> Viktor Dukhovni via Postfix-users <[email protected]>: > > On Wed, Sep 23, 2026 at 10:18:33AM +0000, patpro--- via Postfix-users wrote: > >> Thank you. I’ll evaluate later if I go the wireguard road to secure a >> point-to-point tunnel or I go «on the open» with TLS restrictions. The >> tunnel can fail, but it’s agostic about what’s going through. >> >> Secure-channel TLS is a config inside Postfix but probably less prone >> to failure in the long run. > > Yes, the tunnel involves additional moving parts, with a Postfix secure > channel you just need to ensure that each side knows the other's public > key:
I disagree on the moving parts: - it's static routing (once set up, you're good) - once the tunnel is up, it fails only when the underlying network fails, which would break TLS delivery too - the WireGuard config doesn't change and using preshared keys it's supposed to be quantum resistant (AES); it's also a quite short config (less complex) - the WireGuard protocol has been security audited - WireGuard is an in-tree kernel module (fewer API changes like with OpenSSL 1/2/3 over the years; no separate updates) - with postfix you would have two separate instances to manage (config, logs to check, etc.) - less complexity compared to OpenSSL (update frequency, attack surface) - certificates (usually) expire, WireGuard keys do not - ... Don't get me wrong, Postfix is the best mail server I know of, but from my point of view it's key to keep complexity and failure points low in this case. Best regards, Gerald _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
