diff --git a/CHANGELOG.md b/CHANGELOG.md index 232d32fc..5838b28d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,10 @@ and this project adheres to - Bump keycloak to 26.6.3 - Bump keycloak to 26.6.4 +### Fixed + +- 🐛(mta-out) fix relay block indentation breaking SASL auth #733 + ## [0.8.0] - 2026-06-18 ### Added diff --git a/src/mta-out/etc/main.cf.j2 b/src/mta-out/etc/main.cf.j2 index fe4f4efe..aec6c524 100644 --- a/src/mta-out/etc/main.cf.j2 +++ b/src/mta-out/etc/main.cf.j2 @@ -81,18 +81,18 @@ message_size_limit = {{ MAX_OUTGOING_EMAIL_SIZE }} {% if SMTP_RELAY_HOST %} # Configured to relay through an upstream host relayhost = {{ SMTP_RELAY_HOST }} - {# --- Authentication TO Relay Host (if specified) --- #} - {% if SMTP_RELAY_USERNAME and SMTP_RELAY_PASSWORD %} - # Enable SASL authentication when connecting to the relay host. - smtp_sasl_auth_enable = yes - # Use the password map generated by entrypoint.sh. - smtp_sasl_password_maps = hash:/etc/postfix/sasl/relay_passwd - # Don't allow anonymous authentication. - smtp_sasl_security_options = noanonymous - {% else %} - # Disable SASL authentication if relay credentials are not provided. - smtp_sasl_auth_enable = no - {% endif %} +{# --- Authentication TO Relay Host (if specified) --- #} +{% if SMTP_RELAY_USERNAME and SMTP_RELAY_PASSWORD %} +# Enable SASL authentication when connecting to the relay host. +smtp_sasl_auth_enable = yes +# Use the password map generated by entrypoint.sh. +smtp_sasl_password_maps = hash:/etc/postfix/sasl/relay_passwd +# Don't allow anonymous authentication. +smtp_sasl_security_options = noanonymous +{% else %} +# Disable SASL authentication if relay credentials are not provided. +smtp_sasl_auth_enable = no +{% endif %} {% else %} # Configured for direct delivery via DNS MX lookup # Use DNS (MX records) to find the next hop.