Uguqulelo olutsha lwe-Exim 4.93 yomncedisi weposi

Emva kweenyanga ezi-10 zophuhliso yathatha indawo ukukhutshwa kweseva yemeyile Exim 4.93, apho izilungiso eziqokelelweyo zenziwe kwaye iimpawu ezintsha zongezwa. Ngokuhambelana noNovemba uphando oluzenzekelayo malunga nesigidi sabancedisi beposi, isabelo sika-Exim yi-56.90% (kunyaka ophelileyo 56.56%), i-Postfix isetyenziswa kwi-34.98% (33.79%) yeeseva zeposi, i-Sendmail - 3.90% (5.59%), iMicrosoft Exchange - 0.51% ( 0.85%).

Siseko utshintsho:

  • Inkxaso yeziqinisekiso zangaphandle (RFC 4422). Ukusebenzisa umyalelo othi "SASL EXTERNAL", umxhasi unokwazisa umncedisi ukuba asebenzise iziqinisekiso ezigqithiswe kwiinkonzo zangaphandle ezifana ne-IP Security (RFC4301) kunye ne-TLS yokuqinisekisa;
  • Yongeza ukukwazi ukusebenzisa ifomati ye-JSON yokukhangela ukujonga. Kwakhona kongezwe ukhetho lweemaski ezinemiqathango "forll" kunye "nayiphi na" usebenzisa i-JSON.
  • Kongezwe i-$tls_in_cipher_std kunye ne-$tls_out_cipher_std izinto eziguquguqukayo eziqulathe amagama e-cipher suites ehambelana negama elisuka kwi-RFC.
  • Iiflegi ezintsha zongeziwe ukulawula ukuboniswa kwee-ID zomyalezo kwilogi (zisetwe ngoseto Isikhethi se-log_select): “msg_id” (yenziwe ngokuzenzekelayo) ngesichongi somyalezo kunye ne “msg_id_created” nesazisi esenzelwe umyalezo omtsha.
  • Inkxaso eyongeziweyo yokhetho lwe-"case_insensitive" kwimo ye-"verify=not_blind" yokungahoyi isimo soonobumba ngexesha lokuqinisekisa.
  • Ukhetho lovavanyo olongeziweyo EXPERIMENTAL_TLS_RESUME, olubonelela ukukwazi ukuphinda kuqalise uqhagamshelo oluphazamisekileyo lwe-TLS.
  • Kongezwe i exim_version ukhetho phezu Exim inguqulelo inombolo yemveliso umtya kwiindawo ezahlukeneyo kwaye idlule kwi $ exim_version kunye $version_number variables.
  • Kongezwe i-${sha2_N:} iinketho zomsebenzisi ze-N=256, 384, 512.
  • Iphunyeziwe "i-$ r_ ..." iinguqu, ezibekwe kwiinketho zomzila kwaye ziyafumaneka ukuze zisetyenziswe xa uthatha izigqibo malunga neendlela kunye nokukhetha ukuthutha.
  • Inkxaso ye-IPv6 yongezwe kwizicelo zokujonga i-SPF.
  • Xa kusenziwa iitshekhi nge-DKIM, ukukwazi ukucoca ngeentlobo zezitshixo kunye neehashi zongeziwe.
  • Xa usebenzisa i-TLS 1.3, inkxaso ye-OCSP (iProtokholi yeSimo seSatifikethi se-Intanethi) ibonelelwe iitshekhi ubume bokurhoxiswa kwesatifikethi.
  • Isiganeko esongeziweyo esithi "smtp:ehlo" ukubeka iliso kuluhlu lomsebenzi obonelelwa liqela elikude.
  • Yongeza inketho yelayini yomyalelo ukususa imiyalezo ukusuka kumgca onegama ukuya komnye.
  • Izinto eziguquguqukayo ezongeziweyo ezineenguqulelo zeTLS zezicelo ezingenayo neziphumayo - $tls_in_ver kunye ne-$tls_out_ver.
  • Xa usebenzisa i-OpenSSL, umsebenzi wongezwe ukuze ubhale iifayile ezinezitshixo kwifomathi ye-NSS yokuchaza iipakethi zenethweki ezivaliweyo. Igama lefayile limiselwe nge-SSLKEYLOGFILE eguquguqukayo yemeko-bume. Xa usakha nge-GnuTLS, ukusebenza okufanayo kunikezelwa zizixhobo ze-GnuTLS, kodwa kufuna ukubaleka njengengcambu.

umthombo: opennet.ru

Yongeza izimvo