diff --git a/systems/x86_64-linux/prefect/firewall.nix b/systems/x86_64-linux/prefect/firewall.nix index f821ff16..b58b7409 100644 --- a/systems/x86_64-linux/prefect/firewall.nix +++ b/systems/x86_64-linux/prefect/firewall.nix @@ -4,6 +4,7 @@ networking.firewall = { enable = true; allowedTCPPorts = [ + 25 80 143 179 diff --git a/systems/x86_64-linux/prefect/services/mailserver/stalwart/auth.nix b/systems/x86_64-linux/prefect/services/mailserver/stalwart/auth.nix index 0800f617..b3edaca6 100644 --- a/systems/x86_64-linux/prefect/services/mailserver/stalwart/auth.nix +++ b/systems/x86_64-linux/prefect/services/mailserver/stalwart/auth.nix @@ -1,7 +1,7 @@ { ifThen, otherwise }: let relVer = [ - (ifThen "listener = 'smtp'" "relaxed") + (ifThen "protocol = 'smtp'" "relaxed") (otherwise "disable") ]; in diff --git a/systems/x86_64-linux/prefect/services/mailserver/stalwart/default.nix b/systems/x86_64-linux/prefect/services/mailserver/stalwart/default.nix index 064a8097..6244ab34 100644 --- a/systems/x86_64-linux/prefect/services/mailserver/stalwart/default.nix +++ b/systems/x86_64-linux/prefect/services/mailserver/stalwart/default.nix @@ -161,7 +161,7 @@ in # https://stalw.art/docs/email/maintenance email.auto-expunge = "180d"; changes.max-history = 10000; - session = import ./session.nix { inherit isAuthenticated otherwise; }; + session = import ./session.nix { inherit isAuthenticated otherwise ifThen; }; queue = import ./queue.nix { inherit d ifThen otherwise; }; # DNS Settings # https://stalw.art/docs/mta/outbound/dns diff --git a/systems/x86_64-linux/prefect/services/mailserver/stalwart/session.nix b/systems/x86_64-linux/prefect/services/mailserver/stalwart/session.nix index 2d1d3d11..65f73d71 100644 --- a/systems/x86_64-linux/prefect/services/mailserver/stalwart/session.nix +++ b/systems/x86_64-linux/prefect/services/mailserver/stalwart/session.nix @@ -1,4 +1,8 @@ -{ isAuthenticated, otherwise }: +{ + isAuthenticated, + otherwise, + ifThen, +}: # MTA Settings # https://stalw.art/docs/mta/overview { @@ -8,6 +12,10 @@ # # https://stalw.art/docs/mta/inbound/ehlo ehlo = { require = true; + reject-non-fqdn = [ + (ifThen "protocol = 'smtp'" true) + (otherwise false) + ]; }; # # RCPT Stage # # https://stalw.art/docs/mta/inbound/rcpt @@ -18,6 +26,17 @@ ]; subaddressing = true; }; + auth = { + mechanisms = [ + (ifThen "protocol != 'smtp'" "[plain, login]") + (otherwise false) + ]; + directory = "'default'"; + require = [ + (ifThen "protocol != 'smtp'" true) + (otherwise false) + ]; + }; extensions = let ifAuthed = [