2.3.15 Dockerfile

2021-06-22 Thread Jörg Faudin Schulz
I'm having hard-to-debug issues compiling 2.3.15 using Alpine; for some reasons I'd like to repeat that using buster. Where did you publish the Dockerfile for the 'official' repository?

Re: Dovecot v2.3.15 released

2021-06-22 Thread Alessio Cecchi
Il 21/06/21 13:18, Timo Sirainen ha scritto:  + imap: Support official RFC8970 preview/snippet syntax. Old methods of    retrieving preview information via IMAP commands ("SNIPPET and PREVIEW    with explicit algorithm selection") have been deprecated. Hi, After upgrading dovecot from 2.3.14 t

Re: libdict_lua linking issues

2021-06-22 Thread James
On 22/06/2021 12:30, Timo Sirainen wrote: libtool: link: gcc -std=gnu99 -m64 -march=x86-64 -fPIC -Os -Wall -W -Wmissing-prototypes -Wmissing-declarations -Wpointer-arith -Wchar-subscripts -Wformat=2 -Wbad-function-cast -fno-builtin-strftime -Wstrict-aliasing=2 -m64 -o test-dict test-dict.o ./

Re: libdict_lua linking issues

2021-06-22 Thread Daniel J. Luke
On Tue, Jun 22, 2021 at 01:30:49PM +0200, Timo Sirainen wrote: > > And on OmniOS / Solaris it failed with: > > > > libtool: link: gcc -std=gnu99 -m64 -march=x86-64 -fPIC -Os -Wall -W > > -Wmissing-prototypes -Wmissing-declarations -Wpointer-arith > > -Wchar-subscripts -Wformat=2 -Wbad-function-c

Re: libdict_lua linking issues

2021-06-22 Thread James
On 22/06/2021 12:30, Timo Sirainen wrote: And on OmniOS / Solaris it failed with: libtool: link: gcc -std=gnu99 -m64 -march=x86-64 -fPIC -Os -Wall -W -Wmissing-prototypes -Wmissing-declarations -Wpointer-arith -Wchar-subscripts -Wformat=2 -Wbad-function-cast -fno-builtin-strftime -Wstrict-ali

ssl_min_protocol v2.3.15

2021-06-22 Thread Theo Pannen
Hello, it seems that the default value for ssl_min_protocol has changed from TLSv1 to TLSv1.2, right? After upgrading to v2.3.15 and with ssl_min_protocol commented out, the server no longer offers TLSv1 and TLSv1.1. This is a good idea, but should be documented. Theo

Re: libdict_lua linking issues

2021-06-22 Thread Timo Sirainen
On 21. Jun 2021, at 18.57, James wrote: > > On 21/06/2021 17:39, Daniel J. Luke wrote: >> On Jun 21, 2021, at 7:20 AM, Timo Sirainen wrote: >>> Here's a new release with some security fixes and quite a lot of other >>> changes as well. >>> >>> * Removed support for Lua 5.2. Use version 5.1 or

Re: CVE-2021-33515: SMTP Submission service STARTTLS injection

2021-06-22 Thread Timo Sirainen
On 22. Jun 2021, at 11.11, li...@lazygranch.com wrote: > >> Vulnerability Details: >> >> On-path attacker could inject plaintext commands before STARTTLS >> negotiation that would be executed after STARTTLS finished with the >> client. Only the SMTP submission service is affected. > > Centos 7 h

Dovecot deliver and imap process hangs

2021-06-22 Thread Rok Saksida
Hello. Dovecot version: 2.2.36 OS: CentOS Linux release 7.9.2009 (Core) Kernel: 3.10.0-1160.11.1.el7.x86_64 I have two dovecot servers in replication master/master. Sometimes happens that deliver or imap process hangs and causing high CPU usage. In log's I only see locking failures but not init

Re: CVE-2021-33515: SMTP Submission service STARTTLS injection

2021-06-22 Thread Götz Reinicke
> Am 22.06.2021 um 11:11 schrieb li...@lazygranch.com: > > > > On Mon, 21 Jun 2021 13:51:30 +0200 > Timo Sirainen wrote: > >> Open-Xchange Security Advisory 2021-06-21 >> >> Product: Dovecot >> Vendor: OX Software GmbH >> Internal reference: DOV-4583 (Bug ID) >> Vulnerability type: CWE-74:

Re: CVE-2021-33515: SMTP Submission service STARTTLS injection

2021-06-22 Thread li...@lazygranch.com
On Mon, 21 Jun 2021 13:51:30 +0200 Timo Sirainen wrote: > Open-Xchange Security Advisory 2021-06-21 > > Product: Dovecot > Vendor: OX Software GmbH > Internal reference: DOV-4583 (Bug ID) > Vulnerability type: CWE-74: Failure to Sanitize Data into a Different > Plane ('Injection') Vulnerable

Upgrade path

2021-06-22 Thread Andrea Gabellini
Hello, I have a configuration with two proxy/director and two backend with replication. All at version 2.3.10.1. What is the suggested upgrade path to 2.3.15? I think to switch traffic to only one proxy and one backend and upgrade the two servers that remain without traffic. Then I switch th