On Wed, Sep 23, 2026 at 01:56:00PM +0200, Gerald Galster via Postfix-users 
wrote:

> > Yes, the tunnel involves additional moving parts, with a Postfix secure
> > channel you just need to ensure that each side knows the other's public
> > key:
> 
> I disagree on the moving parts:
> 
> - it's static routing (once set up, you're good)

The TLS secure channel is equally static.

> - once the tunnel is up, it fails only when the underlying network fails,
>   which would break TLS delivery too

Same, for TLS, but without the addtional requirement to configure
WireGuard, and make sure that only Postfix SMTP traffic is forwarded
via the tunnel.

> - the WireGuard config doesn't change and using preshared keys it's supposed
>   to be quantum resistant (AES); it's also a quite short config (less complex)

Postfix 3.10 or later with OpenSSL 3.5 or later supports ML-KEM key
exchange and ML-DSA signatures.  Both date back to early 2025, so
no longer bleeding edge.

> - the WireGuard protocol has been security audited
> - WireGuard is an in-tree kernel module (fewer API changes like with OpenSSL
>   1/2/3 over the years; no separate updates)

Postfix needs OpenSSL in any case.  A matching version will be part of
both the client and server systems.

> - with postfix you would have two separate instances to manage (config, logs 
> to
>   check, etc.)

The server and client are needed anyway, that's what the tunnel is
supposed to connect.  The secure channel configuration does not add
anything extra.

> - less complexity compared to OpenSSL (update frequency, attack surface)
> - certificates (usually) expire, WireGuard keys do not
> - ...

No expiring certificates are needed, just a suitable self-signed
key-wrapper.

    $ openssl genpkey -algorithm ml-dsa-44 -out pqss.pem

    $ openssl pkey -in pqss.pem -pubout -outform DER |
      openssl dgst -sha256 -c |
      sed 's/.* //'
    
d4:38:a2:22:44:18:af:fb:f3:c2:65:fb:8a:78:e6:e0:56:0d:6e:f1:0f:a5:84:3c:72:37:91:09:dc:a1:96:ce

    $ openssl req -x509 -new -key pqkey.pem -subj / \
      -not_after 99991231235959Z >> pqss.pem

    $ openssl x509 -in pqss.pem -noout -text -certopt 
no_header,no_sigdump,no_pubkey
        Version: 3 (0x2)
        Serial Number:
            70:13:e1:a8:56:5e:a0:e6:cf:e5:5b:33:39:d7:fe:60:52:92:3c:dc
        Signature Algorithm: ML-DSA-44
        Issuer: 
        Validity
            Not Before: Sep 23 12:36:12 2026 GMT
            Not After : Dec 31 23:59:59 9999 GMT
        Subject: 
        X509v3 extensions:
            X509v3 Subject Key Identifier: 
                80:1B:84:3A:B6:12:C5:52:02:4A:8A:DB:C6:DB:D6:F6:6B:79:58:5F
            X509v3 Authority Key Identifier: 
                80:1B:84:3A:B6:12:C5:52:02:4A:8A:DB:C6:DB:D6:F6:6B:79:58:5F
            X509v3 Basic Constraints: critical
                CA:TRUE

With "fingerprint" as the security level and "smtpd_tls_enable_rpk = yes",
the certificate is never sent on the wire, only the raw public key is sent
in each direction.

> Don't get me wrong, Postfix is the best mail server I know of, but
> from my point of view it's key to keep complexity and failure points
> low in this case.

A Postfix secure channel, with fixed keys is not difficult to set up,
and requires no active maintenance.  There's no need for a separate
WireGuard tunnel.

-- 
    Viktor.  🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to