Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Running the server

Security notes

What the server does

  • Encryption everywhere. Webmail, this admin center, phones and apps connect over TLS. Mail between servers is encrypted whenever the other side supports it. Passwords are never accepted over an unencrypted connection.
  • Passwords are stored as Argon2id hashes, never in readable form. For NTLM, an encrypted NTLM hash is kept too.
  • Guessing is throttled. After 10 wrong passwords within 15 minutes, further attempts for that account and from that IP address are refused for a while.
  • Web sessions end after 8 hours without activity and after 24 hours at most, and are protected against cross-site request forgery. Resetting a password signs the person out of webmail everywhere.
  • Mail content is sanitized before webmail shows it: scripts are removed, and pictures from the internet stay blocked until the reader allows them, so senders cannot track opens.
  • Administrator roles limit who can change what, and Change history records every change.
  • Updates are signed and checked by apt before installing (see Updates).
  • Outgoing mail can be DKIM-signed per domain (see Email signing); mail from the internet that is forwarded on is never signed, so the server cannot vouch for a spoofed sender.
  • The firewall set up at installation opens only the ports the server uses.

NTLM sign-in for Outlook

Outlook for Windows prefers NTLM (Windows sign-in) over sending the password with every request. The server supports it for Outlook's connections (automatic setup, Exchange Web Services, MAPI over HTTP and the offline address book), not for phones, which keep using the password. It is off until you turn it on:

sudo oms ntlm status      # is it on, and how many accounts are ready
sudo oms ntlm enable
sudo oms ntlm disable
sudo oms ntlm purge       # forget every stored NTLM hash
  • Accounts become ready as people sign in. NTLM needs the account's NTLM hash, which the server can only compute from the password: it is stored whenever a password is set, and at the next sign-in with the password (webmail, a phone, IMAP, or Outlook itself before NTLM is on). Accounts that are not ready yet fail NTLM, and the log says why. Turn it on once oms ntlm status shows most accounts ready, or reset the passwords of the others.
  • The NTLM hash works like a password for NTLM, so it is encrypted with a key kept outside the database (/var/lib/obsidian-mailserver/keys/credential.key). A database backup alone does not reveal it; back up the key file with the server's other data. oms ntlm purge removes all of them.
  • Only NTLMv2 is accepted, only over HTTPS, and only after the same guessing limits as passwords.
  • Extended Protection (Oms.Ntlm.ChannelBinding, see Configuration) ties each sign-in to the server's certificate, so it cannot be relayed through another server. If a proxy in front of the server handles HTTPS, set it to None.
  • Signing in as DOMAIN\name works when the domain is written as the email domain (example.com\name); otherwise sign in with the email address.

What to add

GapRecommendation
No spam or virus filterPut a filtering gateway or service in front of the server (see DNS).
No two-factor sign-in yetUse long, unique passwords. Consider keeping webmail and the admin center reachable only from your network or a VPN, and publishing only what phones need.
Admin center reachable wherever webmail isRestrict port 443 at your firewall or reverse proxy if only some networks should reach /admin.

Good habits

  • Give each administrator their own account and the lowest role that does the job; use Helpdesk for password resets.
  • Keep the RelayFrom list for internal apps short (see Mail flow).
  • Install updates promptly: sudo apt update && sudo apt upgrade.
  • Keep backups off the server and test a restore (see Backups).
  • Protect the obsidian console account: it can change everything. Prefer SSH keys over passwords for remote access.
  • Block or erase lost phones promptly (see Phones and tablets).