intercept_box
| Value | Named Filter |
|---|
Named filter for intercept-box settings.
Updated:
Revision: d0c46ac
Note: This is pre-release documentation.
Please access https://doc.dovecotpro.com/latest/ for documentation on released versions.
intercept-box) Plugin Note
This plugin is provided by Dovecot Pro's Lawful Intercept Framework.
This is a mail storage driver intended to be configured to a special user that receives intercepted mails via LMTP or IMAP APPEND. Saving a mail to any of its folders results in the mail being saved to the specified fs/path. The saved mail is written to the intercept file without any modifications - no additional metadata is saved.
This plugin is independent of the rest of the intercept infrastructure, i.e. it doesn't use the intercept-proxy service or support any configurable drivers.
The way this plugin is intended to be used is to configure MTA to send mails to a special intercept user via LMTP. This user has a Sieve script, which gets the intercepted user information from the email headers or in the +detail of the recipient address.
The folder name is in format: <user> <timestamp> <type>. These fields can be used in intercept_box_path. The field contents are not validated in any way.
intercept_box| Value | Named Filter |
|---|
Named filter for intercept-box settings.
intercept_box_add_headers| Default | [None] |
|---|---|
| Value | String List |
| See Also |
Headers to add to HTTP requests, when intercept_box is configured
with HTTP-based fs storage.
See intercept_box_path for supported variable substitutions.
intercept_box_path| Default | [None] |
|---|---|
| Value | string |
Path to save the mail intercepted via the intercept-box plugin.
For example:
intercept_box_path = %{crypted_user}/%{timestamp}.%{generate:guid128}.SMTP.%{type}.eml
Variable substitutions supported:
| Variable | Description |
|---|---|
user |
user@domain (based on the folder name) |
crypted_user |
user@domain encrypted via intercept_crypted_user |
timestamp |
timestamp (based on the folder name) |
type |
type (based on the folder name) |
Mail User Variables can also be used.
protocol lmtp {
# Generally, it is expected that userdb will return
# "mail_location=intercept:" for users that need interception.
mail_plugins {
intercept_box = yes
}
}
intercept_box {
# POSIX interception
fs posix {
prefix = /tmp/intercept/%{user}/%{protocol}-
}
}
intercept_box_crypt_key = secret
intercept_box_crypt_cipher = aes-256-cbc
intercept_box_path = %{crypted_user}/%{timestamp}.%{generate:guid128}.SMTP.%{type}.eml
intercept_box_add_headers {
X-Dovecot-Hash = /intercept/trace/%{crypted_user | substr(0,2)}/%{crypted_user | substr(2,3)}/
}Intercepted mails can be written to object storage using Dictmap. This replaces the fs posix filter in the example above. All fs filters inside the same block form a single chain, so fs posix can't be combined with fs dictmap.
This example reuses the mails dict and the user_other_objects Cassandra table from the obox configuration, see @fs_dictmap_defaults = cassandra and Cassandra Keyspace/Tables. The mails are mapped to object IDs with dict keys shared/dictmap/<fs_dictmap_dict_prefix><intercept_box_path>. The only default dict map that matches these keys is shared/dictmap/$user/other/$object_name, so intercept_box_path must be in <user>/other/<name> format. Using %{crypted_user} as the first path component stores each intercepted user's mails in their own Cassandra partition.
The intercept_box filter's fs is initialized once for the intercept user, not separately for each folder. So the folder name based variables (crypted_user, timestamp and type) can't be used in the fs settings. They can only be used in intercept_box_path and intercept_box_add_headers.
See S3 Compatible Storage for configuring the fs s3 settings.
intercept_box {
fs dictmap {
# Store the objects with path <storage_objectid_prefix><object ID>
storage_objectid_prefix = intercept/
}
# Use the same dict as obox
dict proxy {
name = mails
socket_path = dict-async
}
# Object storage, configured with the fs_s3_* settings
fs s3 {
}
}
# Must match the shared/dictmap/$user/other/$object_name dict map
intercept_box_path = %{crypted_user}/other/%{timestamp}.%{generate:guid128}.SMTP.%{type}.eml