Alexander Graf
b02ceab72f
handle DEFER_ON_TLS_ERROR as bool
...
use /conf/mta-sts-daemon.yml when override is missing
2021-09-09 18:00:48 +02:00
Florent Daigniere
489520f067
forgot about alpine/lmdb
2021-09-01 08:41:39 +02:00
Florent Daigniere
a1da4daa4c
Implement the DANE-only lookup policyd
...
https://github.com/Snawoot/postfix-mta-sts-resolver/issues/67 for
context
2021-08-31 20:24:06 +02:00
Florent Daigniere
67db72d774
Behave like documented
2021-08-30 17:00:12 +02:00
Florent Daigniere
a8142dabbe
Introduce DEFER_ON_TLS_ERROR
...
This will default to True and defer emails that fail even "loose"
validation of DANE or MTA-STS
It should work most of the time but if it doesn't and you would rather
see your emails delivered, you can turn it off.
2021-08-30 14:21:28 +02:00
Florent Daigniere
4f96e99144
MTA-STS (use rather than publish policies)
2021-08-29 17:40:37 +02:00
Florent Daigniere
65a27b1c7f
add additional options to make DANE easier
2021-08-20 14:18:07 +02:00
Florent Daigniere
fb8d52ceb2
Merge branch 'master' of https://github.com/Mailu/Mailu into tls_policy_map
2021-08-20 14:17:34 +02:00
bors[bot]
b57df78dac
Merge #1916
...
1916: Ratelimit outgoing emails per user r=mergify[bot] a=nextgens
## What type of PR?
Feature
## What does this PR do?
A conflict-free version of #1360 implementing per-user sender limits
### Related issue(s)
- close #1360
- close #1031
- close #1774
## Prerequistes
Before we can consider review and merge, please make sure the following list is done and checked.
If an entry in not applicable, you can check it or remove it from the list.
- [x] In case of feature or enhancement: documentation updated accordingly
- [x] Unless it's docs or a minor change: add [changelog](https://mailu.io/master/contributors/workflow.html#changelog ) entry file.
Co-authored-by: Florent Daigniere <nextgens@freenetproject.org>
Co-authored-by: Dimitri Huisman <diman@huisman.xyz>
2021-08-18 19:28:28 +00:00
Florent Daigniere
b066a5e2ac
add a default tls_policy_map
2021-08-14 08:48:42 +02:00
Florent Daigniere
1df79f8132
give PFS a chance
2021-08-14 08:48:04 +02:00
Florent Daigniere
925105075c
this is required in fact
2021-08-13 20:35:40 +02:00
Florent Daigniere
772e5efb7d
Disable pipelining to prevent bypass
2021-08-11 22:47:29 +02:00
Florent Daigniere
2b05e72ce4
Revert "maybe fix the tests"
...
This reverts commit f971b47fb9
.
2021-08-10 08:51:55 +02:00
Florent Daigniere
f971b47fb9
maybe fix the tests
2021-08-10 08:22:23 +02:00
Florent Daigniere
4a871c0905
this causes trouble with the test
2021-08-09 23:29:17 +02:00
Florent Daigniere
55cdb1a534
be explicit about what we support
2021-08-09 17:42:33 +02:00
Florent Daigniere
ecadf46ac6
fix PFS
2021-08-09 17:39:15 +02:00
Florent Daigniere
de3620da4a
Don't send credentials in clear ever
2021-08-09 17:29:42 +02:00
Florent Daigniere
4535c42e70
This isn't required
2021-08-09 17:29:42 +02:00
Florent Daigniere
1101e401e8
Apply the restriction on the right port
2021-08-09 14:58:58 +02:00
Florent Daigniere
d6ce5d0c06
Remove a warning: limits don't apply to trusted hosts
2021-08-08 20:21:24 +02:00
Florent Daigniere
bcdc137677
Alpine has removed support for btree and hash
2021-08-08 19:18:33 +02:00
Florent Daigniere
1438253a06
Ratelimit outgoing emails per user
2021-08-08 09:21:14 +02:00
Florent Daigniere
8bc1d6c08b
Replace PUBLIC_HOSTNAME/IP in Received headers
...
This will ensure that we don't get spam points for not respecting the
RFC
2021-07-18 18:24:46 +02:00
Florent Daigniere
513d2a4c5e
Fix bug #1660 : nested headers shouldn't be touched
2021-03-09 19:43:08 +01:00
Thomas Rehn
05ab244638
Ensure that the rendered file ends with newline in order to make postconf
work correctly
2020-10-04 16:36:37 +02:00
Michael Wyraz
e4454d776a
Allow to enforce TLS for outbound using OUTBOUND_TLS_LEVEL=encrypt (default is 'may')
2020-05-02 20:58:07 +02:00
SunMar
ac6b8d62dd
Remove reject_unverified_recipient
from smtpd_client_restrictions
...
Fix for #1292 , though I'm not sure if this is the right way to fix the issue. It was added in 175349a224
.
2020-03-18 22:22:11 +01:00
kaiyou
bd69b7a491
Add support for SRS, related to #328
2020-01-14 01:18:30 +01:00
Michael Wyraz
a907fe4cac
Split HOST_ANTISPAM in HOST_ANTISPAM_MILTER and HOST_ANTISPAM_WEBUI
2019-10-13 20:13:02 +02:00
Ionut Filip
075417bf90
Merged master and fixed conflicts
2019-08-21 20:35:24 +03:00
Dario Ernst
ce0c24e076
Merge branch 'master' into HorayNarea-feat-upgrade-alpine
2019-07-14 09:40:58 +00:00
Daniel Huber
ae290482c0
Format relay credentials file with jinja
2019-06-26 20:22:02 +02:00
Daniel Huber
515e95076a
Merge branch 'master' into feat-relay-auth
2019-06-26 19:52:54 +02:00
Dario Ernst
d155b2c533
Start postfix directly with stdout logging
2019-06-25 19:24:05 +00:00
Daniel Huber
7dcb2eb006
Add authentication for email relays
2019-03-04 18:54:53 +01:00
Florian Peschka
b9fd29a52f
Add extra newline to main.cf
...
This should prevent jinja from stripping the newline, which causes overrides to be appended after the comment section
see #941
2019-02-19 21:09:50 +01:00
Ionut Filip
4c25c83419
HOST_* and *_ADDRESS variables cleanup
2019-02-18 14:46:48 +02:00
Tim Möhlmann
8172f3eab8
Move the Mailu Docker network to a fixed subnet.
...
This will make network configuration and host based authentication
more robust, across different deployment platforms.
The options `RELAYNETS` and`POD_ADDRESS_RANGE` are kept for compatibility.
However, their usage have become optional.
2018-12-06 12:08:22 +02:00
kaiyou
1fcaef7c7e
Merge branch 'master' into fix-sender-checks
2018-10-20 10:18:36 +02:00
mergify[bot]
118ea0f3fb
Merge pull request #604 from ofthesun9/feature-swarm
...
Enabling swarm deployment on master branch
2018-10-19 09:18:34 +00:00
kaiyou
f647d1a0bc
Merge branch 'master' into fix-sender-checks
2018-10-16 20:41:18 +02:00
kaiyou
5035975c41
Remove Postfix debugging
2018-10-15 22:07:38 +02:00
kaiyou
00b5ae11db
Merge branch 'master' into feat-abstract-db
2018-10-10 08:41:56 +02:00
kaiyou
8b189ed145
Separate senderaccess and senderlogin maps
2018-10-07 16:23:53 +02:00
ofthesun9
74796201ec
Merge branch 'master' into feature-swarm
2018-10-07 08:00:12 +00:00
kaiyou
fc99eb7b34
Re-enable sender access check to prevent source spoofing
2018-10-07 01:52:01 +02:00
kaiyou
f3f0b98755
Fix relay restrictions so email gets delivered correctly
2018-10-07 01:28:22 +02:00
ofthesun9
09d77bc2de
Handle the case where the variable REJECT_UNLISTED_RECIPIENT is not set
2018-10-04 18:55:56 +00:00