# Configuration question regarding postfix and djigzo

**URL:** <https://community.ciphermail.com/t/configuration-question-regarding-postfix-and-djigzo/221>\
**Category:** Gateway\
**Created:** [July 20, 2011, 8:28am UTC](https://community.ciphermail.com/t/configuration-question-regarding-postfix-and-djigzo/221 "2011-07-20T08:28:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefan\_Gunther](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@Stefan\_Gunther](https://community.ciphermail.com/u/Stefan_Gunther)\
**Post date:** [July 20, 2011, 8:28am UTC](https://community.ciphermail.com/t/configuration-question-regarding-postfix-and-djigzo/221/1 "2011-07-20T08:28:43Z")

</div>

Hello,

we have installed the groupware Zarafa (together with Postfix) on a  
Ubuntu 10.04 System.  
Zarafa has its own user management, therefore postfix doesn't know  
anything about the users it should deliver mail for, but it works.

We have now integrated djigzo into the mail flow.

The interesting thing now is, that whenI send an email from the command  
line, the mail will be delivered. When I use fetchmail to poll a mail  
and forward it to the same user, postfix tells me, that this user  
doesn't exist. This was possible before adding the djigzo configuration.

My question now is: How does the djigzo configuration change the  
configuration of postfix, so that postfix wants to check the user?  
Or the other way round: How do I tell postfix to just forward the email  
to a local transport (in this case it is mailbox\_transport = zarafa)?

Thanks for any suggstions or hints,

Stefan

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [July 20, 2011, 8:38am UTC](https://community.ciphermail.com/t/configuration-question-regarding-postfix-and-djigzo/221/2 "2011-07-20T08:38:12Z")

</div>

> Hello,
> 
> we have installed the groupware Zarafa (together with Postfix) on a  
> Ubuntu 10.04 System.  
> Zarafa has its own user management, therefore postfix doesn't know  
> anything about the users it should deliver mail for, but it works.
> 
> We have now integrated djigzo into the mail flow.

With "integrated" you mean using the same Postfix instance? i.e., is  
Djigzo using the same Postfix instance as Zarafa?

> The interesting thing now is, that whenI send an email from the command  
> line, the mail will be delivered. When I use fetchmail to poll a mail  
> and forward it to the same user, postfix tells me, that this user  
> doesn't exist. This was possible before adding the djigzo configuration.

The command line probably uses postdrop and fetchmail sends it to the  
SMTP port.

> My question now is: How does the djigzo configuration change the  
> configuration of postfix, so that postfix wants to check the user?  
> Or the other way round: How do I tell postfix to just forward the email  
> to a local transport (in this case it is mailbox\_transport = zarafa)?

If you are using just one Postfix instance for Zarafa and Djigzo, can  
you post the Postfix main and master config file?

Kind regards,

Martijn Brinkers

> **···**
>
> On 07/20/2011 10:28 AM, Stefan-Michael Guenther wrote:
> 
> --  
> Djigzo open source email encryption

---

<div class="post-metadata">

**Author:** ![Stefan\_Gunther](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@Stefan\_Gunther](https://community.ciphermail.com/u/Stefan_Gunther)\
**Post date:** [July 20, 2011, 2:21pm UTC](https://community.ciphermail.com/t/configuration-question-regarding-postfix-and-djigzo/221/3 "2011-07-20T14:21:04Z")

</div>

Hi,

> With "integrated" you mean using the same Postfix instance? i.e., is  
> Djigzo using the same Postfix instance as Zarafa?

yes.

> The command line probably uses postdrop and fetchmail sends it to the  
> SMTP port.

yes.

> If you are using just one Postfix instance for Zarafa and Djigzo, can  
> you post the Postfix main and master config file?

of course, here are the files. By the way, we are also using Amavis,  
therefore we have changed the ports that Djigzo uses.

