The new version of the Exim mail server 4.93

After 10 months of development the release of the mail server Exim 4.93, which includes accumulated fixes and new features. In accordance with the November automated survey approximately one million mail servers, with Exim holding 56.90% share (up from 56.56% a year ago), Postfix is used on 34.98% (33.79%) of mail servers, Sendmail accounts for 3.90% (5.59%), and Microsoft Exchange has a share of 0.51% (0.85%).

Key changes:

  • Support for external authenticators (RFC 4422). Using the "SASL EXTERNAL" command, a client can inform the server about the use of authentication credentials provided through external services such as IP Security (RFC4301) and TLS;
  • The ability to use JSON format for lookup checks has been added. Also, conditional mask options "forall" and "any" that utilize JSON have been introduced.
  • New variables $tls_in_cipher_std and $tls_out_cipher_std have been added, containing the names of cipher suites corresponding to the names in the RFC.
  • New flags have been added to control the reflection of message identifiers in the log (set through the setting log_selector): "msg_id" (enabled by default) with the message identifier, and "msg_id_created" with the new message's generated identifier.
  • Support for the "case_insensitive" option has been added to the "verify=not_blind" mode for ignoring character case during checks.
  • An experimental option EXPERIMENTAL_TLS_RESUME has been added to allow the resumption of previously interrupted TLS connections.
  • The exim_version option has been added to override the version number string displayed in various places and passed through the $exim_version and $version_number variables.
  • Variants of the operator ${sha2_N:} have been added for N=256, 384, 512.
  • The variables "$r_…" have been implemented, set from routing options and available for use during routing decisions and transport selection.
  • Support for IPv6 has been added in SPF lookup queries.
  • When performing checks via DKIM, the ability to filter by key types and hashes has been added.
  • With TLS 1.3, support for the OCSP (Online Certificate Status Protocol) extension has been provided for of verification certificate revocation status.
  • An event "smtp:ehlo" has been added to monitor the capabilities provided by the remote party.
  • A command-line option has been added for moving messages from one named queue to another.
  • Variables for TLS versions for incoming and outgoing requests have been introduced — $tls_in_ver and $tls_out_ver.
  • With OpenSSL, a feature has been added to log files with keys in NSS format for decoding intercepted network packets. The file name is set through the environment variable SSLKEYLOGFILE. When built with GnuTLS, similar functionality is provided by GnuTLS tools but requires root permissions.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster