[exim] Exim.conf Setting for passing username@hostservername…

Pàgina inicial
Delete this message
Reply to this message
Autor: Russell \"Elik\" Rademacher
A: exim-users
Assumpte: [exim] Exim.conf Setting for passing username@hostservername to spamc for Remote Spamd by Exiscan
Greetings folks,

I would like to get some help on trying to resolve a problem of mine
here. We have offloaded all spamassassin off to the remote dedicated
server, and it works great. However, I have one problem. I need to
figure out a way to make exim pass the username plus the host servername
to the spamd so it can query the MySQL DB and acts on the user prefs if
it exists for that user.

Take for example, the account name is elik, and it is located on
sparta.micfo.com. I want it to pass the username as
elik@??? to spamc to pass to the spamd itself. Right now,
it only use username and I want to change that.

Note that this is on cpanel enabled server so some people might be
familiar with it.

#!!# cPanel Exim 4 Config

domainlist rbl_blacklist = lsearch;/etc/rblblacklist
domainlist rbl_bypass = lsearch;/etc/rblbypass
hostlist rbl_whitelist = lsearch;/etc/relayhosts :
deliver_queue_load_max = 9
queue_run_max = 9
queue_only_load = 9
av_scanner = clamd: 3310

#!!# These options specify the Access Control Lists (ACLs) that
#!!# are used for incoming SMTP messages - after the RCPT and DATA
#!!# commands, respectively.

acl_smtp_rcpt = check_recipient
acl_smtp_data = check_message

#!!# This setting defines a named domain list called
#!!# local_domains, created from the old options that
#!!# referred to local domains. It will be referenced
#!!# later on by the syntax "+local_domains".
#!!# Other domain and host lists may follow.

domainlist local_domains = lsearch;/etc/localdomains

domainlist relay_domains = lsearch;/etc/localdomains : \
hostlist relay_hosts = lsearch;/etc/relayhosts : \
hostlist auth_relay_hosts = *

#                  Runtime configuration file for Exim               #

# This is a default configuration file which will operate correctly in
# uncomplicated installations. Please see the manual for a complete list
# of all the runtime configuration options that can be included in a
# configuration file. There are many more than are mentioned here. The
# manual is in the file doc/spec.txt in the Exim distribution as a plain
# ASCII file. Other formats (PostScript, Texinfo, HTML) are available from
# the Exim ftp sites. The manual is also online via the Exim web sites.

# This file is divided into several parts, all but the last of which are
# terminated by a line containing the word "end". The parts must appear
# in the correct order, and all must be present (even if some of them are
# in fact empty). Blank lines, and lines starting with # are ignored.

#                    MAIN CONFIGURATION SETTINGS                     #

perl_startup = do '/etc/exim.pl'

#dns_retry = 1
#dns_retrans = 1s

# Specify your host's canonical name here. This should normally be the fully
# qualified "official" name of your host. If this option is not set, the
# uname() function is called to obtain the name.

smtp_banner = "${primary_hostname} ESMTP Exim ${version_number} \
\#${compile_number} ${tod_full} \n\
We do not authorize the use of this system to transport unsolicited, \n\
and/or bulk e-mail."

#nobody as the sender seems to annoy people
untrusted_set_sender = *
local_from_check = false

rfc1413_query_timeout = 2s

split_spool_directory = yes

smtp_connect_backlog = 50
smtp_accept_max = 100

# primary_hostname =
auto_thaw = 6d
ignore_bounce_errors_after = 7d
timeout_frozen_after = 8d

# Specify the domain you want to be added to all unqualified addresses
# here. An unqualified address is one that does not contain an "@" character
# followed by a domain. For example, "caesar@???" is a fully qualified
# address, but the string "caesar" (i.e. just a login name) is an
# email address. Unqualified addresses are accepted only from local
callers by
# default. See the receiver_unqualified_{hosts,nets} options if you want
# to permit unqualified addresses from remote sources. If this option is
# not set, the primary_hostname value is used for qualification.

# qualify_domain =

# If you want unqualified recipient addresses to be qualified with a
# domain to unqualified sender addresses, specify the recipient domain here.
# If this option is not set, the qualify_domain value is used.

# qualify_recipient =

# Specify your local domains as a colon-separated list here. If this option
# is not set (i.e. not mentioned in the configuration file), the
# qualify_recipient value is used as the only local domain. If you do
not want
# to do any local deliveries, uncomment the following line, but do not
# any data for it. This sets local_domains to an empty string, which is not
# the same as not mentioning it at all. An empty string specifies that there
# are no local domains; not setting it at all causes the default value (the
# setting of qualify_recipient) to be used.

#!!# message_filter renamed system_filter
system_filter = /etc/antivirus.exim
message_body_visible = 5000
# If you want to accept mail addressed to your host's literal IP
address, for
# example, mail addressed to "user@???", then uncomment the
# following line, or supply the literal domain(s) as part of "local_domains"
# above.

# local_domains_include_host_literals

# No local deliveries will ever be run under the uids of these users (a
# separated list). An attempt to do so gets changed so that it runs
under the
# uid of "nobody" instead. This is a paranoic safety catch. Note the default
# setting means you cannot deliver mail addressed to root as if it were a
# normal user. This isn't usually a problem, as most sites have an alias for
# root that redirects such mail to a human administrator.

never_users = root

# The use of your host as a mail relay by any host, including the local host
# calling its own SMTP port, is locked out by default. If you want to permit
# relaying from the local host, you should set
# host_accept_relay = localhost
# If you want to permit relaying through your host from certain hosts or IP
# networks, you need to set the option appropriately, for example
# If you are an MX backup or gateway of some kind for some domains, you must
# set relay_domains to match those domains. This will allow any host to
# relay through your host to those domains.
# See the section of the manual entitled "Control of relaying" for more
# information.

# The setting below causes Exim to do a reverse DNS lookup on all incoming
# IP calls, in order to get the true host name. If you feel this is too
# expensive, you can specify the networks for which a lookup is done, or
# remove the setting entirely.

#host_lookup =

# By default, Exim expects all envelope addresses to be fully qualified,
# is, they must contain both a local part and a domain. If you want to
# unqualified addresses (just a local part) from certain hosts, you can
# these hosts by setting one or both of
# receiver_unqualified_hosts =
# sender_unqualified_hosts =
# to control sender and receiver addresses, respectively. When this is done,
# unqualified addresses are qualified using the settings of qualify_domain
# and/or qualify_recipient (see above).
# unqualified addresses are qualified using the settings of qualify_domain
# and/or qualify_recipient (see above).

# Exim contains support for the Realtime Blocking List (RBL) that is being
# maintained as part of the DNS. See http://maps.vix.com/rbl/ for
# Uncommenting the first line below will make Exim reject mail from any
# host whose IP address is blacklisted in the RBL at maps.vix.com. Some
# others have followed the RBL lead and have produced other lists: DUL is
# a list of dial-up addresses, and ORBS is a list of open relay systems. The
# second line below checks all three lists.

# rbl_domains = rbl.maps.vix.com
# rbl_domains = rbl.maps.vix.com

# If you want Exim to support the "percent hack" for all your local domains,
# uncomment the following line. This is the feature by which mail addressed
# to x%y@z (where z is one of your local domains) is locally rerouted to
# x@y and sent on. Otherwise x%y is treated as an ordinary local part.

# percent_hack_domains = *

#sender_host_accept = +include_unknown:*
#sender_host_reject = +include_unknown:lsearch*;/etc/spammers

tls_certificate = /etc/exim.crt
tls_privatekey = /etc/exim.key
tls_advertise_hosts = *

helo_accept_junk_hosts = *

smtp_enforce_sync = false

#!!# This new section of the configuration contains ACLs #!!#
#!!# (Access Control Lists) derived from the Exim 3      #!!#
#!!# policy control options.                             #!!#

#!!# These ACLs are crudely constructed from Exim 3 options.
#!!# They are almost certainly not optimal. You should study
#!!# them and rewrite as necessary.

