The mail server Postfix 3.10.0 has been released.

After nearly a year of development, a new stable release of the Postfix mail server — 3.10.0 — has been published. At the same time, support for the Postfix 3.6 branch, released in early 2021, has been discontinued. The project's code is written in C and is distributed under the EPL 2.0 (Eclipse Public License) and IPL 1.0 (IBM Public License).

Postfix is one of the rare projects that combines high security, reliability, and performance, achieved through a multi-processing architecture that isolates individual handlers, along with a strict code formatting and patch auditing policy. To protect against memory errors, the project uses secure variants of functions for memory allocation and deallocation, as well as a set of abstract wrapper functions for working with buffers (which check for buffer overflows and access to freed memory), file operations, output formatting, buffered input/output, and string manipulation (including capabilities for handling strings of arbitrary size and automatic resizing).

According to a February automated survey of around 550,000 mail servers, serversPostfix is used on 37.64% (up from 36.81% a year ago) of mail servers, while Exim holds 56.03% (down from 56.61%), Sendmail — 3.39% (down from 3.60%), MailEnable — 1.80% (down from 1.82%), MDaemon — 0.39% (down from 0.40%), Microsoft Exchange — 0.19% (unchanged), and OpenSMTPD — 0.10% (up from 0.09%).

The mail server Postfix 3.10.0 has been released.

Key innovations:

  • The ability to use quantum-resistant cryptographic algorithms in TLS has been added. To use these algorithms, the OpenSSL library branch 3.5 is required, which is still in development. New TLS group syntax for post-quantum algorithms has not been introduced in Postfix; instead, it relies on OpenSSL settings that will be applied when setting the parameters 'tls_eecdh_auto_curves' and 'tls_ffdhe_auto_groups' to empty values.
  • Support for the message header 'TLS-Required: no' (RFC 8689) has been added, under which delivery will occur even when the specified TLS security policy cannot be implemented. With this header present, the SMTP client operates in 'smtp_tls_security_level = may' mode, meaning it does not check the certificate. server It can revert to a plaintext data transfer connection. In the next significant version of Postfix, we aim to implement the SMTP extension REQUIRETLS.
  • Support has been added for the TLS-RPT (Transport Layer Security Reporting) protocol, which allows tracking delivery failures that occur when a secure connection mandated by the use of DANE (DNS-based Authentication of Named Entities) or MTA-STS (MTA Strict Transport Security) extensions cannot be established. The owner of a mail domain defines the parameters for TLS-RPT in DNS, after which mail servers will send reports with information about successful and failed TLS connections to the MX servers servicing the domain. The implementation is based on the libtlsrpt library.
  • A new setting "smtpd_hide_client_session = yes" has been introduced, which disables the insertion of client session information when the SMTP server substitutes the "Received:" header. An example of a truncated header is: "Received: by mail.example.com (Postfix) id postfix-queue-id for ; Day, dd Mon yyyy hh:mm:ss tz-offset (zone)".
  • The ability to MIME-encode (RFC 2047) names in generated Postfix headers "From:" that include non-ASCII characters has been added. The proposed encoding scheme allows bypassing the use of the SMTPUTF8 extension (RFC 6531), which is not supported by all applications. The result of MIME-encoding appears as ‘"=?charset?Q?gibberish?=‘. A parameter "full_name_encoding_charset" has been added to determine the original encoding of names, defaulting to utf8.
  • The logic for handling failed connections has been modified when specifying only one server in the settings for "mysql:" or "pgsql:". Such a server is now treated as a load balancer, and in the case of a single failure, the retry request is sent immediately, without a 60-second delay.
  • In Milter, the logging of information regarding the reason for placing a message in quarantine has been implemented.
  • In the SMTP server, the logging of the queue identifier or the value "NOQUEUE" is ensured when a connection is terminated due to a timeout, disruption, or exceeding the limit on the number of errors. The cleanup process logs "queueid: canceled" for messages with a transaction that was started but not completed.
  • In the Dovecot SASL client, when logging the message 'Invalid authentication mechanism,' the authentication mechanism that failed to be used is now indicated. The SMTP server now logs 'reject' entries showing the values of the sasl_method, sasl_username, and sasl_sender settings.
  • Due to changes in the internal protocol used by the delivery agent, after updating Postfix, a restart is required using the command 'postfix reload' or with the commands 'postfix stop' and 'postfix start.' Otherwise, a warning will be logged: 'unexpected attribute smtputf8 from xxx socket (expecting: sendopts).'

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster