Postfix 3.6.0 ๋ฉ”์ผ ์„œ๋ฒ„ ๋ฆด๋ฆฌ์Šค

3.6.0๋…„๊ฐ„์˜ ๊ฐœ๋ฐœ ๋์— Postfix ๋ฉ”์ผ ์„œ๋ฒ„์˜ ์ƒˆ๋กœ์šด ์•ˆ์ • ๋ฒ„์ „์ธ 3.2์ด ์ถœ์‹œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋™์‹œ์— 2017๋…„ ์ดˆ์— ์ถœ์‹œ๋œ Postfix 2.0 ๋ธŒ๋žœ์น˜์— ๋Œ€ํ•œ ์ง€์› ์ข…๋ฃŒ๋ฅผ ๋ฐœํ‘œํ–ˆ์Šต๋‹ˆ๋‹ค. Postfix๋Š” ์ž˜ ๊ณ ์•ˆ๋œ ์•„ํ‚คํ…์ฒ˜์™€ ์ฝ”๋“œ ์„ค๊ณ„ ๋ฐ ํŒจ์น˜ ๊ฐ์‚ฌ์— ๋Œ€ํ•œ ์ƒ๋‹นํžˆ ์—„๊ฒฉํ•œ ์ •์ฑ… ๋•๋ถ„์— ๋†’์€ ๋ณด์•ˆ, ์•ˆ์ •์„ฑ ๋ฐ ์„ฑ๋Šฅ์„ ๋™์‹œ์— ๊ฒฐํ•ฉํ•œ ๋ณด๊ธฐ ๋“œ๋ฌธ ํ”„๋กœ์ ํŠธ ์ค‘ ํ•˜๋‚˜์ž…๋‹ˆ๋‹ค. ํ”„๋กœ์ ํŠธ ์ฝ”๋“œ๋Š” EPL 1.0(Eclipse Public License) ๋ฐ IPL XNUMX(IBM Public License)์— ๋”ฐ๋ผ ๋ฐฐํฌ๋ฉ๋‹ˆ๋‹ค.

600์›” ์•ฝ 33.66๋งŒ ๊ฐœ์˜ ๋ฉ”์ผ์„œ๋ฒ„๋ฅผ ๋Œ€์ƒ์œผ๋กœ ์‹ค์‹œํ•œ ์ž๋™ ์กฐ์‚ฌ์— ๋”ฐ๋ฅด๋ฉด, Postfix๊ฐ€ 34.29%(59.14๋…„ ์ „ 57.77%)์˜ ๋ฉ”์ผ ์„œ๋ฒ„์—์„œ ์‚ฌ์šฉ๋˜๊ณ  ์žˆ์œผ๋ฉฐ, Exim์ด 3.6%(3.83%), Sendmail์ด 2.02%(2.12%)๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š” ๊ฒƒ์œผ๋กœ ๋‚˜ํƒ€๋‚ฌ์Šต๋‹ˆ๋‹ค. %), MailEnable - 0.60%( 0.77%), MDaemon - 0.32%(0.47%), Microsoft Exchange - XNUMX%(XNUMX%).

์ฃผ์š” ํ˜์‹ :

  • Postfix ๊ตฌ์„ฑ ์š”์†Œ ๊ฐ„์˜ ์ƒํ˜ธ ์ž‘์šฉ์— ์‚ฌ์šฉ๋˜๋Š” ๋‚ด๋ถ€ ํ”„๋กœํ† ์ฝœ์˜ ๋ณ€๊ฒฝ์œผ๋กœ ์ธํ•ด ์—…๋ฐ์ดํŠธํ•˜๊ธฐ ์ „์— "postfix stop" ๋ช…๋ น์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉ”์ผ ์„œ๋ฒ„๋ฅผ ์ค‘์ง€ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด ํ”ฝ์—…, qmgr, verify, tlsproxy ๋ฐ postscreen ํ”„๋กœ์„ธ์Šค์™€ ์ƒํ˜ธ ์ž‘์šฉํ•  ๋•Œ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•˜์—ฌ Postfix๊ฐ€ ๋‹ค์‹œ ์‹œ์ž‘๋  ๋•Œ๊นŒ์ง€ ์ด๋ฉ”์ผ ์ „์†ก์ด ์ง€์—ฐ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ์ผ๋ถ€ ์ปค๋ฎค๋‹ˆํ‹ฐ ๊ตฌ์„ฑ์›์ด ์ธ์ข…์ฐจ๋ณ„๋กœ ์ธ์‹ํ•˜๋Š” '๋ฐฑ์ธ'๊ณผ 'ํ‘์ธ'์ด๋ผ๋Š” ๋‹จ์–ด์— ๋Œ€ํ•œ ์–ธ๊ธ‰์ด ์‚ญ์ œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด์ œ "ํ™”์ดํŠธ๋ฆฌ์ŠคํŠธ" ๋ฐ "๋ธ”๋ž™๋ฆฌ์ŠคํŠธ" ๋Œ€์‹  "ํ—ˆ์šฉ ๋ชฉ๋ก" ๋ฐ "๊ฑฐ๋ถ€ ๋ชฉ๋ก"์„ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: ๋งค๊ฐœ๋ณ€์ˆ˜ postscreen_allowlist_interfaces, postscreen_denylist_action ๋ฐ postscreen_dnsbl_allowlist_threshold). ๋ณ€๊ฒฝ ์‚ฌํ•ญ์€ ๋ฌธ์„œํ™”, ์‚ฌํ›„ ํ™”๋ฉด ํ”„๋กœ์„ธ์Šค ์„ค์ •(๋‚ด์žฅ ๋ฐฉํ™”๋ฒฝ) ๋ฐ ๋กœ๊ทธ ์ •๋ณด ๋ฐ˜์˜์— ์˜ํ–ฅ์„ ๋ฏธ์นฉ๋‹ˆ๋‹ค. postfix/postscreen[pid]: ALLOWLIST VETO [์ฃผ์†Œ]:port postfix/postscreen[pid]: ALLOWLISTED [์ฃผ์†Œ]:port postfix/postscreen[pid]: DENYLISTED [address]:port

    ๋กœ๊ทธ์˜ ์ด์ „ ์šฉ์–ด๋ฅผ ๋ณด์กดํ•˜๊ธฐ ์œ„ํ•ด "compatibility_level = 3.6" ์ด์ „์— main.cf์— ์ง€์ •๋˜์–ด์•ผ ํ•˜๋Š” "relative_logging = no" ๋งค๊ฐœ๋ณ€์ˆ˜๊ฐ€ ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค. ์ด์ „ ์‚ฌํ›„ ํ™”๋ฉด ์„ค์ • ์ด๋ฆ„์— ๋Œ€ํ•œ ์ง€์›์€ ์ด์ „ ๋ฒ„์ „๊ณผ์˜ ํ˜ธํ™˜์„ฑ์„ ์œ„ํ•ด ์œ ์ง€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ ๊ตฌ์„ฑ ํŒŒ์ผ โ€œmaster.cfโ€๋Š” ํ˜„์žฌ ๋ณ€๊ฒฝ๋˜์ง€ ์•Š์€ ์ƒํƒœ๋กœ ์œ ์ง€๋ฉ๋‹ˆ๋‹ค.

  • "compatibility_level = 3.6" ๋ชจ๋“œ์—์„œ๋Š” MD256 ๋Œ€์‹  SHA5 ํ•ด์‹œ ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ธฐ๋ณธ ์Šค์œ„์น˜๊ฐ€ ๋งŒ๋“ค์–ด์กŒ์Šต๋‹ˆ๋‹ค. Compatibility_level ๋งค๊ฐœ๋ณ€์ˆ˜์— ์ด์ „ ๋ฒ„์ „์„ ์„ค์ •ํ•˜๋ฉด MD5๊ฐ€ ๊ณ„์† ์‚ฌ์šฉ๋˜์ง€๋งŒ, ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด ๋ช…์‹œ์ ์œผ๋กœ ์ •์˜๋˜์ง€ ์•Š์€ ํ•ด์‹œ ์‚ฌ์šฉ๊ณผ ๊ด€๋ จ๋œ ์„ค์ •์˜ ๊ฒฝ์šฐ ๋กœ๊ทธ์— ๊ฒฝ๊ณ ๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. Diffie-Hellman ํ‚ค ๊ตํ™˜ ํ”„๋กœํ† ์ฝœ์˜ ๋‚ด๋ณด๋‚ด๊ธฐ ๋ฒ„์ „์— ๋Œ€ํ•œ ์ง€์›์ด ์ค‘๋‹จ๋˜์—ˆ์Šต๋‹ˆ๋‹ค(tlsproxy_tls_dh512_param_file ๋งค๊ฐœ๋ณ€์ˆ˜ ๊ฐ’์€ ์ด์ œ ๋ฌด์‹œ๋ฉ๋‹ˆ๋‹ค).
  • master.cf์— ์ž˜๋ชป๋œ ํ•ธ๋“ค๋Ÿฌ ํ”„๋กœ๊ทธ๋žจ์„ ์ง€์ •ํ•˜๋Š” ๊ฒƒ๊ณผ ๊ด€๋ จ๋œ ๋ฌธ์ œ๋ฅผ ๊ฐ„๋‹จํ•˜๊ฒŒ ์ง„๋‹จํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์˜ค๋ฅ˜๋ฅผ ๊ฐ์ง€ํ•˜๊ธฐ ์œ„ํ•ด postdrop์„ ํฌํ•จํ•œ ๊ฐ ๋ฐฑ์—”๋“œ ์„œ๋น„์Šค๋Š” ์ด์ œ ํ†ต์‹ ์„ ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ํ”„๋กœํ† ์ฝœ ์ด๋ฆ„์„ ๊ด‘๊ณ ํ•˜๊ณ  sendmail์„ ํฌํ•จํ•œ ๊ฐ ํด๋ผ์ด์–ธํŠธ ํ”„๋กœ์„ธ์Šค๋Š” ๊ด‘๊ณ ๋œ ํ”„๋กœํ† ์ฝœ ์ด๋ฆ„์ด ์ง€์›๋˜๋Š” ๋ณ€ํ˜•๊ณผ ์ผ์น˜ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • sendmail ๋ฐ postdrop ํ”„๋กœ์„ธ์Šค์— ๋Œ€ํ•œ ๋ณด๋‚ธ ์‚ฌ๋žŒ์˜ ๋ด‰ํˆฌ ์ฃผ์†Œ(SMTP ์„ธ์…˜ ์ค‘ "MAIL FROM" ๋ช…๋ น์—์„œ ์ œ๊ณต๋จ) ํ• ๋‹น์„ ์œ ์—ฐํ•˜๊ฒŒ ์ œ์–ดํ•˜๊ธฐ ์œ„ํ•ด ์ƒˆ๋กœ์šด ๋งคํ•‘ ์œ ํ˜• "local_login_sender_maps"๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด ๋ฃจํŠธ ๋ฐ ํฌ์ŠคํŠธํ”ฝ์Šค๋ฅผ ์ œ์™ธํ•œ ๋กœ์ปฌ ์‚ฌ์šฉ์ž๊ฐ€ ์ด๋ฆ„์— ๋Œ€ํ•œ UID ๋ฐ”์ธ๋”ฉ์„ ์‚ฌ์šฉํ•˜์—ฌ sendmail์— ์ž์‹ ์˜ ๋กœ๊ทธ์ธ๋งŒ ์ง€์ •ํ•˜๋„๋ก ํ—ˆ์šฉํ•˜๋ ค๋ฉด ๋‹ค์Œ ์„ค์ •์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. /etc/postfix/main.cf: local_login_sender_maps = inline :{ { root = *} , { postfix = * } }, pcre:/etc/postfix/login_senders /etc/postfix/login_senders: # ๋กœ๊ทธ์ธ๊ณผ login@domain ํ˜•์‹์„ ๋ชจ๋‘ ์ง€์ •ํ•˜๋Š” ๊ฒƒ์ด ํ—ˆ์šฉ๋ฉ๋‹ˆ๋‹ค. /(.+)/ $1 $1โ€ฆ@example.com
  • ๊ธฐ๋ณธ์ ์œผ๋กœ "smtpd_relay_before_recipient_restrictions=yes" ์„ค์ •์ด ์ถ”๊ฐ€๋˜๊ณ  ํ™œ์„ฑํ™”๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ์„ค์ •์—์„œ๋Š” SMTP ์„œ๋ฒ„๊ฐ€ ์ด์ „๊ณผ ๊ฐ™์ด smtpd_recipient_restrictions ์ด์ „์— smtpd_relay_restrictions๋ฅผ ํ™•์ธํ•˜๊ณ  ๊ทธ ๋ฐ˜๋Œ€๋Š” ํ™•์ธํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
