[DANE] - Update postfix to check TLSA when sending emails to remote servers. #755

Closed
opened 2024-01-10 22:37:07 +01:00 by muppeth · 1 comment
Owner
No description provided.
muppeth added this to the 24.01 - January milestone 2024-01-10 22:37:07 +01:00
muppeth added the
Mail
label 2024-01-10 22:37:07 +01:00
muppeth self-assigned this 2024-01-10 22:37:07 +01:00
Author
Owner

Done in prod and PR made. This update forces postfix to check validity of existing TLSA record when sending email and if invalid do not send.

Currently check is set to smtp_tls_security_level = dane for backward compatibility with non-dane enabled domains which is the right way to do it (not everyone does implement it), as it won't send emails to servers with invalid TLSA.

Done in prod and PR made. This update forces postfix to check validity of existing TLSA record when sending email and if invalid do not send. Currently check is set to `smtp_tls_security_level = dane` for backward compatibility with non-dane enabled domains which is the right way to do it (not everyone does implement it), as it won't send emails to servers with invalid TLSA.
Sign in to join this conversation.
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: Disroot/Disroot-Project#755
No description provided.