Nooca cusub ee server-ka Exim mail 4.94

Kadib 6 bilood oo horumar ah dhacay sii daynta serverka boostada Exim 4.94, kaas oo sixitaan urursan lagu sameeyay laguna soo kordhiyay astaamo cusub. Sida ku cad May sahamin toos ah Qiyaastii hal milyan oo adeegayaal boosto ah, saamiga Exim waa 57.59% (sanad ka hor 53.03%), Postfix waxaa loo isticmaalaa 34.70% (34.51%) ee server-yada boostada, Sendmail - 3.75% (4.05%), Microsoft Exchange - 0.42% 0.57%).

Isbeddellada ku yimaadda sii-deynta cusub waxa laga yaabaa inay jebiyaan iswaafajinta gadaal. Gaar ahaan, noocyada gaadiidka qaarkood kuma shaqeeyaan xogta wasakhaysan (qiimaha ku saleysan xogta laga helay soo-diraha) marka la go'aaminayo goobta la geynayo. Tusaale ahaan, dhibaatooyin ayaa soo bixi kara marka la isticmaalayo doorsoomiyaha $local_part ee goobta “check_local_user” marka xaraf la wareegayo. Doorsoomiyaha cusub ee la nadiifiyay "$ local_part_data" waa in la isticmaalo bedelkii $local_part. Intaa waxaa dheer, hawl-wadeennada ikhtiyaarka madaxa_remove hadda waxay oggolaadaan adeegsiga waji-xidhaha lagu qeexay jilaha "*", kaas oo jebin kara qaabaynta ka saara madax-weyneyaasha ku dhammaanaya calaamad (ka saar maaskaro halkii aad ka saari lahayd madaxyo gaar ah).

Main isbedel:

  • Taageero tijaabo ah oo lagu daray habka SRS (Qorshaha Dib-u-qorista Soo-diraha), kaas oo kuu ogolaanaya inaad dib u qorto ciwaanka soo diraha markaad gudbinayso adigoon jebin jeegaga SPFQaabdhismeedka Siyaasadda Dirayaasha) iyo in la hubiyo in macluumaadka soo-diraha la keydiyo si server-ku uu fariimaha u soo diro haddii ay dhacdo khalad gaarsiinta. Nuxurka habka ayaa ah in marka xiriir la sameeyo, macluumaadka ku saabsan aqoonsiga ee soo diraha asalka ah la gudbiyo, tusaale ahaan, marka dib loo qoro [emailka waa la ilaaliyay] on [emailka waa la ilaaliyay] ayaa lagu tilmaami doonaa"[emailka waa la ilaaliyay]" SRS waxay khusaysaa, tusaale ahaan, marka la abaabulayo shaqada liisaska boostada taaso fariinta asalka ah loo wareejiyo kuwa kale.
  • Markaad isticmaalayso OpenSSL, taageero lagu daray ku xidhidhiyaha kanaalka xaqiiqeeyayaasha (horey u taageeri jiray kaliya GnuTLS).
  • Lagu daray "msg:defer" dhacdo.
  • Taageerada la hirgaliyay ee gsasl-dhinaca macmiilka xaqiijiyaha, kaas oo kaliya lagu tijaabiyay maamulaha sirta ah ee qoraalka ah. Hawlgalka hababka SCRAM-SHA-256 iyo SCRAM-SHA-256-PLUS waxay suurtogal tahay oo keliya gssl.
  • Taageerada xaqiijinta gsasl dhinaca server-ka ee furaha sirta ah ayaa la hirgeliyay, iyada oo u adeegaysa beddelka qaabka qoraalka cad ee hore loo heli karo.
  • Qeexitaannada ku jira liisaska la magacaabay hadda waxaa lagu horgeeyaa "qarin" si loo xakameeyo wax soo saarka nuxurka marka la fulinayo amarka "-bP".
  • Taageerada tijaabada ah ee saldhigyada internetka ayaa lagu daray darawalka xaqiijinta iyada oo loo sii marayo server-ka Dovecot IMAP (horay kaliya saldhigyada domain-kaliya ayaa la taageeray).
  • Odhaahda ACL "kuyuu_kaliya" ayaa hadda lagu qeexi karaa "kuyuu" oo waxay taageertaa doorashada "first_pass_route", oo la mid ah "-odqs" xulashada khadka taliska.
  • Lagu daray doorsoomayaal cusub $ safka_size iyo $local_part_{pre,suf}fix_v.
  • Waxaa lagu daray "sqlite_dbfile" ikhtiyaarka qaabeynta ugu weyn ee isticmaalka marka la qeexayo horgalaha xargaha raadinta. Isbeddelku waxa uu jebiyaa is-waafajinta gadaal-habkii hore ee dejinta horgalayaasha hadda ma shaqeeyo marka la tilmaamayo doorsoomayaasha wasakhaysan ee ku jira weydiimaha raadinta. Qaab cusub ("sqlite_dbfile") ayaa kuu ogolaanaya inaad magaca faylka gooni u dhigto.
  • Ikhtiyaarada lagu daray raadinta baloogyada raadinta si loo soo celiyo dariiqa buuxda oo loo shaandheeyo noocyada faylalka marka la is waafajiyo.
  • Ikhtiyaarada ayaa lagu daray pgsql iyo mysql search blocks si loo cadeeyo magaca serverka oo ka duwan xadhiga raadinta.
  • Baloogyada raadinta ee doorta hal fure, waxaa lagu daray ikhtiyaarka ah in lagu soo celiyo nooca furaha ee aan wasakhnayn haddii ay jiraan tabarrucyo, halkii xogta la raadiyay.
  • Dhammaan xulashooyinka liiska-kulan ee guusha leh, $domain_data iyo $doorsoomayaasha_data_ localpart_waa la dajiyay (horay, liiska canaasiirta ku lug leh xulashada waa la geliyey). Intaa waxaa dheer, liiska canaasiirta loo isticmaalay isbarbardhigga ayaa hadda loo qoondeeyay doorsoomayaasha $0, $1, iwm.
  • Hawlwadeen balaadhinta lagu daray "${listquote { } { }}".
  • Ikhtiyaar ayaa lagu daray ${readsocket {}{}{}} hawlwadeenka ballaarinta si loogu ogolaado natiijooyinka in la kaydiyo.
  • Lagu daray dkim_verify_min_keysizes si ay u taxdo tirada ugu yar ee furaha dadweynaha ee la ogolyahay.
  • La hubiyay in "bounce_message_file" iyo "warn_message_file" la ballaariyay ka hor inta aan la isticmaalin markii ugu horeysay.
  • Doorashada lagu daray "spf_smtp_comment_template" si loo habeeyo qiimaha doorsoomaha "$ spf_smtp_comment".

Source: opennet.ru

Add a comment