The Postfix 3.9.0 mail server has been released

After nearly a year of development, the release of the new stable branch of the Postfix mail server — 3.9.0 — has occurred. At the same time, support for Postfix version 3.5, released in early 2020, has been discontinued. Postfix is one of the rare projects that combines high security, reliability, and performance, achieved through thoughtful architecture and a stringent code formatting and patch auditing policy. The project's code is written in C and distributed under the EPL 2.0 (Eclipse Public License) and IPL 1.0 (IBM Public License).

According to a January automated survey of approximately 400,000 mail servers, serversPostfix is used on 36.81% (up from 33.18% a year ago) of mail servers, Exim holds 56.61% (down from 60.27%), Sendmail — 3.60% (down from 3.62%), MailEnable — 1.82% (down from 1.86%), MDaemon — 0.40% (up from 0.39%), Microsoft Exchange — 0.19% (unchanged), OpenSMTPD — 0.09% (up from 0.06%).

The Postfix 3.9.0 mail server has been released

Key innovations:

  • A client for MongoDB has been added, allowing the storage of a virtual user database, aliases, address mapping lists, and various verification tables in this DBMS. For configuring access to MongoDB, a new table type 'mongodb' has been added. For example, 'alias_maps = proxy:mongodb:/etc/postfix/mongo.cf', where mongo.cf is the configuration file for connecting to MongoDB and filtering queries.
  • In the local delivery agent, an export of the forwarding identifier, provided during the SMTP session via the ENVID (Envelope ID) parameter in the ESMTP MAIL command (RFC 3461), has been added. The identifier is written to the ENVID environment variable and passed to the delivery agent pipe via the command line parameter '${envid}'.
  • Parameters have been added to the clients for storing data in MySQL ('mysql:') and PostgreSQL ('pgsql:'): 'idle_interval' to determine the inactivity time before closing the connection and 'retry_interval' to set the timer for resending requests. By default, these parameters are set to 60 seconds. The value of 'retry_interval' can be decreased, for example, to shorten recovery time after errors when using only one server in the 'hosts' attribute.
  • In the MySQL client, a 'charset' setting has been added to specify the default character encoding. By default, it uses 'utf8mb4', which corresponds to the default settings in MySQL 8.0 (in earlier releases, 'latin1' was used). Support for versions older than MySQL 4.0 (i.e., versions released before 2003) has been discontinued.
  • An optional feature has been provided to request a self-signed (raw) public key for TLS, independent of a certificate authority, instead of an X.509 certificate. The use of raw keys for client and server authentication can be enabled via the parameters 'smtpd_tls_enable_rpk = yes' and 'smtp_tls_enable_rpk = yes', but the behavior during verification heavily depends on the security level set and the local implementation support for raw keys in TLS (see documentation).
  • Initial support for OpenSSL configuration files has been added. The parameter 'tls_config_file' is proposed for referencing a TLS settings file, and the parameter 'tls_config_name' is used to specify the section name with settings from the configuration file. Binding to OpenSSL configuration files can be used to reduce dependency on distribution settings, the change of which may lead to an increase in the proportion of messages sent without encryption.
  • The formatting of day numbers in dates in message headers has been changed — days from 1 to 9 are now prefixed with a zero instead of a space (i.e. '01', '02', etc.). This change was made as RFC 5322 recommends using single spaces as separators in dates.
  • Protection against certain types of 'Blind' attacks (SSRF attacks on web clients targeting access to servers via SMTP) has been added, applied with the setting 'smtpd_forbid_unauth_pipelining = yes' (by default).
  • By default, the setting 'smtpd_forbid_bare_newline = normalize' is enabled, providing the server with protection against 'SMTP smuggling' attacks, which can split a single message into multiple different messages using a non-standard sequence for separating emails. Additionally, protection against outgoing SMTP smuggling attacks has been added, where an attacker uses a Postfix-based server to attack another SMTP server. By default, the setting 'cleanup_replace_stray_cr_lf = yes' is enabled, which replaces extra and characters with spaces.
  • In the DNS client implementation, the size of returned results for DNS queries is now limited to 100 records, which is 20 times more than the maximum supported in the SMTP client. (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community. for a single server.
  • The parameters 'disable_dns_lookup' and 'permit_mx_backup' have been classified as deprecated, as well as some TLS configuration parameters.
  • Support for settings that were declared deprecated nearly 20 years ago has been discontinued: "permit_naked_ip_address," "check_relay_domains," and "reject_maps_rbl."

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster