Hey meyergru
Thanks a lot for this excellent walkthrough!
Finally i found some time to read it carefully and try to understand it ;).
I was aware that the linked guide does only cover HTTPS traffic. Until now i only needed HTTPS. Also i could successfully publish the mailcow UI over HTTPS.
Where i'm not sure if i understand that correctly: the documentation you provided is to terminate TLS Traffic for IMAP and SMTP on HAProxy?
This is not my primary goal. For me it would be perfect if Postfix handles the TLS termination itself and i could just use HAproxy as a TCP proxy. But would i then have to have a Certificate (normally Lets encrypt) on the mailcow server, correct?
I read about solutions to let OPNSense create the LE-certificates and copy it to mailcow. But i want to avoid this if possible.
My goal would be:
HTTPS: as already working: termination on HAProxy, Certificate on HAProxy/OPNSense
IMAPS: proxing to mailcow but with certificate-handling on HAProxy/OPNSense
SMTP (incoming and outgoing): direct
Maybe you have a solutions for this also :)
Thanks again, i really appreciate your help!
regards
Martin
Thanks a lot for this excellent walkthrough!
Finally i found some time to read it carefully and try to understand it ;).
I was aware that the linked guide does only cover HTTPS traffic. Until now i only needed HTTPS. Also i could successfully publish the mailcow UI over HTTPS.
Where i'm not sure if i understand that correctly: the documentation you provided is to terminate TLS Traffic for IMAP and SMTP on HAProxy?
This is not my primary goal. For me it would be perfect if Postfix handles the TLS termination itself and i could just use HAproxy as a TCP proxy. But would i then have to have a Certificate (normally Lets encrypt) on the mailcow server, correct?
I read about solutions to let OPNSense create the LE-certificates and copy it to mailcow. But i want to avoid this if possible.
My goal would be:
HTTPS: as already working: termination on HAProxy, Certificate on HAProxy/OPNSense
IMAPS: proxing to mailcow but with certificate-handling on HAProxy/OPNSense
SMTP (incoming and outgoing): direct
Maybe you have a solutions for this also :)
Thanks again, i really appreciate your help!
regards
Martin