Re: TLSA debugging

2021-08-25 Thread Bastien Durel
Le mardi 24 août 2021 à 11:02 -0400, Viktor Dukhovni a écrit : > On Tue, Aug 24, 2021 at 04:24:30PM +0200, Bastien Durel wrote: > > Hello, > > > > Since I upgraded to debian 11 (postfix 3.5.6, was 3.4.14), my > > cluster > > fails inter-node deliveries. > > You probably need to set the "trust

Re: TLSA debugging

2021-08-24 Thread postfix
I guess we're not generating enough security bugs to trigger urgent updates. :-) Perhaps Debian needs a Postfix maintainer with more cycles to proactively keep it up to date? Or... Dovecot maintains their own repo (https://repo.dovecot.org/) for us common folk to add to our package managers

Re: TLSA debugging

2021-08-24 Thread Wietse Venema
Viktor Dukhovni: > > RES_TRUSTAD support was already released last January with Postfix > > 3.3.9, 3.4.11, and 3.5.1. So we already solved this 7 months ago. > > Why isn't this fix available in downstream distros? Woops, the fix was released by Apr 18, 2020 in Postfix 3.5.1, 3.4.11, 3.3.9. That

Re: TLSA debugging

2021-08-24 Thread Viktor Dukhovni
On Tue, Aug 24, 2021 at 02:28:12PM -0400, Wietse Venema wrote: > > I'll start adding RES_TRUSTAD support to the 3.3-3.5 stable releases. > > It will combine nicely with the OpenSSL 3.x bitrot patch. > > RES_TRUSTAD support was already released last January with Postfix > 3.3.9, 3.4.11, and

Re: TLSA debugging

2021-08-24 Thread Wietse Venema
Wietse Venema: > I'll start adding RES_TRUSTAD support to the 3.3-3.5 stable releases. > It will combine nicely with the OpenSSL 3.x bitrot patch. RES_TRUSTAD support was already released last January with Postfix 3.3.9, 3.4.11, and 3.5.1. So we already solved this 7 months ago. Why isn't this

Re: TLSA debugging

2021-08-24 Thread Wietse Venema
Viktor Dukhovni: > On Tue, Aug 24, 2021 at 11:32:01AM -0400, Wietse Venema wrote: > > > > You probably need to set the "trust AD" option in /etc/resolv.conf > > > > Postfix 3.6 has this comment in dns_lookup.c: > > ... > > Plus some plumbing in dns.h. > > > > Should we back-port this to the

Re: TLSA debugging

2021-08-24 Thread Viktor Dukhovni
On Tue, Aug 24, 2021 at 11:32:01AM -0400, Wietse Venema wrote: > > You probably need to set the "trust AD" option in /etc/resolv.conf > > Postfix 3.6 has this comment in dns_lookup.c: > > /* .IP RES_USE_DNSSEC > /* Request DNSSEC validation. This flag is silently ignored > /* when the

Re: TLSA debugging

2021-08-24 Thread Wietse Venema
Viktor Dukhovni: > On Tue, Aug 24, 2021 at 04:24:30PM +0200, Bastien Durel wrote: > > Hello, > > > > Since I upgraded to debian 11 (postfix 3.5.6, was 3.4.14), my cluster > > fails inter-node deliveries. > > You probably need to set the "trust AD" option in /etc/resolv.conf Postfix 3.6 has this

Re: TLSA debugging

2021-08-24 Thread Viktor Dukhovni
On Tue, Aug 24, 2021 at 04:24:30PM +0200, Bastien Durel wrote: > Hello, > > Since I upgraded to debian 11 (postfix 3.5.6, was 3.4.14), my cluster > fails inter-node deliveries. You probably need to set the "trust AD" option in /etc/resolv.conf

Re: TLSA debugging

2021-08-24 Thread Benny Pedersen
On 2021-08-24 16:24, Bastien Durel wrote: How can I find why these records are not found now ? chroot fails ? I've configured the inter-node relay in master.cf as this: lrelayunix - - y - - smtp -o sender_canonical_maps=fail: -o

TLSA debugging

2021-08-24 Thread Bastien Durel
Hello, Since I upgraded to debian 11 (postfix 3.5.6, was 3.4.14), my cluster fails inter-node deliveries. I have TLSA errors in logs: Aug 24 16:09:26 arrakeen postfix/cluster/smtp[992382]: warning: TLS policy lookup error for [corrin.geekwu.org]:26/corrin.geekwu.org: no TLSA records found Aug