head 1.1; branch 1.1.1; access; symbols netbsd-10-2-RELEASE:1.1.1.11.2.1 netbsd-9-5-RELEASE:1.1.1.9.14.1 netbsd-11-0-RELEASE:1.1.1.13.2.1 netbsd-11-0-RC7:1.1.1.13.2.1 netbsd-11-0-RC6:1.1.1.13.2.1 netbsd-11-0-RC5:1.1.1.13.2.1 netbsd-11-0-RC4:1.1.1.13.2.1 PFIX-3-11-2:1.1.1.14 netbsd-11-0-RC3:1.1.1.13 netbsd-11-0-RC2:1.1.1.13 netbsd-11-0-RC1:1.1.1.13 perseant-exfatfs-base-20250801:1.1.1.13 netbsd-11:1.1.1.13.0.2 netbsd-11-base:1.1.1.13 PFIX-3-10-1:1.1.1.13 netbsd-10-1-RELEASE:1.1.1.11.2.1 perseant-exfatfs-base-20240630:1.1.1.12 perseant-exfatfs:1.1.1.12.0.2 perseant-exfatfs-base:1.1.1.12 netbsd-8-3-RELEASE:1.1.1.9 netbsd-9-4-RELEASE:1.1.1.9.14.1 netbsd-10-0-RELEASE:1.1.1.11.2.1 netbsd-10-0-RC6:1.1.1.11.2.1 netbsd-10-0-RC5:1.1.1.11.2.1 netbsd-10-0-RC4:1.1.1.11.2.1 netbsd-10-0-RC3:1.1.1.11.2.1 netbsd-10-0-RC2:1.1.1.11.2.1 PFIX-3-8-4:1.1.1.12 netbsd-10-0-RC1:1.1.1.11 netbsd-10:1.1.1.11.0.2 netbsd-10-base:1.1.1.11 PFIX-3-7-3:1.1.1.11 netbsd-9-3-RELEASE:1.1.1.9 cjep_sun2x-base1:1.1.1.10 cjep_sun2x:1.1.1.10.0.4 cjep_sun2x-base:1.1.1.10 cjep_staticlib_x-base1:1.1.1.10 netbsd-9-2-RELEASE:1.1.1.9 cjep_staticlib_x:1.1.1.10.0.2 cjep_staticlib_x-base:1.1.1.10 netbsd-9-1-RELEASE:1.1.1.9 PFIX-3-5-2:1.1.1.10 phil-wifi-20200421:1.1.1.10 phil-wifi-20200411:1.1.1.10 is-mlppp:1.1.1.9.0.16 is-mlppp-base:1.1.1.9 phil-wifi-20200406:1.1.1.10 netbsd-8-2-RELEASE:1.1.1.9 PFIX-3-5-0:1.1.1.10 netbsd-9-0-RELEASE:1.1.1.9 netbsd-9-0-RC2:1.1.1.9 netbsd-9-0-RC1:1.1.1.9 phil-wifi-20191119:1.1.1.9 netbsd-9:1.1.1.9.0.14 netbsd-9-base:1.1.1.9 phil-wifi-20190609:1.1.1.9 netbsd-8-1-RELEASE:1.1.1.9 netbsd-8-1-RC1:1.1.1.9 pgoyette-compat-merge-20190127:1.1.1.9 pgoyette-compat-20190127:1.1.1.9 pgoyette-compat-20190118:1.1.1.9 pgoyette-compat-1226:1.1.1.9 pgoyette-compat-1126:1.1.1.9 pgoyette-compat-1020:1.1.1.9 pgoyette-compat-0930:1.1.1.9 pgoyette-compat-0906:1.1.1.9 netbsd-7-2-RELEASE:1.1.1.7 pgoyette-compat-0728:1.1.1.9 netbsd-8-0-RELEASE:1.1.1.9 phil-wifi:1.1.1.9.0.12 phil-wifi-base:1.1.1.9 pgoyette-compat-0625:1.1.1.9 netbsd-8-0-RC2:1.1.1.9 pgoyette-compat-0521:1.1.1.9 pgoyette-compat-0502:1.1.1.9 pgoyette-compat-0422:1.1.1.9 netbsd-8-0-RC1:1.1.1.9 pgoyette-compat-0415:1.1.1.9 pgoyette-compat-0407:1.1.1.9 pgoyette-compat-0330:1.1.1.9 pgoyette-compat-0322:1.1.1.9 pgoyette-compat-0315:1.1.1.9 netbsd-7-1-2-RELEASE:1.1.1.7 pgoyette-compat:1.1.1.9.0.10 pgoyette-compat-base:1.1.1.9 netbsd-7-1-1-RELEASE:1.1.1.7 matt-nb8-mediatek:1.1.1.9.0.8 matt-nb8-mediatek-base:1.1.1.9 perseant-stdc-iso10646:1.1.1.9.0.6 perseant-stdc-iso10646-base:1.1.1.9 netbsd-8:1.1.1.9.0.4 netbsd-8-base:1.1.1.9 prg-localcount2-base3:1.1.1.9 prg-localcount2-base2:1.1.1.9 prg-localcount2-base1:1.1.1.9 prg-localcount2:1.1.1.9.0.2 prg-localcount2-base:1.1.1.9 pgoyette-localcount-20170426:1.1.1.9 bouyer-socketcan-base1:1.1.1.9 pgoyette-localcount-20170320:1.1.1.9 netbsd-7-1:1.1.1.7.0.8 netbsd-7-1-RELEASE:1.1.1.7 netbsd-7-1-RC2:1.1.1.7 PFIX-3-1-4:1.1.1.9 netbsd-7-nhusb-base-20170116:1.1.1.7 bouyer-socketcan:1.1.1.8.0.4 bouyer-socketcan-base:1.1.1.8 pgoyette-localcount-20170107:1.1.1.8 netbsd-7-1-RC1:1.1.1.7 pgoyette-localcount-20161104:1.1.1.8 netbsd-7-0-2-RELEASE:1.1.1.7 localcount-20160914:1.1.1.8 netbsd-7-nhusb:1.1.1.7.0.6 netbsd-7-nhusb-base:1.1.1.7 pgoyette-localcount-20160806:1.1.1.8 pgoyette-localcount-20160726:1.1.1.8 pgoyette-localcount:1.1.1.8.0.2 pgoyette-localcount-base:1.1.1.8 netbsd-7-0-1-RELEASE:1.1.1.7 netbsd-7-0:1.1.1.7.0.4 netbsd-7-0-RELEASE:1.1.1.7 PFIX-2-11-6:1.1.1.8 netbsd-7-0-RC3:1.1.1.7 netbsd-7-0-RC2:1.1.1.7 netbsd-7-0-RC1:1.1.1.7 PFIX-2-11-4:1.1.1.7 PFIX-2-11-3:1.1.1.7 netbsd-5-2-3-RELEASE:1.1.1.1.2.3 netbsd-5-1-5-RELEASE:1.1.1.1.2.2 netbsd-6-0-6-RELEASE:1.1.1.3.6.1 netbsd-6-1-5-RELEASE:1.1.1.3.6.1 netbsd-7:1.1.1.7.0.2 netbsd-7-base:1.1.1.7 PFIX-2-11-1:1.1.1.7 yamt-pagecache-base9:1.1.1.6 yamt-pagecache-tag8:1.1.1.3.4.2 netbsd-6-1-4-RELEASE:1.1.1.3.6.1 netbsd-6-0-5-RELEASE:1.1.1.3.6.1 tls-earlyentropy:1.1.1.6.0.2 tls-earlyentropy-base:1.1.1.7 riastradh-xf86-video-intel-2-7-1-pre-2-21-15:1.1.1.6 riastradh-drm2-base3:1.1.1.6 PFIX-2-10-3:1.1.1.6 netbsd-6-1-3-RELEASE:1.1.1.3.6.1 netbsd-6-0-4-RELEASE:1.1.1.3.6.1 netbsd-5-2-2-RELEASE:1.1.1.1.2.3 netbsd-5-1-4-RELEASE:1.1.1.1.2.2 netbsd-6-1-2-RELEASE:1.1.1.3.6.1 netbsd-6-0-3-RELEASE:1.1.1.3.6.1 PFIX-2-10-2:1.1.1.6 netbsd-5-2-1-RELEASE:1.1.1.1.2.3 netbsd-5-1-3-RELEASE:1.1.1.1.2.2 PFIX-2-9-7:1.1.1.5 netbsd-6-1-1-RELEASE:1.1.1.3.6.1 riastradh-drm2-base2:1.1.1.5 riastradh-drm2-base1:1.1.1.5 riastradh-drm2:1.1.1.5.0.2 riastradh-drm2-base:1.1.1.5 netbsd-6-1:1.1.1.3.6.1.0.6 netbsd-6-0-2-RELEASE:1.1.1.3.6.1 netbsd-6-1-RELEASE:1.1.1.3.6.1 netbsd-6-1-RC4:1.1.1.3.6.1 netbsd-6-1-RC3:1.1.1.3.6.1 agc-symver:1.1.1.5.0.4 agc-symver-base:1.1.1.5 netbsd-6-1-RC2:1.1.1.3.6.1 netbsd-6-1-RC1:1.1.1.3.6.1 yamt-pagecache-base8:1.1.1.5 PFIX-2-9-5:1.1.1.5 netbsd-5-2:1.1.1.1.2.3.0.4 PFIX-2-8-13:1.1.1.4 netbsd-6-0-1-RELEASE:1.1.1.3.6.1 yamt-pagecache-base7:1.1.1.4 netbsd-5-2-RELEASE:1.1.1.1.2.3 netbsd-5-2-RC1:1.1.1.1.2.3 matt-nb6-plus-nbase:1.1.1.3.6.1 yamt-pagecache-base6:1.1.1.4 netbsd-6-0:1.1.1.3.6.1.0.4 netbsd-6-0-RELEASE:1.1.1.3.6.1 netbsd-6-0-RC2:1.1.1.3.6.1 tls-maxphys:1.1.1.4.0.2 tls-maxphys-base:1.1.1.7 matt-nb6-plus:1.1.1.3.6.1.0.2 matt-nb6-plus-base:1.1.1.3.6.1 netbsd-6-0-RC1:1.1.1.3.6.1 PFIX-2-8-12:1.1.1.4 PFIX-2-8-11:1.1.1.4 yamt-pagecache-base5:1.1.1.3 yamt-pagecache-base4:1.1.1.3 PFIX-2-8-8:1.1.1.3 netbsd-6:1.1.1.3.0.6 netbsd-6-base:1.1.1.3 netbsd-5-1-2-RELEASE:1.1.1.1.2.2 netbsd-5-1-1-RELEASE:1.1.1.1.2.2 yamt-pagecache-base3:1.1.1.3 PFIX-2-8-7:1.1.1.3 yamt-pagecache-base2:1.1.1.3 yamt-pagecache:1.1.1.3.0.4 yamt-pagecache-base:1.1.1.3 PFIX-2-8-6:1.1.1.3 PFIX-2-8-5:1.1.1.3 PFIX-2-8-4:1.1.1.3 cherry-xenmp:1.1.1.3.0.2 cherry-xenmp-base:1.1.1.3 PFIX-2-8-3:1.1.1.3 PFIX-2-8-2:1.1.1.3 PFIX-2-8-1:1.1.1.3 bouyer-quota2-nbase:1.1.1.3 bouyer-quota2:1.1.1.2.0.2 bouyer-quota2-base:1.1.1.2 matt-mips64-premerge-20101231:1.1.1.2 matt-nb5-mips64-premerge-20101231:1.1.1.1.4.2 matt-nb5-pq3:1.1.1.1.2.3.0.2 matt-nb5-pq3-base:1.1.1.1.2.3 PFIX-2-7-2:1.1.1.2 netbsd-5-1:1.1.1.1.2.2.0.2 netbsd-5-1-RELEASE:1.1.1.1.2.2 netbsd-5-1-RC4:1.1.1.1.2.2 matt-nb5-mips64-k15:1.1.1.1.4.2 PFIX-2-7-1:1.1.1.2 netbsd-5-1-RC3:1.1.1.1.2.2 netbsd-5-1-RC2:1.1.1.1.2.2 netbsd-5-1-RC1:1.1.1.1.2.2 matt-nb5-mips64:1.1.1.1.0.4 PFIX-2-6-6:1.1.1.1 matt-premerge-20091211:1.1.1.1 netbsd-5:1.1.1.1.0.2 PFIX-2-6-5:1.1.1.1 PFIX-2-6-2:1.1.1.1 VENEMA:1.1.1; locks; strict; comment @# @; 1.1 date 2009.06.23.10.08.28; author tron; state Exp; branches 1.1.1.1; next ; 1.1.1.1 date 2009.06.23.10.08.28; author tron; state Exp; branches 1.1.1.1.2.1 1.1.1.1.4.1; next 1.1.1.2; 1.1.1.2 date 2010.06.17.18.06.16; author tron; state Exp; branches 1.1.1.2.2.1; next 1.1.1.3; 1.1.1.3 date 2011.03.02.19.31.40; author tron; state Exp; branches 1.1.1.3.4.1 1.1.1.3.6.1; next 1.1.1.4; 1.1.1.4 date 2012.06.09.11.26.49; author tron; state Exp; branches 1.1.1.4.2.1; next 1.1.1.5; 1.1.1.5 date 2013.01.02.18.58.39; author tron; state Exp; branches; next 1.1.1.6; 1.1.1.6 date 2013.09.25.19.06.22; author tron; state Exp; branches 1.1.1.6.2.1; next 1.1.1.7; commitid WQnWePIKINywUQ6x; 1.1.1.7 date 2014.07.06.19.27.42; author tron; state Exp; branches; next 1.1.1.8; commitid 5TVMY9WFpCELTlHx; 1.1.1.8 date 2015.09.12.08.20.31; author tron; state Exp; branches 1.1.1.8.2.1 1.1.1.8.4.1; next 1.1.1.9; commitid EZWRFaJwyOgZhWAy; 1.1.1.9 date 2017.02.14.01.13.36; author christos; state Exp; branches 1.1.1.9.12.1 1.1.1.9.14.1; next 1.1.1.10; commitid 3GKuOxtmc3XhbRFz; 1.1.1.10 date 2020.03.18.18.59.28; author christos; state Exp; branches; next 1.1.1.11; commitid hRc0KjfEXOv3PU0C; 1.1.1.11 date 2022.10.08.16.09.02; author christos; state Exp; branches 1.1.1.11.2.1; next 1.1.1.12; commitid kRUbAM0nqDWDQVWD; 1.1.1.12 date 2023.12.23.20.24.49; author christos; state Exp; branches 1.1.1.12.2.1; next 1.1.1.13; commitid b1hV92WYdEWo2DRE; 1.1.1.13 date 2025.02.25.19.11.37; author christos; state Exp; branches 1.1.1.13.2.1; next 1.1.1.14; commitid cLFKwpXD6DqXOSKF; 1.1.1.14 date 2026.05.09.18.39.12; author christos; state Exp; branches; next ; commitid mtbvlXzNqJaszaFG; 1.1.1.1.2.1 date 2009.06.23.10.08.28; author snj; state dead; branches; next 1.1.1.1.2.2; 1.1.1.1.2.2 date 2009.09.15.06.02.14; author snj; state Exp; branches; next 1.1.1.1.2.3; 1.1.1.1.2.3 date 2010.11.21.18.31.24; author riz; state Exp; branches; next ; 1.1.1.1.4.1 date 2009.06.23.10.08.28; author matt; state dead; branches; next 1.1.1.1.4.2; 1.1.1.1.4.2 date 2010.04.21.05.23.31; author matt; state Exp; branches; next ; 1.1.1.2.2.1 date 2011.03.05.15.08.54; author bouyer; state Exp; branches; next ; 1.1.1.3.4.1 date 2012.10.30.18.58.00; author yamt; state Exp; branches; next 1.1.1.3.4.2; 1.1.1.3.4.2 date 2013.01.23.00.04.52; author yamt; state Exp; branches; next 1.1.1.3.4.3; 1.1.1.3.4.3 date 2014.05.22.14.08.01; author yamt; state Exp; branches; next ; commitid cuVqdlp1QcvUzxBx; 1.1.1.3.6.1 date 2012.06.13.19.28.57; author riz; state Exp; branches; next ; 1.1.1.4.2.1 date 2013.02.25.00.27.08; author tls; state Exp; branches; next 1.1.1.4.2.2; 1.1.1.4.2.2 date 2014.08.19.23.59.41; author tls; state Exp; branches; next ; commitid jTnpym9Qu0o4R1Nx; 1.1.1.6.2.1 date 2014.08.10.07.12.47; author tls; state Exp; branches; next ; commitid 0tNMy3UM0qm8IMLx; 1.1.1.8.2.1 date 2017.03.20.06.56.34; author pgoyette; state Exp; branches; next ; commitid jjw7cAwgyKq7RfKz; 1.1.1.8.4.1 date 2017.04.21.16.52.45; author bouyer; state Exp; branches; next ; commitid dUG7nkTKALCadqOz; 1.1.1.9.12.1 date 2020.04.08.14.06.50; author martin; state Exp; branches; next ; commitid Qli2aW9E74UFuA3C; 1.1.1.9.14.1 date 2023.12.25.12.54.36; author martin; state Exp; branches; next ; commitid yzNdlh5ioUjfxQRE; 1.1.1.11.2.1 date 2023.12.25.12.43.24; author martin; state Exp; branches; next ; commitid UCTK9IHygwOntQRE; 1.1.1.12.2.1 date 2025.08.02.05.49.52; author perseant; state Exp; branches; next ; commitid 23j6GFaDws3O875G; 1.1.1.13.2.1 date 2026.05.11.17.13.38; author martin; state Exp; branches; next ; commitid 2QeqaJm8KrXk4qFG; desc @@ 1.1 log @Initial revision @ text @
SMTP(8) SMTP(8)
NAME
smtp - Postfix SMTP+LMTP client
SYNOPSIS
smtp [generic Postfix daemon options]
DESCRIPTION
The Postfix SMTP+LMTP client implements the SMTP and LMTP
mail delivery protocols. It processes message delivery
requests from the queue manager. Each request specifies a
queue file, a sender address, a domain or host to deliver
to, and recipient information. This program expects to be
run from the master(8) process manager.
The SMTP+LMTP client updates the queue file and marks
recipients as finished, or it informs the queue manager
that delivery should be tried again at a later time.
Delivery status reports are sent to the bounce(8),
defer(8) or trace(8) daemon as appropriate.
The SMTP+LMTP client looks up a list of mail exchanger
addresses for the destination host, sorts the list by
preference, and connects to each listed address until it
finds a server that responds.
When a server is not reachable, or when mail delivery
fails due to a recoverable error condition, the SMTP+LMTP
client will try to deliver the mail to an alternate host.
After a successful mail transaction, a connection may be
saved to the scache(8) connection cache server, so that it
may be used by any SMTP+LMTP client for a subsequent
transaction.
By default, connection caching is enabled temporarily for
destinations that have a high volume of mail in the active
queue. Connection caching can be enabled permanently for
specific destinations.
SMTP DESTINATION SYNTAX
SMTP destinations have the following form:
domainname
domainname:port
Look up the mail exchangers for the specified
domain, and connect to the specified port (default:
smtp).
[hostname]
[hostname]:port
Look up the address(es) of the specified host, and
connect to the specified port (default: smtp).
[address]
[address]:port
Connect to the host at the specified address, and
connect to the specified port (default: smtp). An
IPv6 address must be formatted as [ipv6:address].
LMTP DESTINATION SYNTAX
LMTP destinations have the following form:
unix:pathname
Connect to the local UNIX-domain server that is
bound to the specified pathname. If the process
runs chrooted, an absolute pathname is interpreted
relative to the Postfix queue directory.
inet:hostname
inet:hostname:port
inet:[address]
inet:[address]:port
Connect to the specified TCP port on the specified
local or remote host. If no port is specified, con-
nect to the port defined as lmtp in services(4).
If no such service is found, the lmtp_tcp_port con-
figuration parameter (default value of 24) will be
used. An IPv6 address must be formatted as
[ipv6:address].
SECURITY
The SMTP+LMTP client is moderately security-sensitive. It
talks to SMTP or LMTP servers and to DNS servers on the
network. The SMTP+LMTP client can be run chrooted at fixed
low privilege.
STANDARDS
RFC 821 (SMTP protocol)
RFC 822 (ARPA Internet Text Messages)
RFC 1651 (SMTP service extensions)
RFC 1652 (8bit-MIME transport)
RFC 1870 (Message Size Declaration)
RFC 2033 (LMTP protocol)
RFC 2034 (SMTP Enhanced Error Codes)
RFC 2045 (MIME: Format of Internet Message Bodies)
RFC 2046 (MIME: Media Types)
RFC 2554 (AUTH command)
RFC 2821 (SMTP protocol)
RFC 2920 (SMTP Pipelining)
RFC 3207 (STARTTLS command)
RFC 3461 (SMTP DSN Extension)
RFC 3463 (Enhanced Status Codes)
RFC 4954 (AUTH command)
DIAGNOSTICS
Problems and transactions are logged to syslogd(8). Cor-
rupted message files are marked so that the queue manager
can move them to the corrupt queue for further inspection.
Depending on the setting of the notify_classes parameter,
the postmaster is notified of bounces, protocol problems,
and of other trouble.
BUGS
SMTP and LMTP connection caching does not work with TLS.
The necessary support for TLS object passivation and re-
activation does not exist without closing the session,
which defeats the purpose.
SMTP and LMTP connection caching assumes that SASL creden-
tials are valid for all destinations that map onto the
same IP address and TCP port.
CONFIGURATION PARAMETERS
Before Postfix version 2.3, the LMTP client is a separate
program that implements only a subset of the functionality
available with SMTP: there is no support for TLS, and con-
nections are cached in-process, making it ineffective when
the client is used for multiple domains.
Most smtp_xxx configuration parameters have an lmtp_xxx
"mirror" parameter for the equivalent LMTP feature. This
document describes only those LMTP-related parameters that
aren't simply "mirror" parameters.
Changes to main.cf are picked up automatically, as smtp(8)
processes run for only a limited amount of time. Use the
command "postfix reload" to speed up a change.
The text below provides only a parameter summary. See
postconf(5) for more details including examples.
COMPATIBILITY CONTROLS
ignore_mx_lookup_error (no)
Ignore DNS MX lookups that produce no response.
smtp_always_send_ehlo (yes)
Always send EHLO at the start of an SMTP session.
smtp_never_send_ehlo (no)
Never send EHLO at the start of an SMTP session.
smtp_defer_if_no_mx_address_found (no)
Defer mail delivery when no MX record resolves to
an IP address.
smtp_line_length_limit (990)
The maximal length of message header and body lines
that Postfix will send via SMTP.
smtp_pix_workaround_delay_time (10s)
How long the Postfix SMTP client pauses before
sending ".<CR><LF>" in order to work around the PIX
firewall "<CR><LF>.<CR><LF>" bug.
smtp_pix_workaround_threshold_time (500s)
How long a message must be queued before the Post-
fix SMTP client turns on the PIX firewall
"<CR><LF>.<CR><LF>" bug workaround for delivery
through firewalls with "smtp fixup" mode turned on.
smtp_pix_workarounds (disable_esmtp, delay_dotcrlf)
A list that specifies zero or more workarounds for
CISCO PIX firewall bugs.
smtp_pix_workaround_maps (empty)
Lookup tables, indexed by the remote SMTP server
address, with per-destination workarounds for CISCO
PIX firewall bugs.
smtp_quote_rfc821_envelope (yes)
Quote addresses in SMTP MAIL FROM and RCPT TO com-
mands as required by RFC 2821.
smtp_skip_5xx_greeting (yes)
Skip SMTP servers that greet with a 5XX status code
(go away, do not try again later).
smtp_skip_quit_response (yes)
Do not wait for the response to the SMTP QUIT com-
mand.
Available in Postfix version 2.0 and earlier:
smtp_skip_4xx_greeting (yes)
Skip SMTP servers that greet with a 4XX status code
(go away, try again later).
Available in Postfix version 2.2 and later:
smtp_discard_ehlo_keyword_address_maps (empty)
Lookup tables, indexed by the remote SMTP server
address, with case insensitive lists of EHLO key-
words (pipelining, starttls, auth, etc.) that the
Postfix SMTP client will ignore in the EHLO
response from a remote SMTP server.
smtp_discard_ehlo_keywords (empty)
A case insensitive list of EHLO keywords (pipelin-
ing, starttls, auth, etc.) that the Postfix SMTP
client will ignore in the EHLO response from a
remote SMTP server.
smtp_generic_maps (empty)
Optional lookup tables that perform address rewrit-
ing in the SMTP client, typically to transform a
locally valid address into a globally valid address
when sending mail across the Internet.
Available in Postfix version 2.2.9 and later:
smtp_cname_overrides_servername (version dependent)
Allow DNS CNAME records to override the servername
that the Postfix SMTP client uses for logging, SASL
password lookup, TLS policy decisions, or TLS cer-
tificate verification.
Available in Postfix version 2.3 and later:
lmtp_discard_lhlo_keyword_address_maps (empty)
Lookup tables, indexed by the remote LMTP server
address, with case insensitive lists of LHLO key-
words (pipelining, starttls, auth, etc.) that the
LMTP client will ignore in the LHLO response from a
remote LMTP server.
lmtp_discard_lhlo_keywords (empty)
A case insensitive list of LHLO keywords (pipelin-
ing, starttls, auth, etc.) that the LMTP client
will ignore in the LHLO response from a remote LMTP
server.
Available in Postfix version 2.4.4 and later:
send_cyrus_sasl_authzid (no)
When authenticating to a remote SMTP or LMTP server
with the default setting "no", send no SASL autho-
riZation ID (authzid); send only the SASL authenti-
Cation ID (authcid) plus the authcid's password.
Available in Postfix version 2.5 and later:
smtp_header_checks (empty)
Restricted header_checks(5) tables for the Postfix
SMTP client.
smtp_mime_header_checks (empty)
Restricted mime_header_checks(5) tables for the
Postfix SMTP client.
smtp_nested_header_checks (empty)
Restricted nested_header_checks(5) tables for the
Postfix SMTP client.
smtp_body_checks (empty)
Restricted body_checks(5) tables for the Postfix
SMTP client.
Available in Postfix version 2.6 and later:
tcp_windowsize (0)
An optional workaround for routers that break TCP
window scaling.
MIME PROCESSING CONTROLS
Available in Postfix version 2.0 and later:
disable_mime_output_conversion (no)
Disable the conversion of 8BITMIME format to 7BIT
format.
mime_boundary_length_limit (2048)
The maximal length of MIME multipart boundary
strings.
mime_nesting_limit (100)
The maximal recursion level that the MIME processor
will handle.
EXTERNAL CONTENT INSPECTION CONTROLS
Available in Postfix version 2.1 and later:
smtp_send_xforward_command (no)
Send the non-standard XFORWARD command when the
Postfix SMTP server EHLO response announces XFOR-
WARD support.
SASL AUTHENTICATION CONTROLS
smtp_sasl_auth_enable (no)
Enable SASL authentication in the Postfix SMTP
client.
smtp_sasl_password_maps (empty)
Optional SMTP client lookup tables with one user-
name:password entry per remote hostname or domain,
or sender address when sender-dependent authentica-
tion is enabled.
smtp_sasl_security_options (noplaintext, noanonymous)
Postfix SMTP client SASL security options; as of
Postfix 2.3 the list of available features depends
on the SASL client implementation that is selected
with smtp_sasl_type.
Available in Postfix version 2.2 and later:
smtp_sasl_mechanism_filter (empty)
If non-empty, a Postfix SMTP client filter for the
remote SMTP server's list of offered SASL mecha-
nisms.
Available in Postfix version 2.3 and later:
smtp_sender_dependent_authentication (no)
Enable sender-dependent authentication in the Post-
fix SMTP client; this is available only with SASL
authentication, and disables SMTP connection
caching to ensure that mail from different senders
will use the appropriate credentials.
smtp_sasl_path (empty)
Implementation-specific information that the Post-
fix SMTP client passes through to the SASL plug-in
implementation that is selected with
smtp_sasl_type.
smtp_sasl_type (cyrus)
The SASL plug-in type that the Postfix SMTP client
should use for authentication.
Available in Postfix version 2.5 and later:
smtp_sasl_auth_cache_name (empty)
An optional table to prevent repeated SASL authen-
tication failures with the same remote SMTP server
hostname, username and password.
smtp_sasl_auth_cache_time (90d)
The maximal age of an smtp_sasl_auth_cache_name
entry before it is removed.
smtp_sasl_auth_soft_bounce (yes)
When a remote SMTP server rejects a SASL authenti-
cation request with a 535 reply code, defer mail
delivery instead of returning mail as undeliver-
able.
STARTTLS SUPPORT CONTROLS
Detailed information about STARTTLS configuration may be
found in the TLS_README document.
smtp_tls_security_level (empty)
The default SMTP TLS security level for the Postfix
SMTP client; when a non-empty value is specified,
this overrides the obsolete parameters
smtp_use_tls, smtp_enforce_tls, and
smtp_tls_enforce_peername.
smtp_sasl_tls_security_options ($smtp_sasl_secu-
rity_options)
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
sessions.
smtp_starttls_timeout (300s)
Time limit for Postfix SMTP client write and read
operations during TLS startup and shutdown hand-
shake procedures.
smtp_tls_CAfile (empty)
A file containing CA certificates of root CAs
trusted to sign either remote SMTP server certifi-
cates or intermediate CA certificates.
smtp_tls_CApath (empty)
Directory with PEM format certificate authority
certificates that the Postfix SMTP client uses to
verify a remote SMTP server certificate.
smtp_tls_cert_file (empty)
File with the Postfix SMTP client RSA certificate
in PEM format.
smtp_tls_mandatory_ciphers (medium)
The minimum TLS cipher grade that the Postfix SMTP
client will use with mandatory TLS encryption.
smtp_tls_exclude_ciphers (empty)
List of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at all TLS security
levels.
smtp_tls_mandatory_exclude_ciphers (empty)
Additional list of ciphers or cipher types to
exclude from the SMTP client cipher list at manda-
tory TLS security levels.
smtp_tls_dcert_file (empty)
File with the Postfix SMTP client DSA certificate
in PEM format.
smtp_tls_dkey_file ($smtp_tls_dcert_file)
File with the Postfix SMTP client DSA private key
in PEM format.
smtp_tls_key_file ($smtp_tls_cert_file)
File with the Postfix SMTP client RSA private key
in PEM format.
smtp_tls_loglevel (0)
Enable additional Postfix SMTP client logging of
TLS activity.
smtp_tls_note_starttls_offer (no)
Log the hostname of a remote SMTP server that
offers STARTTLS, when TLS is not already enabled
for that server.
smtp_tls_policy_maps (empty)
Optional lookup tables with the Postfix SMTP client
TLS security policy by next-hop destination; when a
non-empty value is specified, this overrides the
obsolete smtp_tls_per_site parameter.
smtp_tls_mandatory_protocols (SSLv3, TLSv1)
List of SSL/TLS protocols that the Postfix SMTP
client will use with mandatory TLS encryption.
smtp_tls_scert_verifydepth (9)
The verification depth for remote SMTP server cer-
tificates.
smtp_tls_secure_cert_match (nexthop, dot-nexthop)
The server certificate peername verification method
for the "secure" TLS security level.
smtp_tls_session_cache_database (empty)
Name of the file containing the optional Postfix
SMTP client TLS session cache.
smtp_tls_session_cache_timeout (3600s)
The expiration time of Postfix SMTP client TLS ses-
sion cache information.
smtp_tls_verify_cert_match (hostname)
The server certificate peername verification method
for the "verify" TLS security level.
tls_daemon_random_bytes (32)
The number of pseudo-random bytes that an smtp(8)
or smtpd(8) process requests from the tlsmgr(8)
server in order to seed its internal pseudo random
number generator (PRNG).
tls_high_cipherlist
(ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "HIGH" grade ciphers.
tls_medium_cipherlist (ALL:!EXPORT:!LOW:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "MEDIUM" or higher grade
ciphers.
tls_low_cipherlist (ALL:!EXPORT:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "LOW" or higher grade
ciphers.
tls_export_cipherlist (ALL:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "EXPORT" or higher grade
ciphers.
tls_null_cipherlist (eNULL:!aNULL)
The OpenSSL cipherlist for "NULL" grade ciphers
that provide authentication without encryption.
Available in Postfix version 2.4 and later:
smtp_sasl_tls_verified_security_options
($smtp_sasl_tls_security_options)
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
sessions with a verified server certificate.
Available in Postfix version 2.5 and later:
smtp_tls_fingerprint_cert_match (empty)
List of acceptable remote SMTP server certificate
fingerprints for the "fingerprint" TLS security
level (smtp_tls_security_level = fingerprint).
smtp_tls_fingerprint_digest (md5)
The message digest algorithm used to construct
remote SMTP server certificate fingerprints.
Available in Postfix version 2.6 and later:
smtp_tls_protocols (!SSLv2)
List of TLS protocols that the Postfix SMTP client
will exclude or include with opportunistic TLS
encryption.
smtp_tls_ciphers (export)
The minimum TLS cipher grade that the Postfix SMTP
client will use with opportunistic TLS encryption.
smtp_tls_eccert_file (empty)
File with the Postfix SMTP client ECDSA certificate
in PEM format.
smtp_tls_eckey_file ($smtp_tls_eccert_file)
File with the Postfix SMTP client ECDSA private key
in PEM format.
OBSOLETE STARTTLS CONTROLS
The following configuration parameters exist for compati-
bility with Postfix versions before 2.3. Support for these
will be removed in a future release.
smtp_use_tls (no)
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
the mail in the clear.
smtp_enforce_tls (no)
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
clear.
smtp_tls_enforce_peername (yes)
With mandatory TLS encryption, require that the
remote SMTP server hostname matches the information
in the remote SMTP server certificate.
smtp_tls_per_site (empty)
Optional lookup tables with the Postfix SMTP client
TLS usage policy by next-hop destination and by
remote SMTP server hostname.
smtp_tls_cipherlist (empty)
Obsolete Postfix < 2.3 control for the Postfix SMTP
client TLS cipher list.
RESOURCE AND RATE CONTROLS
smtp_destination_concurrency_limit ($default_destina-
tion_concurrency_limit)
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
transport.
smtp_destination_recipient_limit ($default_destina-
tion_recipient_limit)
The maximal number of recipients per message for
the smtp message delivery transport.
smtp_connect_timeout (30s)
The SMTP client time limit for completing a TCP
connection, or zero (use the operating system
built-in time limit).
smtp_helo_timeout (300s)
The SMTP client time limit for sending the HELO or
EHLO command, and for receiving the initial server
response.
lmtp_lhlo_timeout (300s)
The LMTP client time limit for sending the LHLO
command, and for receiving the initial server
response.
smtp_xforward_timeout (300s)
The SMTP client time limit for sending the XFORWARD
command, and for receiving the server response.
smtp_mail_timeout (300s)
The SMTP client time limit for sending the MAIL
FROM command, and for receiving the server
response.
smtp_rcpt_timeout (300s)
The SMTP client time limit for sending the SMTP
RCPT TO command, and for receiving the server
response.
smtp_data_init_timeout (120s)
The SMTP client time limit for sending the SMTP
DATA command, and for receiving the server
response.
smtp_data_xfer_timeout (180s)
The SMTP client time limit for sending the SMTP
message content.
smtp_data_done_timeout (600s)
The SMTP client time limit for sending the SMTP
".", and for receiving the server response.
smtp_quit_timeout (300s)
The SMTP client time limit for sending the QUIT
command, and for receiving the server response.
Available in Postfix version 2.1 and later:
smtp_mx_address_limit (5)
The maximal number of MX (mail exchanger) IP
addresses that can result from mail exchanger
lookups, or zero (no limit).
smtp_mx_session_limit (2)
The maximal number of SMTP sessions per delivery
request before giving up or delivering to a fall-
back relay host, or zero (no limit).
smtp_rset_timeout (20s)
The SMTP client time limit for sending the RSET
command, and for receiving the server response.
Available in Postfix version 2.2 and earlier:
lmtp_cache_connection (yes)
Keep Postfix LMTP client connections open for up to
$max_idle seconds.
Available in Postfix version 2.2 and later:
smtp_connection_cache_destinations (empty)
Permanently enable SMTP connection caching for the
specified destinations.
smtp_connection_cache_on_demand (yes)
Temporarily enable SMTP connection caching while a
destination has a high volume of mail in the active
queue.
smtp_connection_reuse_time_limit (300s)
The amount of time during which Postfix will use an
SMTP connection repeatedly.
smtp_connection_cache_time_limit (2s)
When SMTP connection caching is enabled, the amount
of time that an unused SMTP client socket is kept
open before it is closed.
Available in Postfix version 2.3 and later:
connection_cache_protocol_timeout (5s)
Time limit for connection cache connect, send or
receive operations.
TROUBLE SHOOTING CONTROLS
debug_peer_level (2)
The increment in verbose logging level when a
remote client or server matches a pattern in the
debug_peer_list parameter.
debug_peer_list (empty)
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
in $debug_peer_level.
error_notice_recipient (postmaster)
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
resource, software or protocol errors.
internal_mail_filter_classes (empty)
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
non_smtpd_milters, header_checks and body_checks.
notify_classes (resource, software)
The list of error classes that are reported to the
postmaster.
MISCELLANEOUS CONTROLS
best_mx_transport (empty)
Where the Postfix SMTP client should deliver mail
when it detects a "mail loops back to myself" error
condition.
config_directory (see 'postconf -d' output)
The default location of the Postfix main.cf and
master.cf configuration files.
daemon_timeout (18000s)
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
built-in watchdog timer.
delay_logging_resolution_limit (2)
The maximal number of digits after the decimal
point when logging sub-second delay values.
disable_dns_lookups (no)
Disable DNS lookups in the Postfix SMTP and LMTP
clients.
inet_interfaces (all)
The network interface addresses that this mail sys-
tem receives mail on.
inet_protocols (ipv4)
The Internet protocols Postfix will attempt to use
when making or accepting connections.
ipc_timeout (3600s)
The time limit for sending or receiving information
over an internal communication channel.
lmtp_assume_final (no)
When an LMTP server announces no DSN support,
assume that the server performs final delivery, and
send "delivered" delivery status notifications
instead of "relayed".
lmtp_tcp_port (24)
The default TCP port that the Postfix LMTP client
connects to.
max_idle (100s)
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
before terminating voluntarily.
max_use (100)
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
nating voluntarily.
process_id (read-only)
The process ID of a Postfix command or daemon
process.
process_name (read-only)
The process name of a Postfix command or daemon
process.
proxy_interfaces (empty)
The network interface addresses that this mail sys-
tem receives mail on by way of a proxy or network
address translation unit.
smtp_bind_address (empty)
An optional numerical network address that the
Postfix SMTP client should bind to when making an
IPv4 connection.
smtp_bind_address6 (empty)
An optional numerical network address that the
Postfix SMTP client should bind to when making an
IPv6 connection.
smtp_helo_name ($myhostname)
The hostname to send in the SMTP EHLO or HELO com-
mand.
lmtp_lhlo_name ($myhostname)
The hostname to send in the LMTP LHLO command.
smtp_host_lookup (dns)
What mechanisms when the Postfix SMTP client uses
to look up a host's IP address.
smtp_randomize_addresses (yes)
Randomize the order of equal-preference MX host
addresses.
syslog_facility (mail)
The syslog facility of Postfix logging.
syslog_name (see 'postconf -d' output)
The mail system name that is prepended to the
process name in syslog records, so that "smtpd"
becomes, for example, "postfix/smtpd".
Available with Postfix 2.2 and earlier:
fallback_relay (empty)
Optional list of relay hosts for SMTP destinations
that can't be found or that are unreachable.
Available with Postfix 2.3 and later:
smtp_fallback_relay ($fallback_relay)
Optional list of relay hosts for SMTP destinations
that can't be found or that are unreachable.
SEE ALSO
generic(5), output address rewriting
header_checks(5), message header content inspection
body_checks(5), body parts content inspection
qmgr(8), queue manager
bounce(8), delivery status reports
scache(8), connection cache server
postconf(5), configuration parameters
master(5), generic daemon options
master(8), process manager
tlsmgr(8), TLS session and PRNG management
syslogd(8), system logging
README FILES
SASL_README, Postfix SASL howto
TLS_README, Postfix STARTTLS howto
LICENSE
The Secure Mailer license must be distributed with this
software.
AUTHOR(S)
Wietse Venema
IBM T.J. Watson Research
P.O. Box 704
Yorktown Heights, NY 10598, USA
Command pipelining in cooperation with:
Jon Ribbens
Oaktree Internet Solutions Ltd.,
Internet House,
Canal Basin,
Coventry,
CV1 4LY, United Kingdom.
SASL support originally by:
Till Franke
SuSE Rhein/Main AG
65760 Eschborn, Germany
TLS support originally by:
Lutz Jaenicke
BTU Cottbus
Allgemeine Elektrotechnik
Universitaetsplatz 3-4
D-03044 Cottbus, Germany
Revised TLS and SMTP connection cache support by:
Victor Duchovni
Morgan Stanley
SMTP(8)
@
1.1.1.1
log
@Import Postfix 2.6.2.
@
text
@@
1.1.1.2
log
@Import Postfix 2.7.1. Major changes since Postfix 2.6.6:
- Improved before-queue content filter performance. With
"smtpd_proxy_options = speed_adjust", the Postfix SMTP server
receives the entire message before it connects to a before-queue
content filter. Typically, this allows Postfix to handle the same
mail load with fewer content filter processes.
- Improved address verification performance. The verify database is now
persistent by default, and it is automatically cleaned periodically. Under
overload conditions, the Postfix SMTP server no longer waits up to 6 seconds
for an address probe to complete.
- Support for reputation management based on the local SMTP client IP address.
This is typically implemented with "FILTER transportname:" actions in access
maps or header/body checks, and mail delivery transports in master.cf with
unique smtp_bind_address values.
@
text
@a198 4
smtp_reply_filter (empty)
A mechanism to transform replies from remote SMTP
servers one line at a time.
d204 1
a204 1
Do not wait for the response to the SMTP QUIT com-
d216 4
a219 4
Lookup tables, indexed by the remote SMTP server
address, with case insensitive lists of EHLO key-
words (pipelining, starttls, auth, etc.) that the
Postfix SMTP client will ignore in the EHLO
d223 3
a225 3
A case insensitive list of EHLO keywords (pipelin-
ing, starttls, auth, etc.) that the Postfix SMTP
client will ignore in the EHLO response from a
d230 1
a230 1
ing in the SMTP client, typically to transform a
d237 1
a237 1
Allow DNS CNAME records to override the servername
d239 1
a239 1
password lookup, TLS policy decisions, or TLS cer-
d245 3
a247 3
Lookup tables, indexed by the remote LMTP server
address, with case insensitive lists of LHLO key-
words (pipelining, starttls, auth, etc.) that the
d252 2
a253 2
A case insensitive list of LHLO keywords (pipelin-
ing, starttls, auth, etc.) that the LMTP client
d261 1
a261 1
with the default setting "no", send no SASL autho-
d268 1
a268 1
Restricted header_checks(5) tables for the Postfix
d276 1
a276 1
Restricted nested_header_checks(5) tables for the
d280 1
a280 1
Restricted body_checks(5) tables for the Postfix
d286 1
a286 1
An optional workaround for routers that break TCP
d293 1
a293 1
Disable the conversion of 8BITMIME format to 7BIT
d308 2
a309 2
Send the non-standard XFORWARD command when the
Postfix SMTP server EHLO response announces XFOR-
d314 1
a314 1
Enable SASL authentication in the Postfix SMTP
d318 2
a319 2
Optional SMTP client lookup tables with one user-
name:password entry per remote hostname or domain,
d324 3
a326 3
Postfix SMTP client SASL security options; as of
Postfix 2.3 the list of available features depends
on the SASL client implementation that is selected
d332 2
a333 2
If non-empty, a Postfix SMTP client filter for the
remote SMTP server's list of offered SASL mecha-
d340 3
a342 3
fix SMTP client; this is available only with SASL
authentication, and disables SMTP connection
caching to ensure that mail from different senders
d346 3
a348 3
Implementation-specific information that the Post-
fix SMTP client passes through to the SASL plug-in
implementation that is selected with
d352 1
a352 1
The SASL plug-in type that the Postfix SMTP client
d358 2
a359 2
An optional table to prevent repeated SASL authen-
tication failures with the same remote SMTP server
d363 1
a363 1
The maximal age of an smtp_sasl_auth_cache_name
d367 3
a369 3
When a remote SMTP server rejects a SASL authenti-
cation request with a 535 reply code, defer mail
delivery instead of returning mail as undeliver-
d373 1
a373 1
Detailed information about STARTTLS configuration may be
d378 2
a379 2
SMTP client; when a non-empty value is specified,
this overrides the obsolete parameters
d385 2
a386 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d390 2
a391 2
Time limit for Postfix SMTP client write and read
operations during TLS startup and shutdown hand-
d395 2
a396 2
A file containing CA certificates of root CAs
trusted to sign either remote SMTP server certifi-
d400 2
a401 2
Directory with PEM format certificate authority
certificates that the Postfix SMTP client uses to
d405 1
a405 1
File with the Postfix SMTP client RSA certificate
d409 1
a409 1
The minimum TLS cipher grade that the Postfix SMTP
d418 2
a419 2
Additional list of ciphers or cipher types to
exclude from the SMTP client cipher list at manda-
d423 1
a423 1
File with the Postfix SMTP client DSA certificate
d427 1
a427 1
File with the Postfix SMTP client DSA private key
d431 1
a431 1
File with the Postfix SMTP client RSA private key
d435 1
a435 1
Enable additional Postfix SMTP client logging of
d439 2
a440 2
Log the hostname of a remote SMTP server that
offers STARTTLS, when TLS is not already enabled
d446 1
a446 1
non-empty value is specified, this overrides the
d450 1
a450 1
List of SSL/TLS protocols that the Postfix SMTP
d454 1
a454 1
The verification depth for remote SMTP server cer-
d462 1
a462 1
Name of the file containing the optional Postfix
d474 3
a476 3
The number of pseudo-random bytes that an smtp(8)
or smtpd(8) process requests from the tlsmgr(8)
server in order to seed its internal pseudo random
d488 1
a488 1
The OpenSSL cipherlist for "LOW" or higher grade
d496 1
a496 1
The OpenSSL cipherlist for "NULL" grade ciphers
d503 2
a504 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d510 2
a511 2
List of acceptable remote SMTP server certificate
fingerprints for the "fingerprint" TLS security
d515 1
a515 1
The message digest algorithm used to construct
d521 2
a522 2
List of TLS protocols that the Postfix SMTP client
will exclude or include with opportunistic TLS
d526 2
a527 2
The minimum TLS cipher grade that the Postfix SMTP
client will use with opportunistic TLS encryption.
a536 8
Available in Postfix version 2.7 and later:
smtp_tls_block_early_mail_reply (no)
Try to detect a mail hijacking attack based on a
TLS protocol vulnerability (CVE-2009-3555), where
an attacker prepends malicious HELO, MAIL, RCPT,
DATA commands to a Postfix SMTP client TLS session.
d538 1
a538 1
The following configuration parameters exist for compati-
d543 2
a544 2
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
d548 2
a549 2
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
d553 1
a553 1
With mandatory TLS encryption, require that the
d559 1
a559 1
TLS usage policy by next-hop destination and by
d569 2
a570 2
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
d575 1
a575 1
The maximal number of recipients per message for
d579 1
a579 1
The SMTP client time limit for completing a TCP
d584 2
a585 2
The SMTP client time limit for sending the HELO or
EHLO command, and for receiving the initial server
d589 1
a589 1
The LMTP client time limit for sending the LHLO
d598 2
a599 2
The SMTP client time limit for sending the MAIL
FROM command, and for receiving the server
d603 2
a604 2
The SMTP client time limit for sending the SMTP
RCPT TO command, and for receiving the server
d608 2
a609 2
The SMTP client time limit for sending the SMTP
DATA command, and for receiving the server
d613 1
a613 1
The SMTP client time limit for sending the SMTP
d617 1
a617 1
The SMTP client time limit for sending the SMTP
d621 1
a621 1
The SMTP client time limit for sending the QUIT
d632 2
a633 2
The maximal number of SMTP sessions per delivery
request before giving up or delivering to a fall-
d637 1
a637 1
The SMTP client time limit for sending the RSET
d649 1
a649 1
Permanently enable SMTP connection caching for the
d653 1
a653 1
Temporarily enable SMTP connection caching while a
d663 1
a663 1
of time that an unused SMTP client socket is kept
d669 1
a669 1
Time limit for connection cache connect, send or
d674 2
a675 2
The increment in verbose logging level when a
remote client or server matches a pattern in the
d679 3
a681 3
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
d685 2
a686 2
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
d690 2
a691 2
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
d695 1
a695 1
The list of error classes that are reported to the
d700 1
a700 1
Where the Postfix SMTP client should deliver mail
d705 1
a705 1
The default location of the Postfix main.cf and
d709 2
a710 2
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
d714 1
a714 1
The maximal number of digits after the decimal
d718 1
a718 1
Disable DNS lookups in the Postfix SMTP and LMTP
d726 1
a726 1
The Internet protocols Postfix will attempt to use
d734 1
a734 1
When an LMTP server announces no DSN support,
d736 1
a736 1
send "delivered" delivery status notifications
d740 1
a740 1
The default TCP port that the Postfix LMTP client
d744 2
a745 2
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
d749 2
a750 2
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
d754 1
a754 1
The process ID of a Postfix command or daemon
d758 1
a758 1
The process name of a Postfix command or daemon
d763 1
a763 1
tem receives mail on by way of a proxy or network
d767 2
a768 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d772 2
a773 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d777 1
a777 1
The hostname to send in the SMTP EHLO or HELO com-
d784 2
a785 2
What mechanisms the Postfix SMTP client uses to
look up a host's IP address.
d788 1
a788 1
Randomize the order of equal-preference MX host
d795 2
a796 2
The mail system name that is prepended to the
process name in syslog records, so that "smtpd"
d802 1
a802 1
Optional list of relay hosts for SMTP destinations
d808 1
a808 1
Optional list of relay hosts for SMTP destinations
d829 1
a829 1
The Secure Mailer license must be distributed with this
@
1.1.1.2.2.1
log
@Sync with HEAD
@
text
@a292 5
Available in Postfix version 2.8 and later:
smtp_dns_resolver_options (empty)
DNS Resolver options for the Postfix SMTP client.
a548 6
Available in Postfix version 2.8 and later:
tls_disable_workarounds (see 'postconf -d' output)
List or bit-mask of OpenSSL bug work-arounds to
disable.
d550 1
a550 1
The following configuration parameters exist for compati-
d555 2
a556 2
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
d560 2
a561 2
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
d565 1
a565 1
With mandatory TLS encryption, require that the
d571 1
a571 1
TLS usage policy by next-hop destination and by
d581 2
a582 2
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
d587 1
a587 1
The maximal number of recipients per message for
d591 1
a591 1
The SMTP client time limit for completing a TCP
d596 2
a597 2
The SMTP client time limit for sending the HELO or
EHLO command, and for receiving the initial server
d601 1
a601 1
The LMTP client time limit for sending the LHLO
d610 2
a611 2
The SMTP client time limit for sending the MAIL
FROM command, and for receiving the server
d615 2
a616 2
The SMTP client time limit for sending the SMTP
RCPT TO command, and for receiving the server
d620 2
a621 2
The SMTP client time limit for sending the SMTP
DATA command, and for receiving the server
d625 1
a625 1
The SMTP client time limit for sending the SMTP
d629 1
a629 1
The SMTP client time limit for sending the SMTP
d633 1
a633 1
The SMTP client time limit for sending the QUIT
d644 2
a645 2
The maximal number of SMTP sessions per delivery
request before giving up or delivering to a fall-
d649 1
a649 1
The SMTP client time limit for sending the RSET
d661 1
a661 1
Permanently enable SMTP connection caching for the
d665 1
a665 1
Temporarily enable SMTP connection caching while a
d675 1
a675 1
of time that an unused SMTP client socket is kept
d681 1
a681 1
Time limit for connection cache connect, send or
d686 2
a687 2
The increment in verbose logging level when a
remote client or server matches a pattern in the
d691 3
a693 3
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
d697 2
a698 2
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
d702 2
a703 2
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
d707 1
a707 1
The list of error classes that are reported to the
d712 1
a712 1
Where the Postfix SMTP client should deliver mail
d717 1
a717 1
The default location of the Postfix main.cf and
d721 2
a722 2
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
d726 1
a726 1
The maximal number of digits after the decimal
d730 1
a730 1
Disable DNS lookups in the Postfix SMTP and LMTP
d738 1
a738 1
The Internet protocols Postfix will attempt to use
d746 1
a746 1
When an LMTP server announces no DSN support,
d748 1
a748 1
send "delivered" delivery status notifications
d752 1
a752 1
The default TCP port that the Postfix LMTP client
d756 2
a757 2
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
d761 2
a762 2
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
d766 1
a766 1
The process ID of a Postfix command or daemon
d770 1
a770 1
The process name of a Postfix command or daemon
d775 1
a775 1
tem receives mail on by way of a proxy or network
a777 6
smtp_address_preference (ipv6)
The address type ("ipv6", "ipv4" or "any") that the
Postfix SMTP client will try first, when a destina-
tion has IPv6 and IPv4 addresses with equal MX
preference.
@
1.1.1.3
log
@Import Postfix 2.8.1. Changes since version 2.7.*:
Postfix stable release 2.8.0 is available. This release continues the
move towards improving code and documentation, and making the system
better prepared for changes in the threat environment.
The postscreen daemon (a zombie blocker in front of Postfix) is now
included with the stable release. postscreen now supports TLS and can
log the rejected sender, recipient and helo information. See the
POSTSCREEN_README file for recommended usage scenarios.
Support for DNS whitelisting (permit_rhswl_client), and for pattern
matching to filter the responses from DNS white/blacklist servers
(e.g., reject_rhsbl_client zen.spamhaus.org=127.0.0.[1..10]).
Improved message tracking across SMTP-based content filters; the
after-filter SMTP server can log the before-filter queue ID (the
XCLIENT protocol was extended).
Read-only support for sqlite databases. See sqlite_table(5) and
SQLITE_README.
Support for 'footers' that are appended to SMTP server "reject"
responses. See "smtpd_reject_footer" in the postconf(5) manpage.
@
text
@a292 5
Available in Postfix version 2.8 and later:
smtp_dns_resolver_options (empty)
DNS Resolver options for the Postfix SMTP client.
a548 6
Available in Postfix version 2.8 and later:
tls_disable_workarounds (see 'postconf -d' output)
List or bit-mask of OpenSSL bug work-arounds to
disable.
d550 1
a550 1
The following configuration parameters exist for compati-
d555 2
a556 2
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
d560 2
a561 2
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
d565 1
a565 1
With mandatory TLS encryption, require that the
d571 1
a571 1
TLS usage policy by next-hop destination and by
d581 2
a582 2
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
d587 1
a587 1
The maximal number of recipients per message for
d591 1
a591 1
The SMTP client time limit for completing a TCP
d596 2
a597 2
The SMTP client time limit for sending the HELO or
EHLO command, and for receiving the initial server
d601 1
a601 1
The LMTP client time limit for sending the LHLO
d610 2
a611 2
The SMTP client time limit for sending the MAIL
FROM command, and for receiving the server
d615 2
a616 2
The SMTP client time limit for sending the SMTP
RCPT TO command, and for receiving the server
d620 2
a621 2
The SMTP client time limit for sending the SMTP
DATA command, and for receiving the server
d625 1
a625 1
The SMTP client time limit for sending the SMTP
d629 1
a629 1
The SMTP client time limit for sending the SMTP
d633 1
a633 1
The SMTP client time limit for sending the QUIT
d644 2
a645 2
The maximal number of SMTP sessions per delivery
request before giving up or delivering to a fall-
d649 1
a649 1
The SMTP client time limit for sending the RSET
d661 1
a661 1
Permanently enable SMTP connection caching for the
d665 1
a665 1
Temporarily enable SMTP connection caching while a
d675 1
a675 1
of time that an unused SMTP client socket is kept
d681 1
a681 1
Time limit for connection cache connect, send or
d686 2
a687 2
The increment in verbose logging level when a
remote client or server matches a pattern in the
d691 3
a693 3
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
d697 2
a698 2
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
d702 2
a703 2
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
d707 1
a707 1
The list of error classes that are reported to the
d712 1
a712 1
Where the Postfix SMTP client should deliver mail
d717 1
a717 1
The default location of the Postfix main.cf and
d721 2
a722 2
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
d726 1
a726 1
The maximal number of digits after the decimal
d730 1
a730 1
Disable DNS lookups in the Postfix SMTP and LMTP
d738 1
a738 1
The Internet protocols Postfix will attempt to use
d746 1
a746 1
When an LMTP server announces no DSN support,
d748 1
a748 1
send "delivered" delivery status notifications
d752 1
a752 1
The default TCP port that the Postfix LMTP client
d756 2
a757 2
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
d761 2
a762 2
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
d766 1
a766 1
The process ID of a Postfix command or daemon
d770 1
a770 1
The process name of a Postfix command or daemon
d775 1
a775 1
tem receives mail on by way of a proxy or network
a777 6
smtp_address_preference (ipv6)
The address type ("ipv6", "ipv4" or "any") that the
Postfix SMTP client will try first, when a destina-
tion has IPv6 and IPv4 addresses with equal MX
preference.
@
1.1.1.3.4.1
log
@sync with head
@
text
@d458 1
a458 1
smtp_tls_mandatory_protocols (!SSLv2)
@
1.1.1.3.4.2
log
@sync with head
@
text
@d171 1
a171 1
smtp_line_length_limit (998)
d196 2
a197 2
Quote addresses in Postfix SMTP client MAIL FROM
and RCPT TO commands as required by RFC 2821.
d204 2
a205 2
Skip remote SMTP servers that greet with a 5XX sta-
tus code (go away, do not try again later).
d234 3
a236 3
ing in the Postfix SMTP client, typically to trans-
form a locally valid address into a globally valid
address when sending mail across the Internet.
d252 2
a253 2
Postfix LMTP client will ignore in the LHLO
response from a remote LMTP server.
d257 3
a259 3
ing, starttls, auth, etc.) that the Postfix LMTP
client will ignore in the LHLO response from a
remote LMTP server.
a297 15
Available in Postfix version 2.9 and later:
smtp_per_record_deadline (no)
Change the behavior of the smtp_*_timeout time lim-
its, from a time limit per read or write system
call, to a time limit to send or receive a complete
record (an SMTP command line, SMTP response line,
SMTP message content line, or TLS protocol mes-
sage).
smtp_send_dummy_mail_auth (no)
Whether or not to append the "AUTH=<>" option to
the MAIL FROM command in SASL-authenticated SMTP
sessions.
d302 1
a302 1
Disable the conversion of 8BITMIME format to 7BIT
d317 2
a318 2
Send the non-standard XFORWARD command when the
Postfix SMTP server EHLO response announces XFOR-
d323 1
a323 1
Enable SASL authentication in the Postfix SMTP
d327 4
a330 4
Optional Postfix SMTP client lookup tables with one
username:password entry per remote hostname or
domain, or sender address when sender-dependent
authentication is enabled.
d333 3
a335 3
Postfix SMTP client SASL security options; as of
Postfix 2.3 the list of available features depends
on the SASL client implementation that is selected
d341 2
a342 2
If non-empty, a Postfix SMTP client filter for the
remote SMTP server's list of offered SASL mecha-
d349 3
a351 3
fix SMTP client; this is available only with SASL
authentication, and disables SMTP connection
caching to ensure that mail from different senders
d355 3
a357 3
Implementation-specific information that the Post-
fix SMTP client passes through to the SASL plug-in
implementation that is selected with
d361 1
a361 1
The SASL plug-in type that the Postfix SMTP client
d367 2
a368 2
An optional table to prevent repeated SASL authen-
tication failures with the same remote SMTP server
d372 1
a372 1
The maximal age of an smtp_sasl_auth_cache_name
d376 3
a378 3
When a remote SMTP server rejects a SASL authenti-
cation request with a 535 reply code, defer mail
delivery instead of returning mail as undeliver-
a380 7
Available in Postfix version 2.9 and later:
smtp_send_dummy_mail_auth (no)
Whether or not to append the "AUTH=<>" option to
the MAIL FROM command in SASL-authenticated SMTP
sessions.
d382 1
a382 1
Detailed information about STARTTLS configuration may be
d387 2
a388 2
SMTP client; when a non-empty value is specified,
this overrides the obsolete parameters
d394 2
a395 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d399 2
a400 2
Time limit for Postfix SMTP client write and read
operations during TLS startup and shutdown hand-
d404 2
a405 2
A file containing CA certificates of root CAs
trusted to sign either remote SMTP server certifi-
d409 2
a410 2
Directory with PEM format certificate authority
certificates that the Postfix SMTP client uses to
d414 1
a414 1
File with the Postfix SMTP client RSA certificate
d418 1
a418 1
The minimum TLS cipher grade that the Postfix SMTP
d427 3
a429 3
Additional list of ciphers or cipher types to
exclude from the Postfix SMTP client cipher list at
mandatory TLS security levels.
d432 1
a432 1
File with the Postfix SMTP client DSA certificate
d436 1
a436 1
File with the Postfix SMTP client DSA private key
d440 1
a440 1
File with the Postfix SMTP client RSA private key
d444 1
a444 1
Enable additional Postfix SMTP client logging of
d448 2
a449 2
Log the hostname of a remote SMTP server that
offers STARTTLS, when TLS is not already enabled
d455 1
a455 1
non-empty value is specified, this overrides the
d459 1
a459 1
List of SSL/TLS protocols that the Postfix SMTP
d463 1
a463 1
The verification depth for remote SMTP server cer-
d467 2
a468 3
How the Postfix SMTP client verifies the server
certificate peername for the "secure" TLS security
level.
d479 2
a480 3
How the Postfix SMTP client verifies the server
certificate peername for the "verify" TLS security
level.
d483 3
a485 3
The number of pseudo-random bytes that an smtp(8)
or smtpd(8) process requests from the tlsmgr(8)
server in order to seed its internal pseudo random
d497 1
a497 1
The OpenSSL cipherlist for "LOW" or higher grade
d505 1
a505 1
The OpenSSL cipherlist for "NULL" grade ciphers
d512 2
a513 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d519 2
a520 2
List of acceptable remote SMTP server certificate
fingerprints for the "fingerprint" TLS security
d524 1
a524 1
The message digest algorithm used to construct
d530 2
a531 2
List of TLS protocols that the Postfix SMTP client
will exclude or include with opportunistic TLS
d535 2
a536 2
The minimum TLS cipher grade that the Postfix SMTP
client will use with opportunistic TLS encryption.
d549 3
a551 3
Try to detect a mail hijacking attack based on a
TLS protocol vulnerability (CVE-2009-3555), where
an attacker prepends malicious HELO, MAIL, RCPT,
d557 1
a557 1
List or bit-mask of OpenSSL bug work-arounds to
d561 1
a561 1
The following configuration parameters exist for compati-
d566 2
a567 2
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
d571 2
a572 2
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
d576 1
a576 1
With mandatory TLS encryption, require that the
d582 1
a582 1
TLS usage policy by next-hop destination and by
d592 2
a593 2
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
d598 1
a598 1
The maximal number of recipients per message for
d602 2
a603 2
The Postfix SMTP client time limit for completing a
TCP connection, or zero (use the operating system
d607 3
a609 3
The Postfix SMTP client time limit for sending the
HELO or EHLO command, and for receiving the initial
remote SMTP server response.
d612 3
a614 3
The Postfix LMTP client time limit for sending the
LHLO command, and for receiving the initial remote
LMTP server response.
d617 2
a618 3
The Postfix SMTP client time limit for sending the
XFORWARD command, and for receiving the remote SMTP
server response.
d621 3
a623 3
The Postfix SMTP client time limit for sending the
MAIL FROM command, and for receiving the remote
SMTP server response.
d626 3
a628 3
The Postfix SMTP client time limit for sending the
SMTP RCPT TO command, and for receiving the remote
SMTP server response.
d631 3
a633 3
The Postfix SMTP client time limit for sending the
SMTP DATA command, and for receiving the remote
SMTP server response.
d636 2
a637 2
The Postfix SMTP client time limit for sending the
SMTP message content.
d640 2
a641 3
The Postfix SMTP client time limit for sending the
SMTP ".", and for receiving the remote SMTP server
response.
d644 2
a645 3
The Postfix SMTP client time limit for sending the
QUIT command, and for receiving the remote SMTP
server response.
d651 2
a652 2
addresses that can result from Postfix SMTP client
mail exchanger lookups, or zero (no limit).
d656 2
a657 3
request before the Postfix SMTP client gives up or
delivers to a fall-back relay host, or zero (no
limit).
d660 2
a661 3
The Postfix SMTP client time limit for sending the
RSET command, and for receiving the remote SMTP
server response.
a694 10
Available in Postfix version 2.9 and later:
smtp_per_record_deadline (no)
Change the behavior of the smtp_*_timeout time lim-
its, from a time limit per read or write system
call, to a time limit to send or receive a complete
record (an SMTP command line, SMTP response line,
SMTP message content line, or TLS protocol mes-
sage).
d697 2
a698 2
The increment in verbose logging level when a
remote client or server matches a pattern in the
d702 3
a704 3
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
d708 2
a709 2
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
d713 2
a714 2
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
d718 1
a718 1
The list of error classes that are reported to the
d723 1
a723 1
Where the Postfix SMTP client should deliver mail
d728 1
a728 1
The default location of the Postfix main.cf and
d732 2
a733 2
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
d737 1
a737 1
The maximal number of digits after the decimal
d741 1
a741 1
Disable DNS lookups in the Postfix SMTP and LMTP
d748 2
a749 2
inet_protocols (all)
The Internet protocols Postfix will attempt to use
d757 1
a757 1
When a remote LMTP server announces no DSN support,
d759 1
a759 1
send "delivered" delivery status notifications
d763 1
a763 1
The default TCP port that the Postfix LMTP client
d767 2
a768 2
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
d772 2
a773 2
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
d777 1
a777 1
The process ID of a Postfix command or daemon
d781 1
a781 1
The process name of a Postfix command or daemon
d786 1
a786 1
tem receives mail on by way of a proxy or network
d789 1
a789 1
smtp_address_preference (any)
d792 1
a792 1
tion has IPv6 and IPv4 addresses with equal MX
d796 2
a797 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d801 2
a802 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d806 1
a806 1
The hostname to send in the SMTP EHLO or HELO com-
d813 1
a813 1
What mechanisms the Postfix SMTP client uses to
d817 1
a817 1
Randomize the order of equal-preference MX host
d824 2
a825 2
The mail system name that is prepended to the
process name in syslog records, so that "smtpd"
d831 1
a831 1
Optional list of relay hosts for SMTP destinations
d837 1
a837 1
Optional list of relay hosts for SMTP destinations
d858 1
a858 1
The Secure Mailer license must be distributed with this
@
1.1.1.3.4.3
log
@sync with head.
for a reference, the tree before this commit was tagged
as yamt-pagecache-tag8.
this commit was splitted into small chunks to avoid
a limitation of cvs. ("Protocol error: too many arguments")
@
text
@a117 1
RFC 5321 (SMTP protocol)
d197 1
a197 1
and RCPT TO commands as required by RFC 5321.
@
1.1.1.3.6.1
log
@Pull up following revision(s) (requested by tron in ticket #333):
doc/3RDPARTY 1.940 via patch
doc/CHANGES 1.1708 via patch
external/ibm-public/postfix/dist/HISTORY patch
external/ibm-public/postfix/dist/RELEASE_NOTES patch
external/ibm-public/postfix/dist/README_FILES/RELEASE_NOTES patch
external/ibm-public/postfix/dist/README_FILES/TLS_README patch
external/ibm-public/postfix/dist/html/TLS_README.html patch
external/ibm-public/postfix/dist/html/lmtp.8.html patch
external/ibm-public/postfix/dist/html/postconf.5.html patch
external/ibm-public/postfix/dist/html/smtp.8.html patch
external/ibm-public/postfix/dist/html/smtpd.8.html patch
external/ibm-public/postfix/dist/man/man5/postconf.5 patch
external/ibm-public/postfix/dist/man/man8/smtp.8 patch
external/ibm-public/postfix/dist/man/man8/smtpd.8 patch
external/ibm-public/postfix/dist/proto/TLS_README.html patch
external/ibm-public/postfix/dist/proto/postconf.proto patch
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.c patch
external/ibm-public/postfix/dist/src/dnsblog/dnsblog.c patch
external/ibm-public/postfix/dist/src/global/mail_params.h patch
external/ibm-public/postfix/dist/src/global/mail_version.h patch
external/ibm-public/postfix/dist/src/local/Makefile.in patch
external/ibm-public/postfix/dist/src/postlog/postlog.c patch
external/ibm-public/postfix/dist/src/postqueue/Makefile.in patch
external/ibm-public/postfix/dist/src/postqueue/postqueue.c patch
external/ibm-public/postfix/dist/src/smtp/smtp.c patch
external/ibm-public/postfix/dist/src/smtpd/smtpd.c patch
external/ibm-public/postfix/dist/src/tls/tls.h patch
external/ibm-public/postfix/dist/src/tls/tls_client.c patch
external/ibm-public/postfix/dist/src/tls/tls_misc.c patch
external/ibm-public/postfix/dist/src/tls/tls_server.c patch
external/ibm-public/postfix/dist/src/util/events.c patch
external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus.h patch
external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_client.c patch
external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_server.c patch
Update Postfix to version 2.8.11:
- The "change header" milter request could replace the wrong header.
A long header name could match a shorter one, because a length check
was done on the wrong string. Reported by Vladimir Vassiliev.
- Core dump when postlog emitted the "usage" message, caused by an
extraneous null assignment. Reported by Kant (fnord.hammer).
- These releases add support to turn off the TLSv1.1 and TLSv1.2
protocols. Introduced with OpenSSL version 1.0.1, these protocols
are known to cause inter-operability problems, for example with some
hotmail services. The radical workaround is to temporarily turn off
problematic protocols globally:
/etc/postfix/main.cf:
smtp_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
smtp_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
smtpd_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
smtpd_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
However, it may be better to temporarily turn off problematic
protocols for broken sites only:
/etc/postfix/main.cf:
smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
/etc/postfix/tls_policy:
example.com may protocols=!SSLv2:!TLSv1.1:!TLSv1.2
Notes:
Note the use of ":" instead of comma or space. Also, note that there
is NO space around the "=" in "protocols=".
The smtp_tls_policy_maps lookup key must match the "next-hop"
destination that is given to the Postfix SMTP client. If you
override the next-hop destination with transport_maps, relayhost,
sender_dependent_relayhost_maps, or otherwise, you need to specify
the same destination for the smtp_tls_policy_maps lookup key.
- OpenSSL related (all supported Postfix versions).
Some people have reported program crashes when the OpenSSL library
was updated while Postfix was accessing the Postfix TLS session
cache. To avoid this, the Postfix TLS session cache ID now includes
the OpenSSL library version number. This cache ID is not shared via
the network.
- The OpenSSL workaround introduced with the previous stable and legacy
releases did not compile with older gcc compilers. These compilers cant handle #ifdef inside a macro invocation (NOT: definition).
- To avoid repeated warnings from postscreen(8) with "connect to
private/dnsblog service: Connection refused" on FreeBSD, the
dnsblog(8) daemon now uses the single_server program driver instead
of the multi_server driver. This one-line code change has no
performance impact for other systems, and eliminates a high-frequency
accept() race on a shared socket that appears to cause trouble on
FreeBSD. The same single_server program driver has proven itself for
many years in smtpd(8). Problem reported by Sahil Tandon.
- Laptop-friendly support (all supported Postfix versions). A
little-known secret is that Postfix has always had support to avoid
unnecessary disk spin-up for MTIME updates, by doing s/fifo/unix/
in master.cf (this is currently not supported on Solaris systems).
However, two minor fixes are needed to make this bullet-proof.
- In laptop-friendly mode, the "postqueue -f" and "sendmail -q"
commands did not wait until their requests had reached the pickup
and qmgr servers before closing their UNIX-domain request sockets.
- In laptop-friendly mode, the unused postkick command waited for more
than a minute because the event_drain() function was comparing
bitmasks incorrectly on systems with kqueue(2), epoll(2) or
/dev/poll support.
@
text
@d458 1
a458 1
smtp_tls_mandatory_protocols (!SSLv2)
@
1.1.1.4
log
@Import Postfix 2.8.11. Changes since version 2.8.8:
- The "change header" milter request could replace the wrong header. A long
header name could match a shorter one, because a length check was done on
the wrong string. Reported by Vladimir Vassiliev.
- Core dump when postlog emitted the "usage" message, caused by an extraneous
null assignment. Reported by Kant (fnord.hammer).
- These releases add support to turn off the TLSv1.1 and TLSv1.2 protocols.
Introduced with OpenSSL version 1.0.1, these protocols are known to cause
inter-operability problems, for example with some hotmail services.
The radical workaround is to temporarily turn off problematic protocols
globally:
/etc/postfix/main.cf:
smtp_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
smtp_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
smtpd_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
smtpd_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
However, it may be better to temporarily turn off problematic protocols for
broken sites only:
/etc/postfix/main.cf:
smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
/etc/postfix/tls_policy:
example.com may protocols=!SSLv2:!TLSv1.1:!TLSv1.2
Notes:
Note the use of ":" instead of comma or space. Also, note that there is NO
space around the "=" in "protocols=".
The smtp_tls_policy_maps lookup key must match the "next-hop" destination
that is given to the Postfix SMTP client. If you override the next-hop
destination with transport_maps, relayhost, sender_dependent_relayhost_maps,
or otherwise, you need to specify the same destination for the
smtp_tls_policy_maps lookup key.
- OpenSSL related (all supported Postfix versions).
Some people have reported program crashes when the OpenSSL library was
updated while Postfix was accessing the Postfix TLS session cache. To avoid
this, the Postfix TLS session cache ID now includes the OpenSSL library
version number. This cache ID is not shared via the network.
- The OpenSSL workaround introduced with the previous stable and legacy
releases did not compile with older gcc compilers. These compilers can't
handle #ifdef inside a macro invocation (NOT: definition).
- To avoid repeated warnings from postscreen(8) with "connect to
private/dnsblog service: Connection refused" on FreeBSD, the dnsblog(8)
daemon now uses the single_server program driver instead of the multi_server
driver. This one-line code change has no performance impact for other
systems, and eliminates a high-frequency accept() race on a shared socket
that appears to cause trouble on FreeBSD. The same single_server program
driver has proven itself for many years in smtpd(8). Problem reported by
Sahil Tandon.
- Laptop-friendly support (all supported Postfix versions). A little-known
secret is that Postfix has always had support to avoid unnecessary disk
spin-up for MTIME updates, by doing s/fifo/unix/ in master.cf (this is
currently not supported on Solaris systems). However, two minor fixes are
needed to make this bullet-proof.
- In laptop-friendly mode, the "postqueue -f" and "sendmail -q" commands did
not wait until their requests had reached the pickup and qmgr servers before
closing their UNIX-domain request sockets.
- In laptop-friendly mode, the unused postkick command waited for more than
a minute because the event_drain() function was comparing bitmasks
incorrectly on systems with kqueue(2), epoll(2) or /dev/poll support.
@
text
@d458 1
a458 1
smtp_tls_mandatory_protocols (!SSLv2)
@
1.1.1.4.2.1
log
@resync with head
@
text
@d171 1
a171 1
smtp_line_length_limit (998)
d196 2
a197 2
Quote addresses in Postfix SMTP client MAIL FROM
and RCPT TO commands as required by RFC 2821.
d204 2
a205 2
Skip remote SMTP servers that greet with a 5XX sta-
tus code (go away, do not try again later).
d234 3
a236 3
ing in the Postfix SMTP client, typically to trans-
form a locally valid address into a globally valid
address when sending mail across the Internet.
d252 2
a253 2
Postfix LMTP client will ignore in the LHLO
response from a remote LMTP server.
d257 3
a259 3
ing, starttls, auth, etc.) that the Postfix LMTP
client will ignore in the LHLO response from a
remote LMTP server.
a297 15
Available in Postfix version 2.9 and later:
smtp_per_record_deadline (no)
Change the behavior of the smtp_*_timeout time lim-
its, from a time limit per read or write system
call, to a time limit to send or receive a complete
record (an SMTP command line, SMTP response line,
SMTP message content line, or TLS protocol mes-
sage).
smtp_send_dummy_mail_auth (no)
Whether or not to append the "AUTH=<>" option to
the MAIL FROM command in SASL-authenticated SMTP
sessions.
d302 1
a302 1
Disable the conversion of 8BITMIME format to 7BIT
d317 2
a318 2
Send the non-standard XFORWARD command when the
Postfix SMTP server EHLO response announces XFOR-
d323 1
a323 1
Enable SASL authentication in the Postfix SMTP
d327 4
a330 4
Optional Postfix SMTP client lookup tables with one
username:password entry per remote hostname or
domain, or sender address when sender-dependent
authentication is enabled.
d333 3
a335 3
Postfix SMTP client SASL security options; as of
Postfix 2.3 the list of available features depends
on the SASL client implementation that is selected
d341 2
a342 2
If non-empty, a Postfix SMTP client filter for the
remote SMTP server's list of offered SASL mecha-
d349 3
a351 3
fix SMTP client; this is available only with SASL
authentication, and disables SMTP connection
caching to ensure that mail from different senders
d355 3
a357 3
Implementation-specific information that the Post-
fix SMTP client passes through to the SASL plug-in
implementation that is selected with
d361 1
a361 1
The SASL plug-in type that the Postfix SMTP client
d367 2
a368 2
An optional table to prevent repeated SASL authen-
tication failures with the same remote SMTP server
d372 1
a372 1
The maximal age of an smtp_sasl_auth_cache_name
d376 3
a378 3
When a remote SMTP server rejects a SASL authenti-
cation request with a 535 reply code, defer mail
delivery instead of returning mail as undeliver-
a380 7
Available in Postfix version 2.9 and later:
smtp_send_dummy_mail_auth (no)
Whether or not to append the "AUTH=<>" option to
the MAIL FROM command in SASL-authenticated SMTP
sessions.
d382 1
a382 1
Detailed information about STARTTLS configuration may be
d387 2
a388 2
SMTP client; when a non-empty value is specified,
this overrides the obsolete parameters
d394 2
a395 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d399 2
a400 2
Time limit for Postfix SMTP client write and read
operations during TLS startup and shutdown hand-
d404 2
a405 2
A file containing CA certificates of root CAs
trusted to sign either remote SMTP server certifi-
d409 2
a410 2
Directory with PEM format certificate authority
certificates that the Postfix SMTP client uses to
d414 1
a414 1
File with the Postfix SMTP client RSA certificate
d418 1
a418 1
The minimum TLS cipher grade that the Postfix SMTP
d427 3
a429 3
Additional list of ciphers or cipher types to
exclude from the Postfix SMTP client cipher list at
mandatory TLS security levels.
d432 1
a432 1
File with the Postfix SMTP client DSA certificate
d436 1
a436 1
File with the Postfix SMTP client DSA private key
d440 1
a440 1
File with the Postfix SMTP client RSA private key
d444 1
a444 1
Enable additional Postfix SMTP client logging of
d448 2
a449 2
Log the hostname of a remote SMTP server that
offers STARTTLS, when TLS is not already enabled
d455 1
a455 1
non-empty value is specified, this overrides the
d459 1
a459 1
List of SSL/TLS protocols that the Postfix SMTP
d463 1
a463 1
The verification depth for remote SMTP server cer-
d467 2
a468 3
How the Postfix SMTP client verifies the server
certificate peername for the "secure" TLS security
level.
d479 2
a480 3
How the Postfix SMTP client verifies the server
certificate peername for the "verify" TLS security
level.
d483 3
a485 3
The number of pseudo-random bytes that an smtp(8)
or smtpd(8) process requests from the tlsmgr(8)
server in order to seed its internal pseudo random
d497 1
a497 1
The OpenSSL cipherlist for "LOW" or higher grade
d505 1
a505 1
The OpenSSL cipherlist for "NULL" grade ciphers
d512 2
a513 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d519 2
a520 2
List of acceptable remote SMTP server certificate
fingerprints for the "fingerprint" TLS security
d524 1
a524 1
The message digest algorithm used to construct
d530 2
a531 2
List of TLS protocols that the Postfix SMTP client
will exclude or include with opportunistic TLS
d535 2
a536 2
The minimum TLS cipher grade that the Postfix SMTP
client will use with opportunistic TLS encryption.
d549 3
a551 3
Try to detect a mail hijacking attack based on a
TLS protocol vulnerability (CVE-2009-3555), where
an attacker prepends malicious HELO, MAIL, RCPT,
d557 1
a557 1
List or bit-mask of OpenSSL bug work-arounds to
d561 1
a561 1
The following configuration parameters exist for compati-
d566 2
a567 2
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
d571 2
a572 2
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
d576 1
a576 1
With mandatory TLS encryption, require that the
d582 1
a582 1
TLS usage policy by next-hop destination and by
d592 2
a593 2
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
d598 1
a598 1
The maximal number of recipients per message for
d602 2
a603 2
The Postfix SMTP client time limit for completing a
TCP connection, or zero (use the operating system
d607 3
a609 3
The Postfix SMTP client time limit for sending the
HELO or EHLO command, and for receiving the initial
remote SMTP server response.
d612 3
a614 3
The Postfix LMTP client time limit for sending the
LHLO command, and for receiving the initial remote
LMTP server response.
d617 2
a618 3
The Postfix SMTP client time limit for sending the
XFORWARD command, and for receiving the remote SMTP
server response.
d621 3
a623 3
The Postfix SMTP client time limit for sending the
MAIL FROM command, and for receiving the remote
SMTP server response.
d626 3
a628 3
The Postfix SMTP client time limit for sending the
SMTP RCPT TO command, and for receiving the remote
SMTP server response.
d631 3
a633 3
The Postfix SMTP client time limit for sending the
SMTP DATA command, and for receiving the remote
SMTP server response.
d636 2
a637 2
The Postfix SMTP client time limit for sending the
SMTP message content.
d640 2
a641 3
The Postfix SMTP client time limit for sending the
SMTP ".", and for receiving the remote SMTP server
response.
d644 2
a645 3
The Postfix SMTP client time limit for sending the
QUIT command, and for receiving the remote SMTP
server response.
d651 2
a652 2
addresses that can result from Postfix SMTP client
mail exchanger lookups, or zero (no limit).
d656 2
a657 3
request before the Postfix SMTP client gives up or
delivers to a fall-back relay host, or zero (no
limit).
d660 2
a661 3
The Postfix SMTP client time limit for sending the
RSET command, and for receiving the remote SMTP
server response.
a694 10
Available in Postfix version 2.9 and later:
smtp_per_record_deadline (no)
Change the behavior of the smtp_*_timeout time lim-
its, from a time limit per read or write system
call, to a time limit to send or receive a complete
record (an SMTP command line, SMTP response line,
SMTP message content line, or TLS protocol mes-
sage).
d697 2
a698 2
The increment in verbose logging level when a
remote client or server matches a pattern in the
d702 3
a704 3
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
d708 2
a709 2
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
d713 2
a714 2
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
d718 1
a718 1
The list of error classes that are reported to the
d723 1
a723 1
Where the Postfix SMTP client should deliver mail
d728 1
a728 1
The default location of the Postfix main.cf and
d732 2
a733 2
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
d737 1
a737 1
The maximal number of digits after the decimal
d741 1
a741 1
Disable DNS lookups in the Postfix SMTP and LMTP
d748 2
a749 2
inet_protocols (all)
The Internet protocols Postfix will attempt to use
d757 1
a757 1
When a remote LMTP server announces no DSN support,
d759 1
a759 1
send "delivered" delivery status notifications
d763 1
a763 1
The default TCP port that the Postfix LMTP client
d767 2
a768 2
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
d772 2
a773 2
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
d777 1
a777 1
The process ID of a Postfix command or daemon
d781 1
a781 1
The process name of a Postfix command or daemon
d786 1
a786 1
tem receives mail on by way of a proxy or network
d789 1
a789 1
smtp_address_preference (any)
d792 1
a792 1
tion has IPv6 and IPv4 addresses with equal MX
d796 2
a797 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d801 2
a802 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d806 1
a806 1
The hostname to send in the SMTP EHLO or HELO com-
d813 1
a813 1
What mechanisms the Postfix SMTP client uses to
d817 1
a817 1
Randomize the order of equal-preference MX host
d824 2
a825 2
The mail system name that is prepended to the
process name in syslog records, so that "smtpd"
d831 1
a831 1
Optional list of relay hosts for SMTP destinations
d837 1
a837 1
Optional list of relay hosts for SMTP destinations
d858 1
a858 1
The Secure Mailer license must be distributed with this
@
1.1.1.4.2.2
log
@Rebase to HEAD as of a few days ago.
@
text
@d16 31
a46 26
The Postfix SMTP+LMTP client implements the SMTP and LMTP mail delivery
protocols. It processes message delivery requests from the queue man-
ager. Each request specifies a queue file, a sender address, a domain
or host to deliver to, and recipient information. This program expects
to be run from the master(8) process manager.
The SMTP+LMTP client updates the queue file and marks recipients as
finished, or it informs the queue manager that delivery should be tried
again at a later time. Delivery status reports are sent to the
bounce(8), defer(8) or trace(8) daemon as appropriate.
The SMTP+LMTP client looks up a list of mail exchanger addresses for
the destination host, sorts the list by preference, and connects to
each listed address until it finds a server that responds.
When a server is not reachable, or when mail delivery fails due to a
recoverable error condition, the SMTP+LMTP client will try to deliver
the mail to an alternate host.
After a successful mail transaction, a connection may be saved to the
scache(8) connection cache server, so that it may be used by any
SMTP+LMTP client for a subsequent transaction.
By default, connection caching is enabled temporarily for destinations
that have a high volume of mail in the active queue. Connection caching
can be enabled permanently for specific destinations.
d54 3
a56 2
Look up the mail exchangers for the specified domain, and con-
nect to the specified port (default: smtp).
d61 2
a62 2
Look up the address(es) of the specified host, and connect to
the specified port (default: smtp).
d67 3
a69 3
Connect to the host at the specified address, and connect to the
specified port (default: smtp). An IPv6 address must be format-
ted as [ipv6:address].
d75 4
a78 3
Connect to the local UNIX-domain server that is bound to the
specified pathname. If the process runs chrooted, an absolute
pathname is interpreted relative to the Postfix queue directory.
d82 1
a82 1
inet:hostname:port
d87 6
a92 5
Connect to the specified TCP port on the specified local or
remote host. If no port is specified, connect to the port
defined as lmtp in services(4). If no such service is found,
the lmtp_tcp_port configuration parameter (default value of 24)
will be used. An IPv6 address must be formatted as
d96 4
a99 3
The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP
or LMTP servers and to DNS servers on the network. The SMTP+LMTP client
can be run chrooted at fixed low privilege.
a117 1
RFC 5321 (SMTP protocol)
d120 7
a126 6
Problems and transactions are logged to syslogd(8). Corrupted message
files are marked so that the queue manager can move them to the corrupt
queue for further inspection.
Depending on the setting of the notify_classes parameter, the postmas-
ter is notified of bounces, protocol problems, and of other trouble.
d129 8
a136 7
SMTP and LMTP connection caching does not work with TLS. The necessary
support for TLS object passivation and re-activation does not exist
without closing the session, which defeats the purpose.
SMTP and LMTP connection caching assumes that SASL credentials are
valid for all destinations that map onto the same IP address and TCP
port.
d139 14
a152 12
Before Postfix version 2.3, the LMTP client is a separate program that
implements only a subset of the functionality available with SMTP:
there is no support for TLS, and connections are cached in-process,
making it ineffective when the client is used for multiple domains.
Most smtp_xxx configuration parameters have an lmtp_xxx "mirror" param-
eter for the equivalent LMTP feature. This document describes only
those LMTP-related parameters that aren't simply "mirror" parameters.
Changes to main.cf are picked up automatically, as smtp(8) processes
run for only a limited amount of time. Use the command "postfix reload"
to speed up a change.
d154 2
a155 2
The text below provides only a parameter summary. See postconf(5) for
more details including examples.
d168 2
a169 1
Defer mail delivery when no MX record resolves to an IP address.
d172 2
a173 2
The maximal length of message header and body lines that Postfix
will send via SMTP.
d176 3
a178 3
How long the Postfix SMTP client pauses before sending
".<CR><LF>" in order to work around the PIX firewall
"<CR><LF>.<CR><LF>" bug.
d181 4
a184 3
How long a message must be queued before the Postfix SMTP client
turns on the PIX firewall "<CR><LF>.<CR><LF>" bug workaround for
delivery through firewalls with "smtp fixup" mode turned on.
d187 2
a188 2
A list that specifies zero or more workarounds for CISCO PIX
firewall bugs.
d191 3
a193 2
Lookup tables, indexed by the remote SMTP server address, with
per-destination workarounds for CISCO PIX firewall bugs.
d196 2
a197 2
Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO
commands as required by RFC 5321.
d200 2
a201 2
A mechanism to transform replies from remote SMTP servers one
line at a time.
d204 2
a205 1
Skip remote SMTP servers that greet with a 5XX status code.
d208 2
a209 1
Do not wait for the response to the SMTP QUIT command.
d214 2
a215 2
Skip SMTP servers that greet with a 4XX status code (go away,
try again later).
d220 4
a223 3
Lookup tables, indexed by the remote SMTP server address, with
case insensitive lists of EHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix SMTP client will ignore in the EHLO
d227 4
a230 3
A case insensitive list of EHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix SMTP client will ignore in the EHLO
response from a remote SMTP server.
d233 4
a236 4
Optional lookup tables that perform address rewriting in the
Postfix SMTP client, typically to transform a locally valid
address into a globally valid address when sending mail across
the Internet.
d241 4
a244 3
Allow DNS CNAME records to override the servername that the
Postfix SMTP client uses for logging, SASL password lookup, TLS
policy decisions, or TLS certificate verification.
d249 4
a252 3
Lookup tables, indexed by the remote LMTP server address, with
case insensitive lists of LHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix LMTP client will ignore in the LHLO
d256 4
a259 3
A case insensitive list of LHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix LMTP client will ignore in the LHLO
response from a remote LMTP server.
d264 4
a267 4
When authenticating to a remote SMTP or LMTP server with the
default setting "no", send no SASL authoriZation ID (authzid);
send only the SASL authentiCation ID (authcid) plus the auth-
cid's password.
d272 2
a273 1
Restricted header_checks(5) tables for the Postfix SMTP client.
d276 2
a277 2
Restricted mime_header_checks(5) tables for the Postfix SMTP
client.
d280 2
a281 2
Restricted nested_header_checks(5) tables for the Postfix SMTP
client.
d284 2
a285 1
Restricted body_checks(5) tables for the Postfix SMTP client.
d290 2
a291 2
An optional workaround for routers that break TCP window scal-
ing.
d301 5
a305 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
d309 3
a311 7
Whether or not to append the "AUTH=<>" option to the MAIL FROM
command in SASL-authenticated SMTP sessions.
Available in Postfix version 2.11 and later:
smtp_dns_support_level (empty)
Level of DNS support in the Postfix SMTP client.
d317 2
a318 1
Disable the conversion of 8BITMIME format to 7BIT format.
d321 2
a322 1
The maximal length of MIME multipart boundary strings.
d325 2
a326 1
The maximal recursion level that the MIME processor will handle.
d332 3
a334 2
Send the non-standard XFORWARD command when the Postfix SMTP
server EHLO response announces XFORWARD support.
d338 2
a339 1
Enable SASL authentication in the Postfix SMTP client.
d342 4
a345 3
Optional Postfix SMTP client lookup tables with one user-
name:password entry per remote hostname or domain, or sender
address when sender-dependent authentication is enabled.
d348 4
a351 3
Postfix SMTP client SASL security options; as of Postfix 2.3 the
list of available features depends on the SASL client implemen-
tation that is selected with smtp_sasl_type.
d356 3
a358 2
If non-empty, a Postfix SMTP client filter for the remote SMTP
server's list of offered SASL mechanisms.
d363 5
a367 4
Enable sender-dependent authentication in the Postfix SMTP
client; this is available only with SASL authentication, and
disables SMTP connection caching to ensure that mail from dif-
ferent senders will use the appropriate credentials.
d370 4
a373 3
Implementation-specific information that the Postfix SMTP client
passes through to the SASL plug-in implementation that is
selected with smtp_sasl_type.
d376 2
a377 2
The SASL plug-in type that the Postfix SMTP client should use
for authentication.
d382 3
a384 3
An optional table to prevent repeated SASL authentication fail-
ures with the same remote SMTP server hostname, username and
password.
d387 2
a388 2
The maximal age of an smtp_sasl_auth_cache_name entry before it
is removed.
d391 4
a394 3
When a remote SMTP server rejects a SASL authentication request
with a 535 reply code, defer mail delivery instead of returning
mail as undeliverable.
d399 3
a401 2
Whether or not to append the "AUTH=<>" option to the MAIL FROM
command in SASL-authenticated SMTP sessions.
d404 2
a405 2
Detailed information about STARTTLS configuration may be found in the
TLS_README document.
d408 4
a411 3
The default SMTP TLS security level for the Postfix SMTP client;
when a non-empty value is specified, this overrides the obsolete
parameters smtp_use_tls, smtp_enforce_tls, and
d414 5
a418 3
smtp_sasl_tls_security_options ($smtp_sasl_security_options)
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions.
d421 3
a423 2
Time limit for Postfix SMTP client write and read operations
during TLS startup and shutdown handshake procedures.
d426 3
a428 3
A file containing CA certificates of root CAs trusted to sign
either remote SMTP server certificates or intermediate CA cer-
tificates.
d431 3
a433 3
Directory with PEM format certificate authority certificates
that the Postfix SMTP client uses to verify a remote SMTP server
certificate.
d436 2
a437 1
File with the Postfix SMTP client RSA certificate in PEM format.
d440 2
a441 2
The minimum TLS cipher grade that the Postfix SMTP client will
use with mandatory TLS encryption.
d444 3
a446 2
List of ciphers or cipher types to exclude from the Postfix SMTP
client cipher list at all TLS security levels.
d449 3
a451 3
Additional list of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at mandatory TLS security lev-
els.
d454 2
a455 1
File with the Postfix SMTP client DSA certificate in PEM format.
d458 2
a459 1
File with the Postfix SMTP client DSA private key in PEM format.
d462 2
a463 1
File with the Postfix SMTP client RSA private key in PEM format.
d466 2
a467 1
Enable additional Postfix SMTP client logging of TLS activity.
d470 3
a472 2
Log the hostname of a remote SMTP server that offers STARTTLS,
when TLS is not already enabled for that server.
d475 4
a478 3
Optional lookup tables with the Postfix SMTP client TLS security
policy by next-hop destination; when a non-empty value is speci-
fied, this overrides the obsolete smtp_tls_per_site parameter.
d481 2
a482 2
List of SSL/TLS protocols that the Postfix SMTP client will use
with mandatory TLS encryption.
d485 2
a486 1
The verification depth for remote SMTP server certificates.
d489 3
a491 2
How the Postfix SMTP client verifies the server certificate
peername for the "secure" TLS security level.
d494 2
a495 2
Name of the file containing the optional Postfix SMTP client TLS
session cache.
d498 2
a499 2
The expiration time of Postfix SMTP client TLS session cache
information.
d502 3
a504 2
How the Postfix SMTP client verifies the server certificate
peername for the "verify" TLS security level.
d507 4
a510 3
The number of pseudo-random bytes that an smtp(8) or smtpd(8)
process requests from the tlsmgr(8) server in order to seed its
internal pseudo random number generator (PRNG).
d512 2
a513 1
tls_high_cipherlist (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
d517 2
a518 1
The OpenSSL cipherlist for "MEDIUM" or higher grade ciphers.
d521 2
a522 1
The OpenSSL cipherlist for "LOW" or higher grade ciphers.
d525 2
a526 1
The OpenSSL cipherlist for "EXPORT" or higher grade ciphers.
d529 2
a530 2
The OpenSSL cipherlist for "NULL" grade ciphers that provide
authentication without encryption.
d534 5
a538 5
smtp_sasl_tls_verified_security_options ($smtp_sasl_tls_secu-
rity_options)
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions with a verified
server certificate.
d543 3
a545 3
List of acceptable remote SMTP server certificate fingerprints
for the "fingerprint" TLS security level (smtp_tls_secu-
rity_level = fingerprint).
d548 2
a549 2
The message digest algorithm used to construct remote SMTP
server certificate fingerprints.
d554 3
a556 2
List of TLS protocols that the Postfix SMTP client will exclude
or include with opportunistic TLS encryption.
d559 2
a560 2
The minimum TLS cipher grade that the Postfix SMTP client will
use with opportunistic TLS encryption.
d563 2
a564 2
File with the Postfix SMTP client ECDSA certificate in PEM for-
mat.
d567 2
a568 2
File with the Postfix SMTP client ECDSA private key in PEM for-
mat.
d573 4
a576 4
Try to detect a mail hijacking attack based on a TLS protocol
vulnerability (CVE-2009-3555), where an attacker prepends mali-
cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client
TLS session.
d581 2
a582 17
List or bit-mask of OpenSSL bug work-arounds to disable.
Available in Postfix version 2.11 and later:
smtp_tls_trust_anchor_file (empty)
Zero or more PEM-format files with trust-anchor certificates
and/or public keys.
smtp_tls_force_insecure_host_tlsa_lookup (no)
Lookup the associated DANE TLSA RRset even when a hostname is
not an alias and its address records lie in an unsigned zone.
tls_dane_trust_anchor_digest_enable (yes)
RFC 6698 trust-anchor digest support in the Postfix TLS library.
tlsmgr_service_name (tlsmgr)
The name of the tlsmgr(8) service entry in master.cf.
d585 3
a587 3
The following configuration parameters exist for compatibility with
Postfix versions before 2.3. Support for these will be removed in a
future release.
d590 3
a592 2
Opportunistic mode: use TLS when a remote SMTP server announces
STARTTLS support, otherwise send the mail in the clear.
d595 3
a597 2
Enforcement mode: require that remote SMTP servers use TLS
encryption, and never send mail in the clear.
d600 3
a602 3
With mandatory TLS encryption, require that the remote SMTP
server hostname matches the information in the remote SMTP
server certificate.
d605 3
a607 3
Optional lookup tables with the Postfix SMTP client TLS usage
policy by next-hop destination and by remote SMTP server host-
name.
d610 2
a611 2
Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS
cipher list.
d614 10
a623 8
smtp_destination_concurrency_limit ($default_destination_concur-
rency_limit)
The maximal number of parallel deliveries to the same destina-
tion via the smtp message delivery transport.
smtp_destination_recipient_limit ($default_destination_recipient_limit)
The maximal number of recipients per message for the smtp mes-
sage delivery transport.
d626 3
a628 2
The Postfix SMTP client time limit for completing a TCP connec-
tion, or zero (use the operating system built-in time limit).
d631 3
a633 3
The Postfix SMTP client time limit for sending the HELO or EHLO
command, and for receiving the initial remote SMTP server
response.
d636 3
a638 2
The Postfix LMTP client time limit for sending the LHLO command,
and for receiving the initial remote LMTP server response.
d641 3
a643 2
The Postfix SMTP client time limit for sending the XFORWARD com-
mand, and for receiving the remote SMTP server response.
d646 3
a648 2
The Postfix SMTP client time limit for sending the MAIL FROM
command, and for receiving the remote SMTP server response.
d651 3
a653 2
The Postfix SMTP client time limit for sending the SMTP RCPT TO
command, and for receiving the remote SMTP server response.
d656 3
a658 2
The Postfix SMTP client time limit for sending the SMTP DATA
command, and for receiving the remote SMTP server response.
d661 2
a662 2
The Postfix SMTP client time limit for sending the SMTP message
content.
d665 3
a667 2
The Postfix SMTP client time limit for sending the SMTP ".", and
for receiving the remote SMTP server response.
d670 3
a672 2
The Postfix SMTP client time limit for sending the QUIT command,
and for receiving the remote SMTP server response.
d677 3
a679 3
The maximal number of MX (mail exchanger) IP addresses that can
result from Postfix SMTP client mail exchanger lookups, or zero
(no limit).
d682 4
a685 3
The maximal number of SMTP sessions per delivery request before
the Postfix SMTP client gives up or delivers to a fall-back
relay host, or zero (no limit).
d688 3
a690 2
The Postfix SMTP client time limit for sending the RSET command,
and for receiving the remote SMTP server response.
d695 2
a696 2
Keep Postfix LMTP client connections open for up to $max_idle
seconds.
d701 2
a702 2
Permanently enable SMTP connection caching for the specified
destinations.
d705 3
a707 2
Temporarily enable SMTP connection caching while a destination
has a high volume of mail in the active queue.
d710 2
a711 2
The amount of time during which Postfix will use an SMTP connec-
tion repeatedly.
d714 3
a716 2
When SMTP connection caching is enabled, the amount of time that
an unused SMTP client socket is kept open before it is closed.
d721 2
a722 2
Time limit for connection cache connect, send or receive opera-
tions.
d727 5
a731 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
a733 7
Available in Postfix version 2.11 and later:
smtp_connection_reuse_count_limit (0)
When SMTP connection caching is enabled, the number of times
that an SMTP session may be reused before it is closed, or zero
(no limit).
d736 3
a738 2
The increment in verbose logging level when a remote client or
server matches a pattern in the debug_peer_list parameter.
d741 4
a744 3
Optional list of remote client or server hostname or network
address patterns that cause the verbose logging level to
increase by the amount specified in $debug_peer_level.
d747 3
a749 3
The recipient of postmaster notifications about mail delivery
problems that are caused by policy, resource, software or proto-
col errors.
d752 3
a754 3
What categories of Postfix-generated mail are subject to before-
queue content inspection by non_smtpd_milters, header_checks and
body_checks.
d757 2
a758 1
The list of error classes that are reported to the postmaster.
d762 3
a764 2
Where the Postfix SMTP client should deliver mail when it
detects a "mail loops back to myself" error condition.
d767 2
a768 2
The default location of the Postfix main.cf and master.cf con-
figuration files.
d771 3
a773 2
How much time a Postfix daemon process may take to handle a
request before it is terminated by a built-in watchdog timer.
d776 2
a777 2
The maximal number of digits after the decimal point when log-
ging sub-second delay values.
d780 2
a781 1
Disable DNS lookups in the Postfix SMTP and LMTP clients.
d784 2
a785 2
The network interface addresses that this mail system receives
mail on.
d788 2
a789 2
The Internet protocols Postfix will attempt to use when making
or accepting connections.
d792 2
a793 2
The time limit for sending or receiving information over an
internal communication channel.
d796 4
a799 3
When a remote LMTP server announces no DSN support, assume that
the server performs final delivery, and send "delivered" deliv-
ery status notifications instead of "relayed".
d802 2
a803 1
The default TCP port that the Postfix LMTP client connects to.
d806 3
a808 2
The maximum amount of time that an idle Postfix daemon process
waits for an incoming connection before terminating voluntarily.
d811 3
a813 2
The maximal number of incoming connections that a Postfix daemon
process will service before terminating voluntarily.
d816 2
a817 1
The process ID of a Postfix command or daemon process.
d820 2
a821 1
The process name of a Postfix command or daemon process.
d824 3
a826 2
The network interface addresses that this mail system receives
mail on by way of a proxy or network address translation unit.
d829 4
a832 3
The address type ("ipv6", "ipv4" or "any") that the Postfix SMTP
client will try first, when a destination has IPv6 and IPv4
addresses with equal MX preference.
d835 3
a837 2
An optional numerical network address that the Postfix SMTP
client should bind to when making an IPv4 connection.
d840 3
a842 2
An optional numerical network address that the Postfix SMTP
client should bind to when making an IPv6 connection.
d845 2
a846 1
The hostname to send in the SMTP EHLO or HELO command.
d852 2
a853 2
What mechanisms the Postfix SMTP client uses to look up a host's
IP address.
d856 2
a857 1
Randomize the order of equal-preference MX host addresses.
d863 3
a865 3
The mail system name that is prepended to the process name in
syslog records, so that "smtpd" becomes, for example, "post-
fix/smtpd".
d870 2
a871 2
Optional list of relay hosts for SMTP destinations that can't be
found or that are unreachable.
d876 2
a877 2
Optional list of relay hosts for SMTP destinations that can't be
found or that are unreachable.
d897 2
a898 1
The Secure Mailer license must be distributed with this software.
@
1.1.1.5
log
@Import Postfix 2.9.5. Major changes since version 2.8.x:
- Support for long, non-repeating, queue IDs (queue file names). The
main benefit of non-repeating names is simpler logfile analysis. See
the description of "enable_long_queue_ids" in postconf(5) for
details.
- Memcache client support, and support to share postscreen(8) and
verify(8) caches via the proxymap server. Details about memcache
support are in memcache_table(5) and MEMCACHE_README.
- Gradual degradation: if a database is unavailable (can't open, most
read or write errors) a Postfix daemon will log a warning and
continue providing the services that don't depend on that table,
instead of immediately terminating with a fatal error. To terminate
immediately when a database file can't be opened, specify
"daemon_table_open_error_is_fatal = yes".
- Revised postconf(1) command. It warns about unused parameter
name=value settings in main.cf or master.cf (likely mistakes),
understands "dynamic" parameter names such as names that depend on
the name of a master.cf entry (finally, "postconf -n" shows all
parameter settings), and it can display main.cf and master.cf in a
more user-friendly format (postconf -nf, postconf -Mf).
- Read/write deadline support in the SMTP client and server to defend
against application-level DOS attacks that very slowly write or read
data one byte at a time.
@
text
@d171 1
a171 1
smtp_line_length_limit (998)
d196 2
a197 2
Quote addresses in Postfix SMTP client MAIL FROM
and RCPT TO commands as required by RFC 2821.
d204 2
a205 2
Skip remote SMTP servers that greet with a 5XX sta-
tus code (go away, do not try again later).
d234 3
a236 3
ing in the Postfix SMTP client, typically to trans-
form a locally valid address into a globally valid
address when sending mail across the Internet.
d252 2
a253 2
Postfix LMTP client will ignore in the LHLO
response from a remote LMTP server.
d257 3
a259 3
ing, starttls, auth, etc.) that the Postfix LMTP
client will ignore in the LHLO response from a
remote LMTP server.
a297 15
Available in Postfix version 2.9 and later:
smtp_per_record_deadline (no)
Change the behavior of the smtp_*_timeout time lim-
its, from a time limit per read or write system
call, to a time limit to send or receive a complete
record (an SMTP command line, SMTP response line,
SMTP message content line, or TLS protocol mes-
sage).
smtp_send_dummy_mail_auth (no)
Whether or not to append the "AUTH=<>" option to
the MAIL FROM command in SASL-authenticated SMTP
sessions.
d302 1
a302 1
Disable the conversion of 8BITMIME format to 7BIT
d317 2
a318 2
Send the non-standard XFORWARD command when the
Postfix SMTP server EHLO response announces XFOR-
d323 1
a323 1
Enable SASL authentication in the Postfix SMTP
d327 4
a330 4
Optional Postfix SMTP client lookup tables with one
username:password entry per remote hostname or
domain, or sender address when sender-dependent
authentication is enabled.
d333 3
a335 3
Postfix SMTP client SASL security options; as of
Postfix 2.3 the list of available features depends
on the SASL client implementation that is selected
d341 2
a342 2
If non-empty, a Postfix SMTP client filter for the
remote SMTP server's list of offered SASL mecha-
d349 3
a351 3
fix SMTP client; this is available only with SASL
authentication, and disables SMTP connection
caching to ensure that mail from different senders
d355 3
a357 3
Implementation-specific information that the Post-
fix SMTP client passes through to the SASL plug-in
implementation that is selected with
d361 1
a361 1
The SASL plug-in type that the Postfix SMTP client
d367 2
a368 2
An optional table to prevent repeated SASL authen-
tication failures with the same remote SMTP server
d372 1
a372 1
The maximal age of an smtp_sasl_auth_cache_name
d376 3
a378 3
When a remote SMTP server rejects a SASL authenti-
cation request with a 535 reply code, defer mail
delivery instead of returning mail as undeliver-
a380 7
Available in Postfix version 2.9 and later:
smtp_send_dummy_mail_auth (no)
Whether or not to append the "AUTH=<>" option to
the MAIL FROM command in SASL-authenticated SMTP
sessions.
d382 1
a382 1
Detailed information about STARTTLS configuration may be
d387 2
a388 2
SMTP client; when a non-empty value is specified,
this overrides the obsolete parameters
d394 2
a395 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d399 2
a400 2
Time limit for Postfix SMTP client write and read
operations during TLS startup and shutdown hand-
d404 2
a405 2
A file containing CA certificates of root CAs
trusted to sign either remote SMTP server certifi-
d409 2
a410 2
Directory with PEM format certificate authority
certificates that the Postfix SMTP client uses to
d414 1
a414 1
File with the Postfix SMTP client RSA certificate
d418 1
a418 1
The minimum TLS cipher grade that the Postfix SMTP
d427 3
a429 3
Additional list of ciphers or cipher types to
exclude from the Postfix SMTP client cipher list at
mandatory TLS security levels.
d432 1
a432 1
File with the Postfix SMTP client DSA certificate
d436 1
a436 1
File with the Postfix SMTP client DSA private key
d440 1
a440 1
File with the Postfix SMTP client RSA private key
d444 1
a444 1
Enable additional Postfix SMTP client logging of
d448 2
a449 2
Log the hostname of a remote SMTP server that
offers STARTTLS, when TLS is not already enabled
d455 1
a455 1
non-empty value is specified, this overrides the
d459 1
a459 1
List of SSL/TLS protocols that the Postfix SMTP
d463 1
a463 1
The verification depth for remote SMTP server cer-
d467 2
a468 3
How the Postfix SMTP client verifies the server
certificate peername for the "secure" TLS security
level.
d479 2
a480 3
How the Postfix SMTP client verifies the server
certificate peername for the "verify" TLS security
level.
d483 3
a485 3
The number of pseudo-random bytes that an smtp(8)
or smtpd(8) process requests from the tlsmgr(8)
server in order to seed its internal pseudo random
d497 1
a497 1
The OpenSSL cipherlist for "LOW" or higher grade
d505 1
a505 1
The OpenSSL cipherlist for "NULL" grade ciphers
d512 2
a513 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d519 2
a520 2
List of acceptable remote SMTP server certificate
fingerprints for the "fingerprint" TLS security
d524 1
a524 1
The message digest algorithm used to construct
d530 2
a531 2
List of TLS protocols that the Postfix SMTP client
will exclude or include with opportunistic TLS
d535 2
a536 2
The minimum TLS cipher grade that the Postfix SMTP
client will use with opportunistic TLS encryption.
d549 3
a551 3
Try to detect a mail hijacking attack based on a
TLS protocol vulnerability (CVE-2009-3555), where
an attacker prepends malicious HELO, MAIL, RCPT,
d557 1
a557 1
List or bit-mask of OpenSSL bug work-arounds to
d561 1
a561 1
The following configuration parameters exist for compati-
d566 2
a567 2
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
d571 2
a572 2
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
d576 1
a576 1
With mandatory TLS encryption, require that the
d582 1
a582 1
TLS usage policy by next-hop destination and by
d592 2
a593 2
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
d598 1
a598 1
The maximal number of recipients per message for
d602 2
a603 2
The Postfix SMTP client time limit for completing a
TCP connection, or zero (use the operating system
d607 3
a609 3
The Postfix SMTP client time limit for sending the
HELO or EHLO command, and for receiving the initial
remote SMTP server response.
d612 3
a614 3
The Postfix LMTP client time limit for sending the
LHLO command, and for receiving the initial remote
LMTP server response.
d617 2
a618 3
The Postfix SMTP client time limit for sending the
XFORWARD command, and for receiving the remote SMTP
server response.
d621 3
a623 3
The Postfix SMTP client time limit for sending the
MAIL FROM command, and for receiving the remote
SMTP server response.
d626 3
a628 3
The Postfix SMTP client time limit for sending the
SMTP RCPT TO command, and for receiving the remote
SMTP server response.
d631 3
a633 3
The Postfix SMTP client time limit for sending the
SMTP DATA command, and for receiving the remote
SMTP server response.
d636 2
a637 2
The Postfix SMTP client time limit for sending the
SMTP message content.
d640 2
a641 3
The Postfix SMTP client time limit for sending the
SMTP ".", and for receiving the remote SMTP server
response.
d644 2
a645 3
The Postfix SMTP client time limit for sending the
QUIT command, and for receiving the remote SMTP
server response.
d651 2
a652 2
addresses that can result from Postfix SMTP client
mail exchanger lookups, or zero (no limit).
d656 2
a657 3
request before the Postfix SMTP client gives up or
delivers to a fall-back relay host, or zero (no
limit).
d660 2
a661 3
The Postfix SMTP client time limit for sending the
RSET command, and for receiving the remote SMTP
server response.
a694 10
Available in Postfix version 2.9 and later:
smtp_per_record_deadline (no)
Change the behavior of the smtp_*_timeout time lim-
its, from a time limit per read or write system
call, to a time limit to send or receive a complete
record (an SMTP command line, SMTP response line,
SMTP message content line, or TLS protocol mes-
sage).
d697 2
a698 2
The increment in verbose logging level when a
remote client or server matches a pattern in the
d702 3
a704 3
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
d708 2
a709 2
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
d713 2
a714 2
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
d718 1
a718 1
The list of error classes that are reported to the
d723 1
a723 1
Where the Postfix SMTP client should deliver mail
d728 1
a728 1
The default location of the Postfix main.cf and
d732 2
a733 2
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
d737 1
a737 1
The maximal number of digits after the decimal
d741 1
a741 1
Disable DNS lookups in the Postfix SMTP and LMTP
d748 2
a749 2
inet_protocols (all)
The Internet protocols Postfix will attempt to use
d757 1
a757 1
When a remote LMTP server announces no DSN support,
d759 1
a759 1
send "delivered" delivery status notifications
d763 1
a763 1
The default TCP port that the Postfix LMTP client
d767 2
a768 2
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
d772 2
a773 2
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
d777 1
a777 1
The process ID of a Postfix command or daemon
d781 1
a781 1
The process name of a Postfix command or daemon
d786 1
a786 1
tem receives mail on by way of a proxy or network
d789 1
a789 1
smtp_address_preference (any)
d792 1
a792 1
tion has IPv6 and IPv4 addresses with equal MX
d796 2
a797 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d801 2
a802 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d806 1
a806 1
The hostname to send in the SMTP EHLO or HELO com-
d813 1
a813 1
What mechanisms the Postfix SMTP client uses to
d817 1
a817 1
Randomize the order of equal-preference MX host
d824 2
a825 2
The mail system name that is prepended to the
process name in syslog records, so that "smtpd"
d831 1
a831 1
Optional list of relay hosts for SMTP destinations
d837 1
a837 1
Optional list of relay hosts for SMTP destinations
d858 1
a858 1
The Secure Mailer license must be distributed with this
@
1.1.1.6
log
@Import Postfix 2.10.2. Major changes since version 2.9.* are:
- Separation of relay policy (with smtpd_relay_restrictions) from spam policy
(with smtpd_{client, helo, sender, recipient}_restrictions), which makes
accidental open relay configuration less likely. The default is backwards
compatible.
- HAproxy load-balancer support for postscreen(8) and smtpd(8). The nginx
proxy was already supported by Postfix 2.9 smtpd(8), using XCLIENT commands.
- Support for the TLSv1 and TLSv2 protocols, as well as support to turn them
off if needed for inter-operability.
- Laptop-friendly configuration. By default, Postfix now uses UNIX-domain
sockets instead of FIFOs, and thus avoids MTIME file system updates on an
idle mail system.
- Revised postconf(1) command. The "-x" option expands $name in a parameter
value (both main.cf and master.cf); the "-o name=value" option overrides
a main.cf parameter setting; and postconf(1) now warns about a $name that
has no name=value setting.
- Sendmail-style "socketmap" lookup tables.
@
text
@a117 1
RFC 5321 (SMTP protocol)
d197 1
a197 1
and RCPT TO commands as required by RFC 5321.
@
1.1.1.6.2.1
log
@Rebase.
@
text
@d16 31
a46 26
The Postfix SMTP+LMTP client implements the SMTP and LMTP mail delivery
protocols. It processes message delivery requests from the queue man-
ager. Each request specifies a queue file, a sender address, a domain
or host to deliver to, and recipient information. This program expects
to be run from the master(8) process manager.
The SMTP+LMTP client updates the queue file and marks recipients as
finished, or it informs the queue manager that delivery should be tried
again at a later time. Delivery status reports are sent to the
bounce(8), defer(8) or trace(8) daemon as appropriate.
The SMTP+LMTP client looks up a list of mail exchanger addresses for
the destination host, sorts the list by preference, and connects to
each listed address until it finds a server that responds.
When a server is not reachable, or when mail delivery fails due to a
recoverable error condition, the SMTP+LMTP client will try to deliver
the mail to an alternate host.
After a successful mail transaction, a connection may be saved to the
scache(8) connection cache server, so that it may be used by any
SMTP+LMTP client for a subsequent transaction.
By default, connection caching is enabled temporarily for destinations
that have a high volume of mail in the active queue. Connection caching
can be enabled permanently for specific destinations.
d54 3
a56 2
Look up the mail exchangers for the specified domain, and con-
nect to the specified port (default: smtp).
d61 2
a62 2
Look up the address(es) of the specified host, and connect to
the specified port (default: smtp).
d67 3
a69 3
Connect to the host at the specified address, and connect to the
specified port (default: smtp). An IPv6 address must be format-
ted as [ipv6:address].
d75 4
a78 3
Connect to the local UNIX-domain server that is bound to the
specified pathname. If the process runs chrooted, an absolute
pathname is interpreted relative to the Postfix queue directory.
d82 1
a82 1
inet:hostname:port
d87 6
a92 5
Connect to the specified TCP port on the specified local or
remote host. If no port is specified, connect to the port
defined as lmtp in services(4). If no such service is found,
the lmtp_tcp_port configuration parameter (default value of 24)
will be used. An IPv6 address must be formatted as
d96 4
a99 3
The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP
or LMTP servers and to DNS servers on the network. The SMTP+LMTP client
can be run chrooted at fixed low privilege.
d121 7
a127 6
Problems and transactions are logged to syslogd(8). Corrupted message
files are marked so that the queue manager can move them to the corrupt
queue for further inspection.
Depending on the setting of the notify_classes parameter, the postmas-
ter is notified of bounces, protocol problems, and of other trouble.
d130 8
a137 7
SMTP and LMTP connection caching does not work with TLS. The necessary
support for TLS object passivation and re-activation does not exist
without closing the session, which defeats the purpose.
SMTP and LMTP connection caching assumes that SASL credentials are
valid for all destinations that map onto the same IP address and TCP
port.
d140 14
a153 12
Before Postfix version 2.3, the LMTP client is a separate program that
implements only a subset of the functionality available with SMTP:
there is no support for TLS, and connections are cached in-process,
making it ineffective when the client is used for multiple domains.
Most smtp_xxx configuration parameters have an lmtp_xxx "mirror" param-
eter for the equivalent LMTP feature. This document describes only
those LMTP-related parameters that aren't simply "mirror" parameters.
Changes to main.cf are picked up automatically, as smtp(8) processes
run for only a limited amount of time. Use the command "postfix reload"
to speed up a change.
d155 2
a156 2
The text below provides only a parameter summary. See postconf(5) for
more details including examples.
d169 2
a170 1
Defer mail delivery when no MX record resolves to an IP address.
d173 2
a174 2
The maximal length of message header and body lines that Postfix
will send via SMTP.
d177 3
a179 3
How long the Postfix SMTP client pauses before sending
".<CR><LF>" in order to work around the PIX firewall
"<CR><LF>.<CR><LF>" bug.
d182 4
a185 3
How long a message must be queued before the Postfix SMTP client
turns on the PIX firewall "<CR><LF>.<CR><LF>" bug workaround for
delivery through firewalls with "smtp fixup" mode turned on.
d188 2
a189 2
A list that specifies zero or more workarounds for CISCO PIX
firewall bugs.
d192 3
a194 2
Lookup tables, indexed by the remote SMTP server address, with
per-destination workarounds for CISCO PIX firewall bugs.
d197 2
a198 2
Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO
commands as required by RFC 5321.
d201 2
a202 2
A mechanism to transform replies from remote SMTP servers one
line at a time.
d205 2
a206 1
Skip remote SMTP servers that greet with a 5XX status code.
d209 2
a210 1
Do not wait for the response to the SMTP QUIT command.
d215 2
a216 2
Skip SMTP servers that greet with a 4XX status code (go away,
try again later).
d221 4
a224 3
Lookup tables, indexed by the remote SMTP server address, with
case insensitive lists of EHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix SMTP client will ignore in the EHLO
d228 4
a231 3
A case insensitive list of EHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix SMTP client will ignore in the EHLO
response from a remote SMTP server.
d234 4
a237 4
Optional lookup tables that perform address rewriting in the
Postfix SMTP client, typically to transform a locally valid
address into a globally valid address when sending mail across
the Internet.
d242 4
a245 3
Allow DNS CNAME records to override the servername that the
Postfix SMTP client uses for logging, SASL password lookup, TLS
policy decisions, or TLS certificate verification.
d250 4
a253 3
Lookup tables, indexed by the remote LMTP server address, with
case insensitive lists of LHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix LMTP client will ignore in the LHLO
d257 4
a260 3
A case insensitive list of LHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix LMTP client will ignore in the LHLO
response from a remote LMTP server.
d265 4
a268 4
When authenticating to a remote SMTP or LMTP server with the
default setting "no", send no SASL authoriZation ID (authzid);
send only the SASL authentiCation ID (authcid) plus the auth-
cid's password.
d273 2
a274 1
Restricted header_checks(5) tables for the Postfix SMTP client.
d277 2
a278 2
Restricted mime_header_checks(5) tables for the Postfix SMTP
client.
d281 2
a282 2
Restricted nested_header_checks(5) tables for the Postfix SMTP
client.
d285 2
a286 1
Restricted body_checks(5) tables for the Postfix SMTP client.
d291 2
a292 2
An optional workaround for routers that break TCP window scal-
ing.
d302 5
a306 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
d310 3
a312 7
Whether or not to append the "AUTH=<>" option to the MAIL FROM
command in SASL-authenticated SMTP sessions.
Available in Postfix version 2.11 and later:
smtp_dns_support_level (empty)
Level of DNS support in the Postfix SMTP client.
d318 2
a319 1
Disable the conversion of 8BITMIME format to 7BIT format.
d322 2
a323 1
The maximal length of MIME multipart boundary strings.
d326 2
a327 1
The maximal recursion level that the MIME processor will handle.
d333 3
a335 2
Send the non-standard XFORWARD command when the Postfix SMTP
server EHLO response announces XFORWARD support.
d339 2
a340 1
Enable SASL authentication in the Postfix SMTP client.
d343 4
a346 3
Optional Postfix SMTP client lookup tables with one user-
name:password entry per remote hostname or domain, or sender
address when sender-dependent authentication is enabled.
d349 4
a352 3
Postfix SMTP client SASL security options; as of Postfix 2.3 the
list of available features depends on the SASL client implemen-
tation that is selected with smtp_sasl_type.
d357 3
a359 2
If non-empty, a Postfix SMTP client filter for the remote SMTP
server's list of offered SASL mechanisms.
d364 5
a368 4
Enable sender-dependent authentication in the Postfix SMTP
client; this is available only with SASL authentication, and
disables SMTP connection caching to ensure that mail from dif-
ferent senders will use the appropriate credentials.
d371 4
a374 3
Implementation-specific information that the Postfix SMTP client
passes through to the SASL plug-in implementation that is
selected with smtp_sasl_type.
d377 2
a378 2
The SASL plug-in type that the Postfix SMTP client should use
for authentication.
d383 3
a385 3
An optional table to prevent repeated SASL authentication fail-
ures with the same remote SMTP server hostname, username and
password.
d388 2
a389 2
The maximal age of an smtp_sasl_auth_cache_name entry before it
is removed.
d392 4
a395 3
When a remote SMTP server rejects a SASL authentication request
with a 535 reply code, defer mail delivery instead of returning
mail as undeliverable.
d400 3
a402 2
Whether or not to append the "AUTH=<>" option to the MAIL FROM
command in SASL-authenticated SMTP sessions.
d405 2
a406 2
Detailed information about STARTTLS configuration may be found in the
TLS_README document.
d409 4
a412 3
The default SMTP TLS security level for the Postfix SMTP client;
when a non-empty value is specified, this overrides the obsolete
parameters smtp_use_tls, smtp_enforce_tls, and
d415 5
a419 3
smtp_sasl_tls_security_options ($smtp_sasl_security_options)
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions.
d422 3
a424 2
Time limit for Postfix SMTP client write and read operations
during TLS startup and shutdown handshake procedures.
d427 3
a429 3
A file containing CA certificates of root CAs trusted to sign
either remote SMTP server certificates or intermediate CA cer-
tificates.
d432 3
a434 3
Directory with PEM format certificate authority certificates
that the Postfix SMTP client uses to verify a remote SMTP server
certificate.
d437 2
a438 1
File with the Postfix SMTP client RSA certificate in PEM format.
d441 2
a442 2
The minimum TLS cipher grade that the Postfix SMTP client will
use with mandatory TLS encryption.
d445 3
a447 2
List of ciphers or cipher types to exclude from the Postfix SMTP
client cipher list at all TLS security levels.
d450 3
a452 3
Additional list of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at mandatory TLS security lev-
els.
d455 2
a456 1
File with the Postfix SMTP client DSA certificate in PEM format.
d459 2
a460 1
File with the Postfix SMTP client DSA private key in PEM format.
d463 2
a464 1
File with the Postfix SMTP client RSA private key in PEM format.
d467 2
a468 1
Enable additional Postfix SMTP client logging of TLS activity.
d471 3
a473 2
Log the hostname of a remote SMTP server that offers STARTTLS,
when TLS is not already enabled for that server.
d476 4
a479 3
Optional lookup tables with the Postfix SMTP client TLS security
policy by next-hop destination; when a non-empty value is speci-
fied, this overrides the obsolete smtp_tls_per_site parameter.
d482 2
a483 2
List of SSL/TLS protocols that the Postfix SMTP client will use
with mandatory TLS encryption.
d486 2
a487 1
The verification depth for remote SMTP server certificates.
d490 3
a492 2
How the Postfix SMTP client verifies the server certificate
peername for the "secure" TLS security level.
d495 2
a496 2
Name of the file containing the optional Postfix SMTP client TLS
session cache.
d499 2
a500 2
The expiration time of Postfix SMTP client TLS session cache
information.
d503 3
a505 2
How the Postfix SMTP client verifies the server certificate
peername for the "verify" TLS security level.
d508 4
a511 3
The number of pseudo-random bytes that an smtp(8) or smtpd(8)
process requests from the tlsmgr(8) server in order to seed its
internal pseudo random number generator (PRNG).
d513 2
a514 1
tls_high_cipherlist (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
d518 2
a519 1
The OpenSSL cipherlist for "MEDIUM" or higher grade ciphers.
d522 2
a523 1
The OpenSSL cipherlist for "LOW" or higher grade ciphers.
d526 2
a527 1
The OpenSSL cipherlist for "EXPORT" or higher grade ciphers.
d530 2
a531 2
The OpenSSL cipherlist for "NULL" grade ciphers that provide
authentication without encryption.
d535 5
a539 5
smtp_sasl_tls_verified_security_options ($smtp_sasl_tls_secu-
rity_options)
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions with a verified
server certificate.
d544 3
a546 3
List of acceptable remote SMTP server certificate fingerprints
for the "fingerprint" TLS security level (smtp_tls_secu-
rity_level = fingerprint).
d549 2
a550 2
The message digest algorithm used to construct remote SMTP
server certificate fingerprints.
d555 3
a557 2
List of TLS protocols that the Postfix SMTP client will exclude
or include with opportunistic TLS encryption.
d560 2
a561 2
The minimum TLS cipher grade that the Postfix SMTP client will
use with opportunistic TLS encryption.
d564 2
a565 2
File with the Postfix SMTP client ECDSA certificate in PEM for-
mat.
d568 2
a569 2
File with the Postfix SMTP client ECDSA private key in PEM for-
mat.
d574 4
a577 4
Try to detect a mail hijacking attack based on a TLS protocol
vulnerability (CVE-2009-3555), where an attacker prepends mali-
cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client
TLS session.
d582 2
a583 17
List or bit-mask of OpenSSL bug work-arounds to disable.
Available in Postfix version 2.11 and later:
smtp_tls_trust_anchor_file (empty)
Zero or more PEM-format files with trust-anchor certificates
and/or public keys.
smtp_tls_force_insecure_host_tlsa_lookup (no)
Lookup the associated DANE TLSA RRset even when a hostname is
not an alias and its address records lie in an unsigned zone.
tls_dane_trust_anchor_digest_enable (yes)
RFC 6698 trust-anchor digest support in the Postfix TLS library.
tlsmgr_service_name (tlsmgr)
The name of the tlsmgr(8) service entry in master.cf.
d586 3
a588 3
The following configuration parameters exist for compatibility with
Postfix versions before 2.3. Support for these will be removed in a
future release.
d591 3
a593 2
Opportunistic mode: use TLS when a remote SMTP server announces
STARTTLS support, otherwise send the mail in the clear.
d596 3
a598 2
Enforcement mode: require that remote SMTP servers use TLS
encryption, and never send mail in the clear.
d601 3
a603 3
With mandatory TLS encryption, require that the remote SMTP
server hostname matches the information in the remote SMTP
server certificate.
d606 3
a608 3
Optional lookup tables with the Postfix SMTP client TLS usage
policy by next-hop destination and by remote SMTP server host-
name.
d611 2
a612 2
Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS
cipher list.
d615 10
a624 8
smtp_destination_concurrency_limit ($default_destination_concur-
rency_limit)
The maximal number of parallel deliveries to the same destina-
tion via the smtp message delivery transport.
smtp_destination_recipient_limit ($default_destination_recipient_limit)
The maximal number of recipients per message for the smtp mes-
sage delivery transport.
d627 3
a629 2
The Postfix SMTP client time limit for completing a TCP connec-
tion, or zero (use the operating system built-in time limit).
d632 3
a634 3
The Postfix SMTP client time limit for sending the HELO or EHLO
command, and for receiving the initial remote SMTP server
response.
d637 3
a639 2
The Postfix LMTP client time limit for sending the LHLO command,
and for receiving the initial remote LMTP server response.
d642 3
a644 2
The Postfix SMTP client time limit for sending the XFORWARD com-
mand, and for receiving the remote SMTP server response.
d647 3
a649 2
The Postfix SMTP client time limit for sending the MAIL FROM
command, and for receiving the remote SMTP server response.
d652 3
a654 2
The Postfix SMTP client time limit for sending the SMTP RCPT TO
command, and for receiving the remote SMTP server response.
d657 3
a659 2
The Postfix SMTP client time limit for sending the SMTP DATA
command, and for receiving the remote SMTP server response.
d662 2
a663 2
The Postfix SMTP client time limit for sending the SMTP message
content.
d666 3
a668 2
The Postfix SMTP client time limit for sending the SMTP ".", and
for receiving the remote SMTP server response.
d671 3
a673 2
The Postfix SMTP client time limit for sending the QUIT command,
and for receiving the remote SMTP server response.
d678 3
a680 3
The maximal number of MX (mail exchanger) IP addresses that can
result from Postfix SMTP client mail exchanger lookups, or zero
(no limit).
d683 4
a686 3
The maximal number of SMTP sessions per delivery request before
the Postfix SMTP client gives up or delivers to a fall-back
relay host, or zero (no limit).
d689 3
a691 2
The Postfix SMTP client time limit for sending the RSET command,
and for receiving the remote SMTP server response.
d696 2
a697 2
Keep Postfix LMTP client connections open for up to $max_idle
seconds.
d702 2
a703 2
Permanently enable SMTP connection caching for the specified
destinations.
d706 3
a708 2
Temporarily enable SMTP connection caching while a destination
has a high volume of mail in the active queue.
d711 2
a712 2
The amount of time during which Postfix will use an SMTP connec-
tion repeatedly.
d715 3
a717 2
When SMTP connection caching is enabled, the amount of time that
an unused SMTP client socket is kept open before it is closed.
d722 2
a723 2
Time limit for connection cache connect, send or receive opera-
tions.
d728 5
a732 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
a734 7
Available in Postfix version 2.11 and later:
smtp_connection_reuse_count_limit (0)
When SMTP connection caching is enabled, the number of times
that an SMTP session may be reused before it is closed, or zero
(no limit).
d737 3
a739 2
The increment in verbose logging level when a remote client or
server matches a pattern in the debug_peer_list parameter.
d742 4
a745 3
Optional list of remote client or server hostname or network
address patterns that cause the verbose logging level to
increase by the amount specified in $debug_peer_level.
d748 3
a750 3
The recipient of postmaster notifications about mail delivery
problems that are caused by policy, resource, software or proto-
col errors.
d753 3
a755 3
What categories of Postfix-generated mail are subject to before-
queue content inspection by non_smtpd_milters, header_checks and
body_checks.
d758 2
a759 1
The list of error classes that are reported to the postmaster.
d763 3
a765 2
Where the Postfix SMTP client should deliver mail when it
detects a "mail loops back to myself" error condition.
d768 2
a769 2
The default location of the Postfix main.cf and master.cf con-
figuration files.
d772 3
a774 2
How much time a Postfix daemon process may take to handle a
request before it is terminated by a built-in watchdog timer.
d777 2
a778 2
The maximal number of digits after the decimal point when log-
ging sub-second delay values.
d781 2
a782 1
Disable DNS lookups in the Postfix SMTP and LMTP clients.
d785 2
a786 2
The network interface addresses that this mail system receives
mail on.
d789 2
a790 2
The Internet protocols Postfix will attempt to use when making
or accepting connections.
d793 2
a794 2
The time limit for sending or receiving information over an
internal communication channel.
d797 4
a800 3
When a remote LMTP server announces no DSN support, assume that
the server performs final delivery, and send "delivered" deliv-
ery status notifications instead of "relayed".
d803 2
a804 1
The default TCP port that the Postfix LMTP client connects to.
d807 3
a809 2
The maximum amount of time that an idle Postfix daemon process
waits for an incoming connection before terminating voluntarily.
d812 3
a814 2
The maximal number of incoming connections that a Postfix daemon
process will service before terminating voluntarily.
d817 2
a818 1
The process ID of a Postfix command or daemon process.
d821 2
a822 1
The process name of a Postfix command or daemon process.
d825 3
a827 2
The network interface addresses that this mail system receives
mail on by way of a proxy or network address translation unit.
d830 4
a833 3
The address type ("ipv6", "ipv4" or "any") that the Postfix SMTP
client will try first, when a destination has IPv6 and IPv4
addresses with equal MX preference.
d836 3
a838 2
An optional numerical network address that the Postfix SMTP
client should bind to when making an IPv4 connection.
d841 3
a843 2
An optional numerical network address that the Postfix SMTP
client should bind to when making an IPv6 connection.
d846 2
a847 1
The hostname to send in the SMTP EHLO or HELO command.
d853 2
a854 2
What mechanisms the Postfix SMTP client uses to look up a host's
IP address.
d857 2
a858 1
Randomize the order of equal-preference MX host addresses.
d864 3
a866 3
The mail system name that is prepended to the process name in
syslog records, so that "smtpd" becomes, for example, "post-
fix/smtpd".
d871 2
a872 2
Optional list of relay hosts for SMTP destinations that can't be
found or that are unreachable.
d877 2
a878 2
Optional list of relay hosts for SMTP destinations that can't be
found or that are unreachable.
d898 2
a899 1
The Secure Mailer license must be distributed with this software.
@
1.1.1.7
log
@Import Postfix 2.11.1. The main changes since version 2.10.* are:
- Support for PKI-less TLS server certificate verification with DANE
(DNS-based Authentication of Named Entities) where the CA public key
or the server certificate is identified via DNSSEC lookup. This
requires a DNS resolver that validates DNSSEC replies. The problem
with conventional PKI is that there are literally hundreds of
organizations world-wide that can provide a certificate in anyone's
name. DANE limits trust to the people who control the target DNS
zone and its parent zones.
- A new postscreen_dnsbl_whitelist_threshold feature to allow clients
to skip postscreen tests based on their DNSBL score. This can
eliminate email delays due to "after 220 greeting" protocol tests,
which otherwise require that a client reconnects before it can
deliver mail. Some providers such as Google don't retry from the
same IP address, and that can result in large email delivery delays.
- The recipient_delimiter feature now supports different delimiters,
for example both "+" and "-". As before, this implementation
recognizes exactly one delimiter character per email address, and
exactly one address extension per email address.
- Advanced master.cf query/update support to access service attributes
as "name = value" pairs. For example to turn off chroot on all
services use "postconf -F '*/*/chroot = n'", and to change/add a
"-o name=value" setting use "postconf -P 'smtp/inet/name = value'".
This was developed primarily to allow automated tools to manage Postfix
systems without having to parse Postfix configuration files.
@
text
@d16 31
a46 26
The Postfix SMTP+LMTP client implements the SMTP and LMTP mail delivery
protocols. It processes message delivery requests from the queue man-
ager. Each request specifies a queue file, a sender address, a domain
or host to deliver to, and recipient information. This program expects
to be run from the master(8) process manager.
The SMTP+LMTP client updates the queue file and marks recipients as
finished, or it informs the queue manager that delivery should be tried
again at a later time. Delivery status reports are sent to the
bounce(8), defer(8) or trace(8) daemon as appropriate.
The SMTP+LMTP client looks up a list of mail exchanger addresses for
the destination host, sorts the list by preference, and connects to
each listed address until it finds a server that responds.
When a server is not reachable, or when mail delivery fails due to a
recoverable error condition, the SMTP+LMTP client will try to deliver
the mail to an alternate host.
After a successful mail transaction, a connection may be saved to the
scache(8) connection cache server, so that it may be used by any
SMTP+LMTP client for a subsequent transaction.
By default, connection caching is enabled temporarily for destinations
that have a high volume of mail in the active queue. Connection caching
can be enabled permanently for specific destinations.
d54 3
a56 2
Look up the mail exchangers for the specified domain, and con-
nect to the specified port (default: smtp).
d61 2
a62 2
Look up the address(es) of the specified host, and connect to
the specified port (default: smtp).
d67 3
a69 3
Connect to the host at the specified address, and connect to the
specified port (default: smtp). An IPv6 address must be format-
ted as [ipv6:address].
d75 4
a78 3
Connect to the local UNIX-domain server that is bound to the
specified pathname. If the process runs chrooted, an absolute
pathname is interpreted relative to the Postfix queue directory.
d82 1
a82 1
inet:hostname:port
d87 6
a92 5
Connect to the specified TCP port on the specified local or
remote host. If no port is specified, connect to the port
defined as lmtp in services(4). If no such service is found,
the lmtp_tcp_port configuration parameter (default value of 24)
will be used. An IPv6 address must be formatted as
d96 4
a99 3
The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP
or LMTP servers and to DNS servers on the network. The SMTP+LMTP client
can be run chrooted at fixed low privilege.
d121 7
a127 6
Problems and transactions are logged to syslogd(8). Corrupted message
files are marked so that the queue manager can move them to the corrupt
queue for further inspection.
Depending on the setting of the notify_classes parameter, the postmas-
ter is notified of bounces, protocol problems, and of other trouble.
d130 8
a137 7
SMTP and LMTP connection caching does not work with TLS. The necessary
support for TLS object passivation and re-activation does not exist
without closing the session, which defeats the purpose.
SMTP and LMTP connection caching assumes that SASL credentials are
valid for all destinations that map onto the same IP address and TCP
port.
d140 14
a153 12
Before Postfix version 2.3, the LMTP client is a separate program that
implements only a subset of the functionality available with SMTP:
there is no support for TLS, and connections are cached in-process,
making it ineffective when the client is used for multiple domains.
Most smtp_xxx configuration parameters have an lmtp_xxx "mirror" param-
eter for the equivalent LMTP feature. This document describes only
those LMTP-related parameters that aren't simply "mirror" parameters.
Changes to main.cf are picked up automatically, as smtp(8) processes
run for only a limited amount of time. Use the command "postfix reload"
to speed up a change.
d155 2
a156 2
The text below provides only a parameter summary. See postconf(5) for
more details including examples.
d169 2
a170 1
Defer mail delivery when no MX record resolves to an IP address.
d173 2
a174 2
The maximal length of message header and body lines that Postfix
will send via SMTP.
d177 3
a179 3
How long the Postfix SMTP client pauses before sending
".<CR><LF>" in order to work around the PIX firewall
"<CR><LF>.<CR><LF>" bug.
d182 4
a185 3
How long a message must be queued before the Postfix SMTP client
turns on the PIX firewall "<CR><LF>.<CR><LF>" bug workaround for
delivery through firewalls with "smtp fixup" mode turned on.
d188 2
a189 2
A list that specifies zero or more workarounds for CISCO PIX
firewall bugs.
d192 3
a194 2
Lookup tables, indexed by the remote SMTP server address, with
per-destination workarounds for CISCO PIX firewall bugs.
d197 2
a198 2
Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO
commands as required by RFC 5321.
d201 2
a202 2
A mechanism to transform replies from remote SMTP servers one
line at a time.
d205 2
a206 1
Skip remote SMTP servers that greet with a 5XX status code.
d209 2
a210 1
Do not wait for the response to the SMTP QUIT command.
d215 2
a216 2
Skip SMTP servers that greet with a 4XX status code (go away,
try again later).
d221 4
a224 3
Lookup tables, indexed by the remote SMTP server address, with
case insensitive lists of EHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix SMTP client will ignore in the EHLO
d228 4
a231 3
A case insensitive list of EHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix SMTP client will ignore in the EHLO
response from a remote SMTP server.
d234 4
a237 4
Optional lookup tables that perform address rewriting in the
Postfix SMTP client, typically to transform a locally valid
address into a globally valid address when sending mail across
the Internet.
d242 4
a245 3
Allow DNS CNAME records to override the servername that the
Postfix SMTP client uses for logging, SASL password lookup, TLS
policy decisions, or TLS certificate verification.
d250 4
a253 3
Lookup tables, indexed by the remote LMTP server address, with
case insensitive lists of LHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix LMTP client will ignore in the LHLO
d257 4
a260 3
A case insensitive list of LHLO keywords (pipelining, starttls,
auth, etc.) that the Postfix LMTP client will ignore in the LHLO
response from a remote LMTP server.
d265 4
a268 4
When authenticating to a remote SMTP or LMTP server with the
default setting "no", send no SASL authoriZation ID (authzid);
send only the SASL authentiCation ID (authcid) plus the auth-
cid's password.
d273 2
a274 1
Restricted header_checks(5) tables for the Postfix SMTP client.
d277 2
a278 2
Restricted mime_header_checks(5) tables for the Postfix SMTP
client.
d281 2
a282 2
Restricted nested_header_checks(5) tables for the Postfix SMTP
client.
d285 2
a286 1
Restricted body_checks(5) tables for the Postfix SMTP client.
d291 2
a292 2
An optional workaround for routers that break TCP window scal-
ing.
d302 5
a306 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
d310 3
a312 7
Whether or not to append the "AUTH=<>" option to the MAIL FROM
command in SASL-authenticated SMTP sessions.
Available in Postfix version 2.11 and later:
smtp_dns_support_level (empty)
Level of DNS support in the Postfix SMTP client.
d318 2
a319 1
Disable the conversion of 8BITMIME format to 7BIT format.
d322 2
a323 1
The maximal length of MIME multipart boundary strings.
d326 2
a327 1
The maximal recursion level that the MIME processor will handle.
d333 3
a335 2
Send the non-standard XFORWARD command when the Postfix SMTP
server EHLO response announces XFORWARD support.
d339 2
a340 1
Enable SASL authentication in the Postfix SMTP client.
d343 4
a346 3
Optional Postfix SMTP client lookup tables with one user-
name:password entry per remote hostname or domain, or sender
address when sender-dependent authentication is enabled.
d349 4
a352 3
Postfix SMTP client SASL security options; as of Postfix 2.3 the
list of available features depends on the SASL client implemen-
tation that is selected with smtp_sasl_type.
d357 3
a359 2
If non-empty, a Postfix SMTP client filter for the remote SMTP
server's list of offered SASL mechanisms.
d364 5
a368 4
Enable sender-dependent authentication in the Postfix SMTP
client; this is available only with SASL authentication, and
disables SMTP connection caching to ensure that mail from dif-
ferent senders will use the appropriate credentials.
d371 4
a374 3
Implementation-specific information that the Postfix SMTP client
passes through to the SASL plug-in implementation that is
selected with smtp_sasl_type.
d377 2
a378 2
The SASL plug-in type that the Postfix SMTP client should use
for authentication.
d383 3
a385 3
An optional table to prevent repeated SASL authentication fail-
ures with the same remote SMTP server hostname, username and
password.
d388 2
a389 2
The maximal age of an smtp_sasl_auth_cache_name entry before it
is removed.
d392 4
a395 3
When a remote SMTP server rejects a SASL authentication request
with a 535 reply code, defer mail delivery instead of returning
mail as undeliverable.
d400 3
a402 2
Whether or not to append the "AUTH=<>" option to the MAIL FROM
command in SASL-authenticated SMTP sessions.
d405 2
a406 2
Detailed information about STARTTLS configuration may be found in the
TLS_README document.
d409 4
a412 3
The default SMTP TLS security level for the Postfix SMTP client;
when a non-empty value is specified, this overrides the obsolete
parameters smtp_use_tls, smtp_enforce_tls, and
d415 5
a419 3
smtp_sasl_tls_security_options ($smtp_sasl_security_options)
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions.
d422 3
a424 2
Time limit for Postfix SMTP client write and read operations
during TLS startup and shutdown handshake procedures.
d427 3
a429 3
A file containing CA certificates of root CAs trusted to sign
either remote SMTP server certificates or intermediate CA cer-
tificates.
d432 3
a434 3
Directory with PEM format certificate authority certificates
that the Postfix SMTP client uses to verify a remote SMTP server
certificate.
d437 2
a438 1
File with the Postfix SMTP client RSA certificate in PEM format.
d441 2
a442 2
The minimum TLS cipher grade that the Postfix SMTP client will
use with mandatory TLS encryption.
d445 3
a447 2
List of ciphers or cipher types to exclude from the Postfix SMTP
client cipher list at all TLS security levels.
d450 3
a452 3
Additional list of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at mandatory TLS security lev-
els.
d455 2
a456 1
File with the Postfix SMTP client DSA certificate in PEM format.
d459 2
a460 1
File with the Postfix SMTP client DSA private key in PEM format.
d463 2
a464 1
File with the Postfix SMTP client RSA private key in PEM format.
d467 2
a468 1
Enable additional Postfix SMTP client logging of TLS activity.
d471 3
a473 2
Log the hostname of a remote SMTP server that offers STARTTLS,
when TLS is not already enabled for that server.
d476 4
a479 3
Optional lookup tables with the Postfix SMTP client TLS security
policy by next-hop destination; when a non-empty value is speci-
fied, this overrides the obsolete smtp_tls_per_site parameter.
d482 2
a483 2
List of SSL/TLS protocols that the Postfix SMTP client will use
with mandatory TLS encryption.
d486 2
a487 1
The verification depth for remote SMTP server certificates.
d490 3
a492 2
How the Postfix SMTP client verifies the server certificate
peername for the "secure" TLS security level.
d495 2
a496 2
Name of the file containing the optional Postfix SMTP client TLS
session cache.
d499 2
a500 2
The expiration time of Postfix SMTP client TLS session cache
information.
d503 3
a505 2
How the Postfix SMTP client verifies the server certificate
peername for the "verify" TLS security level.
d508 4
a511 3
The number of pseudo-random bytes that an smtp(8) or smtpd(8)
process requests from the tlsmgr(8) server in order to seed its
internal pseudo random number generator (PRNG).
d513 2
a514 1
tls_high_cipherlist (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
d518 2
a519 1
The OpenSSL cipherlist for "MEDIUM" or higher grade ciphers.
d522 2
a523 1
The OpenSSL cipherlist for "LOW" or higher grade ciphers.
d526 2
a527 1
The OpenSSL cipherlist for "EXPORT" or higher grade ciphers.
d530 2
a531 2
The OpenSSL cipherlist for "NULL" grade ciphers that provide
authentication without encryption.
d535 5
a539 5
smtp_sasl_tls_verified_security_options ($smtp_sasl_tls_secu-
rity_options)
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions with a verified
server certificate.
d544 3
a546 3
List of acceptable remote SMTP server certificate fingerprints
for the "fingerprint" TLS security level (smtp_tls_secu-
rity_level = fingerprint).
d549 2
a550 2
The message digest algorithm used to construct remote SMTP
server certificate fingerprints.
d555 3
a557 2
List of TLS protocols that the Postfix SMTP client will exclude
or include with opportunistic TLS encryption.
d560 2
a561 2
The minimum TLS cipher grade that the Postfix SMTP client will
use with opportunistic TLS encryption.
d564 2
a565 2
File with the Postfix SMTP client ECDSA certificate in PEM for-
mat.
d568 2
a569 2
File with the Postfix SMTP client ECDSA private key in PEM for-
mat.
d574 4
a577 4
Try to detect a mail hijacking attack based on a TLS protocol
vulnerability (CVE-2009-3555), where an attacker prepends mali-
cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client
TLS session.
d582 2
a583 17
List or bit-mask of OpenSSL bug work-arounds to disable.
Available in Postfix version 2.11 and later:
smtp_tls_trust_anchor_file (empty)
Zero or more PEM-format files with trust-anchor certificates
and/or public keys.
smtp_tls_force_insecure_host_tlsa_lookup (no)
Lookup the associated DANE TLSA RRset even when a hostname is
not an alias and its address records lie in an unsigned zone.
tls_dane_trust_anchor_digest_enable (yes)
RFC 6698 trust-anchor digest support in the Postfix TLS library.
tlsmgr_service_name (tlsmgr)
The name of the tlsmgr(8) service entry in master.cf.
d586 3
a588 3
The following configuration parameters exist for compatibility with
Postfix versions before 2.3. Support for these will be removed in a
future release.
d591 3
a593 2
Opportunistic mode: use TLS when a remote SMTP server announces
STARTTLS support, otherwise send the mail in the clear.
d596 3
a598 2
Enforcement mode: require that remote SMTP servers use TLS
encryption, and never send mail in the clear.
d601 3
a603 3
With mandatory TLS encryption, require that the remote SMTP
server hostname matches the information in the remote SMTP
server certificate.
d606 3
a608 3
Optional lookup tables with the Postfix SMTP client TLS usage
policy by next-hop destination and by remote SMTP server host-
name.
d611 2
a612 2
Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS
cipher list.
d615 10
a624 8
smtp_destination_concurrency_limit ($default_destination_concur-
rency_limit)
The maximal number of parallel deliveries to the same destina-
tion via the smtp message delivery transport.
smtp_destination_recipient_limit ($default_destination_recipient_limit)
The maximal number of recipients per message for the smtp mes-
sage delivery transport.
d627 3
a629 2
The Postfix SMTP client time limit for completing a TCP connec-
tion, or zero (use the operating system built-in time limit).
d632 3
a634 3
The Postfix SMTP client time limit for sending the HELO or EHLO
command, and for receiving the initial remote SMTP server
response.
d637 3
a639 2
The Postfix LMTP client time limit for sending the LHLO command,
and for receiving the initial remote LMTP server response.
d642 3
a644 2
The Postfix SMTP client time limit for sending the XFORWARD com-
mand, and for receiving the remote SMTP server response.
d647 3
a649 2
The Postfix SMTP client time limit for sending the MAIL FROM
command, and for receiving the remote SMTP server response.
d652 3
a654 2
The Postfix SMTP client time limit for sending the SMTP RCPT TO
command, and for receiving the remote SMTP server response.
d657 3
a659 2
The Postfix SMTP client time limit for sending the SMTP DATA
command, and for receiving the remote SMTP server response.
d662 2
a663 2
The Postfix SMTP client time limit for sending the SMTP message
content.
d666 3
a668 2
The Postfix SMTP client time limit for sending the SMTP ".", and
for receiving the remote SMTP server response.
d671 3
a673 2
The Postfix SMTP client time limit for sending the QUIT command,
and for receiving the remote SMTP server response.
d678 3
a680 3
The maximal number of MX (mail exchanger) IP addresses that can
result from Postfix SMTP client mail exchanger lookups, or zero
(no limit).
d683 4
a686 3
The maximal number of SMTP sessions per delivery request before
the Postfix SMTP client gives up or delivers to a fall-back
relay host, or zero (no limit).
d689 3
a691 2
The Postfix SMTP client time limit for sending the RSET command,
and for receiving the remote SMTP server response.
d696 2
a697 2
Keep Postfix LMTP client connections open for up to $max_idle
seconds.
d702 2
a703 2
Permanently enable SMTP connection caching for the specified
destinations.
d706 3
a708 2
Temporarily enable SMTP connection caching while a destination
has a high volume of mail in the active queue.
d711 2
a712 2
The amount of time during which Postfix will use an SMTP connec-
tion repeatedly.
d715 3
a717 2
When SMTP connection caching is enabled, the amount of time that
an unused SMTP client socket is kept open before it is closed.
d722 2
a723 2
Time limit for connection cache connect, send or receive opera-
tions.
d728 5
a732 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
a734 7
Available in Postfix version 2.11 and later:
smtp_connection_reuse_count_limit (0)
When SMTP connection caching is enabled, the number of times
that an SMTP session may be reused before it is closed, or zero
(no limit).
d737 3
a739 2
The increment in verbose logging level when a remote client or
server matches a pattern in the debug_peer_list parameter.
d742 4
a745 3
Optional list of remote client or server hostname or network
address patterns that cause the verbose logging level to
increase by the amount specified in $debug_peer_level.
d748 3
a750 3
The recipient of postmaster notifications about mail delivery
problems that are caused by policy, resource, software or proto-
col errors.
d753 3
a755 3
What categories of Postfix-generated mail are subject to before-
queue content inspection by non_smtpd_milters, header_checks and
body_checks.
d758 2
a759 1
The list of error classes that are reported to the postmaster.
d763 3
a765 2
Where the Postfix SMTP client should deliver mail when it
detects a "mail loops back to myself" error condition.
d768 2
a769 2
The default location of the Postfix main.cf and master.cf con-
figuration files.
d772 3
a774 2
How much time a Postfix daemon process may take to handle a
request before it is terminated by a built-in watchdog timer.
d777 2
a778 2
The maximal number of digits after the decimal point when log-
ging sub-second delay values.
d781 2
a782 1
Disable DNS lookups in the Postfix SMTP and LMTP clients.
d785 2
a786 2
The network interface addresses that this mail system receives
mail on.
d789 2
a790 2
The Internet protocols Postfix will attempt to use when making
or accepting connections.
d793 2
a794 2
The time limit for sending or receiving information over an
internal communication channel.
d797 4
a800 3
When a remote LMTP server announces no DSN support, assume that
the server performs final delivery, and send "delivered" deliv-
ery status notifications instead of "relayed".
d803 2
a804 1
The default TCP port that the Postfix LMTP client connects to.
d807 3
a809 2
The maximum amount of time that an idle Postfix daemon process
waits for an incoming connection before terminating voluntarily.
d812 3
a814 2
The maximal number of incoming connections that a Postfix daemon
process will service before terminating voluntarily.
d817 2
a818 1
The process ID of a Postfix command or daemon process.
d821 2
a822 1
The process name of a Postfix command or daemon process.
d825 3
a827 2
The network interface addresses that this mail system receives
mail on by way of a proxy or network address translation unit.
d830 4
a833 3
The address type ("ipv6", "ipv4" or "any") that the Postfix SMTP
client will try first, when a destination has IPv6 and IPv4
addresses with equal MX preference.
d836 3
a838 2
An optional numerical network address that the Postfix SMTP
client should bind to when making an IPv4 connection.
d841 3
a843 2
An optional numerical network address that the Postfix SMTP
client should bind to when making an IPv6 connection.
d846 2
a847 1
The hostname to send in the SMTP EHLO or HELO command.
d853 2
a854 2
What mechanisms the Postfix SMTP client uses to look up a host's
IP address.
d857 2
a858 1
Randomize the order of equal-preference MX host addresses.
d864 3
a866 3
The mail system name that is prepended to the process name in
syslog records, so that "smtpd" becomes, for example, "post-
fix/smtpd".
d871 2
a872 2
Optional list of relay hosts for SMTP destinations that can't be
found or that are unreachable.
d877 2
a878 2
Optional list of relay hosts for SMTP destinations that can't be
found or that are unreachable.
d898 2
a899 1
The Secure Mailer license must be distributed with this software.
@
1.1.1.8
log
@Import Postfix 2.11.6. Changes since version 2.11.4:
- Preparation for OpenSSL 1.2 API changes
- The sender_dependent_relayhost_maps feature ignored the relayhost setting
in the case of a DUNNO lookup result. It would use the recipient domain
instead.
- The default TLS settings no longer enable export-grade ciphers, and no
longer enable the SSLv2 and SSLv3 protocols. These ciphers and protocols
have little if any legitimate use today, and have instead become a
vehicle for downgrade attacks.
@
text
@d435 1
a435 1
smtp_tls_mandatory_protocols (!SSLv2, !SSLv3)
d500 1
a500 1
smtp_tls_protocols (!SSLv2, !SSLv3)
d504 1
a504 1
smtp_tls_ciphers (medium)
@
1.1.1.8.4.1
log
@Sync with HEAD
@
text
@a109 3
RFC 6531 (Internationalized SMTP)
RFC 6533 (Internationalized Delivery Status Notifications)
RFC 7672 (SMTP security via opportunistic DANE TLS)
d222 3
a224 4
When the remote SMTP servername is a DNS CNAME, replace the
servername with the result from CNAME expansion for the purpose
of logging, SASL password lookup, TLS policy decisions, or TLS
certificate verification.
d229 2
a230 2
Lookup tables, indexed by the remote LMTP server address, with
case insensitive lists of LHLO keywords (pipelining, starttls,
d235 1
a235 1
A case insensitive list of LHLO keywords (pipelining, starttls,
d242 3
a244 3
When authenticating to a remote SMTP or LMTP server with the
default setting "no", send no SASL authoriZation ID (authzid);
send only the SASL authentiCation ID (authcid) plus the auth-
d250 1
a250 1
Restricted header_checks(5) tables for the Postfix SMTP client.
d253 1
a253 1
Restricted mime_header_checks(5) tables for the Postfix SMTP
d257 1
a257 1
Restricted nested_header_checks(5) tables for the Postfix SMTP
d266 1
a266 1
An optional workaround for routers that break TCP window scal-
d277 4
a280 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
d284 1
a284 1
Whether or not to append the "AUTH=<>" option to the MAIL FROM
a291 10
Available in Postfix version 3.0 and later:
smtp_delivery_status_filter ($default_delivery_status_filter)
Optional filter for the smtp(8) delivery agent to change the
delivery status code or explanatory text of successful or unsuc-
cessful deliveries.
smtp_dns_reply_filter (empty)
Optional filter for Postfix SMTP client DNS lookup results.
d308 1
a308 1
Send the non-standard XFORWARD command when the Postfix SMTP
d316 3
a318 3
Optional Postfix SMTP client lookup tables with one user-
name:password entry per sender, remote hostname or next-hop
domain.
d322 1
a322 1
list of available features depends on the SASL client implemen-
d328 1
a328 1
If non-empty, a Postfix SMTP client filter for the remote SMTP
d335 2
a336 2
client; this is available only with SASL authentication, and
disables SMTP connection caching to ensure that mail from dif-
d341 1
a341 1
passes through to the SASL plug-in implementation that is
d345 1
a345 1
The SASL plug-in type that the Postfix SMTP client should use
d351 2
a352 2
An optional table to prevent repeated SASL authentication fail-
ures with the same remote SMTP server hostname, username and
d356 1
a356 1
The maximal age of an smtp_sasl_auth_cache_name entry before it
d360 2
a361 2
When a remote SMTP server rejects a SASL authentication request
with a 535 reply code, defer mail delivery instead of returning
d367 1
a367 1
Whether or not to append the "AUTH=<>" option to the MAIL FROM
d371 1
a371 1
Detailed information about STARTTLS configuration may be found in the
d381 1
a381 1
The SASL authentication security options that the Postfix SMTP
d385 1
a385 1
Time limit for Postfix SMTP client write and read operations
d389 2
a390 2
A file containing CA certificates of root CAs trusted to sign
either remote SMTP server certificates or intermediate CA cer-
d394 1
a394 1
Directory with PEM format Certification Authority certificates
d402 1
a402 1
The minimum TLS cipher grade that the Postfix SMTP client will
d410 2
a411 2
Additional list of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at mandatory TLS security lev-
d427 1
a427 1
Log the hostname of a remote SMTP server that offers STARTTLS,
d436 1
a436 1
List of SSL/TLS protocols that the Postfix SMTP client will use
d443 1
a443 1
How the Postfix SMTP client verifies the server certificate
d451 1
a451 1
The expiration time of Postfix SMTP client TLS session cache
d455 1
a455 1
How the Postfix SMTP client verifies the server certificate
d459 2
a460 2
The number of pseudo-random bytes that an smtp(8) or smtpd(8)
process requests from the tlsmgr(8) server in order to seed its
d463 2
a464 2
tls_high_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "high" grade ciphers.
d466 2
a467 2
tls_medium_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "medium" or higher grade ciphers.
d469 2
a470 2
tls_low_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "low" or higher grade ciphers.
d472 2
a473 2
tls_export_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "export" or higher grade ciphers.
d476 1
a476 1
The OpenSSL cipherlist for "NULL" grade ciphers that provide
d483 2
a484 2
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions with a verified
d490 2
a491 2
List of acceptable remote SMTP server certificate fingerprints
for the "fingerprint" TLS security level (smtp_tls_secu-
d495 1
a495 1
The message digest algorithm used to construct remote SMTP
d501 1
a501 1
List of TLS protocols that the Postfix SMTP client will exclude
d505 1
a505 1
The minimum TLS cipher grade that the Postfix SMTP client will
d509 1
a509 1
File with the Postfix SMTP client ECDSA certificate in PEM for-
d513 1
a513 1
File with the Postfix SMTP client ECDSA private key in PEM for-
d519 3
a521 3
Try to detect a mail hijacking attack based on a TLS protocol
vulnerability (CVE-2009-3555), where an attacker prepends mali-
cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client
d532 1
a532 1
Zero or more PEM-format files with trust-anchor certificates
d536 1
a536 1
Lookup the associated DANE TLSA RRset even when a hostname is
a544 13
Available in Postfix version 3.0 and later:
smtp_tls_wrappermode (no)
Request that the Postfix SMTP client connects using the legacy
SMTPS protocol instead of using the STARTTLS command.
Available in Postfix version 3.1 and later:
smtp_tls_dane_insecure_mx_policy (dane)
The TLS policy for MX hosts with "secure" TLSA records when the
nexthop destination security level is dane, but the MX record
was found via an "insecure" MX lookup.
a684 11
SMTPUTF8 CONTROLS
Preliminary SMTPUTF8 support is introduced with Postfix 3.0.
smtputf8_enable (yes)
Enable preliminary SMTPUTF8 support for the protocols described
in RFC 6531..6533.
smtputf8_autodetect_classes (sendmail, verify)
Detect that a message requires SMTPUTF8 support for the speci-
fied mail origin classes.
d701 3
a703 3
What categories of Postfix-generated mail are subject to
before-queue content inspection by non_smtpd_milters,
header_checks and body_checks.
d780 1
a780 1
The hostname to send in the SMTP HELO or EHLO command.
a811 12
Available with Postfix 3.0 and later:
smtp_address_verify_target (rcpt)
In the context of email address verification, the SMTP protocol
stage that determines whether an email address is deliverable.
Available with Postfix 3.1 and later:
lmtp_fallback_relay (empty)
Optional list of relay hosts for LMTP destinations that can't be
found or that are unreachable.
a837 5
Wietse Venema
Google, Inc.
111 8th Avenue
New York, NY 10011, USA
@
1.1.1.8.2.1
log
@Sync with HEAD
@
text
@a109 3
RFC 6531 (Internationalized SMTP)
RFC 6533 (Internationalized Delivery Status Notifications)
RFC 7672 (SMTP security via opportunistic DANE TLS)
d222 3
a224 4
When the remote SMTP servername is a DNS CNAME, replace the
servername with the result from CNAME expansion for the purpose
of logging, SASL password lookup, TLS policy decisions, or TLS
certificate verification.
d229 2
a230 2
Lookup tables, indexed by the remote LMTP server address, with
case insensitive lists of LHLO keywords (pipelining, starttls,
d235 1
a235 1
A case insensitive list of LHLO keywords (pipelining, starttls,
d242 3
a244 3
When authenticating to a remote SMTP or LMTP server with the
default setting "no", send no SASL authoriZation ID (authzid);
send only the SASL authentiCation ID (authcid) plus the auth-
d250 1
a250 1
Restricted header_checks(5) tables for the Postfix SMTP client.
d253 1
a253 1
Restricted mime_header_checks(5) tables for the Postfix SMTP
d257 1
a257 1
Restricted nested_header_checks(5) tables for the Postfix SMTP
d266 1
a266 1
An optional workaround for routers that break TCP window scal-
d277 4
a280 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
d284 1
a284 1
Whether or not to append the "AUTH=<>" option to the MAIL FROM
a291 10
Available in Postfix version 3.0 and later:
smtp_delivery_status_filter ($default_delivery_status_filter)
Optional filter for the smtp(8) delivery agent to change the
delivery status code or explanatory text of successful or unsuc-
cessful deliveries.
smtp_dns_reply_filter (empty)
Optional filter for Postfix SMTP client DNS lookup results.
d308 1
a308 1
Send the non-standard XFORWARD command when the Postfix SMTP
d316 3
a318 3
Optional Postfix SMTP client lookup tables with one user-
name:password entry per sender, remote hostname or next-hop
domain.
d322 1
a322 1
list of available features depends on the SASL client implemen-
d328 1
a328 1
If non-empty, a Postfix SMTP client filter for the remote SMTP
d335 2
a336 2
client; this is available only with SASL authentication, and
disables SMTP connection caching to ensure that mail from dif-
d341 1
a341 1
passes through to the SASL plug-in implementation that is
d345 1
a345 1
The SASL plug-in type that the Postfix SMTP client should use
d351 2
a352 2
An optional table to prevent repeated SASL authentication fail-
ures with the same remote SMTP server hostname, username and
d356 1
a356 1
The maximal age of an smtp_sasl_auth_cache_name entry before it
d360 2
a361 2
When a remote SMTP server rejects a SASL authentication request
with a 535 reply code, defer mail delivery instead of returning
d367 1
a367 1
Whether or not to append the "AUTH=<>" option to the MAIL FROM
d371 1
a371 1
Detailed information about STARTTLS configuration may be found in the
d381 1
a381 1
The SASL authentication security options that the Postfix SMTP
d385 1
a385 1
Time limit for Postfix SMTP client write and read operations
d389 2
a390 2
A file containing CA certificates of root CAs trusted to sign
either remote SMTP server certificates or intermediate CA cer-
d394 1
a394 1
Directory with PEM format Certification Authority certificates
d402 1
a402 1
The minimum TLS cipher grade that the Postfix SMTP client will
d410 2
a411 2
Additional list of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at mandatory TLS security lev-
d427 1
a427 1
Log the hostname of a remote SMTP server that offers STARTTLS,
d436 1
a436 1
List of SSL/TLS protocols that the Postfix SMTP client will use
d443 1
a443 1
How the Postfix SMTP client verifies the server certificate
d451 1
a451 1
The expiration time of Postfix SMTP client TLS session cache
d455 1
a455 1
How the Postfix SMTP client verifies the server certificate
d459 2
a460 2
The number of pseudo-random bytes that an smtp(8) or smtpd(8)
process requests from the tlsmgr(8) server in order to seed its
d463 2
a464 2
tls_high_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "high" grade ciphers.
d466 2
a467 2
tls_medium_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "medium" or higher grade ciphers.
d469 2
a470 2
tls_low_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "low" or higher grade ciphers.
d472 2
a473 2
tls_export_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "export" or higher grade ciphers.
d476 1
a476 1
The OpenSSL cipherlist for "NULL" grade ciphers that provide
d483 2
a484 2
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions with a verified
d490 2
a491 2
List of acceptable remote SMTP server certificate fingerprints
for the "fingerprint" TLS security level (smtp_tls_secu-
d495 1
a495 1
The message digest algorithm used to construct remote SMTP
d501 1
a501 1
List of TLS protocols that the Postfix SMTP client will exclude
d505 1
a505 1
The minimum TLS cipher grade that the Postfix SMTP client will
d509 1
a509 1
File with the Postfix SMTP client ECDSA certificate in PEM for-
d513 1
a513 1
File with the Postfix SMTP client ECDSA private key in PEM for-
d519 3
a521 3
Try to detect a mail hijacking attack based on a TLS protocol
vulnerability (CVE-2009-3555), where an attacker prepends mali-
cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client
d532 1
a532 1
Zero or more PEM-format files with trust-anchor certificates
d536 1
a536 1
Lookup the associated DANE TLSA RRset even when a hostname is
a544 13
Available in Postfix version 3.0 and later:
smtp_tls_wrappermode (no)
Request that the Postfix SMTP client connects using the legacy
SMTPS protocol instead of using the STARTTLS command.
Available in Postfix version 3.1 and later:
smtp_tls_dane_insecure_mx_policy (dane)
The TLS policy for MX hosts with "secure" TLSA records when the
nexthop destination security level is dane, but the MX record
was found via an "insecure" MX lookup.
a684 11
SMTPUTF8 CONTROLS
Preliminary SMTPUTF8 support is introduced with Postfix 3.0.
smtputf8_enable (yes)
Enable preliminary SMTPUTF8 support for the protocols described
in RFC 6531..6533.
smtputf8_autodetect_classes (sendmail, verify)
Detect that a message requires SMTPUTF8 support for the speci-
fied mail origin classes.
d701 3
a703 3
What categories of Postfix-generated mail are subject to
before-queue content inspection by non_smtpd_milters,
header_checks and body_checks.
d780 1
a780 1
The hostname to send in the SMTP HELO or EHLO command.
a811 12
Available with Postfix 3.0 and later:
smtp_address_verify_target (rcpt)
In the context of email address verification, the SMTP protocol
stage that determines whether an email address is deliverable.
Available with Postfix 3.1 and later:
lmtp_fallback_relay (empty)
Optional list of relay hosts for LMTP destinations that can't be
found or that are unreachable.
a837 5
Wietse Venema
Google, Inc.
111 8th Avenue
New York, NY 10011, USA
@
1.1.1.9
log
@The stable Postfix release is called postfix-3.0.x where 3=major
release number, 0=minor release number, x=patchlevel. The stable
release never changes except for patches that address bugs or
emergencies. Patches change the patchlevel and the release date.
New features are developed in snapshot releases. These are called
postfix-3.1-yyyymmdd where yyyymmdd is the release date (yyyy=year,
mm=month, dd=day). Patches are never issued for snapshot releases;
instead, a new snapshot is released.
The mail_release_date configuration parameter (format: yyyymmdd)
specifies the release date of a stable release or snapshot release.
If you upgrade from Postfix 2.10 or earlier, read RELEASE_NOTES-2.11
before proceeding.
Notes for distribution maintainers
----------------------------------
* New backwards-compatibility safety net.
With NEW Postfix installs, you MUST install a main.cf file with
the setting "compatibility_level = 2". See conf/main.cf for an
example.
With UPGRADES of existing Postfix systems, you MUST NOT change the
main.cf compatibility_level setting, nor add this setting if it
does not exist.
Several Postfix default settings have changed with Postfix 3.0. To
avoid massive frustration with existing Postfix installations,
Postfix 3.0 comes with a safety net that forces Postfix to keep
running with backwards-compatible main.cf and master.cf default
settings. This safety net depends on the main.cf compatibility_level
setting (default: 0). Details are in COMPATIBILITY_README.
* New Postfix build system.
The Postfix build/install procedure has changed to support Postfix
dynamically-linked libraries and database plugins. These must not
be "shared" with non-Postfix programs, and therefore must not be
installed in a public directory.
To avoid massive frustration due to broken patches, PLEASE BUILD
POSTFIX FIRST WITHOUT APPLYING ANY PATCHES. Follow the INSTALL
instructions (see "Building with Postfix dynamically-linked libraries
and database plugins"), and see how things work and what the
dynamically-linked libraries, database plugin, and configuration
files look like. Then, go ahead and perform your platform-specific
customizations. The INSTALL section "Tips for distribution maintainers"
has further suggestions.
Major changes - critical
------------------------
[Incompat 20140714] After upgrading Postfix, "postfix reload" (or
start/stop) is required. Several Postfix-internal protocols have
been extended to support SMTPUTF8. Failure to reload or restart
will result in mail staying queued, while Postfix daemons log
warning messages about unexpected attributes.
Major changes - default settings
--------------------------------
[Incompat 20141009] The default settings have changed for relay_domains
(new: empty, old: $mydestination) and mynetworks_style (new: host,
old: subnet). However the backwards-compatibility safety net will
prevent these changes from taking effect, giving the system
administrator the option to make an old default setting permanent
in main.cf or to adopt the new default setting, before turning off
backwards compatibility. See COMPATIBILITY_README for details.
[Incompat 20141001] A new backwards-compatibility safety net forces
Postfix to run with backwards-compatible main.cf and master.cf
default settings after an upgrade to a newer but incompatible Postfix
version. See COMPATIBILITY_README for details.
While the backwards-compatible default settings are in effect,
Postfix logs what services or what email would be affected by the
incompatible change. Based on this the administrator can make some
backwards-compatibility settings permanent in main.cf or master.cf,
before turning off backwards compatibility.
See postconf.5.html#compatibility_level for details.
[Incompat 20141001] The default settings
have changed for append_dot_mydomain (new: no. old: yes), master.cf
chroot (new: n, old: y), and smtputf8 (new: yes, old: no).
Major changes - access control
------------------------------
[Feature 20141119] Support for BCC actions in header/body_checks
and milter_header_checks. There is no limit on the number of BCC
actions that may be specified, other than the implicit limit due
to finite storage. BCC support will not be implemented in Postfix
delivery agent header/body_checks.
It works in the same way as always_bcc and sender/recipient_bcc_maps:
there can be only one address per action, recipients are added with
the NOTIFY=NONE delivery status notification option, and duplicate
recipients are ignored (with the same delivery status notification
options).
[Incompat 20141009] The default settings have changed for relay_domains
(new: empty, old: $mydestination) and mynetworks_style (new: host,
old: subnet). However the backwards-compatibility safety net will
prevent these changes from taking effect, giving the system
administrator the option to make an old default setting permanent
in main.cf or to adopt the new default setting, before turning off
backwards compatibility. See COMPATIBILITY_README for details.
[Feature 20140618] New INFO action in access(5) tables, for consistency
with header/body_checks.
[Feature 20140620] New check_xxx_a_access (for xxx in client,
reverse_client, helo, sender, recipient) implements access control
on all A and AAAA IP addresses for respectively the client hostname,
helo parameter, sender domain or recipient domain. This complements
the existing check_xxx_mx_access and check_xxx_ns_access features.
Major changes - address rewriting
---------------------------------
[Incompat 20141001] The default settings have changed for
append_dot_mydomain (new: no. old: yes), master.cf chroot (new:
n, old: y), and smtputf8 (new: yes, old: no).
Major changes - address verification
------------------------------------
[Feature 20141227] The new smtp_address_verify_target parameter
(default: rcpt) specifies what protocol stage decides if a recipient
is valid. Specify "data" for servers that reject invalid recipients
in response to the DATA command.
Major changes - database support
--------------------------------
[Feature 20140512] Support for Berkeley DB version 6.
[Feature 20140618] The "randmap" lookup table performs random
selection. This may be used to implement load balancing, for example:
/etc/postfix/transport:
# Deliver my own domain as usual.
example.com :
.example.com :
/etc/postfix/main.cf:
transport_maps =
# Deliver my own domain as usual.
hash:/etc/postfix/transport
# Deliver other domains via randomly-selected relayhosts
randmap:{smtp:smtp0.example.com, smtp:smtp1.example.com}
A variant of this can randomly select SMTP clients with different
smtp_bind_address settings.
To implement different weights, specify lookup results multiple
times. For example, to choose smtp:smtp1.example.com twice as often
as smtp:smtp0.example.com, specify smtp:smtp1.example.com twice.
A future version may support randmap:/path/to/file to load a list
of results from file.
[Feature 20140618] As the name suggests, the "pipemap" table
implements a pipeline of lookup tables. The name of the table
specifies the pipeline as a sequence of tables. For example, the
following prevents SMTP mail to system accounts that have "nologin"
as their login shell:
/etc/postfix/main.cf:
local_recipient_maps =
pipemap:{unix:passwd.byname, pcre:/etc/postfix/no-nologin.pcre}
alias_maps
/etc/postfix/no-nologin.pcre:
!/nologin/ whatever
Each "pipemap:" query is given to the first table. Each table
lookup result becomes the query for the next table in the pipeline,
and the last table produces the final result. When any table lookup
produces no result, the entire pipeline produces no result.
A future version may support pipemap:/path/to/file to load a list
of lookup tables from file.
[Feature 20140924] Support for unionmap, with the same syntax as
pipemap. This sends a query to all tables, and concatenates non-empty
results, separated by comma.
[Feature 20131121] The "static" lookup table now supports whitespace
when invoked as "static:{ text with whitespace }", so that it can
be used, for example, at the end of smtpd_mumble_restrictions as
"check_mumble_access static:{reject text...}".
[Feature 20141126] "inline:{key=value, { key = text with comma/space}}"
avoids the need to create a database for just a few entries.
Major changes - delivery status notifications
---------------------------------------------
[Feature 20140321] Delivery status filter support, to replace the
delivery status codes and explanatory text of successful or
unsuccessful deliveries by Postfix mail delivery agents.
This was originally implemented for sites that want to turn certain
soft delivery errors into hard delivery errors, but it can also be
used to censor out information from delivery confirmation reports.
This feature is implemented as a filter that replaces the three-number
enhanced status code and descriptive text in Postfix delivery agent
success, bounce, or defer messages. Note: this will not override
"soft_bounce=yes", and this will not change a successful delivery
status into an unsuccessful status or vice versa.
The first example turns specific soft TLS errors into hard
errors, by overriding the first number in the enhanced status code.
/etc/postfix/main.cf:
smtp_delivery_status_filter = pcre:/etc/postfix/smtp_dsn_filter
/etc/postfix/smtp_dsn_filter:
/^4(\.\d+\.\d+ TLS is required, but host \S+ refused to start TLS: .+)/ 5$1
/^4(\.\d+\.\d+ TLS is required, but was not offered by host .+)/ 5$1
The second example removes the destination command name and file
name from local(8) successful delivery reports, so that they will
not be reported when a sender requests confirmation of delivery.
/etc/postfix/main.cf:
local_delivery_status_filter = pcre:/etc/postfix/local_dsn_filter
/etc/postfix/local_dsn_filter:
/^(2\S+ delivered to file).+/ $1
/^(2\S+ delivered to command).+/ $1
This feature is supported in the lmtp(8), local(8), pipe(8), smtp(8)
and virtual(8) delivery agents. That is, all delivery agents that
actually deliver mail. It will not be implemented in the error and
retry pseudo-delivery agents.
The new main.cf parameters and default values are:
default_delivery_status_filter =
lmtp_delivery_status_filter = $default_delivery_status_filter
local_delivery_status_filter = $default_delivery_status_filter
pipe_delivery_status_filter = $default_delivery_status_filter
smtp_delivery_status_filter = $default_delivery_status_filter
virtual_delivery_status_filter = $default_delivery_status_filter
See the postconf(5) manpage for more details.
[Incompat 20140618] The pipe(8) delivery agent will now log a limited
amount of command output upon successful delivery, and will report
that output in "SUCCESS" delivery status reports. This is another
good reason to disable inbound DSN requests at the Internet perimeter.
