Skip to content

Latest commit

 

History

History
95 lines (68 loc) · 3.06 KB

90-2023-10-04.md

File metadata and controls

95 lines (68 loc) · 3.06 KB

2023-10-04 추가

  1. postfix 설정 변경

    • 메일 서버가 mail.ryuar.in 이고,

    • 메일 도메인이 ryuar.in 이기 때문에 아래와 같이 설정 변경

      # /etc/postfix/main.cf
      
      (...)
      
      # from
      # myhostname = ryuar.in
      # to
      myhostname = mail.ryuar.in
      
      (...)
      
  2. DNS 레코드 추가 또는 변경

    Name Type Data
    mail.ryuar.in TXT v=spf1 include:ryuar.in -all
  3. OpenDKIM 인증서를 2048비트로 재발급

    1. 새 인증서 생성

      opendkim-genkey -r -b 2048 -D /etc/opendkim -s mail2048 --subdomains -d ryuar.in
    2. 권한 재설정

      chown opendkim:postfix -R /etc/opendkim
      chmod g+r /etc/opendkim/mail2048.private
    3. 레코드 값 확인

      # cat /etc/opendkim/mail2048.txt
      mail2048._domainkey     IN      TXT     ( "v=DKIM1; k=rsa; s=email; "
        "p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuwCHmIoMxHk3cArugm9pCbU/WM1EQm+f2L69PsiJOPEnApMe5zR9mSQwXdfSxuPjeBBLtB/mnNL4gS8E/SqLIFQCGP109uPgv5wGjuXqocnTG+vsQA+jITg8MN9QlwhpAZ7uDwmWf0pknCt9qmOZYCNImGW73NUlGxWHp0rdmV/XGpPCjXjppPEnVFLpJcnADlUnmMF9E2K6ER"
        "/YQUH3m7OJKav9ssCKZFrUWz/iurRGD1nDCpU4etUdHrSRHrhY0bct8RcGqpDg5Q+qxNAZoB0eJuiKsIhplUnOzWO27l1p9kcUO9YkjVhPOpx5OnWHVCIAFiySlZUlgC14y2jaAwIDAQAB" )  ; ----- DKIM key mail2048 for ryuar.in
    4. /etc/opendkim/opendkim.conf 수정

      # /etc/opendkim/opendkim.conf
      BaseDirectory           /var/lib/opendkim
      Domain                  ryuar.in
      KeyFile                 /etc/opendkim/mail2048.private
      Selector                mail2048
      Socket                  local:/run/opendkim/opendkim.sock
      Syslog                  Yes
      TemporaryDirectory      /run/opendkim
      UMask                   002
      RequireSafeKeys         false
      
    5. DNS 레코드 추가

      Name Type Data
      mail2048._domainkey.ryuar.in TXT v=DKIM1; k=rsa; s=email;p=.......
    6. /etc/amavisd/amavisd.conf 수정

      (...)
      
      # From
      #dkim_key('ryuanerin.kr', 'myselector', '/etc/opendkim/myselector.private');
      #dkim_key(  'ryuaner.in', 'myselector', '/etc/opendkim/myselector.private');
      #dkim_key(    'ryuar.in', 'myselector', '/etc/opendkim/myselector.private');
      # To
      
      dkim_key('ryuanerin.kr', 'mail2048', '/etc/opendkim/mail2048.private');
      dkim_key(  'ryuaner.in', 'mail2048', '/etc/opendkim/mail2048.private');
      dkim_key(    'ryuar.in', 'mail2048', '/etc/opendkim/mail2048.private');
      
      (...)
      
    7. 서비스 재시작

      systemctl restart amavisd opendkim