Re: OpenSSL 3.4.x supported?

Liste des GroupesRevenir à cm sendmail 
Sujet : Re: OpenSSL 3.4.x supported?
De : anon.amish (at) *nospam* gmail.com (AMM)
Groupes : comp.mail.sendmail
Date : 08. Jan 2025, 09:39:28
Autres entêtes
Organisation : A noiseless patient Spider
Message-ID : <vlldk0$2msmi$1@dont-email.me>
References : 1 2 3 4
User-Agent : Mozilla Thunderbird
On 06/01/25 9:48 pm, Claus Aßmann wrote:
AMM  wrote:
 
EOPENSSL_CONF=/etc/mail/sendmail.ossl
 
In my case this file does not exist.
 That's the entire idea - as the release notes entry explains:
 
Note: OpenSSL 3 loads by default an openssl.cnf file from a location
specified in the library which may cause unwanted behaviour in sendmail.
 
It is not clear what unwanted behaviour can occur if OpenSSL defaults
are used?
 Check the OpenSSL config file / documentation, e.g., wrt
"security level".
Thank you for your response. However, it is still not clear what unwanted behaviour can occur? If you can explain, then please do.

 
  Didn't sendmail use OpenSSL defaults, earlier too?
 sendmail never explicitly use{s,d} OpenSSL config files.
 
Ideally, what setting should be mentioned in /etc/mail/sendmail.ossl?
Currently I have this in sendmail.mc file: (using from few years)
dnl # recommended from https://weakdh.org/sysadmin.html
LOCAL_CONFIG
O CipherList=ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA
O DHParameters=/etc/ssl/dhparams.pem
O ServerSSLOptions=+SSL_OP_CIPHER_SERVER_PREFERENCE
Hopefully this is what is sufficient.
Regards
AMM.

Date Sujet#  Auteur
28 Dec 24 * OpenSSL 3.4.x supported?11AMM
28 Dec 24 +* Re: OpenSSL 3.4.x supported?9Claus Aßmann
6 Jan 25 i`* Re: OpenSSL 3.4.x supported?8AMM
6 Jan 25 i `* Re: OpenSSL 3.4.x supported?7Claus Aßmann
7 Jan 25 i  +* Re: OpenSSL 3.4.x supported?3Grant Taylor
7 Jan 25 i  i`* Re: OpenSSL 3.4.x supported?2Claus Aßmann
7 Jan 25 i  i `- Re: OpenSSL 3.4.x supported?1Grant Taylor
8 Jan 25 i  `* Re: OpenSSL 3.4.x supported?3AMM
8 Jan 25 i   +- Re: OpenSSL 3.4.x supported?1Bjørn Mork
8 Jan 25 i   `- Re: OpenSSL 3.4.x supported?1Claus Aßmann
28 Dec 24 `- Re: OpenSSL 3.4.x supported?1HQuest

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal