
|
|
113
|
+dns_ncache_ttl_fix_enable = no
|
111
|
114
|
dnsblog_reply_delay = 0s
|
112
|
115
|
dnsblog_service_name = dnsblog
|
113
|
116
|
dont_remove = 0
|
|
@@ -135,6 +138,7 @@ error_recipient_limit = $default_recipient_limit
|
135
|
138
|
error_recipient_refill_delay = $default_recipient_refill_delay
|
136
|
139
|
error_recipient_refill_limit = $default_recipient_refill_limit
|
137
|
140
|
error_service_name = error
|
|
141
|
+error_transport_rate_delay = $default_transport_rate_delay
|
138
|
142
|
execution_directory_expansion_filter = 1234567890!@%-_=+:,./abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ
|
139
|
143
|
expand_owner_alias = no
|
140
|
144
|
export_environment = TZ MAIL_CONFIG LANG
|
|
@@ -205,6 +209,7 @@ lmtp_dns_resolver_options =
|
205
|
209
|
lmtp_dns_support_level =
|
206
|
210
|
lmtp_enforce_tls = no
|
207
|
211
|
lmtp_extra_recipient_limit = $default_extra_recipient_limit
|
|
212
|
+lmtp_fallback_relay =
|
208
|
213
|
lmtp_generic_maps =
|
209
|
214
|
lmtp_header_checks =
|
210
|
215
|
lmtp_host_lookup = dns
|
|
@@ -281,6 +286,7 @@ lmtp_tls_session_cache_timeout = 3600s
|
281
|
286
|
lmtp_tls_trust_anchor_file =
|
282
|
287
|
lmtp_tls_verify_cert_match = hostname
|
283
|
288
|
lmtp_tls_wrappermode = no
|
|
289
|
+lmtp_transport_rate_delay = $default_transport_rate_delay
|
284
|
290
|
lmtp_use_tls = no
|
285
|
291
|
lmtp_xforward_timeout = 300s
|
286
|
292
|
local_command_shell =
|
|
@@ -303,11 +309,12 @@ local_recipient_maps = proxy:unix:passwd.byname $alias_maps
|
303
|
309
|
local_recipient_refill_delay = $default_recipient_refill_delay
|
304
|
310
|
local_recipient_refill_limit = $default_recipient_refill_limit
|
305
|
311
|
local_transport = local:$myhostname
|
|
312
|
+local_transport_rate_delay = $default_transport_rate_delay
|
306
|
313
|
luser_relay =
|
307
|
314
|
mail_name = Postfix
|
308
|
315
|
mail_owner = postfix
|
309
|
|
-mail_release_date = 20151010
|
310
|
|
-mail_version = 3.0.3
|
|
316
|
+mail_release_date = 20160224
|
|
317
|
+mail_version = 3.1.0
|
311
|
318
|
mailbox_command =
|
312
|
319
|
mailbox_command_maps =
|
313
|
320
|
mailbox_delivery_lock = fcntl, dotlock
|
|
@@ -339,6 +346,7 @@ milter_end_of_header_macros = i
|
339
|
346
|
milter_header_checks =
|
340
|
347
|
milter_helo_macros = {tls_version} {cipher} {cipher_bits} {cert_subject} {cert_issuer}
|
341
|
348
|
milter_macro_daemon_name = $myhostname
|
|
349
|
+milter_macro_defaults =
|
342
|
350
|
milter_macro_v = $mail_name $mail_version
|
343
|
351
|
milter_mail_macros = i {auth_type} {auth_authen} {auth_author} {mail_addr} {mail_host} {mail_mailer}
|
344
|
352
|
milter_protocol = 6
|
|
@@ -360,6 +368,7 @@ nested_header_checks = $header_checks
|
360
|
368
|
non_fqdn_reject_code = 504
|
361
|
369
|
non_smtpd_milters =
|
362
|
370
|
notify_classes = resource, software
|
|
371
|
+openssl_path = openssl
|
363
|
372
|
owner_request_special = yes
|
364
|
373
|
parent_domain_matches_subdomains = debug_peer_list,fast_flush_domains,mynetworks,permit_mx_backup_networks,qmqpd_authorized_clients,relay_domains,smtpd_access_maps
|
365
|
374
|
permit_mx_backup_networks =
|
|
@@ -385,11 +394,12 @@ postscreen_disable_vrfy_command = $disable_vrfy_command
|
385
|
394
|
postscreen_discard_ehlo_keyword_address_maps = $smtpd_discard_ehlo_keyword_address_maps
|
386
|
395
|
postscreen_discard_ehlo_keywords = $smtpd_discard_ehlo_keywords
|
387
|
396
|
postscreen_dnsbl_action = ignore
|
|
397
|
+postscreen_dnsbl_max_ttl = ${postscreen_dnsbl_ttl?{$postscreen_dnsbl_ttl}:{1}}h
|
|
398
|
+postscreen_dnsbl_min_ttl = 60s
|
388
|
399
|
postscreen_dnsbl_reply_map =
|
389
|
400
|
postscreen_dnsbl_sites =
|
390
|
401
|
postscreen_dnsbl_threshold = 1
|
391
|
402
|
postscreen_dnsbl_timeout = 10s
|
392
|
|
-postscreen_dnsbl_ttl = 1h
|
393
|
403
|
postscreen_dnsbl_whitelist_threshold = 0
|
394
|
404
|
postscreen_enforce_tls = $smtpd_enforce_tls
|
395
|
405
|
postscreen_expansion_filter = $smtpd_expansion_filter
|
|
@@ -415,7 +425,6 @@ postscreen_use_tls = $smtpd_use_tls
|
415
|
425
|
postscreen_watchdog_timeout = 10s
|
416
|
426
|
postscreen_whitelist_interfaces = static:all
|
417
|
427
|
prepend_delivered_header = command, file, forward
|
418
|
|
-process_id = 13574
|
419
|
428
|
process_id_directory = pid
|
420
|
429
|
process_name = postconf
|
421
|
430
|
propagate_unmatched_extensions = canonical, virtual
|
|
@@ -467,6 +476,7 @@ relay_recipient_maps =
|
467
|
476
|
relay_recipient_refill_delay = $default_recipient_refill_delay
|
468
|
477
|
relay_recipient_refill_limit = $default_recipient_refill_limit
|
469
|
478
|
relay_transport = relay
|
|
479
|
+relay_transport_rate_delay = $default_transport_rate_delay
|
470
|
480
|
relayhost =
|
471
|
481
|
relocated_maps =
|
472
|
482
|
remote_header_rewrite_domain =
|
|
@@ -490,6 +500,7 @@ retry_minimum_delivery_slots = $default_minimum_delivery_slots
|
490
|
500
|
retry_recipient_limit = $default_recipient_limit
|
491
|
501
|
retry_recipient_refill_delay = $default_recipient_refill_delay
|
492
|
502
|
retry_recipient_refill_limit = $default_recipient_refill_limit
|
|
503
|
+retry_transport_rate_delay = $default_transport_rate_delay
|
493
|
504
|
rewrite_service_name = rewrite
|
494
|
505
|
send_cyrus_sasl_authzid = no
|
495
|
506
|
sender_bcc_maps =
|
|
@@ -587,6 +598,7 @@ smtp_tls_CApath =
|
587
|
598
|
smtp_tls_block_early_mail_reply = no
|
588
|
599
|
smtp_tls_cert_file =
|
589
|
600
|
smtp_tls_ciphers = medium
|
|
601
|
+smtp_tls_dane_insecure_mx_policy = dane
|
590
|
602
|
smtp_tls_dcert_file =
|
591
|
603
|
smtp_tls_dkey_file = $smtp_tls_dcert_file
|
592
|
604
|
smtp_tls_eccert_file =
|
|
@@ -613,12 +625,14 @@ smtp_tls_session_cache_timeout = 3600s
|
613
|
625
|
smtp_tls_trust_anchor_file =
|
614
|
626
|
smtp_tls_verify_cert_match = hostname
|
615
|
627
|
smtp_tls_wrappermode = no
|
|
628
|
+smtp_transport_rate_delay = $default_transport_rate_delay
|
616
|
629
|
smtp_use_tls = no
|
617
|
630
|
smtp_xforward_timeout = 300s
|
618
|
631
|
smtpd_authorized_verp_clients = $authorized_verp_clients
|
619
|
632
|
smtpd_authorized_xclient_hosts =
|
620
|
633
|
smtpd_authorized_xforward_hosts =
|
621
|
634
|
smtpd_banner = $myhostname ESMTP $mail_name
|
|
635
|
+smtpd_client_auth_rate_limit = 0
|
622
|
636
|
smtpd_client_connection_count_limit = 50
|
623
|
637
|
smtpd_client_connection_rate_limit = 0
|
624
|
638
|
smtpd_client_event_limit_exceptions = ${smtpd_client_connection_limit_exceptions:$mynetworks}
|
|
@@ -654,6 +668,7 @@ smtpd_per_record_deadline = ${stress?{yes}:{no}}
|
654
|
668
|
smtpd_policy_service_default_action = 451 4.3.5 Server configuration problem
|
655
|
669
|
smtpd_policy_service_max_idle = 300s
|
656
|
670
|
smtpd_policy_service_max_ttl = 1000s
|
|
671
|
+smtpd_policy_service_policy_context =
|
657
|
672
|
smtpd_policy_service_request_limit = 0
|
658
|
673
|
smtpd_policy_service_retry_delay = 1s
|
659
|
674
|
smtpd_policy_service_timeout = 100s
|
|
@@ -741,11 +756,11 @@ tls_dane_trust_anchor_digest_enable = yes
|
741
|
756
|
tls_disable_workarounds =
|
742
|
757
|
tls_eecdh_strong_curve = prime256v1
|
743
|
758
|
tls_eecdh_ultra_curve = secp384r1
|
744
|
|
-tls_export_cipherlist = aNULL:-aNULL:ALL:+RC4:@STRENGTH
|
745
|
|
-tls_high_cipherlist = aNULL:-aNULL:ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@STRENGTH
|
|
759
|
+tls_export_cipherlist = aNULL:-aNULL:HIGH:MEDIUM:LOW:EXPORT:+RC4:@STRENGTH
|
|
760
|
+tls_high_cipherlist = aNULL:-aNULL:HIGH:@STRENGTH
|
746
|
761
|
tls_legacy_public_key_fingerprints = no
|
747
|
|
-tls_low_cipherlist = aNULL:-aNULL:ALL:!EXPORT:+RC4:@STRENGTH
|
748
|
|
-tls_medium_cipherlist = aNULL:-aNULL:ALL:!EXPORT:!LOW:+RC4:@STRENGTH
|
|
762
|
+tls_low_cipherlist = aNULL:-aNULL:HIGH:MEDIUM:LOW:+RC4:@STRENGTH
|
|
763
|
+tls_medium_cipherlist = aNULL:-aNULL:HIGH:MEDIUM:+RC4:@STRENGTH
|
749
|
764
|
tls_null_cipherlist = eNULL:!aNULL
|
750
|
765
|
tls_preempt_cipherlist = no
|
751
|
766
|
tls_random_bytes = 32
|
|
@@ -837,4 +852,5 @@ virtual_recipient_limit = $default_recipient_limit
|
837
|
852
|
virtual_recipient_refill_delay = $default_recipient_refill_delay
|
838
|
853
|
virtual_recipient_refill_limit = $default_recipient_refill_limit
|
839
|
854
|
virtual_transport = virtual
|
|
855
|
+virtual_transport_rate_delay = $default_transport_rate_delay
|
840
|
856
|
virtual_uid_maps =
|