[Feature 20140907] With "confirm_delay_cleared = yes", Postfix
informs the sender when delayed mail leaves the queue (this is in
addition to the delay_warning_time feature that warns when mail is
still queued). This feature is disabled by default, because it can
result in a sudden burst of notifications when the queue drains at
the end of a prolonged network outage.
Major changes - dns
-------------------
[Feature 20141128] Support for DNS server reply filters in the
Postfix SMTP/LMTP client and SMTP server. This helps to work around
mail delivery problems with sites that have incorrect DNS information.
Note: this has no effect on the implicit DNS lookups that are made
by nsswitch.conf or equivalent mechanisms.
This feature renders each lookup result as one line of text in
standard zone-file format as shown below. The class field is always
"IN", the preference field exists only for MX records, the names
of hosts, domains, etc. end in ".", and those names are in ASCII
form (xn--mumble form for internationalized domain names).
name ttl class type preference value
---------------------------------------------------------
postfix.org. 86400 IN MX 10 mail.cloud9.net.
Typically, one would match this text with a regexp: or pcre: table.
When a match is found, the table lookup result specifies an action.
By default, the table query and the action name are case-insensitive.
Currently, only the IGNORE action is implemented.
For safety reasons, Postfix logs a warning or defers mail delivery
when a DNS reply filter removes all lookup results from a successful
query.
The Postfix SMTP/LMTP client uses the smtp_dns_reply_filter and
lmtp_dns_reply_filter features only for Postfix SMTP client lookups
of MX, A, and AAAAA records to locate a remote SMTP or LMTP server,
including lookups that implement the features reject_unverified_sender
and reject_unverified_recipient. The filters are not used for lookups
made through nsswitch.conf and similar mechanisms.
The Postfix SMTP server uses the smtpd_dns_reply_filter feature
only for Postfix SMTP server lookups of MX, A, AAAAA, and TXT records
to implement the features reject_unknown_helo_hostname,
reject_unknown_sender_domain, reject_unknown_recipient_domain,
reject_rbl_*, and reject_rhsbl_*. The filter is not used for lookups
made through nsswitch.conf and similar mechanisms, such as lookups
of the remote SMTP client name.
[Feature 20141126] Nullmx support (MX records with a null hostname).
This change affects error messages only. The Postfix SMTP client
already bounced mail for such domains, and the Postfix SMTP server
already rejected such domains with reject_unknown_sender/recipient_domain.
This feature introduces a new SMTP server configuration parameter
nullmx_reject_code (default: 556).
Major changes - dynamic linking
-------------------------------
[Feature 20140530] Support to build Postfix with Postfix
dynamically-linked libraries, and with dynamically-loadable database
clients. These MUST NOT be used by non-Postfix programs. Postfix
dynamically-linked libraries introduce minor runtime overhead and
result in smaller Postfix executable files. Dynamically-loadable
database clients are useful when you distribute or install pre-compiled
packages. Postfix 3.0 supports dynamic loading for CDB, LDAP, LMDB,
MYSQL, PCRE, PGSQL, SDBM, and SQLITE database clients.
This implementation is based on Debian code by LaMont Jones, initially
ported by Viktor Dukhovni. Currently, support exists for recent
versions of Linux, FreeBSD, MacOS X, and for the ancient Solaris 9.
To support Postfix dynamically-linked libraries and dynamically-loadable
database clients, the Postfix build procedure had to be changed
(specifically, the files makedefs and Makefile.in, and the files
postfix-install and post-install that install or update Postfix).
[Incompat 20140530] The Postfix 3.0 build procedure expects that
you specify database library dependencies with variables named
AUXLIBS_CDB, AUXLIBS_LDAP, etc. With Postfix 3.0 and later, the
old AUXLIBS variable still supports building a statically-loaded
CDB etc. database client, but only the new AUXLIBS_CDB etc. variables
support building a dynamically-loaded or statically-loaded CDB etc.
database client. See CDB_README, LDAP_README, etc. for details.
Failure to follow this advice will defeat the purpose of dynamic
database client loading. Every Postfix executable file will have
database library dependencies. And that was exactly what dynamic
database client loading was meant to avoid.
Major changes - future proofing
-------------------------------
[Cleanup 20141224] The changes described here have no visible effect
on Postfix behavior, but they make Postfix code easier to maintain,
and therefore make new functionality easier to add.
* Compile-time argument typechecks of non-printf/scanf-like variadic
function argument lists.
* Deprecating the use of "char *" for non-text purposes such as
memory allocation and pointers to application context for call-back
functions. This dates from long-past days before void * became
universally available.
* Replace integer types for counters and sizes with size_t or ssize_t
equivalents. This eliminates some wasteful 64<->32bit conversions
on 64-bit systems.
Major changes - installation pathnames
--------------------------------------
[Incompat 20140625] For compliance with file system policies, some
non-executable files have been moved from $daemon_directory to the
directory specified with the new meta_directory configuration
parameter which has the same default value as the config_directory
parameter. This change affects non-executable files that are shared
between multiple Postfix instances such as postfix-files, dynamicmaps.cf,
and multi-instance template files.
For backwards compatibility with Postfix 2.6 .. 2.11, specify
"meta_directory = $daemon_directory" in main.cf before installing
or upgrading Postfix, or specify "meta_directory = /path/name" on
the "make makefiles", "make install" or "make upgrade" command line.
Major changes - milter
----------------------
[Feature 20140928] Support for per-Milter settings that override
main.cf parameters. For details see the section "Advanced policy
client configuration" in the SMTPD_POLICY_README document.
Here is an example that uses both old and new syntax:
smtpd_milters = { inet:127.0.0.1:port1, default_action=accept, ... },
inet:127.0.0.1:port2, ...
The supported attribute names are: command_timeout, connect_timeout,
content_timeout, default_action, and protocol. These have the same
names as the corresponding main.cf parameters, without the "milter_"
prefix.
The per-milter settings are specified as attribute=value pairs
separated by comma or space; specify { name = value } to allow
spaces around the "=" or within an attribute value.
[Feature 20141018] DMARC compatibility: when a Milter inserts a
header ABOVE Postfix's own Received: header, Postfix no longer
exposes its own Received: header to Milters (violating protocol)
and Postfix no longer hides the Milter-inserted header from Milters
(wtf).
Major changes - parameter syntax
--------------------------------
[Feature 20140921] In preparation for configurable mail headers and
logging, new main.cf support for if-then-else expressions:
${name?{text1}:{text2}}
and for logical expressions:
${{text1}=={text2}?{text3}:{text4}}
${{text1}!={text2}?{text3}:{text4}}
Whitespace before and after {text} is ignored. This can help to
make complex expressions more readable. See the postconf(5) manpage
for further details.
[Feature 20140928] Support for whitespace in daemon command-line
arguments. For details, see the "Command name + arguments" section
in the master(5) manpage. Example:
smtpd -o { parameter = value containing whitespace } ...
The { ... } form is also available for non-option command-line
arguments in master.cf, for example:
pipe ... argv=command { argument containing whitespace } ...
In both cases, whitespace immediately after "{" and before "}"
is ignored.
[Feature 20141005] Postfix import_environment and export_environment
now allow "{ name=value }" to protect whitespace in attribute values.
[Feature 20141006] The new message_drop_header parameter replaces
a hard-coded table that specifies what message headers the cleanup
daemon will remove. The list of supported header names covers RFC
5321, 5322, MIME RFCs, and some historical names.
Major changes - pipe daemon
---------------------------
[Incompat 20140618] The pipe(8) delivery agent will now log a limited
amount of command output upon successful delivery, and will report
that output in "SUCCESS" delivery status reports. This is another
good reason to disable inbound DSN requests at the Internet perimeter.
Major changes - policy client
-----------------------------
[Feature 20140703] This release introduces three new configuration
parameters that control error recovery for failed SMTPD policy
requests.
* smtpd_policy_service_default_action (default: 451 4.3.5 Server
configuration problem): The default action when an SMTPD policy
service request fails.
* smtpd_policy_service_try_limit (default: 2): The maximal number
of attempts to send an SMTPD policy service request before
giving up. This must be a number greater than zero.
* smtpd_policy_service_retry_delay (default: 1s): The delay between
attempts to resend a failed SMTPD policy service request. This
must be a number greater than zero.
See postconf(5) for details and limitations.
[Feature 20140928] Support for per-policy service settings that
override main.cf parameters. For details see the section "Different
settings for different Milter applications" in the MILTER_README
document.
Here is an example that uses both old and new syntax:
smtpd_recipient_restrictions = ...
check_policy_service { inet:127.0.0.1:port3, default_action=DUNNO }
check_policy_service inet:127.0.0.1:port4
...
The per-policy service settings are specified as attribute=value pairs
separated by comma or space; specify { name = value } to allow
spaces around the "=" or within an attribute value.
The supported attribute names are: default_action, max_idle, max_ttl,
request_limit, retry_delay, timeout, try_limit. These have the same
names as the corresponding main.cf parameters, without the
"smtpd_policy_service_" prefix.
[Feature 20140505] A client port attribute was added to the policy
delegation protocol.
[Feature 20140630] New smtpd_policy_service_request_limit feature to
limit the number of requests per Postfix SMTP server policy connection.
This is a workaround to avoid error-recovery delays with policy
servers that cannot maintain a persistent connection.
Major changes - position-independent executables
------------------------------------------------
[Feature 20150205] Preliminary support for building position-independent
executables (PIE), tested on Fedora Core 20, Ubuntu 14.04, FreeBSD
9 and 10, and NetBSD 6. Specify:
$ make makefiles pie=yes ...other arguments...
On some systems, PIE is used by the ASLR exploit mitigation technique
(ASLR = Address-Space Layout Randomization). Whether specifying
"pie=yes" has any effect at all depends on the compiler. Reportedly,
some compilers always produce PIE executables.
Major changes - postscreen
--------------------------
[Feature 20140501] Configurable time limit (postscreen_dnsbl_timeout)
for DNSBL or DNSWL lookups. This is separate from the timeouts in
the dnsblog(8) daemon which are controlled by system resolver(3)
routines.
Major changes - session fingerprint
-----------------------------------
[Feature 20140801] The Postfix SMTP server now logs at the end of
a session how many times an SMTP command was successfully invoked,
followed by the total number of invocations if some invocations
were unsuccessful.
This logging will enough to diagnose many problems without using
verbose logging or network sniffer.
Normal session, no TLS:
disconnect from name[addr] ehlo=1 mail=1 rcpt=1 data=1 quit=1
Normal session. with TLS:
disconnect from name[addr] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1
All recipients rejected, no ESMTP command pipelining:
disconnect from name[addr] ehlo=1 mail=1 rcpt=0/1 quit=1
All recipients rejected, with ESMTP command pipelining:
disconnect from name[addr] ehlo=1 mail=1 rcpt=0/1 data=0/1 rset=1 quit=1
Password guessing bot, hangs up without QUIT:
disconnect from name[addr] ehlo=1 auth=0/1
Mis-configured client trying to use TLS wrappermode on port 587:
disconnect from name[addr] unknown=0/1
Logfile analyzers can trigger on the presence of "/". It indicates
that Postfix rejected at least one command.
[Feature 20150118] As a late addition, the SMTP server now also
logs the total number of commands (as "commands=x/y") even when the
client did not send any commands. This helps logfile analyzers to
recognize sessions without commands.
Major changes - smtp client
---------------------------
[Feature 20141227] The new smtp_address_verify_target parameter
(default: rcpt) determines what protocol stage decides if a recipient
is valid. Specify "data" for servers that reject recipients after
the DATA command.
Major changes - smtputf8
------------------------
[Incompat 20141001] The default settings have changed for
append_dot_mydomain (new: no, old: yes), master.cf chroot (new:
n, old: y), and smtputf8 (new: yes, old: no).
[Incompat 20140714] After upgrading Postfix, "postfix reload" (or
start/stop) is required. Several Postfix-internal protocols have
been extended to support SMTPUTF8. Failure to reload or restart
will result in mail staying queued, while Postfix daemons log
warning messages about unexpected attributes.
[Feature 20140715] Support for Email Address Internationalization
(EAI) as defined in RFC 6531..6533. This supports UTF-8 in SMTP/LMTP
sender addresses, recipient addresses, and message header values.
The implementation is based on initial work by Arnt Gulbrandsen
that was funded by CNNIC.
See SMTPUTF8_README for a description of Postfix SMTPUTF8 support.
[Feature 20150112] UTF-8 Casefolding support for Postfix lookup
tables and matchlists (mydestination, relay_domains, etc.). This
is enabled only with "smtpuf8 = yes".
[Feature 20150112] With smtputf8_enable=yes, SMTP commands with
UTF-8 syntax errors are rejected, table lookup results with invalid
UTF-8 syntax are handled as configuration errors, and UTF-8 syntax
errors in policy server replies result in execution of the policy
server's default action.
Major changes - tls support
---------------------------
(see "Major changes - delivery status notifications" above for
turning 4XX soft errors into 5XX bounces when a remote SMTP server
does not offer STARTTLS support).
[Feature 20140209] the Postfix SMTP client now also falls back to
plaintext when TLS fails AFTER the TLS protocol handshake.
[Feature 20140218] The Postfix SMTP client now requires that a queue
file is older than $minimal_backoff_time, before falling back from
failed TLS to plaintext (both during or after the TLS handshake).
[Feature 20141021] Per IETF TLS WG consensus, the tls_session_ticket_cipher
default setting was changed from aes-128-cbc to aes-256-cbc.
[Feature 20150116] TLS wrappermode support in the Postfix smtp(8)
client (new smtp_tls_wrappermode parameter) and in posttls-finger(1)
(new -w option). There still is life in that deprecated protocol,
and people should not have to jump hoops with stunnel.
@
text
@a109 3
RFC 6531 (Internationalized SMTP)
RFC 6533 (Internationalized Delivery Status Notifications)
RFC 7672 (SMTP security via opportunistic DANE TLS)
d222 3
a224 4
When the remote SMTP servername is a DNS CNAME, replace the
servername with the result from CNAME expansion for the purpose
of logging, SASL password lookup, TLS policy decisions, or TLS
certificate verification.
d229 2
a230 2
Lookup tables, indexed by the remote LMTP server address, with
case insensitive lists of LHLO keywords (pipelining, starttls,
d235 1
a235 1
A case insensitive list of LHLO keywords (pipelining, starttls,
d242 3
a244 3
When authenticating to a remote SMTP or LMTP server with the
default setting "no", send no SASL authoriZation ID (authzid);
send only the SASL authentiCation ID (authcid) plus the auth-
d250 1
a250 1
Restricted header_checks(5) tables for the Postfix SMTP client.
d253 1
a253 1
Restricted mime_header_checks(5) tables for the Postfix SMTP
d257 1
a257 1
Restricted nested_header_checks(5) tables for the Postfix SMTP
d266 1
a266 1
An optional workaround for routers that break TCP window scal-
d277 4
a280 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
d284 1
a284 1
Whether or not to append the "AUTH=<>" option to the MAIL FROM
a291 10
Available in Postfix version 3.0 and later:
smtp_delivery_status_filter ($default_delivery_status_filter)
Optional filter for the smtp(8) delivery agent to change the
delivery status code or explanatory text of successful or unsuc-
cessful deliveries.
smtp_dns_reply_filter (empty)
Optional filter for Postfix SMTP client DNS lookup results.
d308 1
a308 1
Send the non-standard XFORWARD command when the Postfix SMTP
d316 3
a318 3
Optional Postfix SMTP client lookup tables with one user-
name:password entry per sender, remote hostname or next-hop
domain.
d322 1
a322 1
list of available features depends on the SASL client implemen-
d328 1
a328 1
If non-empty, a Postfix SMTP client filter for the remote SMTP
d335 2
a336 2
client; this is available only with SASL authentication, and
disables SMTP connection caching to ensure that mail from dif-
d341 1
a341 1
passes through to the SASL plug-in implementation that is
d345 1
a345 1
The SASL plug-in type that the Postfix SMTP client should use
d351 2
a352 2
An optional table to prevent repeated SASL authentication fail-
ures with the same remote SMTP server hostname, username and
d356 1
a356 1
The maximal age of an smtp_sasl_auth_cache_name entry before it
d360 2
a361 2
When a remote SMTP server rejects a SASL authentication request
with a 535 reply code, defer mail delivery instead of returning
d367 1
a367 1
Whether or not to append the "AUTH=<>" option to the MAIL FROM
d371 1
a371 1
Detailed information about STARTTLS configuration may be found in the
d381 1
a381 1
The SASL authentication security options that the Postfix SMTP
d385 1
a385 1
Time limit for Postfix SMTP client write and read operations
d389 2
a390 2
A file containing CA certificates of root CAs trusted to sign
either remote SMTP server certificates or intermediate CA cer-
d394 1
a394 1
Directory with PEM format Certification Authority certificates
d402 1
a402 1
The minimum TLS cipher grade that the Postfix SMTP client will
d410 2
a411 2
Additional list of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at mandatory TLS security lev-
d427 1
a427 1
Log the hostname of a remote SMTP server that offers STARTTLS,
d436 1
a436 1
List of SSL/TLS protocols that the Postfix SMTP client will use
d443 1
a443 1
How the Postfix SMTP client verifies the server certificate
d451 1
a451 1
The expiration time of Postfix SMTP client TLS session cache
d455 1
a455 1
How the Postfix SMTP client verifies the server certificate
d459 2
a460 2
The number of pseudo-random bytes that an smtp(8) or smtpd(8)
process requests from the tlsmgr(8) server in order to seed its
d463 2
a464 2
tls_high_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "high" grade ciphers.
d466 2
a467 2
tls_medium_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "medium" or higher grade ciphers.
d469 2
a470 2
tls_low_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "low" or higher grade ciphers.
d472 2
a473 2
tls_export_cipherlist (see 'postconf -d' output)
The OpenSSL cipherlist for "export" or higher grade ciphers.
d476 1
a476 1
The OpenSSL cipherlist for "NULL" grade ciphers that provide
d483 2
a484 2
The SASL authentication security options that the Postfix SMTP
client uses for TLS encrypted SMTP sessions with a verified
d490 2
a491 2
List of acceptable remote SMTP server certificate fingerprints
for the "fingerprint" TLS security level (smtp_tls_secu-
d495 1
a495 1
The message digest algorithm used to construct remote SMTP
d501 1
a501 1
List of TLS protocols that the Postfix SMTP client will exclude
d505 1
a505 1
The minimum TLS cipher grade that the Postfix SMTP client will
d509 1
a509 1
File with the Postfix SMTP client ECDSA certificate in PEM for-
d513 1
a513 1
File with the Postfix SMTP client ECDSA private key in PEM for-
d519 3
a521 3
Try to detect a mail hijacking attack based on a TLS protocol
vulnerability (CVE-2009-3555), where an attacker prepends mali-
cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client
d532 1
a532 1
Zero or more PEM-format files with trust-anchor certificates
d536 1
a536 1
Lookup the associated DANE TLSA RRset even when a hostname is
a544 13
Available in Postfix version 3.0 and later:
smtp_tls_wrappermode (no)
Request that the Postfix SMTP client connects using the legacy
SMTPS protocol instead of using the STARTTLS command.
Available in Postfix version 3.1 and later:
smtp_tls_dane_insecure_mx_policy (dane)
The TLS policy for MX hosts with "secure" TLSA records when the
nexthop destination security level is dane, but the MX record
was found via an "insecure" MX lookup.
a684 11
SMTPUTF8 CONTROLS
Preliminary SMTPUTF8 support is introduced with Postfix 3.0.
smtputf8_enable (yes)
Enable preliminary SMTPUTF8 support for the protocols described
in RFC 6531..6533.
smtputf8_autodetect_classes (sendmail, verify)
Detect that a message requires SMTPUTF8 support for the speci-
fied mail origin classes.
d701 3
a703 3
What categories of Postfix-generated mail are subject to
before-queue content inspection by non_smtpd_milters,
header_checks and body_checks.
d780 1
a780 1
The hostname to send in the SMTP HELO or EHLO command.
a811 12
Available with Postfix 3.0 and later:
smtp_address_verify_target (rcpt)
In the context of email address verification, the SMTP protocol
stage that determines whether an email address is deliverable.
Available with Postfix 3.1 and later:
lmtp_fallback_relay (empty)
Optional list of relay hosts for LMTP destinations that can't be
found or that are unreachable.
a837 5
Wietse Venema
Google, Inc.
111 8th Avenue
New York, NY 10011, USA
@
1.1.1.9.14.1
log
@Pull up the following, requeste by kim in ticket #1779:
external/ibm-public/postfix/dist/README_FILES/BDAT_README up to 1.1.1.2
external/ibm-public/postfix/dist/README_FILES/MAILLOG_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/POSTSCREEN_3_5_README up to 1.1.1.1
external/ibm-public/postfix/dist/html/BDAT_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/MAILLOG_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/makedefs.1.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/postlogd.8.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/POSTSCREEN_3_5_README.html up to 1.1.1.2
external/ibm-public/postfix/dist/html/postfix-doc.css up to 1.1.1.1
external/ibm-public/postfix/dist/man/man1/makedefs.1 up to 1.3
external/ibm-public/postfix/dist/man/man8/postlogd.8 up to 1.3
external/ibm-public/postfix/dist/mantools/missing-proxy-read-maps up to 1.1.1.3
external/ibm-public/postfix/dist/mantools/spelldiff up to 1.1.1.1
external/ibm-public/postfix/dist/mantools/check-double-cc up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/check-double-install-proto-text up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/check-double-proto-html up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/comment.c up to 1.2
external/ibm-public/postfix/dist/mantools/check-postfix-files up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/check-spell-cc up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/check-spell-install-proto-text up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/check-spell-proto-html up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/deroff up to 1.1.1.1
external/ibm-public/postfix/dist/mantools/find-double up to 1.1.1.1
external/ibm-public/postfix/dist/mantools/check-double-history up to 1.1.1.1
external/ibm-public/postfix/dist/mantools/check-spell-history up to 1.1.1.1
external/ibm-public/postfix/dist/mantools/check-table-proto up to 1.1.1.1
external/ibm-public/postfix/dist/proto/BDAT_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/MAILLOG_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/POSTSCREEN_3_5_README.html up to 1.1.1.2
external/ibm-public/postfix/dist/proto/stop.double-cc up to 1.1.1.2
external/ibm-public/postfix/dist/proto/stop.double-install-proto-text up to 1.1.1.1
external/ibm-public/postfix/dist/proto/stop.double-proto-html up to 1.1.1.2
external/ibm-public/postfix/dist/proto/stop.spell-cc up to 1.1.1.2
external/ibm-public/postfix/dist/proto/stop.spell-proto-html up to 1.1.1.2
external/ibm-public/postfix/dist/proto/stop.double-history up to 1.1.1.1
external/ibm-public/postfix/dist/proto/stop.spell-history up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/bounce_notify_util_tester.c up to 1.2
external/ibm-public/postfix/dist/src/bounce/logfile-no-msgid-no-eoh-event up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/logfile-no-msgid-with-eoh-event up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/logfile-with-msgid-no-eoh-event up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/logfile-with-msgid-with-eoh-event up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/logfile-with-msgid-with-filter up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/logfile-with-msgid-with-long-line up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/msgfile-no-msgid-no-eoh-event up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/msgfile-no-msgid-with-eoh-event up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/msgfile-with-msgid-no-eoh-event up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/msgfile-with-msgid-with-eoh-event up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/obs_template_test.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/msgfile-with-msgid-with-filter up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/msgfile-with-msgid-with-long-line up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/no-msgid-no-eoh-event-no-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/no-msgid-no-eoh-event-with-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/no-msgid-with-eoh-event-no-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/no-msgid-with-eoh-event-with-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/with-msgid-no-eoh-event-no-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/with-msgid-no-eoh-event-with-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/with-msgid-with-eoh-event-no-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/with-msgid-with-eoh-event-with-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/with-msgid-with-filter-no-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/with-msgid-with-filter-with-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/with-msgid-with-long-line-no-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/bounce/with-msgid-with-long-line-with-thread.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13e up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13f up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13g up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13h up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13i up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13e up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13f up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13g up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13h up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13i up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/test-queue-file13e up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/test-queue-file13f up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/test-queue-file13g up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/test-queue-file13h up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/test-queue-file13i up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17a up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17b up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17c up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17d up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17e up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17f up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17g up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17a1 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17a2 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17b1 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17b2 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17c1 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17c2 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17d1 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17d2 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17e1 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17e2 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17f1 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17f2 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17g1 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17g2 up to 1.1.1.1
external/ibm-public/postfix/dist/src/cleanup/test-queue-file17 up to 1.1.1.1
external/ibm-public/postfix/dist/src/dns/dns_str_resflags.c up to 1.3
external/ibm-public/postfix/dist/src/dns/dns_sec.c up to 1.2
external/ibm-public/postfix/dist/src/global/header_body_checks_strip.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/info_log_addr_form.c up to 1.2
external/ibm-public/postfix/dist/src/global/info_log_addr_form.h up to 1.2
external/ibm-public/postfix/dist/src/global/mail_addr_crunch.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/mail_addr_crunch.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/mail_addr_find.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/map_search.c up to 1.4
external/ibm-public/postfix/dist/src/global/map_search.h up to 1.2
external/ibm-public/postfix/dist/src/global/mail_addr_find.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/mail_addr_form.c up to 1.2
external/ibm-public/postfix/dist/src/global/mail_addr_form.h up to 1.2
external/ibm-public/postfix/dist/src/global/mail_addr_map.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/maillog_client.c up to 1.3
external/ibm-public/postfix/dist/src/global/maillog_client.h up to 1.2
external/ibm-public/postfix/dist/src/global/map_search.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/global/normalize_mailhost_addr.c up to 1.3
external/ibm-public/postfix/dist/src/global/normalize_mailhost_addr.h up to 1.2
external/ibm-public/postfix/dist/src/global/off_cvt.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/off_cvt.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/quote_822_local.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/global/quote_822_local.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/global/quote_flags.c up to 1.2
external/ibm-public/postfix/dist/src/global/reject_deliver_request.c up to 1.2
external/ibm-public/postfix/dist/src/global/compat_level.c up to 1.3
external/ibm-public/postfix/dist/src/global/compat_level.h up to 1.3
external/ibm-public/postfix/dist/src/global/test_main.c up to 1.2
external/ibm-public/postfix/dist/src/global/compat_level_convert.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/compat_level_convert.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/compat_level_expand.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/compat_level_expand.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/config_known_tcp_ports.c up to 1.2
external/ibm-public/postfix/dist/src/global/config_known_tcp_ports.h up to 1.2
external/ibm-public/postfix/dist/src/global/config_known_tcp_ports.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/delivered_hdr.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/hfrom_format.c up to 1.2
external/ibm-public/postfix/dist/src/global/hfrom_format.h up to 1.2
external/ibm-public/postfix/dist/src/global/hfrom_format.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/login_sender_match.c up to 1.2
external/ibm-public/postfix/dist/src/global/login_sender_match.h up to 1.2
external/ibm-public/postfix/dist/src/global/login_sender_match.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/global/sasl_mech_filter.c up to 1.2
external/ibm-public/postfix/dist/src/global/sasl_mech_filter.h up to 1.2
external/ibm-public/postfix/dist/src/global/test_main.h up to 1.2
external/ibm-public/postfix/dist/src/master/dgram_server.c up to 1.3
external/ibm-public/postfix/dist/src/postconf/extract_cfg.sh up to 1.1.1.1
external/ibm-public/postfix/dist/src/postconf/test64.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postconf/test65.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postconf/test66.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postconf/test67.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postconf/test68.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postconf/test69.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postconf/test70.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postconf/test71.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postmap/file_test.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/postmap/file_test.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postmap/quote_test.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/postmap/quote_test.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/postmap/lmdb_abb up to 1.1.1.1
external/ibm-public/postfix/dist/src/postmap/lmdb_abb.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/smtp/smtp_misc.c up to 1.2
external/ibm-public/postfix/dist/src/smtp/smtp_map11.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/smtpd/smtpd_addr_valid.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_addr_valid.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/tls/bad-back-to-back-keys.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/bad-back-to-back-keys.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/bad-ec-cert-before-key.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/bad-ec-cert-before-key.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/bad-key-cert-mismatch.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/bad-key-cert-mismatch.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/bad-rsa-key-last.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/bad-rsa-key-last.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/ecca-cert.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/ecca-pkey.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/ecee-cert.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/ecee-pkey.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/ecroot-cert.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/ecroot-pkey.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/good-mixed-keyfirst.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/good-mixed-keyfirst.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/good-mixed-keylast.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/good-mixed-keylast.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/good-mixed-keymiddle.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/good-mixed-keymiddle.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/goodchains.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/goodchains.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/mkcert.sh up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/rsaca-cert.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/rsaca-pkey.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/rsaee-cert.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/rsaee-pkey.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/rsaroot-cert.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/rsaroot-pkey.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/tls_proxy_client_misc.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_proxy_client_print.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_proxy_client_scan.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_proxy_context_print.c up to 1.3
external/ibm-public/postfix/dist/src/tls/tls_proxy_context_scan.c up to 1.3
external/ibm-public/postfix/dist/src/tls/tls_proxy_server_print.c up to 1.3
external/ibm-public/postfix/dist/src/tls/tls_proxy_server_scan.c up to 1.3
external/ibm-public/postfix/dist/src/tls/warn-mixed-multi-key.pem up to 1.1.1.1
external/ibm-public/postfix/dist/src/tls/warn-mixed-multi-key.pem.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/trivial-rewrite/transport.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/trivial-rewrite/transport.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/mkmap_db.c up to 1.2
external/ibm-public/postfix/dist/src/util/mkmap.h up to 1.2
external/ibm-public/postfix/dist/src/util/argv_attr.h up to 1.3
external/ibm-public/postfix/dist/src/util/argv_attr_print.c up to 1.3
external/ibm-public/postfix/dist/src/util/argv_attr_scan.c up to 1.3
external/ibm-public/postfix/dist/src/util/byte_mask.c up to 1.2
external/ibm-public/postfix/dist/src/util/byte_mask.h up to 1.2
external/ibm-public/postfix/dist/src/util/byte_mask.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/byte_mask.ref0 up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/byte_mask.ref1 up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/byte_mask.ref2 up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_file.c up to 1.3
external/ibm-public/postfix/dist/src/util/dict_cidr_file.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/logwriter.c up to 1.2
external/ibm-public/postfix/dist/src/util/dict_cidr_file.map up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_cidr_file.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_inline_file.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_pcre_file.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_pcre_file.map up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_pcre_file.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_pipe_test.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_pipe_test.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_random.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_random_file.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_regexp_file.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_regexp_file.map up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_regexp_file.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_static_file.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_thash.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_thash.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_union_test.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_union_test.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/logwriter.h up to 1.2
external/ibm-public/postfix/dist/src/util/miss_endif_cidr.map up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/miss_endif_cidr.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/miss_endif_pcre.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/miss_endif_re.map up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/miss_endif_regexp.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/msg_logger.c up to 1.3
external/ibm-public/postfix/dist/src/util/msg_logger.h up to 1.2
external/ibm-public/postfix/dist/src/util/split_qnameval.c up to 1.2
external/ibm-public/postfix/dist/src/util/unix_dgram_connect.c up to 1.3
external/ibm-public/postfix/dist/src/util/unix_dgram_listen.c up to 1.3
external/ibm-public/postfix/dist/src/util/vbuf_print_test.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/vbuf_print_test.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/vstream_test.in up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/vstream_test.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/vstring_test.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/sane_strtol.c up to 1.2
external/ibm-public/postfix/dist/src/util/argv_split_at.c up to 1.2
external/ibm-public/postfix/dist/src/util/dict_stream.c up to 1.2
external/ibm-public/postfix/dist/src/util/dict_inline_cidr.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_inline_pcre.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_inline_regexp.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/dict_stream.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/find_inet.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/hash_fnv.c up to 1.3
external/ibm-public/postfix/dist/src/util/hash_fnv.h up to 1.3
external/ibm-public/postfix/dist/src/util/known_tcp_ports.c up to 1.2
external/ibm-public/postfix/dist/src/util/known_tcp_ports.h up to 1.2
external/ibm-public/postfix/dist/src/util/known_tcp_ports.ref up to 1.1.1.1
external/ibm-public/postfix/dist/src/util/ldseed.c up to 1.2
external/ibm-public/postfix/dist/src/util/ldseed.h up to 1.2
external/ibm-public/postfix/dist/src/util/mystrtok.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/sane_strtol.h up to 1.2
external/ibm-public/postfix/dist/src/util/inet_addr_sizes.c up to 1.2
external/ibm-public/postfix/dist/src/util/inet_addr_sizes.h up to 1.2
external/ibm-public/postfix/dist/src/util/inet_prefix_top.c up to 1.2
external/ibm-public/postfix/dist/src/util/inet_prefix_top.h up to 1.2
external/ibm-public/postfix/dist/src/util/mkmap_cdb.c up to 1.2
external/ibm-public/postfix/dist/src/util/mkmap_dbm.c up to 1.2
external/ibm-public/postfix/dist/src/util/mkmap_fail.c up to 1.2
external/ibm-public/postfix/dist/src/util/mkmap_lmdb.c up to 1.2
external/ibm-public/postfix/dist/src/util/mkmap_open.c up to 1.2
external/ibm-public/postfix/dist/src/util/mkmap_sdbm.c up to 1.2
external/ibm-public/postfix/dist/src/postlogd/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/postlogd/postlogd.c up to 1.3
external/ibm-public/postfix/dist/RELEASE_NOTES-3.1 up to 1.1.1.1
external/ibm-public/postfix/dist/RELEASE_NOTES-3.2 up to 1.1.1.1
external/ibm-public/postfix/dist/RELEASE_NOTES-3.3 up to 1.1.1.1
external/ibm-public/postfix/dist/RELEASE_NOTES-3.4 up to 1.1.1.1
external/ibm-public/postfix/dist/RELEASE_NOTES-3.5 up to 1.1.1.1
external/ibm-public/postfix/dist/RELEASE_NOTES-3.6 up to 1.1.1.1
external/ibm-public/postfix/dist/WISHLIST up to 1.1.1.2
external/ibm-public/postfix/dist/RELEASE_NOTES-3.7 up to 1.1.1.1
external/ibm-public/postfix/dist/README_FILES/CYRUS_README delete
external/ibm-public/postfix/dist/src/global/mkmap.h delete
external/ibm-public/postfix/dist/src/global/mkmap_cdb.c delete
external/ibm-public/postfix/dist/src/global/mkmap_db.c delete
external/ibm-public/postfix/dist/src/global/mkmap_dbm.c delete
external/ibm-public/postfix/dist/src/global/mkmap_fail.c delete
external/ibm-public/postfix/dist/src/global/mkmap_lmdb.c delete
external/ibm-public/postfix/dist/src/global/mkmap_open.c delete
external/ibm-public/postfix/dist/src/global/mkmap_sdbm.c delete
external/ibm-public/postfix/dist/src/smtp/map11_map delete
external/ibm-public/postfix/dist/src/tls/tls_proxy_print.c delete
external/ibm-public/postfix/dist/src/tls/tls_proxy_scan.c delete
external/ibm-public/postfix/dist/src/util/percentm.c delete
external/ibm-public/postfix/dist/src/util/percentm.h delete
external/ibm-public/postfix/Makefile.inc up to 1.31 (+patch)
external/ibm-public/postfix/dist/AAAREADME up to 1.1.1.4
external/ibm-public/postfix/dist/HISTORY up to 1.1.1.29
external/ibm-public/postfix/dist/INSTALL up to 1.1.1.9
external/ibm-public/postfix/dist/LICENSE up to 1.1.1.2
external/ibm-public/postfix/dist/Makefile up to 1.1.1.3
external/ibm-public/postfix/dist/Makefile.in up to 1.1.1.10
external/ibm-public/postfix/dist/Makefile.init up to 1.1.1.3
external/ibm-public/postfix/dist/RELEASE_NOTES up to 1.1.1.17
external/ibm-public/postfix/dist/TLS_ACKNOWLEDGEMENTS up to 1.1.1.2
external/ibm-public/postfix/dist/TLS_CHANGES up to 1.1.1.2
external/ibm-public/postfix/dist/TLS_LICENSE up to 1.1.1.2
external/ibm-public/postfix/dist/US_PATENT_6321267 up to 1.1.1.2
external/ibm-public/postfix/dist/makedefs up to 1.16
external/ibm-public/postfix/dist/postfix-env.sh up to 1.1.1.2
external/ibm-public/postfix/dist/postfix-install up to 1.8
external/ibm-public/postfix/dist/README_FILES/AAAREADME up to 1.1.1.6
external/ibm-public/postfix/dist/README_FILES/ADDRESS_CLASS_README up to 1.1.1.2
external/ibm-public/postfix/dist/README_FILES/ADDRESS_REWRITING_README up to 1.1.1.5
external/ibm-public/postfix/dist/README_FILES/ADDRESS_VERIFICATION_README up to 1.10
external/ibm-public/postfix/dist/README_FILES/BACKSCATTER_README up to 1.1.1.5
external/ibm-public/postfix/dist/README_FILES/BASIC_CONFIGURATION_README up to 1.1.1.6
external/ibm-public/postfix/dist/README_FILES/BUILTIN_FILTER_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/COMPATIBILITY_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/CONNECTION_CACHE_README up to 1.1.1.5
external/ibm-public/postfix/dist/README_FILES/DATABASE_README up to 1.1.1.9
external/ibm-public/postfix/dist/README_FILES/DB_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/DEBUG_README up to 1.1.1.5
external/ibm-public/postfix/dist/README_FILES/FILTER_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/FORWARD_SECRECY_README up to 1.1.1.5
external/ibm-public/postfix/dist/README_FILES/INSTALL up to 1.10
external/ibm-public/postfix/dist/README_FILES/IPV6_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/LDAP_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/LINUX_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/LMDB_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/MILTER_README up to 1.1.1.9
external/ibm-public/postfix/dist/README_FILES/MULTI_INSTANCE_README up to 1.1.1.7
external/ibm-public/postfix/dist/README_FILES/MYSQL_README up to 1.1.1.5
external/ibm-public/postfix/dist/README_FILES/OVERVIEW up to 1.1.1.5
external/ibm-public/postfix/dist/README_FILES/PCRE_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/PGSQL_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/POSTSCREEN_README up to 1.1.1.7
external/ibm-public/postfix/dist/README_FILES/QSHAPE_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/RELEASE_NOTES up to 1.1.1.17
external/ibm-public/postfix/dist/README_FILES/SASL_README up to 1.1.1.11
external/ibm-public/postfix/dist/README_FILES/SCHEDULER_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/SMTPD_ACCESS_README up to 1.1.1.6
external/ibm-public/postfix/dist/README_FILES/SMTPD_POLICY_README up to 1.1.1.7
external/ibm-public/postfix/dist/README_FILES/SMTPD_PROXY_README up to 1.1.1.6
external/ibm-public/postfix/dist/README_FILES/SMTPUTF8_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/SOHO_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/SQLITE_README up to 1.1.1.4
external/ibm-public/postfix/dist/README_FILES/STANDARD_CONFIGURATION_README up to 1.1.1.6
external/ibm-public/postfix/dist/README_FILES/STRESS_README up to 1.1.1.6
external/ibm-public/postfix/dist/README_FILES/TLS_LEGACY_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/TLS_README up to 1.14
external/ibm-public/postfix/dist/README_FILES/TUNING_README up to 1.1.1.5
external/ibm-public/postfix/dist/README_FILES/VIRTUAL_README up to 1.1.1.3
external/ibm-public/postfix/dist/README_FILES/XCLIENT_README up to 1.1.1.4
external/ibm-public/postfix/dist/conf/LICENSE up to 1.1.1.2
external/ibm-public/postfix/dist/conf/TLS_LICENSE up to 1.1.1.2
external/ibm-public/postfix/dist/conf/access up to 1.1.1.8
external/ibm-public/postfix/dist/conf/aliases up to 1.1.1.5
external/ibm-public/postfix/dist/conf/canonical up to 1.1.1.5
external/ibm-public/postfix/dist/conf/generic up to 1.1.1.4
external/ibm-public/postfix/dist/conf/header_checks up to 1.1.1.6
external/ibm-public/postfix/dist/conf/main.cf up to 1.10
external/ibm-public/postfix/dist/conf/master.cf up to 1.11
external/ibm-public/postfix/dist/conf/post-install up to 1.4
external/ibm-public/postfix/dist/conf/postfix-files up to 1.9
external/ibm-public/postfix/dist/conf/postfix-script up to 1.4
external/ibm-public/postfix/dist/conf/postfix-tls-script up to 1.5
external/ibm-public/postfix/dist/conf/postmulti-script up to 1.3
external/ibm-public/postfix/dist/conf/relocated up to 1.1.1.3
external/ibm-public/postfix/dist/conf/transport up to 1.1.1.5
external/ibm-public/postfix/dist/conf/virtual up to 1.1.1.6
external/ibm-public/postfix/dist/html/ADDRESS_CLASS_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/ADDRESS_REWRITING_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/ADDRESS_VERIFICATION_README.html up to 1.11
external/ibm-public/postfix/dist/html/BACKSCATTER_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/BASIC_CONFIGURATION_README.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/BUILTIN_FILTER_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/CDB_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/COMPATIBILITY_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/CONNECTION_CACHE_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/CONTENT_INSPECTION_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/DATABASE_README.html up to 1.1.1.10
external/ibm-public/postfix/dist/html/DB_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/DEBUG_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/DSN_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/ETRN_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/FILTER_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/FORWARD_SECRECY_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/INSTALL.html up to 1.10
external/ibm-public/postfix/dist/html/IPV6_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/LDAP_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/LINUX_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/LMDB_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/LOCAL_RECIPIENT_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/MAILDROP_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/MEMCACHE_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/MILTER_README.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/MULTI_INSTANCE_README.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/MYSQL_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/Makefile.in up to 1.1.1.7
external/ibm-public/postfix/dist/html/NFS_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/OVERVIEW.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/PACKAGE_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/PCRE_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/PGSQL_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/POSTSCREEN_README.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/QSHAPE_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/RESTRICTION_CLASS_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/SASL_README.html up to 1.1.1.11
external/ibm-public/postfix/dist/html/SCHEDULER_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/SMTPD_ACCESS_README.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/SMTPD_POLICY_README.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/SMTPD_PROXY_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/SMTPUTF8_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/SOHO_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/SQLITE_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/STANDARD_CONFIGURATION_README.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/STRESS_README.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/TLS_LEGACY_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/TLS_README.html up to 1.15
external/ibm-public/postfix/dist/html/TUNING_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/UUCP_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/VERP_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/VIRTUAL_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/XCLIENT_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/XFORWARD_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/access.5.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/aliases.5.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/anvil.8.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/bounce.5.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/bounce.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/canonical.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/cidr_table.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/cleanup.8.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/defer.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/discard.8.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/dnsblog.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/error.8.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/flush.8.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/generic.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/header_checks.5.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/index.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/ldap_table.5.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/lmdb_table.5.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/lmtp.8.html up to 1.1.1.12
