Age | Commit message (Collapse) | Author | |
---|---|---|---|
2018-04-15 | Enable weak/old stuff in OpenSSL | Phil Pennock | |
Configure OpenSSL with: enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers Include explanation as to why. | |||
2018-04-15 | Testsuite: syslog testcase | Jeremy Harris | |
2018-04-15 | Merge branch '4.next' | Jeremy Harris | |
2018-04-15 | Tidy logging code | Jeremy Harris | |
2018-04-15 | Clear more globals between messages | Jeremy Harris | |
2018-04-15 | Add client-ip info to iprev ${authres } line | Jeremy Harris | |
2018-04-15 | ARC: add optional x= tag to signing | Jeremy Harris | |
2018-04-15 | ARC: add optional t= tags to signing | Jeremy Harris | |
2018-04-15 | Avoid doing logging in signal-handlers. Bug 1007 | Jeremy Harris | |
2018-04-15 | Docs: clean for next release | Jeremy Harris | |
2018-04-15 | Testsuite: tidyup after myslq testingexim-4_91 | Jeremy Harris | |
2018-04-14 | Logging: fix syslog logging for syslog_timestamp=no and log_selector +millisec | Jeremy Harris | |
also syslog_pid=no and log_selector +pid | |||
2018-04-14 | Docs: typo | Jeremy Harris | |
2018-04-14 | Logging: fix syslog logging for syslog_timestamp=no and log_selector +millisec | Jeremy Harris | |
2018-04-13 | DKIM downgrade example again; this time debugged | Phil Pennock | |
As well as previous commit's `len_3` -> `length_3`, we were missing braces around the expansion operator, resulting in trying to dereference an unknown variable `$length_3`, and we were missing the outer braces from the `or` expansion condition. We really need a better way to test ACL expansion without a full harness. :( This bug-fixed version is now running on my system. | |||
2018-04-13 | Fix length expansion operator in DKIM downgrade example | Phil Pennock | |
2018-04-13 | DKIM: add support for the SubjectPublicKeyInfo wrapped form of pubkey | Jeremy Harris | |
2018-04-12 | Docs: add known broken-version info for OpenSSL behavior | Jeremy Harris | |
2018-04-11 | Mention MTA-STS in DANE context; nit fixes | Phil Pennock | |
Did an audit of text changed since commit 6aa6fc9c5 to look for issues which stood out, fixed those. Spelling mistakes, markup issues, minor grammatical infelicities. The public/private CA stuff in the DANE text might push people away from public CAs, but the existence of MTA-STS means that one of those is probably the best choice. Mention what exim.org does, to provide slightly firmer guidance without pressure. List the `dkim_hash` values, `sha512` appears to be new since that text was last touched. | |||
2018-04-11 | Doc: website updates and so forth | Phil Pennock | |
I've added <https://downloads.exim.org/> as a new vhost which doesn't reference FTP and loses the `/pub/exim` prefix. Fixed various other outdated claims and documented Jeremy's PGP key as the main key for releases, with mine (Phil's) and Heiko's as fallbacks. Mention the `.xz` files. | |||
2018-04-09 | Add `receive_time` to list of log_selector values | Phil Pennock | |
2018-04-09 | bugfix: heimdal interaction, check length | Phil Pennock | |
clang noted that taking the address of a struct member will never be 0, so checking against 0 was wrong. It was a `.length` member. I've compiled RC4 with this change and deployed it to my box and I can still authenticate fine. | |||
2018-04-09 | ARC: fix signing when DKIM-signing is also being done | Jeremy Harris | |
The ordering of headers being signed was wrong when a message being forwarded arrived with a dkim signature | |||
2018-04-09 | DMARC: fix history file | Jeremy Harris | |
Too many variables were being cleared between connections Broken-by: c780096c29 4.91 RC2 | |||
2018-04-08 | Better(?!?) fallback for stat: Perl | Phil Pennock | |
We use Perl extensively in other scripts. *sigh* | |||
2018-04-08 | stat portability | Phil Pennock | |
I forgot how much I loathe basic stuff like "get the size of a file, portably, in shell". Bleh. | |||
2018-04-08 | Added util/renew-opendmarc-tlds.sh script to renew PSL | Phil Pennock | |
2018-04-08 | OpenSSL: Revert the disabling of the session-cache. Bug 2255 | Jeremy Harris | |
Session cacheing is never useful, as we use a new context for every TLS startup. However, removing the support triggers odd behaviour from Outlook Express (only when there is an IMAP server on the same machine as Exim): an initial connect from the OE client fails, the immediate retry works. | |||
2018-04-07 | ARC: fix verify to not evaluate the top AMS twiceexim-4_91_RC4 | Jeremy Harris | |
2018-04-07 | Clear more globals between messages | Jeremy Harris | |
2018-04-06 | Logging: fix DKIM precis received log line element. | Jeremy Harris | |
Broken-by: 2c47372fad | |||
2018-04-04 | compiler quietening | Heiko Schlittermann (HS12-RIPE) | |
2018-04-04 | Add client-ip info to iprev ${authres } line | Jeremy Harris | |
2018-04-04 | compiler quietening | Jeremy Harris | |
2018-04-04 | Actually reap node2 process in redis cluster test | Graeme Fowler | |
2018-04-04 | ARC: add optional x= tag to signing | Jeremy Harris | |
2018-04-04 | local_scan: add note on Makefile requirement | Jeremy Harris | |
2018-04-04 | ARC: add optional t= tags to signing | Jeremy Harris | |
2018-04-04 | ARC: log signing-spec errors in mainlog only, not paniclog | Jeremy Harris | |
2018-04-04 | ARC: enhance debug for signing; explicitly init signing context | Jeremy Harris | |
2018-04-04 | Fix non-ARC build | Jeremy Harris | |
2018-04-04 | ARC: add guard in verify against lack of the dkim-verify context | Jeremy Harris | |
needed for body-hashing | |||
2018-04-04 | ARC: cutthrough delivery may not be used with ARC signing | Jeremy Harris | |
2018-04-04 | Cutthrough: enforce non-use in combination with DKIM signing or transport filter | Jeremy Harris | |
Broken-by: 02b41d7106 | |||
2018-04-04 | Add ARC signing caveats | Phil Pennock | |
2018-04-04 | ARC: give more detail with "bad signing-spec" message | Jeremy Harris | |
2018-04-04 | ARC: For signing, accept A-R header lacking ARC info as equivalent to "none" | Jeremy Harris | |
2018-04-04 | ARC: add independent-source testcase. Fix signatures by not line-terminating | Jeremy Harris | |
last header line being hashed. | |||
2018-04-04 | ARC: AS header should have no c= tag | Jeremy Harris | |
2018-04-04 | ARC: on the smtp transport option take empty or forced-fail to disable signing | Jeremy Harris | |