Re: question on xforward

2008-11-27 Thread Jan P. Kessler
Victor Duchovni schrieb: Is there any good reason why smtpd_tls_received_header does not include the ccert_fingerprint when available? Perhaps it is because software does not grow on trees and actually needs to be created first? Hey - no offense, we're in the same business! This wa

Re: question on xforward

2008-11-26 Thread Victor Duchovni
On Wed, Nov 26, 2008 at 06:45:53PM -0500, Wietse Venema wrote: > Jan P. Kessler: > > Victor Duchovni schrieb: > > > The topmost header "by your-MTA" is trustworthy, as are any headers > > > above it. > > > > > > > That makes sense, of course. > > > > Is there any good reason why smtpd_tls_rec

Re: question on xforward

2008-11-26 Thread Wietse Venema
Jan P. Kessler: > Victor Duchovni schrieb: > > The topmost header "by your-MTA" is trustworthy, as are any headers > > above it. > > > > That makes sense, of course. > > Is there any good reason why smtpd_tls_received_header does not include > the ccert_fingerprint when available? Perhaps it

Re: question on xforward

2008-11-26 Thread Jan P. Kessler
Victor Duchovni schrieb: The topmost header "by your-MTA" is trustworthy, as are any headers above it. That makes sense, of course. Is there any good reason why smtpd_tls_received_header does not include the ccert_fingerprint when available?

Re: question on xforward

2008-11-26 Thread mouss
Jan P. Kessler a écrit : > Victor Duchovni schrieb: >> On Wed, Nov 26, 2008 at 06:50:13PM +0100, Jan P. Kessler wrote: >> >> >>> would it be possible/valuable to enhance xforward by additional >>> attributes reflecting the tls parameters of the upstream smtp >>> session? Background is the current

Re: question on xforward

2008-11-26 Thread Victor Duchovni
On Wed, Nov 26, 2008 at 08:48:31PM +0100, Jan P. Kessler wrote: > Victor Duchovni schrieb: > >On Wed, Nov 26, 2008 at 06:50:13PM +0100, Jan P. Kessler wrote: > > > > > >>would it be possible/valuable to enhance xforward by additional > >>attributes reflecting the tls parameters of the upstream

Re: question on xforward

2008-11-26 Thread Jan P. Kessler
Victor Duchovni schrieb: On Wed, Nov 26, 2008 at 06:50:13PM +0100, Jan P. Kessler wrote: would it be possible/valuable to enhance xforward by additional attributes reflecting the tls parameters of the upstream smtp session? Background is the current development of a content/proxyfilter.

Re: question on xforward

2008-11-26 Thread Victor Duchovni
On Wed, Nov 26, 2008 at 06:50:13PM +0100, Jan P. Kessler wrote: > would it be possible/valuable to enhance xforward by additional > attributes reflecting the tls parameters of the upstream smtp session? > Background is the current development of a content/proxyfilter. What problem would this so