New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
DANE: implement DANE ... #409
Comments
FWIW, I have made progress with this and I might be able to actually get initial support soon. |
on my laptop I can now DANE-verify the MX at mx1.poolp.org Unfortunately, I won't be able to commit this quite yet: Hopefully I should be done with the refactor in the next couple weeks and commit DANE to master/portable during May. |
What happened to this? |
On Wed, Oct 21, 2015 at 11:47:15PM -0700, Reyk Floeter wrote:
not much, i have a branch somewhere with dane support, but it was just a 1- we need to refactor lka.c a bit, the way it works today makes it hard 2- asr doesn't support DNSSEC so even when the smtpd part is ready there gilles Gilles Chehade |
Resurrected experimental branch: DANE will not be ready for 6.2.0 but should be ready for 6.3.0 |
The Dutch and German governments have mandated the use of DANE for government email. |
The experimental DANE branch link is 404. Is there another branch maintained somewhere? Thanks. |
I have started implementing a standalone DANE resolver which still needs a bit of work before being brought in OpenSMTPD, but if you're curious search for poolpOrg/dane |
I'm requiring TLS for all connections to/from my mailserver. Just now i had to email german police and this is the first time this policy failed, because they use a DANE CA (johnjones mentioned they have to). It would be cool to have the feature. |
I tested running with TLS required as well some time ago - it resulted in mails lost from banks etc. that still aren't sending mail with TLS. :) |
@whataboutpereira That's sad to hear. I don't know where you're from - in Germany there were quite strong efforts to have mail traffic encrypted and i have not missed mails so far. This DANE problem is the first issue and it's quite ironic in the sense that it's my end that is non compliant/compatible. |
Estonia. The supposed IT country. I actually contacted a few of the places we were receiving unencrypted from, but banks were not amongst those who answered and fixed their setups. :) |
Is this still on the map? Looks like it's been almost a year without any update. |
I really love OpenSMTPD mail server. Thanks for your great work :) I also would really love it to be able to use DANE in conjunction with OpenSMTPD. |
We have to do it and our main competitor has it already ;-)
The text was updated successfully, but these errors were encountered: