> Viktor Dukhovni via Postfix-users <[email protected]>:
> 
> On Wed, Sep 23, 2026 at 10:18:33AM +0000, patpro--- via Postfix-users wrote:
> 
>> Thank you. I’ll evaluate later if I go the wireguard road to secure a
>> point-to-point tunnel or I go «on the open» with TLS restrictions. The
>> tunnel can fail, but it’s agostic about what’s going through.
>> 
>> Secure-channel TLS is a config inside Postfix but probably less prone
>> to failure in the long run.
> 
> Yes, the tunnel involves additional moving parts, with a Postfix secure
> channel you just need to ensure that each side knows the other's public
> key:

I disagree on the moving parts:

- it's static routing (once set up, you're good)
- once the tunnel is up, it fails only when the underlying network fails,
  which would break TLS delivery too
- the WireGuard config doesn't change and using preshared keys it's supposed
  to be quantum resistant (AES); it's also a quite short config (less complex)
- the WireGuard protocol has been security audited
- WireGuard is an in-tree kernel module (fewer API changes like with OpenSSL
  1/2/3 over the years; no separate updates)
- with postfix you would have two separate instances to manage (config, logs to
  check, etc.)
- less complexity compared to OpenSSL (update frequency, attack surface)
- certificates (usually) expire, WireGuard keys do not
- ...

Don't get me wrong, Postfix is the best mail server I know of, but from
my point of view it's key to keep complexity and failure points low in this 
case.

Best regards,
Gerald
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to