head 1.1; branch 1.1.1; access; symbols netbsd-10-2-RELEASE:1.1.1.11.2.1 netbsd-9-5-RELEASE:1.1.1.9.14.1 netbsd-11-0-RELEASE:1.1.1.13.2.1 netbsd-11-0-RC7:1.1.1.13.2.1 netbsd-11-0-RC6:1.1.1.13.2.1 netbsd-11-0-RC5:1.1.1.13.2.1 netbsd-11-0-RC4:1.1.1.13.2.1 PFIX-3-11-2:1.1.1.14 netbsd-11-0-RC3:1.1.1.13 netbsd-11-0-RC2:1.1.1.13 netbsd-11-0-RC1:1.1.1.13 perseant-exfatfs-base-20250801:1.1.1.13 netbsd-11:1.1.1.13.0.2 netbsd-11-base:1.1.1.13 PFIX-3-10-1:1.1.1.13 netbsd-10-1-RELEASE:1.1.1.11.2.1 perseant-exfatfs-base-20240630:1.1.1.12 perseant-exfatfs:1.1.1.12.0.2 perseant-exfatfs-base:1.1.1.12 netbsd-8-3-RELEASE:1.1.1.9 netbsd-9-4-RELEASE:1.1.1.9.14.1 netbsd-10-0-RELEASE:1.1.1.11.2.1 netbsd-10-0-RC6:1.1.1.11.2.1 netbsd-10-0-RC5:1.1.1.11.2.1 netbsd-10-0-RC4:1.1.1.11.2.1 netbsd-10-0-RC3:1.1.1.11.2.1 netbsd-10-0-RC2:1.1.1.11.2.1 PFIX-3-8-4:1.1.1.12 netbsd-10-0-RC1:1.1.1.11 netbsd-10:1.1.1.11.0.2 netbsd-10-base:1.1.1.11 PFIX-3-7-3:1.1.1.11 netbsd-9-3-RELEASE:1.1.1.9 cjep_sun2x-base1:1.1.1.10 cjep_sun2x:1.1.1.10.0.4 cjep_sun2x-base:1.1.1.10 cjep_staticlib_x-base1:1.1.1.10 netbsd-9-2-RELEASE:1.1.1.9 cjep_staticlib_x:1.1.1.10.0.2 cjep_staticlib_x-base:1.1.1.10 netbsd-9-1-RELEASE:1.1.1.9 PFIX-3-5-2:1.1.1.10 phil-wifi-20200421:1.1.1.10 phil-wifi-20200411:1.1.1.10 is-mlppp:1.1.1.9.0.16 is-mlppp-base:1.1.1.9 phil-wifi-20200406:1.1.1.10 netbsd-8-2-RELEASE:1.1.1.9 PFIX-3-5-0:1.1.1.10 netbsd-9-0-RELEASE:1.1.1.9 netbsd-9-0-RC2:1.1.1.9 netbsd-9-0-RC1:1.1.1.9 phil-wifi-20191119:1.1.1.9 netbsd-9:1.1.1.9.0.14 netbsd-9-base:1.1.1.9 phil-wifi-20190609:1.1.1.9 netbsd-8-1-RELEASE:1.1.1.9 netbsd-8-1-RC1:1.1.1.9 pgoyette-compat-merge-20190127:1.1.1.9 pgoyette-compat-20190127:1.1.1.9 pgoyette-compat-20190118:1.1.1.9 pgoyette-compat-1226:1.1.1.9 pgoyette-compat-1126:1.1.1.9 pgoyette-compat-1020:1.1.1.9 pgoyette-compat-0930:1.1.1.9 pgoyette-compat-0906:1.1.1.9 netbsd-7-2-RELEASE:1.1.1.7 pgoyette-compat-0728:1.1.1.9 netbsd-8-0-RELEASE:1.1.1.9 phil-wifi:1.1.1.9.0.12 phil-wifi-base:1.1.1.9 pgoyette-compat-0625:1.1.1.9 netbsd-8-0-RC2:1.1.1.9 pgoyette-compat-0521:1.1.1.9 pgoyette-compat-0502:1.1.1.9 pgoyette-compat-0422:1.1.1.9 netbsd-8-0-RC1:1.1.1.9 pgoyette-compat-0415:1.1.1.9 pgoyette-compat-0407:1.1.1.9 pgoyette-compat-0330:1.1.1.9 pgoyette-compat-0322:1.1.1.9 pgoyette-compat-0315:1.1.1.9 netbsd-7-1-2-RELEASE:1.1.1.7 pgoyette-compat:1.1.1.9.0.10 pgoyette-compat-base:1.1.1.9 netbsd-7-1-1-RELEASE:1.1.1.7 matt-nb8-mediatek:1.1.1.9.0.8 matt-nb8-mediatek-base:1.1.1.9 perseant-stdc-iso10646:1.1.1.9.0.6 perseant-stdc-iso10646-base:1.1.1.9 netbsd-8:1.1.1.9.0.4 netbsd-8-base:1.1.1.9 prg-localcount2-base3:1.1.1.9 prg-localcount2-base2:1.1.1.9 prg-localcount2-base1:1.1.1.9 prg-localcount2:1.1.1.9.0.2 prg-localcount2-base:1.1.1.9 pgoyette-localcount-20170426:1.1.1.9 bouyer-socketcan-base1:1.1.1.9 pgoyette-localcount-20170320:1.1.1.9 netbsd-7-1:1.1.1.7.0.8 netbsd-7-1-RELEASE:1.1.1.7 netbsd-7-1-RC2:1.1.1.7 PFIX-3-1-4:1.1.1.9 netbsd-7-nhusb-base-20170116:1.1.1.7 bouyer-socketcan:1.1.1.8.0.4 bouyer-socketcan-base:1.1.1.8 pgoyette-localcount-20170107:1.1.1.8 netbsd-7-1-RC1:1.1.1.7 pgoyette-localcount-20161104:1.1.1.8 netbsd-7-0-2-RELEASE:1.1.1.7 localcount-20160914:1.1.1.8 netbsd-7-nhusb:1.1.1.7.0.6 netbsd-7-nhusb-base:1.1.1.7 pgoyette-localcount-20160806:1.1.1.8 pgoyette-localcount-20160726:1.1.1.8 pgoyette-localcount:1.1.1.8.0.2 pgoyette-localcount-base:1.1.1.8 netbsd-7-0-1-RELEASE:1.1.1.7 netbsd-7-0:1.1.1.7.0.4 netbsd-7-0-RELEASE:1.1.1.7 PFIX-2-11-6:1.1.1.8 netbsd-7-0-RC3:1.1.1.7 netbsd-7-0-RC2:1.1.1.7 netbsd-7-0-RC1:1.1.1.7 PFIX-2-11-4:1.1.1.7 PFIX-2-11-3:1.1.1.7 netbsd-5-2-3-RELEASE:1.1.1.1.2.3 netbsd-5-1-5-RELEASE:1.1.1.1.2.2 netbsd-6-0-6-RELEASE:1.1.1.3.6.1 netbsd-6-1-5-RELEASE:1.1.1.3.6.1 netbsd-7:1.1.1.7.0.2 netbsd-7-base:1.1.1.7 PFIX-2-11-1:1.1.1.7 yamt-pagecache-base9:1.1.1.6 yamt-pagecache-tag8:1.1.1.3.4.2 netbsd-6-1-4-RELEASE:1.1.1.3.6.1 netbsd-6-0-5-RELEASE:1.1.1.3.6.1 tls-earlyentropy:1.1.1.6.0.2 tls-earlyentropy-base:1.1.1.7 riastradh-xf86-video-intel-2-7-1-pre-2-21-15:1.1.1.6 riastradh-drm2-base3:1.1.1.6 PFIX-2-10-3:1.1.1.6 netbsd-6-1-3-RELEASE:1.1.1.3.6.1 netbsd-6-0-4-RELEASE:1.1.1.3.6.1 netbsd-5-2-2-RELEASE:1.1.1.1.2.3 netbsd-5-1-4-RELEASE:1.1.1.1.2.2 netbsd-6-1-2-RELEASE:1.1.1.3.6.1 netbsd-6-0-3-RELEASE:1.1.1.3.6.1 PFIX-2-10-2:1.1.1.6 netbsd-5-2-1-RELEASE:1.1.1.1.2.3 netbsd-5-1-3-RELEASE:1.1.1.1.2.2 PFIX-2-9-7:1.1.1.5 netbsd-6-1-1-RELEASE:1.1.1.3.6.1 riastradh-drm2-base2:1.1.1.5 riastradh-drm2-base1:1.1.1.5 riastradh-drm2:1.1.1.5.0.2 riastradh-drm2-base:1.1.1.5 netbsd-6-1:1.1.1.3.6.1.0.6 netbsd-6-0-2-RELEASE:1.1.1.3.6.1 netbsd-6-1-RELEASE:1.1.1.3.6.1 netbsd-6-1-RC4:1.1.1.3.6.1 netbsd-6-1-RC3:1.1.1.3.6.1 agc-symver:1.1.1.5.0.4 agc-symver-base:1.1.1.5 netbsd-6-1-RC2:1.1.1.3.6.1 netbsd-6-1-RC1:1.1.1.3.6.1 yamt-pagecache-base8:1.1.1.5 PFIX-2-9-5:1.1.1.5 netbsd-5-2:1.1.1.1.2.3.0.4 PFIX-2-8-13:1.1.1.4 netbsd-6-0-1-RELEASE:1.1.1.3.6.1 yamt-pagecache-base7:1.1.1.4 netbsd-5-2-RELEASE:1.1.1.1.2.3 netbsd-5-2-RC1:1.1.1.1.2.3 matt-nb6-plus-nbase:1.1.1.3.6.1 yamt-pagecache-base6:1.1.1.4 netbsd-6-0:1.1.1.3.6.1.0.4 netbsd-6-0-RELEASE:1.1.1.3.6.1 netbsd-6-0-RC2:1.1.1.3.6.1 tls-maxphys:1.1.1.4.0.2 tls-maxphys-base:1.1.1.7 matt-nb6-plus:1.1.1.3.6.1.0.2 matt-nb6-plus-base:1.1.1.3.6.1 netbsd-6-0-RC1:1.1.1.3.6.1 PFIX-2-8-12:1.1.1.4 PFIX-2-8-11:1.1.1.4 yamt-pagecache-base5:1.1.1.3 yamt-pagecache-base4:1.1.1.3 PFIX-2-8-8:1.1.1.3 netbsd-6:1.1.1.3.0.6 netbsd-6-base:1.1.1.3 netbsd-5-1-2-RELEASE:1.1.1.1.2.2 netbsd-5-1-1-RELEASE:1.1.1.1.2.2 yamt-pagecache-base3:1.1.1.3 PFIX-2-8-7:1.1.1.3 yamt-pagecache-base2:1.1.1.3 yamt-pagecache:1.1.1.3.0.4 yamt-pagecache-base:1.1.1.3 PFIX-2-8-6:1.1.1.3 PFIX-2-8-5:1.1.1.3 PFIX-2-8-4:1.1.1.3 cherry-xenmp:1.1.1.3.0.2 cherry-xenmp-base:1.1.1.3 PFIX-2-8-3:1.1.1.3 PFIX-2-8-2:1.1.1.3 PFIX-2-8-1:1.1.1.3 bouyer-quota2-nbase:1.1.1.3 bouyer-quota2:1.1.1.2.0.2 bouyer-quota2-base:1.1.1.2 matt-mips64-premerge-20101231:1.1.1.2 matt-nb5-mips64-premerge-20101231:1.1.1.1.4.2 matt-nb5-pq3:1.1.1.1.2.3.0.2 matt-nb5-pq3-base:1.1.1.1.2.3 PFIX-2-7-2:1.1.1.2 netbsd-5-1:1.1.1.1.2.2.0.2 netbsd-5-1-RELEASE:1.1.1.1.2.2 netbsd-5-1-RC4:1.1.1.1.2.2 matt-nb5-mips64-k15:1.1.1.1.4.2 PFIX-2-7-1:1.1.1.2 netbsd-5-1-RC3:1.1.1.1.2.2 netbsd-5-1-RC2:1.1.1.1.2.2 netbsd-5-1-RC1:1.1.1.1.2.2 matt-nb5-mips64:1.1.1.1.0.4 PFIX-2-6-6:1.1.1.1 matt-premerge-20091211:1.1.1.1 netbsd-5:1.1.1.1.0.2 PFIX-2-6-5:1.1.1.1 PFIX-2-6-2:1.1.1.1 VENEMA:1.1.1; locks; strict; comment @# @; 1.1 date 2009.06.23.10.08.32; author tron; state Exp; branches 1.1.1.1; next ; 1.1.1.1 date 2009.06.23.10.08.32; author tron; state Exp; branches 1.1.1.1.2.1 1.1.1.1.4.1; next 1.1.1.2; 1.1.1.2 date 2010.06.17.18.06.22; author tron; state Exp; branches 1.1.1.2.2.1; next 1.1.1.3; 1.1.1.3 date 2011.03.02.19.31.48; author tron; state Exp; branches 1.1.1.3.4.1 1.1.1.3.6.1; next 1.1.1.4; 1.1.1.4 date 2012.06.09.11.26.53; author tron; state Exp; branches 1.1.1.4.2.1; next 1.1.1.5; 1.1.1.5 date 2013.01.02.18.58.43; author tron; state Exp; branches; next 1.1.1.6; 1.1.1.6 date 2013.09.25.19.06.24; author tron; state Exp; branches 1.1.1.6.2.1; next 1.1.1.7; commitid WQnWePIKINywUQ6x; 1.1.1.7 date 2014.07.06.19.27.44; author tron; state Exp; branches; next 1.1.1.8; commitid 5TVMY9WFpCELTlHx; 1.1.1.8 date 2015.09.12.08.20.31; author tron; state Exp; branches 1.1.1.8.2.1 1.1.1.8.4.1; next 1.1.1.9; commitid EZWRFaJwyOgZhWAy; 1.1.1.9 date 2017.02.14.01.13.36; author christos; state Exp; branches 1.1.1.9.12.1 1.1.1.9.14.1; next 1.1.1.10; commitid 3GKuOxtmc3XhbRFz; 1.1.1.10 date 2020.03.18.18.59.29; author christos; state Exp; branches; next 1.1.1.11; commitid hRc0KjfEXOv3PU0C; 1.1.1.11 date 2022.10.08.16.09.03; author christos; state Exp; branches 1.1.1.11.2.1; next 1.1.1.12; commitid kRUbAM0nqDWDQVWD; 1.1.1.12 date 2023.12.23.20.24.50; author christos; state Exp; branches 1.1.1.12.2.1; next 1.1.1.13; commitid b1hV92WYdEWo2DRE; 1.1.1.13 date 2025.02.25.19.11.38; author christos; state Exp; branches 1.1.1.13.2.1; next 1.1.1.14; commitid cLFKwpXD6DqXOSKF; 1.1.1.14 date 2026.05.09.18.39.14; author christos; state Exp; branches; next ; commitid mtbvlXzNqJaszaFG; 1.1.1.1.2.1 date 2009.06.23.10.08.32; author snj; state dead; branches; next 1.1.1.1.2.2; 1.1.1.1.2.2 date 2009.09.15.06.02.16; author snj; state Exp; branches; next 1.1.1.1.2.3; 1.1.1.1.2.3 date 2010.11.21.18.31.24; author riz; state Exp; branches; next ; 1.1.1.1.4.1 date 2009.06.23.10.08.32; author matt; state dead; branches; next 1.1.1.1.4.2; 1.1.1.1.4.2 date 2010.04.21.05.23.33; author matt; state Exp; branches; next ; 1.1.1.2.2.1 date 2011.03.05.15.08.55; author bouyer; state Exp; branches; next ; 1.1.1.3.4.1 date 2012.10.30.18.58.01; author yamt; state Exp; branches; next 1.1.1.3.4.2; 1.1.1.3.4.2 date 2013.01.23.00.04.54; author yamt; state Exp; branches; next 1.1.1.3.4.3; 1.1.1.3.4.3 date 2014.05.22.14.08.01; author yamt; state Exp; branches; next ; commitid cuVqdlp1QcvUzxBx; 1.1.1.3.6.1 date 2012.06.13.19.28.58; author riz; state Exp; branches; next ; 1.1.1.4.2.1 date 2013.02.25.00.27.10; author tls; state Exp; branches; next 1.1.1.4.2.2; 1.1.1.4.2.2 date 2014.08.19.23.59.41; author tls; state Exp; branches; next ; commitid jTnpym9Qu0o4R1Nx; 1.1.1.6.2.1 date 2014.08.10.07.12.47; author tls; state Exp; branches; next ; commitid 0tNMy3UM0qm8IMLx; 1.1.1.8.2.1 date 2017.03.20.06.56.34; author pgoyette; state Exp; branches; next ; commitid jjw7cAwgyKq7RfKz; 1.1.1.8.4.1 date 2017.04.21.16.52.45; author bouyer; state Exp; branches; next ; commitid dUG7nkTKALCadqOz; 1.1.1.9.12.1 date 2020.04.08.14.06.50; author martin; state Exp; branches; next ; commitid Qli2aW9E74UFuA3C; 1.1.1.9.14.1 date 2023.12.25.12.54.38; author martin; state Exp; branches; next ; commitid yzNdlh5ioUjfxQRE; 1.1.1.11.2.1 date 2023.12.25.12.43.26; author martin; state Exp; branches; next ; commitid UCTK9IHygwOntQRE; 1.1.1.12.2.1 date 2025.08.02.05.49.54; author perseant; state Exp; branches; next ; commitid 23j6GFaDws3O875G; 1.1.1.13.2.1 date 2026.05.11.17.13.40; author martin; state Exp; branches; next ; commitid 2QeqaJm8KrXk4qFG; desc @@ 1.1 log @Initial revision @ text @ Postfix manual - smtp(8)
SMTP(8)                                                                SMTP(8)

NAME
       smtp - Postfix SMTP+LMTP client

SYNOPSIS
       smtp [generic Postfix daemon options]

DESCRIPTION
       The  Postfix SMTP+LMTP client implements the SMTP and LMTP
       mail delivery protocols.  It  processes  message  delivery
       requests  from the queue manager. Each request specifies a
       queue file, a sender address, a domain or host to  deliver
       to, and recipient information.  This program expects to be
       run from the master(8) process manager.

       The SMTP+LMTP client updates  the  queue  file  and  marks
       recipients  as  finished,  or it informs the queue manager
       that delivery should be  tried  again  at  a  later  time.
       Delivery   status  reports  are  sent  to  the  bounce(8),
       defer(8) or trace(8) daemon as appropriate.

       The SMTP+LMTP client looks up a  list  of  mail  exchanger
       addresses  for  the  destination  host,  sorts the list by
       preference, and connects to each listed address  until  it
       finds a server that responds.

       When  a  server  is  not  reachable, or when mail delivery
       fails due to a recoverable error condition, the  SMTP+LMTP
       client  will try to deliver the mail to an alternate host.

       After a successful mail transaction, a connection  may  be
       saved to the scache(8) connection cache server, so that it
       may be used by  any  SMTP+LMTP  client  for  a  subsequent
       transaction.

       By  default, connection caching is enabled temporarily for
       destinations that have a high volume of mail in the active
       queue.  Connection  caching can be enabled permanently for
       specific destinations.

SMTP DESTINATION SYNTAX
       SMTP destinations have the following form:

       domainname

       domainname:port
              Look up  the  mail  exchangers  for  the  specified
              domain, and connect to the specified port (default:
              smtp).

       [hostname]

       [hostname]:port
              Look up the address(es) of the specified host,  and
              connect to the specified port (default: smtp).

       [address]

       [address]:port
              Connect  to  the host at the specified address, and
              connect to the specified port (default:  smtp).  An
              IPv6 address must be formatted as [ipv6:address].

LMTP DESTINATION SYNTAX
       LMTP destinations have the following form:

       unix:pathname
              Connect  to  the  local  UNIX-domain server that is
              bound to the specified  pathname.  If  the  process
              runs  chrooted, an absolute pathname is interpreted
              relative to the Postfix queue directory.

       inet:hostname

       inet:hostname:port

       inet:[address]

       inet:[address]:port
              Connect to the specified TCP port on the  specified
              local or remote host. If no port is specified, con-
              nect to the port defined as  lmtp  in  services(4).
              If no such service is found, the lmtp_tcp_port con-
              figuration parameter (default value of 24) will  be
              used.    An  IPv6  address  must  be  formatted  as
              [ipv6:address].

SECURITY
       The SMTP+LMTP client is moderately security-sensitive.  It
       talks  to  SMTP  or LMTP servers and to DNS servers on the
       network. The SMTP+LMTP client can be run chrooted at fixed
       low privilege.

STANDARDS
       RFC 821 (SMTP protocol)
       RFC 822 (ARPA Internet Text Messages)
       RFC 1651 (SMTP service extensions)
       RFC 1652 (8bit-MIME transport)
       RFC 1870 (Message Size Declaration)
       RFC 2033 (LMTP protocol)
       RFC 2034 (SMTP Enhanced Error Codes)
       RFC 2045 (MIME: Format of Internet Message Bodies)
       RFC 2046 (MIME: Media Types)
       RFC 2554 (AUTH command)
       RFC 2821 (SMTP protocol)
       RFC 2920 (SMTP Pipelining)
       RFC 3207 (STARTTLS command)
       RFC 3461 (SMTP DSN Extension)
       RFC 3463 (Enhanced Status Codes)
       RFC 4954 (AUTH command)

DIAGNOSTICS
       Problems  and transactions are logged to syslogd(8).  Cor-
       rupted message files are marked so that the queue  manager
       can move them to the corrupt queue for further inspection.

       Depending on the setting of the notify_classes  parameter,
       the  postmaster is notified of bounces, protocol problems,
       and of other trouble.

BUGS
       SMTP and LMTP connection caching does not work  with  TLS.
       The  necessary  support for TLS object passivation and re-
       activation does not exist  without  closing  the  session,
       which defeats the purpose.

       SMTP and LMTP connection caching assumes that SASL creden-
       tials are valid for all destinations  that  map  onto  the
       same IP address and TCP port.

CONFIGURATION PARAMETERS
       Before  Postfix version 2.3, the LMTP client is a separate
       program that implements only a subset of the functionality
       available with SMTP: there is no support for TLS, and con-
       nections are cached in-process, making it ineffective when
       the client is used for multiple domains.

       Most  smtp_xxx  configuration  parameters have an lmtp_xxx
       "mirror" parameter for the equivalent LMTP  feature.  This
       document describes only those LMTP-related parameters that
       aren't simply "mirror" parameters.

       Changes to main.cf are picked up automatically, as smtp(8)
       processes  run  for only a limited amount of time. Use the
       command "postfix reload" to speed up a change.

       The text below provides  only  a  parameter  summary.  See
       postconf(5) for more details including examples.

COMPATIBILITY CONTROLS
       ignore_mx_lookup_error (no)
              Ignore DNS MX lookups that produce no response.

       smtp_always_send_ehlo (yes)
              Always send EHLO at the start of an SMTP session.

       smtp_never_send_ehlo (no)
              Never send EHLO at the start of an SMTP session.

       smtp_defer_if_no_mx_address_found (no)
              Defer  mail  delivery when no MX record resolves to
              an IP address.

       smtp_line_length_limit (990)
              The maximal length of message header and body lines
              that Postfix will send via SMTP.

       smtp_pix_workaround_delay_time (10s)
              How  long  the  Postfix  SMTP  client pauses before
              sending ".<CR><LF>" in order to work around the PIX
              firewall "<CR><LF>.<CR><LF>" bug.

       smtp_pix_workaround_threshold_time (500s)
              How  long a message must be queued before the Post-
              fix  SMTP  client  turns  on   the   PIX   firewall
              "<CR><LF>.<CR><LF>"  bug  workaround  for  delivery
              through firewalls with "smtp fixup" mode turned on.

       smtp_pix_workarounds (disable_esmtp, delay_dotcrlf)
              A  list that specifies zero or more workarounds for
              CISCO PIX firewall bugs.

       smtp_pix_workaround_maps (empty)
              Lookup tables, indexed by the  remote  SMTP  server
              address, with per-destination workarounds for CISCO
              PIX firewall bugs.

       smtp_quote_rfc821_envelope (yes)
              Quote addresses in SMTP MAIL FROM and RCPT TO  com-
              mands as required by RFC 2821.

       smtp_skip_5xx_greeting (yes)
              Skip SMTP servers that greet with a 5XX status code
              (go away, do not try again later).

       smtp_skip_quit_response (yes)
              Do not wait for the response to the SMTP QUIT  com-
              mand.

       Available in Postfix version 2.0 and earlier:

       smtp_skip_4xx_greeting (yes)
              Skip SMTP servers that greet with a 4XX status code
              (go away, try again later).

       Available in Postfix version 2.2 and later:

       smtp_discard_ehlo_keyword_address_maps (empty)
              Lookup tables, indexed by the  remote  SMTP  server
              address,  with  case insensitive lists of EHLO key-
              words (pipelining, starttls, auth, etc.)  that  the
              Postfix   SMTP  client  will  ignore  in  the  EHLO
              response from a remote SMTP server.

       smtp_discard_ehlo_keywords (empty)
              A case insensitive list of EHLO keywords  (pipelin-
              ing,  starttls,  auth,  etc.) that the Postfix SMTP
              client will ignore in  the  EHLO  response  from  a
              remote SMTP server.

       smtp_generic_maps (empty)
              Optional lookup tables that perform address rewrit-
              ing in the SMTP client, typically  to  transform  a
              locally valid address into a globally valid address
              when sending mail across the Internet.

       Available in Postfix version 2.2.9 and later:

       smtp_cname_overrides_servername (version dependent)
              Allow DNS CNAME records to override the  servername
              that the Postfix SMTP client uses for logging, SASL
              password lookup, TLS policy decisions, or TLS  cer-
              tificate verification.

       Available in Postfix version 2.3 and later:

       lmtp_discard_lhlo_keyword_address_maps (empty)
              Lookup  tables,  indexed  by the remote LMTP server
              address, with case insensitive lists of  LHLO  key-
              words  (pipelining,  starttls, auth, etc.) that the
              LMTP client will ignore in the LHLO response from a
              remote LMTP server.

       lmtp_discard_lhlo_keywords (empty)
              A  case insensitive list of LHLO keywords (pipelin-
              ing, starttls, auth, etc.)  that  the  LMTP  client
              will ignore in the LHLO response from a remote LMTP
              server.

       Available in Postfix version 2.4.4 and later:

       send_cyrus_sasl_authzid (no)
              When authenticating to a remote SMTP or LMTP server
              with  the default setting "no", send no SASL autho-
              riZation ID (authzid); send only the SASL authenti-
              Cation ID (authcid) plus the authcid's password.

       Available in Postfix version 2.5 and later:

       smtp_header_checks (empty)
              Restricted  header_checks(5) tables for the Postfix
              SMTP client.

       smtp_mime_header_checks (empty)
              Restricted  mime_header_checks(5)  tables  for  the
              Postfix SMTP client.

       smtp_nested_header_checks (empty)
              Restricted  nested_header_checks(5)  tables for the
              Postfix SMTP client.

       smtp_body_checks (empty)
              Restricted body_checks(5) tables  for  the  Postfix
              SMTP client.

       Available in Postfix version 2.6 and later:

       tcp_windowsize (0)
              An  optional  workaround for routers that break TCP
              window scaling.

MIME PROCESSING CONTROLS
       Available in Postfix version 2.0 and later:

       disable_mime_output_conversion (no)
              Disable the conversion of 8BITMIME format  to  7BIT
              format.

       mime_boundary_length_limit (2048)
              The  maximal  length  of  MIME  multipart  boundary
              strings.

       mime_nesting_limit (100)
              The maximal recursion level that the MIME processor
              will handle.

EXTERNAL CONTENT INSPECTION CONTROLS
       Available in Postfix version 2.1 and later:

       smtp_send_xforward_command (no)
              Send  the  non-standard  XFORWARD  command when the
              Postfix SMTP server EHLO response  announces  XFOR-
              WARD support.

SASL AUTHENTICATION CONTROLS
       smtp_sasl_auth_enable (no)
              Enable  SASL  authentication  in  the  Postfix SMTP
              client.

       smtp_sasl_password_maps (empty)
              Optional SMTP client lookup tables with  one  user-
              name:password  entry per remote hostname or domain,
              or sender address when sender-dependent authentica-
              tion is enabled.

       smtp_sasl_security_options (noplaintext, noanonymous)
              Postfix  SMTP  client  SASL security options; as of
              Postfix 2.3 the list of available features  depends
              on  the SASL client implementation that is selected
              with smtp_sasl_type.

       Available in Postfix version 2.2 and later:

       smtp_sasl_mechanism_filter (empty)
              If non-empty, a Postfix SMTP client filter for  the
              remote  SMTP  server's  list of offered SASL mecha-
              nisms.

       Available in Postfix version 2.3 and later:

       smtp_sender_dependent_authentication (no)
              Enable sender-dependent authentication in the Post-
              fix  SMTP  client; this is available only with SASL
              authentication,  and   disables   SMTP   connection
              caching  to ensure that mail from different senders
              will use the appropriate credentials.

       smtp_sasl_path (empty)
              Implementation-specific information that the  Post-
              fix  SMTP client passes through to the SASL plug-in
              implementation    that     is     selected     with
              smtp_sasl_type.

       smtp_sasl_type (cyrus)
              The  SASL plug-in type that the Postfix SMTP client
              should use for authentication.

       Available in Postfix version 2.5 and later:

       smtp_sasl_auth_cache_name (empty)
              An optional table to prevent repeated SASL  authen-
              tication  failures with the same remote SMTP server
              hostname, username and password.

       smtp_sasl_auth_cache_time (90d)
              The maximal  age  of  an  smtp_sasl_auth_cache_name
              entry before it is removed.

       smtp_sasl_auth_soft_bounce (yes)
              When  a remote SMTP server rejects a SASL authenti-
              cation request with a 535 reply  code,  defer  mail
              delivery  instead  of  returning mail as undeliver-
              able.

STARTTLS SUPPORT CONTROLS
       Detailed information about STARTTLS configuration  may  be
       found in the TLS_README document.

       smtp_tls_security_level (empty)
              The default SMTP TLS security level for the Postfix
              SMTP client; when a non-empty value  is  specified,
              this     overrides    the    obsolete    parameters
              smtp_use_tls,         smtp_enforce_tls,         and
              smtp_tls_enforce_peername.

       smtp_sasl_tls_security_options           ($smtp_sasl_secu-
       rity_options)
              The  SASL  authentication security options that the
              Postfix SMTP client uses  for  TLS  encrypted  SMTP
              sessions.

       smtp_starttls_timeout (300s)
              Time  limit  for Postfix SMTP client write and read
              operations during TLS startup  and  shutdown  hand-
              shake procedures.

       smtp_tls_CAfile (empty)
              A  file  containing  CA  certificates  of  root CAs
              trusted to sign either remote SMTP server  certifi-
              cates or intermediate CA certificates.

       smtp_tls_CApath (empty)
              Directory  with  PEM  format  certificate authority
              certificates that the Postfix SMTP client  uses  to
              verify a remote SMTP server certificate.

       smtp_tls_cert_file (empty)
              File  with  the Postfix SMTP client RSA certificate
              in PEM format.

       smtp_tls_mandatory_ciphers (medium)
              The minimum TLS cipher grade that the Postfix  SMTP
              client will use with mandatory TLS encryption.

       smtp_tls_exclude_ciphers (empty)
              List of ciphers or cipher types to exclude from the
              Postfix SMTP client cipher list at all TLS security
              levels.

       smtp_tls_mandatory_exclude_ciphers (empty)
              Additional  list  of  ciphers  or  cipher  types to
              exclude from the SMTP client cipher list at  manda-
              tory TLS security levels.

       smtp_tls_dcert_file (empty)
              File  with  the Postfix SMTP client DSA certificate
              in PEM format.

       smtp_tls_dkey_file ($smtp_tls_dcert_file)
              File with the Postfix SMTP client DSA  private  key
              in PEM format.

       smtp_tls_key_file ($smtp_tls_cert_file)
              File  with  the Postfix SMTP client RSA private key
              in PEM format.

       smtp_tls_loglevel (0)
              Enable additional Postfix SMTP  client  logging  of
              TLS activity.

       smtp_tls_note_starttls_offer (no)
              Log  the  hostname  of  a  remote  SMTP server that
              offers STARTTLS, when TLS is  not  already  enabled
              for that server.

       smtp_tls_policy_maps (empty)
              Optional lookup tables with the Postfix SMTP client
              TLS security policy by next-hop destination; when a
              non-empty  value  is  specified, this overrides the
              obsolete smtp_tls_per_site parameter.

       smtp_tls_mandatory_protocols (SSLv3, TLSv1)
              List of SSL/TLS protocols  that  the  Postfix  SMTP
              client will use with mandatory TLS encryption.

       smtp_tls_scert_verifydepth (9)
              The  verification depth for remote SMTP server cer-
              tificates.

       smtp_tls_secure_cert_match (nexthop, dot-nexthop)
              The server certificate peername verification method
              for the "secure" TLS security level.

       smtp_tls_session_cache_database (empty)
              Name  of  the  file containing the optional Postfix
              SMTP client TLS session cache.

       smtp_tls_session_cache_timeout (3600s)
              The expiration time of Postfix SMTP client TLS ses-
              sion cache information.

       smtp_tls_verify_cert_match (hostname)
              The server certificate peername verification method
              for the "verify" TLS security level.

       tls_daemon_random_bytes (32)
              The number of pseudo-random bytes that  an  smtp(8)
              or  smtpd(8)  process  requests  from the tlsmgr(8)
              server in order to seed its internal pseudo  random
              number generator (PRNG).

       tls_high_cipherlist
       (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "HIGH" grade ciphers.

       tls_medium_cipherlist (ALL:!EXPORT:!LOW:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "MEDIUM" or higher grade
              ciphers.

       tls_low_cipherlist (ALL:!EXPORT:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "LOW"  or  higher  grade
              ciphers.

       tls_export_cipherlist (ALL:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "EXPORT" or higher grade
              ciphers.

       tls_null_cipherlist (eNULL:!aNULL)
              The OpenSSL cipherlist  for  "NULL"  grade  ciphers
              that provide authentication without encryption.

       Available in Postfix version 2.4 and later:

       smtp_sasl_tls_verified_security_options
       ($smtp_sasl_tls_security_options)
              The  SASL  authentication security options that the
              Postfix SMTP client uses  for  TLS  encrypted  SMTP
              sessions with a verified server certificate.

       Available in Postfix version 2.5 and later:

       smtp_tls_fingerprint_cert_match (empty)
              List  of  acceptable remote SMTP server certificate
              fingerprints for  the  "fingerprint"  TLS  security
              level (smtp_tls_security_level = fingerprint).

       smtp_tls_fingerprint_digest (md5)
              The  message  digest  algorithm  used  to construct
              remote SMTP server certificate fingerprints.

       Available in Postfix version 2.6 and later:

       smtp_tls_protocols (!SSLv2)
              List of TLS protocols that the Postfix SMTP  client
              will  exclude  or  include  with  opportunistic TLS
              encryption.

       smtp_tls_ciphers (export)
              The minimum TLS cipher grade that the Postfix  SMTP
              client  will use with opportunistic TLS encryption.

       smtp_tls_eccert_file (empty)
              File with the Postfix SMTP client ECDSA certificate
              in PEM format.

       smtp_tls_eckey_file ($smtp_tls_eccert_file)
              File with the Postfix SMTP client ECDSA private key
              in PEM format.

OBSOLETE STARTTLS CONTROLS
       The following configuration parameters exist for  compati-
       bility with Postfix versions before 2.3. Support for these
       will be removed in a future release.

       smtp_use_tls (no)
              Opportunistic mode: use  TLS  when  a  remote  SMTP
              server  announces  STARTTLS support, otherwise send
              the mail in the clear.

       smtp_enforce_tls (no)
              Enforcement mode: require that remote SMTP  servers
              use  TLS  encryption,  and  never  send mail in the
              clear.

       smtp_tls_enforce_peername (yes)
              With mandatory TLS  encryption,  require  that  the
              remote SMTP server hostname matches the information
              in the remote SMTP server certificate.

       smtp_tls_per_site (empty)
              Optional lookup tables with the Postfix SMTP client
              TLS  usage  policy  by  next-hop destination and by
              remote SMTP server hostname.

       smtp_tls_cipherlist (empty)
              Obsolete Postfix < 2.3 control for the Postfix SMTP
              client TLS cipher list.

RESOURCE AND RATE CONTROLS
       smtp_destination_concurrency_limit      ($default_destina-
       tion_concurrency_limit)
              The  maximal  number  of parallel deliveries to the
              same destination  via  the  smtp  message  delivery
              transport.

       smtp_destination_recipient_limit        ($default_destina-
       tion_recipient_limit)
              The  maximal  number  of recipients per message for
              the smtp message delivery transport.

       smtp_connect_timeout (30s)
              The SMTP client time limit  for  completing  a  TCP
              connection,  or  zero  (use  the  operating  system
              built-in time limit).

       smtp_helo_timeout (300s)
              The SMTP client time limit for sending the HELO  or
              EHLO  command, and for receiving the initial server
              response.

       lmtp_lhlo_timeout (300s)
              The LMTP client time limit  for  sending  the  LHLO
              command,  and  for  receiving  the  initial  server
              response.

       smtp_xforward_timeout (300s)
              The SMTP client time limit for sending the XFORWARD
              command, and for receiving the server response.

       smtp_mail_timeout (300s)
              The  SMTP  client  time  limit for sending the MAIL
              FROM  command,  and  for   receiving   the   server
              response.

       smtp_rcpt_timeout (300s)
              The  SMTP  client  time  limit for sending the SMTP
              RCPT TO  command,  and  for  receiving  the  server
              response.

       smtp_data_init_timeout (120s)
              The  SMTP  client  time  limit for sending the SMTP
              DATA  command,  and  for   receiving   the   server
              response.

       smtp_data_xfer_timeout (180s)
              The  SMTP  client  time  limit for sending the SMTP
              message content.

       smtp_data_done_timeout (600s)
              The SMTP client time limit  for  sending  the  SMTP
              ".", and for receiving the server response.

       smtp_quit_timeout (300s)
              The  SMTP  client  time  limit for sending the QUIT
              command, and for receiving the server response.

       Available in Postfix version 2.1 and later:

       smtp_mx_address_limit (5)
              The  maximal  number  of  MX  (mail  exchanger)  IP
              addresses  that  can  result  from  mail  exchanger
              lookups, or zero (no limit).

       smtp_mx_session_limit (2)
              The maximal number of SMTP  sessions  per  delivery
              request  before  giving up or delivering to a fall-
              back relay host, or zero (no limit).

       smtp_rset_timeout (20s)
              The SMTP client time limit  for  sending  the  RSET
              command, and for receiving the server response.

       Available in Postfix version 2.2 and earlier:

       lmtp_cache_connection (yes)
              Keep Postfix LMTP client connections open for up to
              $max_idle seconds.

       Available in Postfix version 2.2 and later:

       smtp_connection_cache_destinations (empty)
              Permanently enable SMTP connection caching for  the
              specified destinations.

       smtp_connection_cache_on_demand (yes)
              Temporarily  enable SMTP connection caching while a
              destination has a high volume of mail in the active
              queue.

       smtp_connection_reuse_time_limit (300s)
              The amount of time during which Postfix will use an
              SMTP connection repeatedly.

       smtp_connection_cache_time_limit (2s)
              When SMTP connection caching is enabled, the amount
              of  time  that an unused SMTP client socket is kept
              open before it is closed.

       Available in Postfix version 2.3 and later:

       connection_cache_protocol_timeout (5s)
              Time limit for connection cache  connect,  send  or
              receive operations.

TROUBLE SHOOTING CONTROLS
       debug_peer_level (2)
              The  increment  in  verbose  logging  level  when a
              remote client or server matches a  pattern  in  the
              debug_peer_list parameter.

       debug_peer_list (empty)
              Optional  list  of remote client or server hostname
              or network address patterns that cause the  verbose
              logging  level  to increase by the amount specified
              in $debug_peer_level.

       error_notice_recipient (postmaster)
              The recipient  of  postmaster  notifications  about
              mail  delivery  problems that are caused by policy,
              resource, software or protocol errors.

       internal_mail_filter_classes (empty)
              What categories of Postfix-generated mail are  sub-
              ject   to   before-queue   content   inspection  by
              non_smtpd_milters, header_checks and body_checks.

       notify_classes (resource, software)
              The list of error classes that are reported to  the
              postmaster.

MISCELLANEOUS CONTROLS
       best_mx_transport (empty)
              Where  the  Postfix SMTP client should deliver mail
              when it detects a "mail loops back to myself" error
              condition.

       config_directory (see 'postconf -d' output)
              The  default  location  of  the Postfix main.cf and
              master.cf configuration files.

       daemon_timeout (18000s)
              How much time a Postfix daemon process may take  to
              handle  a  request  before  it  is  terminated by a
              built-in watchdog timer.

       delay_logging_resolution_limit (2)
              The maximal number  of  digits  after  the  decimal
              point when logging sub-second delay values.

       disable_dns_lookups (no)
              Disable  DNS  lookups  in the Postfix SMTP and LMTP
              clients.

       inet_interfaces (all)
              The network interface addresses that this mail sys-
              tem receives mail on.

       inet_protocols (ipv4)
              The  Internet protocols Postfix will attempt to use
              when making or accepting connections.

       ipc_timeout (3600s)
              The time limit for sending or receiving information
              over an internal communication channel.

       lmtp_assume_final (no)
              When  an  LMTP  server  announces  no  DSN support,
              assume that the server performs final delivery, and
              send   "delivered"  delivery  status  notifications
              instead of "relayed".

       lmtp_tcp_port (24)
              The default TCP port that the Postfix  LMTP  client
              connects to.

       max_idle (100s)
              The  maximum  amount  of  time that an idle Postfix
              daemon process waits  for  an  incoming  connection
              before terminating voluntarily.

       max_use (100)
              The  maximal  number of incoming connections that a
              Postfix daemon process will service  before  termi-
              nating voluntarily.

       process_id (read-only)
              The  process  ID  of  a  Postfix  command or daemon
              process.

       process_name (read-only)
              The process name of a  Postfix  command  or  daemon
              process.

       proxy_interfaces (empty)
              The network interface addresses that this mail sys-
              tem receives mail on by way of a proxy  or  network
              address translation unit.

       smtp_bind_address (empty)
              An  optional  numerical  network  address  that the
              Postfix SMTP client should bind to when  making  an
              IPv4 connection.

       smtp_bind_address6 (empty)
              An  optional  numerical  network  address  that the
              Postfix SMTP client should bind to when  making  an
              IPv6 connection.

       smtp_helo_name ($myhostname)
              The  hostname to send in the SMTP EHLO or HELO com-
              mand.

       lmtp_lhlo_name ($myhostname)
              The hostname to send in the LMTP LHLO command.

       smtp_host_lookup (dns)
              What mechanisms when the Postfix SMTP  client  uses
              to look up a host's IP address.

       smtp_randomize_addresses (yes)
              Randomize  the  order  of  equal-preference MX host
              addresses.

       syslog_facility (mail)
              The syslog facility of Postfix logging.

       syslog_name (see 'postconf -d' output)
              The mail system  name  that  is  prepended  to  the
              process  name  in  syslog  records, so that "smtpd"
              becomes, for example, "postfix/smtpd".

       Available with Postfix 2.2 and earlier:

       fallback_relay (empty)
              Optional list of relay hosts for SMTP  destinations
              that can't be found or that are unreachable.

       Available with Postfix 2.3 and later:

       smtp_fallback_relay ($fallback_relay)
              Optional  list of relay hosts for SMTP destinations
              that can't be found or that are unreachable.

SEE ALSO
       generic(5), output address rewriting
       header_checks(5), message header content inspection
       body_checks(5), body parts content inspection
       qmgr(8), queue manager
       bounce(8), delivery status reports
       scache(8), connection cache server
       postconf(5), configuration parameters
       master(5), generic daemon options
       master(8), process manager
       tlsmgr(8), TLS session and PRNG management
       syslogd(8), system logging

README FILES
       SASL_README, Postfix SASL howto
       TLS_README, Postfix STARTTLS howto

LICENSE
       The  Secure  Mailer  license must be distributed with this
       software.

AUTHOR(S)
       Wietse Venema
       IBM T.J. Watson Research
       P.O. Box 704
       Yorktown Heights, NY 10598, USA

       Command pipelining in cooperation with:
       Jon Ribbens
       Oaktree Internet Solutions Ltd.,
       Internet House,
       Canal Basin,
       Coventry,
       CV1 4LY, United Kingdom.

       SASL support originally by:
       Till Franke
       SuSE Rhein/Main AG
       65760 Eschborn, Germany

       TLS support originally by:
       Lutz Jaenicke
       BTU Cottbus
       Allgemeine Elektrotechnik
       Universitaetsplatz 3-4
       D-03044 Cottbus, Germany

       Revised TLS and SMTP connection cache support by:
       Victor Duchovni
       Morgan Stanley

                                                                       SMTP(8)
@ 1.1.1.1 log @Import Postfix 2.6.2. @ text @@ 1.1.1.2 log @Import Postfix 2.7.1. Major changes since Postfix 2.6.6: - Improved before-queue content filter performance. With "smtpd_proxy_options = speed_adjust", the Postfix SMTP server receives the entire message before it connects to a before-queue content filter. Typically, this allows Postfix to handle the same mail load with fewer content filter processes. - Improved address verification performance. The verify database is now persistent by default, and it is automatically cleaned periodically. Under overload conditions, the Postfix SMTP server no longer waits up to 6 seconds for an address probe to complete. - Support for reputation management based on the local SMTP client IP address. This is typically implemented with "FILTER transportname:" actions in access maps or header/body checks, and mail delivery transports in master.cf with unique smtp_bind_address values. @ text @a198 4 smtp_reply_filter (empty) A mechanism to transform replies from remote SMTP servers one line at a time. d204 1 a204 1 Do not wait for the response to the SMTP QUIT com- d216 4 a219 4 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO key- words (pipelining, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO d223 3 a225 3 A case insensitive list of EHLO keywords (pipelin- ing, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO response from a d230 1 a230 1 ing in the SMTP client, typically to transform a d237 1 a237 1 Allow DNS CNAME records to override the servername d239 1 a239 1 password lookup, TLS policy decisions, or TLS cer- d245 3 a247 3 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO key- words (pipelining, starttls, auth, etc.) that the d252 2 a253 2 A case insensitive list of LHLO keywords (pipelin- ing, starttls, auth, etc.) that the LMTP client d261 1 a261 1 with the default setting "no", send no SASL autho- d268 1 a268 1 Restricted header_checks(5) tables for the Postfix d276 1 a276 1 Restricted nested_header_checks(5) tables for the d280 1 a280 1 Restricted body_checks(5) tables for the Postfix d286 1 a286 1 An optional workaround for routers that break TCP d293 1 a293 1 Disable the conversion of 8BITMIME format to 7BIT d308 2 a309 2 Send the non-standard XFORWARD command when the Postfix SMTP server EHLO response announces XFOR- d314 1 a314 1 Enable SASL authentication in the Postfix SMTP d318 2 a319 2 Optional SMTP client lookup tables with one user- name:password entry per remote hostname or domain, d324 3 a326 3 Postfix SMTP client SASL security options; as of Postfix 2.3 the list of available features depends on the SASL client implementation that is selected d332 2 a333 2 If non-empty, a Postfix SMTP client filter for the remote SMTP server's list of offered SASL mecha- d340 3 a342 3 fix SMTP client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from different senders d346 3 a348 3 Implementation-specific information that the Post- fix SMTP client passes through to the SASL plug-in implementation that is selected with d352 1 a352 1 The SASL plug-in type that the Postfix SMTP client d358 2 a359 2 An optional table to prevent repeated SASL authen- tication failures with the same remote SMTP server d363 1 a363 1 The maximal age of an smtp_sasl_auth_cache_name d367 3 a369 3 When a remote SMTP server rejects a SASL authenti- cation request with a 535 reply code, defer mail delivery instead of returning mail as undeliver- d373 1 a373 1 Detailed information about STARTTLS configuration may be d378 2 a379 2 SMTP client; when a non-empty value is specified, this overrides the obsolete parameters d385 2 a386 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d390 2 a391 2 Time limit for Postfix SMTP client write and read operations during TLS startup and shutdown hand- d395 2 a396 2 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certifi- d400 2 a401 2 Directory with PEM format certificate authority certificates that the Postfix SMTP client uses to d405 1 a405 1 File with the Postfix SMTP client RSA certificate d409 1 a409 1 The minimum TLS cipher grade that the Postfix SMTP d418 2 a419 2 Additional list of ciphers or cipher types to exclude from the SMTP client cipher list at manda- d423 1 a423 1 File with the Postfix SMTP client DSA certificate d427 1 a427 1 File with the Postfix SMTP client DSA private key d431 1 a431 1 File with the Postfix SMTP client RSA private key d435 1 a435 1 Enable additional Postfix SMTP client logging of d439 2 a440 2 Log the hostname of a remote SMTP server that offers STARTTLS, when TLS is not already enabled d446 1 a446 1 non-empty value is specified, this overrides the d450 1 a450 1 List of SSL/TLS protocols that the Postfix SMTP d454 1 a454 1 The verification depth for remote SMTP server cer- d462 1 a462 1 Name of the file containing the optional Postfix d474 3 a476 3 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its internal pseudo random d488 1 a488 1 The OpenSSL cipherlist for "LOW" or higher grade d496 1 a496 1 The OpenSSL cipherlist for "NULL" grade ciphers d503 2 a504 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d510 2 a511 2 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security d515 1 a515 1 The message digest algorithm used to construct d521 2 a522 2 List of TLS protocols that the Postfix SMTP client will exclude or include with opportunistic TLS d526 2 a527 2 The minimum TLS cipher grade that the Postfix SMTP client will use with opportunistic TLS encryption. a536 8 Available in Postfix version 2.7 and later: smtp_tls_block_early_mail_reply (no) Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends malicious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client TLS session. d538 1 a538 1 The following configuration parameters exist for compati- d543 2 a544 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send d548 2 a549 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the d553 1 a553 1 With mandatory TLS encryption, require that the d559 1 a559 1 TLS usage policy by next-hop destination and by d569 2 a570 2 The maximal number of parallel deliveries to the same destination via the smtp message delivery d575 1 a575 1 The maximal number of recipients per message for d579 1 a579 1 The SMTP client time limit for completing a TCP d584 2 a585 2 The SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial server d589 1 a589 1 The LMTP client time limit for sending the LHLO d598 2 a599 2 The SMTP client time limit for sending the MAIL FROM command, and for receiving the server d603 2 a604 2 The SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the server d608 2 a609 2 The SMTP client time limit for sending the SMTP DATA command, and for receiving the server d613 1 a613 1 The SMTP client time limit for sending the SMTP d617 1 a617 1 The SMTP client time limit for sending the SMTP d621 1 a621 1 The SMTP client time limit for sending the QUIT d632 2 a633 2 The maximal number of SMTP sessions per delivery request before giving up or delivering to a fall- d637 1 a637 1 The SMTP client time limit for sending the RSET d649 1 a649 1 Permanently enable SMTP connection caching for the d653 1 a653 1 Temporarily enable SMTP connection caching while a d663 1 a663 1 of time that an unused SMTP client socket is kept d669 1 a669 1 Time limit for connection cache connect, send or d674 2 a675 2 The increment in verbose logging level when a remote client or server matches a pattern in the d679 3 a681 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified d685 2 a686 2 The recipient of postmaster notifications about mail delivery problems that are caused by policy, d690 2 a691 2 What categories of Postfix-generated mail are sub- ject to before-queue content inspection by d695 1 a695 1 The list of error classes that are reported to the d700 1 a700 1 Where the Postfix SMTP client should deliver mail d705 1 a705 1 The default location of the Postfix main.cf and d709 2 a710 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a d714 1 a714 1 The maximal number of digits after the decimal d718 1 a718 1 Disable DNS lookups in the Postfix SMTP and LMTP d726 1 a726 1 The Internet protocols Postfix will attempt to use d734 1 a734 1 When an LMTP server announces no DSN support, d736 1 a736 1 send "delivered" delivery status notifications d740 1 a740 1 The default TCP port that the Postfix LMTP client d744 2 a745 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection d749 2 a750 2 The maximal number of incoming connections that a Postfix daemon process will service before termi- d754 1 a754 1 The process ID of a Postfix command or daemon d758 1 a758 1 The process name of a Postfix command or daemon d763 1 a763 1 tem receives mail on by way of a proxy or network d767 2 a768 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d772 2 a773 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d777 1 a777 1 The hostname to send in the SMTP EHLO or HELO com- d784 2 a785 2 What mechanisms the Postfix SMTP client uses to look up a host's IP address. d788 1 a788 1 Randomize the order of equal-preference MX host d795 2 a796 2 The mail system name that is prepended to the process name in syslog records, so that "smtpd" d802 1 a802 1 Optional list of relay hosts for SMTP destinations d808 1 a808 1 Optional list of relay hosts for SMTP destinations d829 1 a829 1 The Secure Mailer license must be distributed with this @ 1.1.1.2.2.1 log @Sync with HEAD @ text @a292 5 Available in Postfix version 2.8 and later: smtp_dns_resolver_options (empty) DNS Resolver options for the Postfix SMTP client. a548 6 Available in Postfix version 2.8 and later: tls_disable_workarounds (see 'postconf -d' output) List or bit-mask of OpenSSL bug work-arounds to disable. d550 1 a550 1 The following configuration parameters exist for compati- d555 2 a556 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send d560 2 a561 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the d565 1 a565 1 With mandatory TLS encryption, require that the d571 1 a571 1 TLS usage policy by next-hop destination and by d581 2 a582 2 The maximal number of parallel deliveries to the same destination via the smtp message delivery d587 1 a587 1 The maximal number of recipients per message for d591 1 a591 1 The SMTP client time limit for completing a TCP d596 2 a597 2 The SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial server d601 1 a601 1 The LMTP client time limit for sending the LHLO d610 2 a611 2 The SMTP client time limit for sending the MAIL FROM command, and for receiving the server d615 2 a616 2 The SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the server d620 2 a621 2 The SMTP client time limit for sending the SMTP DATA command, and for receiving the server d625 1 a625 1 The SMTP client time limit for sending the SMTP d629 1 a629 1 The SMTP client time limit for sending the SMTP d633 1 a633 1 The SMTP client time limit for sending the QUIT d644 2 a645 2 The maximal number of SMTP sessions per delivery request before giving up or delivering to a fall- d649 1 a649 1 The SMTP client time limit for sending the RSET d661 1 a661 1 Permanently enable SMTP connection caching for the d665 1 a665 1 Temporarily enable SMTP connection caching while a d675 1 a675 1 of time that an unused SMTP client socket is kept d681 1 a681 1 Time limit for connection cache connect, send or d686 2 a687 2 The increment in verbose logging level when a remote client or server matches a pattern in the d691 3 a693 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified d697 2 a698 2 The recipient of postmaster notifications about mail delivery problems that are caused by policy, d702 2 a703 2 What categories of Postfix-generated mail are sub- ject to before-queue content inspection by d707 1 a707 1 The list of error classes that are reported to the d712 1 a712 1 Where the Postfix SMTP client should deliver mail d717 1 a717 1 The default location of the Postfix main.cf and d721 2 a722 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a d726 1 a726 1 The maximal number of digits after the decimal d730 1 a730 1 Disable DNS lookups in the Postfix SMTP and LMTP d738 1 a738 1 The Internet protocols Postfix will attempt to use d746 1 a746 1 When an LMTP server announces no DSN support, d748 1 a748 1 send "delivered" delivery status notifications d752 1 a752 1 The default TCP port that the Postfix LMTP client d756 2 a757 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection d761 2 a762 2 The maximal number of incoming connections that a Postfix daemon process will service before termi- d766 1 a766 1 The process ID of a Postfix command or daemon d770 1 a770 1 The process name of a Postfix command or daemon d775 1 a775 1 tem receives mail on by way of a proxy or network a777 6 smtp_address_preference (ipv6) The address type ("ipv6", "ipv4" or "any") that the Postfix SMTP client will try first, when a destina- tion has IPv6 and IPv4 addresses with equal MX preference. @ 1.1.1.3 log @Import Postfix 2.8.1. Changes since version 2.7.*: Postfix stable release 2.8.0 is available. This release continues the move towards improving code and documentation, and making the system better prepared for changes in the threat environment. The postscreen daemon (a zombie blocker in front of Postfix) is now included with the stable release. postscreen now supports TLS and can log the rejected sender, recipient and helo information. See the POSTSCREEN_README file for recommended usage scenarios. Support for DNS whitelisting (permit_rhswl_client), and for pattern matching to filter the responses from DNS white/blacklist servers (e.g., reject_rhsbl_client zen.spamhaus.org=127.0.0.[1..10]). Improved message tracking across SMTP-based content filters; the after-filter SMTP server can log the before-filter queue ID (the XCLIENT protocol was extended). Read-only support for sqlite databases. See sqlite_table(5) and SQLITE_README. Support for 'footers' that are appended to SMTP server "reject" responses. See "smtpd_reject_footer" in the postconf(5) manpage. @ text @a292 5 Available in Postfix version 2.8 and later: smtp_dns_resolver_options (empty) DNS Resolver options for the Postfix SMTP client. a548 6 Available in Postfix version 2.8 and later: tls_disable_workarounds (see 'postconf -d' output) List or bit-mask of OpenSSL bug work-arounds to disable. d550 1 a550 1 The following configuration parameters exist for compati- d555 2 a556 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send d560 2 a561 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the d565 1 a565 1 With mandatory TLS encryption, require that the d571 1 a571 1 TLS usage policy by next-hop destination and by d581 2 a582 2 The maximal number of parallel deliveries to the same destination via the smtp message delivery d587 1 a587 1 The maximal number of recipients per message for d591 1 a591 1 The SMTP client time limit for completing a TCP d596 2 a597 2 The SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial server d601 1 a601 1 The LMTP client time limit for sending the LHLO d610 2 a611 2 The SMTP client time limit for sending the MAIL FROM command, and for receiving the server d615 2 a616 2 The SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the server d620 2 a621 2 The SMTP client time limit for sending the SMTP DATA command, and for receiving the server d625 1 a625 1 The SMTP client time limit for sending the SMTP d629 1 a629 1 The SMTP client time limit for sending the SMTP d633 1 a633 1 The SMTP client time limit for sending the QUIT d644 2 a645 2 The maximal number of SMTP sessions per delivery request before giving up or delivering to a fall- d649 1 a649 1 The SMTP client time limit for sending the RSET d661 1 a661 1 Permanently enable SMTP connection caching for the d665 1 a665 1 Temporarily enable SMTP connection caching while a d675 1 a675 1 of time that an unused SMTP client socket is kept d681 1 a681 1 Time limit for connection cache connect, send or d686 2 a687 2 The increment in verbose logging level when a remote client or server matches a pattern in the d691 3 a693 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified d697 2 a698 2 The recipient of postmaster notifications about mail delivery problems that are caused by policy, d702 2 a703 2 What categories of Postfix-generated mail are sub- ject to before-queue content inspection by d707 1 a707 1 The list of error classes that are reported to the d712 1 a712 1 Where the Postfix SMTP client should deliver mail d717 1 a717 1 The default location of the Postfix main.cf and d721 2 a722 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a d726 1 a726 1 The maximal number of digits after the decimal d730 1 a730 1 Disable DNS lookups in the Postfix SMTP and LMTP d738 1 a738 1 The Internet protocols Postfix will attempt to use d746 1 a746 1 When an LMTP server announces no DSN support, d748 1 a748 1 send "delivered" delivery status notifications d752 1 a752 1 The default TCP port that the Postfix LMTP client d756 2 a757 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection d761 2 a762 2 The maximal number of incoming connections that a Postfix daemon process will service before termi- d766 1 a766 1 The process ID of a Postfix command or daemon d770 1 a770 1 The process name of a Postfix command or daemon d775 1 a775 1 tem receives mail on by way of a proxy or network a777 6 smtp_address_preference (ipv6) The address type ("ipv6", "ipv4" or "any") that the Postfix SMTP client will try first, when a destina- tion has IPv6 and IPv4 addresses with equal MX preference. @ 1.1.1.3.4.1 log @sync with head @ text @d458 1 a458 1 smtp_tls_mandatory_protocols (!SSLv2) @ 1.1.1.3.4.2 log @sync with head @ text @d171 1 a171 1 smtp_line_length_limit (998) d196 2 a197 2 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO commands as required by RFC 2821. d204 2 a205 2 Skip remote SMTP servers that greet with a 5XX sta- tus code (go away, do not try again later). d234 3 a236 3 ing in the Postfix SMTP client, typically to trans- form a locally valid address into a globally valid address when sending mail across the Internet. d252 2 a253 2 Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. d257 3 a259 3 ing, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. a297 15 Available in Postfix version 2.9 and later: smtp_per_record_deadline (no) Change the behavior of the smtp_*_timeout time lim- its, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- sage). smtp_send_dummy_mail_auth (no) Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d302 1 a302 1 Disable the conversion of 8BITMIME format to 7BIT d317 2 a318 2 Send the non-standard XFORWARD command when the Postfix SMTP server EHLO response announces XFOR- d323 1 a323 1 Enable SASL authentication in the Postfix SMTP d327 4 a330 4 Optional Postfix SMTP client lookup tables with one username:password entry per remote hostname or domain, or sender address when sender-dependent authentication is enabled. d333 3 a335 3 Postfix SMTP client SASL security options; as of Postfix 2.3 the list of available features depends on the SASL client implementation that is selected d341 2 a342 2 If non-empty, a Postfix SMTP client filter for the remote SMTP server's list of offered SASL mecha- d349 3 a351 3 fix SMTP client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from different senders d355 3 a357 3 Implementation-specific information that the Post- fix SMTP client passes through to the SASL plug-in implementation that is selected with d361 1 a361 1 The SASL plug-in type that the Postfix SMTP client d367 2 a368 2 An optional table to prevent repeated SASL authen- tication failures with the same remote SMTP server d372 1 a372 1 The maximal age of an smtp_sasl_auth_cache_name d376 3 a378 3 When a remote SMTP server rejects a SASL authenti- cation request with a 535 reply code, defer mail delivery instead of returning mail as undeliver- a380 7 Available in Postfix version 2.9 and later: smtp_send_dummy_mail_auth (no) Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d382 1 a382 1 Detailed information about STARTTLS configuration may be d387 2 a388 2 SMTP client; when a non-empty value is specified, this overrides the obsolete parameters d394 2 a395 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d399 2 a400 2 Time limit for Postfix SMTP client write and read operations during TLS startup and shutdown hand- d404 2 a405 2 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certifi- d409 2 a410 2 Directory with PEM format certificate authority certificates that the Postfix SMTP client uses to d414 1 a414 1 File with the Postfix SMTP client RSA certificate d418 1 a418 1 The minimum TLS cipher grade that the Postfix SMTP d427 3 a429 3 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security levels. d432 1 a432 1 File with the Postfix SMTP client DSA certificate d436 1 a436 1 File with the Postfix SMTP client DSA private key d440 1 a440 1 File with the Postfix SMTP client RSA private key d444 1 a444 1 Enable additional Postfix SMTP client logging of d448 2 a449 2 Log the hostname of a remote SMTP server that offers STARTTLS, when TLS is not already enabled d455 1 a455 1 non-empty value is specified, this overrides the d459 1 a459 1 List of SSL/TLS protocols that the Postfix SMTP d463 1 a463 1 The verification depth for remote SMTP server cer- d467 2 a468 3 How the Postfix SMTP client verifies the server certificate peername for the "secure" TLS security level. d479 2 a480 3 How the Postfix SMTP client verifies the server certificate peername for the "verify" TLS security level. d483 3 a485 3 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its internal pseudo random d497 1 a497 1 The OpenSSL cipherlist for "LOW" or higher grade d505 1 a505 1 The OpenSSL cipherlist for "NULL" grade ciphers d512 2 a513 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d519 2 a520 2 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security d524 1 a524 1 The message digest algorithm used to construct d530 2 a531 2 List of TLS protocols that the Postfix SMTP client will exclude or include with opportunistic TLS d535 2 a536 2 The minimum TLS cipher grade that the Postfix SMTP client will use with opportunistic TLS encryption. d549 3 a551 3 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends malicious HELO, MAIL, RCPT, d557 1 a557 1 List or bit-mask of OpenSSL bug work-arounds to d561 1 a561 1 The following configuration parameters exist for compati- d566 2 a567 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send d571 2 a572 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the d576 1 a576 1 With mandatory TLS encryption, require that the d582 1 a582 1 TLS usage policy by next-hop destination and by d592 2 a593 2 The maximal number of parallel deliveries to the same destination via the smtp message delivery d598 1 a598 1 The maximal number of recipients per message for d602 2 a603 2 The Postfix SMTP client time limit for completing a TCP connection, or zero (use the operating system d607 3 a609 3 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server response. d612 3 a614 3 The Postfix LMTP client time limit for sending the LHLO command, and for receiving the initial remote LMTP server response. d617 2 a618 3 The Postfix SMTP client time limit for sending the XFORWARD command, and for receiving the remote SMTP server response. d621 3 a623 3 The Postfix SMTP client time limit for sending the MAIL FROM command, and for receiving the remote SMTP server response. d626 3 a628 3 The Postfix SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the remote SMTP server response. d631 3 a633 3 The Postfix SMTP client time limit for sending the SMTP DATA command, and for receiving the remote SMTP server response. d636 2 a637 2 The Postfix SMTP client time limit for sending the SMTP message content. d640 2 a641 3 The Postfix SMTP client time limit for sending the SMTP ".", and for receiving the remote SMTP server response. d644 2 a645 3 The Postfix SMTP client time limit for sending the QUIT command, and for receiving the remote SMTP server response. d651 2 a652 2 addresses that can result from Postfix SMTP client mail exchanger lookups, or zero (no limit). d656 2 a657 3 request before the Postfix SMTP client gives up or delivers to a fall-back relay host, or zero (no limit). d660 2 a661 3 The Postfix SMTP client time limit for sending the RSET command, and for receiving the remote SMTP server response. a694 10 Available in Postfix version 2.9 and later: smtp_per_record_deadline (no) Change the behavior of the smtp_*_timeout time lim- its, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- sage). d697 2 a698 2 The increment in verbose logging level when a remote client or server matches a pattern in the d702 3 a704 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified d708 2 a709 2 The recipient of postmaster notifications about mail delivery problems that are caused by policy, d713 2 a714 2 What categories of Postfix-generated mail are sub- ject to before-queue content inspection by d718 1 a718 1 The list of error classes that are reported to the d723 1 a723 1 Where the Postfix SMTP client should deliver mail d728 1 a728 1 The default location of the Postfix main.cf and d732 2 a733 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a d737 1 a737 1 The maximal number of digits after the decimal d741 1 a741 1 Disable DNS lookups in the Postfix SMTP and LMTP d748 2 a749 2 inet_protocols (all) The Internet protocols Postfix will attempt to use d757 1 a757 1 When a remote LMTP server announces no DSN support, d759 1 a759 1 send "delivered" delivery status notifications d763 1 a763 1 The default TCP port that the Postfix LMTP client d767 2 a768 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection d772 2 a773 2 The maximal number of incoming connections that a Postfix daemon process will service before termi- d777 1 a777 1 The process ID of a Postfix command or daemon d781 1 a781 1 The process name of a Postfix command or daemon d786 1 a786 1 tem receives mail on by way of a proxy or network d789 1 a789 1 smtp_address_preference (any) d792 1 a792 1 tion has IPv6 and IPv4 addresses with equal MX d796 2 a797 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d801 2 a802 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d806 1 a806 1 The hostname to send in the SMTP EHLO or HELO com- d813 1 a813 1 What mechanisms the Postfix SMTP client uses to d817 1 a817 1 Randomize the order of equal-preference MX host d824 2 a825 2 The mail system name that is prepended to the process name in syslog records, so that "smtpd" d831 1 a831 1 Optional list of relay hosts for SMTP destinations d837 1 a837 1 Optional list of relay hosts for SMTP destinations d858 1 a858 1 The Secure Mailer license must be distributed with this @ 1.1.1.3.4.3 log @sync with head. for a reference, the tree before this commit was tagged as yamt-pagecache-tag8. this commit was splitted into small chunks to avoid a limitation of cvs. ("Protocol error: too many arguments") @ text @a117 1 RFC 5321 (SMTP protocol) d197 1 a197 1 and RCPT TO commands as required by RFC 5321. @ 1.1.1.3.6.1 log @Pull up following revision(s) (requested by tron in ticket #333): doc/3RDPARTY 1.940 via patch doc/CHANGES 1.1708 via patch external/ibm-public/postfix/dist/HISTORY patch external/ibm-public/postfix/dist/RELEASE_NOTES patch external/ibm-public/postfix/dist/README_FILES/RELEASE_NOTES patch external/ibm-public/postfix/dist/README_FILES/TLS_README patch external/ibm-public/postfix/dist/html/TLS_README.html patch external/ibm-public/postfix/dist/html/lmtp.8.html patch external/ibm-public/postfix/dist/html/postconf.5.html patch external/ibm-public/postfix/dist/html/smtp.8.html patch external/ibm-public/postfix/dist/html/smtpd.8.html patch external/ibm-public/postfix/dist/man/man5/postconf.5 patch external/ibm-public/postfix/dist/man/man8/smtp.8 patch external/ibm-public/postfix/dist/man/man8/smtpd.8 patch external/ibm-public/postfix/dist/proto/TLS_README.html patch external/ibm-public/postfix/dist/proto/postconf.proto patch external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.c patch external/ibm-public/postfix/dist/src/dnsblog/dnsblog.c patch external/ibm-public/postfix/dist/src/global/mail_params.h patch external/ibm-public/postfix/dist/src/global/mail_version.h patch external/ibm-public/postfix/dist/src/local/Makefile.in patch external/ibm-public/postfix/dist/src/postlog/postlog.c patch external/ibm-public/postfix/dist/src/postqueue/Makefile.in patch external/ibm-public/postfix/dist/src/postqueue/postqueue.c patch external/ibm-public/postfix/dist/src/smtp/smtp.c patch external/ibm-public/postfix/dist/src/smtpd/smtpd.c patch external/ibm-public/postfix/dist/src/tls/tls.h patch external/ibm-public/postfix/dist/src/tls/tls_client.c patch external/ibm-public/postfix/dist/src/tls/tls_misc.c patch external/ibm-public/postfix/dist/src/tls/tls_server.c patch external/ibm-public/postfix/dist/src/util/events.c patch external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus.h patch external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_client.c patch external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_server.c patch Update Postfix to version 2.8.11: - The "change header" milter request could replace the wrong header. A long header name could match a shorter one, because a length check was done on the wrong string. Reported by Vladimir Vassiliev. - Core dump when postlog emitted the "usage" message, caused by an extraneous null assignment. Reported by Kant (fnord.hammer). - These releases add support to turn off the TLSv1.1 and TLSv1.2 protocols. Introduced with OpenSSL version 1.0.1, these protocols are known to cause inter-operability problems, for example with some hotmail services. The radical workaround is to temporarily turn off problematic protocols globally: /etc/postfix/main.cf: smtp_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2 smtp_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2 smtpd_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2 smtpd_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2 However, it may be better to temporarily turn off problematic protocols for broken sites only: /etc/postfix/main.cf: smtp_tls_policy_maps = hash:/etc/postfix/tls_policy /etc/postfix/tls_policy: example.com may protocols=!SSLv2:!TLSv1.1:!TLSv1.2 Notes: Note the use of ":" instead of comma or space. Also, note that there is NO space around the "=" in "protocols=". The smtp_tls_policy_maps lookup key must match the "next-hop" destination that is given to the Postfix SMTP client. If you override the next-hop destination with transport_maps, relayhost, sender_dependent_relayhost_maps, or otherwise, you need to specify the same destination for the smtp_tls_policy_maps lookup key. - OpenSSL related (all supported Postfix versions). Some people have reported program crashes when the OpenSSL library was updated while Postfix was accessing the Postfix TLS session cache. To avoid this, the Postfix TLS session cache ID now includes the OpenSSL library version number. This cache ID is not shared via the network. - The OpenSSL workaround introduced with the previous stable and legacy releases did not compile with older gcc compilers. These compilers cant handle #ifdef inside a macro invocation (NOT: definition). - To avoid repeated warnings from postscreen(8) with "connect to private/dnsblog service: Connection refused" on FreeBSD, the dnsblog(8) daemon now uses the single_server program driver instead of the multi_server driver. This one-line code change has no performance impact for other systems, and eliminates a high-frequency accept() race on a shared socket that appears to cause trouble on FreeBSD. The same single_server program driver has proven itself for many years in smtpd(8). Problem reported by Sahil Tandon. - Laptop-friendly support (all supported Postfix versions). A little-known secret is that Postfix has always had support to avoid unnecessary disk spin-up for MTIME updates, by doing s/fifo/unix/ in master.cf (this is currently not supported on Solaris systems). However, two minor fixes are needed to make this bullet-proof. - In laptop-friendly mode, the "postqueue -f" and "sendmail -q" commands did not wait until their requests had reached the pickup and qmgr servers before closing their UNIX-domain request sockets. - In laptop-friendly mode, the unused postkick command waited for more than a minute because the event_drain() function was comparing bitmasks incorrectly on systems with kqueue(2), epoll(2) or /dev/poll support. @ text @d458 1 a458 1 smtp_tls_mandatory_protocols (!SSLv2) @ 1.1.1.4 log @Import Postfix 2.8.11. Changes since version 2.8.8: - The "change header" milter request could replace the wrong header. A long header name could match a shorter one, because a length check was done on the wrong string. Reported by Vladimir Vassiliev. - Core dump when postlog emitted the "usage" message, caused by an extraneous null assignment. Reported by Kant (fnord.hammer). - These releases add support to turn off the TLSv1.1 and TLSv1.2 protocols. Introduced with OpenSSL version 1.0.1, these protocols are known to cause inter-operability problems, for example with some hotmail services. The radical workaround is to temporarily turn off problematic protocols globally: /etc/postfix/main.cf: smtp_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2 smtp_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2 smtpd_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2 smtpd_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2 However, it may be better to temporarily turn off problematic protocols for broken sites only: /etc/postfix/main.cf: smtp_tls_policy_maps = hash:/etc/postfix/tls_policy /etc/postfix/tls_policy: example.com may protocols=!SSLv2:!TLSv1.1:!TLSv1.2 Notes: Note the use of ":" instead of comma or space. Also, note that there is NO space around the "=" in "protocols=". The smtp_tls_policy_maps lookup key must match the "next-hop" destination that is given to the Postfix SMTP client. If you override the next-hop destination with transport_maps, relayhost, sender_dependent_relayhost_maps, or otherwise, you need to specify the same destination for the smtp_tls_policy_maps lookup key. - OpenSSL related (all supported Postfix versions). Some people have reported program crashes when the OpenSSL library was updated while Postfix was accessing the Postfix TLS session cache. To avoid this, the Postfix TLS session cache ID now includes the OpenSSL library version number. This cache ID is not shared via the network. - The OpenSSL workaround introduced with the previous stable and legacy releases did not compile with older gcc compilers. These compilers can't handle #ifdef inside a macro invocation (NOT: definition). - To avoid repeated warnings from postscreen(8) with "connect to private/dnsblog service: Connection refused" on FreeBSD, the dnsblog(8) daemon now uses the single_server program driver instead of the multi_server driver. This one-line code change has no performance impact for other systems, and eliminates a high-frequency accept() race on a shared socket that appears to cause trouble on FreeBSD. The same single_server program driver has proven itself for many years in smtpd(8). Problem reported by Sahil Tandon. - Laptop-friendly support (all supported Postfix versions). A little-known secret is that Postfix has always had support to avoid unnecessary disk spin-up for MTIME updates, by doing s/fifo/unix/ in master.cf (this is currently not supported on Solaris systems). However, two minor fixes are needed to make this bullet-proof. - In laptop-friendly mode, the "postqueue -f" and "sendmail -q" commands did not wait until their requests had reached the pickup and qmgr servers before closing their UNIX-domain request sockets. - In laptop-friendly mode, the unused postkick command waited for more than a minute because the event_drain() function was comparing bitmasks incorrectly on systems with kqueue(2), epoll(2) or /dev/poll support. @ text @d458 1 a458 1 smtp_tls_mandatory_protocols (!SSLv2) @ 1.1.1.4.2.1 log @resync with head @ text @d171 1 a171 1 smtp_line_length_limit (998) d196 2 a197 2 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO commands as required by RFC 2821. d204 2 a205 2 Skip remote SMTP servers that greet with a 5XX sta- tus code (go away, do not try again later). d234 3 a236 3 ing in the Postfix SMTP client, typically to trans- form a locally valid address into a globally valid address when sending mail across the Internet. d252 2 a253 2 Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. d257 3 a259 3 ing, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. a297 15 Available in Postfix version 2.9 and later: smtp_per_record_deadline (no) Change the behavior of the smtp_*_timeout time lim- its, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- sage). smtp_send_dummy_mail_auth (no) Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d302 1 a302 1 Disable the conversion of 8BITMIME format to 7BIT d317 2 a318 2 Send the non-standard XFORWARD command when the Postfix SMTP server EHLO response announces XFOR- d323 1 a323 1 Enable SASL authentication in the Postfix SMTP d327 4 a330 4 Optional Postfix SMTP client lookup tables with one username:password entry per remote hostname or domain, or sender address when sender-dependent authentication is enabled. d333 3 a335 3 Postfix SMTP client SASL security options; as of Postfix 2.3 the list of available features depends on the SASL client implementation that is selected d341 2 a342 2 If non-empty, a Postfix SMTP client filter for the remote SMTP server's list of offered SASL mecha- d349 3 a351 3 fix SMTP client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from different senders d355 3 a357 3 Implementation-specific information that the Post- fix SMTP client passes through to the SASL plug-in implementation that is selected with d361 1 a361 1 The SASL plug-in type that the Postfix SMTP client d367 2 a368 2 An optional table to prevent repeated SASL authen- tication failures with the same remote SMTP server d372 1 a372 1 The maximal age of an smtp_sasl_auth_cache_name d376 3 a378 3 When a remote SMTP server rejects a SASL authenti- cation request with a 535 reply code, defer mail delivery instead of returning mail as undeliver- a380 7 Available in Postfix version 2.9 and later: smtp_send_dummy_mail_auth (no) Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d382 1 a382 1 Detailed information about STARTTLS configuration may be d387 2 a388 2 SMTP client; when a non-empty value is specified, this overrides the obsolete parameters d394 2 a395 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d399 2 a400 2 Time limit for Postfix SMTP client write and read operations during TLS startup and shutdown hand- d404 2 a405 2 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certifi- d409 2 a410 2 Directory with PEM format certificate authority certificates that the Postfix SMTP client uses to d414 1 a414 1 File with the Postfix SMTP client RSA certificate d418 1 a418 1 The minimum TLS cipher grade that the Postfix SMTP d427 3 a429 3 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security levels. d432 1 a432 1 File with the Postfix SMTP client DSA certificate d436 1 a436 1 File with the Postfix SMTP client DSA private key d440 1 a440 1 File with the Postfix SMTP client RSA private key d444 1 a444 1 Enable additional Postfix SMTP client logging of d448 2 a449 2 Log the hostname of a remote SMTP server that offers STARTTLS, when TLS is not already enabled d455 1 a455 1 non-empty value is specified, this overrides the d459 1 a459 1 List of SSL/TLS protocols that the Postfix SMTP d463 1 a463 1 The verification depth for remote SMTP server cer- d467 2 a468 3 How the Postfix SMTP client verifies the server certificate peername for the "secure" TLS security level. d479 2 a480 3 How the Postfix SMTP client verifies the server certificate peername for the "verify" TLS security level. d483 3 a485 3 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its internal pseudo random d497 1 a497 1 The OpenSSL cipherlist for "LOW" or higher grade d505 1 a505 1 The OpenSSL cipherlist for "NULL" grade ciphers d512 2 a513 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d519 2 a520 2 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security d524 1 a524 1 The message digest algorithm used to construct d530 2 a531 2 List of TLS protocols that the Postfix SMTP client will exclude or include with opportunistic TLS d535 2 a536 2 The minimum TLS cipher grade that the Postfix SMTP client will use with opportunistic TLS encryption. d549 3 a551 3 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends malicious HELO, MAIL, RCPT, d557 1 a557 1 List or bit-mask of OpenSSL bug work-arounds to d561 1 a561 1 The following configuration parameters exist for compati- d566 2 a567 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send d571 2 a572 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the d576 1 a576 1 With mandatory TLS encryption, require that the d582 1 a582 1 TLS usage policy by next-hop destination and by d592 2 a593 2 The maximal number of parallel deliveries to the same destination via the smtp message delivery d598 1 a598 1 The maximal number of recipients per message for d602 2 a603 2 The Postfix SMTP client time limit for completing a TCP connection, or zero (use the operating system d607 3 a609 3 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server response. d612 3 a614 3 The Postfix LMTP client time limit for sending the LHLO command, and for receiving the initial remote LMTP server response. d617 2 a618 3 The Postfix SMTP client time limit for sending the XFORWARD command, and for receiving the remote SMTP server response. d621 3 a623 3 The Postfix SMTP client time limit for sending the MAIL FROM command, and for receiving the remote SMTP server response. d626 3 a628 3 The Postfix SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the remote SMTP server response. d631 3 a633 3 The Postfix SMTP client time limit for sending the SMTP DATA command, and for receiving the remote SMTP server response. d636 2 a637 2 The Postfix SMTP client time limit for sending the SMTP message content. d640 2 a641 3 The Postfix SMTP client time limit for sending the SMTP ".", and for receiving the remote SMTP server response. d644 2 a645 3 The Postfix SMTP client time limit for sending the QUIT command, and for receiving the remote SMTP server response. d651 2 a652 2 addresses that can result from Postfix SMTP client mail exchanger lookups, or zero (no limit). d656 2 a657 3 request before the Postfix SMTP client gives up or delivers to a fall-back relay host, or zero (no limit). d660 2 a661 3 The Postfix SMTP client time limit for sending the RSET command, and for receiving the remote SMTP server response. a694 10 Available in Postfix version 2.9 and later: smtp_per_record_deadline (no) Change the behavior of the smtp_*_timeout time lim- its, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- sage). d697 2 a698 2 The increment in verbose logging level when a remote client or server matches a pattern in the d702 3 a704 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified d708 2 a709 2 The recipient of postmaster notifications about mail delivery problems that are caused by policy, d713 2 a714 2 What categories of Postfix-generated mail are sub- ject to before-queue content inspection by d718 1 a718 1 The list of error classes that are reported to the d723 1 a723 1 Where the Postfix SMTP client should deliver mail d728 1 a728 1 The default location of the Postfix main.cf and d732 2 a733 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a d737 1 a737 1 The maximal number of digits after the decimal d741 1 a741 1 Disable DNS lookups in the Postfix SMTP and LMTP d748 2 a749 2 inet_protocols (all) The Internet protocols Postfix will attempt to use d757 1 a757 1 When a remote LMTP server announces no DSN support, d759 1 a759 1 send "delivered" delivery status notifications d763 1 a763 1 The default TCP port that the Postfix LMTP client d767 2 a768 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection d772 2 a773 2 The maximal number of incoming connections that a Postfix daemon process will service before termi- d777 1 a777 1 The process ID of a Postfix command or daemon d781 1 a781 1 The process name of a Postfix command or daemon d786 1 a786 1 tem receives mail on by way of a proxy or network d789 1 a789 1 smtp_address_preference (any) d792 1 a792 1 tion has IPv6 and IPv4 addresses with equal MX d796 2 a797 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d801 2 a802 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d806 1 a806 1 The hostname to send in the SMTP EHLO or HELO com- d813 1 a813 1 What mechanisms the Postfix SMTP client uses to d817 1 a817 1 Randomize the order of equal-preference MX host d824 2 a825 2 The mail system name that is prepended to the process name in syslog records, so that "smtpd" d831 1 a831 1 Optional list of relay hosts for SMTP destinations d837 1 a837 1 Optional list of relay hosts for SMTP destinations d858 1 a858 1 The Secure Mailer license must be distributed with this @ 1.1.1.4.2.2 log @Rebase to HEAD as of a few days ago. @ text @d16 31 a46 26 The Postfix SMTP+LMTP client implements the SMTP and LMTP mail delivery protocols. It processes message delivery requests from the queue man- ager. Each request specifies a queue file, a sender address, a domain or host to deliver to, and recipient information. This program expects to be run from the master(8) process manager. The SMTP+LMTP client updates the queue file and marks recipients as finished, or it informs the queue manager that delivery should be tried again at a later time. Delivery status reports are sent to the bounce(8), defer(8) or trace(8) daemon as appropriate. The SMTP+LMTP client looks up a list of mail exchanger addresses for the destination host, sorts the list by preference, and connects to each listed address until it finds a server that responds. When a server is not reachable, or when mail delivery fails due to a recoverable error condition, the SMTP+LMTP client will try to deliver the mail to an alternate host. After a successful mail transaction, a connection may be saved to the scache(8) connection cache server, so that it may be used by any SMTP+LMTP client for a subsequent transaction. By default, connection caching is enabled temporarily for destinations that have a high volume of mail in the active queue. Connection caching can be enabled permanently for specific destinations. d54 3 a56 2 Look up the mail exchangers for the specified domain, and con- nect to the specified port (default: smtp). d61 2 a62 2 Look up the address(es) of the specified host, and connect to the specified port (default: smtp). d67 3 a69 3 Connect to the host at the specified address, and connect to the specified port (default: smtp). An IPv6 address must be format- ted as [ipv6:address]. d75 4 a78 3 Connect to the local UNIX-domain server that is bound to the specified pathname. If the process runs chrooted, an absolute pathname is interpreted relative to the Postfix queue directory. d82 1 a82 1 inet:hostname:port d87 6 a92 5 Connect to the specified TCP port on the specified local or remote host. If no port is specified, connect to the port defined as lmtp in services(4). If no such service is found, the lmtp_tcp_port configuration parameter (default value of 24) will be used. An IPv6 address must be formatted as d96 4 a99 3 The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP or LMTP servers and to DNS servers on the network. The SMTP+LMTP client can be run chrooted at fixed low privilege. a117 1 RFC 5321 (SMTP protocol) d120 7 a126 6 Problems and transactions are logged to syslogd(8). Corrupted message files are marked so that the queue manager can move them to the corrupt queue for further inspection. Depending on the setting of the notify_classes parameter, the postmas- ter is notified of bounces, protocol problems, and of other trouble. d129 8 a136 7 SMTP and LMTP connection caching does not work with TLS. The necessary support for TLS object passivation and re-activation does not exist without closing the session, which defeats the purpose. SMTP and LMTP connection caching assumes that SASL credentials are valid for all destinations that map onto the same IP address and TCP port. d139 14 a152 12 Before Postfix version 2.3, the LMTP client is a separate program that implements only a subset of the functionality available with SMTP: there is no support for TLS, and connections are cached in-process, making it ineffective when the client is used for multiple domains. Most smtp_xxx configuration parameters have an lmtp_xxx "mirror" param- eter for the equivalent LMTP feature. This document describes only those LMTP-related parameters that aren't simply "mirror" parameters. Changes to main.cf are picked up automatically, as smtp(8) processes run for only a limited amount of time. Use the command "postfix reload" to speed up a change. d154 2 a155 2 The text below provides only a parameter summary. See postconf(5) for more details including examples. d168 2 a169 1 Defer mail delivery when no MX record resolves to an IP address. d172 2 a173 2 The maximal length of message header and body lines that Postfix will send via SMTP. d176 3 a178 3 How long the Postfix SMTP client pauses before sending ".<CR><LF>" in order to work around the PIX firewall "<CR><LF>.<CR><LF>" bug. d181 4 a184 3 How long a message must be queued before the Postfix SMTP client turns on the PIX firewall "<CR><LF>.<CR><LF>" bug workaround for delivery through firewalls with "smtp fixup" mode turned on. d187 2 a188 2 A list that specifies zero or more workarounds for CISCO PIX firewall bugs. d191 3 a193 2 Lookup tables, indexed by the remote SMTP server address, with per-destination workarounds for CISCO PIX firewall bugs. d196 2 a197 2 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO commands as required by RFC 5321. d200 2 a201 2 A mechanism to transform replies from remote SMTP servers one line at a time. d204 2 a205 1 Skip remote SMTP servers that greet with a 5XX status code. d208 2 a209 1 Do not wait for the response to the SMTP QUIT command. d214 2 a215 2 Skip SMTP servers that greet with a 4XX status code (go away, try again later). d220 4 a223 3 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO keywords (pipelining, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO d227 4 a230 3 A case insensitive list of EHLO keywords (pipelining, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO response from a remote SMTP server. d233 4 a236 4 Optional lookup tables that perform address rewriting in the Postfix SMTP client, typically to transform a locally valid address into a globally valid address when sending mail across the Internet. d241 4 a244 3 Allow DNS CNAME records to override the servername that the Postfix SMTP client uses for logging, SASL password lookup, TLS policy decisions, or TLS certificate verification. d249 4 a252 3 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO d256 4 a259 3 A case insensitive list of LHLO keywords (pipelining, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. d264 4 a267 4 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- cid's password. d272 2 a273 1 Restricted header_checks(5) tables for the Postfix SMTP client. d276 2 a277 2 Restricted mime_header_checks(5) tables for the Postfix SMTP client. d280 2 a281 2 Restricted nested_header_checks(5) tables for the Postfix SMTP client. d284 2 a285 1 Restricted body_checks(5) tables for the Postfix SMTP client. d290 2 a291 2 An optional workaround for routers that break TCP window scal- ing. d301 5 a305 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d309 3 a311 7 Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. Available in Postfix version 2.11 and later: smtp_dns_support_level (empty) Level of DNS support in the Postfix SMTP client. d317 2 a318 1 Disable the conversion of 8BITMIME format to 7BIT format. d321 2 a322 1 The maximal length of MIME multipart boundary strings. d325 2 a326 1 The maximal recursion level that the MIME processor will handle. d332 3 a334 2 Send the non-standard XFORWARD command when the Postfix SMTP server EHLO response announces XFORWARD support. d338 2 a339 1 Enable SASL authentication in the Postfix SMTP client. d342 4 a345 3 Optional Postfix SMTP client lookup tables with one user- name:password entry per remote hostname or domain, or sender address when sender-dependent authentication is enabled. d348 4 a351 3 Postfix SMTP client SASL security options; as of Postfix 2.3 the list of available features depends on the SASL client implemen- tation that is selected with smtp_sasl_type. d356 3 a358 2 If non-empty, a Postfix SMTP client filter for the remote SMTP server's list of offered SASL mechanisms. d363 5 a367 4 Enable sender-dependent authentication in the Postfix SMTP client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from dif- ferent senders will use the appropriate credentials. d370 4 a373 3 Implementation-specific information that the Postfix SMTP client passes through to the SASL plug-in implementation that is selected with smtp_sasl_type. d376 2 a377 2 The SASL plug-in type that the Postfix SMTP client should use for authentication. d382 3 a384 3 An optional table to prevent repeated SASL authentication fail- ures with the same remote SMTP server hostname, username and password. d387 2 a388 2 The maximal age of an smtp_sasl_auth_cache_name entry before it is removed. d391 4 a394 3 When a remote SMTP server rejects a SASL authentication request with a 535 reply code, defer mail delivery instead of returning mail as undeliverable. d399 3 a401 2 Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d404 2 a405 2 Detailed information about STARTTLS configuration may be found in the TLS_README document. d408 4 a411 3 The default SMTP TLS security level for the Postfix SMTP client; when a non-empty value is specified, this overrides the obsolete parameters smtp_use_tls, smtp_enforce_tls, and d414 5 a418 3 smtp_sasl_tls_security_options ($smtp_sasl_security_options) The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions. d421 3 a423 2 Time limit for Postfix SMTP client write and read operations during TLS startup and shutdown handshake procedures. d426 3 a428 3 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA cer- tificates. d431 3 a433 3 Directory with PEM format certificate authority certificates that the Postfix SMTP client uses to verify a remote SMTP server certificate. d436 2 a437 1 File with the Postfix SMTP client RSA certificate in PEM format. d440 2 a441 2 The minimum TLS cipher grade that the Postfix SMTP client will use with mandatory TLS encryption. d444 3 a446 2 List of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at all TLS security levels. d449 3 a451 3 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security lev- els. d454 2 a455 1 File with the Postfix SMTP client DSA certificate in PEM format. d458 2 a459 1 File with the Postfix SMTP client DSA private key in PEM format. d462 2 a463 1 File with the Postfix SMTP client RSA private key in PEM format. d466 2 a467 1 Enable additional Postfix SMTP client logging of TLS activity. d470 3 a472 2 Log the hostname of a remote SMTP server that offers STARTTLS, when TLS is not already enabled for that server. d475 4 a478 3 Optional lookup tables with the Postfix SMTP client TLS security policy by next-hop destination; when a non-empty value is speci- fied, this overrides the obsolete smtp_tls_per_site parameter. d481 2 a482 2 List of SSL/TLS protocols that the Postfix SMTP client will use with mandatory TLS encryption. d485 2 a486 1 The verification depth for remote SMTP server certificates. d489 3 a491 2 How the Postfix SMTP client verifies the server certificate peername for the "secure" TLS security level. d494 2 a495 2 Name of the file containing the optional Postfix SMTP client TLS session cache. d498 2 a499 2 The expiration time of Postfix SMTP client TLS session cache information. d502 3 a504 2 How the Postfix SMTP client verifies the server certificate peername for the "verify" TLS security level. d507 4 a510 3 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its internal pseudo random number generator (PRNG). d512 2 a513 1 tls_high_cipherlist (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH) d517 2 a518 1 The OpenSSL cipherlist for "MEDIUM" or higher grade ciphers. d521 2 a522 1 The OpenSSL cipherlist for "LOW" or higher grade ciphers. d525 2 a526 1 The OpenSSL cipherlist for "EXPORT" or higher grade ciphers. d529 2 a530 2 The OpenSSL cipherlist for "NULL" grade ciphers that provide authentication without encryption. d534 5 a538 5 smtp_sasl_tls_verified_security_options ($smtp_sasl_tls_secu- rity_options) The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions with a verified server certificate. d543 3 a545 3 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security level (smtp_tls_secu- rity_level = fingerprint). d548 2 a549 2 The message digest algorithm used to construct remote SMTP server certificate fingerprints. d554 3 a556 2 List of TLS protocols that the Postfix SMTP client will exclude or include with opportunistic TLS encryption. d559 2 a560 2 The minimum TLS cipher grade that the Postfix SMTP client will use with opportunistic TLS encryption. d563 2 a564 2 File with the Postfix SMTP client ECDSA certificate in PEM for- mat. d567 2 a568 2 File with the Postfix SMTP client ECDSA private key in PEM for- mat. d573 4 a576 4 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends mali- cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client TLS session. d581 2 a582 17 List or bit-mask of OpenSSL bug work-arounds to disable. Available in Postfix version 2.11 and later: smtp_tls_trust_anchor_file (empty) Zero or more PEM-format files with trust-anchor certificates and/or public keys. smtp_tls_force_insecure_host_tlsa_lookup (no) Lookup the associated DANE TLSA RRset even when a hostname is not an alias and its address records lie in an unsigned zone. tls_dane_trust_anchor_digest_enable (yes) RFC 6698 trust-anchor digest support in the Postfix TLS library. tlsmgr_service_name (tlsmgr) The name of the tlsmgr(8) service entry in master.cf. d585 3 a587 3 The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a future release. d590 3 a592 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send the mail in the clear. d595 3 a597 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the clear. d600 3 a602 3 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP server certificate. d605 3 a607 3 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- name. d610 2 a611 2 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS cipher list. d614 10 a623 8 smtp_destination_concurrency_limit ($default_destination_concur- rency_limit) The maximal number of parallel deliveries to the same destina- tion via the smtp message delivery transport. smtp_destination_recipient_limit ($default_destination_recipient_limit) The maximal number of recipients per message for the smtp mes- sage delivery transport. d626 3 a628 2 The Postfix SMTP client time limit for completing a TCP connec- tion, or zero (use the operating system built-in time limit). d631 3 a633 3 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server response. d636 3 a638 2 The Postfix LMTP client time limit for sending the LHLO command, and for receiving the initial remote LMTP server response. d641 3 a643 2 The Postfix SMTP client time limit for sending the XFORWARD com- mand, and for receiving the remote SMTP server response. d646 3 a648 2 The Postfix SMTP client time limit for sending the MAIL FROM command, and for receiving the remote SMTP server response. d651 3 a653 2 The Postfix SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the remote SMTP server response. d656 3 a658 2 The Postfix SMTP client time limit for sending the SMTP DATA command, and for receiving the remote SMTP server response. d661 2 a662 2 The Postfix SMTP client time limit for sending the SMTP message content. d665 3 a667 2 The Postfix SMTP client time limit for sending the SMTP ".", and for receiving the remote SMTP server response. d670 3 a672 2 The Postfix SMTP client time limit for sending the QUIT command, and for receiving the remote SMTP server response. d677 3 a679 3 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero (no limit). d682 4 a685 3 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back relay host, or zero (no limit). d688 3 a690 2 The Postfix SMTP client time limit for sending the RSET command, and for receiving the remote SMTP server response. d695 2 a696 2 Keep Postfix LMTP client connections open for up to $max_idle seconds. d701 2 a702 2 Permanently enable SMTP connection caching for the specified destinations. d705 3 a707 2 Temporarily enable SMTP connection caching while a destination has a high volume of mail in the active queue. d710 2 a711 2 The amount of time during which Postfix will use an SMTP connec- tion repeatedly. d714 3 a716 2 When SMTP connection caching is enabled, the amount of time that an unused SMTP client socket is kept open before it is closed. d721 2 a722 2 Time limit for connection cache connect, send or receive opera- tions. d727 5 a731 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- a733 7 Available in Postfix version 2.11 and later: smtp_connection_reuse_count_limit (0) When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero (no limit). d736 3 a738 2 The increment in verbose logging level when a remote client or server matches a pattern in the debug_peer_list parameter. d741 4 a744 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified in $debug_peer_level. d747 3 a749 3 The recipient of postmaster notifications about mail delivery problems that are caused by policy, resource, software or proto- col errors. d752 3 a754 3 What categories of Postfix-generated mail are subject to before- queue content inspection by non_smtpd_milters, header_checks and body_checks. d757 2 a758 1 The list of error classes that are reported to the postmaster. d762 3 a764 2 Where the Postfix SMTP client should deliver mail when it detects a "mail loops back to myself" error condition. d767 2 a768 2 The default location of the Postfix main.cf and master.cf con- figuration files. d771 3 a773 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a built-in watchdog timer. d776 2 a777 2 The maximal number of digits after the decimal point when log- ging sub-second delay values. d780 2 a781 1 Disable DNS lookups in the Postfix SMTP and LMTP clients. d784 2 a785 2 The network interface addresses that this mail system receives mail on. d788 2 a789 2 The Internet protocols Postfix will attempt to use when making or accepting connections. d792 2 a793 2 The time limit for sending or receiving information over an internal communication channel. d796 4 a799 3 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- ery status notifications instead of "relayed". d802 2 a803 1 The default TCP port that the Postfix LMTP client connects to. d806 3 a808 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection before terminating voluntarily. d811 3 a813 2 The maximal number of incoming connections that a Postfix daemon process will service before terminating voluntarily. d816 2 a817 1 The process ID of a Postfix command or daemon process. d820 2 a821 1 The process name of a Postfix command or daemon process. d824 3 a826 2 The network interface addresses that this mail system receives mail on by way of a proxy or network address translation unit. d829 4 a832 3 The address type ("ipv6", "ipv4" or "any") that the Postfix SMTP client will try first, when a destination has IPv6 and IPv4 addresses with equal MX preference. d835 3 a837 2 An optional numerical network address that the Postfix SMTP client should bind to when making an IPv4 connection. d840 3 a842 2 An optional numerical network address that the Postfix SMTP client should bind to when making an IPv6 connection. d845 2 a846 1 The hostname to send in the SMTP EHLO or HELO command. d852 2 a853 2 What mechanisms the Postfix SMTP client uses to look up a host's IP address. d856 2 a857 1 Randomize the order of equal-preference MX host addresses. d863 3 a865 3 The mail system name that is prepended to the process name in syslog records, so that "smtpd" becomes, for example, "post- fix/smtpd". d870 2 a871 2 Optional list of relay hosts for SMTP destinations that can't be found or that are unreachable. d876 2 a877 2 Optional list of relay hosts for SMTP destinations that can't be found or that are unreachable. d897 2 a898 1 The Secure Mailer license must be distributed with this software. @ 1.1.1.5 log @Import Postfix 2.9.5. Major changes since version 2.8.x: - Support for long, non-repeating, queue IDs (queue file names). The main benefit of non-repeating names is simpler logfile analysis. See the description of "enable_long_queue_ids" in postconf(5) for details. - Memcache client support, and support to share postscreen(8) and verify(8) caches via the proxymap server. Details about memcache support are in memcache_table(5) and MEMCACHE_README. - Gradual degradation: if a database is unavailable (can't open, most read or write errors) a Postfix daemon will log a warning and continue providing the services that don't depend on that table, instead of immediately terminating with a fatal error. To terminate immediately when a database file can't be opened, specify "daemon_table_open_error_is_fatal = yes". - Revised postconf(1) command. It warns about unused parameter name=value settings in main.cf or master.cf (likely mistakes), understands "dynamic" parameter names such as names that depend on the name of a master.cf entry (finally, "postconf -n" shows all parameter settings), and it can display main.cf and master.cf in a more user-friendly format (postconf -nf, postconf -Mf). - Read/write deadline support in the SMTP client and server to defend against application-level DOS attacks that very slowly write or read data one byte at a time. @ text @d171 1 a171 1 smtp_line_length_limit (998) d196 2 a197 2 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO commands as required by RFC 2821. d204 2 a205 2 Skip remote SMTP servers that greet with a 5XX sta- tus code (go away, do not try again later). d234 3 a236 3 ing in the Postfix SMTP client, typically to trans- form a locally valid address into a globally valid address when sending mail across the Internet. d252 2 a253 2 Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. d257 3 a259 3 ing, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. a297 15 Available in Postfix version 2.9 and later: smtp_per_record_deadline (no) Change the behavior of the smtp_*_timeout time lim- its, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- sage). smtp_send_dummy_mail_auth (no) Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d302 1 a302 1 Disable the conversion of 8BITMIME format to 7BIT d317 2 a318 2 Send the non-standard XFORWARD command when the Postfix SMTP server EHLO response announces XFOR- d323 1 a323 1 Enable SASL authentication in the Postfix SMTP d327 4 a330 4 Optional Postfix SMTP client lookup tables with one username:password entry per remote hostname or domain, or sender address when sender-dependent authentication is enabled. d333 3 a335 3 Postfix SMTP client SASL security options; as of Postfix 2.3 the list of available features depends on the SASL client implementation that is selected d341 2 a342 2 If non-empty, a Postfix SMTP client filter for the remote SMTP server's list of offered SASL mecha- d349 3 a351 3 fix SMTP client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from different senders d355 3 a357 3 Implementation-specific information that the Post- fix SMTP client passes through to the SASL plug-in implementation that is selected with d361 1 a361 1 The SASL plug-in type that the Postfix SMTP client d367 2 a368 2 An optional table to prevent repeated SASL authen- tication failures with the same remote SMTP server d372 1 a372 1 The maximal age of an smtp_sasl_auth_cache_name d376 3 a378 3 When a remote SMTP server rejects a SASL authenti- cation request with a 535 reply code, defer mail delivery instead of returning mail as undeliver- a380 7 Available in Postfix version 2.9 and later: smtp_send_dummy_mail_auth (no) Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d382 1 a382 1 Detailed information about STARTTLS configuration may be d387 2 a388 2 SMTP client; when a non-empty value is specified, this overrides the obsolete parameters d394 2 a395 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d399 2 a400 2 Time limit for Postfix SMTP client write and read operations during TLS startup and shutdown hand- d404 2 a405 2 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certifi- d409 2 a410 2 Directory with PEM format certificate authority certificates that the Postfix SMTP client uses to d414 1 a414 1 File with the Postfix SMTP client RSA certificate d418 1 a418 1 The minimum TLS cipher grade that the Postfix SMTP d427 3 a429 3 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security levels. d432 1 a432 1 File with the Postfix SMTP client DSA certificate d436 1 a436 1 File with the Postfix SMTP client DSA private key d440 1 a440 1 File with the Postfix SMTP client RSA private key d444 1 a444 1 Enable additional Postfix SMTP client logging of d448 2 a449 2 Log the hostname of a remote SMTP server that offers STARTTLS, when TLS is not already enabled d455 1 a455 1 non-empty value is specified, this overrides the d459 1 a459 1 List of SSL/TLS protocols that the Postfix SMTP d463 1 a463 1 The verification depth for remote SMTP server cer- d467 2 a468 3 How the Postfix SMTP client verifies the server certificate peername for the "secure" TLS security level. d479 2 a480 3 How the Postfix SMTP client verifies the server certificate peername for the "verify" TLS security level. d483 3 a485 3 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its internal pseudo random d497 1 a497 1 The OpenSSL cipherlist for "LOW" or higher grade d505 1 a505 1 The OpenSSL cipherlist for "NULL" grade ciphers d512 2 a513 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d519 2 a520 2 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security d524 1 a524 1 The message digest algorithm used to construct d530 2 a531 2 List of TLS protocols that the Postfix SMTP client will exclude or include with opportunistic TLS d535 2 a536 2 The minimum TLS cipher grade that the Postfix SMTP client will use with opportunistic TLS encryption. d549 3 a551 3 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends malicious HELO, MAIL, RCPT, d557 1 a557 1 List or bit-mask of OpenSSL bug work-arounds to d561 1 a561 1 The following configuration parameters exist for compati- d566 2 a567 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send d571 2 a572 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the d576 1 a576 1 With mandatory TLS encryption, require that the d582 1 a582 1 TLS usage policy by next-hop destination and by d592 2 a593 2 The maximal number of parallel deliveries to the same destination via the smtp message delivery d598 1 a598 1 The maximal number of recipients per message for d602 2 a603 2 The Postfix SMTP client time limit for completing a TCP connection, or zero (use the operating system d607 3 a609 3 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server response. d612 3 a614 3 The Postfix LMTP client time limit for sending the LHLO command, and for receiving the initial remote LMTP server response. d617 2 a618 3 The Postfix SMTP client time limit for sending the XFORWARD command, and for receiving the remote SMTP server response. d621 3 a623 3 The Postfix SMTP client time limit for sending the MAIL FROM command, and for receiving the remote SMTP server response. d626 3 a628 3 The Postfix SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the remote SMTP server response. d631 3 a633 3 The Postfix SMTP client time limit for sending the SMTP DATA command, and for receiving the remote SMTP server response. d636 2 a637 2 The Postfix SMTP client time limit for sending the SMTP message content. d640 2 a641 3 The Postfix SMTP client time limit for sending the SMTP ".", and for receiving the remote SMTP server response. d644 2 a645 3 The Postfix SMTP client time limit for sending the QUIT command, and for receiving the remote SMTP server response. d651 2 a652 2 addresses that can result from Postfix SMTP client mail exchanger lookups, or zero (no limit). d656 2 a657 3 request before the Postfix SMTP client gives up or delivers to a fall-back relay host, or zero (no limit). d660 2 a661 3 The Postfix SMTP client time limit for sending the RSET command, and for receiving the remote SMTP server response. a694 10 Available in Postfix version 2.9 and later: smtp_per_record_deadline (no) Change the behavior of the smtp_*_timeout time lim- its, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- sage). d697 2 a698 2 The increment in verbose logging level when a remote client or server matches a pattern in the d702 3 a704 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified d708 2 a709 2 The recipient of postmaster notifications about mail delivery problems that are caused by policy, d713 2 a714 2 What categories of Postfix-generated mail are sub- ject to before-queue content inspection by d718 1 a718 1 The list of error classes that are reported to the d723 1 a723 1 Where the Postfix SMTP client should deliver mail d728 1 a728 1 The default location of the Postfix main.cf and d732 2 a733 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a d737 1 a737 1 The maximal number of digits after the decimal d741 1 a741 1 Disable DNS lookups in the Postfix SMTP and LMTP d748 2 a749 2 inet_protocols (all) The Internet protocols Postfix will attempt to use d757 1 a757 1 When a remote LMTP server announces no DSN support, d759 1 a759 1 send "delivered" delivery status notifications d763 1 a763 1 The default TCP port that the Postfix LMTP client d767 2 a768 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection d772 2 a773 2 The maximal number of incoming connections that a Postfix daemon process will service before termi- d777 1 a777 1 The process ID of a Postfix command or daemon d781 1 a781 1 The process name of a Postfix command or daemon d786 1 a786 1 tem receives mail on by way of a proxy or network d789 1 a789 1 smtp_address_preference (any) d792 1 a792 1 tion has IPv6 and IPv4 addresses with equal MX d796 2 a797 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d801 2 a802 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d806 1 a806 1 The hostname to send in the SMTP EHLO or HELO com- d813 1 a813 1 What mechanisms the Postfix SMTP client uses to d817 1 a817 1 Randomize the order of equal-preference MX host d824 2 a825 2 The mail system name that is prepended to the process name in syslog records, so that "smtpd" d831 1 a831 1 Optional list of relay hosts for SMTP destinations d837 1 a837 1 Optional list of relay hosts for SMTP destinations d858 1 a858 1 The Secure Mailer license must be distributed with this @ 1.1.1.6 log @Import Postfix 2.10.2. Major changes since version 2.9.* are: - Separation of relay policy (with smtpd_relay_restrictions) from spam policy (with smtpd_{client, helo, sender, recipient}_restrictions), which makes accidental open relay configuration less likely. The default is backwards compatible. - HAproxy load-balancer support for postscreen(8) and smtpd(8). The nginx proxy was already supported by Postfix 2.9 smtpd(8), using XCLIENT commands. - Support for the TLSv1 and TLSv2 protocols, as well as support to turn them off if needed for inter-operability. - Laptop-friendly configuration. By default, Postfix now uses UNIX-domain sockets instead of FIFOs, and thus avoids MTIME file system updates on an idle mail system. - Revised postconf(1) command. The "-x" option expands $name in a parameter value (both main.cf and master.cf); the "-o name=value" option overrides a main.cf parameter setting; and postconf(1) now warns about a $name that has no name=value setting. - Sendmail-style "socketmap" lookup tables. @ text @a117 1 RFC 5321 (SMTP protocol) d197 1 a197 1 and RCPT TO commands as required by RFC 5321. @ 1.1.1.6.2.1 log @Rebase. @ text @d16 31 a46 26 The Postfix SMTP+LMTP client implements the SMTP and LMTP mail delivery protocols. It processes message delivery requests from the queue man- ager. Each request specifies a queue file, a sender address, a domain or host to deliver to, and recipient information. This program expects to be run from the master(8) process manager. The SMTP+LMTP client updates the queue file and marks recipients as finished, or it informs the queue manager that delivery should be tried again at a later time. Delivery status reports are sent to the bounce(8), defer(8) or trace(8) daemon as appropriate. The SMTP+LMTP client looks up a list of mail exchanger addresses for the destination host, sorts the list by preference, and connects to each listed address until it finds a server that responds. When a server is not reachable, or when mail delivery fails due to a recoverable error condition, the SMTP+LMTP client will try to deliver the mail to an alternate host. After a successful mail transaction, a connection may be saved to the scache(8) connection cache server, so that it may be used by any SMTP+LMTP client for a subsequent transaction. By default, connection caching is enabled temporarily for destinations that have a high volume of mail in the active queue. Connection caching can be enabled permanently for specific destinations. d54 3 a56 2 Look up the mail exchangers for the specified domain, and con- nect to the specified port (default: smtp). d61 2 a62 2 Look up the address(es) of the specified host, and connect to the specified port (default: smtp). d67 3 a69 3 Connect to the host at the specified address, and connect to the specified port (default: smtp). An IPv6 address must be format- ted as [ipv6:address]. d75 4 a78 3 Connect to the local UNIX-domain server that is bound to the specified pathname. If the process runs chrooted, an absolute pathname is interpreted relative to the Postfix queue directory. d82 1 a82 1 inet:hostname:port d87 6 a92 5 Connect to the specified TCP port on the specified local or remote host. If no port is specified, connect to the port defined as lmtp in services(4). If no such service is found, the lmtp_tcp_port configuration parameter (default value of 24) will be used. An IPv6 address must be formatted as d96 4 a99 3 The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP or LMTP servers and to DNS servers on the network. The SMTP+LMTP client can be run chrooted at fixed low privilege. d121 7 a127 6 Problems and transactions are logged to syslogd(8). Corrupted message files are marked so that the queue manager can move them to the corrupt queue for further inspection. Depending on the setting of the notify_classes parameter, the postmas- ter is notified of bounces, protocol problems, and of other trouble. d130 8 a137 7 SMTP and LMTP connection caching does not work with TLS. The necessary support for TLS object passivation and re-activation does not exist without closing the session, which defeats the purpose. SMTP and LMTP connection caching assumes that SASL credentials are valid for all destinations that map onto the same IP address and TCP port. d140 14 a153 12 Before Postfix version 2.3, the LMTP client is a separate program that implements only a subset of the functionality available with SMTP: there is no support for TLS, and connections are cached in-process, making it ineffective when the client is used for multiple domains. Most smtp_xxx configuration parameters have an lmtp_xxx "mirror" param- eter for the equivalent LMTP feature. This document describes only those LMTP-related parameters that aren't simply "mirror" parameters. Changes to main.cf are picked up automatically, as smtp(8) processes run for only a limited amount of time. Use the command "postfix reload" to speed up a change. d155 2 a156 2 The text below provides only a parameter summary. See postconf(5) for more details including examples. d169 2 a170 1 Defer mail delivery when no MX record resolves to an IP address. d173 2 a174 2 The maximal length of message header and body lines that Postfix will send via SMTP. d177 3 a179 3 How long the Postfix SMTP client pauses before sending ".<CR><LF>" in order to work around the PIX firewall "<CR><LF>.<CR><LF>" bug. d182 4 a185 3 How long a message must be queued before the Postfix SMTP client turns on the PIX firewall "<CR><LF>.<CR><LF>" bug workaround for delivery through firewalls with "smtp fixup" mode turned on. d188 2 a189 2 A list that specifies zero or more workarounds for CISCO PIX firewall bugs. d192 3 a194 2 Lookup tables, indexed by the remote SMTP server address, with per-destination workarounds for CISCO PIX firewall bugs. d197 2 a198 2 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO commands as required by RFC 5321. d201 2 a202 2 A mechanism to transform replies from remote SMTP servers one line at a time. d205 2 a206 1 Skip remote SMTP servers that greet with a 5XX status code. d209 2 a210 1 Do not wait for the response to the SMTP QUIT command. d215 2 a216 2 Skip SMTP servers that greet with a 4XX status code (go away, try again later). d221 4 a224 3 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO keywords (pipelining, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO d228 4 a231 3 A case insensitive list of EHLO keywords (pipelining, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO response from a remote SMTP server. d234 4 a237 4 Optional lookup tables that perform address rewriting in the Postfix SMTP client, typically to transform a locally valid address into a globally valid address when sending mail across the Internet. d242 4 a245 3 Allow DNS CNAME records to override the servername that the Postfix SMTP client uses for logging, SASL password lookup, TLS policy decisions, or TLS certificate verification. d250 4 a253 3 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO d257 4 a260 3 A case insensitive list of LHLO keywords (pipelining, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. d265 4 a268 4 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- cid's password. d273 2 a274 1 Restricted header_checks(5) tables for the Postfix SMTP client. d277 2 a278 2 Restricted mime_header_checks(5) tables for the Postfix SMTP client. d281 2 a282 2 Restricted nested_header_checks(5) tables for the Postfix SMTP client. d285 2 a286 1 Restricted body_checks(5) tables for the Postfix SMTP client. d291 2 a292 2 An optional workaround for routers that break TCP window scal- ing. d302 5 a306 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d310 3 a312 7 Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. Available in Postfix version 2.11 and later: smtp_dns_support_level (empty) Level of DNS support in the Postfix SMTP client. d318 2 a319 1 Disable the conversion of 8BITMIME format to 7BIT format. d322 2 a323 1 The maximal length of MIME multipart boundary strings. d326 2 a327 1 The maximal recursion level that the MIME processor will handle. d333 3 a335 2 Send the non-standard XFORWARD command when the Postfix SMTP server EHLO response announces XFORWARD support. d339 2 a340 1 Enable SASL authentication in the Postfix SMTP client. d343 4 a346 3 Optional Postfix SMTP client lookup tables with one user- name:password entry per remote hostname or domain, or sender address when sender-dependent authentication is enabled. d349 4 a352 3 Postfix SMTP client SASL security options; as of Postfix 2.3 the list of available features depends on the SASL client implemen- tation that is selected with smtp_sasl_type. d357 3 a359 2 If non-empty, a Postfix SMTP client filter for the remote SMTP server's list of offered SASL mechanisms. d364 5 a368 4 Enable sender-dependent authentication in the Postfix SMTP client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from dif- ferent senders will use the appropriate credentials. d371 4 a374 3 Implementation-specific information that the Postfix SMTP client passes through to the SASL plug-in implementation that is selected with smtp_sasl_type. d377 2 a378 2 The SASL plug-in type that the Postfix SMTP client should use for authentication. d383 3 a385 3 An optional table to prevent repeated SASL authentication fail- ures with the same remote SMTP server hostname, username and password. d388 2 a389 2 The maximal age of an smtp_sasl_auth_cache_name entry before it is removed. d392 4 a395 3 When a remote SMTP server rejects a SASL authentication request with a 535 reply code, defer mail delivery instead of returning mail as undeliverable. d400 3 a402 2 Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d405 2 a406 2 Detailed information about STARTTLS configuration may be found in the TLS_README document. d409 4 a412 3 The default SMTP TLS security level for the Postfix SMTP client; when a non-empty value is specified, this overrides the obsolete parameters smtp_use_tls, smtp_enforce_tls, and d415 5 a419 3 smtp_sasl_tls_security_options ($smtp_sasl_security_options) The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions. d422 3 a424 2 Time limit for Postfix SMTP client write and read operations during TLS startup and shutdown handshake procedures. d427 3 a429 3 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA cer- tificates. d432 3 a434 3 Directory with PEM format certificate authority certificates that the Postfix SMTP client uses to verify a remote SMTP server certificate. d437 2 a438 1 File with the Postfix SMTP client RSA certificate in PEM format. d441 2 a442 2 The minimum TLS cipher grade that the Postfix SMTP client will use with mandatory TLS encryption. d445 3 a447 2 List of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at all TLS security levels. d450 3 a452 3 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security lev- els. d455 2 a456 1 File with the Postfix SMTP client DSA certificate in PEM format. d459 2 a460 1 File with the Postfix SMTP client DSA private key in PEM format. d463 2 a464 1 File with the Postfix SMTP client RSA private key in PEM format. d467 2 a468 1 Enable additional Postfix SMTP client logging of TLS activity. d471 3 a473 2 Log the hostname of a remote SMTP server that offers STARTTLS, when TLS is not already enabled for that server. d476 4 a479 3 Optional lookup tables with the Postfix SMTP client TLS security policy by next-hop destination; when a non-empty value is speci- fied, this overrides the obsolete smtp_tls_per_site parameter. d482 2 a483 2 List of SSL/TLS protocols that the Postfix SMTP client will use with mandatory TLS encryption. d486 2 a487 1 The verification depth for remote SMTP server certificates. d490 3 a492 2 How the Postfix SMTP client verifies the server certificate peername for the "secure" TLS security level. d495 2 a496 2 Name of the file containing the optional Postfix SMTP client TLS session cache. d499 2 a500 2 The expiration time of Postfix SMTP client TLS session cache information. d503 3 a505 2 How the Postfix SMTP client verifies the server certificate peername for the "verify" TLS security level. d508 4 a511 3 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its internal pseudo random number generator (PRNG). d513 2 a514 1 tls_high_cipherlist (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH) d518 2 a519 1 The OpenSSL cipherlist for "MEDIUM" or higher grade ciphers. d522 2 a523 1 The OpenSSL cipherlist for "LOW" or higher grade ciphers. d526 2 a527 1 The OpenSSL cipherlist for "EXPORT" or higher grade ciphers. d530 2 a531 2 The OpenSSL cipherlist for "NULL" grade ciphers that provide authentication without encryption. d535 5 a539 5 smtp_sasl_tls_verified_security_options ($smtp_sasl_tls_secu- rity_options) The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions with a verified server certificate. d544 3 a546 3 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security level (smtp_tls_secu- rity_level = fingerprint). d549 2 a550 2 The message digest algorithm used to construct remote SMTP server certificate fingerprints. d555 3 a557 2 List of TLS protocols that the Postfix SMTP client will exclude or include with opportunistic TLS encryption. d560 2 a561 2 The minimum TLS cipher grade that the Postfix SMTP client will use with opportunistic TLS encryption. d564 2 a565 2 File with the Postfix SMTP client ECDSA certificate in PEM for- mat. d568 2 a569 2 File with the Postfix SMTP client ECDSA private key in PEM for- mat. d574 4 a577 4 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends mali- cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client TLS session. d582 2 a583 17 List or bit-mask of OpenSSL bug work-arounds to disable. Available in Postfix version 2.11 and later: smtp_tls_trust_anchor_file (empty) Zero or more PEM-format files with trust-anchor certificates and/or public keys. smtp_tls_force_insecure_host_tlsa_lookup (no) Lookup the associated DANE TLSA RRset even when a hostname is not an alias and its address records lie in an unsigned zone. tls_dane_trust_anchor_digest_enable (yes) RFC 6698 trust-anchor digest support in the Postfix TLS library. tlsmgr_service_name (tlsmgr) The name of the tlsmgr(8) service entry in master.cf. d586 3 a588 3 The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a future release. d591 3 a593 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send the mail in the clear. d596 3 a598 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the clear. d601 3 a603 3 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP server certificate. d606 3 a608 3 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- name. d611 2 a612 2 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS cipher list. d615 10 a624 8 smtp_destination_concurrency_limit ($default_destination_concur- rency_limit) The maximal number of parallel deliveries to the same destina- tion via the smtp message delivery transport. smtp_destination_recipient_limit ($default_destination_recipient_limit) The maximal number of recipients per message for the smtp mes- sage delivery transport. d627 3 a629 2 The Postfix SMTP client time limit for completing a TCP connec- tion, or zero (use the operating system built-in time limit). d632 3 a634 3 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server response. d637 3 a639 2 The Postfix LMTP client time limit for sending the LHLO command, and for receiving the initial remote LMTP server response. d642 3 a644 2 The Postfix SMTP client time limit for sending the XFORWARD com- mand, and for receiving the remote SMTP server response. d647 3 a649 2 The Postfix SMTP client time limit for sending the MAIL FROM command, and for receiving the remote SMTP server response. d652 3 a654 2 The Postfix SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the remote SMTP server response. d657 3 a659 2 The Postfix SMTP client time limit for sending the SMTP DATA command, and for receiving the remote SMTP server response. d662 2 a663 2 The Postfix SMTP client time limit for sending the SMTP message content. d666 3 a668 2 The Postfix SMTP client time limit for sending the SMTP ".", and for receiving the remote SMTP server response. d671 3 a673 2 The Postfix SMTP client time limit for sending the QUIT command, and for receiving the remote SMTP server response. d678 3 a680 3 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero (no limit). d683 4 a686 3 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back relay host, or zero (no limit). d689 3 a691 2 The Postfix SMTP client time limit for sending the RSET command, and for receiving the remote SMTP server response. d696 2 a697 2 Keep Postfix LMTP client connections open for up to $max_idle seconds. d702 2 a703 2 Permanently enable SMTP connection caching for the specified destinations. d706 3 a708 2 Temporarily enable SMTP connection caching while a destination has a high volume of mail in the active queue. d711 2 a712 2 The amount of time during which Postfix will use an SMTP connec- tion repeatedly. d715 3 a717 2 When SMTP connection caching is enabled, the amount of time that an unused SMTP client socket is kept open before it is closed. d722 2 a723 2 Time limit for connection cache connect, send or receive opera- tions. d728 5 a732 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- a734 7 Available in Postfix version 2.11 and later: smtp_connection_reuse_count_limit (0) When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero (no limit). d737 3 a739 2 The increment in verbose logging level when a remote client or server matches a pattern in the debug_peer_list parameter. d742 4 a745 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified in $debug_peer_level. d748 3 a750 3 The recipient of postmaster notifications about mail delivery problems that are caused by policy, resource, software or proto- col errors. d753 3 a755 3 What categories of Postfix-generated mail are subject to before- queue content inspection by non_smtpd_milters, header_checks and body_checks. d758 2 a759 1 The list of error classes that are reported to the postmaster. d763 3 a765 2 Where the Postfix SMTP client should deliver mail when it detects a "mail loops back to myself" error condition. d768 2 a769 2 The default location of the Postfix main.cf and master.cf con- figuration files. d772 3 a774 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a built-in watchdog timer. d777 2 a778 2 The maximal number of digits after the decimal point when log- ging sub-second delay values. d781 2 a782 1 Disable DNS lookups in the Postfix SMTP and LMTP clients. d785 2 a786 2 The network interface addresses that this mail system receives mail on. d789 2 a790 2 The Internet protocols Postfix will attempt to use when making or accepting connections. d793 2 a794 2 The time limit for sending or receiving information over an internal communication channel. d797 4 a800 3 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- ery status notifications instead of "relayed". d803 2 a804 1 The default TCP port that the Postfix LMTP client connects to. d807 3 a809 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection before terminating voluntarily. d812 3 a814 2 The maximal number of incoming connections that a Postfix daemon process will service before terminating voluntarily. d817 2 a818 1 The process ID of a Postfix command or daemon process. d821 2 a822 1 The process name of a Postfix command or daemon process. d825 3 a827 2 The network interface addresses that this mail system receives mail on by way of a proxy or network address translation unit. d830 4 a833 3 The address type ("ipv6", "ipv4" or "any") that the Postfix SMTP client will try first, when a destination has IPv6 and IPv4 addresses with equal MX preference. d836 3 a838 2 An optional numerical network address that the Postfix SMTP client should bind to when making an IPv4 connection. d841 3 a843 2 An optional numerical network address that the Postfix SMTP client should bind to when making an IPv6 connection. d846 2 a847 1 The hostname to send in the SMTP EHLO or HELO command. d853 2 a854 2 What mechanisms the Postfix SMTP client uses to look up a host's IP address. d857 2 a858 1 Randomize the order of equal-preference MX host addresses. d864 3 a866 3 The mail system name that is prepended to the process name in syslog records, so that "smtpd" becomes, for example, "post- fix/smtpd". d871 2 a872 2 Optional list of relay hosts for SMTP destinations that can't be found or that are unreachable. d877 2 a878 2 Optional list of relay hosts for SMTP destinations that can't be found or that are unreachable. d898 2 a899 1 The Secure Mailer license must be distributed with this software. @ 1.1.1.7 log @Import Postfix 2.11.1. The main changes since version 2.10.* are: - Support for PKI-less TLS server certificate verification with DANE (DNS-based Authentication of Named Entities) where the CA public key or the server certificate is identified via DNSSEC lookup. This requires a DNS resolver that validates DNSSEC replies. The problem with conventional PKI is that there are literally hundreds of organizations world-wide that can provide a certificate in anyone's name. DANE limits trust to the people who control the target DNS zone and its parent zones. - A new postscreen_dnsbl_whitelist_threshold feature to allow clients to skip postscreen tests based on their DNSBL score. This can eliminate email delays due to "after 220 greeting" protocol tests, which otherwise require that a client reconnects before it can deliver mail. Some providers such as Google don't retry from the same IP address, and that can result in large email delivery delays. - The recipient_delimiter feature now supports different delimiters, for example both "+" and "-". As before, this implementation recognizes exactly one delimiter character per email address, and exactly one address extension per email address. - Advanced master.cf query/update support to access service attributes as "name = value" pairs. For example to turn off chroot on all services use "postconf -F '*/*/chroot = n'", and to change/add a "-o name=value" setting use "postconf -P 'smtp/inet/name = value'". This was developed primarily to allow automated tools to manage Postfix systems without having to parse Postfix configuration files. @ text @d16 31 a46 26 The Postfix SMTP+LMTP client implements the SMTP and LMTP mail delivery protocols. It processes message delivery requests from the queue man- ager. Each request specifies a queue file, a sender address, a domain or host to deliver to, and recipient information. This program expects to be run from the master(8) process manager. The SMTP+LMTP client updates the queue file and marks recipients as finished, or it informs the queue manager that delivery should be tried again at a later time. Delivery status reports are sent to the bounce(8), defer(8) or trace(8) daemon as appropriate. The SMTP+LMTP client looks up a list of mail exchanger addresses for the destination host, sorts the list by preference, and connects to each listed address until it finds a server that responds. When a server is not reachable, or when mail delivery fails due to a recoverable error condition, the SMTP+LMTP client will try to deliver the mail to an alternate host. After a successful mail transaction, a connection may be saved to the scache(8) connection cache server, so that it may be used by any SMTP+LMTP client for a subsequent transaction. By default, connection caching is enabled temporarily for destinations that have a high volume of mail in the active queue. Connection caching can be enabled permanently for specific destinations. d54 3 a56 2 Look up the mail exchangers for the specified domain, and con- nect to the specified port (default: smtp). d61 2 a62 2 Look up the address(es) of the specified host, and connect to the specified port (default: smtp). d67 3 a69 3 Connect to the host at the specified address, and connect to the specified port (default: smtp). An IPv6 address must be format- ted as [ipv6:address]. d75 4 a78 3 Connect to the local UNIX-domain server that is bound to the specified pathname. If the process runs chrooted, an absolute pathname is interpreted relative to the Postfix queue directory. d82 1 a82 1 inet:hostname:port d87 6 a92 5 Connect to the specified TCP port on the specified local or remote host. If no port is specified, connect to the port defined as lmtp in services(4). If no such service is found, the lmtp_tcp_port configuration parameter (default value of 24) will be used. An IPv6 address must be formatted as d96 4 a99 3 The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP or LMTP servers and to DNS servers on the network. The SMTP+LMTP client can be run chrooted at fixed low privilege. d121 7 a127 6 Problems and transactions are logged to syslogd(8). Corrupted message files are marked so that the queue manager can move them to the corrupt queue for further inspection. Depending on the setting of the notify_classes parameter, the postmas- ter is notified of bounces, protocol problems, and of other trouble. d130 8 a137 7 SMTP and LMTP connection caching does not work with TLS. The necessary support for TLS object passivation and re-activation does not exist without closing the session, which defeats the purpose. SMTP and LMTP connection caching assumes that SASL credentials are valid for all destinations that map onto the same IP address and TCP port. d140 14 a153 12 Before Postfix version 2.3, the LMTP client is a separate program that implements only a subset of the functionality available with SMTP: there is no support for TLS, and connections are cached in-process, making it ineffective when the client is used for multiple domains. Most smtp_xxx configuration parameters have an lmtp_xxx "mirror" param- eter for the equivalent LMTP feature. This document describes only those LMTP-related parameters that aren't simply "mirror" parameters. Changes to main.cf are picked up automatically, as smtp(8) processes run for only a limited amount of time. Use the command "postfix reload" to speed up a change. d155 2 a156 2 The text below provides only a parameter summary. See postconf(5) for more details including examples. d169 2 a170 1 Defer mail delivery when no MX record resolves to an IP address. d173 2 a174 2 The maximal length of message header and body lines that Postfix will send via SMTP. d177 3 a179 3 How long the Postfix SMTP client pauses before sending ".<CR><LF>" in order to work around the PIX firewall "<CR><LF>.<CR><LF>" bug. d182 4 a185 3 How long a message must be queued before the Postfix SMTP client turns on the PIX firewall "<CR><LF>.<CR><LF>" bug workaround for delivery through firewalls with "smtp fixup" mode turned on. d188 2 a189 2 A list that specifies zero or more workarounds for CISCO PIX firewall bugs. d192 3 a194 2 Lookup tables, indexed by the remote SMTP server address, with per-destination workarounds for CISCO PIX firewall bugs. d197 2 a198 2 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO commands as required by RFC 5321. d201 2 a202 2 A mechanism to transform replies from remote SMTP servers one line at a time. d205 2 a206 1 Skip remote SMTP servers that greet with a 5XX status code. d209 2 a210 1 Do not wait for the response to the SMTP QUIT command. d215 2 a216 2 Skip SMTP servers that greet with a 4XX status code (go away, try again later). d221 4 a224 3 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO keywords (pipelining, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO d228 4 a231 3 A case insensitive list of EHLO keywords (pipelining, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO response from a remote SMTP server. d234 4 a237 4 Optional lookup tables that perform address rewriting in the Postfix SMTP client, typically to transform a locally valid address into a globally valid address when sending mail across the Internet. d242 4 a245 3 Allow DNS CNAME records to override the servername that the Postfix SMTP client uses for logging, SASL password lookup, TLS policy decisions, or TLS certificate verification. d250 4 a253 3 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO d257 4 a260 3 A case insensitive list of LHLO keywords (pipelining, starttls, auth, etc.) that the Postfix LMTP client will ignore in the LHLO response from a remote LMTP server. d265 4 a268 4 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- cid's password. d273 2 a274 1 Restricted header_checks(5) tables for the Postfix SMTP client. d277 2 a278 2 Restricted mime_header_checks(5) tables for the Postfix SMTP client. d281 2 a282 2 Restricted nested_header_checks(5) tables for the Postfix SMTP client. d285 2 a286 1 Restricted body_checks(5) tables for the Postfix SMTP client. d291 2 a292 2 An optional workaround for routers that break TCP window scal- ing. d302 5 a306 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d310 3 a312 7 Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. Available in Postfix version 2.11 and later: smtp_dns_support_level (empty) Level of DNS support in the Postfix SMTP client. d318 2 a319 1 Disable the conversion of 8BITMIME format to 7BIT format. d322 2 a323 1 The maximal length of MIME multipart boundary strings. d326 2 a327 1 The maximal recursion level that the MIME processor will handle. d333 3 a335 2 Send the non-standard XFORWARD command when the Postfix SMTP server EHLO response announces XFORWARD support. d339 2 a340 1 Enable SASL authentication in the Postfix SMTP client. d343 4 a346 3 Optional Postfix SMTP client lookup tables with one user- name:password entry per remote hostname or domain, or sender address when sender-dependent authentication is enabled. d349 4 a352 3 Postfix SMTP client SASL security options; as of Postfix 2.3 the list of available features depends on the SASL client implemen- tation that is selected with smtp_sasl_type. d357 3 a359 2 If non-empty, a Postfix SMTP client filter for the remote SMTP server's list of offered SASL mechanisms. d364 5 a368 4 Enable sender-dependent authentication in the Postfix SMTP client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from dif- ferent senders will use the appropriate credentials. d371 4 a374 3 Implementation-specific information that the Postfix SMTP client passes through to the SASL plug-in implementation that is selected with smtp_sasl_type. d377 2 a378 2 The SASL plug-in type that the Postfix SMTP client should use for authentication. d383 3 a385 3 An optional table to prevent repeated SASL authentication fail- ures with the same remote SMTP server hostname, username and password. d388 2 a389 2 The maximal age of an smtp_sasl_auth_cache_name entry before it is removed. d392 4 a395 3 When a remote SMTP server rejects a SASL authentication request with a 535 reply code, defer mail delivery instead of returning mail as undeliverable. d400 3 a402 2 Whether or not to append the "AUTH=<>" option to the MAIL FROM command in SASL-authenticated SMTP sessions. d405 2 a406 2 Detailed information about STARTTLS configuration may be found in the TLS_README document. d409 4 a412 3 The default SMTP TLS security level for the Postfix SMTP client; when a non-empty value is specified, this overrides the obsolete parameters smtp_use_tls, smtp_enforce_tls, and d415 5 a419 3 smtp_sasl_tls_security_options ($smtp_sasl_security_options) The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions. d422 3 a424 2 Time limit for Postfix SMTP client write and read operations during TLS startup and shutdown handshake procedures. d427 3 a429 3 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA cer- tificates. d432 3 a434 3 Directory with PEM format certificate authority certificates that the Postfix SMTP client uses to verify a remote SMTP server certificate. d437 2 a438 1 File with the Postfix SMTP client RSA certificate in PEM format. d441 2 a442 2 The minimum TLS cipher grade that the Postfix SMTP client will use with mandatory TLS encryption. d445 3 a447 2 List of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at all TLS security levels. d450 3 a452 3 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security lev- els. d455 2 a456 1 File with the Postfix SMTP client DSA certificate in PEM format. d459 2 a460 1 File with the Postfix SMTP client DSA private key in PEM format. d463 2 a464 1 File with the Postfix SMTP client RSA private key in PEM format. d467 2 a468 1 Enable additional Postfix SMTP client logging of TLS activity. d471 3 a473 2 Log the hostname of a remote SMTP server that offers STARTTLS, when TLS is not already enabled for that server. d476 4 a479 3 Optional lookup tables with the Postfix SMTP client TLS security policy by next-hop destination; when a non-empty value is speci- fied, this overrides the obsolete smtp_tls_per_site parameter. d482 2 a483 2 List of SSL/TLS protocols that the Postfix SMTP client will use with mandatory TLS encryption. d486 2 a487 1 The verification depth for remote SMTP server certificates. d490 3 a492 2 How the Postfix SMTP client verifies the server certificate peername for the "secure" TLS security level. d495 2 a496 2 Name of the file containing the optional Postfix SMTP client TLS session cache. d499 2 a500 2 The expiration time of Postfix SMTP client TLS session cache information. d503 3 a505 2 How the Postfix SMTP client verifies the server certificate peername for the "verify" TLS security level. d508 4 a511 3 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its internal pseudo random number generator (PRNG). d513 2 a514 1 tls_high_cipherlist (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH) d518 2 a519 1 The OpenSSL cipherlist for "MEDIUM" or higher grade ciphers. d522 2 a523 1 The OpenSSL cipherlist for "LOW" or higher grade ciphers. d526 2 a527 1 The OpenSSL cipherlist for "EXPORT" or higher grade ciphers. d530 2 a531 2 The OpenSSL cipherlist for "NULL" grade ciphers that provide authentication without encryption. d535 5 a539 5 smtp_sasl_tls_verified_security_options ($smtp_sasl_tls_secu- rity_options) The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions with a verified server certificate. d544 3 a546 3 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security level (smtp_tls_secu- rity_level = fingerprint). d549 2 a550 2 The message digest algorithm used to construct remote SMTP server certificate fingerprints. d555 3 a557 2 List of TLS protocols that the Postfix SMTP client will exclude or include with opportunistic TLS encryption. d560 2 a561 2 The minimum TLS cipher grade that the Postfix SMTP client will use with opportunistic TLS encryption. d564 2 a565 2 File with the Postfix SMTP client ECDSA certificate in PEM for- mat. d568 2 a569 2 File with the Postfix SMTP client ECDSA private key in PEM for- mat. d574 4 a577 4 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends mali- cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client TLS session. d582 2 a583 17 List or bit-mask of OpenSSL bug work-arounds to disable. Available in Postfix version 2.11 and later: smtp_tls_trust_anchor_file (empty) Zero or more PEM-format files with trust-anchor certificates and/or public keys. smtp_tls_force_insecure_host_tlsa_lookup (no) Lookup the associated DANE TLSA RRset even when a hostname is not an alias and its address records lie in an unsigned zone. tls_dane_trust_anchor_digest_enable (yes) RFC 6698 trust-anchor digest support in the Postfix TLS library. tlsmgr_service_name (tlsmgr) The name of the tlsmgr(8) service entry in master.cf. d586 3 a588 3 The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a future release. d591 3 a593 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send the mail in the clear. d596 3 a598 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the clear. d601 3 a603 3 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP server certificate. d606 3 a608 3 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- name. d611 2 a612 2 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS cipher list. d615 10 a624 8 smtp_destination_concurrency_limit ($default_destination_concur- rency_limit) The maximal number of parallel deliveries to the same destina- tion via the smtp message delivery transport. smtp_destination_recipient_limit ($default_destination_recipient_limit) The maximal number of recipients per message for the smtp mes- sage delivery transport. d627 3 a629 2 The Postfix SMTP client time limit for completing a TCP connec- tion, or zero (use the operating system built-in time limit). d632 3 a634 3 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server response. d637 3 a639 2 The Postfix LMTP client time limit for sending the LHLO command, and for receiving the initial remote LMTP server response. d642 3 a644 2 The Postfix SMTP client time limit for sending the XFORWARD com- mand, and for receiving the remote SMTP server response. d647 3 a649 2 The Postfix SMTP client time limit for sending the MAIL FROM command, and for receiving the remote SMTP server response. d652 3 a654 2 The Postfix SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the remote SMTP server response. d657 3 a659 2 The Postfix SMTP client time limit for sending the SMTP DATA command, and for receiving the remote SMTP server response. d662 2 a663 2 The Postfix SMTP client time limit for sending the SMTP message content. d666 3 a668 2 The Postfix SMTP client time limit for sending the SMTP ".", and for receiving the remote SMTP server response. d671 3 a673 2 The Postfix SMTP client time limit for sending the QUIT command, and for receiving the remote SMTP server response. d678 3 a680 3 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero (no limit). d683 4 a686 3 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back relay host, or zero (no limit). d689 3 a691 2 The Postfix SMTP client time limit for sending the RSET command, and for receiving the remote SMTP server response. d696 2 a697 2 Keep Postfix LMTP client connections open for up to $max_idle seconds. d702 2 a703 2 Permanently enable SMTP connection caching for the specified destinations. d706 3 a708 2 Temporarily enable SMTP connection caching while a destination has a high volume of mail in the active queue. d711 2 a712 2 The amount of time during which Postfix will use an SMTP connec- tion repeatedly. d715 3 a717 2 When SMTP connection caching is enabled, the amount of time that an unused SMTP client socket is kept open before it is closed. d722 2 a723 2 Time limit for connection cache connect, send or receive opera- tions. d728 5 a732 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- a734 7 Available in Postfix version 2.11 and later: smtp_connection_reuse_count_limit (0) When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero (no limit). d737 3 a739 2 The increment in verbose logging level when a remote client or server matches a pattern in the debug_peer_list parameter. d742 4 a745 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified in $debug_peer_level. d748 3 a750 3 The recipient of postmaster notifications about mail delivery problems that are caused by policy, resource, software or proto- col errors. d753 3 a755 3 What categories of Postfix-generated mail are subject to before- queue content inspection by non_smtpd_milters, header_checks and body_checks. d758 2 a759 1 The list of error classes that are reported to the postmaster. d763 3 a765 2 Where the Postfix SMTP client should deliver mail when it detects a "mail loops back to myself" error condition. d768 2 a769 2 The default location of the Postfix main.cf and master.cf con- figuration files. d772 3 a774 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a built-in watchdog timer. d777 2 a778 2 The maximal number of digits after the decimal point when log- ging sub-second delay values. d781 2 a782 1 Disable DNS lookups in the Postfix SMTP and LMTP clients. d785 2 a786 2 The network interface addresses that this mail system receives mail on. d789 2 a790 2 The Internet protocols Postfix will attempt to use when making or accepting connections. d793 2 a794 2 The time limit for sending or receiving information over an internal communication channel. d797 4 a800 3 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- ery status notifications instead of "relayed". d803 2 a804 1 The default TCP port that the Postfix LMTP client connects to. d807 3 a809 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection before terminating voluntarily. d812 3 a814 2 The maximal number of incoming connections that a Postfix daemon process will service before terminating voluntarily. d817 2 a818 1 The process ID of a Postfix command or daemon process. d821 2 a822 1 The process name of a Postfix command or daemon process. d825 3 a827 2 The network interface addresses that this mail system receives mail on by way of a proxy or network address translation unit. d830 4 a833 3 The address type ("ipv6", "ipv4" or "any") that the Postfix SMTP client will try first, when a destination has IPv6 and IPv4 addresses with equal MX preference. d836 3 a838 2 An optional numerical network address that the Postfix SMTP client should bind to when making an IPv4 connection. d841 3 a843 2 An optional numerical network address that the Postfix SMTP client should bind to when making an IPv6 connection. d846 2 a847 1 The hostname to send in the SMTP EHLO or HELO command. d853 2 a854 2 What mechanisms the Postfix SMTP client uses to look up a host's IP address. d857 2 a858 1 Randomize the order of equal-preference MX host addresses. d864 3 a866 3 The mail system name that is prepended to the process name in syslog records, so that "smtpd" becomes, for example, "post- fix/smtpd". d871 2 a872 2 Optional list of relay hosts for SMTP destinations that can't be found or that are unreachable. d877 2 a878 2 Optional list of relay hosts for SMTP destinations that can't be found or that are unreachable. d898 2 a899 1 The Secure Mailer license must be distributed with this software. @ 1.1.1.8 log @Import Postfix 2.11.6. Changes since version 2.11.4: - Preparation for OpenSSL 1.2 API changes - The sender_dependent_relayhost_maps feature ignored the relayhost setting in the case of a DUNNO lookup result. It would use the recipient domain instead. - The default TLS settings no longer enable export-grade ciphers, and no longer enable the SSLv2 and SSLv3 protocols. These ciphers and protocols have little if any legitimate use today, and have instead become a vehicle for downgrade attacks. @ text @d435 1 a435 1 smtp_tls_mandatory_protocols (!SSLv2, !SSLv3) d500 1 a500 1 smtp_tls_protocols (!SSLv2, !SSLv3) d504 1 a504 1 smtp_tls_ciphers (medium) @ 1.1.1.8.4.1 log @Sync with HEAD @ text @a109 3 RFC 6531 (Internationalized SMTP) RFC 6533 (Internationalized Delivery Status Notifications) RFC 7672 (SMTP security via opportunistic DANE TLS) d222 3 a224 4 When the remote SMTP servername is a DNS CNAME, replace the servername with the result from CNAME expansion for the purpose of logging, SASL password lookup, TLS policy decisions, or TLS certificate verification. d229 2 a230 2 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, d235 1 a235 1 A case insensitive list of LHLO keywords (pipelining, starttls, d242 3 a244 3 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- d250 1 a250 1 Restricted header_checks(5) tables for the Postfix SMTP client. d253 1 a253 1 Restricted mime_header_checks(5) tables for the Postfix SMTP d257 1 a257 1 Restricted nested_header_checks(5) tables for the Postfix SMTP d266 1 a266 1 An optional workaround for routers that break TCP window scal- d277 4 a280 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d284 1 a284 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM a291 10 Available in Postfix version 3.0 and later: smtp_delivery_status_filter ($default_delivery_status_filter) Optional filter for the smtp(8) delivery agent to change the delivery status code or explanatory text of successful or unsuc- cessful deliveries. smtp_dns_reply_filter (empty) Optional filter for Postfix SMTP client DNS lookup results. d308 1 a308 1 Send the non-standard XFORWARD command when the Postfix SMTP d316 3 a318 3 Optional Postfix SMTP client lookup tables with one user- name:password entry per sender, remote hostname or next-hop domain. d322 1 a322 1 list of available features depends on the SASL client implemen- d328 1 a328 1 If non-empty, a Postfix SMTP client filter for the remote SMTP d335 2 a336 2 client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from dif- d341 1 a341 1 passes through to the SASL plug-in implementation that is d345 1 a345 1 The SASL plug-in type that the Postfix SMTP client should use d351 2 a352 2 An optional table to prevent repeated SASL authentication fail- ures with the same remote SMTP server hostname, username and d356 1 a356 1 The maximal age of an smtp_sasl_auth_cache_name entry before it d360 2 a361 2 When a remote SMTP server rejects a SASL authentication request with a 535 reply code, defer mail delivery instead of returning d367 1 a367 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d371 1 a371 1 Detailed information about STARTTLS configuration may be found in the d381 1 a381 1 The SASL authentication security options that the Postfix SMTP d385 1 a385 1 Time limit for Postfix SMTP client write and read operations d389 2 a390 2 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA cer- d394 1 a394 1 Directory with PEM format Certification Authority certificates d402 1 a402 1 The minimum TLS cipher grade that the Postfix SMTP client will d410 2 a411 2 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security lev- d427 1 a427 1 Log the hostname of a remote SMTP server that offers STARTTLS, d436 1 a436 1 List of SSL/TLS protocols that the Postfix SMTP client will use d443 1 a443 1 How the Postfix SMTP client verifies the server certificate d451 1 a451 1 The expiration time of Postfix SMTP client TLS session cache d455 1 a455 1 How the Postfix SMTP client verifies the server certificate d459 2 a460 2 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its d463 2 a464 2 tls_high_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "high" grade ciphers. d466 2 a467 2 tls_medium_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "medium" or higher grade ciphers. d469 2 a470 2 tls_low_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "low" or higher grade ciphers. d472 2 a473 2 tls_export_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "export" or higher grade ciphers. d476 1 a476 1 The OpenSSL cipherlist for "NULL" grade ciphers that provide d483 2 a484 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions with a verified d490 2 a491 2 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security level (smtp_tls_secu- d495 1 a495 1 The message digest algorithm used to construct remote SMTP d501 1 a501 1 List of TLS protocols that the Postfix SMTP client will exclude d505 1 a505 1 The minimum TLS cipher grade that the Postfix SMTP client will d509 1 a509 1 File with the Postfix SMTP client ECDSA certificate in PEM for- d513 1 a513 1 File with the Postfix SMTP client ECDSA private key in PEM for- d519 3 a521 3 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends mali- cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client d532 1 a532 1 Zero or more PEM-format files with trust-anchor certificates d536 1 a536 1 Lookup the associated DANE TLSA RRset even when a hostname is a544 13 Available in Postfix version 3.0 and later: smtp_tls_wrappermode (no) Request that the Postfix SMTP client connects using the legacy SMTPS protocol instead of using the STARTTLS command. Available in Postfix version 3.1 and later: smtp_tls_dane_insecure_mx_policy (dane) The TLS policy for MX hosts with "secure" TLSA records when the nexthop destination security level is dane, but the MX record was found via an "insecure" MX lookup. a684 11 SMTPUTF8 CONTROLS Preliminary SMTPUTF8 support is introduced with Postfix 3.0. smtputf8_enable (yes) Enable preliminary SMTPUTF8 support for the protocols described in RFC 6531..6533. smtputf8_autodetect_classes (sendmail, verify) Detect that a message requires SMTPUTF8 support for the speci- fied mail origin classes. d701 3 a703 3 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, header_checks and body_checks. d780 1 a780 1 The hostname to send in the SMTP HELO or EHLO command. a811 12 Available with Postfix 3.0 and later: smtp_address_verify_target (rcpt) In the context of email address verification, the SMTP protocol stage that determines whether an email address is deliverable. Available with Postfix 3.1 and later: lmtp_fallback_relay (empty) Optional list of relay hosts for LMTP destinations that can't be found or that are unreachable. a837 5 Wietse Venema Google, Inc. 111 8th Avenue New York, NY 10011, USA @ 1.1.1.8.2.1 log @Sync with HEAD @ text @a109 3 RFC 6531 (Internationalized SMTP) RFC 6533 (Internationalized Delivery Status Notifications) RFC 7672 (SMTP security via opportunistic DANE TLS) d222 3 a224 4 When the remote SMTP servername is a DNS CNAME, replace the servername with the result from CNAME expansion for the purpose of logging, SASL password lookup, TLS policy decisions, or TLS certificate verification. d229 2 a230 2 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, d235 1 a235 1 A case insensitive list of LHLO keywords (pipelining, starttls, d242 3 a244 3 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- d250 1 a250 1 Restricted header_checks(5) tables for the Postfix SMTP client. d253 1 a253 1 Restricted mime_header_checks(5) tables for the Postfix SMTP d257 1 a257 1 Restricted nested_header_checks(5) tables for the Postfix SMTP d266 1 a266 1 An optional workaround for routers that break TCP window scal- d277 4 a280 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d284 1 a284 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM a291 10 Available in Postfix version 3.0 and later: smtp_delivery_status_filter ($default_delivery_status_filter) Optional filter for the smtp(8) delivery agent to change the delivery status code or explanatory text of successful or unsuc- cessful deliveries. smtp_dns_reply_filter (empty) Optional filter for Postfix SMTP client DNS lookup results. d308 1 a308 1 Send the non-standard XFORWARD command when the Postfix SMTP d316 3 a318 3 Optional Postfix SMTP client lookup tables with one user- name:password entry per sender, remote hostname or next-hop domain. d322 1 a322 1 list of available features depends on the SASL client implemen- d328 1 a328 1 If non-empty, a Postfix SMTP client filter for the remote SMTP d335 2 a336 2 client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from dif- d341 1 a341 1 passes through to the SASL plug-in implementation that is d345 1 a345 1 The SASL plug-in type that the Postfix SMTP client should use d351 2 a352 2 An optional table to prevent repeated SASL authentication fail- ures with the same remote SMTP server hostname, username and d356 1 a356 1 The maximal age of an smtp_sasl_auth_cache_name entry before it d360 2 a361 2 When a remote SMTP server rejects a SASL authentication request with a 535 reply code, defer mail delivery instead of returning d367 1 a367 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d371 1 a371 1 Detailed information about STARTTLS configuration may be found in the d381 1 a381 1 The SASL authentication security options that the Postfix SMTP d385 1 a385 1 Time limit for Postfix SMTP client write and read operations d389 2 a390 2 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA cer- d394 1 a394 1 Directory with PEM format Certification Authority certificates d402 1 a402 1 The minimum TLS cipher grade that the Postfix SMTP client will d410 2 a411 2 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security lev- d427 1 a427 1 Log the hostname of a remote SMTP server that offers STARTTLS, d436 1 a436 1 List of SSL/TLS protocols that the Postfix SMTP client will use d443 1 a443 1 How the Postfix SMTP client verifies the server certificate d451 1 a451 1 The expiration time of Postfix SMTP client TLS session cache d455 1 a455 1 How the Postfix SMTP client verifies the server certificate d459 2 a460 2 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its d463 2 a464 2 tls_high_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "high" grade ciphers. d466 2 a467 2 tls_medium_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "medium" or higher grade ciphers. d469 2 a470 2 tls_low_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "low" or higher grade ciphers. d472 2 a473 2 tls_export_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "export" or higher grade ciphers. d476 1 a476 1 The OpenSSL cipherlist for "NULL" grade ciphers that provide d483 2 a484 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions with a verified d490 2 a491 2 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security level (smtp_tls_secu- d495 1 a495 1 The message digest algorithm used to construct remote SMTP d501 1 a501 1 List of TLS protocols that the Postfix SMTP client will exclude d505 1 a505 1 The minimum TLS cipher grade that the Postfix SMTP client will d509 1 a509 1 File with the Postfix SMTP client ECDSA certificate in PEM for- d513 1 a513 1 File with the Postfix SMTP client ECDSA private key in PEM for- d519 3 a521 3 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends mali- cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client d532 1 a532 1 Zero or more PEM-format files with trust-anchor certificates d536 1 a536 1 Lookup the associated DANE TLSA RRset even when a hostname is a544 13 Available in Postfix version 3.0 and later: smtp_tls_wrappermode (no) Request that the Postfix SMTP client connects using the legacy SMTPS protocol instead of using the STARTTLS command. Available in Postfix version 3.1 and later: smtp_tls_dane_insecure_mx_policy (dane) The TLS policy for MX hosts with "secure" TLSA records when the nexthop destination security level is dane, but the MX record was found via an "insecure" MX lookup. a684 11 SMTPUTF8 CONTROLS Preliminary SMTPUTF8 support is introduced with Postfix 3.0. smtputf8_enable (yes) Enable preliminary SMTPUTF8 support for the protocols described in RFC 6531..6533. smtputf8_autodetect_classes (sendmail, verify) Detect that a message requires SMTPUTF8 support for the speci- fied mail origin classes. d701 3 a703 3 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, header_checks and body_checks. d780 1 a780 1 The hostname to send in the SMTP HELO or EHLO command. a811 12 Available with Postfix 3.0 and later: smtp_address_verify_target (rcpt) In the context of email address verification, the SMTP protocol stage that determines whether an email address is deliverable. Available with Postfix 3.1 and later: lmtp_fallback_relay (empty) Optional list of relay hosts for LMTP destinations that can't be found or that are unreachable. a837 5 Wietse Venema Google, Inc. 111 8th Avenue New York, NY 10011, USA @ 1.1.1.9 log @The stable Postfix release is called postfix-3.0.x where 3=major release number, 0=minor release number, x=patchlevel. The stable release never changes except for patches that address bugs or emergencies. Patches change the patchlevel and the release date. New features are developed in snapshot releases. These are called postfix-3.1-yyyymmdd where yyyymmdd is the release date (yyyy=year, mm=month, dd=day). Patches are never issued for snapshot releases; instead, a new snapshot is released. The mail_release_date configuration parameter (format: yyyymmdd) specifies the release date of a stable release or snapshot release. If you upgrade from Postfix 2.10 or earlier, read RELEASE_NOTES-2.11 before proceeding. Notes for distribution maintainers ---------------------------------- * New backwards-compatibility safety net. With NEW Postfix installs, you MUST install a main.cf file with the setting "compatibility_level = 2". See conf/main.cf for an example. With UPGRADES of existing Postfix systems, you MUST NOT change the main.cf compatibility_level setting, nor add this setting if it does not exist. Several Postfix default settings have changed with Postfix 3.0. To avoid massive frustration with existing Postfix installations, Postfix 3.0 comes with a safety net that forces Postfix to keep running with backwards-compatible main.cf and master.cf default settings. This safety net depends on the main.cf compatibility_level setting (default: 0). Details are in COMPATIBILITY_README. * New Postfix build system. The Postfix build/install procedure has changed to support Postfix dynamically-linked libraries and database plugins. These must not be "shared" with non-Postfix programs, and therefore must not be installed in a public directory. To avoid massive frustration due to broken patches, PLEASE BUILD POSTFIX FIRST WITHOUT APPLYING ANY PATCHES. Follow the INSTALL instructions (see "Building with Postfix dynamically-linked libraries and database plugins"), and see how things work and what the dynamically-linked libraries, database plugin, and configuration files look like. Then, go ahead and perform your platform-specific customizations. The INSTALL section "Tips for distribution maintainers" has further suggestions. Major changes - critical ------------------------ [Incompat 20140714] After upgrading Postfix, "postfix reload" (or start/stop) is required. Several Postfix-internal protocols have been extended to support SMTPUTF8. Failure to reload or restart will result in mail staying queued, while Postfix daemons log warning messages about unexpected attributes. Major changes - default settings -------------------------------- [Incompat 20141009] The default settings have changed for relay_domains (new: empty, old: $mydestination) and mynetworks_style (new: host, old: subnet). However the backwards-compatibility safety net will prevent these changes from taking effect, giving the system administrator the option to make an old default setting permanent in main.cf or to adopt the new default setting, before turning off backwards compatibility. See COMPATIBILITY_README for details. [Incompat 20141001] A new backwards-compatibility safety net forces Postfix to run with backwards-compatible main.cf and master.cf default settings after an upgrade to a newer but incompatible Postfix version. See COMPATIBILITY_README for details. While the backwards-compatible default settings are in effect, Postfix logs what services or what email would be affected by the incompatible change. Based on this the administrator can make some backwards-compatibility settings permanent in main.cf or master.cf, before turning off backwards compatibility. See postconf.5.html#compatibility_level for details. [Incompat 20141001] The default settings have changed for append_dot_mydomain (new: no. old: yes), master.cf chroot (new: n, old: y), and smtputf8 (new: yes, old: no). Major changes - access control ------------------------------ [Feature 20141119] Support for BCC actions in header/body_checks and milter_header_checks. There is no limit on the number of BCC actions that may be specified, other than the implicit limit due to finite storage. BCC support will not be implemented in Postfix delivery agent header/body_checks. It works in the same way as always_bcc and sender/recipient_bcc_maps: there can be only one address per action, recipients are added with the NOTIFY=NONE delivery status notification option, and duplicate recipients are ignored (with the same delivery status notification options). [Incompat 20141009] The default settings have changed for relay_domains (new: empty, old: $mydestination) and mynetworks_style (new: host, old: subnet). However the backwards-compatibility safety net will prevent these changes from taking effect, giving the system administrator the option to make an old default setting permanent in main.cf or to adopt the new default setting, before turning off backwards compatibility. See COMPATIBILITY_README for details. [Feature 20140618] New INFO action in access(5) tables, for consistency with header/body_checks. [Feature 20140620] New check_xxx_a_access (for xxx in client, reverse_client, helo, sender, recipient) implements access control on all A and AAAA IP addresses for respectively the client hostname, helo parameter, sender domain or recipient domain. This complements the existing check_xxx_mx_access and check_xxx_ns_access features. Major changes - address rewriting --------------------------------- [Incompat 20141001] The default settings have changed for append_dot_mydomain (new: no. old: yes), master.cf chroot (new: n, old: y), and smtputf8 (new: yes, old: no). Major changes - address verification ------------------------------------ [Feature 20141227] The new smtp_address_verify_target parameter (default: rcpt) specifies what protocol stage decides if a recipient is valid. Specify "data" for servers that reject invalid recipients in response to the DATA command. Major changes - database support -------------------------------- [Feature 20140512] Support for Berkeley DB version 6. [Feature 20140618] The "randmap" lookup table performs random selection. This may be used to implement load balancing, for example: /etc/postfix/transport: # Deliver my own domain as usual. example.com : .example.com : /etc/postfix/main.cf: transport_maps = # Deliver my own domain as usual. hash:/etc/postfix/transport # Deliver other domains via randomly-selected relayhosts randmap:{smtp:smtp0.example.com, smtp:smtp1.example.com} A variant of this can randomly select SMTP clients with different smtp_bind_address settings. To implement different weights, specify lookup results multiple times. For example, to choose smtp:smtp1.example.com twice as often as smtp:smtp0.example.com, specify smtp:smtp1.example.com twice. A future version may support randmap:/path/to/file to load a list of results from file. [Feature 20140618] As the name suggests, the "pipemap" table implements a pipeline of lookup tables. The name of the table specifies the pipeline as a sequence of tables. For example, the following prevents SMTP mail to system accounts that have "nologin" as their login shell: /etc/postfix/main.cf: local_recipient_maps = pipemap:{unix:passwd.byname, pcre:/etc/postfix/no-nologin.pcre} alias_maps /etc/postfix/no-nologin.pcre: !/nologin/ whatever Each "pipemap:" query is given to the first table. Each table lookup result becomes the query for the next table in the pipeline, and the last table produces the final result. When any table lookup produces no result, the entire pipeline produces no result. A future version may support pipemap:/path/to/file to load a list of lookup tables from file. [Feature 20140924] Support for unionmap, with the same syntax as pipemap. This sends a query to all tables, and concatenates non-empty results, separated by comma. [Feature 20131121] The "static" lookup table now supports whitespace when invoked as "static:{ text with whitespace }", so that it can be used, for example, at the end of smtpd_mumble_restrictions as "check_mumble_access static:{reject text...}". [Feature 20141126] "inline:{key=value, { key = text with comma/space}}" avoids the need to create a database for just a few entries. Major changes - delivery status notifications --------------------------------------------- [Feature 20140321] Delivery status filter support, to replace the delivery status codes and explanatory text of successful or unsuccessful deliveries by Postfix mail delivery agents. This was originally implemented for sites that want to turn certain soft delivery errors into hard delivery errors, but it can also be used to censor out information from delivery confirmation reports. This feature is implemented as a filter that replaces the three-number enhanced status code and descriptive text in Postfix delivery agent success, bounce, or defer messages. Note: this will not override "soft_bounce=yes", and this will not change a successful delivery status into an unsuccessful status or vice versa. The first example turns specific soft TLS errors into hard errors, by overriding the first number in the enhanced status code. /etc/postfix/main.cf: smtp_delivery_status_filter = pcre:/etc/postfix/smtp_dsn_filter /etc/postfix/smtp_dsn_filter: /^4(\.\d+\.\d+ TLS is required, but host \S+ refused to start TLS: .+)/ 5$1 /^4(\.\d+\.\d+ TLS is required, but was not offered by host .+)/ 5$1 The second example removes the destination command name and file name from local(8) successful delivery reports, so that they will not be reported when a sender requests confirmation of delivery. /etc/postfix/main.cf: local_delivery_status_filter = pcre:/etc/postfix/local_dsn_filter /etc/postfix/local_dsn_filter: /^(2\S+ delivered to file).+/ $1 /^(2\S+ delivered to command).+/ $1 This feature is supported in the lmtp(8), local(8), pipe(8), smtp(8) and virtual(8) delivery agents. That is, all delivery agents that actually deliver mail. It will not be implemented in the error and retry pseudo-delivery agents. The new main.cf parameters and default values are: default_delivery_status_filter = lmtp_delivery_status_filter = $default_delivery_status_filter local_delivery_status_filter = $default_delivery_status_filter pipe_delivery_status_filter = $default_delivery_status_filter smtp_delivery_status_filter = $default_delivery_status_filter virtual_delivery_status_filter = $default_delivery_status_filter See the postconf(5) manpage for more details. [Incompat 20140618] The pipe(8) delivery agent will now log a limited amount of command output upon successful delivery, and will report that output in "SUCCESS" delivery status reports. This is another good reason to disable inbound DSN requests at the Internet perimeter. [Feature 20140907] With "confirm_delay_cleared = yes", Postfix informs the sender when delayed mail leaves the queue (this is in addition to the delay_warning_time feature that warns when mail is still queued). This feature is disabled by default, because it can result in a sudden burst of notifications when the queue drains at the end of a prolonged network outage. Major changes - dns ------------------- [Feature 20141128] Support for DNS server reply filters in the Postfix SMTP/LMTP client and SMTP server. This helps to work around mail delivery problems with sites that have incorrect DNS information. Note: this has no effect on the implicit DNS lookups that are made by nsswitch.conf or equivalent mechanisms. This feature renders each lookup result as one line of text in standard zone-file format as shown below. The class field is always "IN", the preference field exists only for MX records, the names of hosts, domains, etc. end in ".", and those names are in ASCII form (xn--mumble form for internationalized domain names). name ttl class type preference value --------------------------------------------------------- postfix.org. 86400 IN MX 10 mail.cloud9.net. Typically, one would match this text with a regexp: or pcre: table. When a match is found, the table lookup result specifies an action. By default, the table query and the action name are case-insensitive. Currently, only the IGNORE action is implemented. For safety reasons, Postfix logs a warning or defers mail delivery when a DNS reply filter removes all lookup results from a successful query. The Postfix SMTP/LMTP client uses the smtp_dns_reply_filter and lmtp_dns_reply_filter features only for Postfix SMTP client lookups of MX, A, and AAAAA records to locate a remote SMTP or LMTP server, including lookups that implement the features reject_unverified_sender and reject_unverified_recipient. The filters are not used for lookups made through nsswitch.conf and similar mechanisms. The Postfix SMTP server uses the smtpd_dns_reply_filter feature only for Postfix SMTP server lookups of MX, A, AAAAA, and TXT records to implement the features reject_unknown_helo_hostname, reject_unknown_sender_domain, reject_unknown_recipient_domain, reject_rbl_*, and reject_rhsbl_*. The filter is not used for lookups made through nsswitch.conf and similar mechanisms, such as lookups of the remote SMTP client name. [Feature 20141126] Nullmx support (MX records with a null hostname). This change affects error messages only. The Postfix SMTP client already bounced mail for such domains, and the Postfix SMTP server already rejected such domains with reject_unknown_sender/recipient_domain. This feature introduces a new SMTP server configuration parameter nullmx_reject_code (default: 556). Major changes - dynamic linking ------------------------------- [Feature 20140530] Support to build Postfix with Postfix dynamically-linked libraries, and with dynamically-loadable database clients. These MUST NOT be used by non-Postfix programs. Postfix dynamically-linked libraries introduce minor runtime overhead and result in smaller Postfix executable files. Dynamically-loadable database clients are useful when you distribute or install pre-compiled packages. Postfix 3.0 supports dynamic loading for CDB, LDAP, LMDB, MYSQL, PCRE, PGSQL, SDBM, and SQLITE database clients. This implementation is based on Debian code by LaMont Jones, initially ported by Viktor Dukhovni. Currently, support exists for recent versions of Linux, FreeBSD, MacOS X, and for the ancient Solaris 9. To support Postfix dynamically-linked libraries and dynamically-loadable database clients, the Postfix build procedure had to be changed (specifically, the files makedefs and Makefile.in, and the files postfix-install and post-install that install or update Postfix). [Incompat 20140530] The Postfix 3.0 build procedure expects that you specify database library dependencies with variables named AUXLIBS_CDB, AUXLIBS_LDAP, etc. With Postfix 3.0 and later, the old AUXLIBS variable still supports building a statically-loaded CDB etc. database client, but only the new AUXLIBS_CDB etc. variables support building a dynamically-loaded or statically-loaded CDB etc. database client. See CDB_README, LDAP_README, etc. for details. Failure to follow this advice will defeat the purpose of dynamic database client loading. Every Postfix executable file will have database library dependencies. And that was exactly what dynamic database client loading was meant to avoid. Major changes - future proofing ------------------------------- [Cleanup 20141224] The changes described here have no visible effect on Postfix behavior, but they make Postfix code easier to maintain, and therefore make new functionality easier to add. * Compile-time argument typechecks of non-printf/scanf-like variadic function argument lists. * Deprecating the use of "char *" for non-text purposes such as memory allocation and pointers to application context for call-back functions. This dates from long-past days before void * became universally available. * Replace integer types for counters and sizes with size_t or ssize_t equivalents. This eliminates some wasteful 64<->32bit conversions on 64-bit systems. Major changes - installation pathnames -------------------------------------- [Incompat 20140625] For compliance with file system policies, some non-executable files have been moved from $daemon_directory to the directory specified with the new meta_directory configuration parameter which has the same default value as the config_directory parameter. This change affects non-executable files that are shared between multiple Postfix instances such as postfix-files, dynamicmaps.cf, and multi-instance template files. For backwards compatibility with Postfix 2.6 .. 2.11, specify "meta_directory = $daemon_directory" in main.cf before installing or upgrading Postfix, or specify "meta_directory = /path/name" on the "make makefiles", "make install" or "make upgrade" command line. Major changes - milter ---------------------- [Feature 20140928] Support for per-Milter settings that override main.cf parameters. For details see the section "Advanced policy client configuration" in the SMTPD_POLICY_README document. Here is an example that uses both old and new syntax: smtpd_milters = { inet:127.0.0.1:port1, default_action=accept, ... }, inet:127.0.0.1:port2, ... The supported attribute names are: command_timeout, connect_timeout, content_timeout, default_action, and protocol. These have the same names as the corresponding main.cf parameters, without the "milter_" prefix. The per-milter settings are specified as attribute=value pairs separated by comma or space; specify { name = value } to allow spaces around the "=" or within an attribute value. [Feature 20141018] DMARC compatibility: when a Milter inserts a header ABOVE Postfix's own Received: header, Postfix no longer exposes its own Received: header to Milters (violating protocol) and Postfix no longer hides the Milter-inserted header from Milters (wtf). Major changes - parameter syntax -------------------------------- [Feature 20140921] In preparation for configurable mail headers and logging, new main.cf support for if-then-else expressions: ${name?{text1}:{text2}} and for logical expressions: ${{text1}=={text2}?{text3}:{text4}} ${{text1}!={text2}?{text3}:{text4}} Whitespace before and after {text} is ignored. This can help to make complex expressions more readable. See the postconf(5) manpage for further details. [Feature 20140928] Support for whitespace in daemon command-line arguments. For details, see the "Command name + arguments" section in the master(5) manpage. Example: smtpd -o { parameter = value containing whitespace } ... The { ... } form is also available for non-option command-line arguments in master.cf, for example: pipe ... argv=command { argument containing whitespace } ... In both cases, whitespace immediately after "{" and before "}" is ignored. [Feature 20141005] Postfix import_environment and export_environment now allow "{ name=value }" to protect whitespace in attribute values. [Feature 20141006] The new message_drop_header parameter replaces a hard-coded table that specifies what message headers the cleanup daemon will remove. The list of supported header names covers RFC 5321, 5322, MIME RFCs, and some historical names. Major changes - pipe daemon --------------------------- [Incompat 20140618] The pipe(8) delivery agent will now log a limited amount of command output upon successful delivery, and will report that output in "SUCCESS" delivery status reports. This is another good reason to disable inbound DSN requests at the Internet perimeter. Major changes - policy client ----------------------------- [Feature 20140703] This release introduces three new configuration parameters that control error recovery for failed SMTPD policy requests. * smtpd_policy_service_default_action (default: 451 4.3.5 Server configuration problem): The default action when an SMTPD policy service request fails. * smtpd_policy_service_try_limit (default: 2): The maximal number of attempts to send an SMTPD policy service request before giving up. This must be a number greater than zero. * smtpd_policy_service_retry_delay (default: 1s): The delay between attempts to resend a failed SMTPD policy service request. This must be a number greater than zero. See postconf(5) for details and limitations. [Feature 20140928] Support for per-policy service settings that override main.cf parameters. For details see the section "Different settings for different Milter applications" in the MILTER_README document. Here is an example that uses both old and new syntax: smtpd_recipient_restrictions = ... check_policy_service { inet:127.0.0.1:port3, default_action=DUNNO } check_policy_service inet:127.0.0.1:port4 ... The per-policy service settings are specified as attribute=value pairs separated by comma or space; specify { name = value } to allow spaces around the "=" or within an attribute value. The supported attribute names are: default_action, max_idle, max_ttl, request_limit, retry_delay, timeout, try_limit. These have the same names as the corresponding main.cf parameters, without the "smtpd_policy_service_" prefix. [Feature 20140505] A client port attribute was added to the policy delegation protocol. [Feature 20140630] New smtpd_policy_service_request_limit feature to limit the number of requests per Postfix SMTP server policy connection. This is a workaround to avoid error-recovery delays with policy servers that cannot maintain a persistent connection. Major changes - position-independent executables ------------------------------------------------ [Feature 20150205] Preliminary support for building position-independent executables (PIE), tested on Fedora Core 20, Ubuntu 14.04, FreeBSD 9 and 10, and NetBSD 6. Specify: $ make makefiles pie=yes ...other arguments... On some systems, PIE is used by the ASLR exploit mitigation technique (ASLR = Address-Space Layout Randomization). Whether specifying "pie=yes" has any effect at all depends on the compiler. Reportedly, some compilers always produce PIE executables. Major changes - postscreen -------------------------- [Feature 20140501] Configurable time limit (postscreen_dnsbl_timeout) for DNSBL or DNSWL lookups. This is separate from the timeouts in the dnsblog(8) daemon which are controlled by system resolver(3) routines. Major changes - session fingerprint ----------------------------------- [Feature 20140801] The Postfix SMTP server now logs at the end of a session how many times an SMTP command was successfully invoked, followed by the total number of invocations if some invocations were unsuccessful. This logging will enough to diagnose many problems without using verbose logging or network sniffer. Normal session, no TLS: disconnect from name[addr] ehlo=1 mail=1 rcpt=1 data=1 quit=1 Normal session. with TLS: disconnect from name[addr] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 All recipients rejected, no ESMTP command pipelining: disconnect from name[addr] ehlo=1 mail=1 rcpt=0/1 quit=1 All recipients rejected, with ESMTP command pipelining: disconnect from name[addr] ehlo=1 mail=1 rcpt=0/1 data=0/1 rset=1 quit=1 Password guessing bot, hangs up without QUIT: disconnect from name[addr] ehlo=1 auth=0/1 Mis-configured client trying to use TLS wrappermode on port 587: disconnect from name[addr] unknown=0/1 Logfile analyzers can trigger on the presence of "/". It indicates that Postfix rejected at least one command. [Feature 20150118] As a late addition, the SMTP server now also logs the total number of commands (as "commands=x/y") even when the client did not send any commands. This helps logfile analyzers to recognize sessions without commands. Major changes - smtp client --------------------------- [Feature 20141227] The new smtp_address_verify_target parameter (default: rcpt) determines what protocol stage decides if a recipient is valid. Specify "data" for servers that reject recipients after the DATA command. Major changes - smtputf8 ------------------------ [Incompat 20141001] The default settings have changed for append_dot_mydomain (new: no, old: yes), master.cf chroot (new: n, old: y), and smtputf8 (new: yes, old: no). [Incompat 20140714] After upgrading Postfix, "postfix reload" (or start/stop) is required. Several Postfix-internal protocols have been extended to support SMTPUTF8. Failure to reload or restart will result in mail staying queued, while Postfix daemons log warning messages about unexpected attributes. [Feature 20140715] Support for Email Address Internationalization (EAI) as defined in RFC 6531..6533. This supports UTF-8 in SMTP/LMTP sender addresses, recipient addresses, and message header values. The implementation is based on initial work by Arnt Gulbrandsen that was funded by CNNIC. See SMTPUTF8_README for a description of Postfix SMTPUTF8 support. [Feature 20150112] UTF-8 Casefolding support for Postfix lookup tables and matchlists (mydestination, relay_domains, etc.). This is enabled only with "smtpuf8 = yes". [Feature 20150112] With smtputf8_enable=yes, SMTP commands with UTF-8 syntax errors are rejected, table lookup results with invalid UTF-8 syntax are handled as configuration errors, and UTF-8 syntax errors in policy server replies result in execution of the policy server's default action. Major changes - tls support --------------------------- (see "Major changes - delivery status notifications" above for turning 4XX soft errors into 5XX bounces when a remote SMTP server does not offer STARTTLS support). [Feature 20140209] the Postfix SMTP client now also falls back to plaintext when TLS fails AFTER the TLS protocol handshake. [Feature 20140218] The Postfix SMTP client now requires that a queue file is older than $minimal_backoff_time, before falling back from failed TLS to plaintext (both during or after the TLS handshake). [Feature 20141021] Per IETF TLS WG consensus, the tls_session_ticket_cipher default setting was changed from aes-128-cbc to aes-256-cbc. [Feature 20150116] TLS wrappermode support in the Postfix smtp(8) client (new smtp_tls_wrappermode parameter) and in posttls-finger(1) (new -w option). There still is life in that deprecated protocol, and people should not have to jump hoops with stunnel. @ text @a109 3 RFC 6531 (Internationalized SMTP) RFC 6533 (Internationalized Delivery Status Notifications) RFC 7672 (SMTP security via opportunistic DANE TLS) d222 3 a224 4 When the remote SMTP servername is a DNS CNAME, replace the servername with the result from CNAME expansion for the purpose of logging, SASL password lookup, TLS policy decisions, or TLS certificate verification. d229 2 a230 2 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, d235 1 a235 1 A case insensitive list of LHLO keywords (pipelining, starttls, d242 3 a244 3 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- d250 1 a250 1 Restricted header_checks(5) tables for the Postfix SMTP client. d253 1 a253 1 Restricted mime_header_checks(5) tables for the Postfix SMTP d257 1 a257 1 Restricted nested_header_checks(5) tables for the Postfix SMTP d266 1 a266 1 An optional workaround for routers that break TCP window scal- d277 4 a280 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d284 1 a284 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM a291 10 Available in Postfix version 3.0 and later: smtp_delivery_status_filter ($default_delivery_status_filter) Optional filter for the smtp(8) delivery agent to change the delivery status code or explanatory text of successful or unsuc- cessful deliveries. smtp_dns_reply_filter (empty) Optional filter for Postfix SMTP client DNS lookup results. d308 1 a308 1 Send the non-standard XFORWARD command when the Postfix SMTP d316 3 a318 3 Optional Postfix SMTP client lookup tables with one user- name:password entry per sender, remote hostname or next-hop domain. d322 1 a322 1 list of available features depends on the SASL client implemen- d328 1 a328 1 If non-empty, a Postfix SMTP client filter for the remote SMTP d335 2 a336 2 client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from dif- d341 1 a341 1 passes through to the SASL plug-in implementation that is d345 1 a345 1 The SASL plug-in type that the Postfix SMTP client should use d351 2 a352 2 An optional table to prevent repeated SASL authentication fail- ures with the same remote SMTP server hostname, username and d356 1 a356 1 The maximal age of an smtp_sasl_auth_cache_name entry before it d360 2 a361 2 When a remote SMTP server rejects a SASL authentication request with a 535 reply code, defer mail delivery instead of returning d367 1 a367 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d371 1 a371 1 Detailed information about STARTTLS configuration may be found in the d381 1 a381 1 The SASL authentication security options that the Postfix SMTP d385 1 a385 1 Time limit for Postfix SMTP client write and read operations d389 2 a390 2 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certificates or intermediate CA cer- d394 1 a394 1 Directory with PEM format Certification Authority certificates d402 1 a402 1 The minimum TLS cipher grade that the Postfix SMTP client will d410 2 a411 2 Additional list of ciphers or cipher types to exclude from the Postfix SMTP client cipher list at mandatory TLS security lev- d427 1 a427 1 Log the hostname of a remote SMTP server that offers STARTTLS, d436 1 a436 1 List of SSL/TLS protocols that the Postfix SMTP client will use d443 1 a443 1 How the Postfix SMTP client verifies the server certificate d451 1 a451 1 The expiration time of Postfix SMTP client TLS session cache d455 1 a455 1 How the Postfix SMTP client verifies the server certificate d459 2 a460 2 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its d463 2 a464 2 tls_high_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "high" grade ciphers. d466 2 a467 2 tls_medium_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "medium" or higher grade ciphers. d469 2 a470 2 tls_low_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "low" or higher grade ciphers. d472 2 a473 2 tls_export_cipherlist (see 'postconf -d' output) The OpenSSL cipherlist for "export" or higher grade ciphers. d476 1 a476 1 The OpenSSL cipherlist for "NULL" grade ciphers that provide d483 2 a484 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP sessions with a verified d490 2 a491 2 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security level (smtp_tls_secu- d495 1 a495 1 The message digest algorithm used to construct remote SMTP d501 1 a501 1 List of TLS protocols that the Postfix SMTP client will exclude d505 1 a505 1 The minimum TLS cipher grade that the Postfix SMTP client will d509 1 a509 1 File with the Postfix SMTP client ECDSA certificate in PEM for- d513 1 a513 1 File with the Postfix SMTP client ECDSA private key in PEM for- d519 3 a521 3 Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends mali- cious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client d532 1 a532 1 Zero or more PEM-format files with trust-anchor certificates d536 1 a536 1 Lookup the associated DANE TLSA RRset even when a hostname is a544 13 Available in Postfix version 3.0 and later: smtp_tls_wrappermode (no) Request that the Postfix SMTP client connects using the legacy SMTPS protocol instead of using the STARTTLS command. Available in Postfix version 3.1 and later: smtp_tls_dane_insecure_mx_policy (dane) The TLS policy for MX hosts with "secure" TLSA records when the nexthop destination security level is dane, but the MX record was found via an "insecure" MX lookup. a684 11 SMTPUTF8 CONTROLS Preliminary SMTPUTF8 support is introduced with Postfix 3.0. smtputf8_enable (yes) Enable preliminary SMTPUTF8 support for the protocols described in RFC 6531..6533. smtputf8_autodetect_classes (sendmail, verify) Detect that a message requires SMTPUTF8 support for the speci- fied mail origin classes. d701 3 a703 3 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, header_checks and body_checks. d780 1 a780 1 The hostname to send in the SMTP HELO or EHLO command. a811 12 Available with Postfix 3.0 and later: smtp_address_verify_target (rcpt) In the context of email address verification, the SMTP protocol stage that determines whether an email address is deliverable. Available with Postfix 3.1 and later: lmtp_fallback_relay (empty) Optional list of relay hosts for LMTP destinations that can't be found or that are unreachable. a837 5 Wietse Venema Google, Inc. 111 8th Avenue New York, NY 10011, USA @ 1.1.1.9.14.1 log @Pull up the following, requeste by kim in ticket #1779: external/ibm-public/postfix/dist/README_FILES/BDAT_README up to 1.1.1.2 external/ibm-public/postfix/dist/README_FILES/MAILLOG_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/POSTSCREEN_3_5_README up to 1.1.1.1 external/ibm-public/postfix/dist/html/BDAT_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/MAILLOG_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/makedefs.1.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/postlogd.8.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/POSTSCREEN_3_5_README.html up to 1.1.1.2 external/ibm-public/postfix/dist/html/postfix-doc.css up to 1.1.1.1 external/ibm-public/postfix/dist/man/man1/makedefs.1 up to 1.3 external/ibm-public/postfix/dist/man/man8/postlogd.8 up to 1.3 external/ibm-public/postfix/dist/mantools/missing-proxy-read-maps up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/spelldiff up to 1.1.1.1 external/ibm-public/postfix/dist/mantools/check-double-cc up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-double-install-proto-text up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-double-proto-html up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/comment.c up to 1.2 external/ibm-public/postfix/dist/mantools/check-postfix-files up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-spell-cc up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-spell-install-proto-text up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-spell-proto-html up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/deroff up to 1.1.1.1 external/ibm-public/postfix/dist/mantools/find-double up to 1.1.1.1 external/ibm-public/postfix/dist/mantools/check-double-history up to 1.1.1.1 external/ibm-public/postfix/dist/mantools/check-spell-history up to 1.1.1.1 external/ibm-public/postfix/dist/mantools/check-table-proto up to 1.1.1.1 external/ibm-public/postfix/dist/proto/BDAT_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/MAILLOG_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/POSTSCREEN_3_5_README.html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/stop.double-cc up to 1.1.1.2 external/ibm-public/postfix/dist/proto/stop.double-install-proto-text up to 1.1.1.1 external/ibm-public/postfix/dist/proto/stop.double-proto-html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/stop.spell-cc up to 1.1.1.2 external/ibm-public/postfix/dist/proto/stop.spell-proto-html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/stop.double-history up to 1.1.1.1 external/ibm-public/postfix/dist/proto/stop.spell-history up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/bounce_notify_util_tester.c up to 1.2 external/ibm-public/postfix/dist/src/bounce/logfile-no-msgid-no-eoh-event up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/logfile-no-msgid-with-eoh-event up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/logfile-with-msgid-no-eoh-event up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/logfile-with-msgid-with-eoh-event up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/logfile-with-msgid-with-filter up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/logfile-with-msgid-with-long-line up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/msgfile-no-msgid-no-eoh-event up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/msgfile-no-msgid-with-eoh-event up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/msgfile-with-msgid-no-eoh-event up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/msgfile-with-msgid-with-eoh-event up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/obs_template_test.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/msgfile-with-msgid-with-filter up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/msgfile-with-msgid-with-long-line up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/no-msgid-no-eoh-event-no-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/no-msgid-no-eoh-event-with-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/no-msgid-with-eoh-event-no-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/no-msgid-with-eoh-event-with-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/with-msgid-no-eoh-event-no-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/with-msgid-no-eoh-event-with-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/with-msgid-with-eoh-event-no-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/with-msgid-with-eoh-event-with-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/with-msgid-with-filter-no-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/with-msgid-with-filter-with-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/with-msgid-with-long-line-no-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/bounce/with-msgid-with-long-line-with-thread.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13e up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13f up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13g up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13h up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in13i up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13e up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13f up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13g up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13h up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13i up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/test-queue-file13e up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/test-queue-file13f up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/test-queue-file13g up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/test-queue-file13h up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/test-queue-file13i up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17a up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17b up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17c up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17d up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17e up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17f up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.in17g up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17a1 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17a2 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17b1 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17b2 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17c1 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17c2 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17d1 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17d2 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17e1 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17e2 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17f1 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17f2 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17g1 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref17g2 up to 1.1.1.1 external/ibm-public/postfix/dist/src/cleanup/test-queue-file17 up to 1.1.1.1 external/ibm-public/postfix/dist/src/dns/dns_str_resflags.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_sec.c up to 1.2 external/ibm-public/postfix/dist/src/global/header_body_checks_strip.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/info_log_addr_form.c up to 1.2 external/ibm-public/postfix/dist/src/global/info_log_addr_form.h up to 1.2 external/ibm-public/postfix/dist/src/global/mail_addr_crunch.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/mail_addr_crunch.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/mail_addr_find.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/map_search.c up to 1.4 external/ibm-public/postfix/dist/src/global/map_search.h up to 1.2 external/ibm-public/postfix/dist/src/global/mail_addr_find.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/mail_addr_form.c up to 1.2 external/ibm-public/postfix/dist/src/global/mail_addr_form.h up to 1.2 external/ibm-public/postfix/dist/src/global/mail_addr_map.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/maillog_client.c up to 1.3 external/ibm-public/postfix/dist/src/global/maillog_client.h up to 1.2 external/ibm-public/postfix/dist/src/global/map_search.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/global/normalize_mailhost_addr.c up to 1.3 external/ibm-public/postfix/dist/src/global/normalize_mailhost_addr.h up to 1.2 external/ibm-public/postfix/dist/src/global/off_cvt.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/off_cvt.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/quote_822_local.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/global/quote_822_local.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/global/quote_flags.c up to 1.2 external/ibm-public/postfix/dist/src/global/reject_deliver_request.c up to 1.2 external/ibm-public/postfix/dist/src/global/compat_level.c up to 1.3 external/ibm-public/postfix/dist/src/global/compat_level.h up to 1.3 external/ibm-public/postfix/dist/src/global/test_main.c up to 1.2 external/ibm-public/postfix/dist/src/global/compat_level_convert.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/compat_level_convert.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/compat_level_expand.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/compat_level_expand.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/config_known_tcp_ports.c up to 1.2 external/ibm-public/postfix/dist/src/global/config_known_tcp_ports.h up to 1.2 external/ibm-public/postfix/dist/src/global/config_known_tcp_ports.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/delivered_hdr.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/hfrom_format.c up to 1.2 external/ibm-public/postfix/dist/src/global/hfrom_format.h up to 1.2 external/ibm-public/postfix/dist/src/global/hfrom_format.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/login_sender_match.c up to 1.2 external/ibm-public/postfix/dist/src/global/login_sender_match.h up to 1.2 external/ibm-public/postfix/dist/src/global/login_sender_match.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/sasl_mech_filter.c up to 1.2 external/ibm-public/postfix/dist/src/global/sasl_mech_filter.h up to 1.2 external/ibm-public/postfix/dist/src/global/test_main.h up to 1.2 external/ibm-public/postfix/dist/src/master/dgram_server.c up to 1.3 external/ibm-public/postfix/dist/src/postconf/extract_cfg.sh up to 1.1.1.1 external/ibm-public/postfix/dist/src/postconf/test64.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postconf/test65.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postconf/test66.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postconf/test67.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test68.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postconf/test69.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postconf/test70.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postconf/test71.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postmap/file_test.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/postmap/file_test.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postmap/quote_test.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/postmap/quote_test.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/postmap/lmdb_abb up to 1.1.1.1 external/ibm-public/postfix/dist/src/postmap/lmdb_abb.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/smtp/smtp_misc.c up to 1.2 external/ibm-public/postfix/dist/src/smtp/smtp_map11.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/smtpd/smtpd_addr_valid.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_addr_valid.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/tls/bad-back-to-back-keys.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/bad-back-to-back-keys.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/bad-ec-cert-before-key.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/bad-ec-cert-before-key.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/bad-key-cert-mismatch.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/bad-key-cert-mismatch.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/bad-rsa-key-last.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/bad-rsa-key-last.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/ecca-cert.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/ecca-pkey.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/ecee-cert.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/ecee-pkey.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/ecroot-cert.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/ecroot-pkey.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/good-mixed-keyfirst.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/good-mixed-keyfirst.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/good-mixed-keylast.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/good-mixed-keylast.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/good-mixed-keymiddle.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/good-mixed-keymiddle.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/goodchains.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/goodchains.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/mkcert.sh up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/rsaca-cert.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/rsaca-pkey.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/rsaee-cert.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/rsaee-pkey.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/rsaroot-cert.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/rsaroot-pkey.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_misc.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_print.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_scan.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_proxy_context_print.c up to 1.3 external/ibm-public/postfix/dist/src/tls/tls_proxy_context_scan.c up to 1.3 external/ibm-public/postfix/dist/src/tls/tls_proxy_server_print.c up to 1.3 external/ibm-public/postfix/dist/src/tls/tls_proxy_server_scan.c up to 1.3 external/ibm-public/postfix/dist/src/tls/warn-mixed-multi-key.pem up to 1.1.1.1 external/ibm-public/postfix/dist/src/tls/warn-mixed-multi-key.pem.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/trivial-rewrite/transport.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/trivial-rewrite/transport.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/mkmap_db.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap.h up to 1.2 external/ibm-public/postfix/dist/src/util/argv_attr.h up to 1.3 external/ibm-public/postfix/dist/src/util/argv_attr_print.c up to 1.3 external/ibm-public/postfix/dist/src/util/argv_attr_scan.c up to 1.3 external/ibm-public/postfix/dist/src/util/byte_mask.c up to 1.2 external/ibm-public/postfix/dist/src/util/byte_mask.h up to 1.2 external/ibm-public/postfix/dist/src/util/byte_mask.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/byte_mask.ref0 up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/byte_mask.ref1 up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/byte_mask.ref2 up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_file.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_cidr_file.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/logwriter.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_cidr_file.map up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_cidr_file.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_inline_file.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_pcre_file.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_pcre_file.map up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_pcre_file.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_pipe_test.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_pipe_test.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_random.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_random_file.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_regexp_file.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_regexp_file.map up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_regexp_file.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_static_file.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_thash.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_thash.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_union_test.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_union_test.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/logwriter.h up to 1.2 external/ibm-public/postfix/dist/src/util/miss_endif_cidr.map up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/miss_endif_cidr.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/miss_endif_pcre.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/miss_endif_re.map up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/miss_endif_regexp.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/msg_logger.c up to 1.3 external/ibm-public/postfix/dist/src/util/msg_logger.h up to 1.2 external/ibm-public/postfix/dist/src/util/split_qnameval.c up to 1.2 external/ibm-public/postfix/dist/src/util/unix_dgram_connect.c up to 1.3 external/ibm-public/postfix/dist/src/util/unix_dgram_listen.c up to 1.3 external/ibm-public/postfix/dist/src/util/vbuf_print_test.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/vbuf_print_test.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/vstream_test.in up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/vstream_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/vstring_test.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/sane_strtol.c up to 1.2 external/ibm-public/postfix/dist/src/util/argv_split_at.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_stream.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_inline_cidr.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_inline_pcre.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_inline_regexp.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/dict_stream.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/find_inet.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/hash_fnv.c up to 1.3 external/ibm-public/postfix/dist/src/util/hash_fnv.h up to 1.3 external/ibm-public/postfix/dist/src/util/known_tcp_ports.c up to 1.2 external/ibm-public/postfix/dist/src/util/known_tcp_ports.h up to 1.2 external/ibm-public/postfix/dist/src/util/known_tcp_ports.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/ldseed.c up to 1.2 external/ibm-public/postfix/dist/src/util/ldseed.h up to 1.2 external/ibm-public/postfix/dist/src/util/mystrtok.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/sane_strtol.h up to 1.2 external/ibm-public/postfix/dist/src/util/inet_addr_sizes.c up to 1.2 external/ibm-public/postfix/dist/src/util/inet_addr_sizes.h up to 1.2 external/ibm-public/postfix/dist/src/util/inet_prefix_top.c up to 1.2 external/ibm-public/postfix/dist/src/util/inet_prefix_top.h up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_cdb.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_dbm.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_fail.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_lmdb.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_open.