prevent SMTP smuggling
[ansible.git] / roles / email / tasks / dovecot.yml
index f4929eb320dfa7bf4dbc72999cc880708dfd180a..1766ede7caa9f4fefbe9b6167a0c69e5d5f3db6a 100644 (file)
@@ -1,5 +1,5 @@
 - name: install dovecot
-  apt: name=dovecot-imapd,dovecot-lmtpd,dovecot-mysql,dovecot-pop3d,dovecot-sieve,dovecot-managesieved state=latest
+  apt: name=dovecot-imapd,dovecot-lmtpd,dovecot-mysql,dovecot-pop3d,dovecot-sieve,dovecot-managesieved,python3-mysqldb state=latest
 - name: enable dovecot
   service: name=dovecot enabled=yes
 # configuration
@@ -22,7 +22,7 @@
   template:
     dest: /etc/dovecot/{{ item }}
     src: templates/dovecot/{{ item }}
-    mode: u=rw,g=r,o=
+    mode: u=rw,g=r,o=r # changepw needs read access
     group: dovecot
   loop:
   - conf.d/10-auth.conf
   - conf.d/20-lmtp.conf
   - conf.d/90-quota.conf
   - conf.d/auth-sql.conf.ext
+- name: configure dovecot secrets
+  notify: dovecot
+  template:
+    dest: /etc/dovecot/{{ item }}
+    src: templates/dovecot/{{ item }}
+    mode: u=rw,g=r,o=
+    group: dovecot
+  loop:
   - dovecot-sql.conf.ext
 - name: install quota notification script
   template:
     dest: /etc/dovecot/quota-warning.sh
     src: templates/dovecot/quota-warning.sh
     mode: +x
+# scripts
+- name: create newmail dir
+  file: path=/root/newmail state=directory
+- name: install newmail script
+  template:
+    dest: /root/newmail/newmail
+    src: templates/newmail/newmail
+    mode: u=rwx,g=rx,o=rx
+- name: install newmail config
+  template:
+    dest: /root/newmail/{{ item }}
+    src: templates/newmail/{{ item }}
+  loop:
+  - templates.py
+  - settings.py
+- name: install changepw script
+  when: postfix.dovecot.changepw_cgi is defined
+  template:
+    dest: "{{postfix.dovecot.changepw_cgi}}"
+    src: templates/changepw
+    mode: u=rwx,g=rx,o=