[pfx] Re: (Patch "half-dane" logging corner case) Untrusted TLS connections where email domain does not support DNSSEC but MX server has DNSSEC/DANE records

2024-01-04 Thread Paul Menzel via Postfix-users
Dear Viktor, dear Wietse, Am 25.11.22 um 17:25 schrieb Viktor Dukhovni: On Fri, Nov 25, 2022 at 09:35:28AM -0500, Wietse Venema wrote: Viktor Dukhovni: However, in this case the issue is a minor oversight in the Postfix TLS client code. The intended logging behaviour does not happen. Patch

[pfx] Re: Amazon SES rejects text/rfc822-headers when header includes multipart content type - Workaround?

2024-01-04 Thread postfix--- via Postfix-users
Just a note to update the thread. Amazon reports that they've now corrected this issue in all of their regions, and sending the test case through I mentioned earlier in the thread now works, at least in our region. Cheers! Dan On 11/20/2023 3:52 PM, postfix--- via Postfix-users wrote: On 1

[pfx] Re: Postfix stopped logging lines with sender IP addresses after upgrade

2024-01-04 Thread Pedro David Marco via Postfix-users
On Tuesday, January 2, 2024 at 08:46:01 PM GMT+1, Vince Heuser via Postfix-users wrote: >I recently upgraded to mail_version = 3.4.23 >Suddenly, Postfix no longer logs the lines with IP addresses for the >connections. >There use to be some additional log lines with sender ip addresses.

[pfx] Re: SMTP Smuggling, workarounds and fix

2024-01-04 Thread Geert Hendrickx via Postfix-users
On Thu, Dec 21, 2023 at 07:51:31 -0500, Wietse Venema via Postfix-users wrote: > * With all Postfix versions, "smtpd_data_restrictions = > reject_unauth_pipelining" will stop the published exploit. Hi I just found an unexpected side effect of this particular configuration (unrelated to SMT

[pfx] Re: SMTP Smuggling, workarounds and fix

2024-01-04 Thread Wietse Venema via Postfix-users
Geert Hendrickx via Postfix-users: > On Thu, Dec 21, 2023 at 07:51:31 -0500, Wietse Venema via Postfix-users wrote: > > * With all Postfix versions, "smtpd_data_restrictions = > > reject_unauth_pipelining" will stop the published exploit. > > > Hi > > I just found an unexpected side effect

[pfx] Re: SMTP Smuggling, workarounds and fix

2024-01-04 Thread Wietse Venema via Postfix-users
Wietse Venema via Postfix-users: > Geert Hendrickx via Postfix-users: > > On Thu, Dec 21, 2023 at 07:51:31 -0500, Wietse Venema via Postfix-users > > wrote: > > > * With all Postfix versions, "smtpd_data_restrictions = > > > reject_unauth_pipelining" will stop the published exploit. > > > >

[pfx] Re: SMTP Smuggling, workarounds and fix

2024-01-04 Thread Geert Hendrickx via Postfix-users
On Thu, Jan 04, 2024 at 10:36:23 -0500, Wietse Venema via Postfix-users wrote: > Wietse Venema via Postfix-users: > > Geert Hendrickx via Postfix-users: > > > I just found an unexpected side effect of this particular configuration > > > (unrelated to SMTP smuggling). > > > > > > [...] Or stated d

[pfx] Re: SMTP Smuggling, workarounds and fix

2024-01-04 Thread Wietse Venema via Postfix-users
Geert Hendrickx via Postfix-users: > On Thu, Jan 04, 2024 at 10:36:23 -0500, Wietse Venema via Postfix-users wrote: > > Wietse Venema via Postfix-users: > > > Geert Hendrickx via Postfix-users: > > > > I just found an unexpected side effect of this particular configuration > > > > (unrelated to SMT

[pfx] Re: SMTP Smuggling, workarounds and fix

2024-01-04 Thread Bill Cole via Postfix-users
On 2024-01-04 at 11:15:17 UTC-0500 (Thu, 4 Jan 2024 17:15:17 +0100) Geert Hendrickx via Postfix-users is rumored to have said: My point was not about SMTP smuggling, but about potentially revealing DISCARD rules to the outside world (since they cause later rules to be skipped entirely). Eg. a