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_sdbm.c up to 1.2 external/ibm-public/postfix/dist/src/postlogd/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/postlogd/postlogd.c up to 1.3 external/ibm-public/postfix/dist/RELEASE_NOTES-3.1 up to 1.1.1.1 external/ibm-public/postfix/dist/RELEASE_NOTES-3.2 up to 1.1.1.1 external/ibm-public/postfix/dist/RELEASE_NOTES-3.3 up to 1.1.1.1 external/ibm-public/postfix/dist/RELEASE_NOTES-3.4 up to 1.1.1.1 external/ibm-public/postfix/dist/RELEASE_NOTES-3.5 up to 1.1.1.1 external/ibm-public/postfix/dist/RELEASE_NOTES-3.6 up to 1.1.1.1 external/ibm-public/postfix/dist/WISHLIST up to 1.1.1.2 external/ibm-public/postfix/dist/RELEASE_NOTES-3.7 up to 1.1.1.1 external/ibm-public/postfix/dist/README_FILES/CYRUS_README delete external/ibm-public/postfix/dist/src/global/mkmap.h delete external/ibm-public/postfix/dist/src/global/mkmap_cdb.c delete external/ibm-public/postfix/dist/src/global/mkmap_db.c delete external/ibm-public/postfix/dist/src/global/mkmap_dbm.c delete external/ibm-public/postfix/dist/src/global/mkmap_fail.c delete external/ibm-public/postfix/dist/src/global/mkmap_lmdb.c delete external/ibm-public/postfix/dist/src/global/mkmap_open.c delete external/ibm-public/postfix/dist/src/global/mkmap_sdbm.c delete external/ibm-public/postfix/dist/src/smtp/map11_map delete external/ibm-public/postfix/dist/src/tls/tls_proxy_print.c delete external/ibm-public/postfix/dist/src/tls/tls_proxy_scan.c delete external/ibm-public/postfix/dist/src/util/percentm.c delete external/ibm-public/postfix/dist/src/util/percentm.h delete external/ibm-public/postfix/Makefile.inc up to 1.31 (+patch) external/ibm-public/postfix/dist/AAAREADME up to 1.1.1.4 external/ibm-public/postfix/dist/HISTORY up to 1.1.1.29 external/ibm-public/postfix/dist/INSTALL up to 1.1.1.9 external/ibm-public/postfix/dist/LICENSE up to 1.1.1.2 external/ibm-public/postfix/dist/Makefile up to 1.1.1.3 external/ibm-public/postfix/dist/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/Makefile.init up to 1.1.1.3 external/ibm-public/postfix/dist/RELEASE_NOTES up to 1.1.1.17 external/ibm-public/postfix/dist/TLS_ACKNOWLEDGEMENTS up to 1.1.1.2 external/ibm-public/postfix/dist/TLS_CHANGES up to 1.1.1.2 external/ibm-public/postfix/dist/TLS_LICENSE up to 1.1.1.2 external/ibm-public/postfix/dist/US_PATENT_6321267 up to 1.1.1.2 external/ibm-public/postfix/dist/makedefs up to 1.16 external/ibm-public/postfix/dist/postfix-env.sh up to 1.1.1.2 external/ibm-public/postfix/dist/postfix-install up to 1.8 external/ibm-public/postfix/dist/README_FILES/AAAREADME up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/ADDRESS_CLASS_README up to 1.1.1.2 external/ibm-public/postfix/dist/README_FILES/ADDRESS_REWRITING_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/ADDRESS_VERIFICATION_README up to 1.10 external/ibm-public/postfix/dist/README_FILES/BACKSCATTER_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/BASIC_CONFIGURATION_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/BUILTIN_FILTER_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/COMPATIBILITY_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/CONNECTION_CACHE_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/DATABASE_README up to 1.1.1.9 external/ibm-public/postfix/dist/README_FILES/DB_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/DEBUG_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/FILTER_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/FORWARD_SECRECY_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/INSTALL up to 1.10 external/ibm-public/postfix/dist/README_FILES/IPV6_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/LDAP_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/LINUX_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/LMDB_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/MILTER_README up to 1.1.1.9 external/ibm-public/postfix/dist/README_FILES/MULTI_INSTANCE_README up to 1.1.1.7 external/ibm-public/postfix/dist/README_FILES/MYSQL_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/OVERVIEW up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/PCRE_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/PGSQL_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/POSTSCREEN_README up to 1.1.1.7 external/ibm-public/postfix/dist/README_FILES/QSHAPE_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/RELEASE_NOTES up to 1.1.1.17 external/ibm-public/postfix/dist/README_FILES/SASL_README up to 1.1.1.11 external/ibm-public/postfix/dist/README_FILES/SCHEDULER_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/SMTPD_ACCESS_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/SMTPD_POLICY_README up to 1.1.1.7 external/ibm-public/postfix/dist/README_FILES/SMTPD_PROXY_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/SMTPUTF8_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/SOHO_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/SQLITE_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/STANDARD_CONFIGURATION_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/STRESS_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/TLS_LEGACY_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/TLS_README up to 1.14 external/ibm-public/postfix/dist/README_FILES/TUNING_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/VIRTUAL_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/XCLIENT_README up to 1.1.1.4 external/ibm-public/postfix/dist/conf/LICENSE up to 1.1.1.2 external/ibm-public/postfix/dist/conf/TLS_LICENSE up to 1.1.1.2 external/ibm-public/postfix/dist/conf/access up to 1.1.1.8 external/ibm-public/postfix/dist/conf/aliases up to 1.1.1.5 external/ibm-public/postfix/dist/conf/canonical up to 1.1.1.5 external/ibm-public/postfix/dist/conf/generic up to 1.1.1.4 external/ibm-public/postfix/dist/conf/header_checks up to 1.1.1.6 external/ibm-public/postfix/dist/conf/main.cf up to 1.10 external/ibm-public/postfix/dist/conf/master.cf up to 1.11 external/ibm-public/postfix/dist/conf/post-install up to 1.4 external/ibm-public/postfix/dist/conf/postfix-files up to 1.9 external/ibm-public/postfix/dist/conf/postfix-script up to 1.4 external/ibm-public/postfix/dist/conf/postfix-tls-script up to 1.5 external/ibm-public/postfix/dist/conf/postmulti-script up to 1.3 external/ibm-public/postfix/dist/conf/relocated up to 1.1.1.3 external/ibm-public/postfix/dist/conf/transport up to 1.1.1.5 external/ibm-public/postfix/dist/conf/virtual up to 1.1.1.6 external/ibm-public/postfix/dist/html/ADDRESS_CLASS_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/ADDRESS_REWRITING_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/ADDRESS_VERIFICATION_README.html up to 1.11 external/ibm-public/postfix/dist/html/BACKSCATTER_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/BASIC_CONFIGURATION_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/BUILTIN_FILTER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/CDB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/COMPATIBILITY_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/CONNECTION_CACHE_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/CONTENT_INSPECTION_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/DATABASE_README.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/DB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/DEBUG_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/DSN_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/ETRN_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/FILTER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/FORWARD_SECRECY_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/INSTALL.html up to 1.10 external/ibm-public/postfix/dist/html/IPV6_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/LDAP_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/LINUX_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/LMDB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/LOCAL_RECIPIENT_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/MAILDROP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/MEMCACHE_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/MILTER_README.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/MULTI_INSTANCE_README.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/MYSQL_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/html/NFS_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/OVERVIEW.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/PACKAGE_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/PCRE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/PGSQL_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/POSTSCREEN_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/QSHAPE_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/RESTRICTION_CLASS_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/SASL_README.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/SCHEDULER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/SMTPD_ACCESS_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/SMTPD_POLICY_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/SMTPD_PROXY_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/SMTPUTF8_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/SOHO_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/SQLITE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/STANDARD_CONFIGURATION_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/STRESS_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/TLS_LEGACY_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/TLS_README.html up to 1.15 external/ibm-public/postfix/dist/html/TUNING_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/UUCP_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/VERP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/VIRTUAL_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/XCLIENT_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/XFORWARD_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/access.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/aliases.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/anvil.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/bounce.5.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/bounce.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/canonical.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/cidr_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/cleanup.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/defer.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/discard.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/dnsblog.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/error.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/flush.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/generic.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/header_checks.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/index.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/ldap_table.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/lmdb_table.5.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/lmtp.8.html up to 1.1.1.12 external/ibm-public/postfix/dist/html/local.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/mailq.1.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/master.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/master.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/memcache_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/mysql_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/newaliases.1.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/nisplus_table.5.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/oqmgr.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/pcre_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/pgsql_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/pickup.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/pipe.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postalias.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postcat.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postconf.1.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/postconf.5.html up to 1.19 external/ibm-public/postfix/dist/html/postdrop.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postfix-manuals.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/postfix-tls.1.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/postfix-wrapper.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/postfix.1.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/postkick.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postlock.1.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/postlog.1.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/postmap.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postmulti.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postqueue.1.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/postscreen.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/postsuper.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/posttls-finger.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/proxymap.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/qmgr.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/qmqp-sink.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/qmqp-source.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/qmqpd.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/qshape.1.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/regexp_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/relocated.5.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/scache.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/sendmail.1.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/showq.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/smtp-sink.1.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/smtp-source.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/smtp.8.html up to 1.1.1.12 external/ibm-public/postfix/dist/html/smtpd.8.html up to 1.1.1.13 external/ibm-public/postfix/dist/html/socketmap_table.5.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/spawn.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/sqlite_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/tcp_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/tlsmgr.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/tlsproxy.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/trace.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/transport.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/trivial-rewrite.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/verify.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/virtual.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/virtual.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/man/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/man/man1/postalias.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/postcat.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/postconf.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/postdrop.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/postfix-tls.1 up to 1.3 external/ibm-public/postfix/dist/man/man1/postfix.1 up to 1.6 external/ibm-public/postfix/dist/man/man1/postkick.1 up to 1.3 external/ibm-public/postfix/dist/man/man1/postlock.1 up to 1.3 external/ibm-public/postfix/dist/man/man1/postlog.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/postmap.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/postmulti.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/postqueue.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/postsuper.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/posttls-finger.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/sendmail.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/smtp-sink.1 up to 1.3 external/ibm-public/postfix/dist/man/man5/access.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/aliases.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/canonical.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/cidr_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/generic.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/header_checks.5 up to 1.3 external/ibm-public/postfix/dist/man/man5/ldap_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/lmdb_table.5 up to 1.3 external/ibm-public/postfix/dist/man/man5/master.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/mysql_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/pcre_table.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/pgsql_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/postconf.5 up to 1.19 external/ibm-public/postfix/dist/man/man5/regexp_table.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/relocated.5 up to 1.3 external/ibm-public/postfix/dist/man/man5/socketmap_table.5 up to 1.3 external/ibm-public/postfix/dist/man/man5/sqlite_table.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/tcp_table.5 up to 1.3 external/ibm-public/postfix/dist/man/man5/transport.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/virtual.5 up to 1.5 external/ibm-public/postfix/dist/man/man8/anvil.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/bounce.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/cleanup.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/discard.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/dnsblog.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/error.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/flush.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/local.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/master.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/oqmgr.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/pickup.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/pipe.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/postscreen.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/proxymap.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/qmgr.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/qmqpd.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/scache.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/showq.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/smtp.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/smtpd.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/spawn.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/tlsmgr.8 up to 1.3 external/ibm-public/postfix/dist/man/man8/tlsproxy.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/trivial-rewrite.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/verify.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/virtual.8 up to 1.4 external/ibm-public/postfix/dist/mantools/ccformat up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/check-postlink up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/fixman up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/make-relnotes up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/make_soho_readme up to 1.1.1.4 external/ibm-public/postfix/dist/mantools/makemanidx up to 1.1.1.4 external/ibm-public/postfix/dist/mantools/man2html up to 1.1.1.5 external/ibm-public/postfix/dist/mantools/manlint up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/manspell up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/postconf2man up to 1.1.1.5 external/ibm-public/postfix/dist/mantools/postlink up to 1.1.1.13 external/ibm-public/postfix/dist/mantools/readme2html up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/spell up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/srctoman up to 1.1.1.3 external/ibm-public/postfix/dist/proto/ADDRESS_CLASS_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/ADDRESS_REWRITING_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/ADDRESS_VERIFICATION_README.html up to 1.11 external/ibm-public/postfix/dist/proto/BACKSCATTER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/BASIC_CONFIGURATION_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/BUILTIN_FILTER_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/CDB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/COMPATIBILITY_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/CONNECTION_CACHE_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/CONTENT_INSPECTION_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/DATABASE_README.html up to 1.1.1.10 external/ibm-public/postfix/dist/proto/DB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/DEBUG_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/DSN_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/ETRN_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/FILTER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/FORWARD_SECRECY_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/INSTALL.html up to 1.10 external/ibm-public/postfix/dist/proto/IPV6_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/LDAP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/LINUX_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/LMDB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/LOCAL_RECIPIENT_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/MAILDROP_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/MEMCACHE_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/MILTER_README.html up to 1.1.1.9 external/ibm-public/postfix/dist/proto/MULTI_INSTANCE_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/proto/MYSQL_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/proto/NFS_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/OVERVIEW.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/PACKAGE_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/PCRE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/PGSQL_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/POSTSCREEN_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/proto/QSHAPE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/RESTRICTION_CLASS_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/SASL_README.html up to 1.1.1.11 external/ibm-public/postfix/dist/proto/SCHEDULER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/SMTPD_ACCESS_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/SMTPD_POLICY_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/proto/SMTPD_PROXY_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/SMTPUTF8_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/SQLITE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/STANDARD_CONFIGURATION_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/STRESS_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/proto/TLS_LEGACY_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/TLS_README.html up to 1.14 external/ibm-public/postfix/dist/proto/TUNING_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/UUCP_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/VERP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/VIRTUAL_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/XCLIENT_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/XFORWARD_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/access up to 1.1.1.8 external/ibm-public/postfix/dist/proto/aliases up to 1.1.1.6 external/ibm-public/postfix/dist/proto/canonical up to 1.1.1.5 external/ibm-public/postfix/dist/proto/cidr_table up to 1.1.1.6 external/ibm-public/postfix/dist/proto/generic up to 1.1.1.4 external/ibm-public/postfix/dist/proto/header_checks up to 1.1.1.7 external/ibm-public/postfix/dist/proto/ldap_table up to 1.1.1.7 external/ibm-public/postfix/dist/proto/lmdb_table up to 1.1.1.3 external/ibm-public/postfix/dist/proto/master up to 1.1.1.8 external/ibm-public/postfix/dist/proto/mysql_table up to 1.1.1.8 external/ibm-public/postfix/dist/proto/pcre_table up to 1.1.1.6 external/ibm-public/postfix/dist/proto/pgsql_table up to 1.1.1.8 external/ibm-public/postfix/dist/proto/postconf.html.prolog up to 1.1.1.5 external/ibm-public/postfix/dist/proto/postconf.man.prolog up to 1.1.1.4 external/ibm-public/postfix/dist/proto/postconf.proto up to 1.19 external/ibm-public/postfix/dist/proto/regexp_table up to 1.1.1.6 external/ibm-public/postfix/dist/proto/relocated up to 1.1.1.3 external/ibm-public/postfix/dist/proto/socketmap_table up to 1.1.1.3 external/ibm-public/postfix/dist/proto/sqlite_table up to 1.1.1.5 external/ibm-public/postfix/dist/proto/stop up to 1.1.1.7 external/ibm-public/postfix/dist/proto/tcp_table up to 1.1.1.4 external/ibm-public/postfix/dist/proto/transport up to 1.1.1.5 external/ibm-public/postfix/dist/proto/virtual up to 1.1.1.6 external/ibm-public/postfix/dist/src/anvil/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/anvil/anvil.c up to 1.4 external/ibm-public/postfix/dist/src/bounce/2template_test.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/bounce/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/bounce/bounce.c up to 1.4 external/ibm-public/postfix/dist/src/bounce/bounce_notify_util.c up to 1.4 external/ibm-public/postfix/dist/src/bounce/bounce_service.h up to 1.3 external/ibm-public/postfix/dist/src/bounce/bounce_template.c up to 1.4 external/ibm-public/postfix/dist/src/bounce/bounce_template.h up to 1.3 external/ibm-public/postfix/dist/src/bounce/bounce_templates.c up to 1.3 external/ibm-public/postfix/dist/src/bounce/template_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/cleanup/Makefile.in up to 1.1.1.9 external/ibm-public/postfix/dist/src/cleanup/cleanup.c up to 1.8 external/ibm-public/postfix/dist/src/cleanup/cleanup.h up to 1.10 external/ibm-public/postfix/dist/src/cleanup/cleanup_addr.c up to 1.3 external/ibm-public/postfix/dist/src/cleanup/cleanup_api.c up to 1.4 external/ibm-public/postfix/dist/src/cleanup/cleanup_body_edit.c up to 1.3 external/ibm-public/postfix/dist/src/cleanup/cleanup_envelope.c up to 1.5 external/ibm-public/postfix/dist/src/cleanup/cleanup_init.c up to 1.7 external/ibm-public/postfix/dist/src/cleanup/cleanup_map11.c up to 1.3 external/ibm-public/postfix/dist/src/cleanup/cleanup_map1n.c up to 1.4 external/ibm-public/postfix/dist/src/cleanup/cleanup_message.c up to 1.4 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.c up to 1.5 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13c up to 1.1.1.2 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.ref13d up to 1.1.1.2 external/ibm-public/postfix/dist/src/cleanup/cleanup_out.c up to 1.3 external/ibm-public/postfix/dist/src/cleanup/cleanup_out_recipient.c up to 1.4 external/ibm-public/postfix/dist/src/cleanup/cleanup_region.c up to 1.3 external/ibm-public/postfix/dist/src/cleanup/cleanup_state.c up to 1.4 external/ibm-public/postfix/dist/src/discard/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/discard/discard.c up to 1.3 external/ibm-public/postfix/dist/src/dns/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/dns/dns.h up to 1.6 external/ibm-public/postfix/dist/src/dns/dns_lookup.c up to 1.8 external/ibm-public/postfix/dist/src/dns/dns_rr.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_rr_eq_sa.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_rr_eq_sa.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/dns/dns_rr_eq_sa.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/dns/dns_rr_to_pa.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/dns/dns_rr_to_sa.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/dns/dns_sa_to_rr.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_sa_to_rr.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/dns/dns_strrecord.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_strtype.c up to 1.2 external/ibm-public/postfix/dist/src/dns/dnsbl_ttl_127.0.0.1_bind_ncache.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/dns/dnsbl_ttl_127.0.0.1_bind_plain.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/dns/dnsbl_ttl_127.0.0.2_bind_plain.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/dns/error.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/dns/mxonly_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/dns/no-a.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/dns/no-aaaa.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/dns/no-mx.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/dns/nullmx_test.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/dns/nxdomain_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/dns/test_dns_lookup.c up to 1.3 external/ibm-public/postfix/dist/src/dnsblog/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/dnsblog/dnsblog.c up to 1.4 external/ibm-public/postfix/dist/src/error/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/error/error.c up to 1.3 external/ibm-public/postfix/dist/src/flush/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/flush/flush.c up to 1.4 external/ibm-public/postfix/dist/src/fsstone/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/global/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/src/global/abounce.c up to 1.3 external/ibm-public/postfix/dist/src/global/anvil_clnt.c up to 1.4 external/ibm-public/postfix/dist/src/global/anvil_clnt.h up to 1.3 external/ibm-public/postfix/dist/src/global/been_here.c up to 1.4 external/ibm-public/postfix/dist/src/global/been_here.h up to 1.3 external/ibm-public/postfix/dist/src/global/bounce.c up to 1.3 external/ibm-public/postfix/dist/src/global/bounce_log.c up to 1.3 external/ibm-public/postfix/dist/src/global/cleanup_strerror.c up to 1.2 external/ibm-public/postfix/dist/src/global/cleanup_user.h up to 1.3 external/ibm-public/postfix/dist/src/global/clnt_stream.c up to 1.4 external/ibm-public/postfix/dist/src/global/clnt_stream.h up to 1.2 external/ibm-public/postfix/dist/src/global/db_common.c up to 1.3 external/ibm-public/postfix/dist/src/global/debug_peer.c up to 1.3 external/ibm-public/postfix/dist/src/global/defer.c up to 1.3 external/ibm-public/postfix/dist/src/global/deliver_pass.c up to 1.3 external/ibm-public/postfix/dist/src/global/deliver_request.c up to 1.3 external/ibm-public/postfix/dist/src/global/deliver_request.h up to 1.3 external/ibm-public/postfix/dist/src/global/delivered_hdr.c up to 1.3 external/ibm-public/postfix/dist/src/global/dict_ldap.c up to 1.5 external/ibm-public/postfix/dist/src/global/dict_memcache.c up to 1.3 external/ibm-public/postfix/dist/src/global/dict_mysql.c up to 1.4 external/ibm-public/postfix/dist/src/global/dict_pgsql.c up to 1.4 external/ibm-public/postfix/dist/src/global/dict_proxy.c up to 1.3 external/ibm-public/postfix/dist/src/global/dict_proxy.h up to 1.3 external/ibm-public/postfix/dist/src/global/dict_sqlite.c up to 1.4 external/ibm-public/postfix/dist/src/global/dsb_scan.c up to 1.3 external/ibm-public/postfix/dist/src/global/dsb_scan.h up to 1.2 external/ibm-public/postfix/dist/src/global/dsn_print.c up to 1.3 external/ibm-public/postfix/dist/src/global/dsn_print.h up to 1.2 external/ibm-public/postfix/dist/src/global/dynamicmaps.c up to 1.4 external/ibm-public/postfix/dist/src/global/ehlo_mask.c up to 1.3 external/ibm-public/postfix/dist/src/global/ehlo_mask.h up to 1.3 external/ibm-public/postfix/dist/src/global/flush_clnt.c up to 1.3 external/ibm-public/postfix/dist/src/global/haproxy_srvr.c up to 1.3 external/ibm-public/postfix/dist/src/global/haproxy_srvr.h up to 1.2 external/ibm-public/postfix/dist/src/global/header_body_checks.c up to 1.3 external/ibm-public/postfix/dist/src/global/header_body_checks.h up to 1.3 external/ibm-public/postfix/dist/src/global/log_adhoc.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_addr_crunch.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_addr_crunch.h up to 1.2 external/ibm-public/postfix/dist/src/global/mail_addr_find.c up to 1.4 external/ibm-public/postfix/dist/src/global/mail_addr_find.h up to 1.2 external/ibm-public/postfix/dist/src/global/mail_addr_map.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_addr_map.h up to 1.2 external/ibm-public/postfix/dist/src/global/mail_command_client.c up to 1.4 external/ibm-public/postfix/dist/src/global/mail_conf.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_conf.h up to 1.3 external/ibm-public/postfix/dist/src/global/mail_conf_int.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_conf_long.c up to 1.2 external/ibm-public/postfix/dist/src/global/mail_conf_nint.c up to 1.2 external/ibm-public/postfix/dist/src/global/mail_conf_time.c up to 1.4 external/ibm-public/postfix/dist/src/global/mail_copy.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_dict.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_error.c up to 1.2 external/ibm-public/postfix/dist/src/global/mail_params.c up to 1.5 external/ibm-public/postfix/dist/src/global/mail_params.h up to 1.19 external/ibm-public/postfix/dist/src/global/mail_parm_split.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_proto.h up to 1.5 external/ibm-public/postfix/dist/src/global/mail_queue.h up to 1.3 external/ibm-public/postfix/dist/src/global/mail_stream.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_task.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_version.h up to 1.6 external/ibm-public/postfix/dist/src/global/maps.c up to 1.4 external/ibm-public/postfix/dist/src/global/maps.h up to 1.2 external/ibm-public/postfix/dist/src/global/maps.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/global/memcache_proto.c up to 1.3 external/ibm-public/postfix/dist/src/global/mime_state.c up to 1.3 external/ibm-public/postfix/dist/src/global/mkmap_proxy.c up to 1.2 external/ibm-public/postfix/dist/src/global/msg_stats.h up to 1.2 external/ibm-public/postfix/dist/src/global/msg_stats_print.c up to 1.3 external/ibm-public/postfix/dist/src/global/msg_stats_scan.c up to 1.3 external/ibm-public/postfix/dist/src/global/namadr_list.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/global/namadr_list.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/global/off_cvt.c up to 1.2 external/ibm-public/postfix/dist/src/global/opened.c up to 1.2 external/ibm-public/postfix/dist/src/global/post_mail.c up to 1.4 external/ibm-public/postfix/dist/src/global/post_mail.h up to 1.3 external/ibm-public/postfix/dist/src/global/quote_822_local.c up to 1.3 external/ibm-public/postfix/dist/src/global/quote_822_local.h up to 1.2 external/ibm-public/postfix/dist/src/global/quote_flags.h up to 1.2 external/ibm-public/postfix/dist/src/global/rcpt_buf.c up to 1.4 external/ibm-public/postfix/dist/src/global/rcpt_buf.h up to 1.2 external/ibm-public/postfix/dist/src/global/rcpt_print.c up to 1.3 external/ibm-public/postfix/dist/src/global/rcpt_print.h up to 1.2 external/ibm-public/postfix/dist/src/global/rec_type.h up to 1.3 external/ibm-public/postfix/dist/src/global/record.c up to 1.4 external/ibm-public/postfix/dist/src/global/resolve_clnt.c up to 1.4 external/ibm-public/postfix/dist/src/global/resolve_clnt.h up to 1.2 external/ibm-public/postfix/dist/src/global/rewrite_clnt.c up to 1.3 external/ibm-public/postfix/dist/src/global/scache.h up to 1.3 external/ibm-public/postfix/dist/src/global/scache_clnt.c up to 1.3 external/ibm-public/postfix/dist/src/global/sent.c up to 1.3 external/ibm-public/postfix/dist/src/global/server_acl.c up to 1.3 external/ibm-public/postfix/dist/src/global/server_acl.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/global/server_acl.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/global/smtp_reply_footer.c up to 1.3 external/ibm-public/postfix/dist/src/global/smtp_stream.c up to 1.5 external/ibm-public/postfix/dist/src/global/smtp_stream.h up to 1.4 external/ibm-public/postfix/dist/src/global/smtputf8.h up to 1.3 external/ibm-public/postfix/dist/src/global/split_addr.c up to 1.3 external/ibm-public/postfix/dist/src/global/split_addr.h up to 1.2 external/ibm-public/postfix/dist/src/global/strip_addr.c up to 1.4 external/ibm-public/postfix/dist/src/global/strip_addr.h up to 1.2 external/ibm-public/postfix/dist/src/global/strip_addr.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/global/trace.c up to 1.3 external/ibm-public/postfix/dist/src/global/uxtext.c up to 1.3 external/ibm-public/postfix/dist/src/global/verify.c up to 1.4 external/ibm-public/postfix/dist/src/global/verify_clnt.c up to 1.3 external/ibm-public/postfix/dist/src/global/verify_sender_addr.c up to 1.4 external/ibm-public/postfix/dist/src/global/xtext.c up to 1.3 external/ibm-public/postfix/dist/src/local/Makefile.in up to 1.1.1.8 external/ibm-public/postfix/dist/src/local/alias.c up to 1.3 external/ibm-public/postfix/dist/src/local/forward.c up to 1.4 external/ibm-public/postfix/dist/src/local/local.c up to 1.4 external/ibm-public/postfix/dist/src/local/local_expand.c up to 1.3 external/ibm-public/postfix/dist/src/local/mailbox.c up to 1.4 external/ibm-public/postfix/dist/src/local/unknown.c up to 1.8 external/ibm-public/postfix/dist/src/master/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/master/event_server.c up to 1.4 external/ibm-public/postfix/dist/src/master/mail_server.h up to 1.4 external/ibm-public/postfix/dist/src/master/master.c up to 1.4 external/ibm-public/postfix/dist/src/master/master.h up to 1.2 external/ibm-public/postfix/dist/src/master/master_conf.c up to 1.2 external/ibm-public/postfix/dist/src/master/master_ent.c up to 1.4 external/ibm-public/postfix/dist/src/master/master_listen.c up to 1.2 external/ibm-public/postfix/dist/src/master/master_monitor.c up to 1.3 external/ibm-public/postfix/dist/src/master/master_proto.h up to 1.2 external/ibm-public/postfix/dist/src/master/master_sig.c up to 1.3 external/ibm-public/postfix/dist/src/master/master_spawn.c up to 1.3 external/ibm-public/postfix/dist/src/master/master_vars.c up to 1.3 external/ibm-public/postfix/dist/src/master/master_wakeup.c up to 1.3 external/ibm-public/postfix/dist/src/master/multi_server.c up to 1.4 external/ibm-public/postfix/dist/src/master/single_server.c up to 1.4 external/ibm-public/postfix/dist/src/master/trigger_server.c up to 1.4 external/ibm-public/postfix/dist/src/milter/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/milter/milter.c up to 1.5 external/ibm-public/postfix/dist/src/milter/milter.h up to 1.4 external/ibm-public/postfix/dist/src/milter/milter8.c up to 1.5 external/ibm-public/postfix/dist/src/milter/milter_macros.c up to 1.3 external/ibm-public/postfix/dist/src/milter/test-milter.c up to 1.3 external/ibm-public/postfix/dist/src/oqmgr/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/oqmgr/qmgr.c up to 1.3 external/ibm-public/postfix/dist/src/oqmgr/qmgr.h up to 1.3 external/ibm-public/postfix/dist/src/oqmgr/qmgr_active.c up to 1.3 external/ibm-public/postfix/dist/src/oqmgr/qmgr_deliver.c up to 1.3 external/ibm-public/postfix/dist/src/oqmgr/qmgr_entry.c up to 1.3 external/ibm-public/postfix/dist/src/oqmgr/qmgr_error.c up to 1.2 external/ibm-public/postfix/dist/src/oqmgr/qmgr_feedback.c up to 1.2 external/ibm-public/postfix/dist/src/oqmgr/qmgr_message.c up to 1.4 external/ibm-public/postfix/dist/src/pickup/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/pickup/pickup.c up to 1.4 external/ibm-public/postfix/dist/src/pipe/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/pipe/pipe.c up to 1.4 external/ibm-public/postfix/dist/src/postalias/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/postalias/fail_test.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/postalias/fail_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postalias/postalias.c up to 1.5 external/ibm-public/postfix/dist/src/postcat/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/postcat/postcat.c up to 1.4 external/ibm-public/postfix/dist/src/postconf/Makefile.in up to 1.1.1.11 external/ibm-public/postfix/dist/src/postconf/extract.awk up to 1.1.1.6 external/ibm-public/postfix/dist/src/postconf/install_vars.h up to 1.2 external/ibm-public/postfix/dist/src/postconf/postconf.c up to 1.4 external/ibm-public/postfix/dist/src/postconf/postconf.h up to 1.4 external/ibm-public/postfix/dist/src/postconf/postconf_builtin.c up to 1.4 external/ibm-public/postfix/dist/src/postconf/postconf_dbms.c up to 1.5 external/ibm-public/postfix/dist/src/postconf/postconf_edit.c up to 1.3 external/ibm-public/postfix/dist/src/postconf/postconf_lookup.c up to 1.4 external/ibm-public/postfix/dist/src/postconf/postconf_main.c up to 1.4 external/ibm-public/postfix/dist/src/postconf/postconf_master.c up to 1.8 external/ibm-public/postfix/dist/src/postconf/postconf_misc.c up to 1.3 external/ibm-public/postfix/dist/src/postconf/postconf_user.c up to 1.4 external/ibm-public/postfix/dist/src/postconf/test28.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/postconf/test29.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/postconf/test34.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test35.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test40.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/postconf/test41.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test42.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test43.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test44.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test58.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/postconf/test59.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/postdrop/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/postdrop/postdrop.c up to 1.4 external/ibm-public/postfix/dist/src/postfix/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/postfix/postfix.c up to 1.6 external/ibm-public/postfix/dist/src/postkick/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/postkick/postkick.c up to 1.4 external/ibm-public/postfix/dist/src/postlock/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/postlock/postlock.c up to 1.4 external/ibm-public/postfix/dist/src/postlog/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/postlog/postlog.c up to 1.5 external/ibm-public/postfix/dist/src/postmap/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/postmap/fail_test.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/postmap/fail_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postmap/postmap.c up to 1.5 external/ibm-public/postfix/dist/src/postmulti/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/postmulti/postmulti.c up to 1.4 external/ibm-public/postfix/dist/src/postqueue/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/postqueue/postqueue.c up to 1.5 external/ibm-public/postfix/dist/src/postqueue/showq_compat.c up to 1.4 external/ibm-public/postfix/dist/src/postqueue/showq_json.c up to 1.4 external/ibm-public/postfix/dist/src/postscreen/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/postscreen/postscreen.c up to 1.5 external/ibm-public/postfix/dist/src/postscreen/postscreen.h up to 1.4 external/ibm-public/postfix/dist/src/postscreen/postscreen_dnsbl.c up to 1.4 external/ibm-public/postfix/dist/src/postscreen/postscreen_early.c up to 1.4 external/ibm-public/postfix/dist/src/postscreen/postscreen_endpt.c up to 1.4 external/ibm-public/postfix/dist/src/postscreen/postscreen_haproxy.c up to 1.3 external/ibm-public/postfix/dist/src/postscreen/postscreen_haproxy.h up to 1.2 external/ibm-public/postfix/dist/src/postscreen/postscreen_misc.c up to 1.4 external/ibm-public/postfix/dist/src/postscreen/postscreen_send.c up to 1.3 external/ibm-public/postfix/dist/src/postscreen/postscreen_smtpd.c up to 1.5 external/ibm-public/postfix/dist/src/postscreen/postscreen_starttls.c up to 1.4 external/ibm-public/postfix/dist/src/postscreen/postscreen_state.c up to 1.4 external/ibm-public/postfix/dist/src/postscreen/postscreen_tests.c up to 1.4 external/ibm-public/postfix/dist/src/postsuper/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/postsuper/postsuper.c up to 1.4 external/ibm-public/postfix/dist/src/posttls-finger/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/posttls-finger/posttls-finger.c up to 1.5 external/ibm-public/postfix/dist/src/proxymap/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/proxymap/proxymap.c up to 1.4 external/ibm-public/postfix/dist/src/qmgr/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/qmgr/qmgr.c up to 1.3 external/ibm-public/postfix/dist/src/qmgr/qmgr.h up to 1.3 external/ibm-public/postfix/dist/src/qmgr/qmgr_active.c up to 1.3 external/ibm-public/postfix/dist/src/qmgr/qmgr_deliver.c up to 1.3 external/ibm-public/postfix/dist/src/qmgr/qmgr_entry.c up to 1.3 external/ibm-public/postfix/dist/src/qmgr/qmgr_error.c up to 1.2 external/ibm-public/postfix/dist/src/qmgr/qmgr_feedback.c up to 1.2 external/ibm-public/postfix/dist/src/qmgr/qmgr_message.c up to 1.4 external/ibm-public/postfix/dist/src/qmqpd/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/qmqpd/qmqpd.c up to 1.4 external/ibm-public/postfix/dist/src/qmqpd/qmqpd_peer.c up to 1.3 external/ibm-public/postfix/dist/src/scache/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/scache/scache.c up to 1.4 external/ibm-public/postfix/dist/src/sendmail/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/sendmail/sendmail.c up to 1.4 external/ibm-public/postfix/dist/src/showq/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/showq/showq.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/src/smtp/lmtp_params.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp.c up to 1.13 external/ibm-public/postfix/dist/src/smtp/smtp.h up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_addr.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_addr.h up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_chat.c up to 1.4 external/ibm-public/postfix/dist/src/smtp/smtp_connect.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_key.c up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_map11.c up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_map11.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtp/smtp_params.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_proto.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_rcpt.c up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_reuse.c up to 1.4 external/ibm-public/postfix/dist/src/smtp/smtp_sasl_auth_cache.c up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_sasl_glue.c up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_sasl_proto.c up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_session.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_state.c up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_tls_policy.c up to 1.4 external/ibm-public/postfix/dist/src/smtp/smtp_trouble.c up to 1.3 external/ibm-public/postfix/dist/src/smtpd/Makefile.in up to 1.1.1.11 external/ibm-public/postfix/dist/src/smtpd/pfilter.c up to 1.2 (+patch) external/ibm-public/postfix/dist/src/smtpd/smtpd.c up to 1.20 external/ibm-public/postfix/dist/src/smtpd/smtpd.h up to 1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_acl.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_acl.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_chat.c up to 1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_chat.h up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.c up to 1.6 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.h up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.in2 up to 1.1.1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.in3 up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.ref2 up to 1.1.1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_check_backup.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_check_backup.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_check_dsn.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_check_dsn.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_dns_filter.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_dnswl.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_dnswl.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_error.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_error.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_exp.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_exp.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_expand.h up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_haproxy.c up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_milter.c up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_nullmx.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_nullmx.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/smtpd/smtpd_peer.c up to 1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_proxy.c up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_resolve.c up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_resolve.h up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_sasl_glue.c up to 1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_sasl_proto.c up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_server.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_server.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_state.c up to 1.2 external/ibm-public/postfix/dist/src/smtpstone/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/smtpstone/smtp-sink.c up to 1.3 external/ibm-public/postfix/dist/src/smtpstone/smtp-source.c up to 1.3 external/ibm-public/postfix/dist/src/spawn/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/spawn/spawn.c up to 1.4 external/ibm-public/postfix/dist/src/tls/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/src/tls/tls.h up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_bio_ops.c up to 1.1.1.6 external/ibm-public/postfix/dist/src/tls/tls_certkey.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_client.c up to 1.13 external/ibm-public/postfix/dist/src/tls/tls_dane.c up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_dh.c up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_fprint.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_mgr.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_misc.c up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_proxy.h up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_proxy_clnt.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_rsa.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_scache.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_server.c up to 1.12 external/ibm-public/postfix/dist/src/tls/tls_session.c up to 1.3 external/ibm-public/postfix/dist/src/tls/tls_verify.c up to 1.4 external/ibm-public/postfix/dist/src/tlsmgr/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/tlsmgr/tlsmgr.c up to 1.4 external/ibm-public/postfix/dist/src/tlsproxy/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy.c up to 1.6 external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy.h up to 1.2 external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy_state.c up to 1.3 external/ibm-public/postfix/dist/src/trivial-rewrite/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/trivial-rewrite/resolve.c up to 1.4 external/ibm-public/postfix/dist/src/trivial-rewrite/rewrite.c up to 1.3 external/ibm-public/postfix/dist/src/trivial-rewrite/transport.c up to 1.4 external/ibm-public/postfix/dist/src/trivial-rewrite/trivial-rewrite.c up to 1.4 external/ibm-public/postfix/dist/src/trivial-rewrite/trivial-rewrite.h up to 1.3 external/ibm-public/postfix/dist/src/util/Makefile.in up to 1.1.1.11 external/ibm-public/postfix/dist/src/util/allascii.c up to 1.3 external/ibm-public/postfix/dist/src/util/alldig.c up to 1.2 external/ibm-public/postfix/dist/src/util/argv.c up to 1.4 external/ibm-public/postfix/dist/src/util/argv.h up to 1.4 external/ibm-public/postfix/dist/src/util/attr.h up to 1.5 external/ibm-public/postfix/dist/src/util/attr_clnt.c up to 1.3 external/ibm-public/postfix/dist/src/util/attr_clnt.h up to 1.3 external/ibm-public/postfix/dist/src/util/attr_print0.c up to 1.3 external/ibm-public/postfix/dist/src/util/attr_print64.c up to 1.3 external/ibm-public/postfix/dist/src/util/attr_print_plain.c up to 1.3 external/ibm-public/postfix/dist/src/util/attr_scan0.c up to 1.3 external/ibm-public/postfix/dist/src/util/attr_scan0.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/util/attr_scan64.c up to 1.3 external/ibm-public/postfix/dist/src/util/attr_scan64.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/util/attr_scan_plain.c up to 1.3 external/ibm-public/postfix/dist/src/util/attr_scan_plain.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/util/auto_clnt.c up to 1.4 external/ibm-public/postfix/dist/src/util/auto_clnt.h up to 1.2 external/ibm-public/postfix/dist/src/util/base32_code.h up to 1.3 external/ibm-public/postfix/dist/src/util/base64_code.h up to 1.3 external/ibm-public/postfix/dist/src/util/binhash.c up to 1.3 external/ibm-public/postfix/dist/src/util/binhash.h up to 1.3 external/ibm-public/postfix/dist/src/util/casefold.c up to 1.3 external/ibm-public/postfix/dist/src/util/check_arg.h up to 1.3 external/ibm-public/postfix/dist/src/util/cidr_match.c up to 1.4 external/ibm-public/postfix/dist/src/util/cidr_match.h up to 1.2 external/ibm-public/postfix/dist/src/util/clean_env.c up to 1.3 external/ibm-public/postfix/dist/src/util/clean_env.h up to 1.2 external/ibm-public/postfix/dist/src/util/connect.h up to 1.2 external/ibm-public/postfix/dist/src/util/dict.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict.h up to 1.5 external/ibm-public/postfix/dist/src/util/dict_alloc.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_cache.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_cdb.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_cdb.h up to 1.2 external/ibm-public/postfix/dist/src/util/dict_cidr.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_cidr.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/dict_cidr.map up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/dict_cidr.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/util/dict_db.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_db.h up to 1.4 external/ibm-public/postfix/dist/src/util/dict_dbm.h up to 1.2 external/ibm-public/postfix/dist/src/util/dict_fail.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_fail.h up to 1.2 external/ibm-public/postfix/dist/src/util/dict_inline.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_lmdb.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_lmdb.h up to 1.3 external/ibm-public/postfix/dist/src/util/dict_open.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_pcre.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_pcre.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/dict_pcre.map up to 1.1.1.3 external/ibm-public/postfix/dist/src/util/dict_pcre.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/util/dict_random.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_random.h up to 1.3 external/ibm-public/postfix/dist/src/util/dict_regexp.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_regexp.map up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/dict_regexp.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/util/dict_sdbm.h up to 1.2 external/ibm-public/postfix/dist/src/util/dict_static.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_thash.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_thash.map up to 1.1.1.3 external/ibm-public/postfix/dist/src/util/dict_union.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_utf8.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_utf8_test.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/dup2_pass_on_exec.c up to 1.2 external/ibm-public/postfix/dist/src/util/edit_file.c up to 1.4 external/ibm-public/postfix/dist/src/util/edit_file.h up to 1.3 external/ibm-public/postfix/dist/src/util/extpar.c up to 1.4 external/ibm-public/postfix/dist/src/util/find_inet.c up to 1.3 external/ibm-public/postfix/dist/src/util/gccw.c up to 1.2 external/ibm-public/postfix/dist/src/util/hex_code.c up to 1.3 external/ibm-public/postfix/dist/src/util/hex_code.h up to 1.4 external/ibm-public/postfix/dist/src/util/hex_quote.c up to 1.2 external/ibm-public/postfix/dist/src/util/host_port.h up to 1.3 external/ibm-public/postfix/dist/src/util/htable.c up to 1.4 external/ibm-public/postfix/dist/src/util/inet_addr_host.c up to 1.3 external/ibm-public/postfix/dist/src/util/inet_addr_list.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/inet_addr_list.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/inet_connect.c up to 1.3 external/ibm-public/postfix/dist/src/util/inet_listen.c up to 1.3 external/ibm-public/postfix/dist/src/util/inet_proto.c up to 1.4 external/ibm-public/postfix/dist/src/util/inet_proto.h up to 1.2 external/ibm-public/postfix/dist/src/util/killme_after.c up to 1.2 external/ibm-public/postfix/dist/src/util/listen.h up to 1.3 external/ibm-public/postfix/dist/src/util/load_lib.c up to 1.3 external/ibm-public/postfix/dist/src/util/lstat_as.h up to 1.3 external/ibm-public/postfix/dist/src/util/mac_expand.c up to 1.4 external/ibm-public/postfix/dist/src/util/mac_expand.h up to 1.4 external/ibm-public/postfix/dist/src/util/mac_expand.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/util/mac_expand.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/util/mac_parse.h up to 1.3 external/ibm-public/postfix/dist/src/util/make_dirs.c up to 1.2 external/ibm-public/postfix/dist/src/util/match_list.c up to 1.3 external/ibm-public/postfix/dist/src/util/match_ops.c up to 1.3 external/ibm-public/postfix/dist/src/util/midna_domain.c up to 1.4 external/ibm-public/postfix/dist/src/util/midna_domain.h up to 1.4 external/ibm-public/postfix/dist/src/util/midna_domain_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/msg_output.c up to 1.4 external/ibm-public/postfix/dist/src/util/msg_output.h up to 1.3 external/ibm-public/postfix/dist/src/util/msg_syslog.c up to 1.2 external/ibm-public/postfix/dist/src/util/msg_syslog.h up to 1.3 external/ibm-public/postfix/dist/src/util/mvect.c up to 1.3 external/ibm-public/postfix/dist/src/util/myaddrinfo.c up to 1.3 external/ibm-public/postfix/dist/src/util/myaddrinfo.h up to 1.3 external/ibm-public/postfix/dist/src/util/myaddrinfo.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/util/myaddrinfo4.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/myflock.c up to 1.3 external/ibm-public/postfix/dist/src/util/myflock.h up to 1.3 external/ibm-public/postfix/dist/src/util/mymalloc.c up to 1.4 external/ibm-public/postfix/dist/src/util/mymalloc.h up to 1.4 external/ibm-public/postfix/dist/src/util/mystrtok.c up to 1.4 external/ibm-public/postfix/dist/src/util/name_mask.c up to 1.3 external/ibm-public/postfix/dist/src/util/nbbio.c up to 1.3 external/ibm-public/postfix/dist/src/util/netstring.c up to 1.3 external/ibm-public/postfix/dist/src/util/peekfd.c up to 1.3 external/ibm-public/postfix/dist/src/util/printable.c up to 1.3 external/ibm-public/postfix/dist/src/util/recv_pass_attr.c up to 1.3 external/ibm-public/postfix/dist/src/util/sane_fsops.h up to 1.3 external/ibm-public/postfix/dist/src/util/sane_link.c up to 1.2 external/ibm-public/postfix/dist/src/util/sane_rename.c up to 1.2 external/ibm-public/postfix/dist/src/util/sane_socketpair.h up to 1.3 external/ibm-public/postfix/dist/src/util/slmdb.c up to 1.4 external/ibm-public/postfix/dist/src/util/sock_addr.c up to 1.3 external/ibm-public/postfix/dist/src/util/sock_addr.h up to 1.2 external/ibm-public/postfix/dist/src/util/split_nameval.c up to 1.2 external/ibm-public/postfix/dist/src/util/stat_as.h up to 1.3 external/ibm-public/postfix/dist/src/util/stringops.h up to 1.5 external/ibm-public/postfix/dist/src/util/sys_compat.c up to 1.3 external/ibm-public/postfix/dist/src/util/sys_defs.h up to 1.14 external/ibm-public/postfix/dist/src/util/timed_wait.h up to 1.3 external/ibm-public/postfix/dist/src/util/unix_pass_fd_fix.c up to 1.2 external/ibm-public/postfix/dist/src/util/unix_send_fd.c up to 1.8 external/ibm-public/postfix/dist/src/util/unsafe.c up to 1.2 external/ibm-public/postfix/dist/src/util/valid_hostname.c up to 1.3 external/ibm-public/postfix/dist/src/util/valid_hostname.h up to 1.2 external/ibm-public/postfix/dist/src/util/vbuf.c up to 1.3 external/ibm-public/postfix/dist/src/util/vbuf_print.c up to 1.4 external/ibm-public/postfix/dist/src/util/vstream.c up to 1.4 external/ibm-public/postfix/dist/src/util/vstream.h up to 1.4 external/ibm-public/postfix/dist/src/util/vstream_tweak.c up to 1.3 external/ibm-public/postfix/dist/src/util/vstring.c up to 1.4 external/ibm-public/postfix/dist/src/util/vstring.h up to 1.4 external/ibm-public/postfix/dist/src/util/vstring_vstream.c up to 1.2 external/ibm-public/postfix/dist/src/util/vstring_vstream.h up to 1.3 external/ibm-public/postfix/dist/src/util/watchdog.c up to 1.3 external/ibm-public/postfix/dist/src/verify/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/verify/verify.c up to 1.4 external/ibm-public/postfix/dist/src/virtual/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/virtual/mailbox.c up to 1.3 external/ibm-public/postfix/dist/src/virtual/virtual.c up to 1.4 external/ibm-public/postfix/dist/src/xsasl/Makefile.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/xsasl/xsasl.h up to 1.3 external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_client.c up to 1.3 external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_server.c up to 1.4 external/ibm-public/postfix/dist/src/xsasl/xsasl_dovecot_server.c up to 1.4 external/ibm-public/postfix/dist/src/xsasl/xsasl_saslc_client.c up to 1.2 external/ibm-public/postfix/dist/src/xsasl/xsasl_server.c up to 1.2 external/ibm-public/postfix/lib/dns/Makefile up to 1.4 external/ibm-public/postfix/lib/global/Makefile up to 1.10 external/ibm-public/postfix/lib/masterlib/Makefile up to 1.3 external/ibm-public/postfix/lib/milter/Makefile up to 1.2 external/ibm-public/postfix/lib/tls/Makefile up to 1.4 external/ibm-public/postfix/lib/util/Makefile up to 1.11 external/ibm-public/postfix/lib/xsasl/Makefile up to 1.3 external/ibm-public/postfix/libexec/smtp/Makefile up to 1.4 external/ibm-public/postfix/libexec/smtpd/Makefile up to 1.9 (+patch) external/ibm-public/postfix/libexec/tlsproxy/Makefile up to 1.2 external/ibm-public/postfix/sbin/postconf/Makefile up to 1.9 doc/3RDPARTY (apply patch) Update Postfix to 3.8.4. @ text @d4 1 a4 2 d13 1 a13 1 smtp [generic Postfix daemon options] [flags=DORX] d44 1 a44 3 The Postfix SMTP+LMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). SMTP destinations have the following form: d66 1 a66 3 The Postfix SMTP+LMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). LMTP destinations have the following form: a86 46 SINGLE-RECIPIENT DELIVERY By default, the Postfix SMTP+LMTP client delivers mail to multiple recipients per delivery request. This is undesirable when prepending a Delivered-to: or X-Original-To: message header. To prevent Postfix from sending multiple recipients per delivery request, specify transport_destination_recipient_limit = 1 in the Postfix main.cf file, where transport is the name in the first column of the Postfix master.cf entry for this mail delivery service. COMMAND ATTRIBUTE SYNTAX flags=DORX (optional) Optional message processing flags. D Prepend a "Delivered-To: recipient" message header with the envelope recipient address. Note: for this to work, the transport_destination_recipient_limit must be 1 (see SINGLE-RECIPIENT DELIVERY above for details). The D flag also enforces loop detection: if a message already contains a Delivered-To: header with the same recipient address, then the message is returned as unde- liverable. The address comparison is case insensitive. This feature is available as of Postfix 3.5. O Prepend an "X-Original-To: recipient" message header with the recipient address as given to Postfix. Note: for this to work, the transport_destination_recipient_limit must be 1 (see SINGLE-RECIPIENT DELIVERY above for details). This feature is available as of Postfix 3.5. R Prepend a "Return-Path: <sender>" message header with the envelope sender address. This feature is available as of Postfix 3.5. X Indicates that the delivery is final. This flag affects the status reported in "success" DSN (delivery status notification) messages, and changes it from "relayed" into "delivered". This feature is available as of Postfix 3.5. d88 3 a90 4 The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP or LMTP servers and to DNS servers on the network. The SMTP+LMTP client can be run chrooted at fixed low privilege. d93 20 a112 21 RFC 821 (SMTP protocol) RFC 822 (ARPA Internet Text Messages) RFC 1651 (SMTP service extensions) RFC 1652 (8bit-MIME transport) RFC 1870 (Message Size Declaration) RFC 2033 (LMTP protocol) RFC 2034 (SMTP Enhanced Error Codes) RFC 2045 (MIME: Format of Internet Message Bodies) RFC 2046 (MIME: Media Types) RFC 2554 (AUTH command) RFC 2821 (SMTP protocol) RFC 2782 (SRV resource records) RFC 2920 (SMTP Pipelining) RFC 3207 (STARTTLS command) RFC 3461 (SMTP DSN Extension) RFC 3463 (Enhanced Status Codes) RFC 4954 (AUTH command) RFC 5321 (SMTP protocol) RFC 6531 (Internationalized SMTP) RFC 6533 (Internationalized Delivery Status Notifications) RFC 7672 (SMTP security via opportunistic DANE TLS) d115 3 a117 3 Problems and transactions are logged to syslogd(8) or postlogd(8). Corrupted message files are marked so that the queue manager can move them to the corrupt queue for further inspection. d119 1 a119 1 Depending on the setting of the notify_classes parameter, the postmas- d123 7 a129 5 SMTP and LMTP connection reuse for TLS (without closing the SMTP or LMTP connection) is not supported before Postfix 3.4. SMTP and LMTP connection reuse assumes that SASL credentials are valid for all destinations that map onto the same IP address and TCP port. d132 3 a134 3 Before Postfix version 2.3, the LMTP client is a separate program that implements only a subset of the functionality available with SMTP: there is no support for TLS, and connections are cached in-process, d138 1 a138 1 eter for the equivalent LMTP feature. This document describes only d141 1 a141 1 Changes to main.cf are picked up automatically, as smtp(8) processes d145 1 a145 1 The text below provides only a parameter summary. See postconf(5) for d166 2 a167 2 How long the Postfix SMTP client pauses before sending ".<CR><LF>" in order to work around the PIX firewall d176 1 a176 1 A list that specifies zero or more workarounds for CISCO PIX d180 1 a180 1 Lookup tables, indexed by the remote SMTP server address, with d184 2 a185 2 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO commands as required by RFC 5321. d188 1 a188 1 A mechanism to transform replies from remote SMTP servers one d200 1 a200 1 Skip SMTP servers that greet with a 4XX status code (go away, d206 2 a207 2 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO keywords (pipelining, starttls, d212 1 a212 1 A case insensitive list of EHLO keywords (pipelining, starttls, d217 3 a219 3 Optional lookup tables that perform address rewriting in the Postfix SMTP client, typically to transform a locally valid address into a globally valid address when sending mail across d225 3 a227 3 When the remote SMTP servername is a DNS CNAME, replace the servername with the result from CNAME expansion for the purpose of logging, SASL password lookup, TLS policy decisions, or TLS d233 2 a234 2 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, d239 1 a239 1 A case insensitive list of LHLO keywords (pipelining, starttls, d246 3 a248 3 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- d254 1 a254 1 Restricted header_checks(5) tables for the Postfix SMTP client. d257 1 a257 1 Restricted mime_header_checks(5) tables for the Postfix SMTP d261 1 a261 1 Restricted nested_header_checks(5) tables for the Postfix SMTP d270 1 a270 1 An optional workaround for routers that break TCP window scal- d278 1 a278 1 Available in Postfix version 2.9 - 3.6: d281 4 a284 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- a286 2 Available in Postfix version 2.9 and later: d288 1 a288 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d299 1 a299 1 Optional filter for the smtp(8) delivery agent to change the a305 56 Available in Postfix version 3.3 and later: smtp_balance_inet_protocols (yes) When a remote destination resolves to a combination of IPv4 and IPv6 addresses, ensure that the Postfix SMTP client can try both address types before it runs into the smtp_mx_address_limit. Available in Postfix 3.5 and later: info_log_address_format (external) The email address form that will be used in non-debug logging (info, warning, etc.). Available in Postfix 3.6 and later: dnssec_probe (ns:.) The DNS query type (default: "ns") and DNS query name (default: ".") that Postfix may use to determine whether DNSSEC validation is available. known_tcp_ports (lmtp=24, smtp=25, smtps=submissions=465, submis- sion=587) Optional setting that avoids lookups in the services(5) data- base. Available in Postfix version 3.7 and later: smtp_per_request_deadline (no) Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for receiving a complete SMTP response. smtp_min_data_rate (500) The minimum plaintext data transfer rate in bytes/second for DATA requests, when deadlines are enabled with smtp_per_request_deadline. header_from_format (standard) The format of the Postfix-generated From: header. Available in Postfix version 3.8 and later: use_srv_lookup (empty) Enables discovery for the specified service(s) using DNS SRV records. ignore_srv_lookup_error (no) When SRV record lookup fails, fall back to MX or IP address lookup as if SRV record lookup was not enabled. allow_srv_lookup_fallback (no) When SRV record lookup fails or no SRV record exists, fall back to MX or IP address lookup as if SRV record lookup was not enabled. d389 4 a392 1 The default SMTP TLS security level for the Postfix SMTP client. d449 3 a451 3 smtp_tls_mandatory_protocols (see 'postconf -d' output) TLS protocols that the Postfix SMTP client will use with manda- tory TLS encryption. a482 6 tls_null_cipherlist (eNULL:!aNULL) The OpenSSL cipherlist for "NULL" grade ciphers that provide authentication without encryption. Available in in Postfix version 2.3..3.7: d489 4 d508 1 a508 1 smtp_tls_fingerprint_digest (see 'postconf -d' output) d514 3 a516 3 smtp_tls_protocols (see postconf -d output) TLS protocols that the Postfix SMTP client will use with oppor- tunistic TLS encryption. a542 9 Available in Postfix version 2.11-3.1: tls_dane_digest_agility (on) Configure RFC7671 DANE TLSA digest algorithm agility. tls_dane_trust_anchor_digest_enable (yes) Enable support for RFC 6698 (DANE TLSA) DNS records that contain digests of trust-anchors with certificate usage "2". d546 1 a546 1 Zero or more PEM-format files with trust-anchor certificates d550 1 a550 1 Lookup the associated DANE TLSA RRset even when a hostname is d553 3 d562 2 a563 2 Request that the Postfix SMTP client connects using the SUBMIS- SIONS/SMTPS protocol instead of using the STARTTLS command. d567 1 a567 1 smtp_tls_dane_insecure_mx_policy (see 'postconf -d' output) a571 41 Available in Postfix version 3.2 and later: tls_eecdh_auto_curves (see 'postconf -d' output) The prioritized list of elliptic curves supported by the Postfix SMTP client and server. Available in Postfix version 3.4 and later: smtp_tls_connection_reuse (no) Try to make multiple deliveries per TLS-encrypted connection. smtp_tls_chain_files (empty) List of one or more PEM files, each holding one or more private keys directly followed by a corresponding certificate chain. smtp_tls_servername (empty) Optional name to send to the remote SMTP server in the TLS Server Name Indication (SNI) extension. Available in Postfix 3.5, 3.4.6, 3.3.5, 3.2.10, 3.1.13 and later: tls_fast_shutdown_enable (yes) A workaround for implementations that hang Postfix while shut- ting down a TLS session, until Postfix times out. Available in Postfix version 3.8 and later: tls_ffdhe_auto_groups (see 'postconf -d' output) The prioritized list of finite-field Diffie-Hellman ephemeral (FFDHE) key exchange groups supported by the Postfix SMTP client and server. Available in Postfix 3.9, 3.8.1, 3.7.6, 3.6.10, 3.5.20 and later: tls_config_file (default) Optional configuration file with baseline OpenSSL settings. tls_config_name (empty) The application name passed by Postfix to OpenSSL library ini- tialization functions. d600 9 d696 1 a696 1 Available in Postfix version 2.9 - 3.6: a711 32 Available in Postfix version 3.4 and later: smtp_tls_connection_reuse (no) Try to make multiple deliveries per TLS-encrypted connection. Available in Postfix version 3.7 and later: smtp_per_request_deadline (no) Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for receiving a complete SMTP response. smtp_min_data_rate (500) The minimum plaintext data transfer rate in bytes/second for DATA requests, when deadlines are enabled with smtp_per_request_deadline. Implemented in the qmgr(8) daemon: transport_destination_concurrency_limit ($default_destination_concur- rency_limit) A transport-specific override for the default_destination_con- currency_limit parameter value, where transport is the master.cf name of the message delivery transport. transport_destination_recipient_limit ($default_destination_recipi- ent_limit) A transport-specific override for the default_destination_recip- ient_limit parameter value, where transport is the master.cf name of the message delivery transport. d716 2 a717 2 Enable preliminary SMTPUTF8 support for the protocols described in RFC 6531, RFC 6532, and RFC 6533. d720 1 a720 1 Detect that a message requires SMTPUTF8 support for the speci- a722 7 Available in Postfix version 3.2 and later: enable_idna2003_compatibility (no) Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII form that is used for DNS lookups. d725 2 a726 3 The increment in verbose logging level when a nexthop destina- tion, remote client or server name or network address matches a pattern given with the debug_peer_list parameter. d729 3 a731 4 Optional list of nexthop destination, remote client or server name or network address patterns that, if matched, cause the verbose logging level to increase by the amount specified in $debug_peer_level. d734 1 a734 1 The recipient of postmaster notifications about mail delivery d739 2 a740 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d748 1 a748 1 Where the Postfix SMTP client should deliver mail when it d752 1 a752 1 The default location of the Postfix main.cf and master.cf con- d756 1 a756 1 How much time a Postfix daemon process may take to handle a d760 1 a760 1 The maximal number of digits after the decimal point when log- d767 2 a768 2 The local network interface addresses that this mail system receives mail on. d770 2 a771 2 inet_protocols (see 'postconf -d output') The Internet protocols Postfix will attempt to use when making d775 1 a775 1 The time limit for sending or receiving information over an d779 2 a780 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d787 1 a787 1 The maximum amount of time that an idle Postfix daemon process d801 2 a802 3 The remote network interface addresses that this mail system receives mail on by way of a proxy or network address transla- tion unit. d834 3 a836 2 A prefix that is prepended to the process name in syslog records, so that, for example, "smtpd" becomes "prefix/smtpd". d847 2 a848 3 Optional list of relay destinations that will be used when an SMTP destination is not found, or when delivery fails due to a non-permanent error. a861 16 Available with Postfix 3.2 and later: smtp_tcp_port (smtp) The default TCP port that the Postfix SMTP client connects to. Available in Postfix 3.3 and later: service_name (read-only) The master.cf service name of a Postfix daemon process. Available in Postfix 3.7 and later: smtp_bind_address_enforce (no) Defer delivery when the Postfix SMTP client cannot apply the smtp_bind_address or smtp_bind_address6 setting. a872 1 postlogd(8), Postfix logging @ 1.1.1.9.12.1 log @Merge changes from current as of 20200406 @ text @d13 1 a13 1 smtp [generic Postfix daemon options] [flags=DORX] d44 1 a44 3 The Postfix SMTP+LMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). SMTP destinations have the following form: d66 1 a66 3 The Postfix SMTP+LMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). LMTP destinations have the following form: a86 46 SINGLE-RECIPIENT DELIVERY By default, the Postfix SMTP+LMTP client delivers mail to multiple recipients per delivery request. This is undesirable when prepending a Delivered-to: or X-Original-To: message header. To prevent Postfix from sending multiple recipients per delivery request, specify transport_destination_recipient_limit = 1 in the Postfix main.cf file, where transport is the name in the first column of the Postfix master.cf entry for this mail delivery service. COMMAND ATTRIBUTE SYNTAX flags=DORX (optional) Optional message processing flags. D Prepend a "Delivered-To: recipient" message header with the envelope recipient address. Note: for this to work, the transport_destination_recipient_limit must be 1 (see SINGLE-RECIPIENT DELIVERY above for details). The D flag also enforces loop detection: if a message already contains a Delivered-To: header with the same recipient address, then the message is returned as unde- liverable. The address comparison is case insensitive. This feature is available as of Postfix 3.5. O Prepend an "X-Original-To: recipient" message header with the recipient address as given to Postfix. Note: for this to work, the transport_destination_recipient_limit must be 1 (see SINGLE-RECIPIENT DELIVERY above for details). This feature is available as of Postfix 3.5. R Prepend a "Return-Path: <sender>" message header with the envelope sender address. This feature is available as of Postfix 3.5. X Indicates that the delivery is final. This flag affects the status reported in "success" DSN (delivery status notification) messages, and changes it from "relayed" into "delivered". This feature is available as of Postfix 3.5. d88 3 a90 4 The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP or LMTP servers and to DNS servers on the network. The SMTP+LMTP client can be run chrooted at fixed low privilege. d115 3 a117 3 Problems and transactions are logged to syslogd(8) or postlogd(8). Corrupted message files are marked so that the queue manager can move them to the corrupt queue for further inspection. d119 1 a119 1 Depending on the setting of the notify_classes parameter, the postmas- d123 7 a129 5 SMTP and LMTP connection reuse for TLS (without closing the SMTP or LMTP connection) is not supported before Postfix 3.4. SMTP and LMTP connection reuse assumes that SASL credentials are valid for all destinations that map onto the same IP address and TCP port. d132 3 a134 3 Before Postfix version 2.3, the LMTP client is a separate program that implements only a subset of the functionality available with SMTP: there is no support for TLS, and connections are cached in-process, d138 1 a138 1 eter for the equivalent LMTP feature. This document describes only d141 1 a141 1 Changes to main.cf are picked up automatically, as smtp(8) processes d145 1 a145 1 The text below provides only a parameter summary. See postconf(5) for d166 2 a167 2 How long the Postfix SMTP client pauses before sending ".<CR><LF>" in order to work around the PIX firewall d176 1 a176 1 A list that specifies zero or more workarounds for CISCO PIX d180 1 a180 1 Lookup tables, indexed by the remote SMTP server address, with d184 1 a184 1 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO d188 1 a188 1 A mechanism to transform replies from remote SMTP servers one d200 1 a200 1 Skip SMTP servers that greet with a 4XX status code (go away, d206 2 a207 2 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO keywords (pipelining, starttls, d212 1 a212 1 A case insensitive list of EHLO keywords (pipelining, starttls, d217 3 a219 3 Optional lookup tables that perform address rewriting in the Postfix SMTP client, typically to transform a locally valid address into a globally valid address when sending mail across d225 3 a227 3 When the remote SMTP servername is a DNS CNAME, replace the servername with the result from CNAME expansion for the purpose of logging, SASL password lookup, TLS policy decisions, or TLS d233 2 a234 2 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, d239 1 a239 1 A case insensitive list of LHLO keywords (pipelining, starttls, d246 3 a248 3 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- d254 1 a254 1 Restricted header_checks(5) tables for the Postfix SMTP client. d257 1 a257 1 Restricted mime_header_checks(5) tables for the Postfix SMTP d261 1 a261 1 Restricted nested_header_checks(5) tables for the Postfix SMTP d270 1 a270 1 An optional workaround for routers that break TCP window scal- d281 4 a284 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d288 1 a288 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d299 1 a299 1 Optional filter for the smtp(8) delivery agent to change the a305 13 Available in Postfix version 3.3 and later: smtp_balance_inet_protocols (yes) When a remote destination resolves to a combination of IPv4 and IPv6 addresses, ensure that the Postfix SMTP client can try both address types before it runs into the smtp_mx_address_limit. Available in Postfix 3.5 and later: info_log_address_format (external) The email address form that will be used in non-debug logging (info, warning, etc.). a542 9 Available in Postfix version 2.11-3.1: tls_dane_digest_agility (on) Configure RFC7671 DANE TLSA digest algorithm agility. tls_dane_trust_anchor_digest_enable (yes) Enable support for RFC 6698 (DANE TLSA) DNS records that contain digests of trust-anchors with certificate usage "2". d546 1 a546 1 Zero or more PEM-format files with trust-anchor certificates d550 1 a550 1 Lookup the associated DANE TLSA RRset even when a hostname is d553 3 a571 19 Available in Postfix version 3.4 and later: smtp_tls_connection_reuse (no) Try to make multiple deliveries per TLS-encrypted connection. smtp_tls_chain_files (empty) List of one or more PEM files, each holding one or more private keys directly followed by a corresponding certificate chain. smtp_tls_servername (empty) Optional name to send to the remote SMTP server in the TLS Server Name Indication (SNI) extension. Available in Postfix 3.5, 3.4.6, 3.3.5, 3.2.10, 3.1.13 and later: tls_fast_shutdown_enable (yes) A workaround for implementations that hang Postfix while shut- ting down a TLS session, until Postfix times out. d573 2 a574 2 The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a d578 1 a578 1 Opportunistic mode: use TLS when a remote SMTP server announces d582 1 a582 1 Enforcement mode: require that remote SMTP servers use TLS d586 2 a587 2 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP d591 2 a592 2 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- d596 1 a596 1 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS d600 9 d610 1 a610 1 The Postfix SMTP client time limit for completing a TCP connec- d614 2 a615 2 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server d627 1 a627 1 The Postfix SMTP client time limit for sending the MAIL FROM d631 1 a631 1 The Postfix SMTP client time limit for sending the SMTP RCPT TO d635 1 a635 1 The Postfix SMTP client time limit for sending the SMTP DATA d639 1 a639 1 The Postfix SMTP client time limit for sending the SMTP message d653 2 a654 2 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero d658 2 a659 2 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back d669 1 a669 1 Keep Postfix LMTP client connections open for up to $max_idle d675 1 a675 1 Permanently enable SMTP connection caching for the specified d679 1 a679 1 Temporarily enable SMTP connection caching while a destination d693 1 a693 1 Time limit for connection cache connect, send or receive opera- d699 4 a702 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d708 2 a709 2 When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero a711 19 Available in Postfix version 3.4 and later: smtp_tls_connection_reuse (no) Try to make multiple deliveries per TLS-encrypted connection. Implemented in the qmgr(8) daemon: transport_destination_concurrency_limit ($default_destination_concur- rency_limit) A transport-specific override for the default_destination_con- currency_limit parameter value, where transport is the master.cf name of the message delivery transport. transport_destination_recipient_limit ($default_destination_recipi- ent_limit) A transport-specific override for the default_destination_recip- ient_limit parameter value, where transport is the master.cf name of the message delivery transport. d716 1 a716 1 Enable preliminary SMTPUTF8 support for the protocols described d720 1 a720 1 Detect that a message requires SMTPUTF8 support for the speci- a722 7 Available in Postfix version 3.2 and later: enable_idna2003_compatibility (no) Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII form that is used for DNS lookups. d725 1 a725 1 The increment in verbose logging level when a remote client or d729 1 a729 1 Optional list of remote client or server hostname or network d734 1 a734 1 The recipient of postmaster notifications about mail delivery d739 2 a740 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d748 1 a748 1 Where the Postfix SMTP client should deliver mail when it d752 1 a752 1 The default location of the Postfix main.cf and master.cf con- d756 1 a756 1 How much time a Postfix daemon process may take to handle a d760 1 a760 1 The maximal number of digits after the decimal point when log- d767 1 a767 1 The network interface addresses that this mail system receives d771 1 a771 1 The Internet protocols Postfix will attempt to use when making d775 1 a775 1 The time limit for sending or receiving information over an d779 2 a780 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d787 1 a787 1 The maximum amount of time that an idle Postfix daemon process d801 1 a801 1 The network interface addresses that this mail system receives d806 1 a806 1 client will try first, when a destination has IPv6 and IPv4 d810 1 a810 1 An optional numerical network address that the Postfix SMTP d814 1 a814 1 An optional numerical network address that the Postfix SMTP d834 3 a836 2 A prefix that is prepended to the process name in syslog records, so that, for example, "smtpd" becomes "prefix/smtpd". a861 10 Available with Postfix 3.2 and later: smtp_tcp_port (smtp) The default TCP port that the Postfix SMTP client connects to. Available in Postfix 3.3 and later: service_name (read-only) The master.cf service name of a Postfix daemon process. a872 1 postlogd(8), Postfix logging @ 1.1.1.10 log @This is the Postfix 3.5 (stable) release. The stable Postfix release is called postfix-3.5.x where 3=major release number, 5=minor release number, x=patchlevel. The stable release never changes except for patches that address bugs or emergencies. Patches change the patchlevel and the release date. New features are developed in snapshot releases. These are called postfix-3.6-yyyymmdd where yyyymmdd is the release date (yyyy=year, mm=month, dd=day). Patches are never issued for snapshot releases; instead, a new snapshot is released. The mail_release_date configuration parameter (format: yyyymmdd) specifies the release date of a stable release or snapshot release. If you upgrade from Postfix 3.3 or earlier, read RELEASE_NOTES-3.4 before proceeding. License change --------------- This software is distributed with a dual license: in addition to the historical IBM Public License 1.0, it is now also distributed with the more recent Eclipse Public License 2.0. Recipients can choose to take the software under the license of their choice. Those who are more comfortable with the IPL can continue with that license. Major changes - multiple relayhost in SMTP ------------------------------------------ [Feature 20200111] the Postfix SMTP and LMTP client support a list of nexthop destinations separated by comma or whitespace. These destinations will be tried in the specified order. The list form can be specified in relayhost, transport_maps, default_transport, and sender_dependent_default_transport_maps. Examples: /etc/postfix/main.cf: relayhost = foo.example, bar.example default_transport = smtp:foo.example, bar.example. NOTE: this is an SMTP and LMTP client feature. It does not work for other Postfix delivery agents. Major changes - certificate access ---------------------------------- [Feature 20190517] Search order support for check_ccert_access. Search order support for other tables is in design (canonical_maps, virtual_alias_maps, transport_maps, etc.). The following check_ccert_access setting uses the built-in search order: it first looks up the client certificate fingerprint, then the client certificate public-key fingerprint, and it stops when a decision is made. /etc/postfix/main.cf: smtpd_mumble_restrictions = ... check_ccert_access hash:/etc/postfix/ccert-access ... The following setting, with explicit search order, produces the exact same result: /etc/postfix/main.cf: smtpd_mumble_restrictions = ... check_ccert_access { hash:/etc/postfix/ccert-access { search_order = cert_fingerprint, pubkey_fingerprint } } ... Support is planned for other certificate features. Major changes - dovecot usability --------------------------------- [Feature 20190615] The SMTP+LMTP delivery agent can now prepend Delivered-To, X-Original-To and Return-Path headers, just like the pipe(8) and local(8) delivery agents. This uses the "flags=DORX" command-line flags in master.cf. See the smtp(8) manpage for details. This obsoletes the "lmtp_assume_final = yes" setting, and replaces it with "flags=...X...", for consistency with the pipe(8) delivery agent. Major changes - forced expiration --------------------------------- [Feature 20200202] Support to force-expire email messages. This introduces new postsuper(1) command-line options to request expiration, and additional information in mailq(1) or postqueue(1) output. The forced-to-expire status is stored in a queue file attribute. An expired message is returned to the sender when the queue manager attempts to deliver that message (note that Postfix will never deliver messages in the hold queue). The postsuper(1) -e and -f options both set the forced-to-expire queue file attribute. The difference is that -f will also release a message if it is in the hold queue. With -e, such a message would not be returned to the sender until it is released with -f or -H. In the mailq(1) or postqueue(1) -p output, a forced-to-expire message is indicated with # after the queue file name. In postqueue(1) JSON output, there is a new per-message field "forced_expire" (with value true or false) that shows the forced-to-expire status. Major changes - haproxy2 protocol --------------------------------- [Feature 20200112] Support for the haproxy v2 protocol. The Postfix implementation supports TCP over IPv4 and IPv6, as well as non-proxied connections; the latter are typically used for heartbeat tests. The haproxy v2 protocol introduces no additional Postfix configuration. The Postfix smtpd(8) and postscreen(8) daemons accept both v1 and v2 protocol versions. Major changes - logging ----------------------- [Incompat 20191109] Postfix daemon processes now log the from= and to= addresses in external (quoted) form in non-debug logging (info, warning, etc.). This means that when an address localpart contains spaces or other special characters, the localpart will be quoted, for example: from=<"name with spaces"@@example.com> Older Postfix versions would log the internal (unquoted) form: from= The external and internal forms are identical for the vast majority of email addresses that contain no spaces or other special characters in the localpart. Specify "info_log_address_format = internal" for backwards compatibility. The logging in external form is consistent with the address form that Postfix 3.2 and later prefer for table lookups. It is therefore the more useful form for non-debug logging. Major changes - IP address normalization ---------------------------------------- [Incompat 20190427] Postfix now normalizes IP addresses received with XCLIENT, XFORWARD, or with the HaProxy protocol, for consistency with direct connections to Postfix. This may change the appearance of logging, and the way that check_client_access will match subnets of an IPv6 address. This is the Postfix 3.4 (stable) release. The stable Postfix release is called postfix-3.4.x where 3=major release number, 4=minor release number, x=patchlevel. The stable release never changes except for patches that address bugs or emergencies. Patches change the patchlevel and the release date. New features are developed in snapshot releases. These are called postfix-3.5-yyyymmdd where yyyymmdd is the release date (yyyy=year, mm=month, dd=day). Patches are never issued for snapshot releases; instead, a new snapshot is released. The mail_release_date configuration parameter (format: yyyymmdd) specifies the release date of a stable release or snapshot release. If you upgrade from Postfix 3.2 or earlier, read RELEASE_NOTES-3.3 before proceeding. License change --------------- This software is distributed with a dual license: in addition to the historical IBM Public License 1.0, it is now also distributed with the more recent Eclipse Public License 2.0. Recipients can choose to take the software under the license of their choice. Those who are more comfortable with the IPL can continue with that license. Summary of changes ------------------ Incompatible changes, bdat support, containers, database support, logging, safety, tls connection pooling, tls support, usability, Incompatible changes -------------------- [Incompat 20180826] The Postfix SMTP server announces CHUNKING (BDAT command) by default. In the unlikely case that this breaks some important remote SMTP client, disable the feature as follows: /etc/postfix/main.cf: # The logging alternative: smtpd_discard_ehlo_keywords = chunking # The non-logging alternative: smtpd_discard_ehlo_keywords = chunking, silent_discard See BDAT_README for more. [Incompat 20190126] This introduces a new master.cf service 'postlog' with type 'unix-dgram' that is used by the new postlogd(8) daemon. Before backing out to an older Postfix version, edit the master.cf file and remove the postlog entry. [Incompat 20190106] Postfix 3.4 drops support for OpenSSL 1.0.1 (end-of-life was December 31, 2016) and all earlier releases. [Incompat 20180701] To avoid performance loss under load, the tlsproxy(8) daemon now requires a zero process limit in master.cf (this setting is provided with the default master.cf file). By default, a tlsproxy(8) process will retire after several hours. To set the tlsproxy process limit to zero: # postconf -F tlsproxy/unix/process_limit=0 # postfix reload Major changes - bdat support -------------------- [Feature 20180826] Postfix SMTP server support for RFC 3030 CHUNKING (the BDAT command) without BINARYMIME, in both smtpd(8) and postscreen(8). This has no effect on Milters, smtpd_mumble_restrictions, and smtpd_proxy_filter. See BDAT_README for more. Major changes - containers -------------------------- [Feature 20190126] Support for logging to file or stdout, instead of using syslog. - Logging to file solves a usability problem for MacOS, and eliminates multiple problems with systemd-based systems. - Logging to stdout is useful when Postfix runs in a container, as it eliminates a syslogd dependency. See MAILLOG_README for configuration examples and logfile rotation. [Feature 20180422] Better handling of undocumented(!) Linux behavior whether or not signals are delivered to a PID=1 process. Major changes - database support -------------------------------- [Feature 20181105] Support for (key, list of filenames) in map source text. - Currently, this feature is used only by tls_server_sni_maps. - When a map is created from source with "postmap -F maptype:mapname", the command processes each key as usual and processes each value as a list of filenames, concatenates the content of those files (with one newline character in-between files), and stores an entry with (key, base64-encoded result). - When a map is queried with "postmap -F -q ...", the command base64-decodes each value. It reports an error when a value is not in base64 form. This "postmap -F -q ..." behavior also works when querying the memory-resident map types cidr:, inline:, pcre:, randmap:, regexp:, and static:. Postfix reads the files specified as table values, stores base64-encoded content, and base64-decodes content upon table lookup. Internally, Postfix will turn on this behavior for lookups (not updates) when a map is opened with the DICT_FLAG_RHS_IS_FILE flag. Major changes - logging ----------------------- [Feature 20190126] Support for logging to file or stdout, instead of using syslog. - Logging to file solves a usability problem for MacOS, and eliminates multiple problems with systemd-based systems. - Logging to stdout is useful when Postfix runs in a container, as it eliminates a syslogd dependency. See MAILLOG_README for configuration examples and logfile rotation. Major changes - safety ---------------------- [Feature 20180623] Automatic retirement: dnsblog(8) and tlsproxy(8) process will now voluntarily retire after after max_idle*max_use, or some sane limit if either limit is disabled. Without this, a process could stay busy for days or more. Major changes - tls connection pooling -------------------------------------- [Feature 20180617] Postfix SMTP client support for multiple deliveries per TLS-encrypted connection. This is primarily to improve mail delivery performance for destinations that throttle clients when they don't combine deliveries. This feature is enabled with "smtp_tls_connection_reuse=yes" in main.cf, or with "tls_connection_reuse=yes" in smtp_tls_policy_maps. It supports all Postfix TLS security levels including dane and dane-only. The implementation of TLS connection reuse relies on the same scache(8) service as used for delivering plaintext SMTP mail, the same tlsproxy(8) daemon as used by the postscreen(8) service for inbound connections, and relies on the same hints from the qmgr(8) daemon. It reuses the configuration parameters described in CONNECTION_CACHE_README. The Postfix SMTP client now logs whether an SMTP-over-TLS connection is newly established ("TLS connection established") or whether the connection is reused ("TLS connection reused"). The following illustrates how TLS connections are reused: Initial plaintext SMTP handshake: smtp(8) -> remote SMTP server Reused SMTP/TLS connection, or new SMTP/TLS connection: smtp(8) -> tlsproxy(8) -> remote SMTP server Cached SMTP/TLS connection: scache(8) -> tlsproxy(8) -> remote SMTP server Major changes - tls support --------------------------- [Feature 20190106] SNI support in the Postfix SMTP server, the Postfix SMTP client, and in the tlsproxy(8) daemon (both server and client roles). See the postconf(5) documentation for the new tls_server_sni_maps and smtp_tls_servername parameters. [Feature 20190106] Support for files that contain multiple (key, certificate, trust chain) instances. This was required to implement server-side SNI table lookups, but it also eliminates the need for separate cert/key files for RSA, DSA, Elliptic Curve, and so on. The file format is documented in the TLS_README sections "Server-side certificate and private key configuration" and "Client-side certificate and private key configuration", and in the postconf(5) documentation for the parameters smtp_tls_chain_files, smtpd_tls_chain_files, tlsproxy_client_chain_files, and tlsproxy_tls_chain_files. Note: the command "postfix tls" does not yet support the new consolidated certificate chain format. If you switch to the new format, you'll need to manage your keys and certificates directly, rather than via postfix-tls(1). Major changes - usability ------------------------- [Feature 20180812] Support for smtpd_reject_footer_maps (as well as the postscreen variant postscreen_reject_footer_maps) for more informative reject messages. This is indexed with the Postfix SMTP server response text, and overrides the footer specified with smtpd_reject_footer. One will want to use a pcre: or regexp: map with this. This is the Postfix 3.3 (stable) release. The stable Postfix release is called postfix-3.3.x where 3=major release number, 3=minor release number, x=patchlevel. The stable release never changes except for patches that address bugs or emergencies. Patches change the patchlevel and the release date. New features are developed in snapshot releases. These are called postfix-3.4-yyyymmdd where yyyymmdd is the release date (yyyy=year, mm=month, dd=day). Patches are never issued for snapshot releases; instead, a new snapshot is released. The mail_release_date configuration parameter (format: yyyymmdd) specifies the release date of a stable release or snapshot release. If you upgrade from Postfix 3.1 or earlier, read RELEASE_NOTES-3.2 before proceeding. License change --------------- This software is distributed with a dual license: in addition to the historical IBM Public License 1.0, it is now also distributed with the more recent Eclipse Public License 2.0. Recipients can choose to take the software under the license of their choice. Those who are more comfortable with the IPL can continue with that license. Major changes - compatibility safety net ---------------------------------------- [20180106] With compatibility_level < 1, the Postfix SMTP server now warns for mail that would be blocked by the Postfix 2.10 smtpd_relay_restrictions feature, without blocking that mail. This extends the compatibility safety net for sites that upgrade from earlier Postfix versions (questions on the postfix-users list show there is a steady trickle). See COMPATIBILITY_README for details. Major changes - configuration ----------------------------- [20170617] The postconf command now warns about unknown parameter names in a Postfix database configuration file. As with other unknown parameter names, these warnings can help to find typos early. [20180113] New read-only service_name parameter that contains the master.cf service name of a Postfix daemon process (it that is empty in a non-daemon process). This can make Postfix SMTP server logging logging distinct by setting the syslog_name in master.cf with "-o syslog_name=postfix/$service_name" for the "submission" and "smtps" services, and can make Postfix SMTP client distinct by setting "-o syslog_name=postfix/$service_name" for the "relay" service. Major changes - container support --------------------------------- [20171218] Preliminary support to run Postfix in the foreground, with "postfix start-fg". This requires that Postfix multi-instance support is disabled. To receive Postfix syslog information on the container's host, mount the host's /dev/log socket inside the container (example: "docker run -v /dev/log:/dev/log ..."), and specify a distinct Postfix "syslog_name" prefix that identifies the logging from the Postfix instance. Postfix does not log systemd events. Major changes - database support --------------------------------- [20170617] The postconf command warns about unknown parameter names in a Postfix database configuration file. [20171227] The pgsql_table(5) hosts parameter now supports the postgresql:// URI syntax. Contributed by Magosányi Árpád. Major changes - header format ----------------------------- [20180010] This release changes the format of 'full name' information in Postfix-generated From: headers, when a local program such as /bin/mail submits a message without From: header. Postfix-generated From: headers with 'full name' information are now formatted as "From: name
" by default. Specify "header_from_format = obsolete" to get the earlier form "From: address (name)". See the postconf(5) manpage for more details. Major changes - invisible changes --------------------------------- [20170617] Additional paranoia in the VSTRING implementation: a null byte after the end of vstring buffers (this is a safety net so that C-style string operations won't scribble past the end); earlier detection of bad length and precision format string specifiers (these are the result of programming error, as Postfix format strings cannot be specified externally). Major changes - milter support ------------------------------ [20171223] Milter applications can now send RET and ENVID parameters in SMFIR_CHGFROM (change envelope sender) requests. Major changes - mixed IPv6/IPv4 support --------------------------------------- [20170505] Workaround for mail delivery problems when 1) both Postfix IPv6 and IPv4 support are enabled, 2) some destination announces more primary IPv6 MX addresses than primary IPv4 MX addresses, 3) the destination is unreachable over IPv6, and 4) Postfix runs into the smtp_mx_address_limit before it can try to deliver over IPv4. When both Postfix IPv6 and IPv4 support are enabled, the Postfix SMTP client will now relax MX preferences so that it can schedule similar numbers of IPv4 and IPv6 destination addresses. This ensures that an IPv6 connectivity problem will not prevent mail from being delivered over IPv4 (and vice versa). Specify "smtp_balance_inet_protocols = no" to disable this workaround. Major changes - xclient ----------------------- [20171218] The Postfix SMTP server now allows the XCLIENT command before STARTTLS when TLS is required. This is useful for servers that run behind a reverse proxy server such as nginx. This is the Postfix 3.2 (stable) release. The stable Postfix release is called postfix-3.2.x where 3=major release number, 2=minor release number, x=patchlevel. The stable release never changes except for patches that address bugs or emergencies. Patches change the patchlevel and the release date. New features are developed in snapshot releases. These are called postfix-3.3-yyyymmdd where yyyymmdd is the release date (yyyy=year, mm=month, dd=day). Patches are never issued for snapshot releases; instead, a new snapshot is released. The mail_release_date configuration parameter (format: yyyymmdd) specifies the release date of a stable release or snapshot release. If you upgrade from Postfix 3.0 or earlier, read RELEASE_NOTES-3.1 before proceeding. Invisible changes ----------------- In addition to the visible changes described below, there is an ongoing overhaul of low-level code. With each change come updated tests to ensure that future changes will not 'break' compatibility with past behavior. Major changes - address mapping ------------------------------- [Feature 20170128] Postfix 3.2 fixes the handling of address extensions with email addresses that contain spaces. For example, the virtual_alias_maps, canonical_maps, and smtp_generic_maps features now correctly propagate an address extension from "aa bb+ext"@@example.com to "cc dd+ext"@@other.example, instead of producing broken output. Major changes - header/body_checks ---------------------------------- [Feature 20161008] "PASS" and "STRIP" actions in header/body_checks. "STRIP" is similar to "IGNORE" but also logs the action, and "PASS" disables header, body, and Milter inspection for the remainder of the message content. Contributed by Hobbit. Major changes - log analysis ---------------------------- [Feature 20160330] The collate.pl script by Viktor Dukhovni for grouping Postfix logfile records into "sessions" based on queue ID and process ID information. It's in the auxiliary/collate directory of the Postfix source tree. Major changes - maps support ---------------------------- [Feature 20160527] Postfix 3.2 cidr tables support if/endif and negation (by prepending ! to a pattern), just like regexp and pcre tables. The primarily purpose is to improve readability of complex tables. See the cidr_table(5) manpage for syntax details. [Incompat 20160925] In the Postfix MySQL database client, the default option_group value has changed to "client", to enable reading of "client" option group settings in the MySQL options file. This fixes a "not found" problem with Postfix queries that contain UTF8-encoded non-ASCII text. Specify an empty option_group value (option_group =) to get backwards-compatible behavior. [Feature 20161217] Stored-procedure support for MySQL databases. Contributed by John Fawcett. See mysql_table(5) for instructions. [Feature 20170128] The postmap command, and the inline: and texthash: maps now support spaces in left-hand field of the lookup table "source text". Use double quotes (") around a left-hand field that contains spaces, and use backslash (\) to protect embedded quotes in a left-hand field. There is no change in the processing of the right-hand field. Major changes - milter support ------------------------------ [Feature 20160611] The Postfix SMTP server local IP address and port are available in the policy delegation protocol (attribute names: server_address, server_port), in the Milter protocol (macro names: {daemon_addr}, {daemon_port}), and in the XCLIENT protocol (attribute names: DESTADDR, DESTPORT). [Feature 20161024] smtpd_milter_maps support for per-client Milter configuration that overrides smtpd_milters, and that has the same syntax. A lookup result of "DISABLE" turns off Milter support. See MILTER_README.html for details. Major changes - policy delegation --------------------------------- [Feature 20160611] The Postfix SMTP server local IP address and port are available in the policy delegation protocol (attribute names: server_address, server_port), in the Milter protocol (macro names: {daemon_addr}, {daemon_port}), and in the XCLIENT protocol (attribute names: DESTADDR, DESTPORT). Major changes - postqueue ------------------------- [Incompat 20170129] The postqueue command no longer forces all message arrival times to be reported in UTC. To get the old behavior, set TZ=UTC in main.cf:import_environment (this override is not recommended, as it affects all Postfix utities and daemons). Major changes - safety ---------------------- [Incompat 20161227] For safety reasons, the sendmail -C option must specify an authorized directory: the default configuration directory, a directory that is listed in the default main.cf file with alternate_config_directories or multi_instance_directories, or the command must be invoked with root privileges (UID 0 and EUID 0). This mitigates a recurring problem with the PHP mail() function. Major changes - sasl -------------------- [Feature 20160625] The Postfix SMTP server now passes remote client and local server network address and port information to the Cyrus SASL library. Build with ``make makefiles "CCARGS=$CCARGS -DNO_IP_CYRUS_SASL_AUTH"'' for backwards compatibility. Major changes - smtputf8 ------------------------ [Feature 20161103] Postfix 3.2 disables the 'transitional' compatibility between the IDNA2003 and IDNA2008 standards for internationalized domain names (domain names beyond the limits of US-ASCII). This change makes Postfix behavior consistent with contemporary web browsers. It affects the handling of some corner cases such as German sz and Greek zeta. See http://unicode.org/cldr/utility/idna.jsp for more examples. Specify "enable_idna2003_compatibility = yes" to restore historical behavior (but keep in mind that the rest of the world may not make that same choice). Major changes - tls ------------------- [Feature 20160828] Fixes for deprecated OpenSSL 1.1.0 API features, so that Postfix will build without depending on backwards-compatibility support. [Incompat 20161204] Postfix 3.2 removes tentative features that were implemented before the DANE spec was finalized: - Support for certificate usage PKIX-EE(1), - The ability to disable digest agility (Postfix now behaves as if "tls_dane_digest_agility = on"), and - The ability to disable support for "TLSA 2 [01] [12]" records that specify the digest of a trust anchor (Postfix now behaves as if "tls_dane_trust_anchor_digest_enable = yes). [Feature 20161217] Postfix 3.2 enables elliptic curve negotiation with OpenSSL >= 1.0.2. This changes the default smtpd_tls_eecdh_grade setting to "auto", and introduces a new parameter tls_eecdh_auto_curves with the names of curves that may be negotiated. The default tls_eecdh_auto_curves setting is determined at compile time, and depends on the Postfix and OpenSSL versions. At runtime, Postfix will skip curve names that aren't supported by the OpenSSL library. Major changes - xclient ----------------------- [Feature 20160611] The Postfix SMTP server local IP address and port are available in the policy delegation protocol (attribute names: server_address, server_port), in the Milter protocol (macro names: {daemon_addr}, {daemon_port}), and in the XCLIENT protocol (attribute names: DESTADDR, DESTPORT). @ text @d13 1 a13 1 smtp [generic Postfix daemon options] [flags=DORX] d44 1 a44 3 The Postfix SMTP+LMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). SMTP destinations have the following form: d66 1 a66 3 The Postfix SMTP+LMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). LMTP destinations have the following form: a86 46 SINGLE-RECIPIENT DELIVERY By default, the Postfix SMTP+LMTP client delivers mail to multiple recipients per delivery request. This is undesirable when prepending a Delivered-to: or X-Original-To: message header. To prevent Postfix from sending multiple recipients per delivery request, specify transport_destination_recipient_limit = 1 in the Postfix main.cf file, where transport is the name in the first column of the Postfix master.cf entry for this mail delivery service. COMMAND ATTRIBUTE SYNTAX flags=DORX (optional) Optional message processing flags. D Prepend a "Delivered-To: recipient" message header with the envelope recipient address. Note: for this to work, the transport_destination_recipient_limit must be 1 (see SINGLE-RECIPIENT DELIVERY above for details). The D flag also enforces loop detection: if a message already contains a Delivered-To: header with the same recipient address, then the message is returned as unde- liverable. The address comparison is case insensitive. This feature is available as of Postfix 3.5. O Prepend an "X-Original-To: recipient" message header with the recipient address as given to Postfix. Note: for this to work, the transport_destination_recipient_limit must be 1 (see SINGLE-RECIPIENT DELIVERY above for details). This feature is available as of Postfix 3.5. R Prepend a "Return-Path: <sender>" message header with the envelope sender address. This feature is available as of Postfix 3.5. X Indicates that the delivery is final. This flag affects the status reported in "success" DSN (delivery status notification) messages, and changes it from "relayed" into "delivered". This feature is available as of Postfix 3.5. d88 3 a90 4 The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP or LMTP servers and to DNS servers on the network. The SMTP+LMTP client can be run chrooted at fixed low privilege. d115 3 a117 3 Problems and transactions are logged to syslogd(8) or postlogd(8). Corrupted message files are marked so that the queue manager can move them to the corrupt queue for further inspection. d119 1 a119 1 Depending on the setting of the notify_classes parameter, the postmas- d123 7 a129 5 SMTP and LMTP connection reuse for TLS (without closing the SMTP or LMTP connection) is not supported before Postfix 3.4. SMTP and LMTP connection reuse assumes that SASL credentials are valid for all destinations that map onto the same IP address and TCP port. d132 3 a134 3 Before Postfix version 2.3, the LMTP client is a separate program that implements only a subset of the functionality available with SMTP: there is no support for TLS, and connections are cached in-process, d138 1 a138 1 eter for the equivalent LMTP feature. This document describes only d141 1 a141 1 Changes to main.cf are picked up automatically, as smtp(8) processes d145 1 a145 1 The text below provides only a parameter summary. See postconf(5) for d166 2 a167 2 How long the Postfix SMTP client pauses before sending ".<CR><LF>" in order to work around the PIX firewall d176 1 a176 1 A list that specifies zero or more workarounds for CISCO PIX d180 1 a180 1 Lookup tables, indexed by the remote SMTP server address, with d184 1 a184 1 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO d188 1 a188 1 A mechanism to transform replies from remote SMTP servers one d200 1 a200 1 Skip SMTP servers that greet with a 4XX status code (go away, d206 2 a207 2 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO keywords (pipelining, starttls, d212 1 a212 1 A case insensitive list of EHLO keywords (pipelining, starttls, d217 3 a219 3 Optional lookup tables that perform address rewriting in the Postfix SMTP client, typically to transform a locally valid address into a globally valid address when sending mail across d225 3 a227 3 When the remote SMTP servername is a DNS CNAME, replace the servername with the result from CNAME expansion for the purpose of logging, SASL password lookup, TLS policy decisions, or TLS d233 2 a234 2 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, d239 1 a239 1 A case insensitive list of LHLO keywords (pipelining, starttls, d246 3 a248 3 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- d254 1 a254 1 Restricted header_checks(5) tables for the Postfix SMTP client. d257 1 a257 1 Restricted mime_header_checks(5) tables for the Postfix SMTP d261 1 a261 1 Restricted nested_header_checks(5) tables for the Postfix SMTP d270 1 a270 1 An optional workaround for routers that break TCP window scal- d281 4 a284 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d288 1 a288 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d299 1 a299 1 Optional filter for the smtp(8) delivery agent to change the a305 13 Available in Postfix version 3.3 and later: smtp_balance_inet_protocols (yes) When a remote destination resolves to a combination of IPv4 and IPv6 addresses, ensure that the Postfix SMTP client can try both address types before it runs into the smtp_mx_address_limit. Available in Postfix 3.5 and later: info_log_address_format (external) The email address form that will be used in non-debug logging (info, warning, etc.). a542 9 Available in Postfix version 2.11-3.1: tls_dane_digest_agility (on) Configure RFC7671 DANE TLSA digest algorithm agility. tls_dane_trust_anchor_digest_enable (yes) Enable support for RFC 6698 (DANE TLSA) DNS records that contain digests of trust-anchors with certificate usage "2". d546 1 a546 1 Zero or more PEM-format files with trust-anchor certificates d550 1 a550 1 Lookup the associated DANE TLSA RRset even when a hostname is d553 3 a571 19 Available in Postfix version 3.4 and later: smtp_tls_connection_reuse (no) Try to make multiple deliveries per TLS-encrypted connection. smtp_tls_chain_files (empty) List of one or more PEM files, each holding one or more private keys directly followed by a corresponding certificate chain. smtp_tls_servername (empty) Optional name to send to the remote SMTP server in the TLS Server Name Indication (SNI) extension. Available in Postfix 3.5, 3.4.6, 3.3.5, 3.2.10, 3.1.13 and later: tls_fast_shutdown_enable (yes) A workaround for implementations that hang Postfix while shut- ting down a TLS session, until Postfix times out. d573 2 a574 2 The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a d578 1 a578 1 Opportunistic mode: use TLS when a remote SMTP server announces d582 1 a582 1 Enforcement mode: require that remote SMTP servers use TLS d586 2 a587 2 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP d591 2 a592 2 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- d596 1 a596 1 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS d600 9 d610 1 a610 1 The Postfix SMTP client time limit for completing a TCP connec- d614 2 a615 2 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server d627 1 a627 1 The Postfix SMTP client time limit for sending the MAIL FROM d631 1 a631 1 The Postfix SMTP client time limit for sending the SMTP RCPT TO d635 1 a635 1 The Postfix SMTP client time limit for sending the SMTP DATA d639 1 a639 1 The Postfix SMTP client time limit for sending the SMTP message d653 2 a654 2 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero d658 2 a659 2 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back d669 1 a669 1 Keep Postfix LMTP client connections open for up to $max_idle d675 1 a675 1 Permanently enable SMTP connection caching for the specified d679 1 a679 1 Temporarily enable SMTP connection caching while a destination d693 1 a693 1 Time limit for connection cache connect, send or receive opera- d699 4 a702 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d708 2 a709 2 When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero a711 19 Available in Postfix version 3.4 and later: smtp_tls_connection_reuse (no) Try to make multiple deliveries per TLS-encrypted connection. Implemented in the qmgr(8) daemon: transport_destination_concurrency_limit ($default_destination_concur- rency_limit) A transport-specific override for the default_destination_con- currency_limit parameter value, where transport is the master.cf name of the message delivery transport. transport_destination_recipient_limit ($default_destination_recipi- ent_limit) A transport-specific override for the default_destination_recip- ient_limit parameter value, where transport is the master.cf name of the message delivery transport. d716 1 a716 1 Enable preliminary SMTPUTF8 support for the protocols described d720 1 a720 1 Detect that a message requires SMTPUTF8 support for the speci- a722 7 Available in Postfix version 3.2 and later: enable_idna2003_compatibility (no) Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII form that is used for DNS lookups. d725 1 a725 1 The increment in verbose logging level when a remote client or d729 1 a729 1 Optional list of remote client or server hostname or network d734 1 a734 1 The recipient of postmaster notifications about mail delivery d739 2 a740 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d748 1 a748 1 Where the Postfix SMTP client should deliver mail when it d752 1 a752 1 The default location of the Postfix main.cf and master.cf con- d756 1 a756 1 How much time a Postfix daemon process may take to handle a d760 1 a760 1 The maximal number of digits after the decimal point when log- d767 1 a767 1 The network interface addresses that this mail system receives d771 1 a771 1 The Internet protocols Postfix will attempt to use when making d775 1 a775 1 The time limit for sending or receiving information over an d779 2 a780 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d787 1 a787 1 The maximum amount of time that an idle Postfix daemon process d801 1 a801 1 The network interface addresses that this mail system receives d806 1 a806 1 client will try first, when a destination has IPv6 and IPv4 d810 1 a810 1 An optional numerical network address that the Postfix SMTP d814 1 a814 1 An optional numerical network address that the Postfix SMTP d834 3 a836 2 A prefix that is prepended to the process name in syslog records, so that, for example, "smtpd" becomes "prefix/smtpd". a861 10 Available with Postfix 3.2 and later: smtp_tcp_port (smtp) The default TCP port that the Postfix SMTP client connects to. Available in Postfix 3.3 and later: service_name (read-only) The master.cf service name of a Postfix daemon process. a872 1 postlogd(8), Postfix logging @ 1.1.1.11 log @Import Postfix-3.7.3 (previous version was 3.5.2) This is the Postfix 3.7 (stable) release. The stable Postfix release is called postfix-3.7.x where 3=major release number, 7=minor release number, x=patchlevel. The stable release never changes except for patches that address bugs or emergencies. Patches change the patchlevel and the release date. New features are developed in snapshot releases. These are called postfix-3.8-yyyymmdd where yyyymmdd is the release date (yyyy=year, mm=month, dd=day). Patches are never issued for snapshot releases; instead, a new snapshot is released. The mail_release_date configuration parameter (format: yyyymmdd) specifies the release date of a stable release or snapshot release. If you upgrade from Postfix 3.5 or earlier, read RELEASE_NOTES-3.6 before proceeding. License change --------------- This software is distributed with a dual license: in addition to the historical IBM Public License 1.0, it is now also distributed with the more recent Eclipse Public License 2.0. Recipients can choose to take the software under the license of their choice. Those who are more comfortable with the IPL can continue with that license. Bugfix for messages not delivered after "warning: Unexpected record type 'X' ============================================================================ Due to a bug introduced in Postfix 3.7.0, a message could falsely be flagged as corrupt with "warning: Unexpected record type 'X'". Such messages were moved to the "corrupt" queue directory, where they may still be found. See below for instructions to deal with these falsely flagged messages. This could happen for messages with 5000 or more recipients, or with fewer recipients on a busy mail server. The problem was first reported by Frank Brendel, reproduced by John Alex. A file in the "corrupt" queue directory may be inspected with the command "postcat /var/spool/postfix/corrupt/. If delivery of the file is still desired, the file can be moved back to /var/spool/postfix/incoming after updating Postfix and executing "postfix reload". Major changes - configuration ----------------------------- [Feature 20210605] Support to inline the content of small cidr:, pcre:, and regexp: tables in Postfix parameter values. Example: smtpd_forbidden_commands = CONNECT GET POST regexp:{{/^[^A-Z]/ Thrash}} This is the new smtpd_forbidden_commands default value. It will immediately disconnect a remote SMTP client when a command does not start with a letter (a-z or A-Z). The basic syntax is: /etc/postfix/main.cf: parameter = .. map-type:{ { rule-1 }, { rule-2 } .. } .. /etc/postfix/master.cf: .. -o { parameter = .. map-type:{ { rule-1 }, { rule-2 } .. } .. } .. where map-type is one of cidr, pcre, or regexp. Postfix ignores whitespace after '{' and before '}', and writes each rule as one text line to a nameless in-memory file: in-memory file: rule-1 rule-2 .. Postfix parses the result as if it is a file in /etc/postfix. Note: if a rule contains $, specify $$ to keep Postfix from trying to do $name expansion as it evaluates the parameter value. Major changes - lmdb support ---------------------------- [Feature 20210605] Overhauled the LMDB client's error handling, and added integration tests for future-proofing. There are no visible changes in documented behavior. Major changes - logging ----------------------- [Feature 20210815] To make the maillog_file feature more useful, the postlog(1) command is now set-gid postdrop, so that unprivileged programs can use it to write logging through the postlogd(8) daemon. This required hardening the postlog(1) command against privilege escalation attacks. DO NOT turn on the set-gid bit with older postlog(1) implementations. Major changes - pcre2 support ----------------------------- [Feature 20211127] Support for the pcre2 library (the legacy pcre library is no longer maintained). The Postfix build procedure automatically detects if the pcre2 library is installed, and if it is unavailable, the Postfix build procedure will detect if the legacy pcre library is installed. See PCRE_README if you need to build Postfix with a specific library. Visible differences: some error messages may have a different text, and the 'X' pattern flag is no longer supported with pcre2. Major changes - security ------------------------ [Feature 20220102] Postfix programs now randomize the initial state of in-memory hash tables, to defend against hash collision attacks involving a large number of attacker-chosen lookup keys. Presently, the only known opportunity for such attacks involves remote SMTP client IPv6 addresses in the anvil(8) service. The attack would require making hundreds of short-lived connections per second from thousands of different IP addresses, because the anvil(8) service drops inactive counters after 100s. Other in-memory hash tables with attacker-chosen lookup keys are by design limited in size. The fix is cheap, and therefore implemented for all Postfix in-memory hash tables. Problem reported by Pascal Junod. [Feature 20211030] The postqueue command now sanitizes non-printable characters (such as newlines) in strings before they are formatted as json or as legacy output. These outputs are piped into other programs that are run by administrative users. This closes a hypothetical opportunity for privilege escalation. [Feature 20210815] Updated defense against remote clients or servers that 'trickle' SMTP or LMTP traffic, based on per-request deadlines and minimum data rates. Per-request deadlines: The new {smtpd,smtp,lmtp}_per_request_deadline parameters replace {smtpd,smtp,lmtp}_per_record_deadline, with backwards compatible default settings. This defense is enabled by default in the Postfix SMTP server in case of overload. The new smtpd_per_record_deadline parameter limits the combined time for the Postfix SMTP server to receive a request and to send a response, while the new {smtp,lmtp}_per_record_deadline parameters limit the combined time for the Postfix SMTP or LMTP client to send a request and to receive a response. Minimum data rates: The new smtpd_min_data_rate parameter enforces a minimum plaintext data transfer rate for DATA and BDAT requests, but only when smtpd_per_record_deadline is enabled. After a read operation transfers N plaintext bytes (possibly after TLS decryption), and after the DATA or BDAT request deadline is decreased by the elapsed time of that read operation, the DATA or BDAT request deadline is increased by N/smtpd_min_data_rate seconds. However, the deadline is never increased beyond the smtpd_timeout value. The default minimum data rate is 500 (bytes/second) but is still subject to change. The new {smtp,lmtp}_min_data_rate parameters enforce the corresponding minimum DATA transfer rates for the Postfix SMTP and LMTP client. Major changes - tls support --------------------------- [Cleanup 20220121] The new tlsproxy_client_security_level parameter replaces tlsproxy_client_level, and the new tlsproxy_client_policy_maps parameter replaces tlsproxy_client_policy. This is for consistent parameter naming (tlsproxy_client_xxx corresponds to smtp_tls_xxx). This change was made with backwards-compatible default settings. [Feature 20210926] Postfix was updated to support OpenSSL 3.0.0 API features, and to work around OpenSSL 3.0.0 bit-rot (avoid using deprecated API features). Other code health ----------------- [typos] Typo fixes by raf. [pre-release checks] Added pre-release checks to detect a) new typos in documentation and source-code comments, b) missing entries in the postfix-files file (some documentation would not be installed), c) missing rules in the postlink script (some text would not have a hyperlink in documentation), and d) missing map-based $parameter names in the proxy_read_maps default value (the proxymap daemon would not automatically authorize some proxied maps). [memory stream] Improved support for memory-based streams made it possible to inline small cidr:, pcre:, and regexp: maps in Postfix parameter values, and to eliminate some ad-hoc code that converted tlsproxy(8) protocol data to or from serialized form. ************************************************************************* This is the Postfix 3.6 (stable) release. The stable Postfix release is called postfix-3.6.x where 3=major release number, 6=minor release number, x=patchlevel. The stable release never changes except for patches that address bugs or emergencies. Patches change the patchlevel and the release date. New features are developed in snapshot releases. These are called postfix-3.7-yyyymmdd where yyyymmdd is the release date (yyyy=year, mm=month, dd=day). Patches are never issued for snapshot releases; instead, a new snapshot is released. The mail_release_date configuration parameter (format: yyyymmdd) specifies the release date of a stable release or snapshot release. If you upgrade from Postfix 3.4 or earlier, read RELEASE_NOTES-3.5 before proceeding. License change --------------- This software is distributed with a dual license: in addition to the historical IBM Public License 1.0, it is now also distributed with the more recent Eclipse Public License 2.0. Recipients can choose to take the software under the license of their choice. Those who are more comfortable with the IPL can continue with that license. Major changes - internal protocol identification ------------------------------------------------ [Incompat 20200920] Internal protocols have changed. You need to "postfix stop" before updating, or before backing out to an earlier release, otherwise long-running daemons (pickup, qmgr, verify, tlsproxy, postscreen) may fail to communicate with the rest of Postfix, causing mail delivery delays until Postfix is restarted. This change does not affect message files in Postfix queue directories, only the communication between running Postfix programs. With this change, every Postfix internal service, including the postdrop command, announces the name of its protocol before doing any other I/O. Every Postfix client program, including the Postfix sendmail command, will verify that the protocol name matches what it is supposed to be. The purpose of this change is to produce better error messages, for example, when someone configures the discard daemon as a bounce service in master.cf, or vice versa. This change may break third-party programs that implement a Postfix-internal protocol such as qpsmtpd. Such programs have never been supported. Fortunately, this will be an easy fix: look at the first data from the cleanup daemon: if it is a protocol announcement, you're talking to Postfix 3.6 or later. That's the only real change. Major changes - tls ------------------- [Incompat 20200705] The minimum supported OpenSSL version is 1.1.1, which will reach the end of life by 2023-09-11. Postfix 3.6 is expected to reach the end of support in 2025. Until then, Postfix will be updated as needed for compatibility with OpenSSL. The default fingerprint digest has changed from md5 to sha256 (Postfix 3.6 with compatibility_level >= 3.6). With a lower compatibility_level setting, Postfix defaults to using md5, and logs a warning when a Postfix configuration specifies no explicit digest type. Export-grade Diffie-Hellman key exchange is no longer supported, and the tlsproxy_tls_dh512_param_file parameter is ignored, [Feature 20200906] The tlstype.pl helper script by Viktor Dukhovni reports TLS information per message delivery. This processes output from the collate.pl script. See auxiliary/collate/README.tlstype and auxiliary/collate/tlstype.pl. Major changes - compatibility level ----------------------------------- [Feature 20210109] Starting with Postfix version 3.6, the compatibility level is "3.6". In future Postfix releases, the compatibility level will be the Postfix version that introduced the last incompatible change. The level is formatted as 'major.minor.patch', where 'patch' is usually omitted and defaults to zero. Earlier compatibility levels are 0, 1 and 2. This also introduces main.cf and master.cf support for the <=level, " which matches an empty sender address, and the "@@domain" wildcard pattern. More information about those can be found in the postconf(5) manpage. Example: /etc/postfix/main.cf: # Allow root and postfix full control, anyone else can only # send mail as themselves. Use "uid:" followed by the numerical # UID when the UID has no entry in the UNIX password file. local_login_sender_maps = inline:{ { root = *}, { postfix = * } }, pcre:/etc/postfix/login_senders /etc/postfix/login_senders: # Allow both the bare username and the user@@domain forms. /(.+)/ $1 $1@@example.com Major changes - order of relay and recipient restrictions --------------------------------------------------------- [Incompat 20210131] With smtpd_relay_before_recipient_restrictions=yes, the Postfix SMTP server will evaluate smtpd_relay_restrictions before smtpd_recipient_restrictions. This is the default behavior with compatibility_level >= 3.6. This change makes the implemented behavior consistent with existing documentation. There is a backwards-compatibility warning that allows users to freeze historical behavior. See COMPATIBILITY_README for details. Major changes - respectful logging ---------------------------------- [Feature 20210220] Postfix version 3.6 deprecates terminology that implies white is better than black. Instead, Postfix prefers 'allowlist', 'denylist', and variations on those words. This change affects Postfix documentation, and postscreen parameters and logging. To keep the old postscreen logging set "respectful_logging = no" in main.cf. Noel Jones assisted with the initial transition. Changes in documentation ------------------------ Postfix documentation was updated to use 'allowlist', 'denylist', etc. These documentation changes do not affect Postfix behavior. Changes in parameter names -------------------------- The following postscreen parameters replace names that contain 'blacklist' or 'whitelist': postscreen_allowlist_interfaces postscreen_denylist_action postscreen_dnsbl_allowlist_threshold These new parameters have backwards-compatible default settings that support the old parameter names, so that the name change should not affect Postfix behavior. This means that existing management tools that use the old parameter names should keep working as before. This compatibility safety net may break when some management tools use the new parameter names, and some use the old names, such that different tools will disagree on how Postfix works. Changes in logging ------------------ The following logging replaces forms that contain 'blacklist' or 'whitelist': postfix/postscreen[pid]: ALLOWLIST VETO [address]:port postfix/postscreen[pid]: ALLOWLISTED [address]:port postfix/postscreen[pid]: DENYLISTED [address]:port To avoid breaking logfile analysis tools, Postfix keeps logging the old forms by default, as long as the compatibility_level parameter setting is less than 3.6, and the respectful_logging parameter is not explicitly configured. As a reminder, Postfix will log the following: postfix/postscreen[pid]: Using backwards-compatible default setting respectful_logging=no for client [address]:port To keep logging the old form, make the setting "respectful_logging = no" permanent in main.cf, for example: # postconf "respectful_logging = no" # postfix reload To stop the reminder, configure the respectful_logging parameter to "yes" or "no", or configure "compatibility_level = 3.6". Major changes - threaded bounces -------------------------------- [Feature 20201205] Support for threaded bounces. This allows mail readers to present a non-delivery, delayed delivery, or successful delivery notification in the same email thread as the original message. Unfortunately, this also makes it easy for users to mistakenly delete the whole email thread (all related messages), instead of deleting only the delivery status notification. To enable, specify "enable_threaded_bounces = yes". Other changes - smtpd_sasl_mechanism_list ----------------------------------------- [Feature 20200906] The smtpd_sasl_mechanism_list parameter (default: !external, static:rest) prevents confusing errors when a SASL backend announces EXTERNAL support which Postfix does not support. Other changes - delivery logging -------------------------------- [Incompat 20200531] Postfix delivery agents now log an explicit record when delegating delivery to a different Postfix delivery agent. For example, with "best_mx_transport = local", an SMTP delivery agent will now log when a recipient will be delivered locally. This makes the delegating delivery agent visible, where it would otherwise have remained invisible, which would complicate troubleshooting. postfix/smtp[pid]: queueid: passing to transport=local This will usually be followed by logging for an actual delivery: postfix/local[pid]: queueid: to=, relay=local, ... Other examples: the local delivery agent will log a record that it defers mailbox delivery through mailbox_transport or through fallback_transport. Other changes - error logging ----------------------------- [Incompat 20200531] Postfix programs will now log "Application error" instead of "Success" or "Unknown error: 0" when an operation fails with errno == 0, i.e., the error originates from non-kernel code. Other changes - dns lookups --------------------------- [Feature 20200509] The threadsafe resolver API (res_nxxx() calls) is now the default, not because the API is threadsafe, but because this is the API where new features are being added. To build old style, build with: make makefiles CCARGS="-DNO_RES_NCALLS..." This is the default for systems that are known not to support the threadsafe resolver API. @ text @d4 1 a4 1 d144 20 a163 20 RFC 821 (SMTP protocol) RFC 822 (ARPA Internet Text Messages) RFC 1651 (SMTP service extensions) RFC 1652 (8bit-MIME transport) RFC 1870 (Message Size Declaration) RFC 2033 (LMTP protocol) RFC 2034 (SMTP Enhanced Error Codes) RFC 2045 (MIME: Format of Internet Message Bodies) RFC 2046 (MIME: Media Types) RFC 2554 (AUTH command) RFC 2821 (SMTP protocol) RFC 2920 (SMTP Pipelining) RFC 3207 (STARTTLS command) RFC 3461 (SMTP DSN Extension) RFC 3463 (Enhanced Status Codes) RFC 4954 (AUTH command) RFC 5321 (SMTP protocol) RFC 6531 (Internationalized SMTP) RFC 6533 (Internationalized Delivery Status Notifications) RFC 7672 (SMTP security via opportunistic DANE TLS) d234 1 a234 1 commands as required by RFC 5321. d327 1 a327 1 Available in Postfix version 2.9 - 3.6: a335 2 Available in Postfix version 2.9 and later: d364 1 a364 1 info_log_address_format (external) a367 28 Available in Postfix 3.6 and later: dnssec_probe (ns:.) The DNS query type (default: "ns") and DNS query name (default: ".") that Postfix may use to determine whether DNSSEC validation is available. known_tcp_ports (lmtp=24, smtp=25, smtps=submissions=465, submis- sion=587) Optional setting that avoids lookups in the services(5) data- base. Available in Postfix version 3.7 and later: smtp_per_request_deadline (no) Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for receiving a complete SMTP response. smtp_min_data_rate (500) The minimum plaintext data transfer rate in bytes/second for DATA requests, when deadlines are enabled with smtp_per_request_deadline. header_from_format (standard) The format of the Postfix-generated From: header. d511 3 a513 3 smtp_tls_mandatory_protocols (see 'postconf -d' output) TLS protocols that the Postfix SMTP client will use with manda- tory TLS encryption. d570 1 a570 1 smtp_tls_fingerprint_digest (see 'postconf -d' output) d576 3 a578 3 smtp_tls_protocols (see postconf -d output) TLS protocols that the Postfix SMTP client will use with oppor- tunistic TLS encryption. d608 1 a608 1 Configure RFC7671 DANE TLSA digest algorithm agility. d611 1 a611 1 Enable support for RFC 6698 (DANE TLSA) DNS records that contain d635 1 a635 1 smtp_tls_dane_insecure_mx_policy (see 'postconf -d' output) d774 1 a774 1 Available in Postfix version 2.9 - 3.6: a794 13 Available in Postfix version 3.7 and later: smtp_per_request_deadline (no) Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for receiving a complete SMTP response. smtp_min_data_rate (500) The minimum plaintext data transfer rate in bytes/second for DATA requests, when deadlines are enabled with smtp_per_request_deadline. d797 1 a797 1 transport_destination_concurrency_limit ($default_destination_concur- d799 2 a800 2 A transport-specific override for the default_destination_con- currency_limit parameter value, where transport is the master.cf d803 1 a803 1 transport_destination_recipient_limit ($default_destination_recipi- d806 1 a806 1 ient_limit parameter value, where transport is the master.cf d813 2 a814 2 Enable preliminary SMTPUTF8 support for the protocols described in RFC 6531..6533. d817 1 a817 1 Detect that a message requires SMTPUTF8 support for the speci- d823 2 a824 2 Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII d829 2 a830 3 The increment in verbose logging level when a nexthop destina- tion, remote client or server name or network address matches a pattern given with the debug_peer_list parameter. d833 3 a835 4 Optional list of nexthop destination, remote client or server name or network address patterns that, if matched, cause the verbose logging level to increase by the amount specified in $debug_peer_level. d838 1 a838 1 The recipient of postmaster notifications about mail delivery d843 2 a844 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d852 1 a852 1 Where the Postfix SMTP client should deliver mail when it d856 1 a856 1 The default location of the Postfix main.cf and master.cf con- d860 1 a860 1 How much time a Postfix daemon process may take to handle a d864 1 a864 1 The maximal number of digits after the decimal point when log- d871 1 a871 1 The network interface addresses that this mail system receives d874 2 a875 2 inet_protocols (see 'postconf -d output') The Internet protocols Postfix will attempt to use when making d879 1 a879 1 The time limit for sending or receiving information over an d883 2 a884 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d891 1 a891 1 The maximum amount of time that an idle Postfix daemon process d905 1 a905 1 The network interface addresses that this mail system receives d910 1 a910 1 client will try first, when a destination has IPv6 and IPv4 d914 1 a914 1 An optional numerical network address that the Postfix SMTP d918 1 a918 1 An optional numerical network address that the Postfix SMTP d938 1 a938 1 A prefix that is prepended to the process name in syslog d956 1 a956 1 In the context of email address verification, the SMTP protocol a974 6 Available in Postfix 3.7 and later: smtp_bind_address_enforce (no) Defer delivery when the Postfix SMTP client cannot apply the smtp_bind_address or smtp_bind_address6 setting. @ 1.1.1.11.2.1 log @Pullup the following, requested by kim in ticket #518: external/ibm-public/postfix/dist/html/postfix-doc.css up to 1.1.1.1 external/ibm-public/postfix/dist/mantools/check-double-history up to 1.1.1.1 external/ibm-public/postfix/dist/mantools/check-spell-history up to 1.1.1.1 external/ibm-public/postfix/dist/mantools/check-table-proto up to 1.1.1.1 external/ibm-public/postfix/dist/proto/stop.double-history up to 1.1.1.1 external/ibm-public/postfix/dist/proto/stop.spell-history up to 1.1.1.1 external/ibm-public/postfix/dist/src/postconf/test71.ref up to 1.1.1.1 external/ibm-public/postfix/dist/src/util/mkmap_db.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap.h up to 1.2 external/ibm-public/postfix/dist/src/util/inet_addr_sizes.c up to 1.2 external/ibm-public/postfix/dist/src/util/inet_addr_sizes.h up to 1.2 external/ibm-public/postfix/dist/src/util/inet_prefix_top.c up to 1.2 external/ibm-public/postfix/dist/src/util/inet_prefix_top.h up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_cdb.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_dbm.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_fail.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_lmdb.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_open.c up to 1.2 external/ibm-public/postfix/dist/src/util/mkmap_sdbm.c up to 1.2 external/ibm-public/postfix/dist/RELEASE_NOTES-3.7 up to 1.1.1.1 external/ibm-public/postfix/dist/src/global/mkmap.h delete external/ibm-public/postfix/dist/src/global/mkmap_cdb.c delete external/ibm-public/postfix/dist/src/global/mkmap_db.c delete external/ibm-public/postfix/dist/src/global/mkmap_dbm.c delete external/ibm-public/postfix/dist/src/global/mkmap_fail.c delete external/ibm-public/postfix/dist/src/global/mkmap_lmdb.c delete external/ibm-public/postfix/dist/src/global/mkmap_open.c delete external/ibm-public/postfix/dist/src/global/mkmap_sdbm.c delete external/ibm-public/postfix/dist/HISTORY up to 1.1.1.29 external/ibm-public/postfix/dist/INSTALL up to 1.1.1.9 external/ibm-public/postfix/dist/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/RELEASE_NOTES up to 1.1.1.17 external/ibm-public/postfix/dist/WISHLIST up to 1.1.1.2 external/ibm-public/postfix/dist/makedefs up to 1.16 external/ibm-public/postfix/dist/postfix-env.sh up to 1.1.1.2 external/ibm-public/postfix/dist/README_FILES/ADDRESS_CLASS_README up to 1.1.1.2 external/ibm-public/postfix/dist/README_FILES/BASIC_CONFIGURATION_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/DEBUG_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/FORWARD_SECRECY_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/INSTALL up to 1.10 external/ibm-public/postfix/dist/README_FILES/IPV6_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/MAILLOG_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/MILTER_README up to 1.1.1.9 external/ibm-public/postfix/dist/README_FILES/MYSQL_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/PGSQL_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/QSHAPE_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/RELEASE_NOTES up to 1.1.1.17 external/ibm-public/postfix/dist/README_FILES/SASL_README up to 1.1.1.11 external/ibm-public/postfix/dist/README_FILES/SMTPD_POLICY_README up to 1.1.1.7 external/ibm-public/postfix/dist/README_FILES/SMTPD_PROXY_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/SQLITE_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/STANDARD_CONFIGURATION_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/TLS_README up to 1.14 external/ibm-public/postfix/dist/conf/aliases up to 1.1.1.5 external/ibm-public/postfix/dist/conf/main.cf up to 1.10 external/ibm-public/postfix/dist/conf/master.cf up to 1.11 external/ibm-public/postfix/dist/conf/postfix-files up to 1.9 external/ibm-public/postfix/dist/conf/postfix-script up to 1.4 external/ibm-public/postfix/dist/conf/postfix-tls-script up to 1.5 external/ibm-public/postfix/dist/conf/virtual up to 1.1.1.6 external/ibm-public/postfix/dist/html/ADDRESS_CLASS_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/ADDRESS_REWRITING_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/ADDRESS_VERIFICATION_README.html up to 1.11 external/ibm-public/postfix/dist/html/BACKSCATTER_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/BASIC_CONFIGURATION_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/BDAT_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/BUILTIN_FILTER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/CDB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/COMPATIBILITY_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/CONNECTION_CACHE_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/CONTENT_INSPECTION_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/DATABASE_README.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/DB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/DEBUG_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/DSN_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/ETRN_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/FILTER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/FORWARD_SECRECY_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/INSTALL.html up to 1.10 external/ibm-public/postfix/dist/html/IPV6_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/LDAP_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/LINUX_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/LMDB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/LOCAL_RECIPIENT_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/MAILDROP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/MAILLOG_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/MEMCACHE_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/MILTER_README.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/MULTI_INSTANCE_README.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/MYSQL_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/NFS_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/OVERVIEW.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/PACKAGE_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/PCRE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/PGSQL_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/POSTSCREEN_3_5_README.html up to 1.1.1.2 external/ibm-public/postfix/dist/html/POSTSCREEN_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/QSHAPE_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/RESTRICTION_CLASS_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/SASL_README.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/SCHEDULER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/SMTPD_ACCESS_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/SMTPD_POLICY_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/SMTPD_PROXY_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/SMTPUTF8_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/SOHO_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/SQLITE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/STANDARD_CONFIGURATION_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/STRESS_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/TLS_LEGACY_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/TLS_README.html up to 1.15 external/ibm-public/postfix/dist/html/TUNING_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/UUCP_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/VERP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/VIRTUAL_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/XCLIENT_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/XFORWARD_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/access.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/aliases.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/anvil.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/bounce.5.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/bounce.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/canonical.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/cidr_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/cleanup.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/defer.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/discard.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/dnsblog.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/error.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/flush.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/generic.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/header_checks.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/index.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/ldap_table.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/lmdb_table.5.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/lmtp.8.html up to 1.1.1.12 external/ibm-public/postfix/dist/html/local.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/mailq.1.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/makedefs.1.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/master.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/master.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/memcache_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/mysql_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/newaliases.1.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/nisplus_table.5.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/oqmgr.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/pcre_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/pgsql_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/pickup.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/pipe.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postalias.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postcat.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postconf.1.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/postconf.5.html up to 1.19 external/ibm-public/postfix/dist/html/postdrop.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postfix-manuals.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/postfix-tls.1.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/postfix-wrapper.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/postfix.1.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/postkick.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postlock.1.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/postlog.1.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/postlogd.8.html up to 1.1.1.3 external/ibm-public/postfix/dist/html/postmap.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postmulti.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/postqueue.1.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/postscreen.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/postsuper.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/posttls-finger.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/proxymap.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/qmgr.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/qmqp-sink.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/qmqp-source.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/qmqpd.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/qshape.1.html up to 1.1.1.4 external/ibm-public/postfix/dist/html/regexp_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/relocated.5.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/scache.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/sendmail.1.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/showq.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/smtp-sink.1.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/smtp-source.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/smtp.8.html up to 1.1.1.12 external/ibm-public/postfix/dist/html/smtpd.8.html up to 1.1.1.13 external/ibm-public/postfix/dist/html/socketmap_table.5.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/spawn.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/sqlite_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/tcp_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/tlsmgr.8.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/tlsproxy.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/trace.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/transport.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/trivial-rewrite.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/verify.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/virtual.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/virtual.8.html up to 1.1.1.7 external/ibm-public/postfix/dist/man/man1/postfix-tls.1 up to 1.3 external/ibm-public/postfix/dist/man/man1/postfix.1 up to 1.6 external/ibm-public/postfix/dist/man/man1/postlog.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/postqueue.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/posttls-finger.1 up to 1.5 external/ibm-public/postfix/dist/man/man5/aliases.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/cidr_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/ldap_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/mysql_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/pcre_table.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/pgsql_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/postconf.5 up to 1.19 external/ibm-public/postfix/dist/man/man5/regexp_table.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/virtual.5 up to 1.5 external/ibm-public/postfix/dist/man/man8/postscreen.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/smtp.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/smtpd.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/tlsproxy.8 up to 1.5 external/ibm-public/postfix/dist/mantools/check-double-cc up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-double-install-proto-text up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-double-proto-html up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-postfix-files up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-postlink up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/check-spell-cc up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-spell-install-proto-text up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-spell-proto-html up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/make_soho_readme up to 1.1.1.4 external/ibm-public/postfix/dist/mantools/makemanidx up to 1.1.1.4 external/ibm-public/postfix/dist/mantools/man2html up to 1.1.1.5 external/ibm-public/postfix/dist/mantools/manlint up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/manspell up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/missing-proxy-read-maps up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/postlink up to 1.1.1.13 external/ibm-public/postfix/dist/mantools/spell up to 1.1.1.3 external/ibm-public/postfix/dist/proto/ADDRESS_CLASS_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/ADDRESS_REWRITING_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/ADDRESS_VERIFICATION_README.html up to 1.11 external/ibm-public/postfix/dist/proto/BACKSCATTER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/BASIC_CONFIGURATION_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/BDAT_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/BUILTIN_FILTER_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/CDB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/COMPATIBILITY_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/CONNECTION_CACHE_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/CONTENT_INSPECTION_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/DATABASE_README.html up to 1.1.1.10 external/ibm-public/postfix/dist/proto/DB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/DEBUG_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/DSN_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/ETRN_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/FILTER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/FORWARD_SECRECY_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/INSTALL.html up to 1.10 external/ibm-public/postfix/dist/proto/IPV6_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/LDAP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/LINUX_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/LMDB_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/LOCAL_RECIPIENT_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/MAILDROP_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/MAILLOG_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/MEMCACHE_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/MILTER_README.html up to 1.1.1.9 external/ibm-public/postfix/dist/proto/MULTI_INSTANCE_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/proto/MYSQL_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/NFS_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/OVERVIEW.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/PACKAGE_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/PCRE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/PGSQL_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/POSTSCREEN_3_5_README.html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/POSTSCREEN_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/proto/QSHAPE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/RESTRICTION_CLASS_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/SASL_README.html up to 1.1.1.11 external/ibm-public/postfix/dist/proto/SCHEDULER_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/SMTPD_ACCESS_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/SMTPD_POLICY_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/proto/SMTPD_PROXY_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/SMTPUTF8_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/SQLITE_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/STANDARD_CONFIGURATION_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/STRESS_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/proto/TLS_LEGACY_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/TLS_README.html up to 1.14 external/ibm-public/postfix/dist/proto/TUNING_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/UUCP_README.html up to 1.1.1.3 external/ibm-public/postfix/dist/proto/VERP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/VIRTUAL_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/XCLIENT_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/XFORWARD_README.html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/aliases up to 1.1.1.6 external/ibm-public/postfix/dist/proto/cidr_table up to 1.1.1.6 external/ibm-public/postfix/dist/proto/ldap_table up to 1.1.1.7 external/ibm-public/postfix/dist/proto/mysql_table up to 1.1.1.8 external/ibm-public/postfix/dist/proto/pcre_table up to 1.1.1.6 external/ibm-public/postfix/dist/proto/pgsql_table up to 1.1.1.8 external/ibm-public/postfix/dist/proto/postconf.html.prolog up to 1.1.1.5 external/ibm-public/postfix/dist/proto/postconf.proto up to 1.19 external/ibm-public/postfix/dist/proto/regexp_table up to 1.1.1.6 external/ibm-public/postfix/dist/proto/stop up to 1.1.1.7 external/ibm-public/postfix/dist/proto/stop.double-cc up to 1.1.1.2 external/ibm-public/postfix/dist/proto/stop.double-proto-html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/stop.spell-cc up to 1.1.1.2 external/ibm-public/postfix/dist/proto/stop.spell-proto-html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/virtual up to 1.1.1.6 external/ibm-public/postfix/dist/src/cleanup/cleanup_map1n.c up to 1.4 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.c up to 1.5 external/ibm-public/postfix/dist/src/dns/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/dns/dns.h up to 1.6 external/ibm-public/postfix/dist/src/dns/dns_lookup.c up to 1.8 external/ibm-public/postfix/dist/src/dns/dns_rr.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_rr_eq_sa.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_sa_to_rr.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_str_resflags.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_strrecord.c up to 1.3 external/ibm-public/postfix/dist/src/dns/dns_strtype.c up to 1.2 external/ibm-public/postfix/dist/src/global/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/src/global/compat_level.c up to 1.3 external/ibm-public/postfix/dist/src/global/compat_level.h up to 1.3 external/ibm-public/postfix/dist/src/global/dict_ldap.c up to 1.5 external/ibm-public/postfix/dist/src/global/dict_memcache.c up to 1.3 external/ibm-public/postfix/dist/src/global/dict_mysql.c up to 1.4 external/ibm-public/postfix/dist/src/global/dict_pgsql.c up to 1.4 external/ibm-public/postfix/dist/src/global/dict_proxy.h up to 1.3 external/ibm-public/postfix/dist/src/global/dict_sqlite.c up to 1.4 external/ibm-public/postfix/dist/src/global/dynamicmaps.c up to 1.4 external/ibm-public/postfix/dist/src/global/header_body_checks.h up to 1.3 external/ibm-public/postfix/dist/src/global/mail_dict.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_params.h up to 1.19 external/ibm-public/postfix/dist/src/global/mail_proto.h up to 1.5 external/ibm-public/postfix/dist/src/global/mail_version.h up to 1.6 external/ibm-public/postfix/dist/src/global/map_search.c up to 1.4 external/ibm-public/postfix/dist/src/global/map_search.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/global/maps.c up to 1.4 external/ibm-public/postfix/dist/src/global/maps.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/global/mkmap_proxy.c up to 1.2 external/ibm-public/postfix/dist/src/global/namadr_list.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/global/namadr_list.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/global/smtp_stream.c up to 1.5 external/ibm-public/postfix/dist/src/global/smtp_stream.h up to 1.4 external/ibm-public/postfix/dist/src/local/local_expand.c up to 1.3 external/ibm-public/postfix/dist/src/milter/milter8.c up to 1.5 external/ibm-public/postfix/dist/src/postalias/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/postalias/postalias.c up to 1.5 external/ibm-public/postfix/dist/src/postconf/Makefile.in up to 1.1.1.11 external/ibm-public/postfix/dist/src/postconf/postconf.h up to 1.4 external/ibm-public/postfix/dist/src/postconf/postconf_dbms.c up to 1.5 external/ibm-public/postfix/dist/src/postconf/postconf_edit.c up to 1.3 external/ibm-public/postfix/dist/src/postconf/postconf_main.c up to 1.4 external/ibm-public/postfix/dist/src/postconf/postconf_master.c up to 1.8 external/ibm-public/postfix/dist/src/postconf/postconf_misc.c up to 1.3 external/ibm-public/postfix/dist/src/postconf/test58.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/postfix/postfix.c up to 1.6 external/ibm-public/postfix/dist/src/postlog/postlog.c up to 1.5 external/ibm-public/postfix/dist/src/postlogd/Makefile.in up to 1.1.1.3 external/ibm-public/postfix/dist/src/postmap/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/postmap/postmap.c up to 1.5 external/ibm-public/postfix/dist/src/postqueue/postqueue.c up to 1.5 external/ibm-public/postfix/dist/src/postscreen/postscreen.c up to 1.5 external/ibm-public/postfix/dist/src/postscreen/postscreen_smtpd.c up to 1.5 external/ibm-public/postfix/dist/src/posttls-finger/posttls-finger.c up to 1.5 external/ibm-public/postfix/dist/src/proxymap/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/showq/showq.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/src/smtp/lmtp_params.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp.c up to 1.13 external/ibm-public/postfix/dist/src/smtp/smtp.h up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_addr.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_addr.h up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_connect.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_params.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_proto.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_reuse.c up to 1.4 external/ibm-public/postfix/dist/src/smtp/smtp_session.c up to 1.5 external/ibm-public/postfix/dist/src/smtpd/Makefile.in up to 1.1.1.11 external/ibm-public/postfix/dist/src/smtpd/smtpd.c up to 1.20 external/ibm-public/postfix/dist/src/smtpd/smtpd.h up to 1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.c up to 1.6 external/ibm-public/postfix/dist/src/smtpd/smtpd_peer.c up to 1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_proxy.c up to 1.3 external/ibm-public/postfix/dist/src/smtpd/smtpd_sasl_glue.c up to 1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_server.in up to 1.1.1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_server.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/tls/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/src/tls/tls.h up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_client.c up to 1.13 external/ibm-public/postfix/dist/src/tls/tls_dane.c up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_dh.c up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_fprint.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_misc.c up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_proxy.h up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_misc.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_print.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_scan.c up to 1.4 external/ibm-public/postfix/dist/src/tls/tls_server.c up to 1.12 external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy.c up to 1.6 external/ibm-public/postfix/dist/src/util/Makefile.in up to 1.1.1.11 external/ibm-public/postfix/dist/src/util/argv.c up to 1.4 external/ibm-public/postfix/dist/src/util/argv.h up to 1.4 external/ibm-public/postfix/dist/src/util/attr.h up to 1.5 external/ibm-public/postfix/dist/src/util/clean_env.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict.h up to 1.5 external/ibm-public/postfix/dist/src/util/dict_cache.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_cdb.h up to 1.2 external/ibm-public/postfix/dist/src/util/dict_cidr.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_db.h up to 1.4 external/ibm-public/postfix/dist/src/util/dict_dbm.h up to 1.2 external/ibm-public/postfix/dist/src/util/dict_fail.h up to 1.2 external/ibm-public/postfix/dist/src/util/dict_lmdb.h up to 1.3 external/ibm-public/postfix/dist/src/util/dict_open.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_pcre.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_regexp.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_sdbm.h up to 1.2 external/ibm-public/postfix/dist/src/util/hash_fnv.c up to 1.3 external/ibm-public/postfix/dist/src/util/hash_fnv.h up to 1.3 external/ibm-public/postfix/dist/src/util/htable.c up to 1.4 external/ibm-public/postfix/dist/src/util/inet_connect.c up to 1.3 external/ibm-public/postfix/dist/src/util/make_dirs.c up to 1.2 external/ibm-public/postfix/dist/src/util/match_list.c up to 1.3 external/ibm-public/postfix/dist/src/util/mystrtok.c up to 1.4 external/ibm-public/postfix/dist/src/util/mystrtok.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/sock_addr.c up to 1.3 external/ibm-public/postfix/dist/src/util/sock_addr.h up to 1.2 external/ibm-public/postfix/dist/src/util/split_nameval.c up to 1.2 external/ibm-public/postfix/dist/src/util/stringops.h up to 1.5 external/ibm-public/postfix/dist/src/util/sys_defs.h up to 1.14 external/ibm-public/postfix/dist/src/util/unix_send_fd.c up to 1.8 external/ibm-public/postfix/dist/src/util/valid_hostname.c up to 1.3 external/ibm-public/postfix/dist/src/util/valid_hostname.h up to 1.2 external/ibm-public/postfix/dist/src/xsasl/xsasl_cyrus_server.c up to 1.4 external/ibm-public/postfix/lib/global/Makefile up to 1.10 external/ibm-public/postfix/lib/util/Makefile up to 1.11 doc/3RDPARTY (apply patch) Update Postfix to 3.8.4. @ text @a4 1 a154 1 RFC 2782 (SRV resource records) a397 15 Available in Postfix version 3.8 and later: use_srv_lookup (empty) Enables discovery for the specified service(s) using DNS SRV records. ignore_srv_lookup_error (no) When SRV record lookup fails, fall back to MX or IP address lookup as if SRV record lookup was not enabled. allow_srv_lookup_fallback (no) When SRV record lookup fails or no SRV record exists, fall back to MX or IP address lookup as if SRV record lookup was not enabled. d481 4 a484 1 The default SMTP TLS security level for the Postfix SMTP client. a574 6 tls_null_cipherlist (eNULL:!aNULL) The OpenSSL cipherlist for "NULL" grade ciphers that provide authentication without encryption. Available in in Postfix version 2.3..3.7: d581 4 d660 2 a661 2 Request that the Postfix SMTP client connects using the SUBMIS- SIONS/SMTPS protocol instead of using the STARTTLS command. a669 6 Available in Postfix version 3.2 and later: tls_eecdh_auto_curves (see 'postconf -d' output) The prioritized list of elliptic curves supported by the Postfix SMTP client and server. d676 1 a676 1 List of one or more PEM files, each holding one or more private d680 1 a680 1 Optional name to send to the remote SMTP server in the TLS d686 1 a686 1 A workaround for implementations that hang Postfix while shut- a688 16 Available in Postfix version 3.8 and later: tls_ffdhe_auto_groups (see 'postconf -d' output) The prioritized list of finite-field Diffie-Hellman ephemeral (FFDHE) key exchange groups supported by the Postfix SMTP client and server. Available in Postfix 3.9, 3.8.1, 3.7.6, 3.6.10, 3.5.20 and later: tls_config_file (default) Optional configuration file with baseline OpenSSL settings. tls_config_name (empty) The application name passed by Postfix to OpenSSL library ini- tialization functions. d690 2 a691 2 The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a d695 1 a695 1 Opportunistic mode: use TLS when a remote SMTP server announces d699 1 a699 1 Enforcement mode: require that remote SMTP servers use TLS d703 2 a704 2 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP d708 2 a709 2 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- d713 1 a713 1 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS d718 1 a718 1 The Postfix SMTP client time limit for completing a TCP connec- d722 2 a723 2 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server d735 1 a735 1 The Postfix SMTP client time limit for sending the MAIL FROM d739 1 a739 1 The Postfix SMTP client time limit for sending the SMTP RCPT TO d743 1 a743 1 The Postfix SMTP client time limit for sending the SMTP DATA d747 1 a747 1 The Postfix SMTP client time limit for sending the SMTP message d761 2 a762 2 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero d766 2 a767 2 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back d777 1 a777 1 Keep Postfix LMTP client connections open for up to $max_idle d783 1 a783 1 Permanently enable SMTP connection caching for the specified d787 1 a787 1 Temporarily enable SMTP connection caching while a destination d801 1 a801 1 Time limit for connection cache connect, send or receive opera- d807 4 a810 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d816 2 a817 2 When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero d828 3 a830 3 Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for d834 1 a834 1 The minimum plaintext data transfer rate in bytes/second for d842 1 a842 1 A transport-specific override for the default_destination_con- d849 1 a849 1 ient_limit parameter value, where transport is the master.cf d856 2 a857 2 Enable preliminary SMTPUTF8 support for the protocols described in RFC 6531, RFC 6532, and RFC 6533. d860 1 a860 1 Detect that a message requires SMTPUTF8 support for the speci- d866 2 a867 2 Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII d872 2 a873 2 The increment in verbose logging level when a nexthop destina- tion, remote client or server name or network address matches a d877 3 a879 3 Optional list of nexthop destination, remote client or server name or network address patterns that, if matched, cause the verbose logging level to increase by the amount specified in d883 1 a883 1 The recipient of postmaster notifications about mail delivery d888 2 a889 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d897 1 a897 1 Where the Postfix SMTP client should deliver mail when it d901 1 a901 1 The default location of the Postfix main.cf and master.cf con- d905 1 a905 1 How much time a Postfix daemon process may take to handle a d909 1 a909 1 The maximal number of digits after the decimal point when log- d916 2 a917 2 The local network interface addresses that this mail system receives mail on. d920 1 a920 1 The Internet protocols Postfix will attempt to use when making d924 1 a924 1 The time limit for sending or receiving information over an d928 2 a929 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d936 1 a936 1 The maximum amount of time that an idle Postfix daemon process d950 2 a951 3 The remote network interface addresses that this mail system receives mail on by way of a proxy or network address transla- tion unit. d995 2 a996 3 Optional list of relay destinations that will be used when an SMTP destination is not found, or when delivery fails due to a non-permanent error. d1001 1 a1001 1 In the context of email address verification, the SMTP protocol d1023 1 a1023 1 Defer delivery when the Postfix SMTP client cannot apply the @ 1.1.1.12 log @Import Postfix 3.8.4 (last was 3.7.3) December 22, 2023: 3.8.4/3.7.9 ============================== Security: this release adds support to defend against an email spoofing attack (SMTP smuggling) on recipients at a Postfix server. For background, see https://www.postfix.org/smtp-smuggling.html. Sites concerned about SMTP smuggling attacks should enable this feature on Internet-facing Postfix servers. For compatibility with non-standard clients, Postfix by default excludes clients in mynetworks from this countermeasure. The recommended settings are: # Optionally disconnect remote SMTP clients that send bare newlines, # but allow local clients with non-standard SMTP implementations # such as netcat, fax machines, or load balancer health checks. # smtpd_forbid_bare_newline = yes smtpd_forbid_bare_newline_exclusions = $mynetworks The smtpd_forbid_bare_newline feature is disabled by default. November 1, 2023: 3.8.3/3.7.8 ============================= Bugfix (defect introduced Postfix 2.5, date 20080104): the Postfix SMTP server was waiting for a client command instead of replying immediately, after a client certificate verification error in TLS wrappermode. Reported by Andreas Kinzler. Usability: the Postfix SMTP server (finally) attempts to log the SASL username after authentication failure. In Postfix logging, this appends ", sasl_username=xxx" after the reason for SASL authentication failure. The logging replaces an unavailable reason with "(reason unavailable)", and replaces an unavailable sasl_username with "(unavailable)". Based on code by Jozsef Kadlecsik. Compatibility bugfix (defect introduced: Postfix 2.11, date 20130405): in forward_path, the expression ${recipient_delimiter} would expand to an empty string when a recipient address had no recipient delimiter. The compatibility fix is to use a configured recipient delimiter value instead. Reported by Tod A. Sandman. September 1, 2023: 3.8.2/3.7.7 ============================== Bugfix (defect introduced: Postfix alpha, 19980207): the valid_hostname() check in the Postfix DNS client library was blocking unusual but legitimate wildcard names (*.name) in some DNS lookup results and lookup requests. Examples: name class/type result *.one.example IN CNAME *.other.example *.other.example IN A 10.0.0.1 *.other.example IN TLSA ..certificate info... Such syntax is blesed in RFC 1034 section 4.3.3. Bugfix (defect introduced: Postfix 3.0, 20140218): when an address verification probe fails during or after an opportunistic TLS handshake, don't enforce a minimum time-in-queue before falling back to plaintext. Problem reported by Serg. June 5, 2023: 3.8.1/3.7.6 ========================= Optional: harden a Postfix SMTP server against remote SMTP clients that violate RFC 2920 (or 5321) command pipelining constraints. With "smtpd_forbid_unauth_pipelining = yes", the server disconnects a client immediately, after responding with "554 5.5.0 Error: SMTP protocol synchronization" and after logging "improper command pipelining" with the unexpected remote SMTP client input. This feature is disabled by default in Postfix 3.5-3.8 to avoid breaking home-grown utilities, but it is enabled by default in Postfix 3.9. A similar feature is enabled by default in the Exim SMTP server. Optional: some OS distributions crank up TLS security to 11, and in doing so increase the number of plaintext email deliveries. This introduces basic OpenSSL configuration file support that may be used to override OS-level settings. Details are in the postconf(5) manpage under tls_config_file and tls_config_name. Bugfix (defect introduced: Postfix 1.0): the command "postconf .. name=v1 .. name=v2 .." (multiple instances of the same parameter name) created multiple main.cf name=value entries with the same parameter name. It now logs a warning and skips the earlier name(s) and value(s). Found during code maintenance. Bugfix (defect introduced: Postfix 3.3): the command "postconf -M name1/type1='name2 type2 ...'" died with a segmentation violation when the request matched multiple master.cf entries. The master.cf file was not damaged. Problem reported by SATOH Fumiyasu. Bugfix (defect introduced: Postfix 2.11): the command "postconf -M name1/type1='name2 type2 ...'" could add a service definition to master.cf that conflicted with an already existing service definition. It now replaces all existing service definitions that match the service pattern 'name1/type1' or the service name and type in 'name2 type2 ...' with a single service definition 'name2 type2 ...'