<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://wiki.callooh.com/index.php?action=history&amp;feed=atom&amp;title=SMTP_Auth</id>
	<title>SMTP Auth - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.callooh.com/index.php?action=history&amp;feed=atom&amp;title=SMTP_Auth"/>
	<link rel="alternate" type="text/html" href="https://wiki.callooh.com/index.php?title=SMTP_Auth&amp;action=history"/>
	<updated>2026-10-03T05:47:34Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Callooh Wiki</subtitle>
	<generator>MediaWiki 1.45.1</generator>
	<entry>
		<id>https://wiki.callooh.com/index.php?title=SMTP_Auth&amp;diff=10&amp;oldid=prev</id>
		<title>Reini: Schützte „SMTP Auth“ [edit=autoconfirmed:move=autoconfirmed]</title>
		<link rel="alternate" type="text/html" href="https://wiki.callooh.com/index.php?title=SMTP_Auth&amp;diff=10&amp;oldid=prev"/>
		<updated>2009-08-23T13:02:43Z</updated>

		<summary type="html">&lt;p&gt;Schützte „&lt;a href=&quot;/index.php?title=SMTP_Auth&quot; title=&quot;SMTP Auth&quot;&gt;SMTP Auth&lt;/a&gt;“ [edit=autoconfirmed:move=autoconfirmed]&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 23. August 2009, 13:02 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;de&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(kein Unterschied)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Reini</name></author>
	</entry>
	<entry>
		<id>https://wiki.callooh.com/index.php?title=SMTP_Auth&amp;diff=6&amp;oldid=prev</id>
		<title>193.81.98.66: Die Seite wurde neu angelegt: „=SMTP Auth (SMTP-Authentifizierung)=  ==Wo== * FW4 * TODO: FW2  ==Besonderheiten== * Da wir Login und Plain als Authentifizierungs-Verfahren verwenden, und bei be...“</title>
		<link rel="alternate" type="text/html" href="https://wiki.callooh.com/index.php?title=SMTP_Auth&amp;diff=6&amp;oldid=prev"/>
		<updated>2009-08-04T08:21:39Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „=SMTP Auth (SMTP-Authentifizierung)=  ==Wo== * FW4 * TODO: FW2  ==Besonderheiten== * Da wir Login und Plain als Authentifizierungs-Verfahren verwenden, und bei be...“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=SMTP Auth (SMTP-Authentifizierung)=&lt;br /&gt;
&lt;br /&gt;
==Wo==&lt;br /&gt;
* FW4&lt;br /&gt;
* TODO: FW2&lt;br /&gt;
&lt;br /&gt;
==Besonderheiten==&lt;br /&gt;
* Da wir Login und Plain als Authentifizierungs-Verfahren verwenden, und bei beiden Username/Passwort unverschlüsselt übertragen werden, sollte smtps verwendet werden.  &lt;br /&gt;
&lt;br /&gt;
==Konfiguration==&lt;br /&gt;
Sendmail wird Sasl2 via saslauthd zum Authentifizieren benutzen. Darum konfigurieren wir als ersten Schritt&lt;br /&gt;
===Saslauthd===&lt;br /&gt;
* /etc/default/saslauthd&lt;br /&gt;
 START=yes&lt;br /&gt;
&lt;br /&gt;
 MECHANISMS=&amp;quot;ldap&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* /etc/saslauthd.conf&lt;br /&gt;
 ldap_servers: ldap://192.168.10.8/ ldap://192.168.10.15/&lt;br /&gt;
 ldap_search_base: ou=users,dc=creative,dc=co,dc=at&lt;br /&gt;
&lt;br /&gt;
* starten und testen&lt;br /&gt;
 /etc/init.d/saslauthd start&lt;br /&gt;
&lt;br /&gt;
 testsaslauthd -u username -p password&lt;br /&gt;
&lt;br /&gt;
=&amp;gt; soll &amp;lt;code&amp;gt;0: OK &amp;quot;Success.&amp;quot;&amp;lt;/code&amp;gt;liefern&lt;br /&gt;
&lt;br /&gt;
===SASL===&lt;br /&gt;
* /usr/lib/sasl2/Sendmail.conf&lt;br /&gt;
 pwcheck_method: saslauthd&lt;br /&gt;
 allowanonymouslogin: 0&lt;br /&gt;
 allowplaintext: 1&lt;br /&gt;
 mech_list: LOGIN PLAIN&lt;br /&gt;
&lt;br /&gt;
===Sendmail===&lt;br /&gt;
==== SMTPs Daemon aktivieren====&lt;br /&gt;
in sendmail.mc:&lt;br /&gt;
&lt;br /&gt;
 DAEMON_OPTIONS(`Name=IPv4, Family=inet&amp;#039;)&lt;br /&gt;
 DAEMON_OPTIONS(`Name=IPv6, Family=inet6, Modifiers=O&amp;#039;)&lt;br /&gt;
 DAEMON_OPTIONS(`Port=smtps, Name=TLSMTA, M=s&amp;#039;)dnl&lt;br /&gt;
&lt;br /&gt;
relevant ist die dritte Zeile, die ersten beiden werden nur benötigt falls sie noch nicht vorhanden sind.&lt;br /&gt;
&lt;br /&gt;
sendmail.cf generieren, sendmail restarten und mit &amp;lt;code&amp;gt;netstat -ln | grep 465&amp;lt;/code&amp;gt; prüfen ob smtps aktiviert ist.&lt;br /&gt;
(&amp;lt;code&amp;gt;netstat -ln | grep 25&amp;lt;/code&amp;gt; sollte natürlich nachwievor zumindest eine Zeile zurückgeben)&lt;br /&gt;
&lt;br /&gt;
* Modifier (M=?)&lt;br /&gt;
 a  Auth erzwingen&lt;br /&gt;
 A  Auth deaktivieren&lt;br /&gt;
 s  SSL/TLS aktivieren&lt;br /&gt;
&lt;br /&gt;
Variante, wie auf fw4 eingesetzt (via SSL nur Verbindungen mit Auth, ohne SSL Auth deaktivieren um Auth-Attacken vorzubeugen):&lt;br /&gt;
 DAEMON_OPTIONS(`Name=IPv4, Family=inet, M=A&amp;#039;)&lt;br /&gt;
 DAEMON_OPTIONS(`Name=IPv6, Family=inet6, Modifiers=O&amp;#039;)&lt;br /&gt;
 DAEMON_OPTIONS(`Port=smtps, Name=TLSMTA, M=sa&amp;#039;)dnl&lt;br /&gt;
&lt;br /&gt;
====Zertifikate====&lt;br /&gt;
Da wir ab jetzt TLS bzw. SSL verwenden, brauchen wir auch Zertifikate.&lt;br /&gt;
Unter Debian ist folgenden Zeile in der sendmail.mc ausreichend:&lt;br /&gt;
 include(`/etc/mail/tls/starttls.m4&amp;#039;)dnl&lt;br /&gt;
&lt;br /&gt;
Die Zertifikate müssen sich dann auch unter &amp;lt;code&amp;gt;/etc/mail/tls&amp;lt;/code&amp;gt; befinden, wahrscheinlich tun sie das bereits ;-)&lt;br /&gt;
&lt;br /&gt;
Getestet kann das damit werden:&lt;br /&gt;
 openssl s_client -connect localhost:465&lt;br /&gt;
&lt;br /&gt;
====Auth====&lt;br /&gt;
in sendmail.mc:&lt;br /&gt;
 dnl ### smtp auth ### dnl&lt;br /&gt;
 define(`confAUTH_MECHANISMS&amp;#039;, `LOGIN PLAIN&amp;#039;)dnl&lt;br /&gt;
 TRUST_AUTH_MECH(`LOGIN PLAIN&amp;#039;)dnl&lt;br /&gt;
&lt;br /&gt;
===IPTables===&lt;br /&gt;
eingehende Verbindungen auf Port 465 zulassen:&lt;br /&gt;
 iptables -A INPUT .. -p tcp --dport ssmtp -j ACCEPT&lt;br /&gt;
&lt;br /&gt;
==Testen==&lt;br /&gt;
Username und Passwort base64 encoden:&lt;br /&gt;
  perl -MMIME::Base64 -e &amp;#039;print encode_base64(&amp;quot;\000username\000pass&amp;quot;)&amp;#039;&lt;br /&gt;
  $ AHJ3ZQBqYmFXMGsh&lt;br /&gt;
&lt;br /&gt;
 openssl s_client -crlf -connect localhost:465&lt;br /&gt;
&lt;br /&gt;
SMTP Chat:&lt;br /&gt;
 ..&lt;br /&gt;
 AUTH PLAIN AHJ3ZQBqYmFXMGsh&lt;br /&gt;
 235 2.0.0 OK Authenticated&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Kategorie:CMTechnik]]&lt;/div&gt;</summary>
		<author><name>193.81.98.66</name></author>
	</entry>
</feed>