September 23, 2021 Roberto Puzzanghera 75 comments
- Inter7's original page
- Combined patch v. 2021.09.23
- More info here
Vpopmail provides an easy way to manage virtual email domains and non /etc/passwd email accounts on your mail servers.
The purpose of this note is to show how to use
Mysql as the authentication system. Having a users database also offers the advantage of communicating with the database via
PHP, and creating web-based user interfaces to manage accounts.
The patch we'll apply is the result of the following bunch of patches:
- sql-aliasdomains patch, which makes vpopmail save the aliasdomains to
MySQL. This makes the
dovecotsql auth driver aware of the aliasdomains, provided that you modify the sql query as well (see the
dovecotpage for more info).
- defaultdelivery patch, which makes vpopmail to copy your favourite delivery agent (stored in QMAILDIR/control/defauldelivery) into the .qmail-default file of any newly created domain, overriding the default vpopmail's behaviour, where vpopmail copies its delivery agent vdelivermail. You have to configure with
--enable-defaultdeliveryto enable this.
If the functionality is disabled (
--disable-defaultdelivery, which is the default option)
vdelivermailis installed with the "delete" option instead of "bounce-no-mailbox", which is not reasonable anymore.
- dovecot-pwd_query patch
If you want to use the
dovecot's sql auth driver with one table for each domain (
--disable-many-domains) you have to heavily customize your password query. With this patch
vpopmailinstalls the sql procedure and functions in the database when you create a new domain. The procedure can be called by
dovecotto perform the auth.
The sql stuff supports aliasdomains and
mysqllimits and will be loaded from
~/vpopmail/etc/pwd-query_disable-many-domains.sql. You can customize the sql procedure editing this file.
You have to configure with
--enable-mysql-bin=PATHas we have to install the procedure calling the
mysqlbin as a shell command (no way to load an sql query from a file in C language, comments welcome).
- recipient check patch. It can be used with Erwin Hoffmann's s/qmail to accomplish the recipent check. Not important in my installation, look at doc/README.vrcptcheck for more info.
- gcc-10-compat patch, which gets vpopmail to compile with
August 22, 2021 Roberto Puzzanghera 325 comments
The complete changelog and patch info are inside the README.PATCH file.
- Aug 22, 2021
-minor fix to qlog: now it logs the auth-type correctly (diff)
-chkuser: defined extra allowed characters in sender/rcpt addresses and added the slash to the list (tx Thomas). diff here
-RSA key and DH parameters are created 4096 bit long also in Makefile-cert. qmail-smtpd.c and qmail-remote.c updated accordingly (tx Eric Broch).
-Makefile-cert: the certs will be owned by vpopmail:vchkpw
-update_tmprsadh.sh: RSA key and DH parameters increased to 4096 bits
received.c: some adjustments to compile with gcc-10 (diff here)
-dk-filter: corrected a bug where dk-filter was using DKIMDOMAIN unconditionally. Now it uses DKIMDOMAIN only if _SENDER is null (tx Manvendra Bhangui).
-added a fix for CVE-2005-2513 (tx C)
-qmail-smtpd.c: added rcptcount = 0; in smtp_rset function to prevent the maxrcpto error if control/maxrcpt limit has been exceeded in multiple messages sent sequentially rather than in a single mail (tx Alexandre Fonceca)
-qmail-remote-logging patch added (more info here)
-DKIM patch updated to v. 1.28
* outgoing messages from null sender ("<>") will be signed as well with the domain in env variable DKIMDOMAIN
* declaring NODK env variable disables old domainkeys signature, while defining NODKIM disables DKIM.
July 14, 2021 Roberto Puzzanghera 0 comments
This page concerns the setup of several filtering networks which help
spamassassin to decide if a given message is spam or not. Enabling them, together with the bayesian learning system, drastically improves the
spamassassin efficiency in doing this.
July 12, 2021 Roberto Puzzanghera 20 comments
SpamAssassin can now load users' score files from an SQL database. The concept here is to have a web application (PHP/perl/ASP/etc.) that will allow users to be able to update their local preferences on how SpamAssassin will filter their e-mail. The most common use for a system like this would be for users to be able to update the white/black list of addresses without the need for them to update their $HOME/.spamassassin/user_prefs file.
You can skip this page if you want to manage only global options via /etc/mail/spamassassin.
Be aware that user rules will be easily managed by means of the "sauprefs" plugin of Rouncube webmail.
- Jul 12, 2021
-bug fix: the "preference" varchar length in the database "userprefs" table was increased to 50 (was 30) to create space for long labels such as "bayes_auto_learn_threshold_spam", which resulted truncated before the modification.
June 20, 2021 Roberto Puzzanghera 0 comments
Now that we have the spam filters in place we have to train our bayesian system and report our spam to
The obvious thing that comes in mind at this point could be to call
spamassassin --report in cascade when clicking in the
Roundcube webmail's "Mark as Junk" button (look at the
multi_driver drivers of the markasjunk plugin), but this option has a couple of downsides:
- the learning process, the resulting journal syncing and the connection to several filtering networks takes up to 10 seconds, a time interval that our users don't want to wait.
- even worse, when they click the "Mark as Junk" button it is not always for a real spam message. For example, think about the regular newsletters that they no longer want to read and that they decide to conveniently label as spamming instead of unsubscribe in the proper way.
Therefore it is better to run these two tasks by means a cronjob every night (and this is going to solve the first issue), processing the messages stored in a folder where the users had copied only real spam or ham messages (then fixing the second as well).
March 9, 2021 Roberto Puzzanghera 36 comments
Those who are still using the
vpopmail auth driver should consider a migration to another backend, as on January 4, 2021
dovecot-2.3.13 was released and the
vpopmail auth driver removed (more info here).
I'll show below how to support domain aliases with the sql driver both with all domains in the same
vpopmail table and with one table for each domain (
--disable-many-domains). You can find how to setup the driver in this page. A short reference to
vconvert program is presented toward the bottom of this page, in case one is planning to switch to sql.
If you browse the comments below you'll find some other nice solutions to replace the
- Tyler Simkin posted his auth.lua file (enhanced by Rick Richards to work with encrypted passwords)
- Laurent Bercot posted a solution based on passwd-file driver
- Pablo Murillo improved the sql password_query to work with one table for each domain
- erdgeist showed how to convert cdb accounts to postgres
As some commentators have pointed out, switching to the
dovecot's sql auth driver can be painful if one has domain aliases. I will show below how to make
dovecot aware of the
aliasdomains, so that a user who tries to login with a domain alias can pass the authentication.
The idea is to save the pairs alias/domain in a new "aliasdomains"
MySQL table, for example:
MariaDB [vpopmail]> SELECT * FROM aliasdomains; +----------------------+----------------------+ | alias | domain | +----------------------+----------------------+ | alias.net | realdomain.net | +----------------------+----------------------+
...and then modify the
sql query in order to select the user's domain from this table in case the domain is an alias or from the
vpopmail table otherwise.
vpopmail so that it will transparently do the sql stuff when creating/deleting the alias in the usual way by means of the
September 1, 2020 Roberto Puzzanghera 73 comments
- Author: Inter7
- Version: 1.2.16
- Download the sources from http://sourceforge.net/projects/qmailadmin/files/
- Combined patch v. 20210312
qmailAdmin is a free software package that provides a web interface for managing a qmail system with virtual domains. It provides admin for adding/deleting users, Aliases, Forwards, Mailing lists and Autoresponders.
Combined patch details
- qmailadmin-skin, a patch that I created during covid-19 spare time, provides a new responsive skin to the control panel. It modifies everything under the html dir and many .c files in order to adjust the html embedded into the source files. Added a stylesheet style.css in the images folder and a couple of png files for the qmail logo. It should be much easier to modify the
qmailadmin's skin from now on.
- patch to call
cracklibin order to check for the password strenght. This should avoid unsafe accounts created by domain administrators such as "test 123456".
- A nice patch (thanks to Tony, original author unknown) which gets
qmailadminto have authentication failures logged. This makes possible to ban malicious IPs via
fail2ban. It is required to create the log file
/var/log/qma-auth.loginitially and assign write priviledges to
- ezmlm-idx 7 compatibility patch (author unknown), which restores the compatibility with
ezmlm-idx-7(thanks to J.D. Trolinger for the advice).
- a fix to the catchall account (thanks to Luca Franceschini).
- another fix to autorespond.c to correct the way
.qmailfiles are modified
-mod_user.html: cleaned the html as it was printing unneeded strings
- mod_user.html: added the "value" attribute to the name/gecos input tag
- Makefile.in: added a line to install the css, as already done for Makefile.am
(tx Pablo Murillo)
- mod_user.html: removed the "required" attribute on password field, to allow modifications in case of no password change
May 10, 2021 Roberto Puzzanghera 11 comments
These days I'm forced again to do lessons from remote. My school asked me to refer to
Google Meet for the videoconferences and one thing I disliked was the
Jam interactive whiteboard, which is completely inadequate for scientific subjects. On the other hand OpenBoard, my favourite board tool that I successfully use with
Zoom, seemed not to be recognized as an application to be shared, because it runs fullscreen.
After some googleing I found a patch from this guy (I big thank for his work!) which forces OpenBoard to run in a window, but at the cost of passing a variable at compilation time. I modified the logic of that patch so that a user can set how OpenBoard will run just modifying an option in the config file. The "run windowed" feature is disabled by default, so it will not bother those teachers who are already familiar with the interface, but it can be easily switched on by advanced users.
March 25, 2021 Roberto Puzzanghera 27 comments
- Info: http://spamassassin.apache.org/
- Docs: http://spamassassin.apache.org/full/3.4.x/doc/
- Latest version: 3.4.6
- Download: http://spamassassin.apache.org/downloads.cgi
SpamAssassin is a mature, widely-deployed open source project that serves as a mail filter to identify Spam. SpamAssassin uses a variety of mechanisms including header and text analysis, Bayesian filtering, DNS blocklists, and collaborative filtering databases. SpamAssassin runs on a server, and filters spam before it reaches your mailbox.
- Jul 14, 2021
- added DCC setup (next page)
- moved the configuration of Razor, Pyzor and Spamcop to a separate page