external/ibm-public/postfix/dist/html/local.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/mailq.1.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/master.5.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/master.8.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/memcache_table.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/mysql_table.5.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/newaliases.1.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/nisplus_table.5.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/oqmgr.8.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/pcre_table.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/pgsql_table.5.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/pickup.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/pipe.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/postalias.1.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/postcat.1.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/postconf.1.html up to 1.1.1.11
external/ibm-public/postfix/dist/html/postconf.5.html up to 1.19
external/ibm-public/postfix/dist/html/postdrop.1.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/postfix-manuals.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/postfix-tls.1.html up to 1.1.1.3
external/ibm-public/postfix/dist/html/postfix-wrapper.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/postfix.1.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/postkick.1.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/postlock.1.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/postlog.1.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/postmap.1.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/postmulti.1.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/postqueue.1.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/postscreen.8.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/postsuper.1.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/posttls-finger.1.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/proxymap.8.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/qmgr.8.html up to 1.1.1.9
external/ibm-public/postfix/dist/html/qmqp-sink.1.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/qmqp-source.1.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/qmqpd.8.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/qshape.1.html up to 1.1.1.4
external/ibm-public/postfix/dist/html/regexp_table.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/relocated.5.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/scache.8.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/sendmail.1.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/showq.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/smtp-sink.1.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/smtp-source.1.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/smtp.8.html up to 1.1.1.12
external/ibm-public/postfix/dist/html/smtpd.8.html up to 1.1.1.13
external/ibm-public/postfix/dist/html/socketmap_table.5.html up to 1.1.1.5
external/ibm-public/postfix/dist/html/spawn.8.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/sqlite_table.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/tcp_table.5.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/tlsmgr.8.html up to 1.1.1.6
external/ibm-public/postfix/dist/html/tlsproxy.8.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/trace.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/transport.5.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/trivial-rewrite.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/verify.8.html up to 1.1.1.8
external/ibm-public/postfix/dist/html/virtual.5.html up to 1.1.1.7
external/ibm-public/postfix/dist/html/virtual.8.html up to 1.1.1.7
external/ibm-public/postfix/dist/man/Makefile.in up to 1.1.1.7
external/ibm-public/postfix/dist/man/man1/postalias.1 up to 1.4
external/ibm-public/postfix/dist/man/man1/postcat.1 up to 1.4
external/ibm-public/postfix/dist/man/man1/postconf.1 up to 1.4
external/ibm-public/postfix/dist/man/man1/postdrop.1 up to 1.4
external/ibm-public/postfix/dist/man/man1/postfix-tls.1 up to 1.3
external/ibm-public/postfix/dist/man/man1/postfix.1 up to 1.6
external/ibm-public/postfix/dist/man/man1/postkick.1 up to 1.3
external/ibm-public/postfix/dist/man/man1/postlock.1 up to 1.3
external/ibm-public/postfix/dist/man/man1/postlog.1 up to 1.5
external/ibm-public/postfix/dist/man/man1/postmap.1 up to 1.4
external/ibm-public/postfix/dist/man/man1/postmulti.1 up to 1.4
external/ibm-public/postfix/dist/man/man1/postqueue.1 up to 1.5
external/ibm-public/postfix/dist/man/man1/postsuper.1 up to 1.4
external/ibm-public/postfix/dist/man/man1/posttls-finger.1 up to 1.5
external/ibm-public/postfix/dist/man/man1/sendmail.1 up to 1.4
external/ibm-public/postfix/dist/man/man1/smtp-sink.1 up to 1.3
external/ibm-public/postfix/dist/man/man5/access.5 up to 1.4
external/ibm-public/postfix/dist/man/man5/aliases.5 up to 1.5
external/ibm-public/postfix/dist/man/man5/canonical.5 up to 1.4
external/ibm-public/postfix/dist/man/man5/cidr_table.5 up to 1.5
external/ibm-public/postfix/dist/man/man5/generic.5 up to 1.4
external/ibm-public/postfix/dist/man/man5/header_checks.5 up to 1.3
external/ibm-public/postfix/dist/man/man5/ldap_table.5 up to 1.5
external/ibm-public/postfix/dist/man/man5/lmdb_table.5 up to 1.3
external/ibm-public/postfix/dist/man/man5/master.5 up to 1.4
external/ibm-public/postfix/dist/man/man5/mysql_table.5 up to 1.5
external/ibm-public/postfix/dist/man/man5/pcre_table.5 up to 1.4
external/ibm-public/postfix/dist/man/man5/pgsql_table.5 up to 1.5
external/ibm-public/postfix/dist/man/man5/postconf.5 up to 1.19
external/ibm-public/postfix/dist/man/man5/regexp_table.5 up to 1.4
external/ibm-public/postfix/dist/man/man5/relocated.5 up to 1.3
external/ibm-public/postfix/dist/man/man5/socketmap_table.5 up to 1.3
external/ibm-public/postfix/dist/man/man5/sqlite_table.5 up to 1.4
external/ibm-public/postfix/dist/man/man5/tcp_table.5 up to 1.3
external/ibm-public/postfix/dist/man/man5/transport.5 up to 1.4
external/ibm-public/postfix/dist/man/man5/virtual.5 up to 1.5
external/ibm-public/postfix/dist/man/man8/anvil.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/bounce.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/cleanup.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/discard.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/dnsblog.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/error.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/flush.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/local.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/master.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/oqmgr.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/pickup.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/pipe.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/postscreen.8 up to 1.5
external/ibm-public/postfix/dist/man/man8/proxymap.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/qmgr.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/qmqpd.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/scache.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/showq.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/smtp.8 up to 1.5
external/ibm-public/postfix/dist/man/man8/smtpd.8 up to 1.5
external/ibm-public/postfix/dist/man/man8/spawn.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/tlsmgr.8 up to 1.3
external/ibm-public/postfix/dist/man/man8/tlsproxy.8 up to 1.5
external/ibm-public/postfix/dist/man/man8/trivial-rewrite.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/verify.8 up to 1.4
external/ibm-public/postfix/dist/man/man8/virtual.8 up to 1.4
external/ibm-public/postfix/dist/mantools/ccformat up to 1.1.1.3
external/ibm-public/postfix/dist/mantools/check-postlink up to 1.1.1.3
external/ibm-public/postfix/dist/mantools/fixman up to 1.1.1.3
external/ibm-public/postfix/dist/mantools/make-relnotes up to 1.1.1.3
external/ibm-public/postfix/dist/mantools/make_soho_readme up to 1.1.1.4
external/ibm-public/postfix/dist/mantools/makemanidx up to 1.1.1.4
external/ibm-public/postfix/dist/mantools/man2html up to 1.1.1.5
external/ibm-public/postfix/dist/mantools/manlint up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/manspell up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/postconf2man up to 1.1.1.5
external/ibm-public/postfix/dist/mantools/postlink up to 1.1.1.13
external/ibm-public/postfix/dist/mantools/readme2html up to 1.1.1.2
external/ibm-public/postfix/dist/mantools/spell up to 1.1.1.3
external/ibm-public/postfix/dist/mantools/srctoman up to 1.1.1.3
external/ibm-public/postfix/dist/proto/ADDRESS_CLASS_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/ADDRESS_REWRITING_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/ADDRESS_VERIFICATION_README.html up to 1.11
external/ibm-public/postfix/dist/proto/BACKSCATTER_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/BASIC_CONFIGURATION_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/BUILTIN_FILTER_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/CDB_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/COMPATIBILITY_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/CONNECTION_CACHE_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/CONTENT_INSPECTION_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/DATABASE_README.html up to 1.1.1.10
external/ibm-public/postfix/dist/proto/DB_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/DEBUG_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/DSN_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/ETRN_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/FILTER_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/FORWARD_SECRECY_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/INSTALL.html up to 1.10
external/ibm-public/postfix/dist/proto/IPV6_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/LDAP_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/LINUX_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/LMDB_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/LOCAL_RECIPIENT_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/MAILDROP_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/MEMCACHE_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/MILTER_README.html up to 1.1.1.9
external/ibm-public/postfix/dist/proto/MULTI_INSTANCE_README.html up to 1.1.1.8
external/ibm-public/postfix/dist/proto/MYSQL_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/Makefile.in up to 1.1.1.7
external/ibm-public/postfix/dist/proto/NFS_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/OVERVIEW.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/PACKAGE_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/PCRE_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/PGSQL_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/POSTSCREEN_README.html up to 1.1.1.8
external/ibm-public/postfix/dist/proto/QSHAPE_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/RESTRICTION_CLASS_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/SASL_README.html up to 1.1.1.11
external/ibm-public/postfix/dist/proto/SCHEDULER_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/SMTPD_ACCESS_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/SMTPD_POLICY_README.html up to 1.1.1.7
external/ibm-public/postfix/dist/proto/SMTPD_PROXY_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/SMTPUTF8_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/SQLITE_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/STANDARD_CONFIGURATION_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/STRESS_README.html up to 1.1.1.7
external/ibm-public/postfix/dist/proto/TLS_LEGACY_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/TLS_README.html up to 1.14
external/ibm-public/postfix/dist/proto/TUNING_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/UUCP_README.html up to 1.1.1.3
external/ibm-public/postfix/dist/proto/VERP_README.html up to 1.1.1.5
external/ibm-public/postfix/dist/proto/VIRTUAL_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/XCLIENT_README.html up to 1.1.1.6
external/ibm-public/postfix/dist/proto/XFORWARD_README.html up to 1.1.1.4
external/ibm-public/postfix/dist/proto/access up to 1.1.1.8
external/ibm-public/postfix/dist/proto/aliases up to 1.1.1.6
external/ibm-public/postfix/dist/proto/canonical up to 1.1.1.5
external/ibm-public/postfix/dist/proto/cidr_table up to 1.1.1.6
external/ibm-public/postfix/dist/proto/generic up to 1.1.1.4
external/ibm-public/postfix/dist/proto/header_checks up to 1.1.1.7
external/ibm-public/postfix/dist/proto/ldap_table up to 1.1.1.7
external/ibm-public/postfix/dist/proto/lmdb_table up to 1.1.1.3
external/ibm-public/postfix/dist/proto/master up to 1.1.1.8
external/ibm-public/postfix/dist/proto/mysql_table up to 1.1.1.8
external/ibm-public/postfix/dist/proto/pcre_table up to 1.1.1.6
external/ibm-public/postfix/dist/proto/pgsql_table up to 1.1.1.8
external/ibm-public/postfix/dist/proto/postconf.html.prolog up to 1.1.1.5
external/ibm-public/postfix/dist/proto/postconf.man.prolog up to 1.1.1.4
external/ibm-public/postfix/dist/proto/postconf.proto up to 1.19
external/ibm-public/postfix/dist/proto/regexp_table up to 1.1.1.6
external/ibm-public/postfix/dist/proto/relocated up to 1.1.1.3
external/ibm-public/postfix/dist/proto/socketmap_table up to 1.1.1.3
external/ibm-public/postfix/dist/proto/sqlite_table up to 1.1.1.5
external/ibm-public/postfix/dist/proto/stop up to 1.1.1.7
external/ibm-public/postfix/dist/proto/tcp_table up to 1.1.1.4
external/ibm-public/postfix/dist/proto/transport up to 1.1.1.5
external/ibm-public/postfix/dist/proto/virtual up to 1.1.1.6
external/ibm-public/postfix/dist/src/anvil/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/anvil/anvil.c up to 1.4
external/ibm-public/postfix/dist/src/bounce/2template_test.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/bounce/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/bounce/bounce.c up to 1.4
external/ibm-public/postfix/dist/src/bounce/bounce_notify_util.c up to 1.4
external/ibm-public/postfix/dist/src/bounce/bounce_service.h up to 1.3
external/ibm-public/postfix/dist/src/bounce/bounce_template.c up to 1.4
external/ibm-public/postfix/dist/src/bounce/bounce_template.h up to 1.3
external/ibm-public/postfix/dist/src/bounce/bounce_templates.c up to 1.3
external/ibm-public/postfix/dist/src/bounce/template_test.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/cleanup/Makefile.in up to 1.1.1.9
external/ibm-public/postfix/dist/src/cleanup/cleanup.c up to 1.8
external/ibm-public/postfix/dist/src/cleanup/cleanup.h up to 1.10
external/ibm-public/postfix/dist/src/cleanup/cleanup_addr.c up to 1.3
external/ibm-public/postfix/dist/src/cleanup/cleanup_api.c up to 1.4
external/ibm-public/postfix/dist/src/cleanup/cleanup_body_edit.c up to 1.3
external/ibm-public/postfix/dist/src/cleanup/cleanup_envelope.c up to 1.5
external/ibm-public/postfix/dist/src/cleanup/cleanup_init.c up to 1.7
external/ibm-public/postfix/dist/src/cleanup/cleanup_map11.c up to 1.3
external/ibm-public/postfix/dist/src/cleanup/cleanup_map1n.c up to 1.4
external/ibm-public/postfix/dist/src/cleanup/cleanup_message.c up to 1.4
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.c up to 1.5
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13c up to 1.1.1.2
external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13d up to 1.1.1.2
external/ibm-public/postfix/dist/src/cleanup/cleanup_out.c up to 1.3
external/ibm-public/postfix/dist/src/cleanup/cleanup_out_recipient.c up to 1.4
external/ibm-public/postfix/dist/src/cleanup/cleanup_region.c up to 1.3
external/ibm-public/postfix/dist/src/cleanup/cleanup_state.c up to 1.4
external/ibm-public/postfix/dist/src/discard/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/discard/discard.c up to 1.3
external/ibm-public/postfix/dist/src/dns/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/dns/dns.h up to 1.6
external/ibm-public/postfix/dist/src/dns/dns_lookup.c up to 1.8
external/ibm-public/postfix/dist/src/dns/dns_rr.c up to 1.3
external/ibm-public/postfix/dist/src/dns/dns_rr_eq_sa.c up to 1.3
external/ibm-public/postfix/dist/src/dns/dns_rr_eq_sa.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/dns/dns_rr_eq_sa.ref up to 1.1.1.5
external/ibm-public/postfix/dist/src/dns/dns_rr_to_pa.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/dns/dns_rr_to_sa.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/dns/dns_sa_to_rr.c up to 1.3
external/ibm-public/postfix/dist/src/dns/dns_sa_to_rr.ref up to 1.1.1.5
external/ibm-public/postfix/dist/src/dns/dns_strrecord.c up to 1.3
external/ibm-public/postfix/dist/src/dns/dns_strtype.c up to 1.2
external/ibm-public/postfix/dist/src/dns/dnsbl_ttl_127.0.0.1_bind_ncache.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/dns/dnsbl_ttl_127.0.0.1_bind_plain.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/dns/dnsbl_ttl_127.0.0.2_bind_plain.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/dns/error.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/dns/mxonly_test.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/dns/no-a.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/dns/no-aaaa.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/dns/no-mx.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/dns/nullmx_test.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/dns/nxdomain_test.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/dns/test_dns_lookup.c up to 1.3
external/ibm-public/postfix/dist/src/dnsblog/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/dnsblog/dnsblog.c up to 1.4
external/ibm-public/postfix/dist/src/error/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/error/error.c up to 1.3
external/ibm-public/postfix/dist/src/flush/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/flush/flush.c up to 1.4
external/ibm-public/postfix/dist/src/fsstone/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/global/Makefile.in up to 1.1.1.10
external/ibm-public/postfix/dist/src/global/abounce.c up to 1.3
external/ibm-public/postfix/dist/src/global/anvil_clnt.c up to 1.4
external/ibm-public/postfix/dist/src/global/anvil_clnt.h up to 1.3
external/ibm-public/postfix/dist/src/global/been_here.c up to 1.4
external/ibm-public/postfix/dist/src/global/been_here.h up to 1.3
external/ibm-public/postfix/dist/src/global/bounce.c up to 1.3
external/ibm-public/postfix/dist/src/global/bounce_log.c up to 1.3
external/ibm-public/postfix/dist/src/global/cleanup_strerror.c up to 1.2
external/ibm-public/postfix/dist/src/global/cleanup_user.h up to 1.3
external/ibm-public/postfix/dist/src/global/clnt_stream.c up to 1.4
external/ibm-public/postfix/dist/src/global/clnt_stream.h up to 1.2
external/ibm-public/postfix/dist/src/global/db_common.c up to 1.3
external/ibm-public/postfix/dist/src/global/debug_peer.c up to 1.3
external/ibm-public/postfix/dist/src/global/defer.c up to 1.3
external/ibm-public/postfix/dist/src/global/deliver_pass.c up to 1.3
external/ibm-public/postfix/dist/src/global/deliver_request.c up to 1.3
external/ibm-public/postfix/dist/src/global/deliver_request.h up to 1.3
external/ibm-public/postfix/dist/src/global/delivered_hdr.c up to 1.3
external/ibm-public/postfix/dist/src/global/dict_ldap.c up to 1.5
external/ibm-public/postfix/dist/src/global/dict_memcache.c up to 1.3
external/ibm-public/postfix/dist/src/global/dict_mysql.c up to 1.4
external/ibm-public/postfix/dist/src/global/dict_pgsql.c up to 1.4
external/ibm-public/postfix/dist/src/global/dict_proxy.c up to 1.3
external/ibm-public/postfix/dist/src/global/dict_proxy.h up to 1.3
external/ibm-public/postfix/dist/src/global/dict_sqlite.c up to 1.4
external/ibm-public/postfix/dist/src/global/dsb_scan.c up to 1.3
external/ibm-public/postfix/dist/src/global/dsb_scan.h up to 1.2
external/ibm-public/postfix/dist/src/global/dsn_print.c up to 1.3
external/ibm-public/postfix/dist/src/global/dsn_print.h up to 1.2
external/ibm-public/postfix/dist/src/global/dynamicmaps.c up to 1.4
external/ibm-public/postfix/dist/src/global/ehlo_mask.c up to 1.3
external/ibm-public/postfix/dist/src/global/ehlo_mask.h up to 1.3
external/ibm-public/postfix/dist/src/global/flush_clnt.c up to 1.3
external/ibm-public/postfix/dist/src/global/haproxy_srvr.c up to 1.3
external/ibm-public/postfix/dist/src/global/haproxy_srvr.h up to 1.2
external/ibm-public/postfix/dist/src/global/header_body_checks.c up to 1.3
external/ibm-public/postfix/dist/src/global/header_body_checks.h up to 1.3
external/ibm-public/postfix/dist/src/global/log_adhoc.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_addr_crunch.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_addr_crunch.h up to 1.2
external/ibm-public/postfix/dist/src/global/mail_addr_find.c up to 1.4
external/ibm-public/postfix/dist/src/global/mail_addr_find.h up to 1.2
external/ibm-public/postfix/dist/src/global/mail_addr_map.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_addr_map.h up to 1.2
external/ibm-public/postfix/dist/src/global/mail_command_client.c up to 1.4
external/ibm-public/postfix/dist/src/global/mail_conf.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_conf.h up to 1.3
external/ibm-public/postfix/dist/src/global/mail_conf_int.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_conf_long.c up to 1.2
external/ibm-public/postfix/dist/src/global/mail_conf_nint.c up to 1.2
external/ibm-public/postfix/dist/src/global/mail_conf_time.c up to 1.4
external/ibm-public/postfix/dist/src/global/mail_copy.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_dict.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_error.c up to 1.2
external/ibm-public/postfix/dist/src/global/mail_params.c up to 1.5
external/ibm-public/postfix/dist/src/global/mail_params.h up to 1.19
external/ibm-public/postfix/dist/src/global/mail_parm_split.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_proto.h up to 1.5
external/ibm-public/postfix/dist/src/global/mail_queue.h up to 1.3
external/ibm-public/postfix/dist/src/global/mail_stream.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_task.c up to 1.3
external/ibm-public/postfix/dist/src/global/mail_version.h up to 1.6
external/ibm-public/postfix/dist/src/global/maps.c up to 1.4
external/ibm-public/postfix/dist/src/global/maps.h up to 1.2
external/ibm-public/postfix/dist/src/global/maps.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/global/memcache_proto.c up to 1.3
external/ibm-public/postfix/dist/src/global/mime_state.c up to 1.3
external/ibm-public/postfix/dist/src/global/mkmap_proxy.c up to 1.2
external/ibm-public/postfix/dist/src/global/msg_stats.h up to 1.2
external/ibm-public/postfix/dist/src/global/msg_stats_print.c up to 1.3
external/ibm-public/postfix/dist/src/global/msg_stats_scan.c up to 1.3
external/ibm-public/postfix/dist/src/global/namadr_list.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/global/namadr_list.ref up to 1.1.1.5
external/ibm-public/postfix/dist/src/global/off_cvt.c up to 1.2
external/ibm-public/postfix/dist/src/global/opened.c up to 1.2
external/ibm-public/postfix/dist/src/global/post_mail.c up to 1.4
external/ibm-public/postfix/dist/src/global/post_mail.h up to 1.3
external/ibm-public/postfix/dist/src/global/quote_822_local.c up to 1.3
external/ibm-public/postfix/dist/src/global/quote_822_local.h up to 1.2
external/ibm-public/postfix/dist/src/global/quote_flags.h up to 1.2
external/ibm-public/postfix/dist/src/global/rcpt_buf.c up to 1.4
external/ibm-public/postfix/dist/src/global/rcpt_buf.h up to 1.2
external/ibm-public/postfix/dist/src/global/rcpt_print.c up to 1.3
external/ibm-public/postfix/dist/src/global/rcpt_print.h up to 1.2
external/ibm-public/postfix/dist/src/global/rec_type.h up to 1.3
external/ibm-public/postfix/dist/src/global/record.c up to 1.4
external/ibm-public/postfix/dist/src/global/resolve_clnt.c up to 1.4
external/ibm-public/postfix/dist/src/global/resolve_clnt.h up to 1.2
external/ibm-public/postfix/dist/src/global/rewrite_clnt.c up to 1.3
external/ibm-public/postfix/dist/src/global/scache.h up to 1.3
external/ibm-public/postfix/dist/src/global/scache_clnt.c up to 1.3
external/ibm-public/postfix/dist/src/global/sent.c up to 1.3
external/ibm-public/postfix/dist/src/global/server_acl.c up to 1.3
external/ibm-public/postfix/dist/src/global/server_acl.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/global/server_acl.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/global/smtp_reply_footer.c up to 1.3
external/ibm-public/postfix/dist/src/global/smtp_stream.c up to 1.5
external/ibm-public/postfix/dist/src/global/smtp_stream.h up to 1.4
external/ibm-public/postfix/dist/src/global/smtputf8.h up to 1.3
external/ibm-public/postfix/dist/src/global/split_addr.c up to 1.3
external/ibm-public/postfix/dist/src/global/split_addr.h up to 1.2
external/ibm-public/postfix/dist/src/global/strip_addr.c up to 1.4
external/ibm-public/postfix/dist/src/global/strip_addr.h up to 1.2
external/ibm-public/postfix/dist/src/global/strip_addr.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/global/trace.c up to 1.3
external/ibm-public/postfix/dist/src/global/uxtext.c up to 1.3
external/ibm-public/postfix/dist/src/global/verify.c up to 1.4
external/ibm-public/postfix/dist/src/global/verify_clnt.c up to 1.3
external/ibm-public/postfix/dist/src/global/verify_sender_addr.c up to 1.4
external/ibm-public/postfix/dist/src/global/xtext.c up to 1.3
external/ibm-public/postfix/dist/src/local/Makefile.in up to 1.1.1.8
external/ibm-public/postfix/dist/src/local/alias.c up to 1.3
external/ibm-public/postfix/dist/src/local/forward.c up to 1.4
external/ibm-public/postfix/dist/src/local/local.c up to 1.4
external/ibm-public/postfix/dist/src/local/local_expand.c up to 1.3
external/ibm-public/postfix/dist/src/local/mailbox.c up to 1.4
external/ibm-public/postfix/dist/src/local/unknown.c up to 1.8
external/ibm-public/postfix/dist/src/master/Makefile.in up to 1.1.1.7
external/ibm-public/postfix/dist/src/master/event_server.c up to 1.4
external/ibm-public/postfix/dist/src/master/mail_server.h up to 1.4
external/ibm-public/postfix/dist/src/master/master.c up to 1.4
external/ibm-public/postfix/dist/src/master/master.h up to 1.2
external/ibm-public/postfix/dist/src/master/master_conf.c up to 1.2
external/ibm-public/postfix/dist/src/master/master_ent.c up to 1.4
external/ibm-public/postfix/dist/src/master/master_listen.c up to 1.2
external/ibm-public/postfix/dist/src/master/master_monitor.c up to 1.3
external/ibm-public/postfix/dist/src/master/master_proto.h up to 1.2
external/ibm-public/postfix/dist/src/master/master_sig.c up to 1.3
external/ibm-public/postfix/dist/src/master/master_spawn.c up to 1.3
external/ibm-public/postfix/dist/src/master/master_vars.c up to 1.3
external/ibm-public/postfix/dist/src/master/master_wakeup.c up to 1.3
external/ibm-public/postfix/dist/src/master/multi_server.c up to 1.4
external/ibm-public/postfix/dist/src/master/single_server.c up to 1.4
external/ibm-public/postfix/dist/src/master/trigger_server.c up to 1.4
external/ibm-public/postfix/dist/src/milter/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/milter/milter.c up to 1.5
external/ibm-public/postfix/dist/src/milter/milter.h up to 1.4
external/ibm-public/postfix/dist/src/milter/milter8.c up to 1.5
external/ibm-public/postfix/dist/src/milter/milter_macros.c up to 1.3
external/ibm-public/postfix/dist/src/milter/test-milter.c up to 1.3
external/ibm-public/postfix/dist/src/oqmgr/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/oqmgr/qmgr.c up to 1.3
external/ibm-public/postfix/dist/src/oqmgr/qmgr.h up to 1.3
external/ibm-public/postfix/dist/src/oqmgr/qmgr_active.c up to 1.3
external/ibm-public/postfix/dist/src/oqmgr/qmgr_deliver.c up to 1.3
external/ibm-public/postfix/dist/src/oqmgr/qmgr_entry.c up to 1.3
external/ibm-public/postfix/dist/src/oqmgr/qmgr_error.c up to 1.2
external/ibm-public/postfix/dist/src/oqmgr/qmgr_feedback.c up to 1.2
external/ibm-public/postfix/dist/src/oqmgr/qmgr_message.c up to 1.4
external/ibm-public/postfix/dist/src/pickup/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/pickup/pickup.c up to 1.4
external/ibm-public/postfix/dist/src/pipe/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/pipe/pipe.c up to 1.4
external/ibm-public/postfix/dist/src/postalias/Makefile.in up to 1.1.1.6
external/ibm-public/postfix/dist/src/postalias/fail_test.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/postalias/fail_test.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postalias/postalias.c up to 1.5
external/ibm-public/postfix/dist/src/postcat/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/postcat/postcat.c up to 1.4
external/ibm-public/postfix/dist/src/postconf/Makefile.in up to 1.1.1.11
external/ibm-public/postfix/dist/src/postconf/extract.awk up to 1.1.1.6
external/ibm-public/postfix/dist/src/postconf/install_vars.h up to 1.2
external/ibm-public/postfix/dist/src/postconf/postconf.c up to 1.4
external/ibm-public/postfix/dist/src/postconf/postconf.h up to 1.4
external/ibm-public/postfix/dist/src/postconf/postconf_builtin.c up to 1.4
external/ibm-public/postfix/dist/src/postconf/postconf_dbms.c up to 1.5
external/ibm-public/postfix/dist/src/postconf/postconf_edit.c up to 1.3
external/ibm-public/postfix/dist/src/postconf/postconf_lookup.c up to 1.4
external/ibm-public/postfix/dist/src/postconf/postconf_main.c up to 1.4
external/ibm-public/postfix/dist/src/postconf/postconf_master.c up to 1.8
external/ibm-public/postfix/dist/src/postconf/postconf_misc.c up to 1.3
external/ibm-public/postfix/dist/src/postconf/postconf_user.c up to 1.4
external/ibm-public/postfix/dist/src/postconf/test28.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/postconf/test29.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/postconf/test34.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postconf/test35.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postconf/test40.ref up to 1.1.1.4
external/ibm-public/postfix/dist/src/postconf/test41.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postconf/test42.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postconf/test43.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postconf/test44.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postconf/test58.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/postconf/test59.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/postdrop/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/postdrop/postdrop.c up to 1.4
external/ibm-public/postfix/dist/src/postfix/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/postfix/postfix.c up to 1.6
external/ibm-public/postfix/dist/src/postkick/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/postkick/postkick.c up to 1.4
external/ibm-public/postfix/dist/src/postlock/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/postlock/postlock.c up to 1.4
external/ibm-public/postfix/dist/src/postlog/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/postlog/postlog.c up to 1.5
external/ibm-public/postfix/dist/src/postmap/Makefile.in up to 1.1.1.7
external/ibm-public/postfix/dist/src/postmap/fail_test.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/postmap/fail_test.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/postmap/postmap.c up to 1.5
external/ibm-public/postfix/dist/src/postmulti/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/postmulti/postmulti.c up to 1.4
external/ibm-public/postfix/dist/src/postqueue/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/postqueue/postqueue.c up to 1.5
external/ibm-public/postfix/dist/src/postqueue/showq_compat.c up to 1.4
external/ibm-public/postfix/dist/src/postqueue/showq_json.c up to 1.4
external/ibm-public/postfix/dist/src/postscreen/Makefile.in up to 1.1.1.7
external/ibm-public/postfix/dist/src/postscreen/postscreen.c up to 1.5
external/ibm-public/postfix/dist/src/postscreen/postscreen.h up to 1.4
external/ibm-public/postfix/dist/src/postscreen/postscreen_dnsbl.c up to 1.4
external/ibm-public/postfix/dist/src/postscreen/postscreen_early.c up to 1.4
external/ibm-public/postfix/dist/src/postscreen/postscreen_endpt.c up to 1.4
external/ibm-public/postfix/dist/src/postscreen/postscreen_haproxy.c up to 1.3
external/ibm-public/postfix/dist/src/postscreen/postscreen_haproxy.h up to 1.2
external/ibm-public/postfix/dist/src/postscreen/postscreen_misc.c up to 1.4
external/ibm-public/postfix/dist/src/postscreen/postscreen_send.c up to 1.3
external/ibm-public/postfix/dist/src/postscreen/postscreen_smtpd.c up to 1.5
external/ibm-public/postfix/dist/src/postscreen/postscreen_starttls.c up to 1.4
external/ibm-public/postfix/dist/src/postscreen/postscreen_state.c up to 1.4
external/ibm-public/postfix/dist/src/postscreen/postscreen_tests.c up to 1.4
external/ibm-public/postfix/dist/src/postsuper/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/postsuper/postsuper.c up to 1.4
external/ibm-public/postfix/dist/src/posttls-finger/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/posttls-finger/posttls-finger.c up to 1.5
external/ibm-public/postfix/dist/src/proxymap/Makefile.in up to 1.1.1.6
external/ibm-public/postfix/dist/src/proxymap/proxymap.c up to 1.4
external/ibm-public/postfix/dist/src/qmgr/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/qmgr/qmgr.c up to 1.3
external/ibm-public/postfix/dist/src/qmgr/qmgr.h up to 1.3
external/ibm-public/postfix/dist/src/qmgr/qmgr_active.c up to 1.3
external/ibm-public/postfix/dist/src/qmgr/qmgr_deliver.c up to 1.3
external/ibm-public/postfix/dist/src/qmgr/qmgr_entry.c up to 1.3
external/ibm-public/postfix/dist/src/qmgr/qmgr_error.c up to 1.2
external/ibm-public/postfix/dist/src/qmgr/qmgr_feedback.c up to 1.2
external/ibm-public/postfix/dist/src/qmgr/qmgr_message.c up to 1.4
external/ibm-public/postfix/dist/src/qmqpd/Makefile.in up to 1.1.1.6
external/ibm-public/postfix/dist/src/qmqpd/qmqpd.c up to 1.4
external/ibm-public/postfix/dist/src/qmqpd/qmqpd_peer.c up to 1.3
external/ibm-public/postfix/dist/src/scache/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/scache/scache.c up to 1.4
external/ibm-public/postfix/dist/src/sendmail/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/sendmail/sendmail.c up to 1.4
external/ibm-public/postfix/dist/src/showq/Makefile.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/showq/showq.c up to 1.5
external/ibm-public/postfix/dist/src/smtp/Makefile.in up to 1.1.1.10
external/ibm-public/postfix/dist/src/smtp/lmtp_params.c up to 1.5
external/ibm-public/postfix/dist/src/smtp/smtp.c up to 1.13
external/ibm-public/postfix/dist/src/smtp/smtp.h up to 1.5
external/ibm-public/postfix/dist/src/smtp/smtp_addr.c up to 1.5
external/ibm-public/postfix/dist/src/smtp/smtp_addr.h up to 1.3
external/ibm-public/postfix/dist/src/smtp/smtp_chat.c up to 1.4
external/ibm-public/postfix/dist/src/smtp/smtp_connect.c up to 1.5
external/ibm-public/postfix/dist/src/smtp/smtp_key.c up to 1.3
external/ibm-public/postfix/dist/src/smtp/smtp_map11.c up to 1.3
external/ibm-public/postfix/dist/src/smtp/smtp_map11.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtp/smtp_params.c up to 1.5
external/ibm-public/postfix/dist/src/smtp/smtp_proto.c up to 1.5
external/ibm-public/postfix/dist/src/smtp/smtp_rcpt.c up to 1.3
external/ibm-public/postfix/dist/src/smtp/smtp_reuse.c up to 1.4
external/ibm-public/postfix/dist/src/smtp/smtp_sasl_auth_cache.c up to 1.3
external/ibm-public/postfix/dist/src/smtp/smtp_sasl_glue.c up to 1.3
external/ibm-public/postfix/dist/src/smtp/smtp_sasl_proto.c up to 1.3
external/ibm-public/postfix/dist/src/smtp/smtp_session.c up to 1.5
external/ibm-public/postfix/dist/src/smtp/smtp_state.c up to 1.3
external/ibm-public/postfix/dist/src/smtp/smtp_tls_policy.c up to 1.4
external/ibm-public/postfix/dist/src/smtp/smtp_trouble.c up to 1.3
external/ibm-public/postfix/dist/src/smtpd/Makefile.in up to 1.1.1.11
external/ibm-public/postfix/dist/src/smtpd/pfilter.c up to 1.2 (+patch)
external/ibm-public/postfix/dist/src/smtpd/smtpd.c up to 1.20
external/ibm-public/postfix/dist/src/smtpd/smtpd.h up to 1.5
external/ibm-public/postfix/dist/src/smtpd/smtpd_acl.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_acl.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_chat.c up to 1.4
external/ibm-public/postfix/dist/src/smtpd/smtpd_chat.h up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_check.c up to 1.6
external/ibm-public/postfix/dist/src/smtpd/smtpd_check.h up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_check.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_check.in2 up to 1.1.1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_check.in3 up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_check.ref up to 1.1.1.5
external/ibm-public/postfix/dist/src/smtpd/smtpd_check.ref2 up to 1.1.1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_check_backup.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_check_backup.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_check_dsn.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_check_dsn.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_dns_filter.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_dnswl.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/smtpd/smtpd_dnswl.ref up to 1.1.1.4
external/ibm-public/postfix/dist/src/smtpd/smtpd_error.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_error.ref up to 1.1.1.4
external/ibm-public/postfix/dist/src/smtpd/smtpd_exp.in up to 1.1.1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_exp.ref up to 1.1.1.5
external/ibm-public/postfix/dist/src/smtpd/smtpd_expand.h up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_haproxy.c up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_milter.c up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_nullmx.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_nullmx.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/smtpd/smtpd_peer.c up to 1.5
external/ibm-public/postfix/dist/src/smtpd/smtpd_proxy.c up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_resolve.c up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_resolve.h up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_sasl_glue.c up to 1.5
external/ibm-public/postfix/dist/src/smtpd/smtpd_sasl_proto.c up to 1.3
external/ibm-public/postfix/dist/src/smtpd/smtpd_server.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/smtpd/smtpd_server.ref up to 1.1.1.4
external/ibm-public/postfix/dist/src/smtpd/smtpd_state.c up to 1.2
external/ibm-public/postfix/dist/src/smtpstone/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/smtpstone/smtp-sink.c up to 1.3
external/ibm-public/postfix/dist/src/smtpstone/smtp-source.c up to 1.3
external/ibm-public/postfix/dist/src/spawn/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/spawn/spawn.c up to 1.4
external/ibm-public/postfix/dist/src/tls/Makefile.in up to 1.1.1.10
external/ibm-public/postfix/dist/src/tls/tls.h up to 1.5
external/ibm-public/postfix/dist/src/tls/tls_bio_ops.c up to 1.1.1.6
external/ibm-public/postfix/dist/src/tls/tls_certkey.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_client.c up to 1.13
external/ibm-public/postfix/dist/src/tls/tls_dane.c up to 1.5
external/ibm-public/postfix/dist/src/tls/tls_dh.c up to 1.5
external/ibm-public/postfix/dist/src/tls/tls_fprint.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_mgr.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_misc.c up to 1.5
external/ibm-public/postfix/dist/src/tls/tls_proxy.h up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_proxy_clnt.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_rsa.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_scache.c up to 1.4
external/ibm-public/postfix/dist/src/tls/tls_server.c up to 1.12
external/ibm-public/postfix/dist/src/tls/tls_session.c up to 1.3
external/ibm-public/postfix/dist/src/tls/tls_verify.c up to 1.4
external/ibm-public/postfix/dist/src/tlsmgr/Makefile.in up to 1.1.1.6
external/ibm-public/postfix/dist/src/tlsmgr/tlsmgr.c up to 1.4
external/ibm-public/postfix/dist/src/tlsproxy/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy.c up to 1.6
external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy.h up to 1.2
external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy_state.c up to 1.3
external/ibm-public/postfix/dist/src/trivial-rewrite/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/trivial-rewrite/resolve.c up to 1.4
external/ibm-public/postfix/dist/src/trivial-rewrite/rewrite.c up to 1.3
external/ibm-public/postfix/dist/src/trivial-rewrite/transport.c up to 1.4
external/ibm-public/postfix/dist/src/trivial-rewrite/trivial-rewrite.c up to 1.4
external/ibm-public/postfix/dist/src/trivial-rewrite/trivial-rewrite.h up to 1.3
external/ibm-public/postfix/dist/src/util/Makefile.in up to 1.1.1.11
external/ibm-public/postfix/dist/src/util/allascii.c up to 1.3
external/ibm-public/postfix/dist/src/util/alldig.c up to 1.2
external/ibm-public/postfix/dist/src/util/argv.c up to 1.4
external/ibm-public/postfix/dist/src/util/argv.h up to 1.4
external/ibm-public/postfix/dist/src/util/attr.h up to 1.5
external/ibm-public/postfix/dist/src/util/attr_clnt.c up to 1.3
external/ibm-public/postfix/dist/src/util/attr_clnt.h up to 1.3
external/ibm-public/postfix/dist/src/util/attr_print0.c up to 1.3
external/ibm-public/postfix/dist/src/util/attr_print64.c up to 1.3
external/ibm-public/postfix/dist/src/util/attr_print_plain.c up to 1.3
external/ibm-public/postfix/dist/src/util/attr_scan0.c up to 1.3
external/ibm-public/postfix/dist/src/util/attr_scan0.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/util/attr_scan64.c up to 1.3
external/ibm-public/postfix/dist/src/util/attr_scan64.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/util/attr_scan_plain.c up to 1.3
external/ibm-public/postfix/dist/src/util/attr_scan_plain.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/util/auto_clnt.c up to 1.4
external/ibm-public/postfix/dist/src/util/auto_clnt.h up to 1.2
external/ibm-public/postfix/dist/src/util/base32_code.h up to 1.3
external/ibm-public/postfix/dist/src/util/base64_code.h up to 1.3
external/ibm-public/postfix/dist/src/util/binhash.c up to 1.3
external/ibm-public/postfix/dist/src/util/binhash.h up to 1.3
external/ibm-public/postfix/dist/src/util/casefold.c up to 1.3
external/ibm-public/postfix/dist/src/util/check_arg.h up to 1.3
external/ibm-public/postfix/dist/src/util/cidr_match.c up to 1.4
external/ibm-public/postfix/dist/src/util/cidr_match.h up to 1.2
external/ibm-public/postfix/dist/src/util/clean_env.c up to 1.3
external/ibm-public/postfix/dist/src/util/clean_env.h up to 1.2
external/ibm-public/postfix/dist/src/util/connect.h up to 1.2
external/ibm-public/postfix/dist/src/util/dict.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict.h up to 1.5
external/ibm-public/postfix/dist/src/util/dict_alloc.c up to 1.3
external/ibm-public/postfix/dist/src/util/dict_cache.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict_cdb.c up to 1.3
external/ibm-public/postfix/dist/src/util/dict_cdb.h up to 1.2
external/ibm-public/postfix/dist/src/util/dict_cidr.c up to 1.5
external/ibm-public/postfix/dist/src/util/dict_cidr.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/dict_cidr.map up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/dict_cidr.ref up to 1.1.1.4
external/ibm-public/postfix/dist/src/util/dict_db.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict_db.h up to 1.4
external/ibm-public/postfix/dist/src/util/dict_dbm.h up to 1.2
external/ibm-public/postfix/dist/src/util/dict_fail.c up to 1.2
external/ibm-public/postfix/dist/src/util/dict_fail.h up to 1.2
external/ibm-public/postfix/dist/src/util/dict_inline.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict_lmdb.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict_lmdb.h up to 1.3
external/ibm-public/postfix/dist/src/util/dict_open.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict_pcre.c up to 1.5
external/ibm-public/postfix/dist/src/util/dict_pcre.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/dict_pcre.map up to 1.1.1.3
external/ibm-public/postfix/dist/src/util/dict_pcre.ref up to 1.1.1.4
external/ibm-public/postfix/dist/src/util/dict_random.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict_random.h up to 1.3
external/ibm-public/postfix/dist/src/util/dict_regexp.c up to 1.5
external/ibm-public/postfix/dist/src/util/dict_regexp.map up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/dict_regexp.ref up to 1.1.1.3
external/ibm-public/postfix/dist/src/util/dict_sdbm.h up to 1.2
external/ibm-public/postfix/dist/src/util/dict_static.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict_thash.c up to 1.4
external/ibm-public/postfix/dist/src/util/dict_thash.map up to 1.1.1.3
external/ibm-public/postfix/dist/src/util/dict_union.c up to 1.3
external/ibm-public/postfix/dist/src/util/dict_utf8.c up to 1.3
external/ibm-public/postfix/dist/src/util/dict_utf8_test.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/dup2_pass_on_exec.c up to 1.2
external/ibm-public/postfix/dist/src/util/edit_file.c up to 1.4
external/ibm-public/postfix/dist/src/util/edit_file.h up to 1.3
external/ibm-public/postfix/dist/src/util/extpar.c up to 1.4
external/ibm-public/postfix/dist/src/util/find_inet.c up to 1.3
external/ibm-public/postfix/dist/src/util/gccw.c up to 1.2
external/ibm-public/postfix/dist/src/util/hex_code.c up to 1.3
external/ibm-public/postfix/dist/src/util/hex_code.h up to 1.4
external/ibm-public/postfix/dist/src/util/hex_quote.c up to 1.2
external/ibm-public/postfix/dist/src/util/host_port.h up to 1.3
external/ibm-public/postfix/dist/src/util/htable.c up to 1.4
external/ibm-public/postfix/dist/src/util/inet_addr_host.c up to 1.3
external/ibm-public/postfix/dist/src/util/inet_addr_list.in up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/inet_addr_list.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/inet_connect.c up to 1.3
external/ibm-public/postfix/dist/src/util/inet_listen.c up to 1.3
external/ibm-public/postfix/dist/src/util/inet_proto.c up to 1.4
external/ibm-public/postfix/dist/src/util/inet_proto.h up to 1.2
external/ibm-public/postfix/dist/src/util/killme_after.c up to 1.2
external/ibm-public/postfix/dist/src/util/listen.h up to 1.3
external/ibm-public/postfix/dist/src/util/load_lib.c up to 1.3
external/ibm-public/postfix/dist/src/util/lstat_as.h up to 1.3
external/ibm-public/postfix/dist/src/util/mac_expand.c up to 1.4
external/ibm-public/postfix/dist/src/util/mac_expand.h up to 1.4
external/ibm-public/postfix/dist/src/util/mac_expand.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/util/mac_expand.ref up to 1.1.1.4
external/ibm-public/postfix/dist/src/util/mac_parse.h up to 1.3
external/ibm-public/postfix/dist/src/util/make_dirs.c up to 1.2
external/ibm-public/postfix/dist/src/util/match_list.c up to 1.3
external/ibm-public/postfix/dist/src/util/match_ops.c up to 1.3
external/ibm-public/postfix/dist/src/util/midna_domain.c up to 1.4
external/ibm-public/postfix/dist/src/util/midna_domain.h up to 1.4
external/ibm-public/postfix/dist/src/util/midna_domain_test.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/msg_output.c up to 1.4
external/ibm-public/postfix/dist/src/util/msg_output.h up to 1.3
external/ibm-public/postfix/dist/src/util/msg_syslog.c up to 1.2
external/ibm-public/postfix/dist/src/util/msg_syslog.h up to 1.3
external/ibm-public/postfix/dist/src/util/mvect.c up to 1.3
external/ibm-public/postfix/dist/src/util/myaddrinfo.c up to 1.3
external/ibm-public/postfix/dist/src/util/myaddrinfo.h up to 1.3
external/ibm-public/postfix/dist/src/util/myaddrinfo.ref up to 1.1.1.5
external/ibm-public/postfix/dist/src/util/myaddrinfo4.ref up to 1.1.1.2
external/ibm-public/postfix/dist/src/util/myflock.c up to 1.3
external/ibm-public/postfix/dist/src/util/myflock.h up to 1.3
external/ibm-public/postfix/dist/src/util/mymalloc.c up to 1.4
external/ibm-public/postfix/dist/src/util/mymalloc.h up to 1.4
external/ibm-public/postfix/dist/src/util/mystrtok.c up to 1.4
external/ibm-public/postfix/dist/src/util/name_mask.c up to 1.3
external/ibm-public/postfix/dist/src/util/nbbio.c up to 1.3
external/ibm-public/postfix/dist/src/util/netstring.c up to 1.3
external/ibm-public/postfix/dist/src/util/peekfd.c up to 1.3
external/ibm-public/postfix/dist/src/util/printable.c up to 1.3
external/ibm-public/postfix/dist/src/util/recv_pass_attr.c up to 1.3
external/ibm-public/postfix/dist/src/util/sane_fsops.h up to 1.3
external/ibm-public/postfix/dist/src/util/sane_link.c up to 1.2
external/ibm-public/postfix/dist/src/util/sane_rename.c up to 1.2
external/ibm-public/postfix/dist/src/util/sane_socketpair.h up to 1.3
external/ibm-public/postfix/dist/src/util/slmdb.c up to 1.4
external/ibm-public/postfix/dist/src/util/sock_addr.c up to 1.3
external/ibm-public/postfix/dist/src/util/sock_addr.h up to 1.2
external/ibm-public/postfix/dist/src/util/split_nameval.c up to 1.2
external/ibm-public/postfix/dist/src/util/stat_as.h up to 1.3
external/ibm-public/postfix/dist/src/util/stringops.h up to 1.5
external/ibm-public/postfix/dist/src/util/sys_compat.c up to 1.3
external/ibm-public/postfix/dist/src/util/sys_defs.h up to 1.14
external/ibm-public/postfix/dist/src/util/timed_wait.h up to 1.3
external/ibm-public/postfix/dist/src/util/unix_pass_fd_fix.c up to 1.2
external/ibm-public/postfix/dist/src/util/unix_send_fd.c up to 1.8
external/ibm-public/postfix/dist/src/util/unsafe.c up to 1.2
external/ibm-public/postfix/dist/src/util/valid_hostname.c up to 1.3
external/ibm-public/postfix/dist/src/util/valid_hostname.h up to 1.2
external/ibm-public/postfix/dist/src/util/vbuf.c up to 1.3
external/ibm-public/postfix/dist/src/util/vbuf_print.c up to 1.4
external/ibm-public/postfix/dist/src/util/vstream.c up to 1.4
external/ibm-public/postfix/dist/src/util/vstream.h up to 1.4
external/ibm-public/postfix/dist/src/util/vstream_tweak.c up to 1.3
external/ibm-public/postfix/dist/src/util/vstring.c up to 1.4
external/ibm-public/postfix/dist/src/util/vstring.h up to 1.4
external/ibm-public/postfix/dist/src/util/vstring_vstream.c up to 1.2
external/ibm-public/postfix/dist/src/util/vstring_vstream.h up to 1.3
external/ibm-public/postfix/dist/src/util/watchdog.c up to 1.3
external/ibm-public/postfix/dist/src/verify/Makefile.in up to 1.1.1.6
external/ibm-public/postfix/dist/src/verify/verify.c up to 1.4
external/ibm-public/postfix/dist/src/virtual/Makefile.in up to 1.1.1.5
external/ibm-public/postfix/dist/src/virtual/mailbox.c up to 1.3
external/ibm-public/postfix/dist/src/virtual/virtual.c up to 1.4
external/ibm-public/postfix/dist/src/xsasl/Makefile.in up to 1.1.1.4
external/ibm-public/postfix/dist/src/xsasl/xsasl.h up to 1.3
external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_client.c up to 1.3
external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_server.c up to 1.4
external/ibm-public/postfix/dist/src/xsasl/xsasl_dovecot_server.c up to 1.4
external/ibm-public/postfix/dist/src/xsasl/xsasl_saslc_client.c up to 1.2
external/ibm-public/postfix/dist/src/xsasl/xsasl_server.c up to 1.2
external/ibm-public/postfix/lib/dns/Makefile up to 1.4
external/ibm-public/postfix/lib/global/Makefile up to 1.10
external/ibm-public/postfix/lib/masterlib/Makefile up to 1.3
external/ibm-public/postfix/lib/milter/Makefile up to 1.2
external/ibm-public/postfix/lib/tls/Makefile up to 1.4
external/ibm-public/postfix/lib/util/Makefile up to 1.11
external/ibm-public/postfix/lib/xsasl/Makefile up to 1.3
external/ibm-public/postfix/libexec/smtp/Makefile up to 1.4
external/ibm-public/postfix/libexec/smtpd/Makefile up to 1.9 (+patch)
external/ibm-public/postfix/libexec/tlsproxy/Makefile up to 1.2
external/ibm-public/postfix/sbin/postconf/Makefile up to 1.9
doc/3RDPARTY (apply patch)
Update Postfix to 3.8.4.
@
text
@d4 1
a4 2
d13 1
a13 1
smtp [generic Postfix daemon options] [flags=DORX]
d44 1
a44 3
The Postfix SMTP+LMTP client supports multiple destinations separated
by comma or whitespace (Postfix 3.5 and later). SMTP destinations have
the following form:
d66 1
a66 3
The Postfix SMTP+LMTP client supports multiple destinations separated
by comma or whitespace (Postfix 3.5 and later). LMTP destinations have
the following form:
a86 46
SINGLE-RECIPIENT DELIVERY
By default, the Postfix SMTP+LMTP client delivers mail to multiple
recipients per delivery request. This is undesirable when prepending a
Delivered-to: or X-Original-To: message header. To prevent Postfix from
sending multiple recipients per delivery request, specify
transport_destination_recipient_limit = 1
in the Postfix main.cf file, where transport is the name in the first
column of the Postfix master.cf entry for this mail delivery service.
COMMAND ATTRIBUTE SYNTAX
flags=DORX (optional)
Optional message processing flags.
D Prepend a "Delivered-To: recipient" message header with
the envelope recipient address. Note: for this to work,
the transport_destination_recipient_limit must be 1 (see
SINGLE-RECIPIENT DELIVERY above for details).
The D flag also enforces loop detection: if a message
already contains a Delivered-To: header with the same
recipient address, then the message is returned as unde-
liverable. The address comparison is case insensitive.
This feature is available as of Postfix 3.5.
O Prepend an "X-Original-To: recipient" message header with
the recipient address as given to Postfix. Note: for this
to work, the transport_destination_recipient_limit must
be 1 (see SINGLE-RECIPIENT DELIVERY above for details).
This feature is available as of Postfix 3.5.
R Prepend a "Return-Path: <sender>" message header with the
envelope sender address.
This feature is available as of Postfix 3.5.
X Indicates that the delivery is final. This flag affects
the status reported in "success" DSN (delivery status
notification) messages, and changes it from "relayed"
into "delivered".
This feature is available as of Postfix 3.5.
d88 3
a90 4
The SMTP+LMTP client is moderately security-sensitive. It
talks to SMTP or LMTP servers and to DNS servers on the
network. The SMTP+LMTP client can be run chrooted at fixed
low privilege.
d93 20
a112 21
RFC 821 (SMTP protocol)
RFC 822 (ARPA Internet Text Messages)
RFC 1651 (SMTP service extensions)
RFC 1652 (8bit-MIME transport)
RFC 1870 (Message Size Declaration)
RFC 2033 (LMTP protocol)
RFC 2034 (SMTP Enhanced Error Codes)
RFC 2045 (MIME: Format of Internet Message Bodies)
RFC 2046 (MIME: Media Types)
RFC 2554 (AUTH command)
RFC 2821 (SMTP protocol)
RFC 2782 (SRV resource records)
RFC 2920 (SMTP Pipelining)
RFC 3207 (STARTTLS command)
RFC 3461 (SMTP DSN Extension)
RFC 3463 (Enhanced Status Codes)
RFC 4954 (AUTH command)
RFC 5321 (SMTP protocol)
RFC 6531 (Internationalized SMTP)
RFC 6533 (Internationalized Delivery Status Notifications)
RFC 7672 (SMTP security via opportunistic DANE TLS)
d115 3
a117 3
Problems and transactions are logged to syslogd(8) or postlogd(8).
Corrupted message files are marked so that the queue manager can move
them to the corrupt queue for further inspection.
d119 1
a119 1
Depending on the setting of the notify_classes parameter, the postmas-
d123 7
a129 5
SMTP and LMTP connection reuse for TLS (without closing the SMTP or
LMTP connection) is not supported before Postfix 3.4.
SMTP and LMTP connection reuse assumes that SASL credentials are valid
for all destinations that map onto the same IP address and TCP port.
d132 3
a134 3
Before Postfix version 2.3, the LMTP client is a separate program that
implements only a subset of the functionality available with SMTP:
there is no support for TLS, and connections are cached in-process,
d138 1
a138 1
eter for the equivalent LMTP feature. This document describes only
d141 1
a141 1
Changes to main.cf are picked up automatically, as smtp(8) processes
d145 1
a145 1
The text below provides only a parameter summary. See postconf(5) for
d166 2
a167 2
How long the Postfix SMTP client pauses before sending
".<CR><LF>" in order to work around the PIX firewall
d176 1
a176 1
A list that specifies zero or more workarounds for CISCO PIX
d180 1
a180 1
Lookup tables, indexed by the remote SMTP server address, with
d184 2
a185 2
Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO
commands as required by RFC 5321.
d188 1
a188 1
A mechanism to transform replies from remote SMTP servers one
d200 1
a200 1
Skip SMTP servers that greet with a 4XX status code (go away,
d206 2
a207 2
Lookup tables, indexed by the remote SMTP server address, with
case insensitive lists of EHLO keywords (pipelining, starttls,
d212 1
a212 1
A case insensitive list of EHLO keywords (pipelining, starttls,
d217 3
a219 3
Optional lookup tables that perform address rewriting in the
Postfix SMTP client, typically to transform a locally valid
address into a globally valid address when sending mail across
d225 3
a227 3
When the remote SMTP servername is a DNS CNAME, replace the
servername with the result from CNAME expansion for the purpose
of logging, SASL password lookup, TLS policy decisions, or TLS
d233 2
a234 2
Lookup tables, indexed by the remote LMTP server address, with
case insensitive lists of LHLO keywords (pipelining, starttls,
d239 1
a239 1
A case insensitive list of LHLO keywords (pipelining, starttls,
d246 3
a248 3
When authenticating to a remote SMTP or LMTP server with the
default setting "no", send no SASL authoriZation ID (authzid);
send only the SASL authentiCation ID (authcid) plus the auth-
d254 1
a254 1
Restricted header_checks(5) tables for the Postfix SMTP client.
d257 1
a257 1
Restricted mime_header_checks(5) tables for the Postfix SMTP
d261 1
a261 1
Restricted nested_header_checks(5) tables for the Postfix SMTP
d270 1
a270 1
An optional workaround for routers that break TCP window scal-
d278 1
a278 1
Available in Postfix version 2.9 - 3.6:
d281 4
a284 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
a286 2
Available in Postfix version 2.9 and later:
d288 1
a288 1
Whether or not to append the "AUTH=<>" option to the MAIL FROM
d299 1
a299 1
Optional filter for the smtp(8) delivery agent to change the
a305 56
Available in Postfix version 3.3 and later:
smtp_balance_inet_protocols (yes)
When a remote destination resolves to a combination of IPv4 and
IPv6 addresses, ensure that the Postfix SMTP client can try both
address types before it runs into the smtp_mx_address_limit.
Available in Postfix 3.5 and later:
info_log_address_format (external)
The email address form that will be used in non-debug logging
(info, warning, etc.).
Available in Postfix 3.6 and later:
dnssec_probe (ns:.)
The DNS query type (default: "ns") and DNS query name (default:
".") that Postfix may use to determine whether DNSSEC validation
is available.
known_tcp_ports (lmtp=24, smtp=25, smtps=submissions=465, submis-
sion=587)
Optional setting that avoids lookups in the services(5) data-
base.
Available in Postfix version 3.7 and later:
smtp_per_request_deadline (no)
Change the behavior of the smtp_*_timeout time limits, from a
time limit per plaintext or TLS read or write call, to a com-
bined time limit for sending a complete SMTP request and for
receiving a complete SMTP response.
smtp_min_data_rate (500)
The minimum plaintext data transfer rate in bytes/second for
DATA requests, when deadlines are enabled with
smtp_per_request_deadline.
header_from_format (standard)
The format of the Postfix-generated From: header.
Available in Postfix version 3.8 and later:
use_srv_lookup (empty)
Enables discovery for the specified service(s) using DNS SRV
records.
ignore_srv_lookup_error (no)
When SRV record lookup fails, fall back to MX or IP address
lookup as if SRV record lookup was not enabled.
allow_srv_lookup_fallback (no)
When SRV record lookup fails or no SRV record exists, fall back
to MX or IP address lookup as if SRV record lookup was not
enabled.
d389 4
a392 1
The default SMTP TLS security level for the Postfix SMTP client.
d449 3
a451 3
smtp_tls_mandatory_protocols (see 'postconf -d' output)
TLS protocols that the Postfix SMTP client will use with manda-
tory TLS encryption.
a482 6
tls_null_cipherlist (eNULL:!aNULL)
The OpenSSL cipherlist for "NULL" grade ciphers that provide
authentication without encryption.
Available in in Postfix version 2.3..3.7:
d489 4
d508 1
a508 1
smtp_tls_fingerprint_digest (see 'postconf -d' output)
d514 3
a516 3
smtp_tls_protocols (see postconf -d output)
TLS protocols that the Postfix SMTP client will use with oppor-
tunistic TLS encryption.
a542 9
Available in Postfix version 2.11-3.1:
tls_dane_digest_agility (on)
Configure RFC7671 DANE TLSA digest algorithm agility.
tls_dane_trust_anchor_digest_enable (yes)
Enable support for RFC 6698 (DANE TLSA) DNS records that contain
digests of trust-anchors with certificate usage "2".
d546 1
a546 1
Zero or more PEM-format files with trust-anchor certificates
d550 1
a550 1
Lookup the associated DANE TLSA RRset even when a hostname is
d553 3
d562 2
a563 2
Request that the Postfix SMTP client connects using the SUBMIS-
SIONS/SMTPS protocol instead of using the STARTTLS command.
d567 1
a567 1
smtp_tls_dane_insecure_mx_policy (see 'postconf -d' output)
a571 41
Available in Postfix version 3.2 and later:
tls_eecdh_auto_curves (see 'postconf -d' output)
The prioritized list of elliptic curves supported by the Postfix
SMTP client and server.
Available in Postfix version 3.4 and later:
smtp_tls_connection_reuse (no)
Try to make multiple deliveries per TLS-encrypted connection.
smtp_tls_chain_files (empty)
List of one or more PEM files, each holding one or more private
keys directly followed by a corresponding certificate chain.
smtp_tls_servername (empty)
Optional name to send to the remote SMTP server in the TLS
Server Name Indication (SNI) extension.
Available in Postfix 3.5, 3.4.6, 3.3.5, 3.2.10, 3.1.13 and later:
tls_fast_shutdown_enable (yes)
A workaround for implementations that hang Postfix while shut-
ting down a TLS session, until Postfix times out.
Available in Postfix version 3.8 and later:
tls_ffdhe_auto_groups (see 'postconf -d' output)
The prioritized list of finite-field Diffie-Hellman ephemeral
(FFDHE) key exchange groups supported by the Postfix SMTP client
and server.
Available in Postfix 3.9, 3.8.1, 3.7.6, 3.6.10, 3.5.20 and later:
tls_config_file (default)
Optional configuration file with baseline OpenSSL settings.
tls_config_name (empty)
The application name passed by Postfix to OpenSSL library ini-
tialization functions.
d600 9
d696 1
a696 1
Available in Postfix version 2.9 - 3.6:
a711 32
Available in Postfix version 3.4 and later:
smtp_tls_connection_reuse (no)
Try to make multiple deliveries per TLS-encrypted connection.
Available in Postfix version 3.7 and later:
smtp_per_request_deadline (no)
Change the behavior of the smtp_*_timeout time limits, from a
time limit per plaintext or TLS read or write call, to a com-
bined time limit for sending a complete SMTP request and for
receiving a complete SMTP response.
smtp_min_data_rate (500)
The minimum plaintext data transfer rate in bytes/second for
DATA requests, when deadlines are enabled with
smtp_per_request_deadline.
Implemented in the qmgr(8) daemon:
transport_destination_concurrency_limit ($default_destination_concur-
rency_limit)
A transport-specific override for the default_destination_con-
currency_limit parameter value, where transport is the master.cf
name of the message delivery transport.
transport_destination_recipient_limit ($default_destination_recipi-
ent_limit)
A transport-specific override for the default_destination_recip-
ient_limit parameter value, where transport is the master.cf
name of the message delivery transport.
d716 2
a717 2
Enable preliminary SMTPUTF8 support for the protocols described
in RFC 6531, RFC 6532, and RFC 6533.
d720 1
a720 1
Detect that a message requires SMTPUTF8 support for the speci-
a722 7
Available in Postfix version 3.2 and later:
enable_idna2003_compatibility (no)
Enable 'transitional' compatibility between IDNA2003 and
IDNA2008, when converting UTF-8 domain names to/from the ASCII
form that is used for DNS lookups.
d725 2
a726 3
The increment in verbose logging level when a nexthop destina-
tion, remote client or server name or network address matches a
pattern given with the debug_peer_list parameter.
d729 3
a731 4
Optional list of nexthop destination, remote client or server
name or network address patterns that, if matched, cause the
verbose logging level to increase by the amount specified in
$debug_peer_level.
d734 1
a734 1
The recipient of postmaster notifications about mail delivery
d739 2
a740 2
What categories of Postfix-generated mail are subject to
before-queue content inspection by non_smtpd_milters,
d748 1
a748 1
Where the Postfix SMTP client should deliver mail when it
d752 1
a752 1
The default location of the Postfix main.cf and master.cf con-
d756 1
a756 1
How much time a Postfix daemon process may take to handle a
d760 1
a760 1
The maximal number of digits after the decimal point when log-
d767 2
a768 2
The local network interface addresses that this mail system
receives mail on.
d770 2
a771 2
inet_protocols (see 'postconf -d output')
The Internet protocols Postfix will attempt to use when making
d775 1
a775 1
The time limit for sending or receiving information over an
d779 2
a780 2
When a remote LMTP server announces no DSN support, assume that
the server performs final delivery, and send "delivered" deliv-
d787 1
a787 1
The maximum amount of time that an idle Postfix daemon process
d801 2
a802 3
The remote network interface addresses that this mail system
receives mail on by way of a proxy or network address transla-
tion unit.
d834 3
a836 2
A prefix that is prepended to the process name in syslog
records, so that, for example, "smtpd" becomes "prefix/smtpd".
d847 2
a848 3
Optional list of relay destinations that will be used when an
SMTP destination is not found, or when delivery fails due to a
non-permanent error.
a861 16
Available with Postfix 3.2 and later:
smtp_tcp_port (smtp)
The default TCP port that the Postfix SMTP client connects to.
Available in Postfix 3.3 and later:
service_name (read-only)
The master.cf service name of a Postfix daemon process.
Available in Postfix 3.7 and later:
smtp_bind_address_enforce (no)
Defer delivery when the Postfix SMTP client cannot apply the
smtp_bind_address or smtp_bind_address6 setting.
a872 1
postlogd(8), Postfix logging
@
1.1.1.9.12.1
log
@Merge changes from current as of 20200406
@
text
@d13 1
a13 1
smtp [generic Postfix daemon options] [flags=DORX]
d44 1
a44 3
The Postfix SMTP+LMTP client supports multiple destinations separated
by comma or whitespace (Postfix 3.5 and later). SMTP destinations have
the following form:
d66 1
a66 3
The Postfix SMTP+LMTP client supports multiple destinations separated
by comma or whitespace (Postfix 3.5 and later). LMTP destinations have
the following form:
a86 46
SINGLE-RECIPIENT DELIVERY
By default, the Postfix SMTP+LMTP client delivers mail to multiple
recipients per delivery request. This is undesirable when prepending a
Delivered-to: or X-Original-To: message header. To prevent Postfix from
sending multiple recipients per delivery request, specify
transport_destination_recipient_limit = 1
in the Postfix main.cf file, where transport is the name in the first
column of the Postfix master.cf entry for this mail delivery service.
COMMAND ATTRIBUTE SYNTAX
flags=DORX (optional)
Optional message processing flags.
D Prepend a "Delivered-To: recipient" message header with
the envelope recipient address. Note: for this to work,
the transport_destination_recipient_limit must be 1 (see
SINGLE-RECIPIENT DELIVERY above for details).
The D flag also enforces loop detection: if a message
already contains a Delivered-To: header with the same
recipient address, then the message is returned as unde-
liverable. The address comparison is case insensitive.
This feature is available as of Postfix 3.5.
O Prepend an "X-Original-To: recipient" message header with
the recipient address as given to Postfix. Note: for this
to work, the transport_destination_recipient_limit must
be 1 (see SINGLE-RECIPIENT DELIVERY above for details).
This feature is available as of Postfix 3.5.
R Prepend a "Return-Path: <sender>" message header with the
envelope sender address.
This feature is available as of Postfix 3.5.
X Indicates that the delivery is final. This flag affects
the status reported in "success" DSN (delivery status
notification) messages, and changes it from "relayed"
into "delivered".
This feature is available as of Postfix 3.5.
d88 3
a90 4
The SMTP+LMTP client is moderately security-sensitive. It
talks to SMTP or LMTP servers and to DNS servers on the
network. The SMTP+LMTP client can be run chrooted at fixed
low privilege.
d115 3
a117 3
Problems and transactions are logged to syslogd(8) or postlogd(8).
Corrupted message files are marked so that the queue manager can move
them to the corrupt queue for further inspection.
d119 1
a119 1
Depending on the setting of the notify_classes parameter, the postmas-
d123 7
a129 5
SMTP and LMTP connection reuse for TLS (without closing the SMTP or
LMTP connection) is not supported before Postfix 3.4.
SMTP and LMTP connection reuse assumes that SASL credentials are valid
for all destinations that map onto the same IP address and TCP port.
d132 3
a134 3
Before Postfix version 2.3, the LMTP client is a separate program that
implements only a subset of the functionality available with SMTP:
there is no support for TLS, and connections are cached in-process,
d138 1
a138 1
eter for the equivalent LMTP feature. This document describes only
d141 1
a141 1
Changes to main.cf are picked up automatically, as smtp(8) processes
d145 1
a145 1
The text below provides only a parameter summary. See postconf(5) for
d166 2
a167 2
How long the Postfix SMTP client pauses before sending
".<CR><LF>" in order to work around the PIX firewall
d176 1
a176 1
A list that specifies zero or more workarounds for CISCO PIX
d180 1
a180 1
Lookup tables, indexed by the remote SMTP server address, with
d184 1
a184 1
Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO
d188 1
a188 1
A mechanism to transform replies from remote SMTP servers one
d200 1
a200 1
Skip SMTP servers that greet with a 4XX status code (go away,
d206 2
a207 2
Lookup tables, indexed by the remote SMTP server address, with
case insensitive lists of EHLO keywords (pipelining, starttls,
d212 1
a212 1
A case insensitive list of EHLO keywords (pipelining, starttls,
d217 3
a219 3
Optional lookup tables that perform address rewriting in the
Postfix SMTP client, typically to transform a locally valid
address into a globally valid address when sending mail across
d225 3
a227 3
When the remote SMTP servername is a DNS CNAME, replace the
servername with the result from CNAME expansion for the purpose
of logging, SASL password lookup, TLS policy decisions, or TLS
d233 2
a234 2
Lookup tables, indexed by the remote LMTP server address, with
case insensitive lists of LHLO keywords (pipelining, starttls,
d239 1
a239 1
A case insensitive list of LHLO keywords (pipelining, starttls,
d246 3
a248 3
When authenticating to a remote SMTP or LMTP server with the
default setting "no", send no SASL authoriZation ID (authzid);
send only the SASL authentiCation ID (authcid) plus the auth-
d254 1
a254 1
Restricted header_checks(5) tables for the Postfix SMTP client.
d257 1
a257 1
Restricted mime_header_checks(5) tables for the Postfix SMTP
d261 1
a261 1
Restricted nested_header_checks(5) tables for the Postfix SMTP
d270 1
a270 1
An optional workaround for routers that break TCP window scal-
d281 4
a284 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
d288 1
a288 1
Whether or not to append the "AUTH=<>" option to the MAIL FROM
d299 1
a299 1
Optional filter for the smtp(8) delivery agent to change the
a305 13
Available in Postfix version 3.3 and later:
smtp_balance_inet_protocols (yes)
When a remote destination resolves to a combination of IPv4 and
IPv6 addresses, ensure that the Postfix SMTP client can try both
address types before it runs into the smtp_mx_address_limit.
Available in Postfix 3.5 and later:
info_log_address_format (external)
The email address form that will be used in non-debug logging
(info, warning, etc.).
a542 9
Available in Postfix version 2.11-3.1:
tls_dane_digest_agility (on)
Configure RFC7671 DANE TLSA digest algorithm agility.
tls_dane_trust_anchor_digest_enable (yes)
Enable support for RFC 6698 (DANE TLSA) DNS records that contain
digests of trust-anchors with certificate usage "2".
d546 1
a546 1
Zero or more PEM-format files with trust-anchor certificates
d550 1
a550 1
Lookup the associated DANE TLSA RRset even when a hostname is
d553 3
a571 19
Available in Postfix version 3.4 and later:
smtp_tls_connection_reuse (no)
Try to make multiple deliveries per TLS-encrypted connection.
smtp_tls_chain_files (empty)
List of one or more PEM files, each holding one or more private
keys directly followed by a corresponding certificate chain.
smtp_tls_servername (empty)
Optional name to send to the remote SMTP server in the TLS
Server Name Indication (SNI) extension.
Available in Postfix 3.5, 3.4.6, 3.3.5, 3.2.10, 3.1.13 and later:
tls_fast_shutdown_enable (yes)
A workaround for implementations that hang Postfix while shut-
ting down a TLS session, until Postfix times out.
d573 2
a574 2
The following configuration parameters exist for compatibility with
Postfix versions before 2.3. Support for these will be removed in a
d578 1
a578 1
Opportunistic mode: use TLS when a remote SMTP server announces
d582 1
a582 1
Enforcement mode: require that remote SMTP servers use TLS
d586 2
a587 2
With mandatory TLS encryption, require that the remote SMTP
server hostname matches the information in the remote SMTP
d591 2
a592 2
Optional lookup tables with the Postfix SMTP client TLS usage
policy by next-hop destination and by remote SMTP server host-
d596 1
a596 1
Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS
d600 9
d610 1
a610 1
The Postfix SMTP client time limit for completing a TCP connec-
d614 2
a615 2
The Postfix SMTP client time limit for sending the HELO or EHLO
command, and for receiving the initial remote SMTP server
d627 1
a627 1
The Postfix SMTP client time limit for sending the MAIL FROM
d631 1
a631 1
The Postfix SMTP client time limit for sending the SMTP RCPT TO
d635 1
a635 1
The Postfix SMTP client time limit for sending the SMTP DATA
d639 1
a639 1
The Postfix SMTP client time limit for sending the SMTP message
d653 2
a654 2
The maximal number of MX (mail exchanger) IP addresses that can
result from Postfix SMTP client mail exchanger lookups, or zero
d658 2
a659 2
The maximal number of SMTP sessions per delivery request before
the Postfix SMTP client gives up or delivers to a fall-back
d669 1
a669 1
Keep Postfix LMTP client connections open for up to $max_idle
d675 1
a675 1
Permanently enable SMTP connection caching for the specified
d679 1
a679 1
Temporarily enable SMTP connection caching while a destination
d693 1
a693 1
Time limit for connection cache connect, send or receive opera-
d699 4
a702 4
Change the behavior of the smtp_*_timeout time limits, from a
time limit per read or write system call, to a time limit to
send or receive a complete record (an SMTP command line, SMTP
response line, SMTP message content line, or TLS protocol mes-
d708 2
a709 2
When SMTP connection caching is enabled, the number of times
that an SMTP session may be reused before it is closed, or zero
a711 19
Available in Postfix version 3.4 and later:
smtp_tls_connection_reuse (no)
Try to make multiple deliveries per TLS-encrypted connection.
Implemented in the qmgr(8) daemon:
transport_destination_concurrency_limit ($default_destination_concur-
rency_limit)
A transport-specific override for the default_destination_con-
currency_limit parameter value, where transport is the master.cf
name of the message delivery transport.
transport_destination_recipient_limit ($default_destination_recipi-
ent_limit)
A transport-specific override for the default_destination_recip-
ient_limit parameter value, where transport is the master.cf
name of the message delivery transport.
d716 1
a716 1
Enable preliminary SMTPUTF8 support for the protocols described
d720 1
a720 1
Detect that a message requires SMTPUTF8 support for the speci-
a722 7
Available in Postfix version 3.2 and later:
enable_idna2003_compatibility (no)
Enable 'transitional' compatibility between IDNA2003 and
IDNA2008, when converting UTF-8 domain names to/from the ASCII
form that is used for DNS lookups.
d725 1
a725 1
The increment in verbose logging level when a remote client or
d729 1
a729 1
Optional list of remote client or server hostname or network
d734 1
a734 1
The recipient of postmaster notifications about mail delivery
d739 2
a740 2
What categories of Postfix-generated mail are subject to
before-queue content inspection by non_smtpd_milters,
d748 1
a748 1
Where the Postfix SMTP client should deliver mail when it
d752 1
a752 1
The default location of the Postfix main.cf and master.cf con-
d756 1
a756 1
How much time a Postfix daemon process may take to handle a
d760 1
a760 1
The maximal number of digits after the decimal point when log-
d767 1
a767 1
The network interface addresses that this mail system receives
d771 1
a771 1
The Internet protocols Postfix will attempt to use when making
d775 1
a775 1
The time limit for sending or receiving information over an
d779 2
a780 2
When a remote LMTP server announces no DSN support, assume that
the server performs final delivery, and send "delivered" deliv-
d787 1
a787 1
The maximum amount of time that an idle Postfix daemon process
d801 1
a801 1
The network interface addresses that this mail system receives
d806 1
a806 1
client will try first, when a destination has IPv6 and IPv4
d810 1
a810 1
An optional numerical network address that the Postfix SMTP
d814 1
a814 1
An optional numerical network address that the Postfix SMTP
d834 3
a836 2
A prefix that is prepended to the process name in syslog
records, so that, for example, "smtpd" becomes "prefix/smtpd".
a861 10
Available with Postfix 3.2 and later:
smtp_tcp_port (smtp)
The default TCP port that the Postfix SMTP client connects to.
Available in Postfix 3.3 and later:
service_name (read-only)
The master.cf service name of a Postfix daemon process.
a872 1
postlogd(8), Postfix logging
@
1.1.1.10
log
@This is the Postfix 3.5 (stable) release.
The stable Postfix release is called postfix-3.5.x where 3=major
release number, 5=minor release number, x=patchlevel. The stable
release never changes except for patches that address bugs or
emergencies. Patches change the patchlevel and the release date.
New features are developed in snapshot releases. These are called
postfix-3.6-yyyymmdd where yyyymmdd is the release date (yyyy=year,
mm=month, dd=day). Patches are never issued for snapshot releases;
instead, a new snapshot is released.
The mail_release_date configuration parameter (format: yyyymmdd)
specifies the release date of a stable release or snapshot release.
If you upgrade from Postfix 3.3 or earlier, read RELEASE_NOTES-3.4
before proceeding.
License change
---------------
This software is distributed with a dual license: in addition to the
historical IBM Public License 1.0, it is now also distributed with the
more recent Eclipse Public License 2.0. Recipients can choose to take
the software under the license of their choice. Those who are more
comfortable with the IPL can continue with that license.
Major changes - multiple relayhost in SMTP
------------------------------------------
[Feature 20200111] the Postfix SMTP and LMTP client support a list
of nexthop destinations separated by comma or whitespace. These
destinations will be tried in the specified order.
The list form can be specified in relayhost, transport_maps,
default_transport, and sender_dependent_default_transport_maps.
Examples:
/etc/postfix/main.cf:
relayhost = foo.example, bar.example
default_transport = smtp:foo.example, bar.example.
NOTE: this is an SMTP and LMTP client feature. It does not work for
other Postfix delivery agents.
Major changes - certificate access
----------------------------------
[Feature 20190517] Search order support for check_ccert_access.
Search order support for other tables is in design (canonical_maps,
virtual_alias_maps, transport_maps, etc.).
The following check_ccert_access setting uses the built-in search
order: it first looks up the client certificate fingerprint, then
the client certificate public-key fingerprint, and it stops when a
decision is made.
/etc/postfix/main.cf:
smtpd_mumble_restrictions =
...
check_ccert_access hash:/etc/postfix/ccert-access
...
The following setting, with explicit search order, produces the
exact same result:
/etc/postfix/main.cf:
smtpd_mumble_restrictions =
...
check_ccert_access {
hash:/etc/postfix/ccert-access {
search_order = cert_fingerprint, pubkey_fingerprint } }
...
Support is planned for other certificate features.
Major changes - dovecot usability
---------------------------------
[Feature 20190615] The SMTP+LMTP delivery agent can now prepend
Delivered-To, X-Original-To and Return-Path headers, just like the
pipe(8) and local(8) delivery agents.
This uses the "flags=DORX" command-line flags in master.cf. See the
smtp(8) manpage for details.
This obsoletes the "lmtp_assume_final = yes" setting, and replaces
it with "flags=...X...", for consistency with the pipe(8) delivery
agent.
Major changes - forced expiration
---------------------------------
[Feature 20200202] Support to force-expire email messages. This
introduces new postsuper(1) command-line options to request expiration,
and additional information in mailq(1) or postqueue(1) output.
The forced-to-expire status is stored in a queue file attribute.
An expired message is returned to the sender when the queue manager
attempts to deliver that message (note that Postfix will never
deliver messages in the hold queue).
The postsuper(1) -e and -f options both set the forced-to-expire
queue file attribute. The difference is that -f will also release
a message if it is in the hold queue. With -e, such a message would
not be returned to the sender until it is released with -f or -H.
In the mailq(1) or postqueue(1) -p output, a forced-to-expire message
is indicated with # after the queue file name. In postqueue(1) JSON
output, there is a new per-message field "forced_expire" (with value
true or false) that shows the forced-to-expire status.
Major changes - haproxy2 protocol
---------------------------------
[Feature 20200112] Support for the haproxy v2 protocol. The Postfix
implementation supports TCP over IPv4 and IPv6, as well as non-proxied
connections; the latter are typically used for heartbeat tests.
The haproxy v2 protocol introduces no additional Postfix configuration.
The Postfix smtpd(8) and postscreen(8) daemons accept both v1 and
v2 protocol versions.
Major changes - logging
-----------------------
[Incompat 20191109] Postfix daemon processes now log the from= and
to= addresses in external (quoted) form in non-debug logging (info,
warning, etc.). This means that when an address localpart contains
spaces or other special characters, the localpart will be quoted,
for example:
from=<"name with spaces"@@example.com>
Older Postfix versions would log the internal (unquoted) form:
from=
SMTP(8) SMTP(8)
NAME
smtp - Postfix SMTP+LMTP client
SYNOPSIS
smtp [generic Postfix daemon options]
DESCRIPTION
The Postfix SMTP+LMTP client implements the SMTP and LMTP
mail delivery protocols. It processes message delivery
requests from the queue manager. Each request specifies a
queue file, a sender address, a domain or host to deliver
to, and recipient information. This program expects to be
run from the master(8) process manager.
The SMTP+LMTP client updates the queue file and marks
recipients as finished, or it informs the queue manager
that delivery should be tried again at a later time.
Delivery status reports are sent to the bounce(8),
defer(8) or trace(8) daemon as appropriate.
The SMTP+LMTP client looks up a list of mail exchanger
addresses for the destination host, sorts the list by
preference, and connects to each listed address until it
finds a server that responds.
When a server is not reachable, or when mail delivery
fails due to a recoverable error condition, the SMTP+LMTP
client will try to deliver the mail to an alternate host.
After a successful mail transaction, a connection may be
saved to the scache(8) connection cache server, so that it
may be used by any SMTP+LMTP client for a subsequent
transaction.
By default, connection caching is enabled temporarily for
destinations that have a high volume of mail in the active
queue. Connection caching can be enabled permanently for
specific destinations.
SMTP DESTINATION SYNTAX
SMTP destinations have the following form:
domainname
domainname:port
Look up the mail exchangers for the specified
domain, and connect to the specified port (default:
smtp).
[hostname]
[hostname]:port
Look up the address(es) of the specified host, and
connect to the specified port (default: smtp).
[address]
[address]:port
Connect to the host at the specified address, and
connect to the specified port (default: smtp). An
IPv6 address must be formatted as [ipv6:address].
LMTP DESTINATION SYNTAX
LMTP destinations have the following form:
unix:pathname
Connect to the local UNIX-domain server that is
bound to the specified pathname. If the process
runs chrooted, an absolute pathname is interpreted
relative to the Postfix queue directory.
inet:hostname
inet:hostname:port
inet:[address]
inet:[address]:port
Connect to the specified TCP port on the specified
local or remote host. If no port is specified, con-
nect to the port defined as lmtp in services(4).
If no such service is found, the lmtp_tcp_port con-
figuration parameter (default value of 24) will be
used. An IPv6 address must be formatted as
[ipv6:address].
SECURITY
The SMTP+LMTP client is moderately security-sensitive. It
talks to SMTP or LMTP servers and to DNS servers on the
network. The SMTP+LMTP client can be run chrooted at fixed
low privilege.
STANDARDS
RFC 821 (SMTP protocol)
RFC 822 (ARPA Internet Text Messages)
RFC 1651 (SMTP service extensions)
RFC 1652 (8bit-MIME transport)
RFC 1870 (Message Size Declaration)
RFC 2033 (LMTP protocol)
RFC 2034 (SMTP Enhanced Error Codes)
RFC 2045 (MIME: Format of Internet Message Bodies)
RFC 2046 (MIME: Media Types)
RFC 2554 (AUTH command)
RFC 2821 (SMTP protocol)
RFC 2920 (SMTP Pipelining)
RFC 3207 (STARTTLS command)
RFC 3461 (SMTP DSN Extension)
RFC 3463 (Enhanced Status Codes)
RFC 4954 (AUTH command)
DIAGNOSTICS
Problems and transactions are logged to syslogd(8). Cor-
rupted message files are marked so that the queue manager
can move them to the corrupt queue for further inspection.
Depending on the setting of the notify_classes parameter,
the postmaster is notified of bounces, protocol problems,
and of other trouble.
BUGS
SMTP and LMTP connection caching does not work with TLS.
The necessary support for TLS object passivation and re-
activation does not exist without closing the session,
which defeats the purpose.
SMTP and LMTP connection caching assumes that SASL creden-
tials are valid for all destinations that map onto the
same IP address and TCP port.
CONFIGURATION PARAMETERS
Before Postfix version 2.3, the LMTP client is a separate
program that implements only a subset of the functionality
available with SMTP: there is no support for TLS, and con-
nections are cached in-process, making it ineffective when
the client is used for multiple domains.
Most smtp_xxx configuration parameters have an lmtp_xxx
"mirror" parameter for the equivalent LMTP feature. This
document describes only those LMTP-related parameters that
aren't simply "mirror" parameters.
Changes to main.cf are picked up automatically, as smtp(8)
processes run for only a limited amount of time. Use the
command "postfix reload" to speed up a change.
The text below provides only a parameter summary. See
postconf(5) for more details including examples.
COMPATIBILITY CONTROLS
ignore_mx_lookup_error (no)
Ignore DNS MX lookups that produce no response.
smtp_always_send_ehlo (yes)
Always send EHLO at the start of an SMTP session.
smtp_never_send_ehlo (no)
Never send EHLO at the start of an SMTP session.
smtp_defer_if_no_mx_address_found (no)
Defer mail delivery when no MX record resolves to
an IP address.
smtp_line_length_limit (990)
The maximal length of message header and body lines
that Postfix will send via SMTP.
smtp_pix_workaround_delay_time (10s)
How long the Postfix SMTP client pauses before
sending ".<CR><LF>" in order to work around the PIX
firewall "<CR><LF>.<CR><LF>" bug.
smtp_pix_workaround_threshold_time (500s)
How long a message must be queued before the Post-
fix SMTP client turns on the PIX firewall
"<CR><LF>.<CR><LF>" bug workaround for delivery
through firewalls with "smtp fixup" mode turned on.
smtp_pix_workarounds (disable_esmtp, delay_dotcrlf)
A list that specifies zero or more workarounds for
CISCO PIX firewall bugs.
smtp_pix_workaround_maps (empty)
Lookup tables, indexed by the remote SMTP server
address, with per-destination workarounds for CISCO
PIX firewall bugs.
smtp_quote_rfc821_envelope (yes)
Quote addresses in SMTP MAIL FROM and RCPT TO com-
mands as required by RFC 2821.
smtp_skip_5xx_greeting (yes)
Skip SMTP servers that greet with a 5XX status code
(go away, do not try again later).
smtp_skip_quit_response (yes)
Do not wait for the response to the SMTP QUIT com-
mand.
Available in Postfix version 2.0 and earlier:
smtp_skip_4xx_greeting (yes)
Skip SMTP servers that greet with a 4XX status code
(go away, try again later).
Available in Postfix version 2.2 and later:
smtp_discard_ehlo_keyword_address_maps (empty)
Lookup tables, indexed by the remote SMTP server
address, with case insensitive lists of EHLO key-
words (pipelining, starttls, auth, etc.) that the
Postfix SMTP client will ignore in the EHLO
response from a remote SMTP server.
smtp_discard_ehlo_keywords (empty)
A case insensitive list of EHLO keywords (pipelin-
ing, starttls, auth, etc.) that the Postfix SMTP
client will ignore in the EHLO response from a
remote SMTP server.
smtp_generic_maps (empty)
Optional lookup tables that perform address rewrit-
ing in the SMTP client, typically to transform a
locally valid address into a globally valid address
when sending mail across the Internet.
Available in Postfix version 2.2.9 and later:
smtp_cname_overrides_servername (version dependent)
Allow DNS CNAME records to override the servername
that the Postfix SMTP client uses for logging, SASL
password lookup, TLS policy decisions, or TLS cer-
tificate verification.
Available in Postfix version 2.3 and later:
lmtp_discard_lhlo_keyword_address_maps (empty)
Lookup tables, indexed by the remote LMTP server
address, with case insensitive lists of LHLO key-
words (pipelining, starttls, auth, etc.) that the
LMTP client will ignore in the LHLO response from a
remote LMTP server.
lmtp_discard_lhlo_keywords (empty)
A case insensitive list of LHLO keywords (pipelin-
ing, starttls, auth, etc.) that the LMTP client
will ignore in the LHLO response from a remote LMTP
server.
Available in Postfix version 2.4.4 and later:
send_cyrus_sasl_authzid (no)
When authenticating to a remote SMTP or LMTP server
with the default setting "no", send no SASL autho-
riZation ID (authzid); send only the SASL authenti-
Cation ID (authcid) plus the authcid's password.
Available in Postfix version 2.5 and later:
smtp_header_checks (empty)
Restricted header_checks(5) tables for the Postfix
SMTP client.
smtp_mime_header_checks (empty)
Restricted mime_header_checks(5) tables for the
Postfix SMTP client.
smtp_nested_header_checks (empty)
Restricted nested_header_checks(5) tables for the
Postfix SMTP client.
smtp_body_checks (empty)
Restricted body_checks(5) tables for the Postfix
SMTP client.
Available in Postfix version 2.6 and later:
tcp_windowsize (0)
An optional workaround for routers that break TCP
window scaling.
MIME PROCESSING CONTROLS
Available in Postfix version 2.0 and later:
disable_mime_output_conversion (no)
Disable the conversion of 8BITMIME format to 7BIT
format.
mime_boundary_length_limit (2048)
The maximal length of MIME multipart boundary
strings.
mime_nesting_limit (100)
The maximal recursion level that the MIME processor
will handle.
EXTERNAL CONTENT INSPECTION CONTROLS
Available in Postfix version 2.1 and later:
smtp_send_xforward_command (no)
Send the non-standard XFORWARD command when the
Postfix SMTP server EHLO response announces XFOR-
WARD support.
SASL AUTHENTICATION CONTROLS
smtp_sasl_auth_enable (no)
Enable SASL authentication in the Postfix SMTP
client.
smtp_sasl_password_maps (empty)
Optional SMTP client lookup tables with one user-
name:password entry per remote hostname or domain,
or sender address when sender-dependent authentica-
tion is enabled.
smtp_sasl_security_options (noplaintext, noanonymous)
Postfix SMTP client SASL security options; as of
Postfix 2.3 the list of available features depends
on the SASL client implementation that is selected
with smtp_sasl_type.
Available in Postfix version 2.2 and later:
smtp_sasl_mechanism_filter (empty)
If non-empty, a Postfix SMTP client filter for the
remote SMTP server's list of offered SASL mecha-
nisms.
Available in Postfix version 2.3 and later:
smtp_sender_dependent_authentication (no)
Enable sender-dependent authentication in the Post-
fix SMTP client; this is available only with SASL
authentication, and disables SMTP connection
caching to ensure that mail from different senders
will use the appropriate credentials.
smtp_sasl_path (empty)
Implementation-specific information that the Post-
fix SMTP client passes through to the SASL plug-in
implementation that is selected with
smtp_sasl_type.
smtp_sasl_type (cyrus)
The SASL plug-in type that the Postfix SMTP client
should use for authentication.
Available in Postfix version 2.5 and later:
smtp_sasl_auth_cache_name (empty)
An optional table to prevent repeated SASL authen-
tication failures with the same remote SMTP server
hostname, username and password.
smtp_sasl_auth_cache_time (90d)
The maximal age of an smtp_sasl_auth_cache_name
entry before it is removed.
smtp_sasl_auth_soft_bounce (yes)
When a remote SMTP server rejects a SASL authenti-
cation request with a 535 reply code, defer mail
delivery instead of returning mail as undeliver-
able.
