Revisions of exim
Stephan Kulow (coolo)
accepted
request 139402
from
Lars Müller (lmuelle)
(revision 20)
- update to 4.80.1 - SECURITY: protect DKIM DNS decoding from remote exploit; CVE-2012-5671; (bnc#786652).
Ismail Dönmez (namtrac)
accepted
request 131173
from
Lars Müller (lmuelle)
(revision 19)
- update to 4.80 - Bugzilla 949 - Documentation tweak. - Bugzilla 1093 - eximstats DATA reject detection regexps improved. - Bugzilla 1169 - primary_hostname spelling was incorrect in docs. - Implemented gsasl authenticator. - Implemented heimdal_gssapi authenticator with "server_keytab" option. - Local/Makefile support for (AUTH|LOOKUP)_*_PC=foo to use `pkg-config foo` for cflags/libs. - Swapped $auth1/$auth2 for gsasl GSSAPI mechanism, to be more consistent with rest of GSASL and with heimdal_gssapi. - Local/Makefile support for USE_(GNUTLS|OPENSSL)_PC=foo to use `pkg-config foo` for cflags/libs for the TLS implementation. - New expansion variable $tls_bits; Cyrus SASL server connection properties get this fed in as external SSF. A number of robustness and debugging improvements to the cyrus_sasl authenticator. - cyrus_sasl server now expands the server_realm option. - Bugzilla 1214 - Log authentication information in reject log. - Added dbmjz lookup type. - Let heimdal_gssapi authenticator take a SASL message without an authzid. - MAIL args handles TAB as well as SP, for better interop with non-compliant senders. - Bugzilla 1237 - fix cases where printf format usage not indicated. - tls_peerdn now print-escaped for spool files. Observed some $tls_peerdn in wild which contained \n, which resulted in spool file corruption. - TLS fixes for OpenSSL: support TLS 1.1 & 1.2; new "openssl_options" values; set SSL_MODE_AUTO_RETRY so that OpenSSL will retry a read or write after TLS renegotiation, which otherwise led to messages "Got SSL error 2". - Bugzilla 1239 - fix DKIM verification when signature was not inserted as a tracking header (ie: a signed header comes before the signature). - Bugzilla 660 - Multi-valued attributes from ldap now parseable as a comma-sep list; embedded commas doubled. - Refactored ACL "verify =" logic to table-driven dispatch. - LDAP: Check for errors of TLS initialisation, to give correct diagnostics. - Removed "dont_insert_empty_fragments" fron "openssl_options". Removed SSL_clear() after SSL_new() which led to protocol negotiation failures. We appear to now support TLS1.1+ with Exim. - OpenSSL: new expansion var $tls_sni, which if used in tls_certificate lets Exim select keys and certificates based upon TLS SNI from client. Also option tls_sni on SMTP Transports. Also clear $tls_bits correctly before an outbound SMTP session. New log_selector, +tls_sni. - Bugzilla 1122 - check localhost_number expansion for failure, avoid NULL dereference. - Revert part of NM/04, it broke log_path containing %D expansions. Left warnings. Added "eximon gdb" invocation mode. - Defaulting "accept_8bitmime" to true, not false. - Added -bw for inetd wait mode support. - Added PCRE_CONFIG=yes support to Makefile for using pcre-config to locate the relevant includes and libraries. Made this the default. - Fixed headers_only on smtp transports (was not sending trailing dot). Bugzilla 1246, report and most of solution from Tomasz Kusy. - ${eval } now uses 64-bit and supports a "g" suffix (like to "k" and "m"). This may cause build issues on older platforms. - Revamped GnuTLS support, passing tls_require_ciphers to gnutls_priority_init, ignoring Exim options gnutls_require_kx, gnutls_require_mac & gnutls_require_protocols (no longer supported). Added SNI support via GnuTLS too. Made ${randint:..} supplier available, if using not-too-old GnuTLS. - Added EXPERIMENTAL_OCSP for OpenSSL. - Applied dnsdb SPF support patch from Janne Snabb. Applied second patch from Janne, implementing suggestion to default multiple-strings-in-record handling to match SPF spec. - Added expansion variable $tod_epoch_l for a higher-precision time. - Fix DCC dcc_header content corruption (stack memory referenced, read-only, out of scope). Patch from Wolfgang Breyha, report from Stuart Northfield. - Fix three issues highlighted by clang analyser static analysis. Only crash-plausible issue would require the Cambridge-specific iplookup router and a misconfiguration. Report from Marcin Mirosław. - Another attempt to deal with PCRE_PRERELEASE, this one less buggy. - %D in printf continues to cause issues (-Wformat=security), so for now guard some of the printf checks behind WANT_DEEPER_PRINTF_CHECKS. As part of this, removing so much warning spew let me fix some minor real issues in debug logging. - GnuTLS was always using default tls_require_ciphers, due to a missing assignment on my part. Fixed. - Added tls_dh_max_bits option, defaulting to current hard-coded limit of NSS, for GnuTLS/NSS interop. - Validate tls_require_ciphers on startup, since debugging an invalid string otherwise requires a connection and a bunch more work and it's relatively easy to get wrong. Should also expose TLS library linkage problems. - Pull in <features.h> on Linux, for some portability edge-cases of 64-bit ${eval} (JH/03). - Define _GNU_SOURCE in exim.h; it's needed for some releases of protection layer was required, which is not implemented. Bugzilla 1254 - Overhaul DH prime handling, supply RFC-specified DH primes as built into Exim, default to IKE id 23 from RFC 5114 (2048 bit). Make tls_dhparam take prime identifiers. Also unbreak combination of OpenSSL+DH_params+TLSSNI. - Disable SSLv2 by default in OpenSSL support.
Adrian Schröter (adrianSuSE)
committed
(revision 18)
branched from openSUSE:Factory
Stephan Kulow (coolo)
accepted
request 109834
from
Lars Müller (lmuelle)
(revision 17)
The reformating of the spec file was performed by osc build I guess. Also the reordering some lines of the package definition. As the removal of '# norootforbuild'. - Disable format-security and missing-format-attribute warnings via CFLAGS on pre-11.2 systems. - Remove obsoleted Authors lines from spec file. - update to 4.77 See the package changelog for the full history. - update to 4.77 See the package changelog for the full history. - Package /var/log/exim owned by user and group mail; (bnc#670711).
Stephan Kulow (coolo)
committed
(revision 16)
replace license with spdx.org variant
Adrian Schröter (adrianSuSE)
committed
(revision 15)
Sascha Peilicke (saschpe)
committed
(revision 14)
Autobuild autoformatter for 69936
Sascha Peilicke (saschpe)
accepted
request 69936
from
Cristian Rodríguez (elvigia)
(revision 13)
- check format strings (forwarded request 69894 from dirkmueller)
Sascha Peilicke (saschpe)
committed
(revision 12)
Autobuild autoformatter for 69839
Sascha Peilicke (saschpe)
accepted
request 69839
from
Lars Müller (lmuelle)
(revision 11)
- The new ldap_require_cert option would segfault if used; use upstream patch to address the ldap_set_option() issue; (beo#230); (beo#1108). - Cast third arg to void * when calling ldap_set_option(). - update to 4.75 - Don't pass DKIM compound log line as format string; (beo#1106); (bnc#692227).
Ruediger Oertel (oertel)
committed
(revision 10)
Autobuild autoformatter for 67025
Ruediger Oertel (oertel)
accepted
request 67025
from
Sascha Peilicke (saschpe)
(revision 9)
Accepted submit request 67025 from user dirkmueller
autobuild
committed
(revision 8)
11.4 source split
Ruediger Oertel (oertel)
committed
(revision 7)
Autobuild autoformatter for 60121
Ruediger Oertel (oertel)
accepted
request 60121
from
Lars Müller (lmuelle)
(revision 6)
Accepted submit request 60121 from user lmuelle
Marcus Rueckert (darix)
committed
(revision 5)
Autobuild autoformatter for 60084
Marcus Rueckert (darix)
accepted
request 60084
from
Lars Müller (lmuelle)
(revision 4)
Accepted submit request 60084 from user lmuelle
Marcus Rueckert (darix)
committed
(revision 3)
Autobuild autoformatter for 55626
Marcus Rueckert (darix)
accepted
request 55626
from
Lars Müller (lmuelle)
(revision 2)
Accepted submit request 55626 from user lmuelle
autobuild
accepted
request 44082
from
Marcus Rueckert (darix)
(revision 1)
Copy from server:mail/exim based on submit request 44082 from user darix
Displaying revisions 61 - 80 of 80