master.cf

> **···**
>
> -------------  
> smtp inet n - - - - smtpd  
> &nbsp;&nbsp;-o message\_size\_limit=${djigzo\_before\_filter\_message\_size\_limit}  
> pickup fifo n - - 60 1 pickup  
> cleanup unix n - - - 0 cleanup  
> qmgr fifo n - n 300 1 qmgr  
> #qmgr fifo n - - 300 1 oqmgr  
> tlsmgr unix - - - 1000? 1 tlsmgr  
> rewrite unix - - - - - trivial-rewrite  
> bounce unix - - - - 0 bounce  
> defer unix - - - - 0 bounce  
> trace unix - - - - 0 bounce  
> verify unix - - - - 1 verify  
> flush unix n - - 1000? 0 flush  
> proxymap unix - - n - - proxymap  
> proxywrite unix - - n - 1 proxymap  
> smtp unix - - - - - smtp  
> # When relaying mail as backup MX, disable fallback\_relay to avoid MX loops  
> relay unix - - - - - smtp  
> &nbsp;&nbsp;-o smtp\_fallback\_relay=  
> # -o smtp\_helo\_timeout=5 -o smtp\_connect\_timeout=5  
> showq unix n - - - - showq  
> error unix - - - - - error  
> retry unix - - - - - error  
> discard unix - - - - - discard  
> local unix - n n - - local  
> virtual unix - n n - - virtual  
> lmtp unix - - - - - lmtp  
> anvil unix - - - - 1 anvil  
> scache unix - - - - 1 scache  
> maildrop unix - n n - - pipe  
> flags=DRhu user=vmail argv=/usr/bin/maildrop -d ${recipient}  
> uucp unix - n n - - pipe  
> flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail  
> ($recipient)  
> ifmail unix - n n - - pipe  
> flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)  
> bsmtp unix - n n - - pipe  
> flags=Fq. user=bsmtp argv=/usr/lib/bsmtp/bsmtp -t$nexthop -f$sender  
> $recipient  
> scalemail-backend unix - n n - 2 pipe  
> flags=R user=scalemail argv=/usr/lib/scalemail/bin/scalemail-store  
> ${nexthop} ${user} ${extension}  
> mailman unix - n n - - pipe  
> flags=FR user=list argv=/usr/lib/mailman/bin/postfix-to-mailman.py  
> ${nexthop} ${user}  
> zarafa unix - n n - 10 pipe  
> flags= user=vmail argv=/usr/bin/zarafa-dagent ${user}
> 
> djigzo unix - - n - 4 smtp  
> -o smtp\_send\_xforward\_command=yes  
> -o disable\_dns\_lookups=yes  
> -o smtp\_generic\_maps=
> 
> 127.0.0.1:10026 inet n - n - 10 smtpd  
> -o content\_filter=  
> -o  
> receive\_override\_options=no\_unknown\_recipient\_checks,no\_header\_body\_checks,no\_milters  
> -o smtpd\_helo\_restrictions=  
> -o smtpd\_client\_restrictions=  
> -o smtpd\_sender\_restrictions=  
> -o smtpd\_recipient\_restrictions=permit\_mynetworks,reject  
> -o mynetworks=127.0.0.0/8  
> -o smtpd\_authorized\_xforward\_hosts=127.0.0.0/8  
> -o smtpd\_authorized\_xclient\_hosts=127.0.0.0/8
> 
> 127.0.0.1:10025 inet n - n - - smtpd  
> -o content\_filter=  
> -o local\_recipient\_maps=  
> -o relay\_recipient\_maps=  
> -o smtpd\_restriction\_classes=  
> -o smtpd\_client\_restrictions=  
> -o smtpd\_helo\_restrictions=  
> -o smtpd\_sender\_restrictions=  
> -o smtpd\_recipient\_restrictions=permit\_mynetworks,reject  
> -o mynetworks=127.0.0.0/8  
> -o strict\_rfc821\_envelopes=yes  
> -o smtpd\_error\_sleep\_time=0  
> -o smtpd\_soft\_error\_limit=1001  
> -o smtpd\_hard\_error\_limit=1000
> 
> main.cf  
> --------  
> readme\_directory = no  
> myorigin = /etc/mailname  
> mydestination = ${djigzo\_mydestination}, in-put.de, zarafaserver.in-put.de,  
> localhost  
> inet\_interfaces = all  
> virtual\_mailbox\_maps = hash:/etc/postfix/virtual  
> virtual\_alias\_maps = hash:/etc/postfix/virtual  
> virtual\_transport = lmtp:127.0.0.1:2003  
> mailbox\_transport = zarafa  
> zarafa\_destination\_recipient\_limit = 1  
> djigzo\_after\_filter\_message\_size\_limit = 512000000  
> djigzo\_mailbox\_size\_limit = 512000000  
> djigzo\_smtp\_helo\_name =  
> djigzo\_relay\_transport\_host = 192.168.0.101  
> djigzo\_relay\_transport\_host\_mx\_lookup =  
> djigzo\_relay\_transport\_host\_port = 25  
> djigzo\_reject\_unverified\_recipient =  
> djigzo\_unverified\_recipient\_reject\_code = 450  
> djigzo\_parent\_domain\_matches\_subdomains =  
> smtpd\_banner = ESMTP  
> biff = no  
> append\_dot\_mydomain = no  
> myhostname = ${djigzo\_myhostname}  
> mynetworks = 127.0.0.0/8, ${djigzo\_mynetworks}  
> relayhost =  
> ${djigzo\_relayhost\_mx\_lookup:${djigzo\_relayhost?[}}${djigzo\_relayhost}${djigzo\_relayhost\_mx\_lookup:${djigzo\_relayhost?]}}${djigzo\_relayhost?:${djigzo\_relayhost\_port}}  
> relay\_domains = ${djigzo\_relay\_domains}  
> message\_size\_limit = ${djigzo\_after\_filter\_message\_size\_limit}  
> mailbox\_size\_limit = ${djigzo\_mailbox\_size\_limit}  
> smtp\_helo\_name =  
> ${djigzo\_smtp\_helo\_name?$djigzo\_smtp\_helo\_name}${djigzo\_smtp\_helo\_name:$myhostname}  
> relay\_transport =  
> relay${djigzo\_relay\_transport\_host?:${djigzo\_relay\_transport\_host\_mx\_lookup:[}$djigzo\_relay\_transport\_host${djigzo\_relay\_transport\_host\_mx\_lookup:]}:$djigzo\_relay\_transport\_host\_port}  
> smtpd\_recipient\_restrictions = permit\_mynetworks, reject\_unauth\_destination  
> ${djigzo\_reject\_unverified\_recipient?, reject\_unverified\_recipient}  
> unverified\_recipient\_reject\_code = $djigzo\_unverified\_recipient\_reject\_code  
> parent\_domain\_matches\_subdomains = $djigzo\_parent\_domain\_matches\_subdomains  
> smtpd\_discard\_ehlo\_keywords = silent-discard, dsn, etrn  
> smtpd\_etrn\_restrictions = reject  
> alias\_maps = hash:/etc/aliases  
> alias\_database = hash:/etc/aliases  
> recipient\_delimiter = +  
> smtpd\_authorized\_xforward\_hosts = 127.0.0.1/32  
> content\_filter = djigzo:127.0.0.1:10023  
> smtpd\_sasl\_auth\_enable = yes  
> broken\_sasl\_auth\_clients = yes  
> smtpd\_sasl\_security\_options = noanonymous  
> smtpd\_tls\_key\_file = /etc/zarafa/gateway/privkey.pem  
> smtpd\_tls\_cert\_file = /etc/zarafa/gateway/cert.pem  
> smtpd\_use\_tls = yes  
> smtpd\_tls\_loglevel = 2  
> tls\_random\_source = dev:/dev/urandom  
> djigzo\_mynetworks = 127.0.0.0/8, 192.168.0.0/24  
> djigzo\_myhostname = zarafaserver.in-put.de  
> djigzo\_relayhost = 192.168.0.101  
> djigzo\_relayhost\_mx\_lookup =  
> djigzo\_relayhost\_port = 25  
> djigzo\_before\_filter\_message\_size\_limit = 10240000
> 
> Thanks for your help.
> 
> Best regards,
> 
> Stefan

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [July 20, 2011, 2:42pm UTC](https://community.ciphermail.com/t/configuration-question-regarding-postfix-and-djigzo/221/4 "2011-07-20T14:42:16Z")

</div>

> Hi,
> 
> > With "integrated" you mean using the same Postfix instance? i.e., is  
> > Djigzo using the same Postfix instance as Zarafa?
> 
> yes.
> 
> > The command line probably uses postdrop and fetchmail sends it to the  
> > SMTP port.
> 
> yes.
> 
> > If you are using just one Postfix instance for Zarafa and Djigzo, can  
> > you post the Postfix main and master config file?
> 
> of course, here are the files. By the way, we are also using Amavis,  
> therefore we have changed the ports that Djigzo uses.

It seems you didn't provide any value for the "local\_recipient\_maps"  
setting and therefore the default value will be used which means that  
local users are looked up using the passwd file. If you set  
local\_recipient\_maps to an empty value you disable local recipient checking.

"To turn off local recipient checking in the Postfix SMTP server,  
specify "local\_recipient\_maps =" (i.e. empty)."

According to the Zarafa Wiki, they tell you to set local\_recipient\_maps  
to an empty value, i.e.,

local\_recipient\_maps =

See [http://www.zarafa.com/wiki/index.php/MTA\_integration](http://www.zarafa.com/wiki/index.php/MTA_integration)

I'm not sure how Zarafa handles email for non-existing users to prevent  
back-scatter. It might be that you need to check against an ldap or  
something similar.

