mailserver: silence mixed-TLS-directive warning + drop SMTP scanner noise from Loki
Two mailserver-namespace log-noise cleanups (cluster's #1 Loki error source, from the 2026-06-06 log triage): 1. TLS warning: docker-mailserver SSL_TYPE=manual writes the authoritative smtpd_tls_chain_files at boot, so the legacy smtpd_tls_cert_file/key_file in our postfix-main.cf override were IGNORED and triggered postfix's 'Both smtpd_tls_chain_files and ... legacy ...' warning. Dropped the two legacy lines (functional no-op; chain_files already wins). Verified via live postconf. 2. Scanner noise (~9k lines/hr): narrow Alloy stage.drop for the benign public-SMTP probe patterns (unknown[unknown] SSL_accept resets, postscreen half-open drops, rate-limit-exceeded from unknown). Real delivery logs + real-IP SASL failures KEPT; CrowdSec bans these IPs independently, so security posture is unchanged. Validated with 'alloy fmt' (exit 0). Reversible. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
de181a9afc
commit
8a3bbde38c
2 changed files with 19 additions and 2 deletions
|
|
@ -8,8 +8,11 @@ smtp_sasl_password_maps = hash:/etc/postfix/sasl/passwd
|
|||
smtp_sasl_security_options = noanonymous
|
||||
smtp_sasl_tls_security_options = noanonymous
|
||||
smtp_tls_security_level = encrypt
|
||||
smtpd_tls_cert_file=/tmp/ssl/tls.crt
|
||||
smtpd_tls_key_file=/tmp/ssl/tls.key
|
||||
# TLS cert/key come from docker-mailserver's SSL_TYPE=manual flow, which writes
|
||||
# the authoritative `smtpd_tls_chain_files` into main.cf at boot. Setting the
|
||||
# legacy smtpd_tls_cert_file/smtpd_tls_key_file here too makes postfix warn
|
||||
# ("Both smtpd_tls_chain_files and one or more of the legacy ...") and ignore
|
||||
# them. Dropped to silence the warning — functionally a no-op (chain_files wins).
|
||||
smtpd_use_tls=yes
|
||||
# Require STARTTLS before any AUTH command on the SMTPD listener.
|
||||
# Without this, a misconfigured client that skips STARTTLS would send
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue