Networking and System AdministrationUnit 76 min read
Web & Mail Servers: Apache, Postfix, SMTP, POP3, IMAP, HTTPS, DNS, Security
Unit 7 of Networking and System Administration explores how web and email servers function, covering Apache/Nginx configurations, SMTP/POP3/IMAP protocols, email routing, HTTPS encryption, and security best practices with real-world examples from eSewa, Ncell, and global platforms like Gmail.
Core Concepts
Web Servers: The Foundation of the Internet
Web servers are software applications that process client requests via HTTP/HTTPS and deliver web content (HTML, CSS, JS, images). They handle:
- Static content (pre-built files)
- Dynamic content (generated via scripts like PHP, Python)
- Routing requests to backend services
classDiagram
class Client {
+send HTTP request
+receive HTTP response
}
class WebServer {
+process request
+serve static/dynamic content
+handle HTTPS encryption
}
class Database {
+store user data
+execute queries
}
Client --> WebServer : HTTP/HTTPS
WebServer --> Database : SQL/APIKey Components:
| Component | Role |
|---|---|
| HTTP/HTTPS | Protocol for client-server communication (port 80/443) |
| Virtual Hosts | Host multiple websites on one server using different domain names |
| Reverse Proxy | Distributes requests to backend servers (e.g., Nginx → Apache) |
| SSL/TLS | Encrypts data (HTTPS uses port 443) |
Apache Web Server: Configuration and Security
Configuration Files
Apache uses .conf files (main: /etc/apache2/apache2.conf or /etc/httpd/conf/httpd.conf). Key directives:
<VirtualHost *:80>
ServerName example.com
DocumentRoot /var/www/html
<Directory "/var/www/html">
Options Indexes FollowSymLinks
AllowOverride All
Require all granted
</Directory>
</Virtual
Host>
Worked Example: Hosting Multiple Sites on One Server
Assume a server with IP 203.127.127.127 hosting:
esewa.com(DocumentRoot:/var/www/esewa)ncell.com(DocumentRoot:/var/www/ncell)
<VirtualHost 203.127.127.127:80>
ServerName esewa.com
DocumentRoot /var/www/esewa
</VirtualHost>
<VirtualHost 203.127.127.127:80>
ServerName ncell.com
DocumentRoot /var/www/ncell
</VirtualHost>
Real-World Tie-In: eSewa’s web server uses Apache/Nginx with:
- Load balancing across multiple servers to handle 1M+ daily transactions.
- HTTPS (TLS 1.3) for secure payments (using Let’s Encrypt certificates).
- Reverse proxy to route requests to backend payment processing systems.
Email Servers: Protocols and Workflow
SMTP, POP3, and IMAP
| Protocol | Port | Role | Example Use Case |
|---|---|---|---|
| SMTP | 25 | Sending emails (server-to-server) | Gmail → Ncell’s mail server |
| POP3 | 110 | Downloading emails (client downloads, deletes from server) | Outlook fetching emails from NTC |
| IMAP | 143 | Syncing emails (client mirrors server) | eSewa’s webmail syncing with mobile |
Email Delivery Workflow:
sequenceDiagram
participant Alice as Alice (Client)
participant MX1 as eSewa's MX Server
participant MX2 as Ncell's MX Server
participant Bob as Bob (Recipient)
Alice->>MX1: SMTP (HELO, MAIL FROM, RCPT TO)
MX1->>MX2: SMTP (MX record lookup via DNS)
MX2-->>MX1: SMTP (250 OK)
MX1->>Bob: SMTP (Deliver email)
Bob->>Alice: SMTP (250 Accepted)Security: Hardening Web and Mail Servers
Common Threats and Mitigations
| Threat | Mitigation Strategy |
|---|---|
| SQL Injection | Use prepared statements (e.g., mysqli_real_escape_string() in PHP) |
| DDoS Attacks | Rate limiting, Cloudflare/WAF integration |
| Phishing (Email) | SPF/DKIM/DMARC records, email authentication |
| Man-in-the-Middle | Enforce HTTPS (HSTS), use strong TLS ciphers (e.g., TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) |
Worked Example: Securing eSewa’s Web Server
- HTTPS Enforcement:
<VirtualHost *:443> SSLEngine on SSLCertificateFile /etc/letsencrypt/live/esewa.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/esewa.com/privkey.pem Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" </VirtualHost> - Email Security:
- SPF Record:
v=spf1 include:_spf.google.com ~all(for Gmail integration). - DKIM: Sign emails with a private key to prove authenticity.
- SPF Record:
Mail Server Configuration: Postfix and Dovecot
Postfix (MTA) Configuration
Postfix (/etc/postfix/main.cf) handles email routing. Key settings:
myhostname = mail.esewa.com
mydestination = $myhostname, localhost.$mydomain, localhost
relayhost = [smtp.gmail.com]:587
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.esewa.com/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.esewa.com/privkey.pem
Dovecot (IMAP/POP3) Configuration
Dovecot (/etc/dovecot/dovecot.conf) manages email retrieval:
protocols = imap pop3
ssl_cert = </etc/letsencrypt/live/mail.esewa.com/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.esewa.com/privkey.pem
Real-World Tie-In: Ncell’s Email Service
- Uses Postfix for SMTP relaying to global providers (e.g., Google, Yahoo).
- Dovecot for IMAP access via Ncell’s app.
- DMARC Policy:
p=rejectto block spoofed emails (e.g.,support@ncell.comfrom unauthorized senders).
Exam Tip
- Configuration Files: Memorize key directives for Apache (
VirtualHost,DocumentRoot) and Postfix (mydestination,relayhost). - Protocols: Know the ports (SMTP:25, IMAP:143, HTTPS:443) and their roles. Draw the SMTP handshake sequence diagram.
- Security: Explain HTTPS (TLS handshake), SPF/DKIM/DMARC, and Apache security modules (e.g.,
mod_security). - Worked Examples: Be ready to configure a virtual host for a Nepalese company (e.g., Daraz) or secure an email server for a bank.
- Troubleshooting: Common exam questions ask how to fix:
- "Apache not serving a website" → Check
DocumentRootand permissions. - "Emails not reaching Gmail" → Verify SPF/DKIM records and Postfix
relayhost.
- "Apache not serving a website" → Check
Visual Summary:
mindmap
root((Web & Mail Servers))
Apache
Configuration
Virtual Hosts
Security (mod_security, HTTPS)
Email Protocols
SMTP (Port 25)
IMAP/POP3 (Ports 143/110)
Postfix/Dovecot
MTA (Postfix)
MDA (Dovecot)
Security
TLS/SSL
SPF/DKIM/DMARC
Real-World
eSewa (HTTPS + Load Balancing)
Ncell (Postfix + DMARC)Based on the TU BIM syllabus for Networking and System Administration (IT271), unit 7.
Discussion
Loading…