Kind regards,

Martijn Brinkers

> **···**
>
> On 07/20/2011 04:21 PM, Stefan-Michael Guenther wrote:  
> From: [Postfix Configuration Parameters](http://www.postfix.org/postconf.5.html#local_recipient_maps)
> 
> > master.cf  
> > -------------  
> > smtp inet n - - - - smtpd  
> > &nbsp;&nbsp;-o message\_size\_limit=${djigzo\_before\_filter\_message\_size\_limit}  
> > pickup fifo n - - 60 1 pickup  
> > cleanup unix n - - - 0 cleanup  
> > qmgr fifo n - n 300 1 qmgr  
> > #qmgr fifo n - - 300 1 oqmgr  
> > tlsmgr unix - - - 1000? 1 tlsmgr  
> > rewrite unix - - - - - trivial-rewrite  
> > bounce unix - - - - 0 bounce  
> > defer unix - - - - 0 bounce  
> > trace unix - - - - 0 bounce  
> > verify unix - - - - 1 verify  
> > flush unix n - - 1000? 0 flush  
> > proxymap unix - - n - - proxymap  
> > proxywrite unix - - n - 1 proxymap  
> > smtp unix - - - - - smtp  
> > # When relaying mail as backup MX, disable fallback\_relay to avoid MX loops  
> > relay unix - - - - - smtp  
> > &nbsp;&nbsp;-o smtp\_fallback\_relay=  
> > # -o smtp\_helo\_timeout=5 -o smtp\_connect\_timeout=5  
> > showq unix n - - - - showq  
> > error unix - - - - - error  
> > retry unix - - - - - error  
> > discard unix - - - - - discard  
> > local unix - n n - - local  
> > virtual unix - n n - - virtual  
> > lmtp unix - - - - - lmtp  
> > anvil unix - - - - 1 anvil  
> > scache unix - - - - 1 scache  
> > maildrop unix - n n - - pipe  
> > flags=DRhu user=vmail argv=/usr/bin/maildrop -d ${recipient}  
> > uucp unix - n n - - pipe  
> > flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail  
> > ($recipient)  
> > ifmail unix - n n - - pipe  
> > flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)  
> > bsmtp unix - n n - - pipe  
> > flags=Fq. user=bsmtp argv=/usr/lib/bsmtp/bsmtp -t$nexthop -f$sender  
> > $recipient  
> > scalemail-backend unix - n n - 2 pipe  
> > flags=R user=scalemail argv=/usr/lib/scalemail/bin/scalemail-store  
> > ${nexthop} ${user} ${extension}  
> > mailman unix - n n - - pipe  
> > flags=FR user=list argv=/usr/lib/mailman/bin/postfix-to-mailman.py  
> > ${nexthop} ${user}  
> > zarafa unix - n n - 10 pipe  
> > flags= user=vmail argv=/usr/bin/zarafa-dagent ${user}
> > 
> > djigzo unix - - n - 4 smtp  
> > -o smtp\_send\_xforward\_command=yes  
> > -o disable\_dns\_lookups=yes  
> > -o smtp\_generic\_maps=
> > 
> > 127.0.0.1:10026 inet n - n - 10 smtpd  
> > -o content\_filter=  
> > -o  
> > receive\_override\_options=no\_unknown\_recipient\_checks,no\_header\_body\_checks,no\_milters  
> > -o smtpd\_helo\_restrictions=  
> > -o smtpd\_client\_restrictions=  
> > -o smtpd\_sender\_restrictions=  
> > -o smtpd\_recipient\_restrictions=permit\_mynetworks,reject  
> > -o mynetworks=127.0.0.0/8  
> > -o smtpd\_authorized\_xforward\_hosts=127.0.0.0/8  
> > -o smtpd\_authorized\_xclient\_hosts=127.0.0.0/8
> > 
> > 127.0.0.1:10025 inet n - n - - smtpd  
> > -o content\_filter=  
> > -o local\_recipient\_maps=  
> > -o relay\_recipient\_maps=  
> > -o smtpd\_restriction\_classes=  
> > -o smtpd\_client\_restrictions=  
> > -o smtpd\_helo\_restrictions=  
> > -o smtpd\_sender\_restrictions=  
> > -o smtpd\_recipient\_restrictions=permit\_mynetworks,reject  
> > -o mynetworks=127.0.0.0/8  
> > -o strict\_rfc821\_envelopes=yes  
> > -o smtpd\_error\_sleep\_time=0  
> > -o smtpd\_soft\_error\_limit=1001  
> > -o smtpd\_hard\_error\_limit=1000
> > 
> > main.cf  
> > --------  
> > readme\_directory = no  
> > myorigin = /etc/mailname  
> > mydestination = ${djigzo\_mydestination}, in-put.de, zarafaserver.in-put.de,  
> > localhost  
> > inet\_interfaces = all  
> > virtual\_mailbox\_maps = hash:/etc/postfix/virtual  
> > virtual\_alias\_maps = hash:/etc/postfix/virtual  
> > virtual\_transport = lmtp:127.0.0.1:2003  
> > mailbox\_transport = zarafa  
> > zarafa\_destination\_recipient\_limit = 1  
> > djigzo\_after\_filter\_message\_size\_limit = 512000000  
> > djigzo\_mailbox\_size\_limit = 512000000  
> > djigzo\_smtp\_helo\_name =  
> > djigzo\_relay\_transport\_host = 192.168.0.101  
> > djigzo\_relay\_transport\_host\_mx\_lookup =  
> > djigzo\_relay\_transport\_host\_port = 25  
> > djigzo\_reject\_unverified\_recipient =  
> > djigzo\_unverified\_recipient\_reject\_code = 450  
> > djigzo\_parent\_domain\_matches\_subdomains =  
> > smtpd\_banner = ESMTP  
> > biff = no  
> > append\_dot\_mydomain = no  
> > myhostname = ${djigzo\_myhostname}  
> > mynetworks = 127.0.0.0/8, ${djigzo\_mynetworks}  
> > relayhost =  
> > ${djigzo\_relayhost\_mx\_lookup:${djigzo\_relayhost?[}}${djigzo\_relayhost}${djigzo\_relayhost\_mx\_lookup:${djigzo\_relayhost?]}}${djigzo\_relayhost?:${djigzo\_relayhost\_port}}  
> > relay\_domains = ${djigzo\_relay\_domains}  
> > message\_size\_limit = ${djigzo\_after\_filter\_message\_size\_limit}  
> > mailbox\_size\_limit = ${djigzo\_mailbox\_size\_limit}  
> > smtp\_helo\_name =  
> > ${djigzo\_smtp\_helo\_name?$djigzo\_smtp\_helo\_name}${djigzo\_smtp\_helo\_name:$myhostname}  
> > relay\_transport =  
> > relay${djigzo\_relay\_transport\_host?:${djigzo\_relay\_transport\_host\_mx\_lookup:[}$djigzo\_relay\_transport\_host${djigzo\_relay\_transport\_host\_mx\_lookup:]}:$djigzo\_relay\_transport\_host\_port}  
> > smtpd\_recipient\_restrictions = permit\_mynetworks, reject\_unauth\_destination  
> > ${djigzo\_reject\_unverified\_recipient?, reject\_unverified\_recipient}  
> > unverified\_recipient\_reject\_code = $djigzo\_unverified\_recipient\_reject\_code  
> > parent\_domain\_matches\_subdomains = $djigzo\_parent\_domain\_matches\_subdomains  
> > smtpd\_discard\_ehlo\_keywords = silent-discard, dsn, etrn  
> > smtpd\_etrn\_restrictions = reject  
> > alias\_maps = hash:/etc/aliases  
> > alias\_database = hash:/etc/aliases  
> > recipient\_delimiter = +  
> > smtpd\_authorized\_xforward\_hosts = 127.0.0.1/32  
> > content\_filter = djigzo:127.0.0.1:10023  
> > smtpd\_sasl\_auth\_enable = yes  
> > broken\_sasl\_auth\_clients = yes  
> > smtpd\_sasl\_security\_options = noanonymous  
> > smtpd\_tls\_key\_file = /etc/zarafa/gateway/privkey.pem  
> > smtpd\_tls\_cert\_file = /etc/zarafa/gateway/cert.pem  
> > smtpd\_use\_tls = yes  
> > smtpd\_tls\_loglevel = 2  
> > tls\_random\_source = dev:/dev/urandom  
> > djigzo\_mynetworks = 127.0.0.0/8, 192.168.0.0/24  
> > djigzo\_myhostname = zarafaserver.in-put.de  
> > djigzo\_relayhost = 192.168.0.101  
> > djigzo\_relayhost\_mx\_lookup =  
> > djigzo\_relayhost\_port = 25  
> > djigzo\_before\_filter\_message\_size\_limit = 10240000
> > 
> > Thanks for your help.
> > 
> > Best regards,
> > 
> > Stefan
> 
> --  
> Djigzo open source email encryption
