ZCS 8 postconf changes won't stick

Discuss your pilot or production implementation with other Zimbra admins or our engineers.
MeneM
Posts: 41
Joined: Fri Sep 12, 2014 9:54 pm

ZCS 8 postconf changes won't stick

Postby MeneM » Tue Nov 20, 2012 1:20 pm

I'm trying to follow the Smarthost Authentication wiki here: Outgoing SMTP Authentication - Zimbra :: Wiki
But the settings I make won't stay put in zimbra. See this example for instance:
zimbra@zimbra:~$ postconf -n | grep -i smtp_sasl_password_maps

smtp_sasl_password_maps =

zimbra@zimbra:~$ postconf -e smtp_sasl_password_maps=hash:/opt/zimbra/conf/relay_password

zimbra@zimbra:~$ postconf -n | grep -i smtp_sasl_password_maps

smtp_sasl_password_maps = hash:/opt/zimbra/conf/relay_password

zimbra@zimbra:~$

zimbra@zimbra:~$

zimbra@zimbra:~$ zimbra restart

zimbra: command not found

zimbra@zimbra:~$ zmcon

zmconfigdctl zmcontrol

zimbra@zimbra:~$ zmcontrol restart

Host benelec.net

Stopping vmware-ha...Done.

Stopping zmconfigd...Done.

Stopping stats...Done.

Stopping mta...Done.

Stopping spell...Done.

Stopping snmp...Done.

Stopping cbpolicyd...Done.

Stopping archiving...Done.

Stopping antivirus...Done.

Stopping antispam...Done.

Stopping proxy...Done.

Stopping memcached...Done.

Stopping mailbox...Done.

Stopping logger...Done.

Stopping ldap...Done.

Host benelec.net

Starting ldap...Done.

Starting zmconfigd...Done.

Starting logger...Done.

Starting mailbox...Done.

Starting antispam...Done.

Starting antivirus...Done.

Starting snmp...Done.

Starting spell...Done.

Starting mta...Done.

Starting stats...Done.

zimbra@zimbra:~$ postconf -n | grep -i smtp_sasl_password_maps

smtp_sasl_password_maps =

Usually I just do a postfix reload, but the outcome is the same. The settings are simply reset after a reload/restart.


The complete setting:

zimbra@zimbra:~$ postconf -n

alias_maps = hash:/etc/aliases

always_add_missing_headers = yes

bounce_notice_recipient = postmaster

bounce_queue_lifetime = 5d

broken_sasl_auth_clients = yes

command_directory = /opt/zimbra/postfix/sbin

config_directory = /opt/zimbra/postfix-2.10-20120422.2z/conf

content_filter = smtp-amavis:[127.0.0.1]:10024

daemon_directory = /opt/zimbra/postfix/libexec

delay_warning_time = 0h

disable_dns_lookups = no

header_checks =

in_flow_delay = 1s

inet_protocols = ipv4

lmtp_connection_cache_destinations =

lmtp_connection_cache_time_limit = 4s

lmtp_host_lookup = dns

local_header_rewrite_clients = permit_mynetworks,permit_sasl_authenticated

mail_owner = postfix

mailbox_size_limit = 0

mailq_path = /opt/zimbra/postfix/sbin/mailq

manpage_directory = /opt/zimbra/postfix/man

maximal_backoff_time = 4000s

message_size_limit = 10240000

minimal_backoff_time = 300s

mydestination = localhost

myhostname = benelec.net

mynetworks = 127.0.0.0/8 192.168.1.0/24 [::1]/128 [fe80::%eth0]/64

newaliases_path = /opt/zimbra/postfix/sbin/newaliases

non_smtpd_milters =

notify_classes = resource,software

propagate_unmatched_extensions = canonical

queue_directory = /opt/zimbra/data/postfix/spool

queue_run_delay = 300s

recipient_delimiter =

relayhost =

sender_canonical_maps = proxy:ldap:/opt/zimbra/conf/ldap-scm.cf

sendmail_path = /opt/zimbra/postfix/sbin/sendmail

setgid_group = postdrop

smtp_cname_overrides_servername = no

smtp_sasl_auth_enable = no

smtp_sasl_mechanism_filter =

smtp_sasl_password_maps =

smtp_sasl_security_options = noplaintext,noanonymous

smtp_tls_security_level =

smtp_use_tls = yes

smtpd_client_restrictions = reject_unauth_pipelining

smtpd_data_restrictions = reject_unauth_pipelining

smtpd_end_of_data_restrictions =

smtpd_helo_required = yes

smtpd_milters = inet:localhost:8465

smtpd_recipient_restrictions = reject_non_fqdn_recipient, permit_sasl_authenticated, permit_mynetworks, reject_unauth_destination, reject_unlisted_recipient, reject_non_fqdn_sender, permit

smtpd_reject_unlisted_recipient = no

smtpd_sasl_auth_enable = yes

smtpd_sasl_authenticated_header = no

smtpd_sasl_security_options = noanonymous

smtpd_sasl_tls_security_options = $smtpd_sasl_security_options

smtpd_sender_restrictions = check_sender_access regexp:/opt/zimbra/postfix/conf/tag_as_originating.re, permit_mynetworks, permit_sasl_authenticated, permit_tls_clientcerts, check_sender_access regexp:/opt/zimbra/postfix/conf/tag_as_foreign.re

smtpd_tls_auth_only = yes

smtpd_tls_cert_file = /opt/zimbra/conf/smtpd.crt

smtpd_tls_key_file = /opt/zimbra/conf/smtpd.key

smtpd_tls_loglevel = 1

smtpd_tls_security_level = may

transport_maps = proxy:ldap:/opt/zimbra/conf/ldap-transport.cf

virtual_alias_domains = proxy:ldap:/opt/zimbra/conf/ldap-vad.cf

virtual_alias_expansion_limit = 10000

virtual_alias_maps = proxy:ldap:/opt/zimbra/conf/ldap-vam.cf

virtual_mailbox_domains = proxy:ldap:/opt/zimbra/conf/ldap-vmd.cf

virtual_mailbox_maps = proxy:ldap:/opt/zimbra/conf/ldap-vmm.cf

virtual_transport = error

Anyone have any idea? Suggestions?


phoenix
Ambassador
Ambassador
Posts: 26341
Joined: Fri Sep 12, 2014 9:56 pm
Location: Liverpool, England

ZCS 8 postconf changes won't stick

Postby phoenix » Tue Nov 20, 2012 2:41 pm

[quote user="MeneM"]Anyone have any idea? Suggestions?[/QUOTE]What does the out you've posted have to do with the zmprov command? You haven't used zmprov to make any of those changes nor have you given details of which version or release of ZCS you're using. I'll take a guess and suggest you read some of these threads for your answer.
Regards

Bill

Rspamd: A high performance spamassassin replacement

If you'd like to see this implemented in a future version of ZCS then please vote on Bugzilla entries 97706 & 108168
MeneM
Posts: 41
Joined: Fri Sep 12, 2014 9:54 pm

ZCS 8 postconf changes won't stick

Postby MeneM » Tue Nov 20, 2012 11:50 pm

I'm sorry I was dead tired yesterday evening. I had been pounding this thing for hours. (What should have been 15 minutes of work)
So yeah, I meant "postconf".... :rolleyes: sorry.
I just wanted to implement smarthost with TLS authentication, which works with this config:

smtp_sasl_auth_enable = yes

smtp_sasl_password_maps = hash:/etc/postfix/sasl_password

smtp_sasl_security_options = noanonymous
on a different postfix machine we have.
But when I try to make such changes (Glanced from the wiki) they don't seem to stay put.
The only change that looks like it stays "in" is the smarthost/port itself. Which I do in the Webinterface.
My version of Zimbra is 8.0.0 GA5434 build 20120907144631 on a debian host.
p.s.

It seems we joined this forum on the same date, sep 2005. Zimbra was starting to get hot back then!
phoenix
Ambassador
Ambassador
Posts: 26341
Joined: Fri Sep 12, 2014 9:56 pm
Location: Liverpool, England

ZCS 8 postconf changes won't stick

Postby phoenix » Wed Nov 21, 2012 12:44 am

[quote user="MeneM"]I'm sorry I was dead tired yesterday evening. I had been pounding this thing for hours. (What should have been 15 minutes of work)
So yeah, I meant "postconf".... :rolleyes: sorry.[/QUOTE]That's OK, I'll change the thread title.
[quote user="MeneM"]But when I try to make such changes (Glanced from the wiki) they don't seem to stay put.[/QUOTE]Take a look at the threads for ZCS 8 in my link above (I've fixed the link).
[quote user="MeneM"]p.s.

It seems we joined this forum on the same date, sep 2005. Zimbra was starting to get hot back then![/QUOTE]Doesn't time fly when you're having fun? :D
Regards

Bill

Rspamd: A high performance spamassassin replacement

If you'd like to see this implemented in a future version of ZCS then please vote on Bugzilla entries 97706 & 108168

Return to “Administrators”

Who is online

Users browsing this forum: No registered users and 10 guests