# inet_protocols
service postfix restart
-else # exim. has debian specific stuff for now
+else # begin exim. has debian specific stuff for now
+ if [[ -e /p/c/filesystem ]]; then
+ /a/exe/vpn-mk-client-cert -n mail li
+ fi
+
+ cat >/etc/systemd/system/mailroute.service <<'EOF'
+[Unit]
+# this unit is configured to start and stop whenever openvpn-client@mail.service
+# does
+Description=Routing for email vpn
+After=network.target
+BindsTo=openvpn-client@mail.service
+After=openvpn-client@mail.service
+
+[Service]
+Type=oneshot
+ExecStart=/a/bin/distro-setup/mail-route start
+ExecStop=/a/bin/distro-setup/mail-route stop
+RemainAfterExit=yes
+
+[Install]
+RequiredBy=openvpn-client@mail.service
+EOF
+
+ cat >/etc/systemd/system/offlineimapsync.timer <<'EOF'
+[Unit]
+Description=Run offlineimap-sync once every 5 mins
+
+[Timer]
+OnCalendar=*:0/5
+
+[Install]
+WantedBy=timers.target
+EOF
+
+ cat >/etc/systemd/system/offlineimapsync.service <<'EOF'
+[Unit]
+Description=Offlineimap sync
+After=multi-user.target
+
+[Service]
+User=ian
+Type=oneshot
+ExecStart=/a/bin/log-quiet/sysd-mail-once offlineimap-sync /a/bin/distro-setup/offlineimap-sync
+EOF
+ systemctl daemon-reload
+ systemctl enable mailroute
# wording of question from dpkg-reconfigure exim4-config
# 1. internet site; mail is sent and received directly using SMTP
source /a/bin/bash_unpublished/source-semi-priv
exim_main_dir=/etc/exim4/conf.d/main
mkdir -p $exim_main_dir
+
+
if [[ $HOSTNAME == $MAIL_HOST ]]; then
debconf-set-selections <<EOF
LOCAL_DELIVERY = dovecot_lmtp
-# options exim has to avoid altering the default config files
+# options exim has to avoid having to alter the default config files
CHECK_RCPT_LOCAL_ACL_FILE = /etc/exim4/rcpt_local_acl
CHECK_DATA_LOCAL_ACL_FILE = /etc/exim4/data_local_acl
EOF
- cat >/etc/systemd/system/offlineimapsync.timer <<'EOF'
-[Unit]
-Description=Run offlineimap-sync once every 5 mins
-
-[Timer]
-OnCalendar=*:0/5
-
-[Install]
-WantedBy=timers.target
-EOF
-
- cat >/etc/systemd/system/offlineimapsync.service <<'EOF'
-[Unit]
-Description=Offlineimap sync
-After=multi-user.target
-
-[Service]
-User=ian
-Type=oneshot
-ExecStart=/a/bin/log-quiet/sysd-mail-once offlineimap-sync /a/bin/distro-setup/offlineimap-sync
-EOF
- systemctl daemon-reload
systemctl enable offlineimapsync.timer
systemctl start offlineimapsync.timer
+ systemctl restart openvpn-client@mail
+ systemctl enable openvpn-client@mail
else # $HOSTNAME != $MAIL_HOST
systemctl disable offlineimapsync.timer &>/dev/null ||:
systemctl stop offlineimapsync.timer &>/dev/null ||:
+ systemctl disable openvpn-client@mail
+ systemctl stop openvpn-client@mail
#
#
# would only exist because I wrote it i the previous condition,
exim4-config exim4/dc_eximconfig_configtype select mail sent by smarthost; no local mail
exim4-config exim4/dc_smarthost string $smarthost
EOF
+
fi # end $HOSTNAME != $MAIL_HOST
# if we already have it installed, need to reconfigure, without being prompted
# just noticed this in the config file, seems like a good idea.
sed -i '/^\s*NICE\s*=/d' /etc/default/spamassassin
e 'NICE="--nicelevel 15"' >>/etc/default/spamassassin
+ systemctl start spamassassin
systemctl reload spamassassin
cat >/etc/systemd/system/spamddnsfix.service <<'EOF'
fi
if [[ $HOSTNAME == $MAIL_HOST ]]; then
local_mx=mail.iankelling.org
- rsync_common="rsync -ogt --chown=root:Debian-exim --chmod=640 root@li:/p/c/machine_specific/li/webservercerts/$local_mx-"
- ${rsync_common}chained.pem /etc/exim4/exim.crt
- ${rsync_common}domain.key /etc/exim4/exim.key
+ rsync_common="rsync -ogtL --chown=root:Debian-exim --chmod=640 root@li:/etc/letsencrypt/live/$local_mx/"
+ ${rsync_common}fullchain.pem /etc/exim4/exim.crt
+ ${rsync_common}privkey.pem /etc/exim4/exim.key
fi
EOF
chmod 755 $f
[Service]
Type=oneshot
-ExecStart=/usr/local/bin/sysd-mail-once mailcert /usr/local/bin/mail-cert-cron
+ExecStart=/a/bin/log-quiet/sysd-mail-once mailcert /usr/local/bin/mail-cert-cron
EOF
cat >/etc/systemd/system/mailcert.timer <<'EOF'
# begin setup passwd.client
f=/etc/exim4/passwd.client
+ rm -f /etc/exim4/passwd.client
install -m 640 -g Debian-exim /dev/null $f
cat /etc/mailpass| while read -r domain port pass; do
# reference: exim4_passwd_client(5)
# put spool dir in directory that spans multiple distros.
# based on http://www.postfix.org/qmgr.8.html and my notes in gnus
+#
+# todo: I'm suspicious of uids for Debian-exim being the same across
+# distros. It would be good to test this.
dir=/nocow/$type
sdir=/var/spool/$type
# we only do this if our system has $dir
if [[ -e $dir && $(readlink -f $sdir) != $dir ]]; then
- systectl stop $type
+ systemctl stop $type
if [[ ! -e $dir && -d $sdir ]]; then
mv $sdir $dir
fi