begin acl

#!!# ACL that is used after the RCPT command
# Exim 3 had no checking on -bs messages, so for compatibility
# we accept if the source is local SMTP (i.e. not over TCP/IP).
# We do this by testing for an empty sending host field.
accept hosts = :

#**# RBL List Begin
# Always accept mail to postmaster & abuse for any local domain

# Check sending hosts against DNS black lists.
# Accept all locally generated messages
# Reject message if address listed in blacklist.
deny message = Message rejected because $sender_fullhost is blacklisted
at $dnslist_domain see $dnslist_text
!hosts = +relay_hosts
!authenticated = *
dnslists = dnsbl.njabl.org : \
bl.spamcop.net : \
sbl.spamhaus.org : \
list.dsbl.org : \
cbl.abuseat.org : \
# RBL Bypass Local Domain List
!domains = +rbl_bypass
# RBL Whitelist incoming hosts
!hosts = +rbl_whitelist
#**# RBL List End

  # Accept bounces to lists even if callbacks or other checks would fail
  warn     message      = X-WhitelistedRCPT-nohdrfromcallback: Yes
           condition    = \
           ${if and {{match{$local_part}{(.*)-bounces\+.*}} \
{/usr/local/cpanel/3rdparty/mailman/lists/${lc:$1}/config.pck}}} \

  accept   condition    = \
           ${if and {{match{$local_part}{(.*)-bounces\+.*}} \
{/usr/local/cpanel/3rdparty/mailman/lists/${lc:$1}/config.pck}}} \

  # Accept bounces to lists even if callbacks or other checks would fail
  warn     message      = X-WhitelistedRCPT-nohdrfromcallback: Yes
           condition    = \
           ${if and {{match{$local_part}{(.*)-bounces\+.*}} \

  accept   condition    = \
           ${if and {{match{$local_part}{(.*)-bounces\+.*}} \

#if it gets here it isn't mailman

#sender verifications are required for all messages that are not sent
to lists

require verify = sender
accept domains = +local_domains

#recipient verifications are required for all messages that are not
sent to the local machine
#this was done at multiple users requests

message = "The recipient cannot be verified. Please check all
recipients of this message to verify they are valid."
verify = recipient

accept domains = +relay_domains

  warn  message = ${perl{popbeforesmtpwarn}{$sender_host_name}}
        hosts = +relay_hosts
  accept  hosts = +relay_hosts

  warn  message = ${perl{popbeforesmtpwarn}{$sender_host_address}}
        condition = ${perl{checkrelayhost}{$sender_host_address}}
  accept  condition = ${perl{checkrelayhost}{$sender_host_address}}

  accept  hosts = +auth_relay_hosts
          message = $sender_fullhost is currently not permitted to \
                        relay through this server. Perhaps you \
                        have not logged into the pop/imap server in the \
                        last 30 minutes or do not have SMTP 
Authentication turned on in your email client.
          authenticated = *

  deny    message = $sender_fullhost is currently not permitted to \
                        relay through this server. Perhaps you \
                        have not logged into the pop/imap server in the \
                        last 30 minutes or do not have SMTP 
Authentication turned on in your email client.

#!!# ACL that is used after the DATA command
# Enabling this will make the server non-rfc compliant
# require verify = header_sender
##### clamav ACL, reject virus infected mails with proper error

deny message = This message contains malformed MIME ($demime_reason).
demime = *
condition = ${if >{$demime_errorlevel}{2}{1}{0}}

deny message = This message contains a virus or other harmful content \
demime = *
malware = *

# Add X-Scanned Header

warn message = X-Antivirus-Scanner: Clean mail though you should still
use an Antivirus

##### end clamav ACL
begin authenticators

driver = plaintext
public_name = PLAIN
server_prompts = :
server_condition = "${perl{checkuserpass}{$1}{$2}{$3}}"
server_set_id = $2

driver = plaintext
public_name = LOGIN
server_prompts = "Username:: : Password::"
server_condition = "${perl{checkuserpass}{$1}{$2}}"
server_set_id = $1

