¼ø¶È»ñÎÁ/Âè09²ó

Top / ¼ø¶È»ñÎÁ / Âè09²ó

ǧ¾Ú¥·¥¹¥Æ¥à¤Ë¤Ä¤¤¤Æ°ìÈÌŪ¤ÊÏÃ

unix ¥µ¡¼¥Ð¤Ë¸Â¤é¤º¡¤¥³¥ó¥Ô¥å¡¼¥¿°ìÈ̤ˡÖǧ¾Ú¡×¤È¤¤¤¦»ÅÁȤߤÏÉԲķç¤Ç¤¢¤ë.
´ðËÜŪ¤Ë¡¤´í¸±¤ÊÎΰè¤Ç¤¢¤ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤ò¥Ñ¥¹¥ï¡¼¥É¤ò¤É¤Î¤è¤¦¤Ë¤ä¤ê¤È¤ê¤¹¤ë¤«¡¤¥Ñ¥¹¥ï¡¼¥É¤È¥æ¡¼¥¶Ì¾¤Ê¤É¤Î¾È¹ç¤ò¤É¤Î¤è¤¦¤Ë¹Ô¤¦¤Î¤«¤ÎÆóÅÀ¤Ë¤Ä¤¤¤ÆÍÍ¡¹¤ÊÊýË¡¤¬¤¢¤ê¡¤¤³¤ì¤é¤ò½ÀÆð¤ËÁª¤Ù¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤â¤Î¤¬Â¿¤¤.
¤½¤Î¤¿¤á¤Ë½é³Ø¼Ô¤Ë¤Ïº®Í𤬤¢¤ë¤«¤È»×¤¦¤¬¡¤¼ÂºÝ¤Ï¤³¤ÎÆ󥫽ê¤ÎÁªÂò¤À¤È¤¤¤¦¹½¿Þ¤¬Ê¬¤«¤ì¤Ðʬ¤«¤ê¤ä¤¹¤¤¤À¤í¤¦.
¼ÂºÝ¡¤¤ª¤ª¤Þ¤«¤Ë¤Ï¡¤unix ¾å¤Ç¤Î¥½¥Õ¥È¥¦¥§¥¢¤ÏÄ̾ï¤Ï°Ê²¼¤Î¿Þ¤Î¤è¤¦¤Ê¹½Â¤¤ò¤·¤Æ¤¤¤ë¤Î¤Ç¡¤¤³¤Î¹½¿Þ¤òƬ¤Ë¤¤¤ì¤Æ°Ê²¼¤ÎÏäòÆɤá¤Ð¤ï¤«¤ë¤À¤í¤¦.

authentication-structure_ss.png

ǧ¾Ú¤Î°ìÈÌŪ¤Ê»ÅÁȤß

Á°²ó¤«¤é¤Î³¤­

SMTP Auth ¤ÎÀßÄê(postfix)

¤µ¤Æ¡¤SMTP Auth ¤ÎÀßÄê¤È¤Ê¤ë¤È¥Þ¥Ë¥å¥¢¥ë¤Ë¤âÆä˵­½Ò¤¬¤Ê¤¤¤³¤È¤À¤·¡¤¾ðÊó¤ò¤­¤Á¤ó¤ÈÄ´¤Ù¤Æ¤«¤é¹Ô¤Ê¤¤¤¿¤¤.
SMTP Auth ¤Ë´Ø¤·¤Æ¤Ï¤Þ¤À¤Þ¤ÀÊѹ¹¤¬¤¢¤¤¤Ä¤¤¤Ç¤¤¤ë¤è¤¦¤Ê¤Î¤Ç¡¤¤³¤¦¤¤¤¦¤È¤­¤Ï¤Þ¤º¤ÏËÜ²È http://www.postfix.org/ ¤Ç³Îǧ¤·¤¿¤¤¡¥
¶ñÂÎŪ¤Ë¤Ï http://www.postfix.org/SASL_README.html ¤ò¥Á¥§¥Ã¥¯¤¹¤ë¤³¤È¤Ë¤Ê¤ë. ¤¹¤ë¤È¡¤¤Þ¤º¤Ï¼¡¤Î¤è¤¦¤Ë½ñ¤¤¤Æ¤¢¤ë¤È¤³¤í¤¬»²¹Í¤Ë¤Ê¤ë.

 Enabling SASL authentication in the Postfix SMTP server
 
 In order to enable SASL support in the Postfix SMTP server:
 
   /etc/postfix/main.cf:
       smtpd_sasl_auth_enable = yes
 
 In order to allow mail relaying by authenticated remote SMTP clients:
 
   /etc/postfix/main.cf:
       smtpd_recipient_restrictions = 
           permit_mynetworks 
           permit_sasl_authenticated 
           reject_unauth_destination
 
 To report SASL login names in Received: message headers (Postfix version 2.3 and later):
 
   /etc/postfix/main.cf:
       smtpd_sasl_authenticated_header = yes
 
 Note: the SASL login names will be shared with the entire world.
 
 Older Microsoft SMTP client software implements a non-standard version 
 of the AUTH protocol syntax, and expects that the SMTP server replies to 
 EHLO with "250 AUTH=mechanism-list" instead of "250 AUTH mechanism-list". 
 To accommodate such clients (in addition to conformant clients) use the following:
 
   /etc/postfix/main.cf:
       broken_sasl_auth_clients = yes

¤Þ¤º¤Ï¤³¤Î»Ø¼¨¤Ë¤·¤¿¤¬¤Ã¤Æ main.cf ¤ò½¤Àµ¤·¤è¤¦. ¤¿¤À¤·¡¤¾å¤ÎʸÃæ¤Î/etc/postfix ¤Ï FreeBSD ¤Ç¤Ï /usr/local/etc/postfix ¤ËÊѹ¹¤µ¤ì¤Æ¤¤¤ë¤Î¤ÇǾÆâ¤ÇÊÑ´¹¤·¤Ê¤¬¤éÆɤ⤦. ¤Þ¤¿¡¤"smtp" ¤È "smtpd" (ºÇ¸å¤Ë "d" ¤¬¤Ä¤¤¤Æ¤¤¤ë)¤È¤Ç¤Ï°ÕÌ£¤¬°ã¤Ã¤Æ¤¯¤ë¤Î¤Ç¡¤¥¿¥¤¥×¥ß¥¹¤ò¤·¤Æ¤¤¤Ê¤¤¤«Ãí°Õ¿¼¤¯µ­½Ò¤·¤è¤¦. ¤³¤³¤Ç¤ÏÁ´Éô¤Ç 4¤Ä¤Îµ­½Ò¤¬²Ã¤ï¤ë¤³¤È¤Ë¤Ê¤ë. ¤³¤ì¤Ï main.cf ¤ÎºÇ¸å¤Ë¸Ç¤á¤Æµ­½Ò¤·¤Æ¤âÌäÂê¤Ê¤¤¤Ï¤º¤À.

¤µ¤é¤Ë¾åµ­»ñÎÁ¤òÆɤ߿ʤà¤È¡¤

 Cyrus SASL configuration for the Postfix SMTP server

¤Ç»Ï¤Þ¤ëÉôʬ¤¬¤¢¤ë¤Î¤Ç¤³¤ì¤Þ¤¿Æɤޤʤ¤¤È¤¤¤±¤Ê¤¤. ¤¿¤À¤³¤³¤ÏÆɤó¤Ç¤âÎɤ¯Ê¬¤«¤é¤Ê¤¤Éôʬ¤â¿¤¤¤À¤í¤¦¤«¤é½¤Àµ²Õ½ê¤ò½ñ¤¤¤Æ¤ª¤¯¤È¡¤main.cf ¤Ë¤È¤ê¤¢¤¨¤º°Ê²¼¤ÎÆó¤Ä¤Îµ­½Ò¤ò²Ã¤¨¤Æ¤ª¤±¤Ð¤è¤¤.

 smtpd_sasl_path = smtpd
 smtpd_sasl_local_domain = $myhostname

¤¿¤À¤·¡¤¤³¤³¤òÆɤßÈô¤Ð¤µ¤Ê¤¤Êý¤¬Îɤ¤. ¤È¤¤¤¦¤Î¤â¡¤SMTP auth ¤Ë»È¤¦¥Ñ¥¹¥ï¡¼¥É¤Îºî¤êÊý¤¬ÃúÇ«¤Ë½ñ¤¤¤Æ¤¢¤ë¤Î¤À.
¶ñÂÎŪ¤Ë¤Ï¡¤

 saslpasswd2 -c -u `postconf -h myhostname` exampleuser

¤È¤»¤è¡¤¤È½ñ¤¤¤Æ¤¢¤ë(ºÇ¸å¤Î "exampleuser" ¤È¤¤¤¦¤Î¤Ï¥æ¡¼¥¶Ì¾¤ËÃÖ¤­´¹¤¨¤ÆÆɤà¤Ù¤·)*1.

SMTP Auth ¤ÎÆ°ºî³Îǧ

¥æ¡¼¥¶¤ÎÅÐÏ¿(SMTP Auth ÀìÍѤÇ)

SMTP Auth ¤ò¹Ô¤¦ºÝ¡¤¥æ¡¼¥¶¤È¥Ñ¥¹¥ï¡¼¥É¤Î¾È¹ç¤ò¤É¤¦¤¤¤¦¥Ç¡¼¥¿¤Ë´ð¤Å¤¤¤Æ¹Ô¤¦¤«¤Ë¤ÏËÜÍè¤ÏÁªÂò»è¤¬Ê£¿ô¤¢¤ë.
º£²ó¤ÏÆäËÊ£¿ô¤ÎÁªÂò»è¤ò»ØÄꤷ¤Æ¤¤¤Ê¤¤*2¤Î¤Ç»È¤¨¤ë¤Î¤Ï¥Ç¥Õ¥©¥ë¥È¤Î pwcheck_method ¤Î¤ß¡¤¤Ä¤Þ¤ê¡¤SMTP Auth ¤¬ÍøÍѤ¹¤ë SASL ÀìÍѤΥ桼¥¶/¥Ñ¥¹¥ï¡¼¥Éɽ¤òÍøÍѤ¹¤ë¤³¤È¤Ë¤Ê¤ë.