STARTTLS SUPPORT CONTROLS
Detailed information about STARTTLS configuration may be
found in the TLS_README document.
smtp_tls_security_level (empty)
The default SMTP TLS security level for the Postfix
SMTP client; when a non-empty value is specified,
this overrides the obsolete parameters
smtp_use_tls, smtp_enforce_tls, and
smtp_tls_enforce_peername.
smtp_sasl_tls_security_options ($smtp_sasl_secu-
rity_options)
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
sessions.
smtp_starttls_timeout (300s)
Time limit for Postfix SMTP client write and read
operations during TLS startup and shutdown hand-
shake procedures.
smtp_tls_CAfile (empty)
A file containing CA certificates of root CAs
trusted to sign either remote SMTP server certifi-
cates or intermediate CA certificates.
smtp_tls_CApath (empty)
Directory with PEM format certificate authority
certificates that the Postfix SMTP client uses to
verify a remote SMTP server certificate.
smtp_tls_cert_file (empty)
File with the Postfix SMTP client RSA certificate
in PEM format.
smtp_tls_mandatory_ciphers (medium)
The minimum TLS cipher grade that the Postfix SMTP
client will use with mandatory TLS encryption.
smtp_tls_exclude_ciphers (empty)
List of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at all TLS security
levels.
smtp_tls_mandatory_exclude_ciphers (empty)
Additional list of ciphers or cipher types to
exclude from the SMTP client cipher list at manda-
tory TLS security levels.
smtp_tls_dcert_file (empty)
File with the Postfix SMTP client DSA certificate
in PEM format.
smtp_tls_dkey_file ($smtp_tls_dcert_file)
File with the Postfix SMTP client DSA private key
in PEM format.
smtp_tls_key_file ($smtp_tls_cert_file)
File with the Postfix SMTP client RSA private key
in PEM format.
smtp_tls_loglevel (0)
Enable additional Postfix SMTP client logging of
TLS activity.
smtp_tls_note_starttls_offer (no)
Log the hostname of a remote SMTP server that
offers STARTTLS, when TLS is not already enabled
for that server.
smtp_tls_policy_maps (empty)
Optional lookup tables with the Postfix SMTP client
TLS security policy by next-hop destination; when a
non-empty value is specified, this overrides the
obsolete smtp_tls_per_site parameter.
smtp_tls_mandatory_protocols (SSLv3, TLSv1)
List of SSL/TLS protocols that the Postfix SMTP
client will use with mandatory TLS encryption.
smtp_tls_scert_verifydepth (9)
The verification depth for remote SMTP server cer-
tificates.
smtp_tls_secure_cert_match (nexthop, dot-nexthop)
The server certificate peername verification method
for the "secure" TLS security level.
smtp_tls_session_cache_database (empty)
Name of the file containing the optional Postfix
SMTP client TLS session cache.
smtp_tls_session_cache_timeout (3600s)
The expiration time of Postfix SMTP client TLS ses-
sion cache information.
smtp_tls_verify_cert_match (hostname)
The server certificate peername verification method
for the "verify" TLS security level.
tls_daemon_random_bytes (32)
The number of pseudo-random bytes that an smtp(8)
or smtpd(8) process requests from the tlsmgr(8)
server in order to seed its internal pseudo random
number generator (PRNG).
tls_high_cipherlist
(ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "HIGH" grade ciphers.
tls_medium_cipherlist (ALL:!EXPORT:!LOW:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "MEDIUM" or higher grade
ciphers.
tls_low_cipherlist (ALL:!EXPORT:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "LOW" or higher grade
ciphers.
tls_export_cipherlist (ALL:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "EXPORT" or higher grade
ciphers.
tls_null_cipherlist (eNULL:!aNULL)
The OpenSSL cipherlist for "NULL" grade ciphers
that provide authentication without encryption.
Available in Postfix version 2.4 and later:
smtp_sasl_tls_verified_security_options
($smtp_sasl_tls_security_options)
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
sessions with a verified server certificate.
Available in Postfix version 2.5 and later:
smtp_tls_fingerprint_cert_match (empty)
List of acceptable remote SMTP server certificate
fingerprints for the "fingerprint" TLS security
level (smtp_tls_security_level = fingerprint).
smtp_tls_fingerprint_digest (md5)
The message digest algorithm used to construct
remote SMTP server certificate fingerprints.
Available in Postfix version 2.6 and later:
smtp_tls_protocols (!SSLv2)
List of TLS protocols that the Postfix SMTP client
will exclude or include with opportunistic TLS
encryption.
smtp_tls_ciphers (export)
The minimum TLS cipher grade that the Postfix SMTP
client will use with opportunistic TLS encryption.
smtp_tls_eccert_file (empty)
File with the Postfix SMTP client ECDSA certificate
in PEM format.
smtp_tls_eckey_file ($smtp_tls_eccert_file)
File with the Postfix SMTP client ECDSA private key
in PEM format.
OBSOLETE STARTTLS CONTROLS
The following configuration parameters exist for compati-
bility with Postfix versions before 2.3. Support for these
will be removed in a future release.
smtp_use_tls (no)
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
the mail in the clear.
smtp_enforce_tls (no)
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
clear.
smtp_tls_enforce_peername (yes)
With mandatory TLS encryption, require that the
remote SMTP server hostname matches the information
in the remote SMTP server certificate.
smtp_tls_per_site (empty)
Optional lookup tables with the Postfix SMTP client
TLS usage policy by next-hop destination and by
remote SMTP server hostname.
smtp_tls_cipherlist (empty)
Obsolete Postfix < 2.3 control for the Postfix SMTP
client TLS cipher list.
RESOURCE AND RATE CONTROLS
smtp_destination_concurrency_limit ($default_destina-
tion_concurrency_limit)
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
transport.
smtp_destination_recipient_limit ($default_destina-
tion_recipient_limit)
The maximal number of recipients per message for
the smtp message delivery transport.
smtp_connect_timeout (30s)
The SMTP client time limit for completing a TCP
connection, or zero (use the operating system
built-in time limit).
smtp_helo_timeout (300s)
The SMTP client time limit for sending the HELO or
EHLO command, and for receiving the initial server
response.
lmtp_lhlo_timeout (300s)
The LMTP client time limit for sending the LHLO
command, and for receiving the initial server
response.
smtp_xforward_timeout (300s)
The SMTP client time limit for sending the XFORWARD
command, and for receiving the server response.
smtp_mail_timeout (300s)
The SMTP client time limit for sending the MAIL
FROM command, and for receiving the server
response.
smtp_rcpt_timeout (300s)
The SMTP client time limit for sending the SMTP
RCPT TO command, and for receiving the server
response.
smtp_data_init_timeout (120s)
The SMTP client time limit for sending the SMTP
DATA command, and for receiving the server
response.
smtp_data_xfer_timeout (180s)
The SMTP client time limit for sending the SMTP
message content.
smtp_data_done_timeout (600s)
The SMTP client time limit for sending the SMTP
".", and for receiving the server response.
smtp_quit_timeout (300s)
The SMTP client time limit for sending the QUIT
command, and for receiving the server response.
Available in Postfix version 2.1 and later:
smtp_mx_address_limit (5)
The maximal number of MX (mail exchanger) IP
addresses that can result from mail exchanger
lookups, or zero (no limit).
smtp_mx_session_limit (2)
The maximal number of SMTP sessions per delivery
request before giving up or delivering to a fall-
back relay host, or zero (no limit).
smtp_rset_timeout (20s)
The SMTP client time limit for sending the RSET
command, and for receiving the server response.
Available in Postfix version 2.2 and earlier:
lmtp_cache_connection (yes)
Keep Postfix LMTP client connections open for up to
$max_idle seconds.
Available in Postfix version 2.2 and later:
smtp_connection_cache_destinations (empty)
Permanently enable SMTP connection caching for the
specified destinations.
smtp_connection_cache_on_demand (yes)
Temporarily enable SMTP connection caching while a
destination has a high volume of mail in the active
queue.
smtp_connection_reuse_time_limit (300s)
The amount of time during which Postfix will use an
SMTP connection repeatedly.
smtp_connection_cache_time_limit (2s)
When SMTP connection caching is enabled, the amount
of time that an unused SMTP client socket is kept
open before it is closed.
Available in Postfix version 2.3 and later:
connection_cache_protocol_timeout (5s)
Time limit for connection cache connect, send or
receive operations.
TROUBLE SHOOTING CONTROLS
debug_peer_level (2)
The increment in verbose logging level when a
remote client or server matches a pattern in the
debug_peer_list parameter.
debug_peer_list (empty)
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
in $debug_peer_level.
error_notice_recipient (postmaster)
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
resource, software or protocol errors.
internal_mail_filter_classes (empty)
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
non_smtpd_milters, header_checks and body_checks.
notify_classes (resource, software)
The list of error classes that are reported to the
postmaster.
MISCELLANEOUS CONTROLS
best_mx_transport (empty)
Where the Postfix SMTP client should deliver mail
when it detects a "mail loops back to myself" error
condition.
config_directory (see 'postconf -d' output)
The default location of the Postfix main.cf and
master.cf configuration files.
daemon_timeout (18000s)
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
built-in watchdog timer.
delay_logging_resolution_limit (2)
The maximal number of digits after the decimal
point when logging sub-second delay values.
disable_dns_lookups (no)
Disable DNS lookups in the Postfix SMTP and LMTP
clients.
inet_interfaces (all)
The network interface addresses that this mail sys-
tem receives mail on.
inet_protocols (ipv4)
The Internet protocols Postfix will attempt to use
when making or accepting connections.
ipc_timeout (3600s)
The time limit for sending or receiving information
over an internal communication channel.
lmtp_assume_final (no)
When an LMTP server announces no DSN support,
assume that the server performs final delivery, and
send "delivered" delivery status notifications
instead of "relayed".
lmtp_tcp_port (24)
The default TCP port that the Postfix LMTP client
connects to.
max_idle (100s)
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
before terminating voluntarily.
max_use (100)
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
nating voluntarily.
process_id (read-only)
The process ID of a Postfix command or daemon
process.
process_name (read-only)
The process name of a Postfix command or daemon
process.
proxy_interfaces (empty)
The network interface addresses that this mail sys-
tem receives mail on by way of a proxy or network
address translation unit.
smtp_bind_address (empty)
An optional numerical network address that the
Postfix SMTP client should bind to when making an
IPv4 connection.
smtp_bind_address6 (empty)
An optional numerical network address that the
Postfix SMTP client should bind to when making an
IPv6 connection.
smtp_helo_name ($myhostname)
The hostname to send in the SMTP EHLO or HELO com-
mand.
lmtp_lhlo_name ($myhostname)
The hostname to send in the LMTP LHLO command.
smtp_host_lookup (dns)
What mechanisms when the Postfix SMTP client uses
to look up a host's IP address.
smtp_randomize_addresses (yes)
Randomize the order of equal-preference MX host
addresses.
syslog_facility (mail)
The syslog facility of Postfix logging.
syslog_name (see 'postconf -d' output)
The mail system name that is prepended to the
process name in syslog records, so that "smtpd"
becomes, for example, "postfix/smtpd".
Available with Postfix 2.2 and earlier:
fallback_relay (empty)
Optional list of relay hosts for SMTP destinations
that can't be found or that are unreachable.
Available with Postfix 2.3 and later:
smtp_fallback_relay ($fallback_relay)
Optional list of relay hosts for SMTP destinations
that can't be found or that are unreachable.
SEE ALSO
generic(5), output address rewriting
header_checks(5), message header content inspection
body_checks(5), body parts content inspection
qmgr(8), queue manager
bounce(8), delivery status reports
scache(8), connection cache server
postconf(5), configuration parameters
master(5), generic daemon options
master(8), process manager
tlsmgr(8), TLS session and PRNG management
syslogd(8), system logging
README FILES
SASL_README, Postfix SASL howto
TLS_README, Postfix STARTTLS howto
LICENSE
The Secure Mailer license must be distributed with this
software.
AUTHOR(S)
Wietse Venema
IBM T.J. Watson Research
P.O. Box 704
Yorktown Heights, NY 10598, USA
Command pipelining in cooperation with:
Jon Ribbens
Oaktree Internet Solutions Ltd.,
Internet House,
Canal Basin,
Coventry,
CV1 4LY, United Kingdom.
SASL support originally by:
Till Franke
SuSE Rhein/Main AG
65760 Eschborn, Germany
TLS support originally by:
Lutz Jaenicke
BTU Cottbus
Allgemeine Elektrotechnik
Universitaetsplatz 3-4
D-03044 Cottbus, Germany
Revised TLS and SMTP connection cache support by:
Victor Duchovni
Morgan Stanley
SMTP(8)
@
1.1.1.1.2.1
log
@file lmtp.8.html was added on branch netbsd-5 on 2009-09-15 06:02:14 +0000
@
text
@d1 863
@
1.1.1.1.2.2
log
@Apply patch (requested by tron in ticket #944):
Update Postfix to 2.6.5.
@
text
@a0 863
SMTP(8) SMTP(8)
NAME
smtp - Postfix SMTP+LMTP client
SYNOPSIS
smtp [generic Postfix daemon options]
DESCRIPTION
The Postfix SMTP+LMTP client implements the SMTP and LMTP
mail delivery protocols. It processes message delivery
requests from the queue manager. Each request specifies a
queue file, a sender address, a domain or host to deliver
to, and recipient information. This program expects to be
run from the master(8) process manager.
The SMTP+LMTP client updates the queue file and marks
recipients as finished, or it informs the queue manager
that delivery should be tried again at a later time.
Delivery status reports are sent to the bounce(8),
defer(8) or trace(8) daemon as appropriate.
The SMTP+LMTP client looks up a list of mail exchanger
addresses for the destination host, sorts the list by
preference, and connects to each listed address until it
finds a server that responds.
When a server is not reachable, or when mail delivery
fails due to a recoverable error condition, the SMTP+LMTP
client will try to deliver the mail to an alternate host.
After a successful mail transaction, a connection may be
saved to the scache(8) connection cache server, so that it
may be used by any SMTP+LMTP client for a subsequent
transaction.
By default, connection caching is enabled temporarily for
destinations that have a high volume of mail in the active
queue. Connection caching can be enabled permanently for
specific destinations.
SMTP DESTINATION SYNTAX
SMTP destinations have the following form:
domainname
domainname:port
Look up the mail exchangers for the specified
domain, and connect to the specified port (default:
smtp).
[hostname]
[hostname]:port
Look up the address(es) of the specified host, and
connect to the specified port (default: smtp).
[address]
[address]:port
Connect to the host at the specified address, and
connect to the specified port (default: smtp). An
IPv6 address must be formatted as [ipv6:address].
LMTP DESTINATION SYNTAX
LMTP destinations have the following form:
unix:pathname
Connect to the local UNIX-domain server that is
bound to the specified pathname. If the process
runs chrooted, an absolute pathname is interpreted
relative to the Postfix queue directory.
inet:hostname
inet:hostname:port
inet:[address]
inet:[address]:port
Connect to the specified TCP port on the specified
local or remote host. If no port is specified, con-
nect to the port defined as lmtp in services(4).
If no such service is found, the lmtp_tcp_port con-
figuration parameter (default value of 24) will be
used. An IPv6 address must be formatted as
[ipv6:address].
SECURITY
The SMTP+LMTP client is moderately security-sensitive. It
talks to SMTP or LMTP servers and to DNS servers on the
network. The SMTP+LMTP client can be run chrooted at fixed
low privilege.
STANDARDS
RFC 821 (SMTP protocol)
RFC 822 (ARPA Internet Text Messages)
RFC 1651 (SMTP service extensions)
RFC 1652 (8bit-MIME transport)
RFC 1870 (Message Size Declaration)
RFC 2033 (LMTP protocol)
RFC 2034 (SMTP Enhanced Error Codes)
RFC 2045 (MIME: Format of Internet Message Bodies)
RFC 2046 (MIME: Media Types)
RFC 2554 (AUTH command)
RFC 2821 (SMTP protocol)
RFC 2920 (SMTP Pipelining)
RFC 3207 (STARTTLS command)
RFC 3461 (SMTP DSN Extension)
RFC 3463 (Enhanced Status Codes)
RFC 4954 (AUTH command)
DIAGNOSTICS
Problems and transactions are logged to syslogd(8). Cor-
rupted message files are marked so that the queue manager
can move them to the corrupt queue for further inspection.
Depending on the setting of the notify_classes parameter,
the postmaster is notified of bounces, protocol problems,
and of other trouble.
BUGS
SMTP and LMTP connection caching does not work with TLS.
The necessary support for TLS object passivation and re-
activation does not exist without closing the session,
which defeats the purpose.
SMTP and LMTP connection caching assumes that SASL creden-
tials are valid for all destinations that map onto the
same IP address and TCP port.
CONFIGURATION PARAMETERS
Before Postfix version 2.3, the LMTP client is a separate
program that implements only a subset of the functionality
available with SMTP: there is no support for TLS, and con-
nections are cached in-process, making it ineffective when
the client is used for multiple domains.
Most smtp_xxx configuration parameters have an lmtp_xxx
"mirror" parameter for the equivalent LMTP feature. This
document describes only those LMTP-related parameters that
aren't simply "mirror" parameters.
Changes to main.cf are picked up automatically, as smtp(8)
processes run for only a limited amount of time. Use the
command "postfix reload" to speed up a change.
The text below provides only a parameter summary. See
postconf(5) for more details including examples.
COMPATIBILITY CONTROLS
ignore_mx_lookup_error (no)
Ignore DNS MX lookups that produce no response.
smtp_always_send_ehlo (yes)
Always send EHLO at the start of an SMTP session.
smtp_never_send_ehlo (no)
Never send EHLO at the start of an SMTP session.
smtp_defer_if_no_mx_address_found (no)
Defer mail delivery when no MX record resolves to
an IP address.
smtp_line_length_limit (990)
The maximal length of message header and body lines
that Postfix will send via SMTP.
smtp_pix_workaround_delay_time (10s)
How long the Postfix SMTP client pauses before
sending ".<CR><LF>" in order to work around the PIX
firewall "<CR><LF>.<CR><LF>" bug.
smtp_pix_workaround_threshold_time (500s)
How long a message must be queued before the Post-
fix SMTP client turns on the PIX firewall
"<CR><LF>.<CR><LF>" bug workaround for delivery
through firewalls with "smtp fixup" mode turned on.
smtp_pix_workarounds (disable_esmtp, delay_dotcrlf)
A list that specifies zero or more workarounds for
CISCO PIX firewall bugs.
smtp_pix_workaround_maps (empty)
Lookup tables, indexed by the remote SMTP server
address, with per-destination workarounds for CISCO
PIX firewall bugs.
smtp_quote_rfc821_envelope (yes)
Quote addresses in SMTP MAIL FROM and RCPT TO com-
mands as required by RFC 2821.
smtp_skip_5xx_greeting (yes)
Skip SMTP servers that greet with a 5XX status code
(go away, do not try again later).
smtp_skip_quit_response (yes)
Do not wait for the response to the SMTP QUIT com-
mand.
Available in Postfix version 2.0 and earlier:
smtp_skip_4xx_greeting (yes)
Skip SMTP servers that greet with a 4XX status code
(go away, try again later).
Available in Postfix version 2.2 and later:
smtp_discard_ehlo_keyword_address_maps (empty)
Lookup tables, indexed by the remote SMTP server
address, with case insensitive lists of EHLO key-
words (pipelining, starttls, auth, etc.) that the
Postfix SMTP client will ignore in the EHLO
response from a remote SMTP server.
smtp_discard_ehlo_keywords (empty)
A case insensitive list of EHLO keywords (pipelin-
ing, starttls, auth, etc.) that the Postfix SMTP
client will ignore in the EHLO response from a
remote SMTP server.
smtp_generic_maps (empty)
Optional lookup tables that perform address rewrit-
ing in the SMTP client, typically to transform a
locally valid address into a globally valid address
when sending mail across the Internet.
Available in Postfix version 2.2.9 and later:
smtp_cname_overrides_servername (version dependent)
Allow DNS CNAME records to override the servername
that the Postfix SMTP client uses for logging, SASL
password lookup, TLS policy decisions, or TLS cer-
tificate verification.
Available in Postfix version 2.3 and later:
lmtp_discard_lhlo_keyword_address_maps (empty)
Lookup tables, indexed by the remote LMTP server
address, with case insensitive lists of LHLO key-
words (pipelining, starttls, auth, etc.) that the
LMTP client will ignore in the LHLO response from a
remote LMTP server.
lmtp_discard_lhlo_keywords (empty)
A case insensitive list of LHLO keywords (pipelin-
ing, starttls, auth, etc.) that the LMTP client
will ignore in the LHLO response from a remote LMTP
server.
Available in Postfix version 2.4.4 and later:
send_cyrus_sasl_authzid (no)
When authenticating to a remote SMTP or LMTP server
with the default setting "no", send no SASL autho-
riZation ID (authzid); send only the SASL authenti-
Cation ID (authcid) plus the authcid's password.
Available in Postfix version 2.5 and later:
smtp_header_checks (empty)
Restricted header_checks(5) tables for the Postfix
SMTP client.
smtp_mime_header_checks (empty)
Restricted mime_header_checks(5) tables for the
Postfix SMTP client.
smtp_nested_header_checks (empty)
Restricted nested_header_checks(5) tables for the
Postfix SMTP client.
smtp_body_checks (empty)
Restricted body_checks(5) tables for the Postfix
SMTP client.
Available in Postfix version 2.6 and later:
tcp_windowsize (0)
An optional workaround for routers that break TCP
window scaling.
MIME PROCESSING CONTROLS
Available in Postfix version 2.0 and later:
disable_mime_output_conversion (no)
Disable the conversion of 8BITMIME format to 7BIT
format.
mime_boundary_length_limit (2048)
The maximal length of MIME multipart boundary
strings.
mime_nesting_limit (100)
The maximal recursion level that the MIME processor
will handle.
EXTERNAL CONTENT INSPECTION CONTROLS
Available in Postfix version 2.1 and later:
smtp_send_xforward_command (no)
Send the non-standard XFORWARD command when the
Postfix SMTP server EHLO response announces XFOR-
WARD support.
SASL AUTHENTICATION CONTROLS
smtp_sasl_auth_enable (no)
Enable SASL authentication in the Postfix SMTP
client.
smtp_sasl_password_maps (empty)
Optional SMTP client lookup tables with one user-
name:password entry per remote hostname or domain,
or sender address when sender-dependent authentica-
tion is enabled.
smtp_sasl_security_options (noplaintext, noanonymous)
Postfix SMTP client SASL security options; as of
Postfix 2.3 the list of available features depends
on the SASL client implementation that is selected
with smtp_sasl_type.
Available in Postfix version 2.2 and later:
smtp_sasl_mechanism_filter (empty)
If non-empty, a Postfix SMTP client filter for the
remote SMTP server's list of offered SASL mecha-
nisms.
Available in Postfix version 2.3 and later:
smtp_sender_dependent_authentication (no)
Enable sender-dependent authentication in the Post-
fix SMTP client; this is available only with SASL
authentication, and disables SMTP connection
caching to ensure that mail from different senders
will use the appropriate credentials.
smtp_sasl_path (empty)
Implementation-specific information that the Post-
fix SMTP client passes through to the SASL plug-in
implementation that is selected with
smtp_sasl_type.
smtp_sasl_type (cyrus)
The SASL plug-in type that the Postfix SMTP client
should use for authentication.
Available in Postfix version 2.5 and later:
smtp_sasl_auth_cache_name (empty)
An optional table to prevent repeated SASL authen-
tication failures with the same remote SMTP server
hostname, username and password.
smtp_sasl_auth_cache_time (90d)
The maximal age of an smtp_sasl_auth_cache_name
entry before it is removed.
smtp_sasl_auth_soft_bounce (yes)
When a remote SMTP server rejects a SASL authenti-
cation request with a 535 reply code, defer mail
delivery instead of returning mail as undeliver-
able.
STARTTLS SUPPORT CONTROLS
Detailed information about STARTTLS configuration may be
found in the TLS_README document.
smtp_tls_security_level (empty)
The default SMTP TLS security level for the Postfix
SMTP client; when a non-empty value is specified,
this overrides the obsolete parameters
smtp_use_tls, smtp_enforce_tls, and
smtp_tls_enforce_peername.
smtp_sasl_tls_security_options ($smtp_sasl_secu-
rity_options)
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
sessions.
smtp_starttls_timeout (300s)
Time limit for Postfix SMTP client write and read
operations during TLS startup and shutdown hand-
shake procedures.
smtp_tls_CAfile (empty)
A file containing CA certificates of root CAs
trusted to sign either remote SMTP server certifi-
cates or intermediate CA certificates.
smtp_tls_CApath (empty)
Directory with PEM format certificate authority
certificates that the Postfix SMTP client uses to
verify a remote SMTP server certificate.
smtp_tls_cert_file (empty)
File with the Postfix SMTP client RSA certificate
in PEM format.
smtp_tls_mandatory_ciphers (medium)
The minimum TLS cipher grade that the Postfix SMTP
client will use with mandatory TLS encryption.
smtp_tls_exclude_ciphers (empty)
List of ciphers or cipher types to exclude from the
Postfix SMTP client cipher list at all TLS security
levels.
smtp_tls_mandatory_exclude_ciphers (empty)
Additional list of ciphers or cipher types to
exclude from the SMTP client cipher list at manda-
tory TLS security levels.
smtp_tls_dcert_file (empty)
File with the Postfix SMTP client DSA certificate
in PEM format.
smtp_tls_dkey_file ($smtp_tls_dcert_file)
File with the Postfix SMTP client DSA private key
in PEM format.
smtp_tls_key_file ($smtp_tls_cert_file)
File with the Postfix SMTP client RSA private key
in PEM format.
smtp_tls_loglevel (0)
Enable additional Postfix SMTP client logging of
TLS activity.
smtp_tls_note_starttls_offer (no)
Log the hostname of a remote SMTP server that
offers STARTTLS, when TLS is not already enabled
for that server.
smtp_tls_policy_maps (empty)
Optional lookup tables with the Postfix SMTP client
TLS security policy by next-hop destination; when a
non-empty value is specified, this overrides the
obsolete smtp_tls_per_site parameter.
smtp_tls_mandatory_protocols (SSLv3, TLSv1)
List of SSL/TLS protocols that the Postfix SMTP
client will use with mandatory TLS encryption.
smtp_tls_scert_verifydepth (9)
The verification depth for remote SMTP server cer-
tificates.
smtp_tls_secure_cert_match (nexthop, dot-nexthop)
The server certificate peername verification method
for the "secure" TLS security level.
smtp_tls_session_cache_database (empty)
Name of the file containing the optional Postfix
SMTP client TLS session cache.
smtp_tls_session_cache_timeout (3600s)
The expiration time of Postfix SMTP client TLS ses-
sion cache information.
smtp_tls_verify_cert_match (hostname)
The server certificate peername verification method
for the "verify" TLS security level.
tls_daemon_random_bytes (32)
The number of pseudo-random bytes that an smtp(8)
or smtpd(8) process requests from the tlsmgr(8)
server in order to seed its internal pseudo random
number generator (PRNG).
tls_high_cipherlist
(ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "HIGH" grade ciphers.
tls_medium_cipherlist (ALL:!EXPORT:!LOW:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "MEDIUM" or higher grade
ciphers.
tls_low_cipherlist (ALL:!EXPORT:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "LOW" or higher grade
ciphers.
tls_export_cipherlist (ALL:+RC4:@@STRENGTH)
The OpenSSL cipherlist for "EXPORT" or higher grade
ciphers.
tls_null_cipherlist (eNULL:!aNULL)
The OpenSSL cipherlist for "NULL" grade ciphers
that provide authentication without encryption.
Available in Postfix version 2.4 and later:
smtp_sasl_tls_verified_security_options
($smtp_sasl_tls_security_options)
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
sessions with a verified server certificate.
Available in Postfix version 2.5 and later:
smtp_tls_fingerprint_cert_match (empty)
List of acceptable remote SMTP server certificate
fingerprints for the "fingerprint" TLS security
level (smtp_tls_security_level = fingerprint).
smtp_tls_fingerprint_digest (md5)
The message digest algorithm used to construct
remote SMTP server certificate fingerprints.
Available in Postfix version 2.6 and later:
smtp_tls_protocols (!SSLv2)
List of TLS protocols that the Postfix SMTP client
will exclude or include with opportunistic TLS
encryption.
smtp_tls_ciphers (export)
The minimum TLS cipher grade that the Postfix SMTP
client will use with opportunistic TLS encryption.
smtp_tls_eccert_file (empty)
File with the Postfix SMTP client ECDSA certificate
in PEM format.
smtp_tls_eckey_file ($smtp_tls_eccert_file)
File with the Postfix SMTP client ECDSA private key
in PEM format.
OBSOLETE STARTTLS CONTROLS
The following configuration parameters exist for compati-
bility with Postfix versions before 2.3. Support for these
will be removed in a future release.
smtp_use_tls (no)
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
the mail in the clear.
smtp_enforce_tls (no)
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
clear.
smtp_tls_enforce_peername (yes)
With mandatory TLS encryption, require that the
remote SMTP server hostname matches the information
in the remote SMTP server certificate.
smtp_tls_per_site (empty)
Optional lookup tables with the Postfix SMTP client
TLS usage policy by next-hop destination and by
remote SMTP server hostname.
smtp_tls_cipherlist (empty)
Obsolete Postfix < 2.3 control for the Postfix SMTP
client TLS cipher list.
RESOURCE AND RATE CONTROLS
smtp_destination_concurrency_limit ($default_destina-
tion_concurrency_limit)
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
transport.
smtp_destination_recipient_limit ($default_destina-
tion_recipient_limit)
The maximal number of recipients per message for
the smtp message delivery transport.
smtp_connect_timeout (30s)
The SMTP client time limit for completing a TCP
connection, or zero (use the operating system
built-in time limit).
smtp_helo_timeout (300s)
The SMTP client time limit for sending the HELO or
EHLO command, and for receiving the initial server
response.
lmtp_lhlo_timeout (300s)
The LMTP client time limit for sending the LHLO
command, and for receiving the initial server
response.
smtp_xforward_timeout (300s)
The SMTP client time limit for sending the XFORWARD
command, and for receiving the server response.
smtp_mail_timeout (300s)
The SMTP client time limit for sending the MAIL
FROM command, and for receiving the server
response.
smtp_rcpt_timeout (300s)
The SMTP client time limit for sending the SMTP
RCPT TO command, and for receiving the server
response.
smtp_data_init_timeout (120s)
The SMTP client time limit for sending the SMTP
DATA command, and for receiving the server
response.
smtp_data_xfer_timeout (180s)
The SMTP client time limit for sending the SMTP
message content.
smtp_data_done_timeout (600s)
The SMTP client time limit for sending the SMTP
".", and for receiving the server response.
smtp_quit_timeout (300s)
The SMTP client time limit for sending the QUIT
command, and for receiving the server response.
Available in Postfix version 2.1 and later:
smtp_mx_address_limit (5)
The maximal number of MX (mail exchanger) IP
addresses that can result from mail exchanger
lookups, or zero (no limit).
smtp_mx_session_limit (2)
The maximal number of SMTP sessions per delivery
request before giving up or delivering to a fall-
back relay host, or zero (no limit).
smtp_rset_timeout (20s)
The SMTP client time limit for sending the RSET
command, and for receiving the server response.
Available in Postfix version 2.2 and earlier:
lmtp_cache_connection (yes)
Keep Postfix LMTP client connections open for up to
$max_idle seconds.
Available in Postfix version 2.2 and later:
smtp_connection_cache_destinations (empty)
Permanently enable SMTP connection caching for the
specified destinations.
smtp_connection_cache_on_demand (yes)
Temporarily enable SMTP connection caching while a
destination has a high volume of mail in the active
queue.
smtp_connection_reuse_time_limit (300s)
The amount of time during which Postfix will use an
SMTP connection repeatedly.
smtp_connection_cache_time_limit (2s)
When SMTP connection caching is enabled, the amount
of time that an unused SMTP client socket is kept
open before it is closed.
Available in Postfix version 2.3 and later:
connection_cache_protocol_timeout (5s)
Time limit for connection cache connect, send or
receive operations.
TROUBLE SHOOTING CONTROLS
debug_peer_level (2)
The increment in verbose logging level when a
remote client or server matches a pattern in the
debug_peer_list parameter.
debug_peer_list (empty)
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
in $debug_peer_level.
error_notice_recipient (postmaster)
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
resource, software or protocol errors.
internal_mail_filter_classes (empty)
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
non_smtpd_milters, header_checks and body_checks.
notify_classes (resource, software)
The list of error classes that are reported to the
postmaster.
MISCELLANEOUS CONTROLS
best_mx_transport (empty)
Where the Postfix SMTP client should deliver mail
when it detects a "mail loops back to myself" error
condition.
config_directory (see 'postconf -d' output)
The default location of the Postfix main.cf and
master.cf configuration files.
daemon_timeout (18000s)
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
built-in watchdog timer.
delay_logging_resolution_limit (2)
The maximal number of digits after the decimal
point when logging sub-second delay values.
disable_dns_lookups (no)
Disable DNS lookups in the Postfix SMTP and LMTP
clients.
inet_interfaces (all)
The network interface addresses that this mail sys-
tem receives mail on.
inet_protocols (ipv4)
The Internet protocols Postfix will attempt to use
when making or accepting connections.
ipc_timeout (3600s)
The time limit for sending or receiving information
over an internal communication channel.
lmtp_assume_final (no)
When an LMTP server announces no DSN support,
assume that the server performs final delivery, and
send "delivered" delivery status notifications
instead of "relayed".
lmtp_tcp_port (24)
The default TCP port that the Postfix LMTP client
connects to.
max_idle (100s)
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
before terminating voluntarily.
max_use (100)
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
nating voluntarily.
process_id (read-only)
The process ID of a Postfix command or daemon
process.
process_name (read-only)
The process name of a Postfix command or daemon
process.
proxy_interfaces (empty)
The network interface addresses that this mail sys-
tem receives mail on by way of a proxy or network
address translation unit.
smtp_bind_address (empty)
An optional numerical network address that the
Postfix SMTP client should bind to when making an
IPv4 connection.
smtp_bind_address6 (empty)
An optional numerical network address that the
Postfix SMTP client should bind to when making an
IPv6 connection.
smtp_helo_name ($myhostname)
The hostname to send in the SMTP EHLO or HELO com-
mand.
lmtp_lhlo_name ($myhostname)
The hostname to send in the LMTP LHLO command.
smtp_host_lookup (dns)
What mechanisms when the Postfix SMTP client uses
to look up a host's IP address.
smtp_randomize_addresses (yes)
Randomize the order of equal-preference MX host
addresses.
syslog_facility (mail)
The syslog facility of Postfix logging.
syslog_name (see 'postconf -d' output)
The mail system name that is prepended to the
process name in syslog records, so that "smtpd"
becomes, for example, "postfix/smtpd".
Available with Postfix 2.2 and earlier:
fallback_relay (empty)
Optional list of relay hosts for SMTP destinations
that can't be found or that are unreachable.
Available with Postfix 2.3 and later:
smtp_fallback_relay ($fallback_relay)
Optional list of relay hosts for SMTP destinations
that can't be found or that are unreachable.
SEE ALSO
generic(5), output address rewriting
header_checks(5), message header content inspection
body_checks(5), body parts content inspection
qmgr(8), queue manager
bounce(8), delivery status reports
scache(8), connection cache server
postconf(5), configuration parameters
master(5), generic daemon options
master(8), process manager
tlsmgr(8), TLS session and PRNG management
syslogd(8), system logging
README FILES
SASL_README, Postfix SASL howto
TLS_README, Postfix STARTTLS howto
LICENSE
The Secure Mailer license must be distributed with this
software.
AUTHOR(S)
Wietse Venema
IBM T.J. Watson Research
P.O. Box 704
Yorktown Heights, NY 10598, USA
Command pipelining in cooperation with:
Jon Ribbens
Oaktree Internet Solutions Ltd.,
Internet House,
Canal Basin,
Coventry,
CV1 4LY, United Kingdom.
SASL support originally by:
Till Franke
SuSE Rhein/Main AG
65760 Eschborn, Germany
TLS support originally by:
Lutz Jaenicke
BTU Cottbus
Allgemeine Elektrotechnik
Universitaetsplatz 3-4
D-03044 Cottbus, Germany
Revised TLS and SMTP connection cache support by:
Victor Duchovni
Morgan Stanley
SMTP(8)
@
1.1.1.1.2.3
log
@Pull up following revision(s) (requested by tron in ticket #1425):
Update Postfix to version 2.7.1:
- Improved before-queue content filter performance. With
"smtpd_proxy_options = speed_adjust", the Postfix SMTP server
receives the entire message before it connects to a before-queue
content filter. Typically, this allows Postfix to handle the same
mail load with fewer content filter processes.
- Improved address verification performance. The verify database is now
persistent by default, and it is automatically cleaned periodically.
Under overload conditions, the Postfix SMTP server no longer waits
up to 6 seconds for an address probe to complete.
- Support for reputation management based on the local SMTP client
IP address. This is typically implemented with
"FILTER transportname:" actions in access maps or header/body checks,
and mail delivery transports in master.cf with
unique smtp_bind_address values.
@
text
@a198 4
smtp_reply_filter (empty)
A mechanism to transform replies from remote SMTP
servers one line at a time.
d204 1
a204 1
Do not wait for the response to the SMTP QUIT com-
d216 4
a219 4
Lookup tables, indexed by the remote SMTP server
address, with case insensitive lists of EHLO key-
words (pipelining, starttls, auth, etc.) that the
Postfix SMTP client will ignore in the EHLO
d223 3
a225 3
A case insensitive list of EHLO keywords (pipelin-
ing, starttls, auth, etc.) that the Postfix SMTP
client will ignore in the EHLO response from a
d230 1
a230 1
ing in the SMTP client, typically to transform a
d237 1
a237 1
Allow DNS CNAME records to override the servername
d239 1
a239 1
password lookup, TLS policy decisions, or TLS cer-
d245 3
a247 3
Lookup tables, indexed by the remote LMTP server
address, with case insensitive lists of LHLO key-
words (pipelining, starttls, auth, etc.) that the
d252 2
a253 2
A case insensitive list of LHLO keywords (pipelin-
ing, starttls, auth, etc.) that the LMTP client
d261 1
a261 1
with the default setting "no", send no SASL autho-
d268 1
a268 1
Restricted header_checks(5) tables for the Postfix
d276 1
a276 1
Restricted nested_header_checks(5) tables for the
d280 1
a280 1
Restricted body_checks(5) tables for the Postfix
d286 1
a286 1
An optional workaround for routers that break TCP
d293 1
a293 1
Disable the conversion of 8BITMIME format to 7BIT
d308 2
a309 2
Send the non-standard XFORWARD command when the
Postfix SMTP server EHLO response announces XFOR-
d314 1
a314 1
Enable SASL authentication in the Postfix SMTP
d318 2
a319 2
Optional SMTP client lookup tables with one user-
name:password entry per remote hostname or domain,
d324 3
a326 3
Postfix SMTP client SASL security options; as of
Postfix 2.3 the list of available features depends
on the SASL client implementation that is selected
d332 2
a333 2
If non-empty, a Postfix SMTP client filter for the
remote SMTP server's list of offered SASL mecha-
d340 3
a342 3
fix SMTP client; this is available only with SASL
authentication, and disables SMTP connection
caching to ensure that mail from different senders
d346 3
a348 3
Implementation-specific information that the Post-
fix SMTP client passes through to the SASL plug-in
implementation that is selected with
d352 1
a352 1
The SASL plug-in type that the Postfix SMTP client
d358 2
a359 2
An optional table to prevent repeated SASL authen-
tication failures with the same remote SMTP server
d363 1
a363 1
The maximal age of an smtp_sasl_auth_cache_name
d367 3
a369 3
When a remote SMTP server rejects a SASL authenti-
cation request with a 535 reply code, defer mail
delivery instead of returning mail as undeliver-
d373 1
a373 1
Detailed information about STARTTLS configuration may be
d378 2
a379 2
SMTP client; when a non-empty value is specified,
this overrides the obsolete parameters
d385 2
a386 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d390 2
a391 2
Time limit for Postfix SMTP client write and read
operations during TLS startup and shutdown hand-
d395 2
a396 2
A file containing CA certificates of root CAs
trusted to sign either remote SMTP server certifi-
d400 2
a401 2
Directory with PEM format certificate authority
certificates that the Postfix SMTP client uses to
d405 1
a405 1
File with the Postfix SMTP client RSA certificate
d409 1
a409 1
The minimum TLS cipher grade that the Postfix SMTP
d418 2
a419 2
Additional list of ciphers or cipher types to
exclude from the SMTP client cipher list at manda-
d423 1
a423 1
File with the Postfix SMTP client DSA certificate
d427 1
a427 1
File with the Postfix SMTP client DSA private key
d431 1
a431 1
File with the Postfix SMTP client RSA private key
d435 1
a435 1
Enable additional Postfix SMTP client logging of
d439 2
a440 2
Log the hostname of a remote SMTP server that
offers STARTTLS, when TLS is not already enabled
d446 1
a446 1
non-empty value is specified, this overrides the
d450 1
a450 1
List of SSL/TLS protocols that the Postfix SMTP
d454 1
a454 1
The verification depth for remote SMTP server cer-
d462 1
a462 1
Name of the file containing the optional Postfix
d474 3
a476 3
The number of pseudo-random bytes that an smtp(8)
or smtpd(8) process requests from the tlsmgr(8)
server in order to seed its internal pseudo random
d488 1
a488 1
The OpenSSL cipherlist for "LOW" or higher grade
d496 1
a496 1
The OpenSSL cipherlist for "NULL" grade ciphers
d503 2
a504 2
The SASL authentication security options that the
Postfix SMTP client uses for TLS encrypted SMTP
d510 2
a511 2
List of acceptable remote SMTP server certificate
fingerprints for the "fingerprint" TLS security
d515 1
a515 1
The message digest algorithm used to construct
d521 2
a522 2
List of TLS protocols that the Postfix SMTP client
will exclude or include with opportunistic TLS
d526 2
a527 2
The minimum TLS cipher grade that the Postfix SMTP
client will use with opportunistic TLS encryption.
a536 8
Available in Postfix version 2.7 and later:
smtp_tls_block_early_mail_reply (no)
Try to detect a mail hijacking attack based on a
TLS protocol vulnerability (CVE-2009-3555), where
an attacker prepends malicious HELO, MAIL, RCPT,
DATA commands to a Postfix SMTP client TLS session.
d538 1
a538 1
The following configuration parameters exist for compati-
d543 2
a544 2
Opportunistic mode: use TLS when a remote SMTP
server announces STARTTLS support, otherwise send
d548 2
a549 2
Enforcement mode: require that remote SMTP servers
use TLS encryption, and never send mail in the
d553 1
a553 1
With mandatory TLS encryption, require that the
d559 1
a559 1
TLS usage policy by next-hop destination and by
d569 2
a570 2
The maximal number of parallel deliveries to the
same destination via the smtp message delivery
d575 1
a575 1
The maximal number of recipients per message for
d579 1
a579 1
The SMTP client time limit for completing a TCP
d584 2
a585 2
The SMTP client time limit for sending the HELO or
EHLO command, and for receiving the initial server
d589 1
a589 1
The LMTP client time limit for sending the LHLO
d598 2
a599 2
The SMTP client time limit for sending the MAIL
FROM command, and for receiving the server
d603 2
a604 2
The SMTP client time limit for sending the SMTP
RCPT TO command, and for receiving the server
d608 2
a609 2
The SMTP client time limit for sending the SMTP
DATA command, and for receiving the server
d613 1
a613 1
The SMTP client time limit for sending the SMTP
d617 1
a617 1
The SMTP client time limit for sending the SMTP
d621 1
a621 1
The SMTP client time limit for sending the QUIT
d632 2
a633 2
The maximal number of SMTP sessions per delivery
request before giving up or delivering to a fall-
d637 1
a637 1
The SMTP client time limit for sending the RSET
d649 1
a649 1
Permanently enable SMTP connection caching for the
d653 1
a653 1
Temporarily enable SMTP connection caching while a
d663 1
a663 1
of time that an unused SMTP client socket is kept
d669 1
a669 1
Time limit for connection cache connect, send or
d674 2
a675 2
The increment in verbose logging level when a
remote client or server matches a pattern in the
d679 3
a681 3
Optional list of remote client or server hostname
or network address patterns that cause the verbose
logging level to increase by the amount specified
d685 2
a686 2
The recipient of postmaster notifications about
mail delivery problems that are caused by policy,
d690 2
a691 2
What categories of Postfix-generated mail are sub-
ject to before-queue content inspection by
d695 1
a695 1
The list of error classes that are reported to the
d700 1
a700 1
Where the Postfix SMTP client should deliver mail
d705 1
a705 1
The default location of the Postfix main.cf and
d709 2
a710 2
How much time a Postfix daemon process may take to
handle a request before it is terminated by a
d714 1
a714 1
The maximal number of digits after the decimal
d718 1
a718 1
Disable DNS lookups in the Postfix SMTP and LMTP
d726 1
a726 1
The Internet protocols Postfix will attempt to use
d734 1
a734 1
When an LMTP server announces no DSN support,
d736 1
a736 1
send "delivered" delivery status notifications
d740 1
a740 1
The default TCP port that the Postfix LMTP client
d744 2
a745 2
The maximum amount of time that an idle Postfix
daemon process waits for an incoming connection
d749 2
a750 2
The maximal number of incoming connections that a
Postfix daemon process will service before termi-
d754 1
a754 1
The process ID of a Postfix command or daemon
d758 1
a758 1
The process name of a Postfix command or daemon
d763 1
a763 1
tem receives mail on by way of a proxy or network
d767 2
a768 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d772 2
a773 2
An optional numerical network address that the
Postfix SMTP client should bind to when making an
d777 1
a777 1
The hostname to send in the SMTP EHLO or HELO com-
d784 2
a785 2
What mechanisms the Postfix SMTP client uses to
look up a host's IP address.
d788 1
a788 1
Randomize the order of equal-preference MX host
d795 2
a796 2
The mail system name that is prepended to the
process name in syslog records, so that "smtpd"
d802 1
a802 1
Optional list of relay hosts for SMTP destinations
d808 1
a808 1
Optional list of relay hosts for SMTP destinations
d829 1
a829 1
The Secure Mailer license must be distributed with this
@