. Problem reported by SATOH Fumiyasu. Bugfix (defect introduced: Postfix 3.8) the posttls-finger command could access uninitialized memory when reconnecting. This also fixes a malformed warning message when a destination contains ":service" information. Reported by Thomas Korbar. Bugfix (defect introduced: Postfix 3.2): the MySQL client could return "not found" instead of "error" (for example, resulting in a 5XX SMTP status instead of 4XX) during the time that all MySQL server connections were turned down after error. Found during code maintenance. File: global/dict_mysql.c. This was already fixed in Postfix 3.4-3.7. April 18, 2023: 3.7.5 ===================== Bugfix (problem introduced in Postfix 3.5): check_ccert_access did not handle inline map specifications. Report and fix by Sean Gallagher. Bugfix (problem introduced in Postfix 3.4): the posttls-finger command failed to detect that a connection was resumed in the case that a server did not return a certificate. Fix by Viktor Dukhovni. Workaround: OpenSSL 3.x EVP_get_cipherbyname() can return lazily-bound handles. Postfix now checks that the expected functionality will be available instead of failing later. Fix by Viktor Dukhovni. Safety: the long form "{ name = value }" in import_environment or export_environment is not documented (with spaces around the '='), but it was silently accepted, and it was stored in the process environment as the invalid form "name = value", thus not setting or overriding an entry for "name". This form is now stored as the expected "name=value". Found during code maintenance. Bugfix (problem introduced in Postfix 3.2): the MySQL client could return "not found" instead of "error" (for example, resulting in a 5XX SMTP status instead of 4XX) during the time that all MySQL server connections were turned down after error. Found during code maintenance. April 17, 2023: 3.8.0 ===================== Support to look up DNS SRV records in the Postfix SMTP/LMTP client, Based on code by Tomas Korbar (Red Hat). For example, with "use_srv_lookup = submission" and "relayhost = example.com:submission", the Postfix SMTP client will look up DNS SRV records for _submission._tcp.example.com, and will relay email through the hosts and ports that are specified with those records. TLS obsolescence: Postfix now treats the "export" and "low" cipher grade settings as "medium". The "export" and "low" grades are no longer supported in OpenSSL 1.1.1, the minimum version required in Postfix 3.6.0 and later. Also, Postfix default settings now exclude deprecated or unused ciphers (SEED, IDEA, 3DES, RC2, RC4, RC5), digest (MD5), key exchange algorithms (DH, ECDH), and public key algorithm (DSS). Attack resistance: the Postfix SMTP server can now aggregate smtpd_client_*_rate and smtpd_client_*_count statistics by network block instead of by IP address, to raise the bar against a memory exhaustion attack in the anvil(8) server; Postfix TLS support unconditionally disables TLS renegotiation in the middle of an SMTP connection, to avoid a CPU exhaustion attack. The PostgreSQL client encoding is now configurable with the "encoding" Postfix configuration file attribute. The default is "UTF8". Previously the encoding was hard-coded as "LATIN1", which is not useful in the context of SMTP. The postconf command now warns for #comment in or after a Postfix parameter value. Postfix programs do not support #comment after other text, and treat that as input. January 12, 2023: 3.7.4 ======================= Workaround: with OpenSSL 3 and later always turn on SSL_OP_IGNORE_UNEXPECTED_EOF, to avoid warning messages and missed opportunities for TLS session reuse. This is safe because the SMTP protocol implements application-level framing, and is therefore not affected by TLS truncation attacks. Fix by Viktor Dukhovni. Workaround: OpenSSL 3.x EVP_get_digestbyname() can return lazily-bound handles for digest implementations. In sufficiently hostile configurations, Postfix could mistakenly believe that a digest algorithm is available, and fail when it is not. A similar workaround may be needed for EVP_get_cipherbyname(). Fix by Viktor Dukhovni. Bugfix (bug introduced in Postfix 2.11): the checkok() macro in tls/tls_fprint.c evaluated its argument unconditionally; it should evaluate the argument only if there was no prior error. Found during code review. Bugfix (bug introduced in Postfix 2.8): postscreen died with a segmentation violation when postscreen_dnsbl_threshold < 1. It should reject such input with a fatal error instead. Discovered by Benny Pedersen. Bitrot: fixes for linker warnings from newer Darwin (MacOS) versions. Viktor Dukhovni. Portability: Linux 6 support. Added missing documentation that cidr:, pcre: and regexp: tables support inline specification only in Postfix 3.7 and later. @ text @a4 1 a154 1 RFC 2782 (SRV resource records) a397 15 Available in Postfix version 3.8 and later: use_srv_lookup (empty) Enables discovery for the specified service(s) using DNS SRV records. ignore_srv_lookup_error (no) When SRV record lookup fails, fall back to MX or IP address lookup as if SRV record lookup was not enabled. allow_srv_lookup_fallback (no) When SRV record lookup fails or no SRV record exists, fall back to MX or IP address lookup as if SRV record lookup was not enabled. d481 4 a484 1 The default SMTP TLS security level for the Postfix SMTP client. a574 6 tls_null_cipherlist (eNULL:!aNULL) The OpenSSL cipherlist for "NULL" grade ciphers that provide authentication without encryption. Available in in Postfix version 2.3..3.7: d581 4 d660 2 a661 2 Request that the Postfix SMTP client connects using the SUBMIS- SIONS/SMTPS protocol instead of using the STARTTLS command. a669 6 Available in Postfix version 3.2 and later: tls_eecdh_auto_curves (see 'postconf -d' output) The prioritized list of elliptic curves supported by the Postfix SMTP client and server. d676 1 a676 1 List of one or more PEM files, each holding one or more private d680 1 a680 1 Optional name to send to the remote SMTP server in the TLS d686 1 a686 1 A workaround for implementations that hang Postfix while shut- a688 16 Available in Postfix version 3.8 and later: tls_ffdhe_auto_groups (see 'postconf -d' output) The prioritized list of finite-field Diffie-Hellman ephemeral (FFDHE) key exchange groups supported by the Postfix SMTP client and server. Available in Postfix 3.9, 3.8.1, 3.7.6, 3.6.10, 3.5.20 and later: tls_config_file (default) Optional configuration file with baseline OpenSSL settings. tls_config_name (empty) The application name passed by Postfix to OpenSSL library ini- tialization functions. d690 2 a691 2 The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a d695 1 a695 1 Opportunistic mode: use TLS when a remote SMTP server announces d699 1 a699 1 Enforcement mode: require that remote SMTP servers use TLS d703 2 a704 2 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP d708 2 a709 2 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- d713 1 a713 1 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS d718 1 a718 1 The Postfix SMTP client time limit for completing a TCP connec- d722 2 a723 2 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server d735 1 a735 1 The Postfix SMTP client time limit for sending the MAIL FROM d739 1 a739 1 The Postfix SMTP client time limit for sending the SMTP RCPT TO d743 1 a743 1 The Postfix SMTP client time limit for sending the SMTP DATA d747 1 a747 1 The Postfix SMTP client time limit for sending the SMTP message d761 2 a762 2 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero d766 2 a767 2 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back d777 1 a777 1 Keep Postfix LMTP client connections open for up to $max_idle d783 1 a783 1 Permanently enable SMTP connection caching for the specified d787 1 a787 1 Temporarily enable SMTP connection caching while a destination d801 1 a801 1 Time limit for connection cache connect, send or receive opera- d807 4 a810 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d816 2 a817 2 When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero d828 3 a830 3 Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for d834 1 a834 1 The minimum plaintext data transfer rate in bytes/second for d842 1 a842 1 A transport-specific override for the default_destination_con- d849 1 a849 1 ient_limit parameter value, where transport is the master.cf d856 2 a857 2 Enable preliminary SMTPUTF8 support for the protocols described in RFC 6531, RFC 6532, and RFC 6533. d860 1 a860 1 Detect that a message requires SMTPUTF8 support for the speci- d866 2 a867 2 Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII d872 2 a873 2 The increment in verbose logging level when a nexthop destina- tion, remote client or server name or network address matches a d877 3 a879 3 Optional list of nexthop destination, remote client or server name or network address patterns that, if matched, cause the verbose logging level to increase by the amount specified in d883 1 a883 1 The recipient of postmaster notifications about mail delivery d888 2 a889 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d897 1 a897 1 Where the Postfix SMTP client should deliver mail when it d901 1 a901 1 The default location of the Postfix main.cf and master.cf con- d905 1 a905 1 How much time a Postfix daemon process may take to handle a d909 1 a909 1 The maximal number of digits after the decimal point when log- d916 2 a917 2 The local network interface addresses that this mail system receives mail on. d920 1 a920 1 The Internet protocols Postfix will attempt to use when making d924 1 a924 1 The time limit for sending or receiving information over an d928 2 a929 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d936 1 a936 1 The maximum amount of time that an idle Postfix daemon process d950 2 a951 3 The remote network interface addresses that this mail system receives mail on by way of a proxy or network address transla- tion unit. d995 2 a996 3 Optional list of relay destinations that will be used when an SMTP destination is not found, or when delivery fails due to a non-permanent error. d1001 1 a1001 1 In the context of email address verification, the SMTP protocol d1023 1 a1023 1 Defer delivery when the Postfix SMTP client cannot apply the @ 1.1.1.12.2.1 log @Sync with HEAD @ text @d2 1 a2 1 "https://www.w3.org/TR/html4/loose.dtd"> d10 2 a11 2 NAME smtp, lmtp - Postfix SMTP+LMTP client d13 1 a13 1 SYNOPSIS d16 1 a16 3 lmtp [generic Postfix daemon options] [flags=DORX] DESCRIPTION d21 1 a21 3 to be run from the master(8) process manager. The process name, smtp or lmtp, controls the protocol, and the names of the configuration parame- ters that will be used. d28 7 a34 2 The server lookup strategy is different for SMTP and LMTP, as described in the sections "SMTP SERVER LOOKUP" and "LMTP SERVER LOOKUP". d36 2 a37 2 After a successful mail transaction, a connection may be saved to the scache(8) connection cache server, so that it may be used by any d40 1 a40 1 By default, connection caching is enabled temporarily for destinations d44 4 a47 6 SMTP SERVER LOOKUP The Postfix SMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). Each destination is tried in the specified order. SMTP destinations have the following form: d51 3 a53 5 domainname:service Look up the mail exchangers for the specified domain, and con- nect to the specified service (default: smtp). Optionally, mail exchangers may be looked up with SRV queries instead of MX; this requires that service is given in symbolic form. d57 3 a59 3 [hostname]:service Look up the address(es) for the specified host, and connect to the specified service (default: smtp). d63 1 a63 1 [address]:service d65 2 a66 7 specified service (default: smtp). An IPv6 address must be for- matted as [ipv6:address]. LMTP SERVER LOOKUP The Postfix LMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). Each destination is tried in the specified order. d68 4 a71 1 LMTP destinations have the following form: d74 2 a75 2 Connect to the local UNIX-domain server that is bound to the specified pathname. If the process runs chrooted, an absolute a77 7 inet:domainname inet:domainname:service Look up the LMTP servers for the specified domain and service (default: lmtp). This form is supported when SRV lookups are enabled, and requires that service is in symbolic form. d80 1 a80 4 inet:hostname:service Look up the address(es) for the specified host, and connect to the specified service (default: lmtp). When SRV lookups are enabled, use the form [hostname] to force address lookups. d84 6 a89 3 inet:[address]:service Connect to the specified local or remote host and service (default: lmtp). An IPv6 address must be formatted as d92 1 a92 1 SINGLE-RECIPIENT DELIVERY d103 1 a103 1 COMMAND ATTRIBUTE SYNTAX d138 5 a142 4 SECURITY The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP or LMTP servers and to DNS servers on the network. The SMTP+LMTP client can be run chrooted at fixed low privilege. d144 1 a144 1 STANDARDS a165 1 RFC 8689 (TLS-Required message header) d167 1 a167 1 DIAGNOSTICS d175 1 a175 1 BUGS d182 5 a186 4 CONFIGURATION PARAMETERS Postfix versions 2.3 and later implement the SMTP and LMTP client with the same program, and choose the protocol and configuration parameters based on the process name, smtp or lmtp. d189 1 a189 1 eter for the equivalent LMTP feature. This document describes only d192 1 a192 1 Changes to main.cf are picked up automatically, as smtp(8) processes d196 1 a196 1 The text below provides only a parameter summary. See postconf(5) for d199 1 a199 1 COMPATIBILITY CONTROLS d217 2 a218 2 How long the Postfix SMTP client pauses before sending ".<CR><LF>" in order to work around the PIX firewall d227 1 a227 1 A list that specifies zero or more workarounds for CISCO PIX d231 1 a231 1 Lookup tables, indexed by the remote SMTP server address, with d235 1 a235 1 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO d239 1 a239 1 A mechanism to transform replies from remote SMTP servers one d251 1 a251 1 Skip SMTP servers that greet with a 4XX status code (go away, d257 2 a258 2 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO keywords (pipelining, starttls, d263 1 a263 1 A case insensitive list of EHLO keywords (pipelining, starttls, d268 3 a270 3 Optional lookup tables that perform address rewriting in the Postfix SMTP client, typically to transform a locally valid address into a globally valid address when sending mail across d276 3 a278 3 When the remote SMTP servername is a DNS CNAME, replace the servername with the result from CNAME expansion for the purpose of logging, SASL password lookup, TLS policy decisions, or TLS d284 2 a285 2 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, d290 1 a290 1 A case insensitive list of LHLO keywords (pipelining, starttls, d297 3 a299 3 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- d305 1 a305 1 Restricted header_checks(5) tables for the Postfix SMTP client. d308 1 a308 1 Restricted mime_header_checks(5) tables for the Postfix SMTP d312 1 a312 1 Restricted nested_header_checks(5) tables for the Postfix SMTP d321 1 a321 1 An optional workaround for routers that break TCP window scal- d332 4 a335 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d341 1 a341 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d352 1 a352 1 Optional filter for the smtp(8) delivery agent to change the d362 1 a362 1 When a remote destination resolves to a combination of IPv4 and d369 1 a369 1 The email address form that will be used in non-debug logging d375 1 a375 1 The DNS query type (default: "ns") and DNS query name (default: d379 1 a379 1 known_tcp_ports (lmtp=24, smtp=25, smtps=submissions=465, submis- d381 1 a381 1 Optional setting that avoids lookups in the services(5) data- d387 3 a389 3 Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for d393 1 a393 1 The minimum plaintext data transfer rate in bytes/second for d403 1 a403 1 Enables discovery for the specified service(s) using DNS SRV d407 1 a407 1 When SRV record lookup fails, fall back to MX or IP address d411 2 a412 2 When SRV record lookup fails or no SRV record exists, fall back to MX or IP address lookup as if SRV record lookup was not d415 1 a415 1 MIME PROCESSING CONTROLS d427 1 a427 1 EXTERNAL CONTENT INSPECTION CONTROLS d431 1 a431 1 Send the non-standard XFORWARD command when the Postfix SMTP d434 1 a434 1 SASL AUTHENTICATION CONTROLS d439 2 a440 2 Optional Postfix SMTP client lookup tables with one user- name:password entry per sender, remote hostname or next-hop d445 1 a445 1 list of available features depends on the SASL client implemen- d451 1 a451 1 If non-empty, a Postfix SMTP client filter for the remote SMTP d458 2 a459 2 client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from dif- d464 1 a464 1 passes through to the SASL plug-in implementation that is d468 1 a468 1 The SASL plug-in type that the Postfix SMTP client should use d474 2 a475 2 An optional table to prevent repeated SASL authentication fail- ures with the same remote SMTP server hostname, username and d479 1 a479 1 The maximal age of an smtp_sasl_auth_cache_name entry before it d483 2 a484 2 When a remote SMTP server rejects a SASL authentication request with a 535 reply code, defer mail delivery instead of returning d490 1 a490 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d493 1 a493 7 Available in Postfix version 3.9 and later: smtp_sasl_password_result_delimiter (:) The delimiter between username and password in sasl_passwd_maps lookup results. STARTTLS SUPPORT CONTROLS d622 1 a622 1 smtp_tls_protocols (see 'postconf -d' output) d677 1 a677 2 SIONS (formerly called SMTPS) protocol instead of using the STARTTLS command. d681 3 a683 3 smtp_tls_dane_insecure_mx_policy (dane) The TLS policy for MX hosts with "secure" TLSA records when the nexthop destination security level is dane, but the MX record d689 2 a690 2 The prioritized list of elliptic curves, that should be enabled in the Postfix SMTP client and server. d698 1 a698 1 List of one or more PEM files, each holding one or more private d702 1 a702 1 Optional name to send to the remote SMTP server in the TLS d708 1 a708 1 A workaround for implementations that hang Postfix while shut- d714 1 a714 1 The prioritized list of finite-field Diffie-Hellman ephemeral d724 1 a724 1 The application name passed by Postfix to OpenSSL library ini- d727 3 a729 27 Available in Postfix version 3.9 and later: smtp_tls_enable_rpk (no) Request that remote SMTP servers send an RFC7250 raw public key instead of an X.509 certificate. Available in Postfix version 3.10 and later: smtp_tlsrpt_enable (no) Enable support for RFC 8460 TLSRPT notifications. smtp_tlsrpt_socket_name (empty) The pathname of a UNIX-domain datagram socket that is managed by a local TLSRPT reporting service. smtp_tlsrpt_skip_reused_handshakes (yes) Do not report the TLSRPT status for TLS protocol handshakes that reuse a previously-negotiated TLS session (there is no new information to report). tls_required_enable (yes) Enable support for the "TLS-Required: no" message header, defined in RFC 8689. OBSOLETE STARTTLS CONTROLS The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a d733 1 a733 1 Opportunistic mode: use TLS when a remote SMTP server announces d737 1 a737 1 Enforcement mode: require that remote SMTP servers use TLS d741 2 a742 2 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP d746 2 a747 2 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- d751 1 a751 1 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS d754 1 a754 1 RESOURCE AND RATE CONTROLS d756 1 a756 1 The Postfix SMTP client time limit for completing a TCP connec- d760 2 a761 2 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server d773 1 a773 1 The Postfix SMTP client time limit for sending the MAIL FROM d777 1 a777 1 The Postfix SMTP client time limit for sending the SMTP RCPT TO d781 1 a781 1 The Postfix SMTP client time limit for sending the SMTP DATA d785 1 a785 1 The Postfix SMTP client time limit for sending the SMTP message d799 2 a800 2 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero d804 2 a805 2 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back d815 1 a815 1 Keep Postfix LMTP client connections open for up to $max_idle d821 1 a821 1 Permanently enable SMTP connection caching for the specified d825 1 a825 1 Temporarily enable SMTP connection caching while a destination d839 1 a839 1 Time limit for connection cache connect, send or receive opera- d845 4 a848 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d854 2 a855 2 When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero d866 3 a868 3 Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for d872 1 a872 1 The minimum plaintext data transfer rate in bytes/second for d880 1 a880 1 A transport-specific override for the default_destination_con- d887 1 a887 1 ient_limit parameter value, where transport is the master.cf d890 1 a890 1 SMTPUTF8 CONTROLS d894 1 a894 1 Enable preliminary SMTPUTF8 support for the protocols described d898 1 a898 1 Detect that a message requires SMTPUTF8 support for the speci- d904 2 a905 2 Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII d908 1 a908 1 TROUBLE SHOOTING CONTROLS d910 2 a911 2 The increment in verbose logging level when a nexthop destina- tion, remote client or server name or network address matches a d915 3 a917 3 Optional list of nexthop destination, remote client or server name or network address patterns that, if matched, cause the verbose logging level to increase by the amount specified in d921 1 a921 1 The recipient of postmaster notifications about mail delivery d926 2 a927 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d933 1 a933 1 MISCELLANEOUS CONTROLS d935 1 a935 1 Where the Postfix SMTP client should deliver mail when it d939 1 a939 1 The default location of the Postfix main.cf and master.cf con- d943 1 a943 1 How much time a Postfix daemon process may take to handle a d947 2 a948 2 The maximal number of digits after the decimal point when log- ging delay values. d954 1 a954 1 The local network interface addresses that this mail system d957 2 a958 2 inet_protocols (see 'postconf -d' output) The Internet protocols Postfix will attempt to use when making d962 1 a962 1 The time limit for sending or receiving information over an d966 2 a967 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d974 1 a974 1 The maximum amount of time that an idle Postfix daemon process d988 2 a989 2 The remote network interface addresses that this mail system receives mail on by way of a proxy or network address transla- d994 1 a994 1 client will try first, when a destination has IPv6 and IPv4 d998 1 a998 1 An optional numerical network address that the Postfix SMTP d1002 1 a1002 1 An optional numerical network address that the Postfix SMTP d1022 1 a1022 1 A prefix that is prepended to the process name in syslog d1034 2 a1035 2 Optional list of relay destinations that will be used when an SMTP destination is not found, or when delivery fails due to a d1041 1 a1041 1 In the context of email address verification, the SMTP protocol d1063 1 a1063 1 Defer delivery when the Postfix SMTP client cannot apply the d1066 1 a1066 1 SEE ALSO d1080 1 a1080 1 README FILES d1084 1 a1084 1 LICENSE @ 1.1.1.13 log @Import postfix-3.10.1 (previous was 3.8.4) Summary: Postfix 3.9 (July 2022): This release focused on enhancing the TLS (Transport Layer Security) capabilities of Postfix. It introduced support for TLSv1.3, allowing for more secure and efficient encrypted communications. Additionally, improvements were made to the handling of TLSA records, which are used in DNS-based Authentication of Named Entities (DANE) to associate TLS certificates with domain names. Postfix 3.10 (July 2023): This version brought significant updates to Postfix's SMTP (Simple Mail Transfer Protocol) functionalities. It added support for the SMTPUTF8 extension, enabling the use of UTF-8 encoding in email addresses and headers, which is essential for internationalization. The release also included performance optimizations, particularly in the handling of large mail queues, and introduced new configuration parameters to provide administrators with finer control over mail processing. The changes are described more in detail in: 3.10 changes: RELEASE_NOTES 3.9 changes: RELEASE_NOTES_3.9 3.8 changes: RELEASE_NOTES_3.8 @ text @d2 1 a2 1 "https://www.w3.org/TR/html4/loose.dtd"> d10 2 a11 2 NAME smtp, lmtp - Postfix SMTP+LMTP client d13 1 a13 1 SYNOPSIS d16 1 a16 3 lmtp [generic Postfix daemon options] [flags=DORX] DESCRIPTION d21 1 a21 3 to be run from the master(8) process manager. The process name, smtp or lmtp, controls the protocol, and the names of the configuration parame- ters that will be used. d28 7 a34 2 The server lookup strategy is different for SMTP and LMTP, as described in the sections "SMTP SERVER LOOKUP" and "LMTP SERVER LOOKUP". d36 2 a37 2 After a successful mail transaction, a connection may be saved to the scache(8) connection cache server, so that it may be used by any d40 1 a40 1 By default, connection caching is enabled temporarily for destinations d44 4 a47 6 SMTP SERVER LOOKUP The Postfix SMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). Each destination is tried in the specified order. SMTP destinations have the following form: d51 3 a53 5 domainname:service Look up the mail exchangers for the specified domain, and con- nect to the specified service (default: smtp). Optionally, mail exchangers may be looked up with SRV queries instead of MX; this requires that service is given in symbolic form. d57 3 a59 3 [hostname]:service Look up the address(es) for the specified host, and connect to the specified service (default: smtp). d63 1 a63 1 [address]:service d65 2 a66 7 specified service (default: smtp). An IPv6 address must be for- matted as [ipv6:address]. LMTP SERVER LOOKUP The Postfix LMTP client supports multiple destinations separated by comma or whitespace (Postfix 3.5 and later). Each destination is tried in the specified order. d68 4 a71 1 LMTP destinations have the following form: d74 2 a75 2 Connect to the local UNIX-domain server that is bound to the specified pathname. If the process runs chrooted, an absolute a77 7 inet:domainname inet:domainname:service Look up the LMTP servers for the specified domain and service (default: lmtp). This form is supported when SRV lookups are enabled, and requires that service is in symbolic form. d80 1 a80 4 inet:hostname:service Look up the address(es) for the specified host, and connect to the specified service (default: lmtp). When SRV lookups are enabled, use the form [hostname] to force address lookups. d84 6 a89 3 inet:[address]:service Connect to the specified local or remote host and service (default: lmtp). An IPv6 address must be formatted as d92 1 a92 1 SINGLE-RECIPIENT DELIVERY d103 1 a103 1 COMMAND ATTRIBUTE SYNTAX d138 5 a142 4 SECURITY The SMTP+LMTP client is moderately security-sensitive. It talks to SMTP or LMTP servers and to DNS servers on the network. The SMTP+LMTP client can be run chrooted at fixed low privilege. d144 1 a144 1 STANDARDS a165 1 RFC 8689 (TLS-Required message header) d167 1 a167 1 DIAGNOSTICS d175 1 a175 1 BUGS d182 5 a186 4 CONFIGURATION PARAMETERS Postfix versions 2.3 and later implement the SMTP and LMTP client with the same program, and choose the protocol and configuration parameters based on the process name, smtp or lmtp. d189 1 a189 1 eter for the equivalent LMTP feature. This document describes only d192 1 a192 1 Changes to main.cf are picked up automatically, as smtp(8) processes d196 1 a196 1 The text below provides only a parameter summary. See postconf(5) for d199 1 a199 1 COMPATIBILITY CONTROLS d217 2 a218 2 How long the Postfix SMTP client pauses before sending ".<CR><LF>" in order to work around the PIX firewall d227 1 a227 1 A list that specifies zero or more workarounds for CISCO PIX d231 1 a231 1 Lookup tables, indexed by the remote SMTP server address, with d235 1 a235 1 Quote addresses in Postfix SMTP client MAIL FROM and RCPT TO d239 1 a239 1 A mechanism to transform replies from remote SMTP servers one d251 1 a251 1 Skip SMTP servers that greet with a 4XX status code (go away, d257 2 a258 2 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO keywords (pipelining, starttls, d263 1 a263 1 A case insensitive list of EHLO keywords (pipelining, starttls, d268 3 a270 3 Optional lookup tables that perform address rewriting in the Postfix SMTP client, typically to transform a locally valid address into a globally valid address when sending mail across d276 3 a278 3 When the remote SMTP servername is a DNS CNAME, replace the servername with the result from CNAME expansion for the purpose of logging, SASL password lookup, TLS policy decisions, or TLS d284 2 a285 2 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO keywords (pipelining, starttls, d290 1 a290 1 A case insensitive list of LHLO keywords (pipelining, starttls, d297 3 a299 3 When authenticating to a remote SMTP or LMTP server with the default setting "no", send no SASL authoriZation ID (authzid); send only the SASL authentiCation ID (authcid) plus the auth- d305 1 a305 1 Restricted header_checks(5) tables for the Postfix SMTP client. d308 1 a308 1 Restricted mime_header_checks(5) tables for the Postfix SMTP d312 1 a312 1 Restricted nested_header_checks(5) tables for the Postfix SMTP d321 1 a321 1 An optional workaround for routers that break TCP window scal- d332 4 a335 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d341 1 a341 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d352 1 a352 1 Optional filter for the smtp(8) delivery agent to change the d362 1 a362 1 When a remote destination resolves to a combination of IPv4 and d369 1 a369 1 The email address form that will be used in non-debug logging d375 1 a375 1 The DNS query type (default: "ns") and DNS query name (default: d379 1 a379 1 known_tcp_ports (lmtp=24, smtp=25, smtps=submissions=465, submis- d381 1 a381 1 Optional setting that avoids lookups in the services(5) data- d387 3 a389 3 Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for d393 1 a393 1 The minimum plaintext data transfer rate in bytes/second for d403 1 a403 1 Enables discovery for the specified service(s) using DNS SRV d407 1 a407 1 When SRV record lookup fails, fall back to MX or IP address d411 2 a412 2 When SRV record lookup fails or no SRV record exists, fall back to MX or IP address lookup as if SRV record lookup was not d415 1 a415 1 MIME PROCESSING CONTROLS d427 1 a427 1 EXTERNAL CONTENT INSPECTION CONTROLS d431 1 a431 1 Send the non-standard XFORWARD command when the Postfix SMTP d434 1 a434 1 SASL AUTHENTICATION CONTROLS d439 2 a440 2 Optional Postfix SMTP client lookup tables with one user- name:password entry per sender, remote hostname or next-hop d445 1 a445 1 list of available features depends on the SASL client implemen- d451 1 a451 1 If non-empty, a Postfix SMTP client filter for the remote SMTP d458 2 a459 2 client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from dif- d464 1 a464 1 passes through to the SASL plug-in implementation that is d468 1 a468 1 The SASL plug-in type that the Postfix SMTP client should use d474 2 a475 2 An optional table to prevent repeated SASL authentication fail- ures with the same remote SMTP server hostname, username and d479 1 a479 1 The maximal age of an smtp_sasl_auth_cache_name entry before it d483 2 a484 2 When a remote SMTP server rejects a SASL authentication request with a 535 reply code, defer mail delivery instead of returning d490 1 a490 1 Whether or not to append the "AUTH=<>" option to the MAIL FROM d493 1 a493 7 Available in Postfix version 3.9 and later: smtp_sasl_password_result_delimiter (:) The delimiter between username and password in sasl_passwd_maps lookup results. STARTTLS SUPPORT CONTROLS d622 1 a622 1 smtp_tls_protocols (see 'postconf -d' output) d677 1 a677 2 SIONS (formerly called SMTPS) protocol instead of using the STARTTLS command. d681 3 a683 3 smtp_tls_dane_insecure_mx_policy (dane) The TLS policy for MX hosts with "secure" TLSA records when the nexthop destination security level is dane, but the MX record d689 2 a690 2 The prioritized list of elliptic curves, that should be enabled in the Postfix SMTP client and server. d698 1 a698 1 List of one or more PEM files, each holding one or more private d702 1 a702 1 Optional name to send to the remote SMTP server in the TLS d708 1 a708 1 A workaround for implementations that hang Postfix while shut- d714 1 a714 1 The prioritized list of finite-field Diffie-Hellman ephemeral d724 1 a724 1 The application name passed by Postfix to OpenSSL library ini- d727 3 a729 27 Available in Postfix version 3.9 and later: smtp_tls_enable_rpk (no) Request that remote SMTP servers send an RFC7250 raw public key instead of an X.509 certificate. Available in Postfix version 3.10 and later: smtp_tlsrpt_enable (no) Enable support for RFC 8460 TLSRPT notifications. smtp_tlsrpt_socket_name (empty) The pathname of a UNIX-domain datagram socket that is managed by a local TLSRPT reporting service. smtp_tlsrpt_skip_reused_handshakes (yes) Do not report the TLSRPT status for TLS protocol handshakes that reuse a previously-negotiated TLS session (there is no new information to report). tls_required_enable (yes) Enable support for the "TLS-Required: no" message header, defined in RFC 8689. OBSOLETE STARTTLS CONTROLS The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a d733 1 a733 1 Opportunistic mode: use TLS when a remote SMTP server announces d737 1 a737 1 Enforcement mode: require that remote SMTP servers use TLS d741 2 a742 2 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP d746 2 a747 2 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- d751 1 a751 1 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS d754 1 a754 1 RESOURCE AND RATE CONTROLS d756 1 a756 1 The Postfix SMTP client time limit for completing a TCP connec- d760 2 a761 2 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server d773 1 a773 1 The Postfix SMTP client time limit for sending the MAIL FROM d777 1 a777 1 The Postfix SMTP client time limit for sending the SMTP RCPT TO d781 1 a781 1 The Postfix SMTP client time limit for sending the SMTP DATA d785 1 a785 1 The Postfix SMTP client time limit for sending the SMTP message d799 2 a800 2 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero d804 2 a805 2 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back d815 1 a815 1 Keep Postfix LMTP client connections open for up to $max_idle d821 1 a821 1 Permanently enable SMTP connection caching for the specified d825 1 a825 1 Temporarily enable SMTP connection caching while a destination d839 1 a839 1 Time limit for connection cache connect, send or receive opera- d845 4 a848 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d854 2 a855 2 When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero d866 3 a868 3 Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for d872 1 a872 1 The minimum plaintext data transfer rate in bytes/second for d880 1 a880 1 A transport-specific override for the default_destination_con- d887 1 a887 1 ient_limit parameter value, where transport is the master.cf d890 1 a890 1 SMTPUTF8 CONTROLS d894 1 a894 1 Enable preliminary SMTPUTF8 support for the protocols described d898 1 a898 1 Detect that a message requires SMTPUTF8 support for the speci- d904 2 a905 2 Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII d908 1 a908 1 TROUBLE SHOOTING CONTROLS d910 2 a911 2 The increment in verbose logging level when a nexthop destina- tion, remote client or server name or network address matches a d915 3 a917 3 Optional list of nexthop destination, remote client or server name or network address patterns that, if matched, cause the verbose logging level to increase by the amount specified in d921 1 a921 1 The recipient of postmaster notifications about mail delivery d926 2 a927 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d933 1 a933 1 MISCELLANEOUS CONTROLS d935 1 a935 1 Where the Postfix SMTP client should deliver mail when it d939 1 a939 1 The default location of the Postfix main.cf and master.cf con- d943 1 a943 1 How much time a Postfix daemon process may take to handle a d947 2 a948 2 The maximal number of digits after the decimal point when log- ging delay values. d954 1 a954 1 The local network interface addresses that this mail system d957 2 a958 2 inet_protocols (see 'postconf -d' output) The Internet protocols Postfix will attempt to use when making d962 1 a962 1 The time limit for sending or receiving information over an d966 2 a967 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d974 1 a974 1 The maximum amount of time that an idle Postfix daemon process d988 2 a989 2 The remote network interface addresses that this mail system receives mail on by way of a proxy or network address transla- d994 1 a994 1 client will try first, when a destination has IPv6 and IPv4 d998 1 a998 1 An optional numerical network address that the Postfix SMTP d1002 1 a1002 1 An optional numerical network address that the Postfix SMTP d1022 1 a1022 1 A prefix that is prepended to the process name in syslog d1034 2 a1035 2 Optional list of relay destinations that will be used when an SMTP destination is not found, or when delivery fails due to a d1041 1 a1041 1 In the context of email address verification, the SMTP protocol d1063 1 a1063 1 Defer delivery when the Postfix SMTP client cannot apply the d1066 1 a1066 1 SEE ALSO d1080 1 a1080 1 README FILES d1084 1 a1084 1 LICENSE @ 1.1.1.13.2.1 log @Pull up the following, requested by christos in ticket #283: external/ibm-public/postfix//dist/README_FILES/NON_BERKELEYDB_README up to external/ibm-public/postfix//dist/README_FILES/REQUIRETLS_README up to external/ibm-public/postfix//dist/conf/postfix-non-bdb-script up to external/ibm-public/postfix//dist/html/NON_BERKELEYDB_README.html up to external/ibm-public/postfix//dist/html/REQUIRETLS_README.html up to external/ibm-public/postfix//dist/html/nbdb_reindexd.8.html up to external/ibm-public/postfix//dist/html/postfix-non-bdb.1.html up to external/ibm-public/postfix//dist/man/man1/postfix-non-bdb.1 up to external/ibm-public/postfix//dist/man/man8/nbdb_reindexd.8 up to external/ibm-public/postfix//dist/mantools/check-proxy-type-table up to external/ibm-public/postfix//dist/proto/NON_BERKELEYDB_README.html up to external/ibm-public/postfix//dist/proto/REQUIRETLS_README.html up to external/ibm-public/postfix//dist/src/cleanup/cleanup_message_test.c up to external/ibm-public/postfix//dist/src/global/ehlo_mask_test.c up to external/ibm-public/postfix//dist/src/global/nbdb_clnt.c up to external/ibm-public/postfix//dist/src/global/allowed_prefix.c up to external/ibm-public/postfix//dist/src/global/allowed_prefix.h up to external/ibm-public/postfix//dist/src/global/allowed_prefix_test.c up to external/ibm-public/postfix//dist/src/global/dict_sqlite_test.c up to external/ibm-public/postfix//dist/src/global/haproxy_srvr_test.c up to external/ibm-public/postfix//dist/src/global/login_sender_match_test.c up to external/ibm-public/postfix//dist/src/global/nbdb_clnt.h up to external/ibm-public/postfix//dist/src/global/nbdb_redirect.c up to external/ibm-public/postfix//dist/src/global/nbdb_redirect.h up to external/ibm-public/postfix//dist/src/global/nbdb_redirect_test.c up to external/ibm-public/postfix//dist/src/global/nbdb_surrogate.c up to external/ibm-public/postfix//dist/src/global/nbdb_surrogate.h up to external/ibm-public/postfix//dist/src/global/nbdb_surrogate_test.c up to external/ibm-public/postfix//dist/src/global/nbdb_util.c up to external/ibm-public/postfix//dist/src/global/nbdb_util.h up to external/ibm-public/postfix//dist/src/global/nbdb_util_test.c up to external/ibm-public/postfix//dist/src/global/pol_stats.c up to external/ibm-public/postfix//dist/src/global/pol_stats.h up to external/ibm-public/postfix//dist/src/global/pol_stats_test.c up to external/ibm-public/postfix//dist/src/postalias/mode_conflict_test.in up to external/ibm-public/postfix//dist/src/postalias/mode_conflict_test.ref up to external/ibm-public/postfix//dist/src/postconf/test77-main.cf up to external/ibm-public/postfix//dist/src/postconf/test77.ref up to external/ibm-public/postfix//dist/src/postconf/test78.ref up to external/ibm-public/postfix//dist/src/postconf/test79.ref up to external/ibm-public/postfix//dist/src/postconf/test80.ref up to external/ibm-public/postfix//dist/src/postconf/test81.ref up to external/ibm-public/postfix//dist/src/postconf/test82.ref up to external/ibm-public/postfix//dist/src/postconf/test83.ref up to external/ibm-public/postfix//dist/src/postconf/test84.ref up to external/ibm-public/postfix//dist/src/postconf/test85.ref up to external/ibm-public/postfix//dist/src/postconf/test86.ref up to external/ibm-public/postfix//dist/src/postconf/test87.ref up to external/ibm-public/postfix//dist/src/postconf/test91.ref up to external/ibm-public/postfix//dist/src/postmap/mode_conflict_test.in up to external/ibm-public/postfix//dist/src/postmap/mode_conflict_test.ref up to external/ibm-public/postfix//dist/src/postmulti/fake_strcmp.c up to external/ibm-public/postfix//dist/src/smtp/smtp_reqtls_policy.c up to external/ibm-public/postfix//dist/src/smtp/smtp_reqtls_policy.h up to external/ibm-public/postfix//dist/src/smtp/smtp_reqtls_policy_test.c up to external/ibm-public/postfix//dist/src/smtp/smtp_tls_policy_test.c up to external/ibm-public/postfix//dist/src/smtpd/smtpd_peer_test.c up to external/ibm-public/postfix//dist/src/util/dict_union_test.c up to external/ibm-public/postfix//dist/src/util/hash_fnv_test.c up to external/ibm-public/postfix//dist/src/util/mac_midna.h up to external/ibm-public/postfix//dist/src/util/normalize_v4mapped_addr.c up to external/ibm-public/postfix//dist/src/util/dict_debug.h up to external/ibm-public/postfix//dist/src/util/dict_debug_test.ref up to external/ibm-public/postfix//dist/src/util/dict_debug_test.sh up to external/ibm-public/postfix//dist/src/util/dict_pipe_test.c up to external/ibm-public/postfix//dist/src/util/mac_midna.c up to external/ibm-public/postfix//dist/src/util/normalize_v4mapped_addr.h up to external/ibm-public/postfix//dist/src/util/normalize_v4mapped_addr_test.c up to external/ibm-public/postfix//dist/src/util/ossl_digest.c up to external/ibm-public/postfix//dist/src/util/ossl_digest.h up to external/ibm-public/postfix//dist/src/util/ossl_digest_test.c up to external/ibm-public/postfix//dist/src/util/wrap_stat.c up to external/ibm-public/postfix//dist/src/util/wrap_stat.h up to external/ibm-public/postfix//dist/src/nbdb_reindexd/Makefile.in up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_index_as.c up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_index_as.h up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_index_as_test.c up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_process.c up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_process.h up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_process_test.c up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_reindexd.c up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_reindexd.h up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_safe.c up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_safe.h up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_safe_test.c up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_sniffer.c up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_sniffer.h up to external/ibm-public/postfix//dist/src/nbdb_reindexd/nbdb_sniffer_test.c up to external/ibm-public/postfix//dist/src/testing/Makefile.in up to external/ibm-public/postfix//dist/src/testing/dict_test_helper.c up to external/ibm-public/postfix//dist/src/testing/dict_test_helper.h up to external/ibm-public/postfix//dist/src/testing/mock_dict.c up to external/ibm-public/postfix//dist/src/testing/mock_dict.h up to external/ibm-public/postfix//dist/src/testing/mock_open_as.c up to external/ibm-public/postfix//dist/src/testing/mock_open_as.h up to external/ibm-public/postfix//dist/src/testing/mock_spawn_command.c up to external/ibm-public/postfix//dist/src/testing/mock_spawn_command.h up to external/ibm-public/postfix//dist/src/testing/mock_stat.c up to external/ibm-public/postfix//dist/src/testing/mock_stat.h up to external/ibm-public/postfix//dist/src/testing/msg_capture.c up to external/ibm-public/postfix//dist/src/testing/msg_capture.h up to external/ibm-public/postfix//dist/src/testing/nosleep.c up to external/ibm-public/postfix//dist/TESTING up to external/ibm-public/postfix//dist/RELEASE_NOTES-3.10 up to external/ibm-public/postfix//dist/src/global/ehlo_mask.in delete external/ibm-public/postfix//dist/src/global/ehlo_mask.ref delete external/ibm-public/postfix//dist/src/util/dict_pipe_test.in delete external/ibm-public/postfix//dist/src/util/dict_pipe_test.ref delete external/ibm-public/postfix//dist/src/util/dict_union_test.in delete external/ibm-public/postfix//dist/src/util/dict_union_test.ref delete external/ibm-public/postfix/Makefile.inc up to 1.32 external/ibm-public/postfix/dist/HISTORY up to 1.1.1.31 external/ibm-public/postfix/dist/INSTALL up to 1.1.1.11 external/ibm-public/postfix/dist/Makefile.in up to 1.1.1.12 external/ibm-public/postfix/dist/RELEASE_NOTES up to 1.1.1.19 external/ibm-public/postfix/dist/makedefs up to 1.18 external/ibm-public/postfix/dist/README_FILES/AAAREADME up to 1.1.1.8 external/ibm-public/postfix/dist/README_FILES/CDB_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/COMPATIBILITY_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/DATABASE_README up to 1.1.1.11 external/ibm-public/postfix/dist/README_FILES/DEPRECATION_README up to 1.1.1.2 external/ibm-public/postfix/dist/README_FILES/INSTALL up to 1.12 external/ibm-public/postfix/dist/README_FILES/MULTI_INSTANCE_README up to 1.1.1.8 external/ibm-public/postfix/dist/README_FILES/MYSQL_README up to 1.1.1.7 external/ibm-public/postfix/dist/README_FILES/OVERVIEW up to 1.1.1.7 external/ibm-public/postfix/dist/README_FILES/RELEASE_NOTES up to 1.1.1.19 external/ibm-public/postfix/dist/README_FILES/SASL_README up to 1.1.1.13 external/ibm-public/postfix/dist/README_FILES/SMTPUTF8_README up to 1.1.1.5 external/ibm-public/postfix/dist/README_FILES/SOHO_README up to 1.1.1.6 external/ibm-public/postfix/dist/README_FILES/STANDARD_CONFIGURATION_README up to 1.1.1.8 external/ibm-public/postfix/dist/README_FILES/TLSRPT_README up to 1.1.1.2 external/ibm-public/postfix/dist/README_FILES/UUCP_README up to 1.1.1.3 external/ibm-public/postfix/dist/README_FILES/VIRTUAL_README up to 1.1.1.4 external/ibm-public/postfix/dist/README_FILES/XCLIENT_README up to 1.1.1.5 external/ibm-public/postfix/dist/conf/access up to 1.1.1.10 external/ibm-public/postfix/dist/conf/aliases up to 1.1.1.7 external/ibm-public/postfix/dist/conf/canonical up to 1.1.1.7 external/ibm-public/postfix/dist/conf/generic up to 1.1.1.6 external/ibm-public/postfix/dist/conf/main.cf up to 1.12 external/ibm-public/postfix/dist/conf/postfix-files up to 1.11 external/ibm-public/postfix/dist/conf/postfix-script up to 1.6 external/ibm-public/postfix/dist/conf/postfix-tls-script up to 1.6 external/ibm-public/postfix/dist/conf/relocated up to 1.1.1.5 external/ibm-public/postfix/dist/conf/transport up to 1.1.1.6 external/ibm-public/postfix/dist/conf/virtual up to 1.1.1.8 external/ibm-public/postfix/dist/html/CDB_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/COMPATIBILITY_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/DATABASE_README.html up to 1.1.1.12 external/ibm-public/postfix/dist/html/DEPRECATION_README.html up to 1.1.1.2 external/ibm-public/postfix/dist/html/INSTALL.html up to 1.12 external/ibm-public/postfix/dist/html/MULTI_INSTANCE_README.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/MYSQL_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/Makefile.in up to 1.1.1.9 external/ibm-public/postfix/dist/html/OVERVIEW.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/SASL_README.html up to 1.1.1.13 external/ibm-public/postfix/dist/html/SMTPUTF8_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/SOHO_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/STANDARD_CONFIGURATION_README.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/TLSRPT_README.html up to 1.1.1.2 external/ibm-public/postfix/dist/html/UUCP_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/VIRTUAL_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/XCLIENT_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/access.5.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/aliases.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/bounce.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/canonical.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/cidr_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/cleanup.8.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/defer.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/discard.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/error.8.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/generic.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/index.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/ldap_table.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/lmdb_table.5.html up to 1.1.1.6 external/ibm-public/postfix/dist/html/lmtp.8.html up to 1.1.1.14 external/ibm-public/postfix/dist/html/mailq.1.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/makedefs.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/memcache_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/mongodb_table.5.html up to 1.1.1.2 external/ibm-public/postfix/dist/html/mysql_table.5.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/newaliases.1.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/nisplus_table.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/oqmgr.8.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/pcre_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/pgsql_table.5.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/postalias.1.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/postconf.1.html up to 1.1.1.13 external/ibm-public/postfix/dist/html/postconf.5.html up to 1.22 external/ibm-public/postfix/dist/html/postdrop.1.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/postfix-manuals.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/postfix-tls.1.html up to 1.1.1.5 external/ibm-public/postfix/dist/html/postfix.1.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/postlog.1.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/postmap.1.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/postmulti.1.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/postqueue.1.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/postscreen.8.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/posttls-finger.1.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/proxymap.8.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/qmgr.8.html up to 1.1.1.11 external/ibm-public/postfix/dist/html/regexp_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/relocated.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/sendmail.1.html up to 1.1.1.10 external/ibm-public/postfix/dist/html/smtp.8.html up to 1.1.1.14 external/ibm-public/postfix/dist/html/smtpd.8.html up to 1.1.1.15 external/ibm-public/postfix/dist/html/socketmap_table.5.html up to 1.1.1.7 external/ibm-public/postfix/dist/html/sqlite_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/tcp_table.5.html up to 1.1.1.8 external/ibm-public/postfix/dist/html/trace.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/transport.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/virtual.5.html up to 1.1.1.9 external/ibm-public/postfix/dist/html/virtual.8.html up to 1.1.1.9 external/ibm-public/postfix/dist/man/Makefile.in up to 1.1.1.9 external/ibm-public/postfix/dist/man/man1/makedefs.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/postalias.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/postconf.1 up to 1.6 external/ibm-public/postfix/dist/man/man1/postdrop.1 up to 1.6 external/ibm-public/postfix/dist/man/man1/postfix-tls.1 up to 1.4 external/ibm-public/postfix/dist/man/man1/postfix.1 up to 1.8 external/ibm-public/postfix/dist/man/man1/postlog.1 up to 1.7 external/ibm-public/postfix/dist/man/man1/postmap.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/postmulti.1 up to 1.5 external/ibm-public/postfix/dist/man/man1/postqueue.1 up to 1.6 external/ibm-public/postfix/dist/man/man1/posttls-finger.1 up to 1.7 external/ibm-public/postfix/dist/man/man1/sendmail.1 up to 1.6 external/ibm-public/postfix/dist/man/man5/access.5 up to 1.6 external/ibm-public/postfix/dist/man/man5/aliases.5 up to 1.7 external/ibm-public/postfix/dist/man/man5/canonical.5 up to 1.6 external/ibm-public/postfix/dist/man/man5/cidr_table.5 up to 1.7 external/ibm-public/postfix/dist/man/man5/generic.5 up to 1.6 external/ibm-public/postfix/dist/man/man5/ldap_table.5 up to 1.7 external/ibm-public/postfix/dist/man/man5/lmdb_table.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/memcache_table.5 up to 1.3 external/ibm-public/postfix/dist/man/man5/mongodb_table.5 up to 1.3 external/ibm-public/postfix/dist/man/man5/mysql_table.5 up to 1.7 external/ibm-public/postfix/dist/man/man5/nisplus_table.5 up to 1.3 external/ibm-public/postfix/dist/man/man5/pcre_table.5 up to 1.6 external/ibm-public/postfix/dist/man/man5/pgsql_table.5 up to 1.7 external/ibm-public/postfix/dist/man/man5/postconf.5 up to 1.21 external/ibm-public/postfix/dist/man/man5/regexp_table.5 up to 1.6 external/ibm-public/postfix/dist/man/man5/relocated.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/socketmap_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/sqlite_table.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/tcp_table.5 up to 1.4 external/ibm-public/postfix/dist/man/man5/transport.5 up to 1.5 external/ibm-public/postfix/dist/man/man5/virtual.5 up to 1.7 external/ibm-public/postfix/dist/man/man8/bounce.8 up to 1.6 external/ibm-public/postfix/dist/man/man8/cleanup.8 up to 1.6 external/ibm-public/postfix/dist/man/man8/discard.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/error.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/oqmgr.8 up to 1.4 external/ibm-public/postfix/dist/man/man8/postscreen.8 up to 1.7 external/ibm-public/postfix/dist/man/man8/proxymap.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/qmgr.8 up to 1.5 external/ibm-public/postfix/dist/man/man8/smtp.8 up to 1.7 external/ibm-public/postfix/dist/man/man8/smtpd.8 up to 1.7 external/ibm-public/postfix/dist/man/man8/virtual.8 up to 1.5 external/ibm-public/postfix/dist/mantools/check-postconf-unimplemented up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-spell-history up to 1.1.1.2 external/ibm-public/postfix/dist/mantools/check-spell-proto-html up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/dehtml up to 1.1.1.3 external/ibm-public/postfix/dist/mantools/postconf2man up to 1.1.1.7 external/ibm-public/postfix/dist/mantools/postlink up to 1.1.1.15 external/ibm-public/postfix/dist/mantools/srctoman up to 1.1.1.5 external/ibm-public/postfix/dist/proto/CDB_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/COMPATIBILITY_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/DATABASE_README.html up to 1.1.1.12 external/ibm-public/postfix/dist/proto/DEPRECATION_README.html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/INSTALL.html up to 1.12 external/ibm-public/postfix/dist/proto/MULTI_INSTANCE_README.html up to 1.1.1.10 external/ibm-public/postfix/dist/proto/MYSQL_README.html up to 1.1.1.7 external/ibm-public/postfix/dist/proto/Makefile.in up to 1.1.1.9 external/ibm-public/postfix/dist/proto/OVERVIEW.html up to 1.1.1.8 external/ibm-public/postfix/dist/proto/SASL_README.html up to 1.1.1.13 external/ibm-public/postfix/dist/proto/SMTPUTF8_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/STANDARD_CONFIGURATION_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/proto/TLSRPT_README.html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/UUCP_README.html up to 1.1.1.5 external/ibm-public/postfix/dist/proto/VIRTUAL_README.html up to 1.1.1.6 external/ibm-public/postfix/dist/proto/XCLIENT_README.html up to 1.1.1.8 external/ibm-public/postfix/dist/proto/access up to 1.1.1.10 external/ibm-public/postfix/dist/proto/aliases up to 1.1.1.8 external/ibm-public/postfix/dist/proto/canonical up to 1.1.1.7 external/ibm-public/postfix/dist/proto/cidr_table up to 1.1.1.8 external/ibm-public/postfix/dist/proto/generic up to 1.1.1.6 external/ibm-public/postfix/dist/proto/index.html up to 1.1.1.2 external/ibm-public/postfix/dist/proto/ldap_table up to 1.1.1.9 external/ibm-public/postfix/dist/proto/lmdb_table up to 1.1.1.4 external/ibm-public/postfix/dist/proto/memcache_table up to 1.1.1.5 external/ibm-public/postfix/dist/proto/mongodb_table up to 1.1.1.2 external/ibm-public/postfix/dist/proto/mysql_table up to 1.1.1.10 external/ibm-public/postfix/dist/proto/nisplus_table up to 1.1.1.4 external/ibm-public/postfix/dist/proto/pcre_table up to 1.1.1.8 external/ibm-public/postfix/dist/proto/pgsql_table up to 1.1.1.10 external/ibm-public/postfix/dist/proto/postconf.html.prolog up to 1.1.1.7 external/ibm-public/postfix/dist/proto/postconf.man.prolog up to 1.1.1.5 external/ibm-public/postfix/dist/proto/postconf.proto up to 1.21 external/ibm-public/postfix/dist/proto/regexp_table up to 1.1.1.8 external/ibm-public/postfix/dist/proto/relocated up to 1.1.1.5 external/ibm-public/postfix/dist/proto/socketmap_table up to 1.1.1.5 external/ibm-public/postfix/dist/proto/sqlite_table up to 1.1.1.6 external/ibm-public/postfix/dist/proto/stop up to 1.1.1.9 external/ibm-public/postfix/dist/proto/stop.double-cc up to 1.1.1.4 external/ibm-public/postfix/dist/proto/stop.double-history up to 1.1.1.3 external/ibm-public/postfix/dist/proto/stop.double-install-proto-text up to 1.1.1.3 external/ibm-public/postfix/dist/proto/stop.double-proto-html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/stop.spell-cc up to 1.1.1.4 external/ibm-public/postfix/dist/proto/stop.spell-history up to 1.1.1.3 external/ibm-public/postfix/dist/proto/stop.spell-proto-html up to 1.1.1.4 external/ibm-public/postfix/dist/proto/tcp_table up to 1.1.1.5 external/ibm-public/postfix/dist/proto/transport up to 1.1.1.6 external/ibm-public/postfix/dist/proto/virtual up to 1.1.1.8 external/ibm-public/postfix/dist/src/bounce/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/bounce/bounce.c up to 1.6 external/ibm-public/postfix/dist/src/bounce/bounce_notify_service.c up to 1.4 external/ibm-public/postfix/dist/src/bounce/bounce_notify_util.c up to 1.6 external/ibm-public/postfix/dist/src/bounce/bounce_notify_verp.c up to 1.4 external/ibm-public/postfix/dist/src/bounce/bounce_one_service.c up to 1.4 external/ibm-public/postfix/dist/src/bounce/bounce_trace_service.c up to 1.4 external/ibm-public/postfix/dist/src/bounce/bounce_warn_service.c up to 1.4 external/ibm-public/postfix/dist/src/cleanup/Makefile.in up to 1.1.1.11 external/ibm-public/postfix/dist/src/cleanup/cleanup.c up to 1.10 external/ibm-public/postfix/dist/src/cleanup/cleanup.h up to 1.12 external/ibm-public/postfix/dist/src/cleanup/cleanup_api.c up to 1.6 external/ibm-public/postfix/dist/src/cleanup/cleanup_bounce.c up to 1.4 external/ibm-public/postfix/dist/src/cleanup/cleanup_init.c up to 1.9 external/ibm-public/postfix/dist/src/cleanup/cleanup_message.c up to 1.6 external/ibm-public/postfix/dist/src/cleanup/cleanup_milter.c up to 1.7 external/ibm-public/postfix/dist/src/cleanup/cleanup_out_recipient.c up to 1.6 external/ibm-public/postfix/dist/src/cleanup/cleanup_state.c up to 1.6 external/ibm-public/postfix/dist/src/discard/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/discard/discard.c up to 1.4 external/ibm-public/postfix/dist/src/dns/dns.h up to 1.8 external/ibm-public/postfix/dist/src/dns/dns_lookup.c up to 1.10 external/ibm-public/postfix/dist/src/error/Makefile.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/error/error.c up to 1.4 external/ibm-public/postfix/dist/src/global/Makefile.in up to 1.1.1.12 external/ibm-public/postfix/dist/src/global/abounce.c up to 1.5 external/ibm-public/postfix/dist/src/global/ascii_header_text.c up to 1.3 external/ibm-public/postfix/dist/src/global/ascii_header_text.h up to 1.3 external/ibm-public/postfix/dist/src/global/bounce.c up to 1.5 external/ibm-public/postfix/dist/src/global/bounce.h up to 1.3 external/ibm-public/postfix/dist/src/global/cleanup_strflags.c up to 1.3 external/ibm-public/postfix/dist/src/global/cleanup_user.h up to 1.5 external/ibm-public/postfix/dist/src/global/config_known_tcp_ports.c up to 1.3 external/ibm-public/postfix/dist/src/global/data_redirect.c up to 1.3 external/ibm-public/postfix/dist/src/global/defer.c up to 1.5 external/ibm-public/postfix/dist/src/global/defer.h up to 1.3 external/ibm-public/postfix/dist/src/global/deliver_pass.c up to 1.5 external/ibm-public/postfix/dist/src/global/dict_ldap.c up to 1.7 external/ibm-public/postfix/dist/src/global/dict_memcache.c up to 1.4 external/ibm-public/postfix/dist/src/global/dict_mongodb.c up to 1.3 external/ibm-public/postfix/dist/src/global/dict_mysql.c up to 1.6 external/ibm-public/postfix/dist/src/global/dict_pgsql.c up to 1.6 external/ibm-public/postfix/dist/src/global/dict_proxy.c up to 1.4 external/ibm-public/postfix/dist/src/global/dict_sqlite.c up to 1.6 external/ibm-public/postfix/dist/src/global/dict_sqlite.h up to 1.2 external/ibm-public/postfix/dist/src/global/dsn_util.c up to 1.2 external/ibm-public/postfix/dist/src/global/ehlo_mask.c up to 1.4 external/ibm-public/postfix/dist/src/global/ehlo_mask.h up to 1.4 external/ibm-public/postfix/dist/src/global/haproxy_srvr.c up to 1.5 external/ibm-public/postfix/dist/src/global/haproxy_srvr.h up to 1.3 external/ibm-public/postfix/dist/src/global/header_opts.c up to 1.4 external/ibm-public/postfix/dist/src/global/header_opts.h up to 1.4 external/ibm-public/postfix/dist/src/global/log_adhoc.c up to 1.4 external/ibm-public/postfix/dist/src/global/log_adhoc.h up to 1.2 external/ibm-public/postfix/dist/src/global/login_sender_match.c up to 1.3 external/ibm-public/postfix/dist/src/global/mail_conf.c up to 1.5 external/ibm-public/postfix/dist/src/global/mail_conf.h up to 1.4 external/ibm-public/postfix/dist/src/global/mail_params.c up to 1.7 external/ibm-public/postfix/dist/src/global/mail_params.h up to 1.21 external/ibm-public/postfix/dist/src/global/mail_proto.h up to 1.7 external/ibm-public/postfix/dist/src/global/mail_version.h up to 1.8 external/ibm-public/postfix/dist/src/global/maps.c up to 1.6 external/ibm-public/postfix/dist/src/global/mime_garb3.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/global/mime_state.c up to 1.4 external/ibm-public/postfix/dist/src/global/mime_state.h up to 1.2 external/ibm-public/postfix/dist/src/global/mynetworks.c up to 1.3 external/ibm-public/postfix/dist/src/global/namadr_list.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/global/namadr_list.ref up to 1.1.1.6 external/ibm-public/postfix/dist/src/global/own_inet_addr.c up to 1.3 external/ibm-public/postfix/dist/src/global/pipe_command.c up to 1.3 external/ibm-public/postfix/dist/src/global/post_mail.c up to 1.6 external/ibm-public/postfix/dist/src/global/rec_type.h up to 1.5 external/ibm-public/postfix/dist/src/global/reject_deliver_request.c up to 1.3 external/ibm-public/postfix/dist/src/global/rfc2047_code.c up to 1.3 external/ibm-public/postfix/dist/src/global/rfc2047_code.h up to 1.3 external/ibm-public/postfix/dist/src/global/sendopts.c up to 1.3 external/ibm-public/postfix/dist/src/global/sent.c up to 1.4 external/ibm-public/postfix/dist/src/global/sent.h up to 1.3 external/ibm-public/postfix/dist/src/global/server_acl.c up to 1.5 external/ibm-public/postfix/dist/src/global/trace.c up to 1.4 external/ibm-public/postfix/dist/src/global/trace.h up to 1.2 external/ibm-public/postfix/dist/src/global/verify.c up to 1.5 external/ibm-public/postfix/dist/src/global/verify.h up to 1.2 external/ibm-public/postfix/dist/src/local/Makefile.in up to 1.1.1.10 external/ibm-public/postfix/dist/src/local/forward.c up to 1.6 external/ibm-public/postfix/dist/src/local/local.c up to 1.6 external/ibm-public/postfix/dist/src/local/local.h up to 1.4 external/ibm-public/postfix/dist/src/master/Makefile.in up to 1.1.1.9 external/ibm-public/postfix/dist/src/master/event_server.c up to 1.5 external/ibm-public/postfix/dist/src/master/multi_server.c up to 1.5 external/ibm-public/postfix/dist/src/milter/milter8.c up to 1.7 external/ibm-public/postfix/dist/src/milter/test-milter.c up to 1.5 external/ibm-public/postfix/dist/src/oqmgr/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/oqmgr/qmgr.c up to 1.4 external/ibm-public/postfix/dist/src/oqmgr/qmgr_bounce.c up to 1.2 external/ibm-public/postfix/dist/src/oqmgr/qmgr_defer.c up to 1.2 external/ibm-public/postfix/dist/src/oqmgr/qmgr_message.c up to 1.6 external/ibm-public/postfix/dist/src/pipe/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/pipe/pipe.c up to 1.6 external/ibm-public/postfix/dist/src/postalias/Makefile.in up to 1.1.1.8 external/ibm-public/postfix/dist/src/postalias/postalias.c up to 1.7 external/ibm-public/postfix/dist/src/postcat/postcat.c up to 1.6 external/ibm-public/postfix/dist/src/postconf/Makefile.in up to 1.1.1.13 external/ibm-public/postfix/dist/src/postconf/extract.awk up to 1.1.1.7 external/ibm-public/postfix/dist/src/postconf/postconf.c up to 1.6 external/ibm-public/postfix/dist/src/postconf/postconf.h up to 1.6 external/ibm-public/postfix/dist/src/postconf/postconf_builtin.c up to 1.5 external/ibm-public/postfix/dist/src/postconf/postconf_dbms.c up to 1.7 external/ibm-public/postfix/dist/src/postconf/postconf_edit.c up to 1.4 external/ibm-public/postfix/dist/src/postconf/postconf_lookup.c up to 1.5 external/ibm-public/postfix/dist/src/postconf/postconf_main.c up to 1.5 external/ibm-public/postfix/dist/src/postconf/postconf_master.c up to 1.9 external/ibm-public/postfix/dist/src/postconf/postconf_unused.c up to 1.3 external/ibm-public/postfix/dist/src/postconf/postconf_user.c up to 1.6 external/ibm-public/postfix/dist/src/postconf/test18.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test2.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test28.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/postconf/test29.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/postconf/test57.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postconf/test59.ref up to 1.1.1.4 external/ibm-public/postfix/dist/src/postconf/test67.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/postconf/test76.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/postdrop/postdrop.c up to 1.6 external/ibm-public/postfix/dist/src/postfix/postfix.c up to 1.8 external/ibm-public/postfix/dist/src/postlog/postlog.c up to 1.7 external/ibm-public/postfix/dist/src/postmap/Makefile.in up to 1.1.1.9 external/ibm-public/postfix/dist/src/postmap/postmap.c up to 1.7 external/ibm-public/postfix/dist/src/postmulti/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/postmulti/postmulti.c up to 1.5 external/ibm-public/postfix/dist/src/postqueue/postqueue.c up to 1.6 external/ibm-public/postfix/dist/src/postqueue/showq_compat.c up to 1.5 external/ibm-public/postfix/dist/src/postqueue/showq_json.c up to 1.6 external/ibm-public/postfix/dist/src/postscreen/postscreen.c up to 1.7 external/ibm-public/postfix/dist/src/postscreen/postscreen_endpt.c up to 1.6 external/ibm-public/postfix/dist/src/posttls-finger/posttls-finger.c up to 1.7 external/ibm-public/postfix/dist/src/proxymap/Makefile.in up to 1.1.1.8 external/ibm-public/postfix/dist/src/proxymap/proxymap.c up to 1.6 external/ibm-public/postfix/dist/src/qmgr/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/qmgr/qmgr.c up to 1.5 external/ibm-public/postfix/dist/src/qmgr/qmgr_bounce.c up to 1.2 external/ibm-public/postfix/dist/src/qmgr/qmgr_defer.c up to 1.2 external/ibm-public/postfix/dist/src/qmgr/qmgr_message.c up to 1.6 external/ibm-public/postfix/dist/src/sendmail/Makefile.in up to 1.1.1.6 external/ibm-public/postfix/dist/src/sendmail/sendmail.c up to 1.6 external/ibm-public/postfix/dist/src/showq/showq.c up to 1.6 external/ibm-public/postfix/dist/src/smtp/Makefile.in up to 1.1.1.12 external/ibm-public/postfix/dist/src/smtp/lmtp_params.c up to 1.7 external/ibm-public/postfix/dist/src/smtp/smtp.c up to 1.15 external/ibm-public/postfix/dist/src/smtp/smtp.h up to 1.7 external/ibm-public/postfix/dist/src/smtp/smtp_connect.c up to 1.7 external/ibm-public/postfix/dist/src/smtp/smtp_key.c up to 1.4 external/ibm-public/postfix/dist/src/smtp/smtp_params.c up to 1.7 external/ibm-public/postfix/dist/src/smtp/smtp_proto.c up to 1.7 external/ibm-public/postfix/dist/src/smtp/smtp_rcpt.c up to 1.4 external/ibm-public/postfix/dist/src/smtp/smtp_state.c up to 1.5 external/ibm-public/postfix/dist/src/smtp/smtp_tls_policy.c up to 1.6 external/ibm-public/postfix/dist/src/smtp/smtp_tlsrpt.c up to 1.3 external/ibm-public/postfix/dist/src/smtp/smtp_trouble.c up to 1.4 external/ibm-public/postfix/dist/src/smtpd/Makefile.in up to 1.1.1.13 external/ibm-public/postfix/dist/src/smtpd/smtpd.c up to 1.22 external/ibm-public/postfix/dist/src/smtpd/smtpd.h up to 1.7 external/ibm-public/postfix/dist/src/smtpd/smtpd_chat.c up to 1.5 external/ibm-public/postfix/dist/src/smtpd/smtpd_check.c up to 1.8 external/ibm-public/postfix/dist/src/smtpd/smtpd_haproxy.c up to 1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_peer.c up to 1.6 external/ibm-public/postfix/dist/src/smtpd/smtpd_proxy.c up to 1.4 external/ibm-public/postfix/dist/src/smtpd/smtpd_proxy.h up to 1.2 external/ibm-public/postfix/dist/src/tls/Makefile.in up to 1.1.1.12 external/ibm-public/postfix/dist/src/tls/tls.h up to 1.7 external/ibm-public/postfix/dist/src/tls/tls_client.c up to 1.15 external/ibm-public/postfix/dist/src/tls/tls_dane.c up to 1.7 external/ibm-public/postfix/dist/src/tls/tls_dane.sh up to 1.1.1.2 external/ibm-public/postfix/dist/src/tls/tls_dh.c up to 1.7 external/ibm-public/postfix/dist/src/tls/tls_misc.c up to 1.7 external/ibm-public/postfix/dist/src/tls/tls_prng_file.c up to 1.3 external/ibm-public/postfix/dist/src/tls/tls_proxy.h up to 1.6 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_misc.c up to 1.5 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_print.c up to 1.6 external/ibm-public/postfix/dist/src/tls/tls_proxy_client_scan.c up to 1.6 external/ibm-public/postfix/dist/src/tls/tls_server.c up to 1.14 external/ibm-public/postfix/dist/src/tls/tls_verify.c up to 1.6 external/ibm-public/postfix/dist/src/tls/tlsrpt_wrapper.c up to 1.3 external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy.c up to 1.8 external/ibm-public/postfix/dist/src/tlsproxy/tlsproxy_state.c up to 1.4 external/ibm-public/postfix/dist/src/trivial-rewrite/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/trivial-rewrite/resolve.c up to 1.6 external/ibm-public/postfix/dist/src/trivial-rewrite/trivial-rewrite.c up to 1.6 external/ibm-public/postfix/dist/src/util/Makefile.in up to 1.1.1.13 external/ibm-public/postfix/dist/src/util/alldig.c up to 1.4 external/ibm-public/postfix/dist/src/util/argv.c up to 1.6 external/ibm-public/postfix/dist/src/util/argv.h up to 1.6 external/ibm-public/postfix/dist/src/util/dict.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict.h up to 1.7 external/ibm-public/postfix/dist/src/util/dict_alloc.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_cache.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_cache.h up to 1.3 external/ibm-public/postfix/dist/src/util/dict_cdb.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_cidr.c up to 1.6 external/ibm-public/postfix/dist/src/util/dict_db.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_dbm.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_debug.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_env.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_fail.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_inline.c up to 1.6 external/ibm-public/postfix/dist/src/util/dict_lmdb.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_ni.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_nis.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_nisplus.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_open.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_pcre.c up to 1.6 external/ibm-public/postfix/dist/src/util/dict_pipe.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_random.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_regexp.c up to 1.6 external/ibm-public/postfix/dist/src/util/dict_sdbm.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_seq.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/dict_sockmap.c up to 1.7 external/ibm-public/postfix/dist/src/util/dict_static.c up to 1.5 external/ibm-public/postfix/dist/src/util/dict_surrogate.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_tcp.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_test.c up to 1.3 external/ibm-public/postfix/dist/src/util/dict_thash.c up to 1.6 external/ibm-public/postfix/dist/src/util/dict_union.c up to 1.4 external/ibm-public/postfix/dist/src/util/dict_unix.c up to 1.2 external/ibm-public/postfix/dist/src/util/dict_utf8_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/hash_fnv.c up to 1.5 external/ibm-public/postfix/dist/src/util/hex_code.c up to 1.5 external/ibm-public/postfix/dist/src/util/hex_code.h up to 1.6 external/ibm-public/postfix/dist/src/util/htable.c up to 1.5 external/ibm-public/postfix/dist/src/util/inet_addr_list.c up to 1.3 external/ibm-public/postfix/dist/src/util/inet_prefix_top.c up to 1.4 external/ibm-public/postfix/dist/src/util/inet_proto.c up to 1.5 external/ibm-public/postfix/dist/src/util/mac_expand.c up to 1.5 external/ibm-public/postfix/dist/src/util/mac_expand.h up to 1.6 external/ibm-public/postfix/dist/src/util/mac_expand.in up to 1.1.1.5 external/ibm-public/postfix/dist/src/util/mac_expand.ref up to 1.1.1.5 external/ibm-public/postfix/dist/src/util/match_list.c up to 1.4 external/ibm-public/postfix/dist/src/util/midna_domain.c up to 1.6 external/ibm-public/postfix/dist/src/util/mkmap_open.c up to 1.3 external/ibm-public/postfix/dist/src/util/msg_vstream.c up to 1.2 external/ibm-public/postfix/dist/src/util/myaddrinfo.c up to 1.4 external/ibm-public/postfix/dist/src/util/myaddrinfo.h up to 1.5 external/ibm-public/postfix/dist/src/util/myaddrinfo.ref up to 1.1.1.6 external/ibm-public/postfix/dist/src/util/myaddrinfo.ref2 up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/myaddrinfo4.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/util/myaddrinfo4.ref2 up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/myflock.c up to 1.4 external/ibm-public/postfix/dist/src/util/name_mask.c up to 1.5 external/ibm-public/postfix/dist/src/util/name_mask.h up to 1.2 external/ibm-public/postfix/dist/src/util/name_mask.ref5 up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/name_mask.ref6 up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/netstring.c up to 1.5 external/ibm-public/postfix/dist/src/util/normalize_ws.c up to 1.3 external/ibm-public/postfix/dist/src/util/open_as.c up to 1.2 external/ibm-public/postfix/dist/src/util/open_as.h up to 1.2 external/ibm-public/postfix/dist/src/util/quote_for_json.c up to 1.3 external/ibm-public/postfix/dist/src/util/sane_sockaddr_to_hostaddr.c up to 1.3 external/ibm-public/postfix/dist/src/util/spawn_command.c up to 1.4 external/ibm-public/postfix/dist/src/util/spawn_command.h up to 1.3 external/ibm-public/postfix/dist/src/util/stringops.h up to 1.7 external/ibm-public/postfix/dist/src/util/sys_defs.h up to 1.16 external/ibm-public/postfix/dist/src/util/unescape.ref up to 1.1.1.3 external/ibm-public/postfix/dist/src/util/vbuf_print.c up to 1.6 external/ibm-public/postfix/dist/src/util/vbuf_print_test.in up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/vbuf_print_test.ref up to 1.1.1.2 external/ibm-public/postfix/dist/src/util/vstream.c up to 1.6 external/ibm-public/postfix/dist/src/util/vstream.h up to 1.5 external/ibm-public/postfix/dist/src/util/vstring.c up to 1.5 external/ibm-public/postfix/dist/src/util/vstring_vstream.c up to 1.3 external/ibm-public/postfix/dist/src/verify/verify.c up to 1.6 external/ibm-public/postfix/dist/src/virtual/Makefile.in up to 1.1.1.7 external/ibm-public/postfix/dist/src/virtual/virtual.c up to 1.5 external/ibm-public/postfix/dist/src/virtual/virtual.h up to 1.2 external/ibm-public/postfix/dist/src/xsasl/xsasl_dovecot_server.c up to 1.6 external/ibm-public/postfix/lib/global/Makefile up to 1.12 external/ibm-public/postfix/lib/util/Makefile up to 1.13 external/ibm-public/postfix/libexec/smtp/Makefile up to 1.5 doc/3RDPARTY (manually edited) Import Postfix 3.11.2. @ text @d177 1 a177 1 RFC 8689 (SMTP REQUIRETLS extension, TLS-Required header) d510 1 a510 1 TLS SUPPORT CONTROLS d514 1 a514 1 smtp_tls_security_level (Postfix >= 3.11: may; Postfix < 3.11: empty) d760 4 a763 4 smtp_tlsrpt_skip_reused_handshakes (Postfix >= 3.11: no, Postfix 3.10: yes) When set to "yes", report the TLSRPT status only for "new" TLS sessions. d769 3 a771 25 Available in Postfix version 3.10.5 and later: smtp_tls_enforce_sts_mx_patterns (yes) Transform the TLS policy from an STS policy plugin: connect to an MX host only if its name matches any STS policy MX host pat- tern, and match the server certificate against the MX hostname. Available in Postfix version 3.11 and later: requiretls_enable (yes) Enable support for the ESMTP verb "REQUIRETLS" in the "MAIL FROM" command. smtp_requiretls_policy (see 'postconf -d smtp_requiretls_policy' out- put) How the Postfix SMTP and LMTP client will enforce REQUIRETLS for messages received with the REQUIRETLS option. smtp_log_tls_feature_status (yes) Enable logging of TLS feature information in delivery status logging. OBSOLETE TLS CONTROLS The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a d775 1 a775 1 Opportunistic mode: use TLS when a remote SMTP server announces d779 1 a779 1 Enforcement mode: require that remote SMTP servers use TLS d783 2 a784 2 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP d788 2 a789 2 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- d793 1 a793 1 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS d798 1 a798 1 The Postfix SMTP client time limit for completing a TCP connec- d802 2 a803 2 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server d815 1 a815 1 The Postfix SMTP client time limit for sending the MAIL FROM d819 1 a819 1 The Postfix SMTP client time limit for sending the SMTP RCPT TO d823 1 a823 1 The Postfix SMTP client time limit for sending the SMTP DATA d827 1 a827 1 The Postfix SMTP client time limit for sending the SMTP message d841 2 a842 2 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero d846 2 a847 2 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back d857 1 a857 1 Keep Postfix LMTP client connections open for up to $max_idle d863 1 a863 1 Permanently enable SMTP connection caching for the specified d867 1 a867 1 Temporarily enable SMTP connection caching while a destination d881 1 a881 1 Time limit for connection cache connect, send or receive opera- d887 4 a890 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d896 2 a897 2 When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero d908 3 a910 3 Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for d914 1 a914 1 The minimum plaintext data transfer rate in bytes/second for d922 1 a922 1 A transport-specific override for the default_destination_con- d929 1 a929 1 ient_limit parameter value, where transport is the master.cf d936 1 a936 1 Enable preliminary SMTPUTF8 support for the protocols described d940 1 a940 1 Detect that a message requires SMTPUTF8 support for the speci- d946 2 a947 2 Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII d952 2 a953 2 The increment in verbose logging level when a nexthop destina- tion, remote client or server name or network address matches a d957 3 a959 3 Optional list of nexthop destination, remote client or server name or network address patterns that, if matched, cause the verbose logging level to increase by the amount specified in d963 1 a963 1 The recipient of postmaster notifications about mail delivery d968 2 a969 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d977 1 a977 1 Where the Postfix SMTP client should deliver mail when it d981 1 a981 1 The default location of the Postfix main.cf and master.cf con- d985 1 a985 1 How much time a Postfix daemon process may take to handle a d989 1 a989 1 The maximal number of digits after the decimal point when log- d996 1 a996 1 The local network interface addresses that this mail system d1000 1 a1000 1 The Internet protocols Postfix will attempt to use when making d1004 1 a1004 1 The time limit for sending or receiving information over an d1008 2 a1009 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d1016 1 a1016 1 The maximum amount of time that an idle Postfix daemon process d1030 2 a1031 2 The remote network interface addresses that this mail system receives mail on by way of a proxy or network address transla- d1036 1 a1036 1 client will try first, when a destination has IPv6 and IPv4 d1040 1 a1040 1 An optional numerical network address that the Postfix SMTP d1044 1 a1044 1 An optional numerical network address that the Postfix SMTP d1064 1 a1064 1 A prefix that is prepended to the process name in syslog d1076 2 a1077 2 Optional list of relay destinations that will be used when an SMTP destination is not found, or when delivery fails due to a d1083 1 a1083 1 In the context of email address verification, the SMTP protocol d1105 1 a1105 1 Defer delivery when the Postfix SMTP client cannot apply the @ 1.1.1.14 log @Import postfix 3.11.2 (previous was 3.10.1) Changes in 3.11.2 Bugfix (defect introduced: Postfix 3.11): the proxymap(8) daemon dereferenced an uninitialized pointer after a request protocol error. This daemon is not exposed to local or remote users. Found by Claude Opus 4.6. Bugfix (defect introduced: 20260309) a change, to set the service_name default value to "amnesiac", violated a test that parameter names in postconf output must match 1:1 with parameter names in the postlink script. Changes in 3.11.1 Bugfix (defect introduced: 20260219): alias_maps errors when default_database_type was not set in main.cf. Fix by Michael Tokarev. Bugfix (defect introduced: Postfix 3.0): buffer over-read when Postfix is configured with an enhanced status code not followed by other text. For example, "5.7.2" without text after the three-number code, in an access(5) table, header or body checks, or with "$rbl_code $rbl_text" in rbl_reply_maps or default_rbl_reply. These are all uncommon configurations. Problem reported by Kamil Frankowicz. Bugfix (defect introduced: Postfix 3.3): null pointer in nbdb_reindexd(8) because the "service_name" value was not propagated. Report by Michael Tokarev. During Postfix start-up, avoid a spurious error message from nbdb_reindexd(8), when non_bdb_migration_level disables automatic re-indexing. Changes in 3.11.0 Postfix stable release 3.11.0 is available. Postfix 3.7 - 3.10 were updated a few weeks ago; after that, Postfix 3.7 will no longer be updated. The main changes are below. See the RELEASE_NOTES file for further details. Berkeley DB migration: Some (Linux) distributions are removing support for BerkeleyDB databases (In Postfix, this means we lose support for the hash: and btree: lookup tables). See NON_BERKELEYDB_README for manual and partially automatic migration from btree: to lmdb:, and from hash: to lmdb: or cdb:. The loss of BerkeleyDB affects Mailman versions that want to execute commands like "postmap hash:/path/to/file" when a mailing list is added or removed. Postfix provides a way to redirect such commands to a supported database type. You don't have to wait until BerkeleyDB support is removed. It can make sense to migrate while BerkeleyDB support is still available (mainly, less downtime). Changes in TLS support: Default TLS security. The Postfix SMTP client smtp_tls_security_level default value is "may" if Postfix was built with TLS support, and the compatibility_level is 3.11 or higher. Support for the RFC 8689 "REQUIRETLS" verb in ESMTP. This requires that every SMTP (and LMTP) server in the forward path is strongly authenticated with DANE, STS, or equivalent, and that every server announces REQUIRETLS support. See REQUIRETLS_README for suggestions to carefully enforce REQUIRETLS without causing massive mail delivery problems. Logging the TLS security level. This shows the desired and actual TLS security level enforcement status and, if a message requests REQUIRETLS, the REQUIRETLS policy enforcement status. For a list of examples see smtp_log_tls_feature_status Workaround for an interface mismatch between the Postfix SMTP client and MTA-STS policy plugins. This introduces a new parameter smtp_tls_enforce_sts_mx_patterns (default: "yes"). The MTA-STS plugin configuration needs to enable TLSRPT support, so that it forwards STS policy attributes to Postfix. Both postfix-tlspol and postfix-mta-sts-resolver have been updated accordingly. With this, the Postfix SMTP client will connect to an MX host only if its name matches any STS policy MX host pattern, and will match a server certificate against the MX hostname. Otherwise, the old behavior stays in effect: connect to any MX host listed in DNS, and match a server certificate against any STS policy MX host pattern. Post-quantum cryptography support. With OpenSSL 3.5 and later, change the tls_eecdh_auto_curves default value to avoid problems with network infrastructure that mishandles TLS hello messages larger than one (Ethernet) TCP segment. This problem is more generally known as "protocol ossification". Miscellaneous changes: Deprecation of obsolete parameters. Postfix programs log a warning that these parameters will be removed. See DEPRECATION_README for a list of deprecated parameters. JSON output support with "postconf -j|-jM|-jF|-jP", "postalias -jq|-js", "postmap -jq|-js", and "postmulti -jl". No support is planned for JSON input support. Milter support: improved Milter error handling for messages that arrive over a long-lived SMTP connection, by changing the default milter_default_action from "tempfail" to the new "shutdown" action (i.e. disconnect the remote SMTP client). This was already back-ported to earlier stable releases. For more changes in the 3.10 branch see: https://www.postfix.org/announcements.html @ text @d177 1 a177 1 RFC 8689 (SMTP REQUIRETLS extension, TLS-Required header) d510 1 a510 1 TLS SUPPORT CONTROLS d514 1 a514 1 smtp_tls_security_level (Postfix >= 3.11: may; Postfix < 3.11: empty) d760 4 a763 4 smtp_tlsrpt_skip_reused_handshakes (Postfix >= 3.11: no, Postfix 3.10: yes) When set to "yes", report the TLSRPT status only for "new" TLS sessions. d769 3 a771 25 Available in Postfix version 3.10.5 and later: smtp_tls_enforce_sts_mx_patterns (yes) Transform the TLS policy from an STS policy plugin: connect to an MX host only if its name matches any STS policy MX host pat- tern, and match the server certificate against the MX hostname. Available in Postfix version 3.11 and later: requiretls_enable (yes) Enable support for the ESMTP verb "REQUIRETLS" in the "MAIL FROM" command. smtp_requiretls_policy (see 'postconf -d smtp_requiretls_policy' out- put) How the Postfix SMTP and LMTP client will enforce REQUIRETLS for messages received with the REQUIRETLS option. smtp_log_tls_feature_status (yes) Enable logging of TLS feature information in delivery status logging. OBSOLETE TLS CONTROLS The following configuration parameters exist for compatibility with Postfix versions before 2.3. Support for these will be removed in a d775 1 a775 1 Opportunistic mode: use TLS when a remote SMTP server announces d779 1 a779 1 Enforcement mode: require that remote SMTP servers use TLS d783 2 a784 2 With mandatory TLS encryption, require that the remote SMTP server hostname matches the information in the remote SMTP d788 2 a789 2 Optional lookup tables with the Postfix SMTP client TLS usage policy by next-hop destination and by remote SMTP server host- d793 1 a793 1 Obsolete Postfix < 2.3 control for the Postfix SMTP client TLS d798 1 a798 1 The Postfix SMTP client time limit for completing a TCP connec- d802 2 a803 2 The Postfix SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial remote SMTP server d815 1 a815 1 The Postfix SMTP client time limit for sending the MAIL FROM d819 1 a819 1 The Postfix SMTP client time limit for sending the SMTP RCPT TO d823 1 a823 1 The Postfix SMTP client time limit for sending the SMTP DATA d827 1 a827 1 The Postfix SMTP client time limit for sending the SMTP message d841 2 a842 2 The maximal number of MX (mail exchanger) IP addresses that can result from Postfix SMTP client mail exchanger lookups, or zero d846 2 a847 2 The maximal number of SMTP sessions per delivery request before the Postfix SMTP client gives up or delivers to a fall-back d857 1 a857 1 Keep Postfix LMTP client connections open for up to $max_idle d863 1 a863 1 Permanently enable SMTP connection caching for the specified d867 1 a867 1 Temporarily enable SMTP connection caching while a destination d881 1 a881 1 Time limit for connection cache connect, send or receive opera- d887 4 a890 4 Change the behavior of the smtp_*_timeout time limits, from a time limit per read or write system call, to a time limit to send or receive a complete record (an SMTP command line, SMTP response line, SMTP message content line, or TLS protocol mes- d896 2 a897 2 When SMTP connection caching is enabled, the number of times that an SMTP session may be reused before it is closed, or zero d908 3 a910 3 Change the behavior of the smtp_*_timeout time limits, from a time limit per plaintext or TLS read or write call, to a com- bined time limit for sending a complete SMTP request and for d914 1 a914 1 The minimum plaintext data transfer rate in bytes/second for d922 1 a922 1 A transport-specific override for the default_destination_con- d929 1 a929 1 ient_limit parameter value, where transport is the master.cf d936 1 a936 1 Enable preliminary SMTPUTF8 support for the protocols described d940 1 a940 1 Detect that a message requires SMTPUTF8 support for the speci- d946 2 a947 2 Enable 'transitional' compatibility between IDNA2003 and IDNA2008, when converting UTF-8 domain names to/from the ASCII d952 2 a953 2 The increment in verbose logging level when a nexthop destina- tion, remote client or server name or network address matches a d957 3 a959 3 Optional list of nexthop destination, remote client or server name or network address patterns that, if matched, cause the verbose logging level to increase by the amount specified in d963 1 a963 1 The recipient of postmaster notifications about mail delivery d968 2 a969 2 What categories of Postfix-generated mail are subject to before-queue content inspection by non_smtpd_milters, d977 1 a977 1 Where the Postfix SMTP client should deliver mail when it d981 1 a981 1 The default location of the Postfix main.cf and master.cf con- d985 1 a985 1 How much time a Postfix daemon process may take to handle a d989 1 a989 1 The maximal number of digits after the decimal point when log- d996 1 a996 1 The local network interface addresses that this mail system d1000 1 a1000 1 The Internet protocols Postfix will attempt to use when making d1004 1 a1004 1 The time limit for sending or receiving information over an d1008 2 a1009 2 When a remote LMTP server announces no DSN support, assume that the server performs final delivery, and send "delivered" deliv- d1016 1 a1016 1 The maximum amount of time that an idle Postfix daemon process d1030 2 a1031 2 The remote network interface addresses that this mail system receives mail on by way of a proxy or network address transla- d1036 1 a1036 1 client will try first, when a destination has IPv6 and IPv4 d1040 1 a1040 1 An optional numerical network address that the Postfix SMTP d1044 1 a1044 1 An optional numerical network address that the Postfix SMTP d1064 1 a1064 1 A prefix that is prepended to the process name in syslog d1076 2 a1077 2 Optional list of relay destinations that will be used when an SMTP destination is not found, or when delivery fails due to a d1083 1 a1083 1 In the context of email address verification, the SMTP protocol d1105 1 a1105 1 Defer delivery when the Postfix SMTP client cannot apply the @ 1.1.1.1.4.1 log @file smtp.8.html was added on branch matt-nb5-mips64 on 2010-04-21 05:23:33 +0000 @ text @d1 863 @ 1.1.1.1.4.2 log @sync to netbsd-5 @ text @a0 863 Postfix manual - smtp(8)
SMTP(8)                                                                SMTP(8)

