]> git.immae.eu Git - perso/Immae/Config/Nix.git/blob - modules/private/mail/opensmtpd.nix
7831ac0d587bcf352426d72962b2e33ce74c16c6
[perso/Immae/Config/Nix.git] / modules / private / mail / opensmtpd.nix
1 { lib, pkgs, config, name, ... }:
2 {
3 config = lib.mkIf config.myServices.mailRelay.enable {
4 secrets.keys = [
5 {
6 dest = "opensmtpd/creds";
7 user = "smtpd";
8 group = "smtpd";
9 permissions = "0400";
10 text = ''
11 eldiron ${name}:${config.myEnv.servers."${name}".ldap.password}
12 '';
13 }
14 ];
15 users.users.smtpd.extraGroups = [ "keys" ];
16 services.opensmtpd = {
17 enable = true;
18 serverConfiguration = ''
19 table creds \
20 "${config.secrets.fullPaths."opensmtpd/creds"}"
21 # FIXME: filtering requires 6.6
22 # filter "fixfrom" \
23 # proc-exec "${pkgs.procmail}/bin/formail -i 'From: ${name}@immae.eu'"
24 action "relay-rewrite-from" relay \
25 helo ${config.hostEnv.FQDN} \
26 host smtp+tls://eldiron@eldiron.immae.eu:587 \
27 auth <creds> \
28 mail-from ${name}@immae.eu
29 action "relay" relay \
30 helo ${config.hostEnv.FQDN} \
31 host smtp+tls://eldiron@eldiron.immae.eu:587 \
32 auth <creds>
33 match for any !mail-from "@immae.eu" action "relay-rewrite-from"
34 match for any mail-from "@immae.eu" action "relay"
35 '';
36 };
37 environment.systemPackages = [ config.services.opensmtpd.package ];
38 services.mail.sendmailSetuidWrapper = {
39 program = "sendmail";
40 source = "${config.services.opensmtpd.package}/bin/smtpctl";
41 setuid = false;
42 setgid = false;
43 };
44 security.wrappers.mailq = {
45 program = "mailq";
46 source = "${config.services.opensmtpd.package}/bin/smtpctl";
47 setuid = false;
48 setgid = false;
49 };
50 };
51 }