Revisions of exim

Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 139402 from Lars Müller's avatar Lars Müller (lmuelle) (revision 20)
- update to 4.80.1
  - SECURITY: protect DKIM DNS decoding from remote exploit; CVE-2012-5671;
    (bnc#786652).
Ismail Dönmez's avatar Ismail Dönmez (namtrac) accepted request 131173 from Lars Müller's avatar Lars Müller (lmuelle) (revision 19)
- update to 4.80
  - Bugzilla 949 - Documentation tweak.
  - Bugzilla 1093 - eximstats DATA reject detection regexps improved.
  - Bugzilla 1169 - primary_hostname spelling was incorrect in docs.
  - Implemented gsasl authenticator.
  - Implemented heimdal_gssapi authenticator with "server_keytab" option.
  - Local/Makefile support for (AUTH|LOOKUP)_*_PC=foo to use
    `pkg-config foo` for cflags/libs.
  - Swapped $auth1/$auth2 for gsasl GSSAPI mechanism, to be more consistent
    with rest of GSASL and with heimdal_gssapi.
  - Local/Makefile support for USE_(GNUTLS|OPENSSL)_PC=foo to use
    `pkg-config foo` for cflags/libs for the TLS implementation.
  - New expansion variable $tls_bits; Cyrus SASL server connection
    properties get this fed in as external SSF.  A number of robustness
    and debugging improvements to the cyrus_sasl authenticator.
  - cyrus_sasl server now expands the server_realm option.
  - Bugzilla 1214 - Log authentication information in reject log.
  - Added dbmjz lookup type.
  - Let heimdal_gssapi authenticator take a SASL message without an authzid.
  - MAIL args handles TAB as well as SP, for better interop with
    non-compliant senders.
  - Bugzilla 1237 - fix cases where printf format usage not indicated.
  - tls_peerdn now print-escaped for spool files.
    Observed some $tls_peerdn in wild which contained \n, which resulted
    in spool file corruption.
  - TLS fixes for OpenSSL: support TLS 1.1 & 1.2; new "openssl_options"
    values; set SSL_MODE_AUTO_RETRY so that OpenSSL will retry a read
    or write after TLS renegotiation, which otherwise led to messages
    "Got SSL error 2".
  - Bugzilla 1239 - fix DKIM verification when signature was not inserted
    as a tracking header (ie: a signed header comes before the signature).
  - Bugzilla 660 - Multi-valued attributes from ldap now parseable as a
    comma-sep list; embedded commas doubled.
  - Refactored ACL "verify =" logic to table-driven dispatch.
  - LDAP: Check for errors of TLS initialisation, to give correct diagnostics.
  - Removed "dont_insert_empty_fragments" fron "openssl_options".
    Removed SSL_clear() after SSL_new() which led to protocol negotiation
    failures.  We appear to now support TLS1.1+ with Exim.
  - OpenSSL: new expansion var $tls_sni, which if used in tls_certificate
    lets Exim select keys and certificates based upon TLS SNI from client.
    Also option tls_sni on SMTP Transports.  Also clear $tls_bits correctly
    before an outbound SMTP session.  New log_selector, +tls_sni.
  - Bugzilla 1122 - check localhost_number expansion for failure, avoid
    NULL dereference.
  - Revert part of NM/04, it broke log_path containing %D expansions.
    Left warnings.  Added "eximon gdb" invocation mode.
  - Defaulting "accept_8bitmime" to true, not false.
  - Added -bw for inetd wait mode support.
  - Added PCRE_CONFIG=yes support to Makefile for using pcre-config to
    locate the relevant includes and libraries.  Made this the default.
  - Fixed headers_only on smtp transports (was not sending trailing dot).
    Bugzilla 1246, report and most of solution from Tomasz Kusy.
  - ${eval } now uses 64-bit and supports a "g" suffix (like to "k" and "m").
    This may cause build issues on older platforms.
  - Revamped GnuTLS support, passing tls_require_ciphers to
    gnutls_priority_init, ignoring Exim options gnutls_require_kx,
    gnutls_require_mac & gnutls_require_protocols (no longer supported).
    Added SNI support via GnuTLS too.
    Made ${randint:..} supplier available, if using not-too-old GnuTLS.
  - Added EXPERIMENTAL_OCSP for OpenSSL.
  - Applied dnsdb SPF support patch from Janne Snabb.
    Applied second patch from Janne, implementing suggestion to default
    multiple-strings-in-record handling to match SPF spec.
  - Added expansion variable $tod_epoch_l for a higher-precision time.
  - Fix DCC dcc_header content corruption (stack memory referenced,
    read-only, out of scope).
    Patch from Wolfgang Breyha, report from Stuart Northfield.
  - Fix three issues highlighted by clang analyser static analysis.
    Only crash-plausible issue would require the Cambridge-specific
    iplookup router and a misconfiguration.
    Report from Marcin Mirosław.
  - Another attempt to deal with PCRE_PRERELEASE, this one less buggy.
