Conversation
…aths on boot Postfix and Dovecot inside the openship-mail container load certificates from /etc/ssl/certs/iRedMail.crt and /etc/ssl/private/iRedMail.key. Because /etc/ssl is ephemeral, container recreations and image updates revert to the baked self-signed certificates even when valid certificates are mounted at /etc/letsencrypt. This reconciles /etc/letsencrypt certificates on every boot into the daemon paths if present, ensuring TLS clients never fail with self-signed certificate errors. Fixes oblien#837
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Postfix and Dovecot inside the \openship-mail\ container load certificates from /etc/ssl/certs/iRedMail.crt\ and /etc/ssl/private/iRedMail.key.
Because /etc/ssl\ is inside the ephemeral container layer (not a persistent volume), recreating the container or updating the image reverts /etc/ssl\ to the baked self-signed certificates — even when valid certificates are mounted at /etc/letsencrypt.
As a result, applications and clients connecting via STARTTLS on port 587 or SSL on 465 (like Node.js / nodemailer, Python, or mail clients) fail with:
\
Error: self-signed certificate (code: ESOCKET, command: CONN)
\\
This PR adds a reconciliation step (\3c) to \�pps/email/docker/entrypoint.sh\ that checks for \mail.\ (or \) under /etc/letsencrypt/live/\ on every boot and symlinks \ullchain.pem\ and \privkey.pem\ into the default daemon certificate paths.
Fixes #837
Verification
odemailer.createTransport().verify()) succeeds without certificate rejection