Re: [mailop] [EXTERNAL] Disabling TLS 1.0 and 1.1 for MTA to MTA communication

2022-08-05 Thread Michael Rathbun via mailop
On 4 Aug 2022 15:29:52 -0400, John Levine via mailop wrote: >If my logs are at all typical, there are no large entities still using >TLS 1.0. I see a lot of spambots, some compromised VPS at the usual >suspects like OVH, one well-known IETFer who knows that he needs to >update his mail server,

Re: [mailop] Google still using SHA1 (and forcing it)?

2022-08-05 Thread Vsevolod Stakhov via mailop
On 04/08/2022 16:12, Chris Adams via mailop wrote: I ran into an issue at $DAYJOB where we had a hard-coded TLS version and ciphersuite set connecting to Google (specifically aspmx.l.google.com). The problem turned out to be a library upgrade had disabled SHA1, so the TLS hello handshake failed.

Re: [mailop] What to do with a look-alike domain used in phishing

2022-08-05 Thread Henry Yen via mailop
A fellow named Mike Andrews used to offer to take over domains once used by, or likely to be used be, spam and malware. I had once grabbed an expired domain used by a spammer network, and I was glad to transfer it over to him rather than continue to pay the annual fee myself. On Mon, Jul 18, 2022