  - %D in printf continues to cause issues (-Wformat=security), so for
    now guard some of the printf checks behind WANT_DEEPER_PRINTF_CHECKS.
    As part of this, removing so much warning spew let me fix some minor
    real issues in debug logging.
  - GnuTLS was always using default tls_require_ciphers, due to a missing
    assignment on my part.  Fixed.
  - Added tls_dh_max_bits option, defaulting to current hard-coded limit
    of NSS, for GnuTLS/NSS interop.
  - Validate tls_require_ciphers on startup, since debugging an invalid
    string otherwise requires a connection and a bunch more work and it's
    relatively easy to get wrong.  Should also expose TLS library linkage
    problems.
  - Pull in <features.h> on Linux, for some portability edge-cases of
    64-bit ${eval} (JH/03).
  - Define _GNU_SOURCE in exim.h; it's needed for some releases of
    protection layer was required, which is not implemented.  Bugzilla 1254
  - Overhaul DH prime handling, supply RFC-specified DH primes as built
    into Exim, default to IKE id 23 from RFC 5114 (2048 bit).  Make
    tls_dhparam take prime identifiers.  Also unbreak combination of
    OpenSSL+DH_params+TLSSNI.
  - Disable SSLv2 by default in OpenSSL support.
Adrian Schröter's avatar Adrian Schröter (adrianSuSE) committed (revision 18)
branched from openSUSE:Factory
Stephan Kulow's avatar Stephan Kulow (coolo) accepted request 109834 from Lars Müller's avatar Lars Müller (lmuelle) (revision 17)
The reformating of the spec file was performed by osc build I guess.
Also the reordering some lines of the package definition.
As the removal of '# norootforbuild'.

- Disable format-security and missing-format-attribute warnings via CFLAGS on
  pre-11.2 systems.
- Remove obsoleted Authors lines from spec file.
- update to 4.77
  See the package changelog for the full history.
- update to 4.77
  See the package changelog for the full history.
- Package /var/log/exim owned by user and group mail; (bnc#670711).
Stephan Kulow's avatar Stephan Kulow (coolo) committed (revision 16)
replace license with spdx.org variant
Adrian Schröter's avatar Adrian Schröter (adrianSuSE) committed (revision 15)
Sascha Peilicke's avatar Sascha Peilicke (saschpe) committed (revision 14)
Autobuild autoformatter for 69936
Sascha Peilicke's avatar Sascha Peilicke (saschpe) accepted request 69936 from Cristian Rodríguez's avatar Cristian Rodríguez (elvigia) (revision 13)
- check format strings (forwarded request 69894 from dirkmueller)
Sascha Peilicke's avatar Sascha Peilicke (saschpe) committed (revision 12)
Autobuild autoformatter for 69839
Sascha Peilicke's avatar Sascha Peilicke (saschpe) accepted request 69839 from Lars Müller's avatar Lars Müller (lmuelle) (revision 11)
- The new ldap_require_cert option would segfault if used; use upstream patch
  to address the ldap_set_option() issue; (beo#230); (beo#1108).
- Cast third arg to void * when calling ldap_set_option().
- update to 4.75
- Don't pass DKIM compound log line as format string; (beo#1106); (bnc#692227).
Ruediger Oertel's avatar Ruediger Oertel (oertel) committed (revision 10)
Autobuild autoformatter for 67025
Ruediger Oertel's avatar Ruediger Oertel (oertel) accepted request 67025 from Sascha Peilicke's avatar Sascha Peilicke (saschpe) (revision 9)
Accepted submit request 67025 from user dirkmueller
autobuild's avatar autobuild committed (revision 8)
11.4 source split
Ruediger Oertel's avatar Ruediger Oertel (oertel) committed (revision 7)
Autobuild autoformatter for 60121
Ruediger Oertel's avatar Ruediger Oertel (oertel) accepted request 60121 from Lars Müller's avatar Lars Müller (lmuelle) (revision 6)
Accepted submit request 60121 from user lmuelle
Marcus Rueckert's avatar Marcus Rueckert (darix) committed (revision 5)
Autobuild autoformatter for 60084
Marcus Rueckert's avatar Marcus Rueckert (darix) accepted request 60084 from Lars Müller's avatar Lars Müller (lmuelle) (revision 4)
Accepted submit request 60084 from user lmuelle
Marcus Rueckert's avatar Marcus Rueckert (darix) committed (revision 3)
Autobuild autoformatter for 55626
Marcus Rueckert's avatar Marcus Rueckert (darix) accepted request 55626 from Lars Müller's avatar Lars Müller (lmuelle) (revision 2)
Accepted submit request 55626 from user lmuelle
autobuild's avatar autobuild accepted request 44082 from Marcus Rueckert's avatar Marcus Rueckert (darix) (revision 1)
Copy from server:mail/exim based on submit request 44082 from user darix
Displaying revisions 61 - 80 of 80
openSUSE Build Service is sponsored by