¤È¤¤¤¦¤³¤È¤Ï¡¤SMTP Auth ¤ò»È¤¦Á°¤Ë¡¤ÍøÍѼԤÎÅÐÏ¿¤¬É¬ÍפÀ¤È¤¤¤¦¤³¤È¤Ç¤¢¤ë.
¶ñÂÎŪ¤Ë¤Ï¡¤¾å¤Ë¤¢¤ë¤è¤¦¤Ë saslpasswd2 ¥³¥Þ¥ó¥É¤ò»È¤¦¤³¤È¤Ë¤Ê¤ë.

¤Á¤Ê¤ß¤Ë¡¤¥æ¡¼¥¶¤È(SMTP Auth ÀìÍѤÎ)¥Ñ¥¹¥ï¡¼¥É¤¬¤­¤Á¤ó¤ÈÅÐÏ¿¤µ¤ì¤¿¤«¤Î³Îǧ¤Ï¡¤

 sasldblistusers2

¤È¤¹¤ë¤È

 ¥æ¡¼¥¶Ì¾@¥Û¥¹¥È̾: userPassword

¤Ê¤É¤È¤¤¤¦É½¼¨¤¬½Ð¤ë¤Î¤Ç³Îǧ¤Ç¤­¤ë.

¼Â½¬

¥æ¡¼¥¶¤ò SMTP Auth ÍѤËÅÐÏ¿¤·¤è¤¦.
¤Þ¤¿¡¤Á°²ó¼ø¶È»ñÎÁ¤ËºÜ¤Ã¤Æ¤¤¤ë¥í¥°¥á¥Ã¥»¡¼¥¸¤Ë¤è¤ë¤È SMTP Auth ¤Ë»È¤¨¤ë "¥æ¡¼¥¶¤È¥Ñ¥¹¥ï¡¼¥É¤Î¾È¹çÊýË¡" ¤Ë¤Ï /etc/passwd, PAM, LDAP ¤Ê¤É¤¬¤¢¤ë¤È½ñ¤«¤ì¤Æ¤¤¤ë.
¤³¤ì¤é¤Ï²¿¤«¡¤Ä´¤Ù¤Æ¤ß¤è.

¼ÂºÝ¤Ë¼ê¤ÇÀܳ¤·¤Æ¤ß¤ë.

SMTP Auth ¤ÇÀܳ¤¹¤ëºÝ¤Îǧ¾ÚÊýË¡¤Ë¤â¤¤¤¯¤Ä¤«¤¢¤ê¡¤¼«Í³¤ËÀßÄê¤ÇÁª¤Ö¤³¤È¤¬¤Ç¤­¤ë.
º£²ó¤Î¥¤¥ó¥¹¥È¡¼¥ë¤Ç¤ÏÆäËÀßÄê¤ò²Ã¤¨¤Ê¤±¤ì¤Ð NTLMǧ¾Ú¡¤loginǧ¾Ú, plainǧ¾Ú¡¤GSSAPIǧ¾Ú, Digest-MD5ǧ¾Ú, CRAM-MD5ǧ¾Ú¤¬»È¤¨¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤À¤í¤¦¡¥

¤½¤³¤Ç¡¤¤³¤Î¤¦¤Á¤Î´Êñ¤ËÍøÍѤǤ­¤ë¤¬°Å¹æ²½¥Ê¥·¤Î plainǧ¾Ú¤È¡¤¤­¤Á¤ó¤È»È¤¦¤Ê¤éÄêÈ֤ΠCRAM-MD5ǧ¾Ú¤ò»î¤·¤Æ¤ß¤è¤¦.

¤½¤ÎÁ°¤Ë¡¤¸å¤ÇÍѤ¤¤ë¥³¥Þ¥ó¥É¤Ç¤¢¤ë mmencode ¤ò½àÈ÷¤È¤·¤Æ¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¤ª¤¯.
¶ñÂÎŪ¤Ë¤Ï¡¤ports ¥³¥ì¥¯¥·¥ç¥ó¤ò¿·¤·¤¯¤·¤Æ¤ª¤¤¤Æ¤«¤é¡¤

 portinstall mmencode

¤È¤¹¤ì¤Ð¤è¤¤.

¼ê¤Ç SMTP Auth ¤ò»î¤¹ : Plain ǧ¾Ú¤Î¾ì¹ç

Plain ǧ¾Ú¤Ï¤ªµ¤³Ú¤Ê¥â¥Î¤Ç¡¤SMTP Auth »þ¤Ëʸ»úÎó "\0¥æ¡¼¥¶Ì¾\0¥Ñ¥¹¥ï¡¼¥É"*3¤ò base64 ¤Ç¥¨¥ó¥³¡¼¥É¤·¤¿¤â¤Î¤ò¥µ¡¼¥Ð¤ËÅϤ¹¤È¤¤¤¦´Êñ¤Ê»ÅÁȤߤÀ.
¤Á¤Ê¤ß¤Ë¡¤base 64 ¤Ï°Å¹æ²½¤Ç¤Ï¤Ê¤¯¤Æ(¥³¥ó¥Ô¥å¡¼¥¿¤Ç°·¤¦¤Î¤ËÊØÍø¤Ë¤Ê¤ë¤è¤¦¤Ê)ñ¤Ê¤ëÊÑ´¹*4¤Ê¤Î¤Ç¡¤¥»¥­¥å¥ê¥Æ¥£¤ÏÁ´¤¯³ÎÊݤµ¤ì¤Ê¤¤¤³¤È¤ËÃí°Õ¤¬É¬ÍפÀ.
¤Ä¤Þ¤ê¡¤¥Ñ¥¹¥ï¡¼¥ÉÅù¤ò base64 ¥¨¥ó¥³¡¼¥É¤·¤¿¤â¤Î(¸å½Ò¤Î mmencode ¤ò¤«¤±¤¿¤â¤Î)¤ò¿Í¤Ë¶µ¤¨¤¿¤ê¤·¤Æ¤Ï¤¤¤±¤Ê¤¤.

¤µ¤Æ¡¤ÀܳÁ°¤ËÀܳ¤ËɬÍפÊʸ»úÎó¤òºî¤Ã¤Æ¤·¤Þ¤ª¤¦.
¶ñÂÎŪ¤Ë¤Ï¡¤¥³¥Þ¥ó¥É¥é¥¤¥ó¤Ç

 printf '\0000¥æ¡¼¥¶Ì¾\0000¥Ñ¥¹¥ï¡¼¥É' | mmencode 

¤È¤¹¤ì¤Ð¤è¤¤*5.
¥æ¡¼¥¶Ì¾¤È¥Ñ¥¹¥ï¡¼¥É¤Ï¤µ¤­¤Û¤É SMTP Auth ÍÑ¤Ë saslpasswd2 ¥³¥Þ¥ó¥É¤ÇÀßÄꤷ¤¿¤â¤Î¤Ç¤¢¤ë.

¤³¤¦¤¹¤ë¤È¡¤'\0¥æ¡¼¥¶Ì¾\0¥Ñ¥¹¥ï¡¼¥É' ¤¬ base64 ¥¨¥ó¥³¡¼¥É¤µ¤ì¤¿Ê¸»úÎ󤬽ÐÎϤµ¤ì¤ë*6¤Î¤Ç¡¤¤³¤ì¤ò¤É¤³¤«¤ØÊݸ¤·¤Æ¤ª¤³¤¦*7.

¤¢¤È¤Ï¤¤¤Ä¤â¤Î¤è¤¦¤Ë telnet localhost 25 ¤Ç¼«Á°¤Î MTA ¤ËÀܳ¤·¤Æ¤ß¤ë.
¤¤¤Ä¤â¤Î¤è¤¦¤Ë "EHLO localhost" ¤È¤·¤Æ±þÅú¤ò¿Ê¤á¤ë¤È¡¤¼¡¤Î¤è¤¦¤Ë SMTP AUTH ¤¬¤Ç¤­¤ë¤è¤È¤¤¤¦É½¼¨¹þ¤ß¤Ç±þÅú¤¬¿Ê¤à¤Ï¤º¤À*8.

 250-(¥Û¥¹¥È̾)
 250-PIPELINING
 250-SIZE 10240000
 250-VRFY
 250-ETRN
 250-AUTH NTLM LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5
 250-AUTH=NTLM LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5
 250-ENHANCEDSTATUSCODES
 250-8BITMIME
 250 DSN

¤³¤ÎÃʳ¬¤Ç SMTP Auth ¤Î Plain ǧ¾Ú¤ò»î¤·¤Æ¤ß¤è¤¦.
¶ñÂÎŪ¤Ë¤Ï¡¤¤³¤³¤Ç

 AUTH PLAIN Àè¤Û¤Ébase64¥¨¥ó¥³¡¼¥É¤·¤Æºî¤Ã¤¿Ê¸»úÎó

¤ÈÆþÎϤ¹¤ì¤Ð¤è¤¤. Plain ǧ¾Ú¤Ï¤³¤ì¤À¤±¤ÇºÑ¤à.
¤½¤·¤Æ

 235 2.0.0 Authentication successful

¤Ê¤É¤È "success" ¤Î°Õ¤¬¥á¥Ã¥»¡¼¥¸¤ÇÊ֤äƤ¯¤ì¤Ð¡¤Ç§¾Ú¤¬Ä̤俤Ȥ¤¤¦¤³¤È¤Ç OK ¤Ç¤¢¤ë.
¤¦¤Þ¤¯¤¤¤«¤Ê¤¤¿Í¤ÏÃúÇ«¤Ë¤³¤ì¤Þ¤Ç¤Îºî¶È¤ò¿¶¤êÊÖ¤í¤¦.

¼Â½¬

¤³¤³¤Þ¤Ç½ñ¤¤¤Æ¤¢¤ë¤³¤È¤ò¼Â¹Ô¤·¤è¤¦.

¼ê¤Ç SMTP Auth ¤ò»î¤¹ : CRAM-MD5 ǧ¾Ú¤Î¾ì¹ç

CRAM-MD5ǧ¾Ú¤ÏÀè¤Î Plainǧ¾Ú¤È°ã¤Ã¤Æ¡¤¥Ñ¥¹¥ï¡¼¥É¤òʿʸ¤ÇÁ÷¤é¤Ê¤¤·Á¼°¤Ç¤¢¤ë. plain ǧ¾Ú¤È°Û¤Ê¤ê¡¤¥Í¥Ã¥È¥ï¡¼¥¯¤òÅðÄ°¤µ¤ì¤Æ¤â¤Þ¤¢°ÂÁ´¤È¤¤¤¨¤è¤¦.
¶ñÂÎŪ¤Ë¤Ï¡¤Àܳ¤¹¤ë¤È¥µ¡¼¥Ð¤¬Å¬Åö¤Êʸ»úÎó¤òÁ÷¤Ã¤Æ¤¯¤ë¤Î¤Ç¡¤¤³¤ì¤ò¥Ñ¥¹¥ï¡¼¥É¤ò¥­¡¼¤Ë¤·¤Æ hmac-md5 ¤Ç¥Ï¥Ã¥·¥å¤òµá¤á(¤³¤ì¤¬¥Ñ¥¹¥ï¡¼¥É¤ò°µ½Ì, °Å¹æ²½¤·¤¿¤³¤È¤ËÁêÅö¤¹¤ë), ¥æ¡¼¥¶Ì¾¤È¤¢¤ï¤»¤Æ base64 ¥¨¥ó¥³¡¼¥É¤·¤ÆÁ÷¤êÊÖ¤·¡¤¥µ¡¼¥Ð¤ÇƱÍͤ˺î¤Ã¤¿¥Ï¥Ã¥·¥å¤ÈƱ¤¸¤Ê¤éǧ¾Ú OK ¤È¤¤¤¦´¶¤¸¤Ë¤Ê¤ë.

¤ä¤ä¤³¤·¤¤¤¬¡¤¼Â¤Ï CRAM-MD5 ¤ò¥Æ¥¹¥È¤¹¤ë¤¿¤á¤Î¥¹¥¯¥ê¥×¥È "userdb-test-cram-md5" ¤¬(¸å¤Î imap ¥¤¥ó¥¹¥È¡¼¥ë¤ÎºÝ¤Ë)¥¤¥ó¥¹¥È¡¼¥ë¤µ¤ì¤ë¤Î¤Ç¡¤¤½¤ì¤òÍѤ¤¤ì¤Ð¤è¤¤.
¤è¤Ã¤Æ¡¤¤³¤³¤Îºî¶È¤Ï¸å½Ò¤Î courier-imap ¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿¸å¤Ë¹Ô¤Ê¤¦¤³¤È.
¤¿¤À¤·¡¤courier-imap ¤ÎÀßÄê¤Ï¤·¤Ê¤¤¤ÇÌá¤Ã¤Æ¤­¤Æ¤è¤¤.

°Ê²¼¤Îºî¶È¤Ë¤Ï¥³¥ó¥½¡¼¥ë¤¬Æó¤Ä°Ê¾å¤¢¤Ã¤¿Êý¤¬ÊØÍø¤Ê¤Î¤Ç¡¤X ¤ÇŬÅö¤Êʸ»úüËö¥¨¥ß¥å¥ì¡¼¥¿¤òÆó¤Äµ¯Æ°¤·¤Æ¤«¤é¹Ô¤ª¤¦.
¾õ¶·¤òʬ¤«¤ê¤ä¤¹¤¯¤¹¤ë¤¿¤á¤Ë¡¤¤³¤ì¤«¤é³Æ¡¹¤Î¥¨¥ß¥å¥ì¡¼¥¿¤ÇÆ°¤¯Æó¤Ä¤Î¥·¥§¥ë¤ò³Æ¡¹ Shell-A, Shell-B ¤È¤·¤Æ½ñ¤¤¤Æ¤ª¤³¤¦.

¤Þ¤º¡¤Shell-A ¤Ç telnet localhost 25 ¤ÇÀè¤ÈƱ¤¸¤è¤¦¤Ë

 250-AUTH NTLM LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5
 250-AUTH=NTLM LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5
 250-ENHANCEDSTATUSCODES
 250-8BITMIME
 250 DSN

¤È¤¤¤¦¤È¤³¤í¤Þ¤Ç¤¤¤³¤¦. ¤½¤·¤Æ¤³¤³¤Ç

 auth cram-md5

¤ÈÆþÎϤ¹¤ë. ¤¹¤ë¤È¡¤

 334 PG5hbmlrYW5vLXNlcnZlcj4=

¤Ê¤É¤È½ÐÎϤ¬Ê֤äƤ¯¤ë.
¤³¤Î PG5hbmlrYW5vLXNlcnZlcj4= ¤¬¥µ¡¼¥Ð¤¬ base64 ¤ÇÁ÷¤Ã¤Æ¤­¤¿Ê¸»úÎó*9¤Ç¤¢¤ë¤Î¤Ç¡¤¤³¤ì¤ò¥æ¡¼¥¶¤Î¥Ñ¥¹¥ï¡¼¥É¤ò¥­¡¼¤Ë¤·¤Æ hmac-md5 ¤Ç¥Ï¥Ã¥·¥å¤ò·×»»¤·¤Æ¥æ¡¼¥¶Ì¾¤È¤¢¤ï¤»¤Æ base64 ¤ÇÁ÷¤êÊÖ¤»¤Ð¤è¤¤. ¤³¤Îʸ»úÎó¤ÎÀ¸À®¤ÏÌÌÅݤˤߤ¨¤ë¤¬¡¤¤Ê¤ó¤Î¤³¤È¤Ï¤Ê¤¯¤ÆÀè¤Î¥³¥Þ¥ó¥É¤ò»È¤¨¤Ð¤è¤¤.

¶ñÂÎŪ¤Ë¤Ï Shell-B ¤Ç userdb-test-cram-md5 ¤ò¼Â¹Ô¤·¤Æ¡¤°Ê²¼¤Î¤è¤¦¤ËÂбþ¤¹¤ì¤Ð¤è¤¤.

 Username? testuser ¢« (SMTP Auth ¤Ë»È¤¦)¥æ¡¼¥¶Ì¾¤òÆþÎϤ¹¤ë
 Password?  password ¢« (SMTP Auth ¤Ë»È¤¦)¥Ñ¥¹¥ï¡¼¥É¤òÆþÎϤ¹¤ë
 Send: AUTH CRAM-MD5 (or for imap, A AUTHENTICATE CRAM-MD5)
 Paste the challenge here:
 + PG5hbmlrYW5vLXNlcnZlcj4= ¢« Shell-A ¤Ç¥µ¡¼¥Ð¤¬Á÷¤Ã¤Æ¤­¤¿Ê¸»úÎó¤òÆþÎϤ¹¤ë.
 Send this response:
 dGVzdHVzZXIgY2NiNjc4YmZjZGY1YWRlMGUyYmE2MmM3ODA3OTA1NGI=

¤¹¤ë¤È¡¤¾å¤Î¤è¤¦¤ËºÇ¸å¤ËÊÖÅú¤¹¤Ù¤­Ê¸»úÎó¤òÀ¸À®¤·¤Æ¤¯¤ì¤ë.

¤½¤³¤Ç¤³¤Îʸ»úÎó(¤³¤ÎÎã¤Î¾ì¹ç¤Ï dGVzdHVzZXIgY2NiNjc4YmZjZGY1YWRlMGUyYmE2MmM3ODA3OTA1NGI=)
¤ò¤µ¤Ã¤­¤Î Shell-A ¤Ç¤Îºî¶È¤Î³¤­¤Ë ÆþÎϤ¹¤ë.
ǧ¾Ú¤¬Ä̤ì¤Ð¤³¤Î¤¢¤È

 235 2.0.0 Authentication successful

¤Ê¤É¤È¤¦¤Þ¤¯¤¤¤¯¤À¤í¤¦.

SMTP over TLS ¤ÎÀßÄê¤ÈÆ°ºî³Îǧ

SMTP over TLS ¤ÎÀßÄê

TLS ¤ÎÍøÍѤˤĤ¤¤Æ¤Ï¡¤ÀßÄê¤Î¤Þ¤¨¤Ë¸°¤È¾ÚÌÀ½ñ¤òÍÑ°Õ¤·¤Ê¤¤¤È¤¤¤±¤Ê¤¤.
web server ¤ÎÀßÄê¤Î»þ¤Ëºî¤Ã¤¿¸°¤È¾ÚÌÀ½ñ¤ò /etc/ssl ¤Ë(ÈÆÍÑŪ¤Ê̾Á°¤Ëľ¤·¤Æ)°ÜÆ°¤µ¤»¤Æ»È¤¦¤â¤è¤·*10¡¤¿·¤·¤¯ºî¤Ã¤Æ¤â¤è¤¤¤À¤í¤¦.

º£²ó¤Ï¸°¤È¾ÚÌÀ½ñ¤ò¿·¤·¤¯ºî¤Ã¤Æ*11 /usr/local/etc/postfix ¤ËÃÖ¤¯¤³¤È¤Ë¤·¤è¤¦. ¤½¤·¤Æ¥Õ¥¡¥¤¥ë̾¤òÎ㤨¤Ð(¸°) postfix.key, (¾ÚÌÀ½ñ) postfix.crt ¤È¤·¤Æ¤ª¤¯.

¤¿¤À¤·¡¤¤³¤Î¥Õ¥¡¥¤¥ë¤¬Â¾¤Î¿Í¤ËÆɤá¤Æ¤·¤Þ¤¦¤Èº¤¤ë¤Î¤Ç¡¤ºî¤Ã¤¿¸å¤¹¤°¤Ë

 chmod 400 postfix.key
 chmod 400 postfix.crt

¤È¤·¤Æ¤ª¤³¤¦.

¤µ¤Æ¡¤Postfix ¤ÎÀßÄê¤Ï¡¤ËܲȤΥɥ­¥å¥á¥ó¥È(http://www.postfix.org/TLS_README.html)¤òÆɤó¤Ç¼«Ê¬¤Ê¤ê¤Ë¼è¼ÎÁªÂò¤¹¤ë¤³¤È¤Ë¤Ê¤ë.
¥µ¡¼¥Ð¤«¥¯¥é¥¤¥¢¥ó¥È¤«¤äǧ¾Ú¤ò¤É¤¦¤¹¤ë¤«¤Ê¤É¿¾¯¤ä¤ä¤³¤·¤¯¤Æ¤è¤¯¤ï¤«¤é¤Ê¤¤¤«¤È»×¤¦¤Î¤Ç¡¤º£²ó¤ÏÀßÄê¤ò½ñ¤¤¤Æ¤·¤Þ¤ª¤¦.
¤È¤ê¤¢¤¨¤º /usr/local/etc/postfix/main.cf ¤Ë

 smtpd_tls_cert_file = /usr/local/etc/postfix/postfix.crt
 smtpd_tls_key_file = /usr/local/etc/postfix/postfix.key
 smtpd_tls_received_header = yes
 smtpd_tls_security_level = may
 
 smtp_tls_security_level = may
 smtp_tls_note_starttls = yes

¤Ê¤É¤È²Ã¤¨¤ì¤ÐÎɤ¤*12. ¤¿¤À¤·¡¤¤³¤ì¤Ï·ÐÏ©¤Î°Å¹æ²½¤À¤±¤Ç¤è¤¤¡¤¤È¤¤¤¦ÀßÄê¤Ê¤Î¤Ç¡¤Ç§¾Ú¤Þ¤Ç¤­¤Á¤ó¤È¤·¤¿¤¤¿Í¤Ï¥É¥­¥å¥á¥ó¥È¤ò¤­¤Á¤ó¤ÈÆɤ⤦.

¤³¤ÎÊÔ½¸¤¬½ª¤ï¤Ã¤¿¤é¡¤postfix ¤ò°ìöÄä»ß¤·¤Æ¤«¤éºÆµ¯Æ°¤¹¤ë.

 /usr/local/etc/rc.d/postfix stop
 /usr/local/etc/rc.d/postfix start

ºÆµ¯Æ°»þ¤Ë²¿¤«¥¨¥é¡¼¤ä·Ù¹ð¤¬½Ð¤Æ¤¤¤Ê¤¤¤«Ãí°Õ¤·¤Æ¤ª¤³¤¦.

SMTP over TLS ¤ÎÆ°ºî³Îǧ

¤¦¤Þ¤¯¤¤¤Ã¤Æ¤¤¤ë¤è¤¦¤À¤Ã¤¿¤éºÆ¤Ó telnet localhost 25 ¤Ç³Îǧ¤·¤Æ¤ß¤ë.
¤³¤ì¤Þ¤Ç¤ÈƱÍͤË(ÅÓÃæ¤Ç EHLO localhost ¤·¤Æ)

 250-(¥Û¥¹¥È̾)
 250-PIPELINING
 250-SIZE 10240000
 250-VRFY
 250-ETRN
 250-STARTTLS
 250-AUTH NTLM LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5
 250-AUTH=NTLM LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5
 250-ENHANCEDSTATUSCODES
 250-8BITMIME
 250 DSN

¤Ê¤É¤È¤Ê¤ë(¤³¤³¤Ç quit ¤ÈÆþÎϤ¹¤ë¤ÈÈ´¤±¤é¤ì¤ë).
Îɤ¯¤ß¤ë¤È "250-STARTTLS" ¤È¤¤¤¦Éôʬ¤¬¤¢¤ê¡¤¤È¤ê¤¢¤¨¤º TLS Âбþ¤ÎÆ°ºî¤ò¤·¤Æ¤¤¤ë¤³¤È¤¬¤ï¤«¤ë.
¤³¤ì¤¬½Ð¤Ê¤¤¤è¤¦¤Ê¤é²¿¤«¤ª¤«¤·¤¤¤Î¤Ç¤³¤ì¤Þ¤Ç¤Îºî¶È¤ò¿¶¤êÊÖ¤í¤¦.

¤µ¤Æ¡¤TLS ¤ÎÆ°ºî¤Î³Îǧ¤À¤¬¡¤¤³¤³¤Ç SMTP ¤ÎÆ°ºî¥Á¥§¥Ã¥¯¤ËÊØÍø¤Ê¥Ä¡¼¥ë¤òƳÆþ¤·¤è¤¦.
¤½¤ì¤Ï swaks (Swiss Army Knife SMTP) ¤È¤è¤Ð¤ì¤ë¤â¤Î¤Ç¤¢¤ê¡¤¤³¤ì¤Þ¤Ç¤Î telnet localhost 25 ¤È¤¤¤¦°ìÏ¢¤Îºî¶È¤ò¼«Æ°Åª¤Ë¤ä¤Ã¤Æ¤¯¤ì¤ëÊØÍø¤Ê¤â¤Î¤Ç¤¢¤ë.

¤È¤¤¤¦¤ï¤±¤Ç¤Þ¤º¤Ï ports¥³¥ì¥¯¥·¥ç¥ó¤ò portsnap ¤Ç¿·¤·¤¯¤·¤Æ¤«¤é swaks ¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤è¤¦.

 portinstall swaks

¤È¤¹¤ì¤Ð¤è¤¤. ¥¤¥ó¥¹¥È¡¼¥ë»þ¤Ë¥ª¥×¥·¥ç¥óÁªÂò²èÌÌ
swaks-install_s.png
¤¬½Ð¤¿¤é¡¤¾¯¤Ê¤¯¤È¤â "MX lookup support" ¤È "TLS support" ¤È¤ò ON ¤Ë¤·¤Æ¤ª¤¤¤Æ¤«¤é¥¤¥ó¥¹¥È¡¼¥ë¤·¤è¤¦(NTLM ¤Ï¤³¤Î¼ø¶È¤Ç¤Ï´Ø·¸¤Ê¤¤). ¤¢¤È¤Ï¥¹¥à¡¼¥º¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤Ç¤­¤ë¤Ï¤º. ¥¤¥ó¥¹¥È¡¼¥ë¤¬½ª¤ï¤Ã¤¿¤éÇ°¤Î°Ù¤Ë rehash ¤·¤Æ¤ª¤³¤¦.

¤µ¤Æ, swaks ¤Î»È¤¤Êý¤Ï swaks --help ¤È¤¹¤ë¤È¥Þ¥Ë¥å¥¢¥ë¤¬Æɤá¤ë¤Î¤Ç¤½¤ì¤ò¤ß¤Æ¤â¤é¤¦¤È¤·¤Æ¡¤¤Þ¤º¤Ï¤ª¤µ¤é¤¤¤â·ó¤Í¤Æ¤³¤ì¤Þ¤Ç¤Î¥Æ¥¹¥È¤òºÆ¸½¤·¤Æ¤ß¤è¤¦.

¤Þ¤º¤Ïñ¤Ë MTA ¤¬Æ°ºî¤·¤Æ¤¤¤ë¤«¤Î³Îǧ¤«¤é.

 swaks --server localhost

¤È¤¹¤ë¤È¡¤¥Æ¥¹¥È¥á¡¼¥ë¤Î°¸Àè¤òʹ¤¤¤Æ¤¯¤ë¤Î¤Ç, ¼«Ê¬¤Î¥¢¥«¥¦¥ó¥È̾¤òÅú¤¨¤è¤¦. ¤¹¤ë¤È

 === Trying localhost:25...
 === Connected to localhost.
 <-  220 ¥µ¡¼¥Ð̾ ESMTP Postfix
  -> EHLO ¥µ¡¼¥Ð̾
 <-  250-¥µ¡¼¥Ð̾
 <-  250-PIPELINING
 <-  250-SIZE 10240000
 <-  250-VRFY
 <-  250-ETRN
 <-  250-STARTTLS
 <-  250-AUTH NTLM LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5
 <-  250-AUTH=NTLM LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5
 <-  250-ENHANCEDSTATUSCODES
 <-  250-8BITMIME
 <-  250 DSN
  -> MAIL FROM:<º¹½Ð¿Í¥¢¥É¥ì¥¹>
 <-  250 2.1.0 Ok
  -> RCPT TO:<°¸Àè>
 <-  250 2.1.5 Ok
  -> DATA
 <-  354 End data with <CR><LF>.<CR><LF>
  -> Date: ÆüÉÕ
  -> To: °¸Àè
  -> From: º¹½Ð¿Í
  -> Subject: test ÆüÉÕ
  -> X-Mailer: swaks v20061116.0 jetmore.org/john/code/#swaks
  ->
  -> This is a test mailing
  ->
  -> .
 <-  250 2.0.0 Ok: queued as D6E7C11430
  -> QUIT
 <-  221 2.0.0 Bye

¤È MTA ¤È¤ä¤ê¼è¤ê¤·¤Æ¡¤¤½¤ÎÅÓÃæ·Ð²á¤ò¤­¤Á¤ó¤È½ÐÎϤ·¤Æ¤¯¤ì¤ë. ¤¤¤Þ¤Ï¥Æ¥¹¥È¥á¡¼¥ë¤ò¼ÂºÝ¤ËÁ÷¤Ã¤¿¤Ï¤º¤Ê¤Î¤Ç¡¤¥¢¥«¥¦¥ó¥È¤Î¥Û¡¼¥à¥Ç¥£¥ì¥¯¥È¥ê¤Î Maildir/new ¤Ë¥á¡¼¥ë¤¬ÆϤ¤¤Æ¤¤¤ë¤Ï¤º¤Ç¤¢¤ë. ³Îǧ¤·¤Æ¤ß¤è¤¦.

¼¡¤Ë¡¤SMTP Auth ¤Î plainǧ¾Ú¤ò»î¤·¤Æ¤ß¤è¤¦. ¤¿¤À¤·¡¤¤¤¤Á¤¤¤Á¥á¡¼¥ë¤¬ÆϤ¯É¬Íפâ¤â¤¦¤Ê¤¤¤Î¤Ç¡¤Æ°ºî³Îǧ¤Î¤ß¤Ç¥á¡¼¥ë¤ÏÁ÷¤é¤Ê¤¤¤è¤¦¤Ë¤·¤è¤¦. ¤½¤ì¤Ë¤Ï¼¡¤Î¤è¤¦¤Ë¤¹¤ì¤Ð¤è¤¤.

 swaks --auth PLAIN --server localhost --quit RCPT

¤¹¤ë¤ÈºÇ½é¤Ë(¼ÂºÝ¤Ë¤ÏÁ÷¤é¤Ê¤¤¤¬)¥Æ¥¹¥È¥á¡¼¥ë¤Î°¸Àè¤òʹ¤¤¤Æ¤­¤Æ¡¤¤½¤Î¸å¤Ë SMTP Auth ¤Îǧ¾Ú¤ËɬÍפʥ桼¥¶Ì¾¤È¥Ñ¥¹¥ï¡¼¥É¤òʹ¤¤¤Æ¤¯¤ë¤Î¤ÇÅú¤¨¤è¤¦. ¤½¤Î¸å¡¤½ÐÎϤò¤è¤¯¸«¤Æ¡¤³Î¤«¤Ë SMTP Auth ¤Î Plainǧ¾Ú¤¬¤¦¤Þ¤¯¤¤¤Ã¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤è¤¦.

¼¡¤Ë SMTP Auth ¤Î CRAM-MD5 ǧ¾Ú¤ò»î¤·¤Æ¤ß¤ë. ¤½¤ì¤Ë¤Ï

 swaks --auth CRAM-MD5 --server localhost --quit RCPT

¤È¤¹¤ì¤Ð¤è¤¤. ¸å¤Ï¤µ¤Ã¤­¤Î¤ÈƱ¤¸¤Ç¤¢¤ë.

¤µ¤Æ¡¤¤ä¤Ã¤È´Î¿´¤Î SMTP over TLS ¤ò¥Æ¥¹¥È¤·¤è¤¦. ¤È¤¤¤Ã¤Æ¤â¤³¤³¤Þ¤Ç¤¯¤ì¤Ð¥Æ¥¹¥È¤Ï¤â¤¦´Êñ¤Ç¡¤

 swaks -tls --server localhost

¤È¤¹¤ì¤Ð¤è¤¤. ¤¿¤À¤·¡¤Ç°¤Î°Ù¤Ë¥Æ¥¹¥È¥á¡¼¥ë¤ò¼ÂºÝ¤ËÁ÷¤í¤¦¤È¤·¤Æ¤¤¤ë.
¤³¤ì¤ò¼Â¹Ô¤·¤Æ¡¤swaks ¤Î½ÐÎϤòÆɤó¤ÇÌäÂ꤬¤Ê¤±¤ì¤Ð OK ¤À. ¤â¤Á¤í¤ó, Maildir/new ¤Ë¼ÂºÝ¤Ë¥á¡¼¥ë¤¬ÆϤ¤¤Æ¤¤¤ë¤«¤â¥Á¥§¥Ã¥¯¤·¤Æ¤ª¤³¤¦.

ºÇ¸å¤Ë¡¤SMTP Auth ¤È SMTP over TLS ¤òÁȤ߹ç¤ï¤»¤Æ¤ß¤è¤¦. SMTP Auth ¤Îǧ¾Ú¤Ï¤Ê¤ó¤Ç¤â¤è¤¤. ¹¥¤­¤Ê¤â¤Î¤ò»È¤Ã¤Æ¤ä¤Ã¤Æ¤ß¤è¤¦.
¶ñÂÎŪ¤Ë¤ÏÎ㤨¤Ð¼¡¤Î¤è¤¦¤Ë¤¹¤ì¤Ð¤è¤¤(SMTP Auth ¤Ï¼«Æ°Åª¤ËÁª¤ó¤Ç¤â¤é¤¦ÀßÄê).

 swaks --auth -tls --server localhost --quit RCPT

¤³¤³¤Ç½ÐÎϤòÃúÇ«¤ËÆɤó¤Ç¤ß¤è¤¦. ¤½¤·¤Æ starttls ¤·¤Æ¤«¤é SMTP Auth¤·¤Æ¤¤¤ë ¤³¤È, ¤Ä¤Þ¤ê¡¤¡Ö°Å¹æ²½¤·¤Æ¤«¤é¥Ñ¥¹¥ï¡¼¥É¤ò¤ä¤ê¼è¤ê¤¹¤ë¡×½çÈ֤ˤʤäƤ¤¤ë¤³¤È¤ËÃí°Õ¤·¤ÆÍߤ·¤¤.
¤³¤ì¤Ï SMTP over TLS ¤ÈÁȤ߹ç¤ï¤»¤ë¤Ê¤é¤Ðǧ¾Ú(¥Ñ¥¹¥ï¡¼¥É¤Î¤ä¤ê¼è¤ê)¤Ïʿʸ¤Ç¤â°ÂÁ´¤Ê¤Ï¤º¡¤¤È¤¤¤¦¤³¤È¤Ç¤¢¤ë*13.

¼Â½¬

SMTP over TLS/SSL ¤Ë¤Ï¾åµ­¤Î StartTLS ¤Î¾¤Ë¤â¤¦¤Ò¤È¤Ä SMTPS ¤È¸Æ¤Ð¤ì¤ë¤â¤Î¤¬¤¢¤ê¡¤º£²ó¤âÀßÄ꼡Âè¤Ç¤Ï¤½¤ì¤òÆ°¤«¤¹¤³¤È¤¬¤Ç¤­¤ë.
¤Ç¤Ï¡¤SMTPS ¤È¤Ï²¿¤«¡¤StartTLS ¤ÈÈæ¤Ù¤Æ¤ÎÍøÅÀ/·çÅÀ¤Ï²¿¤«Ä´¤Ù¤è.
¤µ¤é¤Ë;ÎϤ¬¤¢¤ë¤è¤¦¤À¤Ã¤¿¤é²¿¤«¼ê¸µ¤Î MUA ¤Ç starttls ¤ËÂбþ¤¹¤ë¤è¤¦¤ËÀßÄꤷ¤ÆÆ°ºî³Îǧ¤·¤Æ¤ß¤è.

IMAP/POP ¥µ¡¼¥Ð¤Î¥¤¥ó¥¹¥È¡¼¥ë¡¤´ÉÍý

¤µ¤Æ¡¤¥æ¡¼¥¶°¸¤ËÆϤ¤¤¿¥á¡¼¥ë¤ò MUA ¤ËÅϤ¹¤Î¤Ë¹­¤¯»È¤ï¤ì¤Æ¤¤¤ë POP/IMAP ¤Î¥µ¡¼¥Ð¤Ë¤Ä¤¤¤Æ¤â¿¨¤ì¤è¤¦.
¤¤¤Þ¤À¹­¤¯»È¤ï¤ì¤Æ¤¤¤ë POP¡¤¥æ¡¼¥¶¤Ë¤È¤Ã¤Æ¤ÏÊØÍø¤À¤¬¥µ¡¼¥Ð¤Ø¤ÎÉéô¤¬¹â¤á¤Î¤¿¤á¤Ë¾¦¶È¥Ù¡¼¥¹¤Ç¤Ï¤Ê¤«¤Ê¤«ÍѤ¤¤é¤ì¤Ê¤¤ IMAP¡¤¤ÈÂç¤Þ¤«¤Ë¸À¤¨¤ë.
¤³¤³¤Ç¤Ï¡¤¾­ÍèŪ¤Ê¤³¤È¤â¹Í¤¨¤Æ IMAP ¥µ¡¼¥Ð¤Ë¤Ä¤¤¤Æ³Ø½¬¤·¤Æ¤ß¤è¤¦. ¤Á¤Ê¤ß¤Ë¡¤POP ¥µ¡¼¥Ð¤Ï IMAP ¥µ¡¼¥Ð¤ËÈæ¤Ù¤ì¤Ðñ½ã¤Ê¤Î¤Ç¡¤IMAP ¥µ¡¼¥Ð¤¬°·¤¨¤ì¤ÐPOP ¥µ¡¼¥Ð¤Ë¤Ä¤¤¤Æ¤Ïº¤¤é¤Ê¤¤¤À¤í¤¦.

¤µ¤Æ¡¤IMAP ¥µ¡¼¥Ð¤È¤·¤Æ¤Ï courier-imap ¤¬¹­¤¯»È¤ï¤ì¤Æ¤¤¤ë¤Î¤Ç¼ø¶È¤Ç¤â¤³¤ì¤òÍѤ¤¤è¤¦.
¤Ê¤ª¡¤courier-imap ¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤È°ì½ï¤Ë courier-pop ¤â¥¤¥ó¥¹¥È¡¼¥ë¤µ¤ì¤ë¤Î¤Ç¡¤POP ¥µ¡¼¥Ð¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿¤¤¡¤¤È¤¤¤¦¤È¤­¤Ë courier-imap ¤òÁªÂò¤·¤Æ¤â¤è¤¤.

courier-imap ¤Î¥¤¥ó¥¹¥È¡¼¥ë

¤µ¤Æ¡¤¤¤¤Ä¤â¤Î¤è¤¦¤Ë ports ¥³¥ì¥¯¥·¥ç¥ó¤«¤é¥¤¥ó¥¹¥È¡¼¥ë¤·¤è¤¦.
¤¿¤À¤·¡¤imap ¥µ¡¼¥Ð¤Î¥¤¥ó¥¹¥È¡¼¥ë¤ÎÁ°¤Ë courier-authlib(courier-imap ¤Îǧ¾Ú´Ø·¸¤À¤±È´¤­½Ð¤·¤¿meta ports) ¤Î¥¤¥ó¥¹¥È¡¼¥ë¤ò¹Ô¤Ã¤Æ¤ª¤¯*14.
¤¤¤Ä¤â¤Î¤è¤¦¤Ë

 portinstall courier-authlib

¤È¤¹¤ë. ºÇ½é¤Ë½Ð¤ë¥ª¥×¥·¥ç¥ó²èÌ̤ǤÏ
courierauth-install.png
¤Î¤è¤¦¤Ë¾¯¤Ê¤¯¤È¤â userdb ¤òÁª¤ó¤Ç¤ª¤¯. ¤¢¤È¤Ï¥¹¥à¡¼¥º¤Ë¿Ê¤à¤À¤í¤¦.

¼¡¤Ë

 portinstall courier-imap

¤È¤·¤Æ courier-imap ËÜÂΤò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë. ºÇ½é¤Ë¥ª¥×¥·¥ç¥óÁªÂò²èÌÌ
courierimap-install.png
¤¬½Ð¤ë¤¬¡¤Â¿Ê¬¥Ç¥Õ¥©¥ë¥È¤Ç OpenSSL ¤È IPv6 ¤¬Áª¤Ð¤ì¤Æ¤¤¤ë¤À¤í¤¦. ÆäËÌäÂê¤Ê¤¤¤Î¤Ç¡¤¤½¤Î¤Þ¤Þ OK ¤Ç¤è¤¤.

¤·¤Ð¤é¤¯ÂԤäƤ¤¤ë¤È(¤¤¤¯¤Ä¤«Â¾¤ËɬÍפʥ½¥Õ¥È¥¦¥§¥¢¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Æ¤«¤é)¥¤¥ó¥¹¥È¡¼¥ë¤¬½ª¤ï¤ë.
¤½¤ÎÅÓÃæ¤Ç¤ä¤Ï¤ê¤¤¤¯¤Ä¤«¥á¥Ã¥»¡¼¥¸¤¬½Ð¤ë¤¬¡¤º£²ó¤Ï¾¯¤Ê¤á¤Ç¡¤¼Â¼ÁŪ¤Ë¤Ï¼¡¤Î¤â¤Î¤À¤±¤Ç¤¢¤ë.

 In case you use authpam, you should put the following lines
 in your /etc/pam.d/imap
 auth    required    pam_unix.so         try_first_pass
 account required    pam_unix.so         try_first_pass
 session required    pam_permit.so
 
 You will have to run /usr/local/share/courier-imap/mkimapdcert to create
 a self-signed certificate if you want to use imapd-ssl.
 And you will have to copy and edit the *.dist files to *
 in /usr/local/etc/courier-imap.

¤³¤ì¤Ï¡¤IMAP ¤Îǧ¾ÚÊýË¡¤È¤·¤Æ¾¤ÎÊýË¡¤Ç¤¢¤ë PAM ¤ò»È¤¤¤¿¤±¤ì¤Ð¤³¤¦¤·¤í¡¤¤È¤¤¤¦¤³¤È¤È¡¤IMAP over TLS/SSL ¤ò»È¤¦ºÝ¤Î¼«¸Êǧ¾Ú¾ÚÌÀ½ñ¤Îºî¤êÊý¤¬½ñ¤¤¤Æ¤¢¤ë.
¤¤¤º¤ì¤â·ë¹½½ÅÍפʥá¥Ã¥»¡¼¥¸¤Ê¤Î¤Ç¡¤ÆɤßÈô¤Ð¤µ¤Ê¤¤¤è¤¦¤Ë¤·¤è¤¦.

courier-imap ¤ÎÀßÄê

¤µ¤Æ¡¤¥¤¥ó¥¹¥È¡¼¥ë¤¬ºÑ¤à¤È /usr/local/etc/authlib ¤Ëǧ¾Ú´Ø·¸¤ÎÀßÄ꤬¡¤/usr/local/etc/courier-imap ¤Ë imap/pop ´Ø·¸¤ÎÀßÄê¥Õ¥¡¥¤¥ëÅù¤¬ÃÖ¤«¤ì¤ë.

¤Þ¤ºÇ§¾Ú´Ø·¸¤òÀ°Íý¤·¤è¤¦.
ǧ¾Úµ¡¹½¤½¤Î¤â¤Î¤ÎÀßÄê¤Ë¤Ä¤¤¤Æ¤Ï /usr/local/etc/authlib ¤ËÀßÄê¥Õ¥¡¥¤¥ë¤òÍÑ°Õ¤·¤Æ±¾¡¹¡Ä¤È¤Ê¤ë¤Î¤À¤¬¡¤º£²ó¤Ï userdb ¤·¤«Áª¤ó¤Ç¤¤¤Ê¤¤¤Î¤ÇÀßÄê¤ÏÉÔÍפʾõÂ֤Ǥ¢¤ë. ¤Ê¤Î¤Ç¤³¤Î¥Ç¥£¥ì¥¯¥È¥ê¤Ç¤ä¤ë¤³¤È¤Ï¤Ê¤¤.

¼¡¤Ë¡¤over TLS/SSL ¤Ç»È¤¦¼«¸Êǧ¾Ú¾ÚÌÀ½ñ(courier-imap ¤Ï¤³¤ì¤òÍפ¹¤ë)¤òºî¤ë.
Àè¤Ëºî¤Ã¤¿¸°¤È¾ÚÌÀ½ñ¤È¤Ï°ã¤¦µ¡Ç½¤Î¤â¤Î¤Ê¤Î¤Ç¡¤¿·¤¿¤Ëºî¤é¤Ê¤¤¤È¤¤¤±¤Ê¤¤.

ÊýË¡¤Ï´Êñ¤Ç¡¤/usr/local/etc/courier-imap ¤Ë¥µ¥ó¥×¥ë¤È¤·¤Æ¤ª¤¤¤Æ¤¢¤ë imapd.cnf.dist ¤È pop3d.cnf.dist ¤ò¥³¥Ô¡¼¤·¤Æ imapd.cnf ¤È pop3d.cnf ¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤òºî¤ê¡¤Ãæ¤ò¤ß¤ÆŬÅö¤ËÊÔ½¸.
¤½¤ì¤«¤é¡¤

 cd /usr/local/share/courier-imap/
 mkimapdcert
 mkpop3dcert

¤È¤¹¤ë¤È¡¤/usr/local/share/courier-imap/ ¤Ë imapd.pem, pop3d.pem ¤È¤¤¤¦¼«¸Êǧ¾Ú¾ÚÌÀ½ñ¤¬¤Ç¤­¤ë.
¥Õ¥¡¥¤¥ë̾¤â¾ì½ê¤âÆäËÊѹ¹¤òÍפ·¤Ê¤¤¤Î¤Ç¡¤¤³¤ì¤Ç¾ÚÌÀ½ñ¤ÎºîÀ®¤Ï¤ª¤ï¤ê.

¼¡¤Ë¡¤IMAP ËÜÂΤÎÀßÄê¤ò¹Ô¤ª¤¦. /usr/local/etc/courier-imap ¤Ç¡¤imapd ¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤¹¤ë*15.
¶ñÂÎŪ¤Ë¤Ï¡¤

IMAP_CAPABILITY="IMAP4rev1 UIDPLUS CHILDREN NAMESPACE THREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT QUOTA AUTH=CRAM-MD5 AUTH=CRAM-SHA1 AUTH=CRAM-SHA256 IDLE"

IMAP_CAPABILITY_TLS="$IMAP_CAPABILITY AUTH=PLAIN AUTH=LOGIN"

¤ÎÆ󥫽ê¤ò½¤Àµ(²èÌ̤ÎÅÔ¹ç¤ÇÀÞ¤êÊÖ¤·¤Æ¤¤¤ë¤¬¡¤³Æ¡¹ 1¹Ô¤º¤Ä¤Ê¤Î¤ÇÃí°Õ)¤¹¤ì¤Ð¤è¤¤.
³Æ¡¹¡¤¥Ç¥Õ¥©¥ë¥ÈÃͤ«¤éÊѤï¤Ã¤¿Éôʬ¤ò¸«¤ì¤Ð²¿¤ò¤·¤¿¤«¤Ï¤ï¤«¤ë¤À¤í¤¦. ¤Á¤Ê¤ß¤ËÆó¤ÄÌܤκǸå¤Î AUTH=LOGIN ¤Ï(ŬÅö¤À¤¬) MS Âкö¤Ç¤¢¤ë.

¤¢¤È¡¤POP ¥µ¡¼¥Ð¤â»È¤¤¤¿¤¤¤Ê¤é¤Ð¡¤¤È¤ê¤¢¤¨¤ºÆ±ÍÍ¤Ë pop3d ¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤ÎÃæ¤Î2²Õ½ê¤ò

 POP3AUTH="CRAM-MD5 CRAM-SHA1"
 POP3AUTH_TLS="LOGIN PLAIN"

¤È½¤Àµ¤·¤Æ¤ª¤±¤Ð¤è¤¤.

¤µ¤Æ¡¤¤¢¤È¤Ï IMAP ¥µ¡¼¥Ð¤Îµ¯Æ°½àÈ÷¤Ç¤¢¤ë¤¬¡¤¤³¤ì¤Ï¥Ò¥ó¥È¤¬¾¯¤Ê¤¤.
¤·¤«¤¿¤Ê¤¤¤Î¤Ç¡¤courier-imap ¥¤¥ó¥¹¥È¡¼¥ë»þ¤Î¥á¥Ã¥»¡¼¥¸¤òºÆ¤ÓÆɤà¤È¡¤ºÇ¸å¤ÎÊý¤Ë

     This port has installed the following startup scripts which may cause
     these network services to be started at boot time.
 /usr/local/etc/rc.d/courier-imap-pop3d-ssl.sh
 /usr/local/etc/rc.d/courier-imap-imapd-ssl.sh
 /usr/local/etc/rc.d/courier-imap-imapd.sh
 /usr/local/etc/rc.d/courier-imap-pop3d.sh  

¤È¤¢¤ë¤Î¤Ç¡¤¼ÂºÝ¤Ï¤³¤ì¤é¤Î¥¹¥¯¥ê¥×¥È¤¬µ¯Æ°Áàºî¤ò¹Ô¤¦¤Î¤À¤È¤¤¤¦¤³¤È¤Ï¤ï¤«¤ë.
¤½¤·¤ÆÇ°¤Î°Ù¤Ë /usr/local/etc/rc.d ¥Ç¥£¥ì¥¯¥È¥ê¤òÇÁ¤¤¤Æ¤ß¤ë¤È¡¤¤³¤ì¤é¤Ï³Î¤«¤Ë¤¢¤ê¡¤¤«¤Ä¡¤Â¾¤Ë courier-authdaemond ¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤â¤¢¤ê, ¤³¤ì¤âƱÍͤÎÌò³ä¤òô¤¦¤³¤È¤¬¿ä¬¤Ç¤­¤ë.