#                      REWRITE CONFIGURATION                         #

# There are no rewriting specifications in this default configuration file.

begin rewrite

#!!# Here follow routers created from the old routers,   #!!#
#!!# for handling non-local domains.                     #!!#

begin routers

#!!# If we are trying to deliver to a remote mailman domain that is on
the localhost
#!!# let it go though even if its not in /etc/localdomains since mailman
will eat
#!!# up 100% of the cpu if we don't

    driver = accept
    require_files = 
    local_part_suffix = -admin     : \
                        -bounces   : -bounces+* : \
                        -confirm   : -confirm+* : \
                        -join      : -leave     : \
                        -owner     : -request   : \
                        -subscribe : -unsubscribe
    transport = mailman_virtual_transport

    driver = accept
    require_files = 
    condition    = \
           ${if or {{match{$local_part}{.*_.*}} \
                     {eq{$local_part}{mailman}}} \
    local_part_suffix = -admin     : \
                        -bounces   : -bounces+* : \
                        -confirm   : -confirm+* : \
                        -join      : -leave     : \
                        -owner     : -request   : \
                        -subscribe : -unsubscribe
    domains = +local_domains
    transport = mailman_virtual_transport_nodns

#                      ROUTERS CONFIGURATION                         #
#            Specifies how remote addresses are handled              #
#                          ORDER DOES MATTER                         #
#  A remote address is passed to each in turn until it is accepted.  #

# Remote addresses are those with a domain that does not match any item
# in the "local_domains" setting above.

driver = redirect
condition = "${perl{democheck}}"
data = :fail: demo accounts are not permitted to relay email

# This router routes to remote hosts over SMTP using a DNS lookup with
# default options.

driver = accept
condition = "${perl{checkbx_autowhitelist}{$authenticated_id}}"
require_files = "/usr/local/cpanel/bin/boxtrapper"
transport = boxtrapper_autowhitelist

driver = dnslookup
condition = "${perl{checkspam}}"
domains = ! +local_domains
#ignore verisign to prevent waste of bandwidth
ignore_target_hosts = : :
headers_add = "${perl{mailtrapheaders}}"
transport = remote_smtp

# This router routes to remote hosts over SMTP by explicit IP address,
# given as a "domain literal" in the form [nnn.nnn.nnn.nnn]. The RFCs
# require this facility, which is why it is enabled by default in Exim.
# If you want to lock it out, set forbid_domain_literals in the main
# configuration section above.
driver = ipliteral
condition = "${perl{checkspam}}"
domains = ! +local_domains
headers_add = "${perl{mailtrapheaders}}"
transport = remote_smtp

#!!# This new router is put here to fail all domains that
#!!# were not in local_domains in the Exim 3 configuration.

driver = redirect
domains = ! +local_domains
data = :fail: unrouteable mail domain "$domain"

#!!# Here follow routers created from the old directors, #!!#
#!!# for handling local domains.                         #!!#

#                      DIRECTORS CONFIGURATION                       #
#             Specifies how local addresses are handled              #
#                          ORDER DOES MATTER                         #
#   A local address is passed to each in turn until it is accepted.  #

# Local addresses are those with a domain that matches some item in the
# "local_domains" setting above, or those which are passed back from the
# routers because of a "self=local" setting (not used in this

# This director handles aliasing using a traditional /etc/aliases file.
# If any of your aliases expand to pipes or files, you will need to set
# up a user and a group for these deliveries to run under. You can do
# this by uncommenting the "user" option below (changing the user name
# as appropriate) and adding a "group" option if necessary.
Alternatively, you
# can specify "user" on the transports that are used. Note that those
# listed below are the same as are used for .forward files; you might want
# to set up different ones for pipe and file deliveries from aliases.

