Ensure Security of Postfix SSL Certificate
An XCCDF Group
Description
Create the PKI directory for mail certificates, if it does not already exist:
$ sudo mkdir /etc/pki/tls/mail $ sudo chown root:root /etc/pki/tls/mail $ sudo chmod 755 /etc/pki/tls/mailUsing removable media or some other secure transmission format, install the files generated in the previous step onto the mail server:
/etc/pki/tls/mail/serverkey.pem: the private key mailserverkey.pem /etc/pki/tls/mail/servercert.pem: the certificate file mailservercert.pemVerify the ownership and permissions of these files:
$ sudo chown root:root /etc/pki/tls/mail/serverkey.pem $ sudo chown root:root /etc/pki/tls/mail/servercert.pem $ sudo chmod 600 /etc/pki/tls/mail/serverkey.pem $ sudo chmod 644 /etc/pki/tls/mail/servercert.pemVerify that the CA's public certificate file has been installed as
/etc/pki/tls/CA/cacert.pem
, and has the
correct permissions:
$ sudo chown root:root /etc/pki/tls/CA/cacert.pem $ sudo chmod 644 /etc/pki/tls/CA/cacert.pem
- ID
- xccdf_org.ssgproject.content_group_postfix_install_ssl_cert
- Child Items
- Updated