¤½¤³¤Ç¤³¤ì¤é¤Î¥Õ¥¡¥¤¥ë¤Î¤¦¤Á¡¤IMAP ¥µ¡¼¥Ð¤Îµ¯Æ°¤Ë´ØÏ¢¤·¤½¤¦¤Ê¥¹¥¯¥ê¥×¥È "courier-authdaemond", "courier-imap-imapd.sh", "courier-imap-imapd-ssl.sh" ¤Î3¤Ä¤òľ¤ËÆɤó¤Ç¤ß¤è¤¦.
¤¹¤ë¤È¡¤Î㤨¤Ð courier-imap-imapd.sh ¤Ë¤Ï

 # Define these courier_imap_imapd_* variables in one of these files:
 #       /etc/rc.conf
 #       /etc/rc.conf.local
 #       /etc/rc.conf.d/courier_imap_imapd
 #
 # DO NOT CHANGE THESE DEFAULT VALUES HERE
 
 courier_imap_imapd_enable=${courier_imap_imapd_enable-"NO"}

¤È½ñ¤¤¤Æ¤¢¤ê¡¤¤É¤¦¤ä¤é /etc/rc.conf ¤Ë courier_imap_imapd_enable ¤ÎÆâÍƤòµ­½Ò¤¹¤ì¤ÐÎɤµ¤½¤¦¤À¤È¤¤¤¦¤³¤È¤¬¿ä¬¤Ç¤­¤ë.
ƱÍͤ˾£²¤Ä¤Î¥¹¥¯¥ê¥×¥È¥Õ¥¡¥¤¥ë¤Ë¤âµ­½Ò¤¬¤¢¤ê¡¤¤³¤ì¤é¤òÁí¹ç¤¹¤ë¤È /etc/rc.conf ¤Ë

 # for IMAP
 courier_authdaemond_enable="YES"
 courier_imap_imapd_enable="YES"
 courier_imap_imapd_ssl_enable="YES"

¤Ê¤É¤È½ñ¤­¹þ¤à¤Î¤¬Îɤµ¤½¤¦¤À¤È¤¤¤¦¤³¤È¤¬¿ä¬¤Ç¤­¤ë. ¤½¤³¤Ç¤³¤ì¤ò½ñ¤­¹þ¤ß¡¤Ç°¤Î°Ù¤Ë¥ê¥Ö¡¼¥È¤·¤Æ¤ª¤³¤¦*16.

IMAP ÍѤΥ桼¥¶¾ðÊó¤ÎÅÐÏ¿

º£²ó¤Ï userdb ¤Ç¥Ñ¥¹¥ï¡¼¥É¾È¹ç¤ò¹Ô¤¦¤è¤¦¤Ë¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿¤Î¤Ç, IMAP ÍѤ˥桼¥¶¾ðÊó¤òÅÐÏ¿¤·¤Æ¤ª¤«¤Ê¤¤¤È¤¤¤±¤Ê¤¤.
¶ñÂÎŪ¤Ë¤Ï¼¡¤Î½çÈ֤Ǻî¶È¤ò¹Ô¤¨¤Ð¤è¤¤.

  1. ¤Þ¤º¶õ¤Î¥Ç¥£¥ì¥¯¥È¥ê /usr/local/etc/userdb ¤òºîÀ®¤¹¤ë.
       cd /usr/local/etc
       mkdir userdb
       chmod 700 ./userdb
    ¤Ê¤É¤È¤¹¤ì¤Ð¤è¤¤.
  2. (¥Ñ¥¹¥ï¡¼¥É°Ê³°¤Î)¥æ¡¼¥¶¾ðÊó¤òÅÐÏ¿¤¹¤ë
    • /etc/passwd ¤«¤éºî¤ëÊýË¡
      ´û¤Ë¥·¥¹¥Æ¥à¤Î¥æ¡¼¥¶¤Ç¤â¤¢¤ë¤Ê¤é¤Ð´Êñ¤Ç¤ª¤¹¤¹¤á.
      pw2userdb ¥³¥Þ¥ó¥É¤òÍѤ¤¤Æ
       cd /usr/local/etc/userdb/
       pw2userdb | grep ¥æ¡¼¥¶Ì¾ >> ./users
      ¤È¤¹¤ì¤Ð¤è¤¤.
    • Îí¤«¤éºî¤ëÊýË¡.
      userdb ¥³¥Þ¥ó¥É¤ÇľÀܤ¤¤í¤¤¤í»ØÄꤹ¤ëÊýË¡. ¤Á¤ç¤¤ÌÌÅÝ.
       userdb "john@example.com" set home=/home/vmail \
       mail=/home/vmail/Maildir-john-example  uid=UUU gid=GGG"
      ¤Ê¤É¤È¤¹¤ëÊýË¡.
  3. ¥Ñ¥¹¥ï¡¼¥É¤òÀßÄꤹ¤ë.
     cd /usr/local/etc/userdb
     userdbpw -hmac-md5|userdb users/¥æ¡¼¥¶Ì¾ set hmac-md5pw
    ¤È¤¹¤ì¤Ð¤è¤¤. ¤³¤Î hmac-md5 ¤È¤¤¤¦¤Î¤¬ CRAM-MD5 ¤ÇÍøÍѤµ¤ì¤ë.
    ¤¦¤Þ¤¯¤¤¤Ã¤Æ¤¤¤ë¤«¤É¤¦¤«¡¤users ¥Õ¥¡¥¤¥ë¤òÆɤó¤Ç³Îǧ¤·¤Æ¤ª¤³¤¦.
  4. Äɲá¤Êѹ¹²Õ½ê¤òÍ­¸ú¤Ë¤¹¤ë.
     makeuserdb
    ¤È¤¹¤ì¤Ð¤è¤¤.

¤Ç¤Ï¤³¤³¤Ç¾å¤Î¼ê½ç¤Ë¤·¤¿¤¬¤Ã¤Æ IMAP ÍѤΥ桼¥¶¾ðÊó¤òÅÐÏ¿¤·¤Æ¤ª¤³¤¦.

courier-imap ¤ÎÆ°ºî³Îǧ

SMTP Auth ¤Î»þ¤ÈƱÍͤˡ¤2¤Ä¤Îʸ»úüËö¥¨¥ß¥å¥ì¡¼¥¿¤òÍÑ°Õ¤·¤ÆÆ°ºî³Îǧ¤ò¹Ô¤¦.

¤¿¤À¤·¡¤Æ°ºî³Îǧ¤Ç¤â¤¿¤Ä¤¤¤Æ¤¤¤ë¤È courier-imap ¥µ¡¼¥Ð¤¬Àܳ¤òÀڤäƤ·¤Þ¤¦¤Î¤Ç¡¤¤³¤ì¤Ë;͵¤ò»ý¤¿¤»¤Æ¤ª¤­¤¿¤¤.
¤½¤Î¤¿¤á¤Î½àÈ÷¤òÀè¤Ë¤·¤Æ¤ª¤³¤¦. ¶ñÂÎŪ¤Ë¤Ï¡¤/usr/local/etc/courier-imap/imapd ¥Õ¥¡¥¤¥ë¤Î

 IMAP_IDLE_TIMEOUT=60

¤È¤¤¤¦Éôʬ¤¬¡Ö60ÉÃÈ¿±þ¤¬¤Ê¤±¤ì¤ÐÀÚÃǡפȤ¤¤¦°ÕÌ£¤Ê¤Î¤Ç¡¤¤³¤Î 60 ¤òŬÅö¤ËÁý¤ä¤·¤Æ¤ª¤±¤Ð¤è¤¤.
Î㤨¤Ð 180 ¤°¤é¤¤¤Ë¤¹¤ì¤ÐÌäÂê¤Ê¤¤¤À¤í¤¦.

¤Ê¤ª¡¤¤³¤Î¥Õ¥¡¥¤¥ë¤òÊÔ½¸¤·¤¿¤é courier-imap ¥µ¡¼¥Ð¤ò°ìöÄä¤á¤ÆºÆÅÙÆ°¤«¤µ¤Ê¤¤¤È¤¤¤±¤Ê¤¤¤Î¤Ç¤½¤¦¤·¤Æ¤ª¤³¤¦.
¶ñÂÎŪ¤Ë¤Ï

 /usr/local/etc/rc.d/courier-imap-imapd.sh stop
 /usr/local/etc/rc.d/courier-imap-imapd.sh start

¤È¤·¤Æ¤ª¤±¤Ð¤è¤¤.

¤µ¤Æ¡¤¤Ç¤Ï SMTP Auth ¤Î»þ¤ÈƱ¤¸¤è¤¦¤Ë¤ä¤Ã¤Æ¤ß¤ë.
Shell-A ¤Ç¡¤telnet localhost 143 ¤È¤¹¤ë¤È

 Connected to localhost.
 Escape character is '^]'.
 * OK [CAPABILITY IMAP4rev1 UIDPLUS CHILDREN NAMESPACE THREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT QUOTA AUTH=CRAM-MD5 AUTH=CRAM-SHA1 AUTH=CRAM-SHA256 IDLE ACL ACL2=UNION STARTTLS] Courier-IMAP ready. Copyright 1998-2005 Double Precision, Inc.  See COPYING for distribution information.

¤Ê¤É¤È¸À¤Ã¤Æ¤¯¤ë. ¤³¤³¤Ç¡¤

 a authenticate cram-md5

¤ÈÆþÎϤ¹¤ë¤È

 + PG5hbmlrYS1pbWFwQHNlcnZlcj4=

¤Ê¤É¤È¥µ¡¼¥Ð¤«¤éʸ»úÎó¤¬Á÷¤é¤ì¤Æ¤¯¤ë.

¤³¤Îʸ»úÎó PG5hbmlrYS1pbWFwQHNlcnZlcj4= ¤ËÂФ·¤Æ¡¤Àè¤Û¤É¤ÈƱÍÍ¤Ë Shell-B¤Ç userdb-test-cram-md5 ¥³¥Þ¥ó¥É¤ò»È¤Ã¤ÆÊÖÅúÍÑʸ»úÎó¤òºî¤ë.
Î㤨¤Ð¼¡¤Î¤è¤¦¤Ë¤Ê¤ë¤À¤í¤¦.

 Username? testuser ¢« IMAP ÍѤËÅÐÏ¿¤·¤¿¥æ¡¼¥¶Ì¾
 Password? password ¢« IMAP ÍѤËÅÐÏ¿¤·¤¿¥Ñ¥¹¥ï¡¼¥É
 Send: AUTH CRAM-MD5 (or for imap, A AUTHENTICATE CRAM-MD5)
 Paste the challenge here:
 + PG5hbmlrYS1pbWFwQHNlcnZlcj4= ¢« º£¤Îʸ»úÎó
 Send this response:
 dGVzdHVzZXIgYjlkMDA5MzQ4YmVjMzlkNzcwMWU4MWRiZWE3NmZhN2M=

¤³¤ÎºÇ¸å¤Îʸ»úÎó dGVzdHVzZXIgYjlkMDA5MzQ4YmVjMzlkNzcwMWU4MWRiZWE3NmZhN2M= ¤¬ IMAP ¥µ¡¼¥Ð¤Ë½Ð¤¹¤Ù¤­ÊÖ»ö¤Ë¤Ê¤ë¤Î¤Ç¡¤¤³¤ì¤ò Shell-A ¤Ç¤Îºî¶È¤Î³¤­¤ËÄ¥¤êÉÕ¤±¤ÆÊÖÅú¤È¤¹¤ë.

¤½¤·¤Æ

 a OK LOGIN Ok.

¤È¤Ê¤ì¤Ð¡¤IMAP ¥µ¡¼¥Ð¤Îǧ¾Ú¤¬Ä̤俤Ȥ¤¤¦¤³¤È¤Ë¤Ê¤ê¡¤Æ°ºî¤¬³Îǧ¤Ç¤­¤¿¤³¤È¤Ë¤Ê¤ë*17.

¤Ê¤ª¡¤POP ¥µ¡¼¥Ð¤òΩ¤Á¾å¤²¤¿¤Ê¤é¤ÐƱÍͤ˥ƥ¹¥È¤¬²Äǽ¤Ç¤¢¤ë.
¤½¤ÎºÝ¤Ï

 telnet localhost 110
 (¥µ¡¼¥Ð¤«¤é¤Î±þÅú)
 capa
 (¥µ¡¼¥Ð¤«¤é¤Î±þÅú)
 auth cram-md5
 (¥µ¡¼¥Ð¤«¤éʸ»úÎó¤òÁ÷¤Ã¤Æ¤¯¤ë)
 (¤½¤ì¤ËÂбþ¤·¤ÆÊÖÅúÍÑʸ»úÎó¤òÍÑ°Õ¤·¤Æ¡Ä)
 ÊÖÅúÍÑʸ»úÎóÄ¥¤êÉÕ¤±

¤È¤¤¤¦Î®¤ì¤Ë¤Ê¤ë.

¼Â½¬

¤³¤³¤Þ¤Ç¤Îºî¶È¤ò¹Ô¤ª¤¦.
¤Þ¤¿¡¤Í¾Íµ¤¬¤¢¤ì¤ÐŬÅö¤Ê MUA ¤Ç IMAP ¥µ¡¼¥Ð¤ËÀܳ¤·¤Æ¤ß¤è¤¦.
¤µ¤é¤Ë;͵¤¬¤¢¤ì¤Ð¡¤IMAP over TLS/SSL ÀßÄê¤Ç¥µ¡¼¥Ð¤ËÀܳ¤·¤Æ¤ß¤è¤¦.

¥ì¥Ý¡¼¥È

ÅÓÃæ¤Ç¡ÖÄ´¤Ù¤è¡×¤È»Ø¼¨¤µ¤ì¤¿»ö¹à¤Ë¤Ä¤¤¤ÆÄ´ºº¤ò¹Ô¤¤¡¤Êó¹ð¤»¤è.
¤Þ¤¿¡¤¤³¤³¤Þ¤Ç¤Î¼Â½¬¤ò¹Ô¤¤¡¤Êó¹ð¤»¤è.


*1 Íפϥì¥ë¥à¤òÀµ¤·¤¯ÀßÄꤻ¤è¤È¤¤¤¦¤³¤È¤Ê¤ó¤À¤¬¡¤¤³¤¦¤·¤Æ¤ª¤±¤Ð´Ö°ã¤¨¤ë;ÃϤ¬¸º¤ë¤è¤Í¡¤¤È¤¤¤¦¤³¤È¤«¤Ê
*2 ¾Ü¤·¤¯¤ÏÁ°²ó¤Î¼ø¶È»ñÎÁ¤Ë¤ª¤¤¤Æ "You can use sasldb2 ..." ¤Ç»Ï¤Þ¤ë¥í¥°¥á¥Ã¥»¡¼¥¸Éôʬ¤òÆɤá¤Ðʬ¤«¤ë
*3 \0 ¤Ï¥Ì¥ë¥Ð¥¤¥È
*4 ¤Á¤Ê¤ß¤Ë¡¤base64 ¥¨¥ó¥³¡¼¥É¤·¤¿¥Æ¥­¥¹¥È¤Ï¡¤"mmencode -u" ¤Ç¸µ¤ËÌ᤹¤³¤È¤¬¤Ç¤­¤ë.
*5 \0000 ¤È¤Ê¤Ã¤Æ¤¤¤ë¤È¤³¤í¤Ï \0 ¤Ç¤â¤è¤¤¤Î¤À¤¬¡¤¥Ñ¥¹¥ï¡¼¥É¤Î1ʸ»úÌܤ¬¿ô»ú¤À¤Ã¤¿¤ê¤¹¤ë¤È¤¦¤Þ¤¯¤¤¤«¤Ê¤¤¤Î¤Ç¡¤Ç°¤Î°Ù¤Ë¤³¤¦¤·¤Æ¤¢¤ë.
*6 Î㤨¤Ð '\0test\0password' ¤ò mmencode ¤¹¤ë¤È "AHRlc3QAcGFzc3dvcmQ=" ¤È¤¤¤¦Ê¸»úÎ󤬽ÐÎϤµ¤ì¤ë.
*7 ʸ»úüËö¥¨¥ß¥å¥ì¡¼¥¿¤Ë³Ð¤¨¤µ¤»¤Æ¤·¤Þ¤¨¤Ð³Ú¤À¤í¤¦
*8 250-AUTH ¤Ç»Ï¤Þ¤ë¤Û¤ÜƱ¤¸¹Ô¤¬Æó²ó½Ð¤Æ¤¯¤ë¤Î¤¬ Microsoft ¤Î MUA Âкö¤Ç¤¢¤ë.
*9 ¤³¤ì¤ò "mmencode -u" ¤Ë¤«¤±¤ë¤È¼ÂºÝ¤Îʸ»úÎ󤬤狼¤ë
*10 ¤³¤Î¾ì¹ç¤Ï¤â¤Á¤í¤ó apache ¤ÎÀßÄê¤âľ¤µ¤Ê¤¤¤È¤¤¤±¤Ê¤¤
*11 ¤ä¤êÊý¤Ï¼ø¶ÈÂè07²ó¤Î SSL ¤Î¹àÌܤ˽ñ¤¤¤Æ¤¢¤ë
*12 Postfix ¤ÎÀßÄêÊýË¡¤¬ºÇ¶áÊѤï¤Ã¤¿¤¿¤á¡¤web ¾å¤Ç»²¾È¤Ç¤­¤ëÀßÄê¤Î¿¤¯¤Ï´û¤Ë¸Å¤¯¡¤¤¢¤Þ¤ê¿ä¾©¤Ç¤­¤Ê¤¤¤Î¤Çα°Õ¤¹¤ë¤³¤È.
*13 µÕ¤Ë¸À¤¨¤Ð¡¤over TLS ¤·¤Æ¤¤¤Ê¤¤¤Ê¤é¤Ð¥Í¥Ã¥È¥ï¡¼¥¯¤ò²ð¤·¤Æ Plainǧ¾Ú¤ò»È¤¦¤È´í¤Ê¤¤¤è¤È¤¤¤¦¤³¤È¤Ë¤Ê¤ë
*14 ¤½¤¦¤·¤Ê¤¤¤È¼Â¼ÁŪ¤Ë»È¤¨¤Ê¤¤.
*15 ¤â¤· imapd ¤È¤¤¤¦¥Õ¥¡¥¤¥ë¤¬¤Ê¤±¤ì¤Ð¡¤imapd.dist ¤¬¥µ¥ó¥×¥ë¤Ê¤Î¤Ç¤³¤ì¤ò¥³¥Ô¡¼¤·¤Æºî¤í¤¦.
*16 ÊѤ˥¹¥Ú¡¼¥¹¤òÆþ¤ì¤¿¤ê¤·¤Ê¤¤¤è¤¦¤Ë
*17 ¤³¤³¤Ç¤Ï ^] ¤È¤·¤Æ¤«¤é quit ¤È¤¹¤ì¤ÐÈ´¤±¤é¤ì¤ë