Deploying Roundcube Webmail with Nginx and PHP-FPM

PHP-FPM Process Configuration

Align the PHP processor execution context with the mail system user. Modify the pool configuration file, typically located at /etc/opt/remi/php83/php-fpm.d/www.conf, to ensure permissions match the mail storage owner.

user = vmail
group = vmail
listen.acl_users = vmail
listen = /run/php-fpm/roundcube.sock
listen.owner = vmail
listen.group = vmail
listen.mode = 0660

Enable and launch the PHP service:

systemctl enable php83-php-fpm
systemctl start php83-php-fpm

Nginx Web Server Setup

Installation

Install the web server package via the system package manager:

yum install nginx

Main Configuration

Update /etc/nginx/nginx.conf to run processes under the mail user context and define logging standards.

user  vmail;
worker_processes  auto;
error_log  /var/log/nginx/error.log warn;
pid        /var/run/nginx.pid;

events {
    worker_connections  2048;
}

http {
    include       /etc/nginx/mime.types;
    default_type  application/octet-stream;

    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    access_log  /var/log/nginx/access.log  main;
    sendfile        on;
    keepalive_timeout  120;

    include /etc/nginx/conf.d/*.conf;
}

Virtual Host Configuration

Create a specific configuration file at /etc/nginx/conf.d/webmail.conf. This setup includes SSL termination, security headers, and FastCGI pass-through to PHP.

server {
    listen 80;
    server_name webmail.domain.local;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl http2;
    server_name webmail.domain.local;

    ssl_certificate     /etc/pki/tls/certs/webmail.domain.local.crt;
    ssl_certificate_key /etc/pki/tls/private/webmail.domain.local.key;
    ssl_dhparam         /etc/nginx/dhparam.pem;
    ssl_session_timeout  10m;
    ssl_session_cache    shared:SSL:20m;
    ssl_protocols        TLSv1.2 TLSv1.3;
    ssl_ciphers          HIGH:!aNULL:!MD5;
    ssl_prefer_server_ciphers   on;

    root /srv/http/webmail;
    index index.php;

    client_max_body_size 100m;
    client_body_timeout 120;
    client_header_timeout 120;

    location ~ \.php$ {
        fastcgi_pass unix:/run/php-fpm/roundcube.sock;
        fastcgi_index index.php;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        include fastcgi_params;
    }

    location ~ /\.ht {
        deny all;
    }
}

Directory Preparation

Initialize the document root and assign ownership:

mkdir -p /srv/http/webmail
chown -R vmail:vmail /srv/http/webmail
systemctl start nginx
systemctl enable nginx

Roundcube Application Deployment

Source Extraction

Download the latest stable release and extract it to the web root.

tar -zxvf roundcubemail-1.6.7-complete.tar.gz -C /srv/http/
mv /srv/http/roundcubemail-1.6.7/* /srv/http/webmail/
chown -R vmail:vmail /srv/http/webmail

Database Initialization

Connect to the databaes server to create the storage backend and access credentials.

CREATE DATABASE roundcube_db CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;
USE roundcube_db;
SOURCE /srv/http/webmail/SQL/mysql.initial.sql;

CREATE USER 'rc_user'@'localhost' IDENTIFIED BY 'SecurePass123!';
GRANT ALL PRIVILEGES ON roundcube_db.* TO 'rc_user'@'localhost';
FLUSH PRIVILEGES;

Application Configuration

Copy the sample configuration file and adjust parameters for database connectivity and SMTP transport.

cp /srv/http/webmail/config/config.inc.php.sample /srv/http/webmail/config/config.inc.php

Edit /srv/http/webmail/config/config.inc.php:

$config['db_dsnw'] = 'mysql://rc_user:SecurePass123!@localhost/roundcube_db';
$config['smtp_host'] = 'tls://localhost:587';
$config['smtp_user'] = '%u';
$config['smtp_pass'] = '%p';

// Disable installer module after setup
$config['enable_installer'] = false;

// SSL Verification settings for local SMTP
$config['smtp_conn_options'] = [
    'ssl' => [
        'verify_peer' => false,
        'verify_peer_name' => false,
    ],
];

Security Cleanup

Remove the installation wizard directory to prevent unauthorized reconfiguration:

rm -rf /srv/http/webmail/installer

System Validation

Access the configured domain via a web browser. The login prompt should appear immediately. Authenticate using valid mailbox credentials managed by the underlying Postfix/Dovecot system.

Verify core functionality by composing a new message and sending it to an external address. Check the inbox for incoming mail to confirm IMAP retrieval is functioning correctly. Ensure attachments can be uploaedd and downloaded without errors.

Tags: Roundcube nginx PHP-FPM Webmail Linux

Posted on Wed, 07 Oct 2026 16:55:50 +0000 by jikishlove