# driver = forwardfile
# file = /etc/spam.filter
# no_check_local_user
# no_verify
# filter
# allow_system_actions
driver = accept
condition =
domains = lsearch;/etc/userdomains
transport = virtual_sa_userdelivery

driver = accept
condition = "${perl{checkusersa}{$local_part}{$received_protocol}}"
domains = ! lsearch;/etc/userdomains
transport = local_sa_delivery

#!!# filter renamed allow_filter
driver = redirect
file = /etc/vfilters/${domain}
file_transport = address_file
pipe_transport = virtual_address_pipe
reply_transport = address_reply
user = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"

driver = redirect
domains = ! lsearch;/etc/userdomains
condition = "${perl{hasfilterfile}{$local_part}}"
file = "${perl{getfilterfile}{$local_part}}"
file_transport = address_file
pipe_transport = virtual_address_pipe
reply_transport = address_reply

driver = redirect
data = ${if
file_transport = address_file
group = mail
pipe_transport = virtual_address_pipe
domains = lsearch;/etc/localdomains

driver = accept
condition = "${perl{check_deliver_spam}{$domain}{$local_part}}"
domains = lsearch;/etc/userdomains
transport = virtual_userdelivery_spam

driver = accept
condition = "${perl{checkbx_deliver}{$domain}{$local_part}}"
require_files = "/usr/local/cpanel/bin/boxtrapper"
domains = lsearch;/etc/userdomains
transport = virtual_boxtrapper_userdelivery

driver = accept
condition = "${perl{check_deliver}{$domain}{$local_part}}"
domains = lsearch;/etc/userdomains
transport = virtual_userdelivery

        driver = redirect
        condition = "${perl{checkvalias}{$domain}{$local_part}}"
        domains = lsearch;/etc/localdomains
        data="#Exim Filter\nseen finish"
        group = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"
        user = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"
        disable_logging = true

driver = redirect
condition = ${lookup {$domain} lsearch
{/etc/vdomainaliases/$domain}{yes}{no} }
require_files = /etc/vdomainaliases/$domain
data = $local_part@${lookup {$domain} lsearch
{/etc/vdomainaliases/$domain} }

driver = redirect
data = ${if
file_transport = address_file
group = mail
pipe_transport = virtual_address_pipe
domains = lsearch;/etc/localdomains
# This director handles forwarding using traditional .forward files.
# If you want it also to allow mail filtering when a forward file
# starts with the string "# Exim filter", uncomment the "filter" option.
# The check_ancestor option means that if the forward file generates an
# address that is an ancestor of the current one, the current one gets
# passed on instead. This covers the case where A is aliased to B and B
# has a .forward file pointing to A. The three transports specified at the
# end are those that are used when forwarding generates a direct delivery
# to a file, or to a pipe, or sets up an auto-reply, respectively.

driver = redirect
data = ${lookup{$local_part}lsearch{/etc/aliases}}
file_transport = address_file
pipe_transport = address_pipe
# user = exim

driver = redirect
data = ${lookup{$local_part}lsearch{/etc/localaliases}}
file_transport = address_file
pipe_transport = address_pipe

#!!# filter renamed allow_filter
driver = redirect
domains = ! lsearch;/etc/userdomains
file = $home/.forward
file_transport = address_file
pipe_transport = address_pipe
reply_transport = address_reply

driver = accept
condition = "${perl{checkuserspambox}{$local_part}}"
domains = ! lsearch;/etc/userdomains
transport = local_delivery_spam

driver = accept
condition = "${perl{checkuserbx}{$local_part}}"
require_files = "/usr/local/cpanel/bin/boxtrapper"
domains = ! lsearch;/etc/userdomains
transport = local_boxtrapper_delivery

driver = accept
domains = ! lsearch;/etc/userdomains
transport = local_delivery

# This director matches local user mailboxes.

#                      TRANSPORTS CONFIGURATION                      #
#                       ORDER DOES NOT MATTER                        #
#     Only one appropriate transport is called for each delivery.    #

# A transport is used only when referenced from a director or a router that
# successfully handles an address.

# This transport is used for delivering messages over SMTP connections.

begin transports

driver = smtp

# This transport is used for local delivery to user mailboxes. By default
# it will be run under the uid and gid of the local user, and requires
# the sticky bit to be set on the /var/mail directory. Some systems use
# the alternative approach of running mail deliveries under a particular
# group instead of using the sticky bit. The commented options below show
# how this can be done.

driver = appendfile
directory =
group = mail
mode = 0660
user = $local_part
driver = appendfile
directory =
group = mail
mode = 0660
user = $local_part

driver = pipe
command = /usr/sbin/sendmail -bS
use_bsmtp = true
transport_filter = "/usr/bin/spamc"
user = $local_part
group = mail
log_output = true
current_directory = "/tmp"
home_directory = "/tmp"
return_fail_output = true
return_path_add = false
message_prefix =
message_suffix =
timeout_defer = true
transport_filter_timeout = 5m
temp_errors = 2

# This transport is used for handling pipe deliveries generated by alias
# or .forward files. If the pipe generates any standard output, it is
# to the sender of the message as a delivery error. Set return_fail_output
# instead of return_output if you want this to happen only when the pipe
# to complete normally. You can set different transports for aliases and
# forwards if you want to - see the references to address_pipe below.

driver = pipe

driver = pipe
group = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"
user = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"

# This transport is used for handling deliveries directly to files that are
# generated by aliassing or forwarding.

driver = appendfile
# This transport is used for handling autoreplies generated by the filtering
# option of the forwardfile director.

driver = pipe
command = /usr/sbin/sendmail -bS
use_bsmtp = true
transport_filter = "/usr/bin/spamc"
user = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"
group = mail
log_output = true
current_directory = "/tmp"
home_directory = "/tmp"
return_fail_output = true
return_path_add = false
message_prefix =
message_suffix =
timeout_defer = true
transport_filter_timeout = 5m
temp_errors = 2

driver = appendfile
directory =
group = mail
mode = 0660
quota = "${if
quota_directory =
user = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"

driver = pipe
command = /usr/local/cpanel/bin/boxtrapper --autowhitelist
user = ${perl{getemailuser}{$authenticated_id}}
group = mail
log_output = true
current_directory = "/tmp"
return_fail_output = true
return_path_add = false

driver = pipe
command = /usr/local/cpanel/bin/boxtrapper "${local_part}"
user = $local_part
group = mail
log_output = true
current_directory = "/tmp"
return_fail_output = true
return_path_add = false

driver = pipe
command = /usr/local/cpanel/bin/boxtrapper "${local_part}@${domain}"
user = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"
group = mail
log_output = true
current_directory = "/tmp"
return_fail_output = true
return_path_add = false

driver = appendfile
directory =
group = mail
mode = 0660
quota = "${if
quota_directory =
user = "${lookup{$domain}lsearch* {/etc/userdomains}{$value}}"

driver = autoreply

    driver = pipe
    command = /usr/local/cpanel/3rdparty/mailman/mail/mailman \
              '${if def:local_part_suffix \
                    {${sg{$local_part_suffix}{-(\\w+)(\\+.*)?}{\$1}}} \
                    {post}}' \
    current_directory = /usr/local/cpanel/3rdparty/mailman
    home_directory = /usr/local/cpanel/3rdparty/mailman
    user = mailman
    group = mailman

    driver = pipe
    command = /usr/local/cpanel/3rdparty/mailman/mail/mailman \
              '${if def:local_part_suffix \
                    {${sg{$local_part_suffix}{-(\\w+)(\\+.*)?}{\$1}}} \
                    {post}}' \
    current_directory = /usr/local/cpanel/3rdparty/mailman
    home_directory = /usr/local/cpanel/3rdparty/mailman
    user = mailman
    group = mailman
#                      RETRY CONFIGURATION                           #

# This single retry rule applies to all domains and all errors. It specifies
# retries every 15 minutes for 2 hours, then increasing retry intervals,
# starting at 1 hour and increasing each time by a factor of 1.5, up to 16
# hours, then retries every 8 hours until 4 days have passed since the first
# failed delivery.

# Domain               Error       Retries
# ------               -----       -------

begin retry

*                      *           F,2h,15m; G,16h,1h,1.5; F,4d,8h

# End of Exim 4 configuration