NAME
       smtp - Postfix SMTP+LMTP client

SYNOPSIS
       smtp [generic Postfix daemon options]

DESCRIPTION
       The  Postfix SMTP+LMTP client implements the SMTP and LMTP
       mail delivery protocols.  It  processes  message  delivery
       requests  from the queue manager. Each request specifies a
       queue file, a sender address, a domain or host to  deliver
       to, and recipient information.  This program expects to be
       run from the master(8) process manager.

       The SMTP+LMTP client updates  the  queue  file  and  marks
       recipients  as  finished,  or it informs the queue manager
       that delivery should be  tried  again  at  a  later  time.
       Delivery   status  reports  are  sent  to  the  bounce(8),
       defer(8) or trace(8) daemon as appropriate.

       The SMTP+LMTP client looks up a  list  of  mail  exchanger
       addresses  for  the  destination  host,  sorts the list by
       preference, and connects to each listed address  until  it
       finds a server that responds.

       When  a  server  is  not  reachable, or when mail delivery
       fails due to a recoverable error condition, the  SMTP+LMTP
       client  will try to deliver the mail to an alternate host.

       After a successful mail transaction, a connection  may  be
       saved to the scache(8) connection cache server, so that it
       may be used by  any  SMTP+LMTP  client  for  a  subsequent
       transaction.

       By  default, connection caching is enabled temporarily for
       destinations that have a high volume of mail in the active
       queue.  Connection  caching can be enabled permanently for
       specific destinations.

SMTP DESTINATION SYNTAX
       SMTP destinations have the following form:

       domainname

       domainname:port
              Look up  the  mail  exchangers  for  the  specified
              domain, and connect to the specified port (default:
              smtp).

       [hostname]

       [hostname]:port
              Look up the address(es) of the specified host,  and
              connect to the specified port (default: smtp).

       [address]

       [address]:port
              Connect  to  the host at the specified address, and
              connect to the specified port (default:  smtp).  An
              IPv6 address must be formatted as [ipv6:address].

LMTP DESTINATION SYNTAX
       LMTP destinations have the following form:

       unix:pathname
              Connect  to  the  local  UNIX-domain server that is
              bound to the specified  pathname.  If  the  process
              runs  chrooted, an absolute pathname is interpreted
              relative to the Postfix queue directory.

       inet:hostname

       inet:hostname:port

       inet:[address]

       inet:[address]:port
              Connect to the specified TCP port on the  specified
              local or remote host. If no port is specified, con-
              nect to the port defined as  lmtp  in  services(4).
              If no such service is found, the lmtp_tcp_port con-
              figuration parameter (default value of 24) will  be
              used.    An  IPv6  address  must  be  formatted  as
              [ipv6:address].

SECURITY
       The SMTP+LMTP client is moderately security-sensitive.  It
       talks  to  SMTP  or LMTP servers and to DNS servers on the
       network. The SMTP+LMTP client can be run chrooted at fixed
       low privilege.

STANDARDS
       RFC 821 (SMTP protocol)
       RFC 822 (ARPA Internet Text Messages)
       RFC 1651 (SMTP service extensions)
       RFC 1652 (8bit-MIME transport)
       RFC 1870 (Message Size Declaration)
       RFC 2033 (LMTP protocol)
       RFC 2034 (SMTP Enhanced Error Codes)
       RFC 2045 (MIME: Format of Internet Message Bodies)
       RFC 2046 (MIME: Media Types)
       RFC 2554 (AUTH command)
       RFC 2821 (SMTP protocol)
       RFC 2920 (SMTP Pipelining)
       RFC 3207 (STARTTLS command)
       RFC 3461 (SMTP DSN Extension)
       RFC 3463 (Enhanced Status Codes)
       RFC 4954 (AUTH command)

DIAGNOSTICS
       Problems  and transactions are logged to syslogd(8).  Cor-
       rupted message files are marked so that the queue  manager
       can move them to the corrupt queue for further inspection.

       Depending on the setting of the notify_classes  parameter,
       the  postmaster is notified of bounces, protocol problems,
       and of other trouble.

BUGS
       SMTP and LMTP connection caching does not work  with  TLS.
       The  necessary  support for TLS object passivation and re-
       activation does not exist  without  closing  the  session,
       which defeats the purpose.

       SMTP and LMTP connection caching assumes that SASL creden-
       tials are valid for all destinations  that  map  onto  the
       same IP address and TCP port.

CONFIGURATION PARAMETERS
       Before  Postfix version 2.3, the LMTP client is a separate
       program that implements only a subset of the functionality
       available with SMTP: there is no support for TLS, and con-
       nections are cached in-process, making it ineffective when
       the client is used for multiple domains.

       Most  smtp_xxx  configuration  parameters have an lmtp_xxx
       "mirror" parameter for the equivalent LMTP  feature.  This
       document describes only those LMTP-related parameters that
       aren't simply "mirror" parameters.

       Changes to main.cf are picked up automatically, as smtp(8)
       processes  run  for only a limited amount of time. Use the
       command "postfix reload" to speed up a change.

       The text below provides  only  a  parameter  summary.  See
       postconf(5) for more details including examples.

COMPATIBILITY CONTROLS
       ignore_mx_lookup_error (no)
              Ignore DNS MX lookups that produce no response.

       smtp_always_send_ehlo (yes)
              Always send EHLO at the start of an SMTP session.

       smtp_never_send_ehlo (no)
              Never send EHLO at the start of an SMTP session.

       smtp_defer_if_no_mx_address_found (no)
              Defer  mail  delivery when no MX record resolves to
              an IP address.

       smtp_line_length_limit (990)
              The maximal length of message header and body lines
              that Postfix will send via SMTP.

       smtp_pix_workaround_delay_time (10s)
              How  long  the  Postfix  SMTP  client pauses before
              sending ".<CR><LF>" in order to work around the PIX
              firewall "<CR><LF>.<CR><LF>" bug.

       smtp_pix_workaround_threshold_time (500s)
              How  long a message must be queued before the Post-
              fix  SMTP  client  turns  on   the   PIX   firewall
              "<CR><LF>.<CR><LF>"  bug  workaround  for  delivery
              through firewalls with "smtp fixup" mode turned on.

       smtp_pix_workarounds (disable_esmtp, delay_dotcrlf)
              A  list that specifies zero or more workarounds for
              CISCO PIX firewall bugs.

       smtp_pix_workaround_maps (empty)
              Lookup tables, indexed by the  remote  SMTP  server
              address, with per-destination workarounds for CISCO
              PIX firewall bugs.

       smtp_quote_rfc821_envelope (yes)
              Quote addresses in SMTP MAIL FROM and RCPT TO  com-
              mands as required by RFC 2821.

       smtp_skip_5xx_greeting (yes)
              Skip SMTP servers that greet with a 5XX status code
              (go away, do not try again later).

       smtp_skip_quit_response (yes)
              Do not wait for the response to the SMTP QUIT  com-
              mand.

       Available in Postfix version 2.0 and earlier:

       smtp_skip_4xx_greeting (yes)
              Skip SMTP servers that greet with a 4XX status code
              (go away, try again later).

       Available in Postfix version 2.2 and later:

       smtp_discard_ehlo_keyword_address_maps (empty)
              Lookup tables, indexed by the  remote  SMTP  server
              address,  with  case insensitive lists of EHLO key-
              words (pipelining, starttls, auth, etc.)  that  the
              Postfix   SMTP  client  will  ignore  in  the  EHLO
              response from a remote SMTP server.

       smtp_discard_ehlo_keywords (empty)
              A case insensitive list of EHLO keywords  (pipelin-
              ing,  starttls,  auth,  etc.) that the Postfix SMTP
              client will ignore in  the  EHLO  response  from  a
              remote SMTP server.

       smtp_generic_maps (empty)
              Optional lookup tables that perform address rewrit-
              ing in the SMTP client, typically  to  transform  a
              locally valid address into a globally valid address
              when sending mail across the Internet.

       Available in Postfix version 2.2.9 and later:

       smtp_cname_overrides_servername (version dependent)
              Allow DNS CNAME records to override the  servername
              that the Postfix SMTP client uses for logging, SASL
              password lookup, TLS policy decisions, or TLS  cer-
              tificate verification.

       Available in Postfix version 2.3 and later:

       lmtp_discard_lhlo_keyword_address_maps (empty)
              Lookup  tables,  indexed  by the remote LMTP server
              address, with case insensitive lists of  LHLO  key-
              words  (pipelining,  starttls, auth, etc.) that the
              LMTP client will ignore in the LHLO response from a
              remote LMTP server.

       lmtp_discard_lhlo_keywords (empty)
              A  case insensitive list of LHLO keywords (pipelin-
              ing, starttls, auth, etc.)  that  the  LMTP  client
              will ignore in the LHLO response from a remote LMTP
              server.

       Available in Postfix version 2.4.4 and later:

       send_cyrus_sasl_authzid (no)
              When authenticating to a remote SMTP or LMTP server
              with  the default setting "no", send no SASL autho-
              riZation ID (authzid); send only the SASL authenti-
              Cation ID (authcid) plus the authcid's password.

       Available in Postfix version 2.5 and later:

       smtp_header_checks (empty)
              Restricted  header_checks(5) tables for the Postfix
              SMTP client.

       smtp_mime_header_checks (empty)
              Restricted  mime_header_checks(5)  tables  for  the
              Postfix SMTP client.

       smtp_nested_header_checks (empty)
              Restricted  nested_header_checks(5)  tables for the
              Postfix SMTP client.

       smtp_body_checks (empty)
              Restricted body_checks(5) tables  for  the  Postfix
              SMTP client.

       Available in Postfix version 2.6 and later:

       tcp_windowsize (0)
              An  optional  workaround for routers that break TCP
              window scaling.

MIME PROCESSING CONTROLS
       Available in Postfix version 2.0 and later:

       disable_mime_output_conversion (no)
              Disable the conversion of 8BITMIME format  to  7BIT
              format.

       mime_boundary_length_limit (2048)
              The  maximal  length  of  MIME  multipart  boundary
              strings.

       mime_nesting_limit (100)
              The maximal recursion level that the MIME processor
              will handle.

EXTERNAL CONTENT INSPECTION CONTROLS
       Available in Postfix version 2.1 and later:

       smtp_send_xforward_command (no)
              Send  the  non-standard  XFORWARD  command when the
              Postfix SMTP server EHLO response  announces  XFOR-
              WARD support.

SASL AUTHENTICATION CONTROLS
       smtp_sasl_auth_enable (no)
              Enable  SASL  authentication  in  the  Postfix SMTP
              client.

       smtp_sasl_password_maps (empty)
              Optional SMTP client lookup tables with  one  user-
              name:password  entry per remote hostname or domain,
              or sender address when sender-dependent authentica-
              tion is enabled.

       smtp_sasl_security_options (noplaintext, noanonymous)
              Postfix  SMTP  client  SASL security options; as of
              Postfix 2.3 the list of available features  depends
              on  the SASL client implementation that is selected
              with smtp_sasl_type.

       Available in Postfix version 2.2 and later:

       smtp_sasl_mechanism_filter (empty)
              If non-empty, a Postfix SMTP client filter for  the
              remote  SMTP  server's  list of offered SASL mecha-
              nisms.

       Available in Postfix version 2.3 and later:

       smtp_sender_dependent_authentication (no)
              Enable sender-dependent authentication in the Post-
              fix  SMTP  client; this is available only with SASL
              authentication,  and   disables   SMTP   connection
              caching  to ensure that mail from different senders
              will use the appropriate credentials.

       smtp_sasl_path (empty)
              Implementation-specific information that the  Post-
              fix  SMTP client passes through to the SASL plug-in
              implementation    that     is     selected     with
              smtp_sasl_type.

       smtp_sasl_type (cyrus)
              The  SASL plug-in type that the Postfix SMTP client
              should use for authentication.

       Available in Postfix version 2.5 and later:

       smtp_sasl_auth_cache_name (empty)
              An optional table to prevent repeated SASL  authen-
              tication  failures with the same remote SMTP server
              hostname, username and password.

       smtp_sasl_auth_cache_time (90d)
              The maximal  age  of  an  smtp_sasl_auth_cache_name
              entry before it is removed.

       smtp_sasl_auth_soft_bounce (yes)
              When  a remote SMTP server rejects a SASL authenti-
              cation request with a 535 reply  code,  defer  mail
              delivery  instead  of  returning mail as undeliver-
              able.

STARTTLS SUPPORT CONTROLS
       Detailed information about STARTTLS configuration  may  be
       found in the TLS_README document.

       smtp_tls_security_level (empty)
              The default SMTP TLS security level for the Postfix
              SMTP client; when a non-empty value  is  specified,
              this     overrides    the    obsolete    parameters
              smtp_use_tls,         smtp_enforce_tls,         and
              smtp_tls_enforce_peername.

       smtp_sasl_tls_security_options           ($smtp_sasl_secu-
       rity_options)
              The  SASL  authentication security options that the
              Postfix SMTP client uses  for  TLS  encrypted  SMTP
              sessions.

       smtp_starttls_timeout (300s)
              Time  limit  for Postfix SMTP client write and read
              operations during TLS startup  and  shutdown  hand-
              shake procedures.

       smtp_tls_CAfile (empty)
              A  file  containing  CA  certificates  of  root CAs
              trusted to sign either remote SMTP server  certifi-
              cates or intermediate CA certificates.

       smtp_tls_CApath (empty)
              Directory  with  PEM  format  certificate authority
              certificates that the Postfix SMTP client  uses  to
              verify a remote SMTP server certificate.

       smtp_tls_cert_file (empty)
              File  with  the Postfix SMTP client RSA certificate
              in PEM format.

       smtp_tls_mandatory_ciphers (medium)
              The minimum TLS cipher grade that the Postfix  SMTP
              client will use with mandatory TLS encryption.

       smtp_tls_exclude_ciphers (empty)
              List of ciphers or cipher types to exclude from the
              Postfix SMTP client cipher list at all TLS security
              levels.

       smtp_tls_mandatory_exclude_ciphers (empty)
              Additional  list  of  ciphers  or  cipher  types to
              exclude from the SMTP client cipher list at  manda-
              tory TLS security levels.

       smtp_tls_dcert_file (empty)
              File  with  the Postfix SMTP client DSA certificate
              in PEM format.

       smtp_tls_dkey_file ($smtp_tls_dcert_file)
              File with the Postfix SMTP client DSA  private  key
              in PEM format.

       smtp_tls_key_file ($smtp_tls_cert_file)
              File  with  the Postfix SMTP client RSA private key
              in PEM format.

       smtp_tls_loglevel (0)
              Enable additional Postfix SMTP  client  logging  of
              TLS activity.

       smtp_tls_note_starttls_offer (no)
              Log  the  hostname  of  a  remote  SMTP server that
              offers STARTTLS, when TLS is  not  already  enabled
              for that server.

       smtp_tls_policy_maps (empty)
              Optional lookup tables with the Postfix SMTP client
              TLS security policy by next-hop destination; when a
              non-empty  value  is  specified, this overrides the
              obsolete smtp_tls_per_site parameter.

       smtp_tls_mandatory_protocols (SSLv3, TLSv1)
              List of SSL/TLS protocols  that  the  Postfix  SMTP
              client will use with mandatory TLS encryption.

       smtp_tls_scert_verifydepth (9)
              The  verification depth for remote SMTP server cer-
              tificates.

       smtp_tls_secure_cert_match (nexthop, dot-nexthop)
              The server certificate peername verification method
              for the "secure" TLS security level.

       smtp_tls_session_cache_database (empty)
              Name  of  the  file containing the optional Postfix
              SMTP client TLS session cache.

       smtp_tls_session_cache_timeout (3600s)
              The expiration time of Postfix SMTP client TLS ses-
              sion cache information.

       smtp_tls_verify_cert_match (hostname)
              The server certificate peername verification method
              for the "verify" TLS security level.

       tls_daemon_random_bytes (32)
              The number of pseudo-random bytes that  an  smtp(8)
              or  smtpd(8)  process  requests  from the tlsmgr(8)
              server in order to seed its internal pseudo  random
              number generator (PRNG).

       tls_high_cipherlist
       (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "HIGH" grade ciphers.

       tls_medium_cipherlist (ALL:!EXPORT:!LOW:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "MEDIUM" or higher grade
              ciphers.

       tls_low_cipherlist (ALL:!EXPORT:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "LOW"  or  higher  grade
              ciphers.

       tls_export_cipherlist (ALL:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "EXPORT" or higher grade
              ciphers.

       tls_null_cipherlist (eNULL:!aNULL)
              The OpenSSL cipherlist  for  "NULL"  grade  ciphers
              that provide authentication without encryption.

       Available in Postfix version 2.4 and later:

       smtp_sasl_tls_verified_security_options
       ($smtp_sasl_tls_security_options)
              The  SASL  authentication security options that the
              Postfix SMTP client uses  for  TLS  encrypted  SMTP
              sessions with a verified server certificate.

       Available in Postfix version 2.5 and later:

       smtp_tls_fingerprint_cert_match (empty)
              List  of  acceptable remote SMTP server certificate
              fingerprints for  the  "fingerprint"  TLS  security
              level (smtp_tls_security_level = fingerprint).

       smtp_tls_fingerprint_digest (md5)
              The  message  digest  algorithm  used  to construct
              remote SMTP server certificate fingerprints.

       Available in Postfix version 2.6 and later:

       smtp_tls_protocols (!SSLv2)
              List of TLS protocols that the Postfix SMTP  client
              will  exclude  or  include  with  opportunistic TLS
              encryption.

       smtp_tls_ciphers (export)
              The minimum TLS cipher grade that the Postfix  SMTP
              client  will use with opportunistic TLS encryption.

       smtp_tls_eccert_file (empty)
              File with the Postfix SMTP client ECDSA certificate
              in PEM format.

       smtp_tls_eckey_file ($smtp_tls_eccert_file)
              File with the Postfix SMTP client ECDSA private key
              in PEM format.

OBSOLETE STARTTLS CONTROLS
       The following configuration parameters exist for  compati-
       bility with Postfix versions before 2.3. Support for these
       will be removed in a future release.

       smtp_use_tls (no)
              Opportunistic mode: use  TLS  when  a  remote  SMTP
              server  announces  STARTTLS support, otherwise send
              the mail in the clear.

       smtp_enforce_tls (no)
              Enforcement mode: require that remote SMTP  servers
              use  TLS  encryption,  and  never  send mail in the
              clear.

       smtp_tls_enforce_peername (yes)
              With mandatory TLS  encryption,  require  that  the
              remote SMTP server hostname matches the information
              in the remote SMTP server certificate.

       smtp_tls_per_site (empty)
              Optional lookup tables with the Postfix SMTP client
              TLS  usage  policy  by  next-hop destination and by
              remote SMTP server hostname.

       smtp_tls_cipherlist (empty)
              Obsolete Postfix < 2.3 control for the Postfix SMTP
              client TLS cipher list.

RESOURCE AND RATE CONTROLS
       smtp_destination_concurrency_limit      ($default_destina-
       tion_concurrency_limit)
              The  maximal  number  of parallel deliveries to the
              same destination  via  the  smtp  message  delivery
              transport.

       smtp_destination_recipient_limit        ($default_destina-
       tion_recipient_limit)
              The  maximal  number  of recipients per message for
              the smtp message delivery transport.

       smtp_connect_timeout (30s)
              The SMTP client time limit  for  completing  a  TCP
              connection,  or  zero  (use  the  operating  system
              built-in time limit).

       smtp_helo_timeout (300s)
              The SMTP client time limit for sending the HELO  or
              EHLO  command, and for receiving the initial server
              response.

       lmtp_lhlo_timeout (300s)
              The LMTP client time limit  for  sending  the  LHLO
              command,  and  for  receiving  the  initial  server
              response.

       smtp_xforward_timeout (300s)
              The SMTP client time limit for sending the XFORWARD
              command, and for receiving the server response.

       smtp_mail_timeout (300s)
              The  SMTP  client  time  limit for sending the MAIL
              FROM  command,  and  for   receiving   the   server
              response.

       smtp_rcpt_timeout (300s)
              The  SMTP  client  time  limit for sending the SMTP
              RCPT TO  command,  and  for  receiving  the  server
              response.

       smtp_data_init_timeout (120s)
              The  SMTP  client  time  limit for sending the SMTP
              DATA  command,  and  for   receiving   the   server
              response.

       smtp_data_xfer_timeout (180s)
              The  SMTP  client  time  limit for sending the SMTP
              message content.

       smtp_data_done_timeout (600s)
              The SMTP client time limit  for  sending  the  SMTP
              ".", and for receiving the server response.

       smtp_quit_timeout (300s)
              The  SMTP  client  time  limit for sending the QUIT
              command, and for receiving the server response.

       Available in Postfix version 2.1 and later:

       smtp_mx_address_limit (5)
              The  maximal  number  of  MX  (mail  exchanger)  IP
              addresses  that  can  result  from  mail  exchanger
              lookups, or zero (no limit).

       smtp_mx_session_limit (2)
              The maximal number of SMTP  sessions  per  delivery
              request  before  giving up or delivering to a fall-
              back relay host, or zero (no limit).

       smtp_rset_timeout (20s)
              The SMTP client time limit  for  sending  the  RSET
              command, and for receiving the server response.

       Available in Postfix version 2.2 and earlier:

       lmtp_cache_connection (yes)
              Keep Postfix LMTP client connections open for up to
              $max_idle seconds.

       Available in Postfix version 2.2 and later:

       smtp_connection_cache_destinations (empty)
              Permanently enable SMTP connection caching for  the
              specified destinations.

       smtp_connection_cache_on_demand (yes)
              Temporarily  enable SMTP connection caching while a
              destination has a high volume of mail in the active
              queue.

       smtp_connection_reuse_time_limit (300s)
              The amount of time during which Postfix will use an
              SMTP connection repeatedly.

       smtp_connection_cache_time_limit (2s)
              When SMTP connection caching is enabled, the amount
              of  time  that an unused SMTP client socket is kept
              open before it is closed.

       Available in Postfix version 2.3 and later:

       connection_cache_protocol_timeout (5s)
              Time limit for connection cache  connect,  send  or
              receive operations.

TROUBLE SHOOTING CONTROLS
       debug_peer_level (2)
              The  increment  in  verbose  logging  level  when a
              remote client or server matches a  pattern  in  the
              debug_peer_list parameter.

       debug_peer_list (empty)
              Optional  list  of remote client or server hostname
              or network address patterns that cause the  verbose
              logging  level  to increase by the amount specified
              in $debug_peer_level.

       error_notice_recipient (postmaster)
              The recipient  of  postmaster  notifications  about
              mail  delivery  problems that are caused by policy,
              resource, software or protocol errors.

       internal_mail_filter_classes (empty)
              What categories of Postfix-generated mail are  sub-
              ject   to   before-queue   content   inspection  by
              non_smtpd_milters, header_checks and body_checks.

       notify_classes (resource, software)
              The list of error classes that are reported to  the
              postmaster.

MISCELLANEOUS CONTROLS
       best_mx_transport (empty)
              Where  the  Postfix SMTP client should deliver mail
              when it detects a "mail loops back to myself" error
              condition.

       config_directory (see 'postconf -d' output)
              The  default  location  of  the Postfix main.cf and
              master.cf configuration files.

       daemon_timeout (18000s)
              How much time a Postfix daemon process may take  to
              handle  a  request  before  it  is  terminated by a
              built-in watchdog timer.

       delay_logging_resolution_limit (2)
              The maximal number  of  digits  after  the  decimal
              point when logging sub-second delay values.

       disable_dns_lookups (no)
              Disable  DNS  lookups  in the Postfix SMTP and LMTP
              clients.

       inet_interfaces (all)
              The network interface addresses that this mail sys-
              tem receives mail on.

       inet_protocols (ipv4)
              The  Internet protocols Postfix will attempt to use
              when making or accepting connections.

       ipc_timeout (3600s)
              The time limit for sending or receiving information
              over an internal communication channel.

       lmtp_assume_final (no)
              When  an  LMTP  server  announces  no  DSN support,
              assume that the server performs final delivery, and
              send   "delivered"  delivery  status  notifications
              instead of "relayed".

       lmtp_tcp_port (24)
              The default TCP port that the Postfix  LMTP  client
              connects to.

       max_idle (100s)
              The  maximum  amount  of  time that an idle Postfix
              daemon process waits  for  an  incoming  connection
              before terminating voluntarily.

       max_use (100)
              The  maximal  number of incoming connections that a
              Postfix daemon process will service  before  termi-
              nating voluntarily.

       process_id (read-only)
              The  process  ID  of  a  Postfix  command or daemon
              process.

       process_name (read-only)
              The process name of a  Postfix  command  or  daemon
              process.

       proxy_interfaces (empty)
              The network interface addresses that this mail sys-
              tem receives mail on by way of a proxy  or  network
              address translation unit.

       smtp_bind_address (empty)
              An  optional  numerical  network  address  that the
              Postfix SMTP client should bind to when  making  an
              IPv4 connection.

       smtp_bind_address6 (empty)
              An  optional  numerical  network  address  that the
              Postfix SMTP client should bind to when  making  an
              IPv6 connection.

       smtp_helo_name ($myhostname)
              The  hostname to send in the SMTP EHLO or HELO com-
              mand.

       lmtp_lhlo_name ($myhostname)
              The hostname to send in the LMTP LHLO command.

       smtp_host_lookup (dns)
              What mechanisms when the Postfix SMTP  client  uses
              to look up a host's IP address.

       smtp_randomize_addresses (yes)
              Randomize  the  order  of  equal-preference MX host
              addresses.

       syslog_facility (mail)
              The syslog facility of Postfix logging.

       syslog_name (see 'postconf -d' output)
              The mail system  name  that  is  prepended  to  the
              process  name  in  syslog  records, so that "smtpd"
              becomes, for example, "postfix/smtpd".

       Available with Postfix 2.2 and earlier:

       fallback_relay (empty)
              Optional list of relay hosts for SMTP  destinations
              that can't be found or that are unreachable.

       Available with Postfix 2.3 and later:

       smtp_fallback_relay ($fallback_relay)
              Optional  list of relay hosts for SMTP destinations
              that can't be found or that are unreachable.

SEE ALSO
       generic(5), output address rewriting
       header_checks(5), message header content inspection
       body_checks(5), body parts content inspection
       qmgr(8), queue manager
       bounce(8), delivery status reports
       scache(8), connection cache server
       postconf(5), configuration parameters
       master(5), generic daemon options
       master(8), process manager
       tlsmgr(8), TLS session and PRNG management
       syslogd(8), system logging

README FILES
       SASL_README, Postfix SASL howto
       TLS_README, Postfix STARTTLS howto

LICENSE
       The  Secure  Mailer  license must be distributed with this
       software.

AUTHOR(S)
       Wietse Venema
       IBM T.J. Watson Research
       P.O. Box 704
       Yorktown Heights, NY 10598, USA

       Command pipelining in cooperation with:
       Jon Ribbens
       Oaktree Internet Solutions Ltd.,
       Internet House,
       Canal Basin,
       Coventry,
       CV1 4LY, United Kingdom.

       SASL support originally by:
       Till Franke
       SuSE Rhein/Main AG
       65760 Eschborn, Germany

       TLS support originally by:
       Lutz Jaenicke
       BTU Cottbus
       Allgemeine Elektrotechnik
       Universitaetsplatz 3-4
       D-03044 Cottbus, Germany

       Revised TLS and SMTP connection cache support by:
       Victor Duchovni
       Morgan Stanley

                                                                       SMTP(8)
@ 1.1.1.1.2.1 log @file smtp.8.html was added on branch netbsd-5 on 2009-09-15 06:02:16 +0000 @ text @d1 863 @ 1.1.1.1.2.2 log @Apply patch (requested by tron in ticket #944): Update Postfix to 2.6.5. @ text @a0 863 Postfix manual - smtp(8)
SMTP(8)                                                                SMTP(8)

NAME
       smtp - Postfix SMTP+LMTP client

SYNOPSIS
       smtp [generic Postfix daemon options]

DESCRIPTION
       The  Postfix SMTP+LMTP client implements the SMTP and LMTP
       mail delivery protocols.  It  processes  message  delivery
       requests  from the queue manager. Each request specifies a
       queue file, a sender address, a domain or host to  deliver
       to, and recipient information.  This program expects to be
       run from the master(8) process manager.

       The SMTP+LMTP client updates  the  queue  file  and  marks
       recipients  as  finished,  or it informs the queue manager
       that delivery should be  tried  again  at  a  later  time.
       Delivery   status  reports  are  sent  to  the  bounce(8),
       defer(8) or trace(8) daemon as appropriate.

       The SMTP+LMTP client looks up a  list  of  mail  exchanger
       addresses  for  the  destination  host,  sorts the list by
       preference, and connects to each listed address  until  it
       finds a server that responds.

       When  a  server  is  not  reachable, or when mail delivery
       fails due to a recoverable error condition, the  SMTP+LMTP
       client  will try to deliver the mail to an alternate host.

       After a successful mail transaction, a connection  may  be
       saved to the scache(8) connection cache server, so that it
       may be used by  any  SMTP+LMTP  client  for  a  subsequent
       transaction.

       By  default, connection caching is enabled temporarily for
       destinations that have a high volume of mail in the active
       queue.  Connection  caching can be enabled permanently for
       specific destinations.

SMTP DESTINATION SYNTAX
       SMTP destinations have the following form:

       domainname

       domainname:port
              Look up  the  mail  exchangers  for  the  specified
              domain, and connect to the specified port (default:
              smtp).

       [hostname]

       [hostname]:port
              Look up the address(es) of the specified host,  and
              connect to the specified port (default: smtp).

       [address]

       [address]:port
              Connect  to  the host at the specified address, and
              connect to the specified port (default:  smtp).  An
              IPv6 address must be formatted as [ipv6:address].

LMTP DESTINATION SYNTAX
       LMTP destinations have the following form:

       unix:pathname
              Connect  to  the  local  UNIX-domain server that is
              bound to the specified  pathname.  If  the  process
              runs  chrooted, an absolute pathname is interpreted
              relative to the Postfix queue directory.

       inet:hostname

       inet:hostname:port

       inet:[address]

       inet:[address]:port
              Connect to the specified TCP port on the  specified
              local or remote host. If no port is specified, con-
              nect to the port defined as  lmtp  in  services(4).
              If no such service is found, the lmtp_tcp_port con-
              figuration parameter (default value of 24) will  be
              used.    An  IPv6  address  must  be  formatted  as
              [ipv6:address].

SECURITY
       The SMTP+LMTP client is moderately security-sensitive.  It
       talks  to  SMTP  or LMTP servers and to DNS servers on the
       network. The SMTP+LMTP client can be run chrooted at fixed
       low privilege.

STANDARDS
       RFC 821 (SMTP protocol)
       RFC 822 (ARPA Internet Text Messages)
       RFC 1651 (SMTP service extensions)
       RFC 1652 (8bit-MIME transport)
       RFC 1870 (Message Size Declaration)
       RFC 2033 (LMTP protocol)
       RFC 2034 (SMTP Enhanced Error Codes)
       RFC 2045 (MIME: Format of Internet Message Bodies)
       RFC 2046 (MIME: Media Types)
       RFC 2554 (AUTH command)
       RFC 2821 (SMTP protocol)
       RFC 2920 (SMTP Pipelining)
       RFC 3207 (STARTTLS command)
       RFC 3461 (SMTP DSN Extension)
       RFC 3463 (Enhanced Status Codes)
       RFC 4954 (AUTH command)

DIAGNOSTICS
       Problems  and transactions are logged to syslogd(8).  Cor-
       rupted message files are marked so that the queue  manager
       can move them to the corrupt queue for further inspection.

       Depending on the setting of the notify_classes  parameter,
       the  postmaster is notified of bounces, protocol problems,
       and of other trouble.

BUGS
       SMTP and LMTP connection caching does not work  with  TLS.
       The  necessary  support for TLS object passivation and re-
       activation does not exist  without  closing  the  session,
       which defeats the purpose.

       SMTP and LMTP connection caching assumes that SASL creden-
       tials are valid for all destinations  that  map  onto  the
       same IP address and TCP port.

CONFIGURATION PARAMETERS
       Before  Postfix version 2.3, the LMTP client is a separate
       program that implements only a subset of the functionality
       available with SMTP: there is no support for TLS, and con-
       nections are cached in-process, making it ineffective when
       the client is used for multiple domains.

       Most  smtp_xxx  configuration  parameters have an lmtp_xxx
       "mirror" parameter for the equivalent LMTP  feature.  This
       document describes only those LMTP-related parameters that
       aren't simply "mirror" parameters.

       Changes to main.cf are picked up automatically, as smtp(8)
       processes  run  for only a limited amount of time. Use the
       command "postfix reload" to speed up a change.

       The text below provides  only  a  parameter  summary.  See
       postconf(5) for more details including examples.

COMPATIBILITY CONTROLS
       ignore_mx_lookup_error (no)
              Ignore DNS MX lookups that produce no response.

       smtp_always_send_ehlo (yes)
              Always send EHLO at the start of an SMTP session.

       smtp_never_send_ehlo (no)
              Never send EHLO at the start of an SMTP session.

       smtp_defer_if_no_mx_address_found (no)
              Defer  mail  delivery when no MX record resolves to
              an IP address.

       smtp_line_length_limit (990)
              The maximal length of message header and body lines
              that Postfix will send via SMTP.

       smtp_pix_workaround_delay_time (10s)
              How  long  the  Postfix  SMTP  client pauses before
              sending ".<CR><LF>" in order to work around the PIX
              firewall "<CR><LF>.<CR><LF>" bug.

       smtp_pix_workaround_threshold_time (500s)
              How  long a message must be queued before the Post-
              fix  SMTP  client  turns  on   the   PIX   firewall
              "<CR><LF>.<CR><LF>"  bug  workaround  for  delivery
              through firewalls with "smtp fixup" mode turned on.

       smtp_pix_workarounds (disable_esmtp, delay_dotcrlf)
              A  list that specifies zero or more workarounds for
              CISCO PIX firewall bugs.

       smtp_pix_workaround_maps (empty)
              Lookup tables, indexed by the  remote  SMTP  server
              address, with per-destination workarounds for CISCO
              PIX firewall bugs.

       smtp_quote_rfc821_envelope (yes)
              Quote addresses in SMTP MAIL FROM and RCPT TO  com-
              mands as required by RFC 2821.

       smtp_skip_5xx_greeting (yes)
              Skip SMTP servers that greet with a 5XX status code
              (go away, do not try again later).

       smtp_skip_quit_response (yes)
              Do not wait for the response to the SMTP QUIT  com-
              mand.

       Available in Postfix version 2.0 and earlier:

       smtp_skip_4xx_greeting (yes)
              Skip SMTP servers that greet with a 4XX status code
              (go away, try again later).

       Available in Postfix version 2.2 and later:

       smtp_discard_ehlo_keyword_address_maps (empty)
              Lookup tables, indexed by the  remote  SMTP  server
              address,  with  case insensitive lists of EHLO key-
              words (pipelining, starttls, auth, etc.)  that  the
              Postfix   SMTP  client  will  ignore  in  the  EHLO
              response from a remote SMTP server.

       smtp_discard_ehlo_keywords (empty)
              A case insensitive list of EHLO keywords  (pipelin-
              ing,  starttls,  auth,  etc.) that the Postfix SMTP
              client will ignore in  the  EHLO  response  from  a
              remote SMTP server.

       smtp_generic_maps (empty)
              Optional lookup tables that perform address rewrit-
              ing in the SMTP client, typically  to  transform  a
              locally valid address into a globally valid address
              when sending mail across the Internet.

       Available in Postfix version 2.2.9 and later:

       smtp_cname_overrides_servername (version dependent)
              Allow DNS CNAME records to override the  servername
              that the Postfix SMTP client uses for logging, SASL
              password lookup, TLS policy decisions, or TLS  cer-
              tificate verification.

       Available in Postfix version 2.3 and later:

       lmtp_discard_lhlo_keyword_address_maps (empty)
              Lookup  tables,  indexed  by the remote LMTP server
              address, with case insensitive lists of  LHLO  key-
              words  (pipelining,  starttls, auth, etc.) that the
              LMTP client will ignore in the LHLO response from a
              remote LMTP server.

       lmtp_discard_lhlo_keywords (empty)
              A  case insensitive list of LHLO keywords (pipelin-
              ing, starttls, auth, etc.)  that  the  LMTP  client
              will ignore in the LHLO response from a remote LMTP
              server.

       Available in Postfix version 2.4.4 and later:

       send_cyrus_sasl_authzid (no)
              When authenticating to a remote SMTP or LMTP server
              with  the default setting "no", send no SASL autho-
              riZation ID (authzid); send only the SASL authenti-
              Cation ID (authcid) plus the authcid's password.

       Available in Postfix version 2.5 and later:

       smtp_header_checks (empty)
              Restricted  header_checks(5) tables for the Postfix
              SMTP client.

       smtp_mime_header_checks (empty)
              Restricted  mime_header_checks(5)  tables  for  the
              Postfix SMTP client.

       smtp_nested_header_checks (empty)
              Restricted  nested_header_checks(5)  tables for the
              Postfix SMTP client.

       smtp_body_checks (empty)
              Restricted body_checks(5) tables  for  the  Postfix
              SMTP client.

       Available in Postfix version 2.6 and later:

       tcp_windowsize (0)
              An  optional  workaround for routers that break TCP
              window scaling.

MIME PROCESSING CONTROLS
       Available in Postfix version 2.0 and later:

       disable_mime_output_conversion (no)
              Disable the conversion of 8BITMIME format  to  7BIT
              format.

       mime_boundary_length_limit (2048)
              The  maximal  length  of  MIME  multipart  boundary
              strings.

       mime_nesting_limit (100)
              The maximal recursion level that the MIME processor
              will handle.

EXTERNAL CONTENT INSPECTION CONTROLS
       Available in Postfix version 2.1 and later:

       smtp_send_xforward_command (no)
              Send  the  non-standard  XFORWARD  command when the
              Postfix SMTP server EHLO response  announces  XFOR-
              WARD support.

SASL AUTHENTICATION CONTROLS
       smtp_sasl_auth_enable (no)
              Enable  SASL  authentication  in  the  Postfix SMTP
              client.

       smtp_sasl_password_maps (empty)
              Optional SMTP client lookup tables with  one  user-
              name:password  entry per remote hostname or domain,
              or sender address when sender-dependent authentica-
              tion is enabled.

       smtp_sasl_security_options (noplaintext, noanonymous)
              Postfix  SMTP  client  SASL security options; as of
              Postfix 2.3 the list of available features  depends
              on  the SASL client implementation that is selected
              with smtp_sasl_type.

       Available in Postfix version 2.2 and later:

       smtp_sasl_mechanism_filter (empty)
              If non-empty, a Postfix SMTP client filter for  the
              remote  SMTP  server's  list of offered SASL mecha-
              nisms.

       Available in Postfix version 2.3 and later:

       smtp_sender_dependent_authentication (no)
              Enable sender-dependent authentication in the Post-
              fix  SMTP  client; this is available only with SASL
              authentication,  and   disables   SMTP   connection
              caching  to ensure that mail from different senders
              will use the appropriate credentials.

       smtp_sasl_path (empty)
              Implementation-specific information that the  Post-
              fix  SMTP client passes through to the SASL plug-in
              implementation    that     is     selected     with
              smtp_sasl_type.

       smtp_sasl_type (cyrus)
              The  SASL plug-in type that the Postfix SMTP client
              should use for authentication.

       Available in Postfix version 2.5 and later:

       smtp_sasl_auth_cache_name (empty)
              An optional table to prevent repeated SASL  authen-
              tication  failures with the same remote SMTP server
              hostname, username and password.

       smtp_sasl_auth_cache_time (90d)
              The maximal  age  of  an  smtp_sasl_auth_cache_name
              entry before it is removed.

       smtp_sasl_auth_soft_bounce (yes)
              When  a remote SMTP server rejects a SASL authenti-
              cation request with a 535 reply  code,  defer  mail
              delivery  instead  of  returning mail as undeliver-
              able.

STARTTLS SUPPORT CONTROLS
       Detailed information about STARTTLS configuration  may  be
       found in the TLS_README document.

       smtp_tls_security_level (empty)
              The default SMTP TLS security level for the Postfix
              SMTP client; when a non-empty value  is  specified,
              this     overrides    the    obsolete    parameters
              smtp_use_tls,         smtp_enforce_tls,         and
              smtp_tls_enforce_peername.

       smtp_sasl_tls_security_options           ($smtp_sasl_secu-
       rity_options)
              The  SASL  authentication security options that the
              Postfix SMTP client uses  for  TLS  encrypted  SMTP
              sessions.

       smtp_starttls_timeout (300s)
              Time  limit  for Postfix SMTP client write and read
              operations during TLS startup  and  shutdown  hand-
              shake procedures.

       smtp_tls_CAfile (empty)
              A  file  containing  CA  certificates  of  root CAs
              trusted to sign either remote SMTP server  certifi-
              cates or intermediate CA certificates.

       smtp_tls_CApath (empty)
              Directory  with  PEM  format  certificate authority
              certificates that the Postfix SMTP client  uses  to
              verify a remote SMTP server certificate.

       smtp_tls_cert_file (empty)
              File  with  the Postfix SMTP client RSA certificate
              in PEM format.

       smtp_tls_mandatory_ciphers (medium)
              The minimum TLS cipher grade that the Postfix  SMTP
              client will use with mandatory TLS encryption.

       smtp_tls_exclude_ciphers (empty)
              List of ciphers or cipher types to exclude from the
              Postfix SMTP client cipher list at all TLS security
              levels.

       smtp_tls_mandatory_exclude_ciphers (empty)
              Additional  list  of  ciphers  or  cipher  types to
              exclude from the SMTP client cipher list at  manda-
              tory TLS security levels.

       smtp_tls_dcert_file (empty)
              File  with  the Postfix SMTP client DSA certificate
              in PEM format.

       smtp_tls_dkey_file ($smtp_tls_dcert_file)
              File with the Postfix SMTP client DSA  private  key
              in PEM format.

       smtp_tls_key_file ($smtp_tls_cert_file)
              File  with  the Postfix SMTP client RSA private key
              in PEM format.

       smtp_tls_loglevel (0)
              Enable additional Postfix SMTP  client  logging  of
              TLS activity.

       smtp_tls_note_starttls_offer (no)
              Log  the  hostname  of  a  remote  SMTP server that
              offers STARTTLS, when TLS is  not  already  enabled
              for that server.

       smtp_tls_policy_maps (empty)
              Optional lookup tables with the Postfix SMTP client
              TLS security policy by next-hop destination; when a
              non-empty  value  is  specified, this overrides the
              obsolete smtp_tls_per_site parameter.

       smtp_tls_mandatory_protocols (SSLv3, TLSv1)
              List of SSL/TLS protocols  that  the  Postfix  SMTP
              client will use with mandatory TLS encryption.

       smtp_tls_scert_verifydepth (9)
              The  verification depth for remote SMTP server cer-
              tificates.

       smtp_tls_secure_cert_match (nexthop, dot-nexthop)
              The server certificate peername verification method
              for the "secure" TLS security level.

       smtp_tls_session_cache_database (empty)
              Name  of  the  file containing the optional Postfix
              SMTP client TLS session cache.

       smtp_tls_session_cache_timeout (3600s)
              The expiration time of Postfix SMTP client TLS ses-
              sion cache information.

       smtp_tls_verify_cert_match (hostname)
              The server certificate peername verification method
              for the "verify" TLS security level.

       tls_daemon_random_bytes (32)
              The number of pseudo-random bytes that  an  smtp(8)
              or  smtpd(8)  process  requests  from the tlsmgr(8)
              server in order to seed its internal pseudo  random
              number generator (PRNG).

       tls_high_cipherlist
       (ALL:!EXPORT:!LOW:!MEDIUM:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "HIGH" grade ciphers.

       tls_medium_cipherlist (ALL:!EXPORT:!LOW:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "MEDIUM" or higher grade
              ciphers.

       tls_low_cipherlist (ALL:!EXPORT:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "LOW"  or  higher  grade
              ciphers.

       tls_export_cipherlist (ALL:+RC4:@@STRENGTH)
              The OpenSSL cipherlist for "EXPORT" or higher grade
              ciphers.

       tls_null_cipherlist (eNULL:!aNULL)
              The OpenSSL cipherlist  for  "NULL"  grade  ciphers
              that provide authentication without encryption.

       Available in Postfix version 2.4 and later:

       smtp_sasl_tls_verified_security_options
       ($smtp_sasl_tls_security_options)
              The  SASL  authentication security options that the
              Postfix SMTP client uses  for  TLS  encrypted  SMTP
              sessions with a verified server certificate.

       Available in Postfix version 2.5 and later:

       smtp_tls_fingerprint_cert_match (empty)
              List  of  acceptable remote SMTP server certificate
              fingerprints for  the  "fingerprint"  TLS  security
              level (smtp_tls_security_level = fingerprint).

       smtp_tls_fingerprint_digest (md5)
              The  message  digest  algorithm  used  to construct
              remote SMTP server certificate fingerprints.

       Available in Postfix version 2.6 and later:

       smtp_tls_protocols (!SSLv2)
              List of TLS protocols that the Postfix SMTP  client
              will  exclude  or  include  with  opportunistic TLS
              encryption.

       smtp_tls_ciphers (export)
              The minimum TLS cipher grade that the Postfix  SMTP
              client  will use with opportunistic TLS encryption.

       smtp_tls_eccert_file (empty)
              File with the Postfix SMTP client ECDSA certificate
              in PEM format.

       smtp_tls_eckey_file ($smtp_tls_eccert_file)
              File with the Postfix SMTP client ECDSA private key
              in PEM format.

OBSOLETE STARTTLS CONTROLS
       The following configuration parameters exist for  compati-
       bility with Postfix versions before 2.3. Support for these
       will be removed in a future release.

       smtp_use_tls (no)
              Opportunistic mode: use  TLS  when  a  remote  SMTP
              server  announces  STARTTLS support, otherwise send
              the mail in the clear.

       smtp_enforce_tls (no)
              Enforcement mode: require that remote SMTP  servers
              use  TLS  encryption,  and  never  send mail in the
              clear.

       smtp_tls_enforce_peername (yes)
              With mandatory TLS  encryption,  require  that  the
              remote SMTP server hostname matches the information
              in the remote SMTP server certificate.

       smtp_tls_per_site (empty)
              Optional lookup tables with the Postfix SMTP client
              TLS  usage  policy  by  next-hop destination and by
              remote SMTP server hostname.

       smtp_tls_cipherlist (empty)
              Obsolete Postfix < 2.3 control for the Postfix SMTP
              client TLS cipher list.

RESOURCE AND RATE CONTROLS
       smtp_destination_concurrency_limit      ($default_destina-
       tion_concurrency_limit)
              The  maximal  number  of parallel deliveries to the
              same destination  via  the  smtp  message  delivery
              transport.

       smtp_destination_recipient_limit        ($default_destina-
       tion_recipient_limit)
              The  maximal  number  of recipients per message for
              the smtp message delivery transport.

       smtp_connect_timeout (30s)
              The SMTP client time limit  for  completing  a  TCP
              connection,  or  zero  (use  the  operating  system
              built-in time limit).

       smtp_helo_timeout (300s)
              The SMTP client time limit for sending the HELO  or
              EHLO  command, and for receiving the initial server
              response.

       lmtp_lhlo_timeout (300s)
              The LMTP client time limit  for  sending  the  LHLO
              command,  and  for  receiving  the  initial  server
              response.

       smtp_xforward_timeout (300s)
              The SMTP client time limit for sending the XFORWARD
              command, and for receiving the server response.

       smtp_mail_timeout (300s)
              The  SMTP  client  time  limit for sending the MAIL
              FROM  command,  and  for   receiving   the   server
              response.

       smtp_rcpt_timeout (300s)
              The  SMTP  client  time  limit for sending the SMTP
              RCPT TO  command,  and  for  receiving  the  server
              response.

       smtp_data_init_timeout (120s)
              The  SMTP  client  time  limit for sending the SMTP
              DATA  command,  and  for   receiving   the   server
              response.

       smtp_data_xfer_timeout (180s)
              The  SMTP  client  time  limit for sending the SMTP
              message content.

       smtp_data_done_timeout (600s)
              The SMTP client time limit  for  sending  the  SMTP
              ".", and for receiving the server response.

       smtp_quit_timeout (300s)
              The  SMTP  client  time  limit for sending the QUIT
              command, and for receiving the server response.

       Available in Postfix version 2.1 and later:

       smtp_mx_address_limit (5)
              The  maximal  number  of  MX  (mail  exchanger)  IP
              addresses  that  can  result  from  mail  exchanger
              lookups, or zero (no limit).

       smtp_mx_session_limit (2)
              The maximal number of SMTP  sessions  per  delivery
              request  before  giving up or delivering to a fall-
              back relay host, or zero (no limit).

       smtp_rset_timeout (20s)
              The SMTP client time limit  for  sending  the  RSET
              command, and for receiving the server response.

       Available in Postfix version 2.2 and earlier:

       lmtp_cache_connection (yes)
              Keep Postfix LMTP client connections open for up to
              $max_idle seconds.

       Available in Postfix version 2.2 and later:

       smtp_connection_cache_destinations (empty)
              Permanently enable SMTP connection caching for  the
              specified destinations.

       smtp_connection_cache_on_demand (yes)
              Temporarily  enable SMTP connection caching while a
              destination has a high volume of mail in the active
              queue.

       smtp_connection_reuse_time_limit (300s)
              The amount of time during which Postfix will use an
              SMTP connection repeatedly.

       smtp_connection_cache_time_limit (2s)
              When SMTP connection caching is enabled, the amount
              of  time  that an unused SMTP client socket is kept
              open before it is closed.

       Available in Postfix version 2.3 and later:

       connection_cache_protocol_timeout (5s)
              Time limit for connection cache  connect,  send  or
              receive operations.

TROUBLE SHOOTING CONTROLS
       debug_peer_level (2)
              The  increment  in  verbose  logging  level  when a
              remote client or server matches a  pattern  in  the
              debug_peer_list parameter.

       debug_peer_list (empty)
              Optional  list  of remote client or server hostname
              or network address patterns that cause the  verbose
              logging  level  to increase by the amount specified
              in $debug_peer_level.

       error_notice_recipient (postmaster)
              The recipient  of  postmaster  notifications  about
              mail  delivery  problems that are caused by policy,
              resource, software or protocol errors.

       internal_mail_filter_classes (empty)
              What categories of Postfix-generated mail are  sub-
              ject   to   before-queue   content   inspection  by
              non_smtpd_milters, header_checks and body_checks.

       notify_classes (resource, software)
              The list of error classes that are reported to  the
              postmaster.

MISCELLANEOUS CONTROLS
       best_mx_transport (empty)
              Where  the  Postfix SMTP client should deliver mail
              when it detects a "mail loops back to myself" error
              condition.

       config_directory (see 'postconf -d' output)
              The  default  location  of  the Postfix main.cf and
              master.cf configuration files.

       daemon_timeout (18000s)
              How much time a Postfix daemon process may take  to
              handle  a  request  before  it  is  terminated by a
              built-in watchdog timer.

       delay_logging_resolution_limit (2)
              The maximal number  of  digits  after  the  decimal
              point when logging sub-second delay values.

       disable_dns_lookups (no)
              Disable  DNS  lookups  in the Postfix SMTP and LMTP
              clients.

       inet_interfaces (all)
              The network interface addresses that this mail sys-
              tem receives mail on.

       inet_protocols (ipv4)
              The  Internet protocols Postfix will attempt to use
              when making or accepting connections.

       ipc_timeout (3600s)
              The time limit for sending or receiving information
              over an internal communication channel.

       lmtp_assume_final (no)
              When  an  LMTP  server  announces  no  DSN support,
              assume that the server performs final delivery, and
              send   "delivered"  delivery  status  notifications
              instead of "relayed".

       lmtp_tcp_port (24)
              The default TCP port that the Postfix  LMTP  client
              connects to.

       max_idle (100s)
              The  maximum  amount  of  time that an idle Postfix
              daemon process waits  for  an  incoming  connection
              before terminating voluntarily.

       max_use (100)
              The  maximal  number of incoming connections that a
              Postfix daemon process will service  before  termi-
              nating voluntarily.

       process_id (read-only)
              The  process  ID  of  a  Postfix  command or daemon
              process.

       process_name (read-only)
              The process name of a  Postfix  command  or  daemon
              process.

       proxy_interfaces (empty)
              The network interface addresses that this mail sys-
              tem receives mail on by way of a proxy  or  network
              address translation unit.

       smtp_bind_address (empty)
              An  optional  numerical  network  address  that the
              Postfix SMTP client should bind to when  making  an
              IPv4 connection.

       smtp_bind_address6 (empty)
              An  optional  numerical  network  address  that the
              Postfix SMTP client should bind to when  making  an
              IPv6 connection.

       smtp_helo_name ($myhostname)
              The  hostname to send in the SMTP EHLO or HELO com-
              mand.

       lmtp_lhlo_name ($myhostname)
              The hostname to send in the LMTP LHLO command.

       smtp_host_lookup (dns)
              What mechanisms when the Postfix SMTP  client  uses
              to look up a host's IP address.

       smtp_randomize_addresses (yes)
              Randomize  the  order  of  equal-preference MX host
              addresses.

       syslog_facility (mail)
              The syslog facility of Postfix logging.

       syslog_name (see 'postconf -d' output)
              The mail system  name  that  is  prepended  to  the
              process  name  in  syslog  records, so that "smtpd"
              becomes, for example, "postfix/smtpd".

       Available with Postfix 2.2 and earlier:

       fallback_relay (empty)
              Optional list of relay hosts for SMTP  destinations
              that can't be found or that are unreachable.

       Available with Postfix 2.3 and later:

       smtp_fallback_relay ($fallback_relay)
              Optional  list of relay hosts for SMTP destinations
              that can't be found or that are unreachable.

SEE ALSO
       generic(5), output address rewriting
       header_checks(5), message header content inspection
       body_checks(5), body parts content inspection
       qmgr(8), queue manager
       bounce(8), delivery status reports
       scache(8), connection cache server
       postconf(5), configuration parameters
       master(5), generic daemon options
       master(8), process manager
       tlsmgr(8), TLS session and PRNG management
       syslogd(8), system logging

README FILES
       SASL_README, Postfix SASL howto
       TLS_README, Postfix STARTTLS howto

LICENSE
       The  Secure  Mailer  license must be distributed with this
       software.

AUTHOR(S)
       Wietse Venema
       IBM T.J. Watson Research
       P.O. Box 704
       Yorktown Heights, NY 10598, USA

       Command pipelining in cooperation with:
       Jon Ribbens
       Oaktree Internet Solutions Ltd.,
       Internet House,
       Canal Basin,
       Coventry,
       CV1 4LY, United Kingdom.

       SASL support originally by:
       Till Franke
       SuSE Rhein/Main AG
       65760 Eschborn, Germany

       TLS support originally by:
       Lutz Jaenicke
       BTU Cottbus
       Allgemeine Elektrotechnik
       Universitaetsplatz 3-4
       D-03044 Cottbus, Germany

       Revised TLS and SMTP connection cache support by:
       Victor Duchovni
       Morgan Stanley

                                                                       SMTP(8)
@ 1.1.1.1.2.3 log @Pull up following revision(s) (requested by tron in ticket #1425): Update Postfix to version 2.7.1: - Improved before-queue content filter performance. With "smtpd_proxy_options = speed_adjust", the Postfix SMTP server receives the entire message before it connects to a before-queue content filter. Typically, this allows Postfix to handle the same mail load with fewer content filter processes. - Improved address verification performance. The verify database is now persistent by default, and it is automatically cleaned periodically. Under overload conditions, the Postfix SMTP server no longer waits up to 6 seconds for an address probe to complete. - Support for reputation management based on the local SMTP client IP address. This is typically implemented with "FILTER transportname:" actions in access maps or header/body checks, and mail delivery transports in master.cf with unique smtp_bind_address values. @ text @a198 4 smtp_reply_filter (empty) A mechanism to transform replies from remote SMTP servers one line at a time. d204 1 a204 1 Do not wait for the response to the SMTP QUIT com- d216 4 a219 4 Lookup tables, indexed by the remote SMTP server address, with case insensitive lists of EHLO key- words (pipelining, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO d223 3 a225 3 A case insensitive list of EHLO keywords (pipelin- ing, starttls, auth, etc.) that the Postfix SMTP client will ignore in the EHLO response from a d230 1 a230 1 ing in the SMTP client, typically to transform a d237 1 a237 1 Allow DNS CNAME records to override the servername d239 1 a239 1 password lookup, TLS policy decisions, or TLS cer- d245 3 a247 3 Lookup tables, indexed by the remote LMTP server address, with case insensitive lists of LHLO key- words (pipelining, starttls, auth, etc.) that the d252 2 a253 2 A case insensitive list of LHLO keywords (pipelin- ing, starttls, auth, etc.) that the LMTP client d261 1 a261 1 with the default setting "no", send no SASL autho- d268 1 a268 1 Restricted header_checks(5) tables for the Postfix d276 1 a276 1 Restricted nested_header_checks(5) tables for the d280 1 a280 1 Restricted body_checks(5) tables for the Postfix d286 1 a286 1 An optional workaround for routers that break TCP d293 1 a293 1 Disable the conversion of 8BITMIME format to 7BIT d308 2 a309 2 Send the non-standard XFORWARD command when the Postfix SMTP server EHLO response announces XFOR- d314 1 a314 1 Enable SASL authentication in the Postfix SMTP d318 2 a319 2 Optional SMTP client lookup tables with one user- name:password entry per remote hostname or domain, d324 3 a326 3 Postfix SMTP client SASL security options; as of Postfix 2.3 the list of available features depends on the SASL client implementation that is selected d332 2 a333 2 If non-empty, a Postfix SMTP client filter for the remote SMTP server's list of offered SASL mecha- d340 3 a342 3 fix SMTP client; this is available only with SASL authentication, and disables SMTP connection caching to ensure that mail from different senders d346 3 a348 3 Implementation-specific information that the Post- fix SMTP client passes through to the SASL plug-in implementation that is selected with d352 1 a352 1 The SASL plug-in type that the Postfix SMTP client d358 2 a359 2 An optional table to prevent repeated SASL authen- tication failures with the same remote SMTP server d363 1 a363 1 The maximal age of an smtp_sasl_auth_cache_name d367 3 a369 3 When a remote SMTP server rejects a SASL authenti- cation request with a 535 reply code, defer mail delivery instead of returning mail as undeliver- d373 1 a373 1 Detailed information about STARTTLS configuration may be d378 2 a379 2 SMTP client; when a non-empty value is specified, this overrides the obsolete parameters d385 2 a386 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d390 2 a391 2 Time limit for Postfix SMTP client write and read operations during TLS startup and shutdown hand- d395 2 a396 2 A file containing CA certificates of root CAs trusted to sign either remote SMTP server certifi- d400 2 a401 2 Directory with PEM format certificate authority certificates that the Postfix SMTP client uses to d405 1 a405 1 File with the Postfix SMTP client RSA certificate d409 1 a409 1 The minimum TLS cipher grade that the Postfix SMTP d418 2 a419 2 Additional list of ciphers or cipher types to exclude from the SMTP client cipher list at manda- d423 1 a423 1 File with the Postfix SMTP client DSA certificate d427 1 a427 1 File with the Postfix SMTP client DSA private key d431 1 a431 1 File with the Postfix SMTP client RSA private key d435 1 a435 1 Enable additional Postfix SMTP client logging of d439 2 a440 2 Log the hostname of a remote SMTP server that offers STARTTLS, when TLS is not already enabled d446 1 a446 1 non-empty value is specified, this overrides the d450 1 a450 1 List of SSL/TLS protocols that the Postfix SMTP d454 1 a454 1 The verification depth for remote SMTP server cer- d462 1 a462 1 Name of the file containing the optional Postfix d474 3 a476 3 The number of pseudo-random bytes that an smtp(8) or smtpd(8) process requests from the tlsmgr(8) server in order to seed its internal pseudo random d488 1 a488 1 The OpenSSL cipherlist for "LOW" or higher grade d496 1 a496 1 The OpenSSL cipherlist for "NULL" grade ciphers d503 2 a504 2 The SASL authentication security options that the Postfix SMTP client uses for TLS encrypted SMTP d510 2 a511 2 List of acceptable remote SMTP server certificate fingerprints for the "fingerprint" TLS security d515 1 a515 1 The message digest algorithm used to construct d521 2 a522 2 List of TLS protocols that the Postfix SMTP client will exclude or include with opportunistic TLS d526 2 a527 2 The minimum TLS cipher grade that the Postfix SMTP client will use with opportunistic TLS encryption. a536 8 Available in Postfix version 2.7 and later: smtp_tls_block_early_mail_reply (no) Try to detect a mail hijacking attack based on a TLS protocol vulnerability (CVE-2009-3555), where an attacker prepends malicious HELO, MAIL, RCPT, DATA commands to a Postfix SMTP client TLS session. d538 1 a538 1 The following configuration parameters exist for compati- d543 2 a544 2 Opportunistic mode: use TLS when a remote SMTP server announces STARTTLS support, otherwise send d548 2 a549 2 Enforcement mode: require that remote SMTP servers use TLS encryption, and never send mail in the d553 1 a553 1 With mandatory TLS encryption, require that the d559 1 a559 1 TLS usage policy by next-hop destination and by d569 2 a570 2 The maximal number of parallel deliveries to the same destination via the smtp message delivery d575 1 a575 1 The maximal number of recipients per message for d579 1 a579 1 The SMTP client time limit for completing a TCP d584 2 a585 2 The SMTP client time limit for sending the HELO or EHLO command, and for receiving the initial server d589 1 a589 1 The LMTP client time limit for sending the LHLO d598 2 a599 2 The SMTP client time limit for sending the MAIL FROM command, and for receiving the server d603 2 a604 2 The SMTP client time limit for sending the SMTP RCPT TO command, and for receiving the server d608 2 a609 2 The SMTP client time limit for sending the SMTP DATA command, and for receiving the server d613 1 a613 1 The SMTP client time limit for sending the SMTP d617 1 a617 1 The SMTP client time limit for sending the SMTP d621 1 a621 1 The SMTP client time limit for sending the QUIT d632 2 a633 2 The maximal number of SMTP sessions per delivery request before giving up or delivering to a fall- d637 1 a637 1 The SMTP client time limit for sending the RSET d649 1 a649 1 Permanently enable SMTP connection caching for the d653 1 a653 1 Temporarily enable SMTP connection caching while a d663 1 a663 1 of time that an unused SMTP client socket is kept d669 1 a669 1 Time limit for connection cache connect, send or d674 2 a675 2 The increment in verbose logging level when a remote client or server matches a pattern in the d679 3 a681 3 Optional list of remote client or server hostname or network address patterns that cause the verbose logging level to increase by the amount specified d685 2 a686 2 The recipient of postmaster notifications about mail delivery problems that are caused by policy, d690 2 a691 2 What categories of Postfix-generated mail are sub- ject to before-queue content inspection by d695 1 a695 1 The list of error classes that are reported to the d700 1 a700 1 Where the Postfix SMTP client should deliver mail d705 1 a705 1 The default location of the Postfix main.cf and d709 2 a710 2 How much time a Postfix daemon process may take to handle a request before it is terminated by a d714 1 a714 1 The maximal number of digits after the decimal d718 1 a718 1 Disable DNS lookups in the Postfix SMTP and LMTP d726 1 a726 1 The Internet protocols Postfix will attempt to use d734 1 a734 1 When an LMTP server announces no DSN support, d736 1 a736 1 send "delivered" delivery status notifications d740 1 a740 1 The default TCP port that the Postfix LMTP client d744 2 a745 2 The maximum amount of time that an idle Postfix daemon process waits for an incoming connection d749 2 a750 2 The maximal number of incoming connections that a Postfix daemon process will service before termi- d754 1 a754 1 The process ID of a Postfix command or daemon d758 1 a758 1 The process name of a Postfix command or daemon d763 1 a763 1 tem receives mail on by way of a proxy or network d767 2 a768 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d772 2 a773 2 An optional numerical network address that the Postfix SMTP client should bind to when making an d777 1 a777 1 The hostname to send in the SMTP EHLO or HELO com- d784 2 a785 2 What mechanisms the Postfix SMTP client uses to look up a host's IP address. d788 1 a788 1 Randomize the order of equal-preference MX host d795 2 a796 2 The mail system name that is prepended to the process name in syslog records, so that "smtpd" d802 1 a802 1 Optional list of relay hosts for SMTP destinations d808 1 a808 1 Optional list of relay hosts for SMTP destinations d829 1 a829 1 The Secure Mailer license must be distributed with this @