  • SASL ๋ฐฑ์—”๋“œ๊ฐ€ Postfix์—์„œ ์ง€์›๋˜์ง€ ์•Š๋Š” "EXTERNAL" ๋ชจ๋“œ๋ฅผ ์ง€์›ํ•œ๋‹ค๊ณ  ์ฃผ์žฅํ•˜๋Š” ๊ฒฝ์šฐ ํ˜ผ๋™๋˜๋Š” ์˜ค๋ฅ˜๋ฅผ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ๊ธฐ๋ณธ๊ฐ’์ด "!external, static:rest"์ธ "smtpd_sasl_mechanism_list" ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค.
  • DNS์—์„œ ์ด๋ฆ„์„ ํ™•์ธํ•  ๋•Œ ๋ฉ€ํ‹ฐ์Šค๋ ˆ๋”ฉ(threadsafe)์„ ์ง€์›ํ•˜๋Š” ์ƒˆ๋กœ์šด API๊ฐ€ ๊ธฐ๋ณธ์ ์œผ๋กœ ํ™œ์„ฑํ™”๋ฉ๋‹ˆ๋‹ค. ์ด์ „ API๋กœ ๋นŒ๋“œํ•˜๋ ค๋ฉด ๋นŒ๋“œํ•  ๋•Œ "make makefiles CCARGS="-DNO_RES_NCALLSโ€ฆ"๋ฅผ ์ง€์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • ๋™์ผํ•œ ํ† ๋ก  ID๋กœ ๋ฐฐ๋‹ฌ ๋ฌธ์ œ, ๋ฐฐ๋‹ฌ ์ง€์—ฐ ๋˜๋Š” ๋ฐฐ๋‹ฌ ํ™•์ธ์— ๋Œ€ํ•œ ์•Œ๋ฆผ์„ ๋Œ€์ฒดํ•˜๊ธฐ ์œ„ํ•ด "enable_threaded_bounces = yes" ๋ชจ๋“œ๋ฅผ ์ถ”๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค(์•Œ๋ฆผ์€ ๋‹ค๋ฅธ ์„œ์‹  ๋ฉ”์‹œ์ง€์™€ ํ•จ๊ป˜ ๋™์ผํ•œ ์Šค๋ ˆ๋“œ์˜ ๋ฉ”์ผ ํด๋ผ์ด์–ธํŠธ์— ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค).
  • ๊ธฐ๋ณธ์ ์œผ๋กœ /etc/services ์‹œ์Šคํ…œ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค๋Š” ๋” ์ด์ƒ SMTP ๋ฐ LMTP์— ๋Œ€ํ•œ TCP ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ๊ฒฐ์ •ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋Œ€์‹ , Known_tcp_ports ๋งค๊ฐœ๋ณ€์ˆ˜(๊ธฐ๋ณธ๊ฐ’ lmtp=24, smtp=25, smtps=submissions=465, submit=587)๋ฅผ ํ†ตํ•ด ํฌํŠธ ๋ฒˆํ˜ธ๊ฐ€ ๊ตฌ์„ฑ๋ฉ๋‹ˆ๋‹ค. Known_tcp_ports์—์„œ ์ผ๋ถ€ ์„œ๋น„์Šค๊ฐ€ ๋ˆ„๋ฝ๋œ ๊ฒฝ์šฐ /etc/services๊ฐ€ ๊ณ„์† ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
  • ํ˜ธํ™˜์„ฑ ์ˆ˜์ค€(โ€œcompatibility_levelโ€)์ด โ€œ3.6โ€์œผ๋กœ ๋†’์•„์กŒ์Šต๋‹ˆ๋‹ค(๋งค๊ฐœ๋ณ€์ˆ˜๋Š” ๊ณผ๊ฑฐ์— ๋‘ ๋ฒˆ ๋ณ€๊ฒฝ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. 3.6์„ ์ œ์™ธํ•˜๊ณ  ์ง€์›๋˜๋Š” ๊ฐ’์€ 0(๊ธฐ๋ณธ๊ฐ’), 1, 2์ž…๋‹ˆ๋‹ค). ์ด์ œ๋ถ€ํ„ฐ "compatibility_level"์€ ํ˜ธํ™˜์„ฑ์„ ์œ„๋ฐ˜ํ•˜๋Š” ๋ณ€๊ฒฝ์ด ์ด๋ฃจ์–ด์ง„ ๋ฒ„์ „ ๋ฒˆํ˜ธ๋กœ ๋ณ€๊ฒฝ๋ฉ๋‹ˆ๋‹ค. ํ˜ธํ™˜์„ฑ ์ˆ˜์ค€์„ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด main.cf ๋ฐ master.cf์— "<=level" ๋ฐ "<level"๊ณผ ๊ฐ™์€ ๋ณ„๋„์˜ ๋น„๊ต ์—ฐ์‚ฐ์ž๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค(ํ‘œ์ค€ ๋น„๊ต ์—ฐ์‚ฐ์ž๋Š” 3.10๋ณด๋‹ค 3.9์„ ๊ณ ๋ คํ•˜๋ฏ€๋กœ ์ ํ•ฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค).

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€