clean-up ssl

This commit is contained in:
andreas
2023-04-06 21:49:21 +00:00
parent b277bff19d
commit 1bdf801fac
20 changed files with 237 additions and 214 deletions

View File

@@ -34,9 +34,9 @@ default_transport = smtp:[relay.zntrl.de]:465
# SMPTD (inbound) TLS parameters
smtpd_tls_CApath = /etc/ssl/certs
smtpd_tls_CAfile = /etc/ssl/certs/balusign-signing-ca.pem
smtpd_tls_cert_file = /etc/ssl/nuc0-full-chain.pem
smtpd_tls_key_file = /etc/ssl/private/nuc0.lan.key
smtpd_tls_CAfile = /etc/postfix/ssl/certs/balusign-signing-ca.pem
smtpd_tls_cert_file = /etc/postfix/ssl/nuc0-full-chain.pem
smtpd_tls_key_file = /etc/postfix/ssl/private/nuc0.lan.key
smtpd_tls_security_level=may
smtpd_tls_loglevel = 1
@@ -44,8 +44,8 @@ smtpd_relay_restrictions = permit_mynetworks permit_sasl_authenticated defer_una
# SMTP (outbound)
smtp_tls_CApath=/etc/ssl/certs
smtp_tls_key_file = /etc/ssl/private/nuc0.lan.key
smtp_tls_cert_file = /etc/ssl/nuc0-full-chain.pem
smtp_tls_key_file = /etc/postfix/ssl/private/nuc0.lan.key
smtp_tls_cert_file = /etc/postfix/ssl/nuc0-full-chain.pem
smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache
smtp_tls_wrappermode = yes
smtp_tls_security_level = encrypt