Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Postfix 3.10 MTA Arrives with OpenSSL 3.5 Support #6354

Open
yawnbox opened this issue Mar 5, 2025 · 0 comments
Open

Postfix 3.10 MTA Arrives with OpenSSL 3.5 Support #6354

yawnbox opened this issue Mar 5, 2025 · 0 comments

Comments

@yawnbox
Copy link

yawnbox commented Mar 5, 2025

Summary

Please update Postfix to 3.10 and OpenSSL to 3.5 to begin to support post-quantum cryptogrpahy.

Motivation

re: https://linuxiac.com/postfix-3-10-mta-arrives-with-openssl-3-5-support/

"One of the most significant highlights of Postfix 3.10 is its forward compatibility with OpenSSL 3.5 post-quantum cryptography. Administrators can manage algorithm selection directly through the new “tls_eecdh_auto_curves” and “tls_ffdhe_auto_groups” parameters. By setting these parameter values to empty, Postfix effectively defers the algorithm selection to OpenSSL’s own configuration.

In addition, the release includes support for the RFC 8689 “TLS-Required: no” message header. This feature makes it possible to request delivery of certain emails, such as TLSRPT summaries, even if the ideal TLS security settings cannot be enforced.

A major new capability also arrives with added support for the TLSRPT protocol. By publishing a specific policy in DNS, a domain can receive daily summaries of successful and failed TLS connections to that domain’s mail servers. This is especially useful for domains leveraging DANE or MTA-STS to protect email security."

Additional context

No response

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant