温馨提示×

centos邮件服务器怎么加密

小樊
40
2026-10-02 23:34:19
栏目: 云计算

在 CentOS 上搭建“邮件服务器”并实现加密,通常包含三个层面:

  1. 传输加密(最重要):SMTP / IMAP / POP3 使用 TLS
  2. 用户认证加密:密码不在网络中明文传输
  3. 磁盘 / 邮件内容加密(可选):防止服务器被攻破后泄露

下面按**最常见方案(Postfix + Dovecot)**说明。


一、传输层加密(SMTP / IMAP / POP3)

1. 准备证书

推荐用 Let’s Encrypt(免费):

yum install -y certbot
certbot certonly --standalone -d mail.example.com

证书路径:

  • 证书:/etc/letsencrypt/live/mail.example.com/fullchain.pem
  • 私钥:/etc/letsencrypt/live/mail.example.com/privkey.pem

2. Postfix(SMTP 加密)

启用 TLS

编辑 /etc/postfix/main.cf:

smtpd_tls_cert_file = /etc/letsencrypt/live/mail.example.com/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.example.com/privkey.pem
smtpd_use_tls = yes
smtpd_tls_auth_only = yes

smtp_tls_security_level = may

提交端口(465 / 587)

smtpd_tls_security_level = encrypt

重启:

systemctl restart postfix

✅ 效果:

  • 25 端口:可选加密
  • 465 / 587:强制加密 + 认证

3. Dovecot(IMAP / POP3 加密)

编辑 /etc/dovecot/conf.d/10-ssl.conf:

ssl = required
ssl_cert = </etc/letsencrypt/live/mail.example.com/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.example.com/privkey.pem

禁用明文登录: /etc/dovecot/conf.d/10-auth.conf

disable_plaintext_auth = yes

重启:

systemctl restart dovecot

✅ 效果:

  • IMAP:993
  • POP3:995
  • 明文密码无法传输

二、认证加密(防止密码泄露)

只要满足:

  • SMTP:465 / 587 + TLS
  • IMAP / POP3:SSL/TLS

✅ 密码已经是加密的

❌ 不要使用:

  • 25 端口明文认证
  • STARTTLS 被客户端关闭

三、可选:磁盘加密(更底层)

LUKS(系统级)

适合物理机 / 私有云:

cryptsetup luksFormat /dev/sdb
cryptsetup open /dev/sdb maildata
mkfs.ext4 /dev/mapper/maildata

挂载到 /var/mail

⚠️ 重启需手动输入密码(或密钥文件)


四、检查是否加密成功

SMTP

openssl s_client -connect mail.example.com:465

IMAP

openssl s_client -connect mail.example.com:993

五、常见错误

❌ 只装 Postfix 没开 TLS
❌ 用 25 端口收邮件
❌ 自签证书没在客户端信任
❌ 明文 auth 没关


六、推荐最小安全配置

项目 建议
SMTP 465 + TLS
IMAP 993 + SSL
认证 禁止明文
证书 Let’s Encrypt
协议 禁用 SSLv3 / TLSv1.0

如果你愿意,可以告诉我:

  • 用的 CentOS 几
  • Postfix / Sendmail / Exim
  • 是否已有邮件服务器

我可以直接给你可复制的完整配置。

0 踩