1. 06 May, 2015 1 commit
  2. 05 May, 2015 2 commits
    • Joshua Tauberer's avatar
      drop legacy, export-grade, and anonymous ciphers from SMTP (port 25, opportunistic) · 7ca42489
      Joshua Tauberer authored
      Even though SMTP (on port 25) is typically opportunistic and a MitM attack can't be prevented, we may as well only offer ciphers that provide some level of security. If a client is so old or misconfigured that it doesn't support newer ciphers, it should hopefully fall back to a non-TLS connection.
      
      Postfix's default was basically anything goes (anonymous and 40-bit ciphers!). Google's MTA's only offer ciphers at 112 bits at greater, and this change approximates that with Postfix's "medium" setting.
      
      Fixes #371
      7ca42489
    • Joshua Tauberer's avatar
      bad ciphers were allowed in smtp submssion · 8c6363f7
      Joshua Tauberer authored
      This disallows aNULL and other bad ciphers in the Postfix submission server.
      
      I missed an option in 45e93f7d recommended by the blog post I was reading.
      
      Fixes #389.
      8c6363f7
  3. 04 May, 2015 3 commits
  4. 03 May, 2015 9 commits
  5. 29 Apr, 2015 2 commits
  6. 28 Apr, 2015 3 commits
  7. 21 Apr, 2015 1 commit
  8. 20 Apr, 2015 1 commit
  9. 19 Apr, 2015 2 commits
  10. 16 Apr, 2015 2 commits
  11. 11 Apr, 2015 8 commits
  12. 09 Apr, 2015 6 commits