Age | Commit message (Collapse) | Author | |
---|---|---|---|
2018-07-18 | Docs: clarify rolled-up dkim status availability in data ACL | Jeremy Harris | |
2018-07-13 | doc: DANE: don't claim TA can be elided from chain | Phil Pennock | |
While technically an implementation can choose to use a public TA from DNS or elsewhere to populate a missing TA from the chain, that creates interoperability issues and the OpenSSL integration code, at least, doesn't support that and after a bit of work drilling through layers of abstraction, I've not figured out what GnuTLS does and I've decided I don't care. So I'm heeding Viktor's advice and changing the docs to just say to publish the TA in the chain sent by the server. | |||
2018-07-10 | nit typo | Phil Pennock | |
2018-07-10 | Document problems with SHA-1 in certs with DANE-TA | Phil Pennock | |
Very few domains are using SHA-1 in EE certs issued from a CA used in DANE-TA anchoring, but some are. Meanwhile apparently GnuTLS now defaults to disabling SHA-1 in chains. Which is eminently reasonable. I do not believe that Exim should re-enable use of SHA-1 here. Let it die. Document with warnings that folks using a private CA for certs to be publicly trusted via DANE-TA should follow decent operational issuance practices. Also update my Channel Binding docs for GSASL to warn that Channel Binding is Broken™. | |||
2018-06-28 | Callouts: enhance debug message | Jeremy Harris | |
2018-06-28 | Testsuite: tweak instructions for running the suite | Jeremy Harris | |
2018-06-27 | Restore rsmapd support | Jeremy Harris | |
Following discussions on the exim-user mailinglist it seems that the conclusion that the interface was nonfunctioning was unwarranted. | |||
2018-06-26 | tidying | Jeremy Harris | |
2018-06-26 | Merge branch 'rspamd-removal' | Jeremy Harris | |
2018-06-26 | Revert "Support Rspamd. Patch from Andrew Lewis, lightly editorialised" | Jeremy Harris | |
This reverts commit c5f280e20a8e3ecd5f016b8fb34a436588915ed2. | |||
2018-06-26 | Revert "Rspamd: add $authenticated_id as User to scan command" | Jeremy Harris | |
This reverts commit 6c54be6459b83b955fbd2fd6d6a844f80c98427a. | |||
2018-06-26 | Revert "Spamd: add missing initialiser. Rspamd mode was incorrectly ↵ | Jeremy Harris | |
sometimes seen." This reverts commit e718bd6285cb0fb45b74b6fc00b7737590dcaa60. | |||
2018-06-26 | Revert "Do not use shutdown() when talking to rspamd. Fixes 1802" | Jeremy Harris | |
This reverts commit 416a0be6df0697848ca551dd3243b652e763792d. | |||
2018-06-26 | Revert "Testsuite: limited support for Content-length:" | Jeremy Harris | |
This reverts commit f6f239461fd62b3a4f3142b6b2a85f8f65eee486. | |||
2018-06-26 | Revert "Avoid repeated string-copy building command-string for rspamd" | Jeremy Harris | |
This reverts commit 5df838645bcdb135355205a115bf918c85987caf. | |||
2018-06-26 | Unbreak non-DANE build | Jeremy Harris | |
Broken-by: afdb5e9cf0 | |||
2018-06-25 | Expansions: A tls option on ${readsocket }. Bug 2282 | Jeremy Harris | |
2018-06-25 | ARC: Fix verification to do AS checks in reverse order | Jeremy Harris | |
Broken from the original introduction (617d39327e) | |||
2018-06-24 | Fix mutiple message send under TLS | Jeremy Harris | |
Broken-by: 74f1a42304 | |||
2018-06-24 | TLS: rework client-side use with an explicit context rather than a global | Jeremy Harris | |
2018-06-21 | Testsuite: workaround older-perl bug | Jeremy Harris | |
2018-06-21 | Testsuite: missing output files | Jeremy Harris | |
2018-06-21 | DKIM: Fix signing for body lines starting with a pair of dots. Bug 2284 | Jeremy Harris | |
Broken-by: 42055a3385 | |||
2018-06-21 | Docs: spelling | Kirill Miazine | |
2018-06-20 | OpenSSL: TLSv1.3 notes | Jeremy Harris | |
2018-06-14 | OpenSSL: enable use of TLS 1.3 (with OpenSSL 1.1.0 and later) | Jeremy Harris | |
2018-06-14 | Add client-ip info to non-pass iprev ${authres } lines | Jeremy Harris | |
2018-06-12 | Clarify the socket address family (UNIX) for server_socket (dovecot) | Heiko Schlittermann (HS12-RIPE) | |
Wishlist item (#2280) is created for INET connections. See https://bugs.exim.org/show_bug.cgi?id=2280 | |||
2018-06-09 | DKIM: support timestamp and expiry tags in signing. Bug 2260 | Jeremy Harris | |
2018-06-07 | Follow CNAME chains only one step. Bug 2264 | Jeremy Harris | |
2018-06-07 | ARC: Fix signing for case when DKIM signing failed | Jeremy Harris | |
2018-06-06 | Change-log | Jeremy Harris | |
2018-06-06 | Fix logging of cmdline args when starting in an unlinked cwd. Bug 2274 | Jeremy Harris | |
2018-05-24 | Use serial number 1 for self-generated selfsigned certificate | Jeremy Harris | |
Broken-by: 23bb69826c | |||
2018-05-20 | ARC: better diagnostics for keyfile issues | Jeremy Harris | |
2018-05-20 | DMARC: do not wipe values set by config options, between message receptions | Jeremy Harris | |
Broken-by: b4757e3611 | |||
2018-05-19 | Docs: add note on DKIM signing-limit security | Jeremy Harris | |
2018-05-19 | Safer handling of argument-logging memory of cwd | Phil Pennock | |
2018-05-16 | Testsuite: output changes arising | Jeremy Harris | |
2018-05-16 | Callouts: record succeeding random local-part tests. Bug 177 | Jeremy Harris | |
2018-05-16 | Content scanning: Fix locking on message spool files. Bug 2275 | Jeremy Harris | |
2018-05-15 | Don't open spool data-files which are symlinks | Phil Pennock | |
2018-05-11 | ARC: fix crash on signing with missing key file | Jeremy Harris | |
2018-05-09 | -bV: include the CONFIGURE_FILE path if it contains a ':' | Heiko Schlittermann (HS12-RIPE) | |
2018-05-07 | tidying | Jeremy Harris | |
2018-05-05 | Cutthrough: fix race resulting in duplicate-delivery. Bug 2273 | Jeremy Harris | |
2018-05-05 | tidying | Jeremy Harris | |
2018-05-03 | Fix typo in readconf.c | Heiko Schlittermann (HS12-RIPE) | |
2018-05-01 | Expansions: new ${lheader:<name>}. Bug 2272 | Jeremy Harris | |
2018-04-29 | tidying | Jeremy Harris | |