Snawoot / postfix-mta-sts-resolver

Daemon which provides TLS client policy for Postfix via socketmap, according to domain MTA-STS policy
MIT License
117 stars 23 forks source link

Notice for Postfix 3.4+ users #65

Closed Snawoot closed 10 months ago

Snawoot commented 4 years ago

There is a bug in Postfix 3.4+ which makes Postfix unable to load the key+cert+chain.

Make sure you have smtpd_tls_eecdh_grade in it's default value auto or you have Postfix version which contains fix for this bug.

polarathene commented 10 months ago

Postfix version which contains fix for this bug

Seems from the linked discussion that it got patched: https://www.mail-archive.com/postfix-users@postfix.org/msg87364.html

If I understand that correctly, 3.4 + 3.5 + 3.6 all received a patch update for it. Anything newer than 3.6 should definitely have the fix.

Snawoot commented 10 months ago

Thank you!