On Wed, Sep 23, 2026 at 01:56:00PM +0200, Gerald Galster via Postfix-users
wrote:
> > Yes, the tunnel involves additional moving parts, with a Postfix secure
> > channel you just need to ensure that each side knows the other's public
> > key:
>
> I disagree on the moving parts:
>
> - it's static routing (once set up, you're good)
The TLS secure channel is equally static.
> - once the tunnel is up, it fails only when the underlying network fails,
> which would break TLS delivery too
Same, for TLS, but without the addtional requirement to configure
WireGuard, and make sure that only Postfix SMTP traffic is forwarded
via the tunnel.
> - the WireGuard config doesn't change and using preshared keys it's supposed
> to be quantum resistant (AES); it's also a quite short config (less complex)
Postfix 3.10 or later with OpenSSL 3.5 or later supports ML-KEM key
exchange and ML-DSA signatures. Both date back to early 2025, so
no longer bleeding edge.
> - the WireGuard protocol has been security audited
> - WireGuard is an in-tree kernel module (fewer API changes like with OpenSSL
> 1/2/3 over the years; no separate updates)
Postfix needs OpenSSL in any case. A matching version will be part of
both the client and server systems.
> - with postfix you would have two separate instances to manage (config, logs
> to
> check, etc.)
The server and client are needed anyway, that's what the tunnel is
supposed to connect. The secure channel configuration does not add
anything extra.
> - less complexity compared to OpenSSL (update frequency, attack surface)
> - certificates (usually) expire, WireGuard keys do not
> - ...
No expiring certificates are needed, just a suitable self-signed
key-wrapper.
$ openssl genpkey -algorithm ml-dsa-44 -out pqss.pem
$ openssl pkey -in pqss.pem -pubout -outform DER |
openssl dgst -sha256 -c |
sed 's/.* //'
d4:38:a2:22:44:18:af:fb:f3:c2:65:fb:8a:78:e6:e0:56:0d:6e:f1:0f:a5:84:3c:72:37:91:09:dc:a1:96:ce
$ openssl req -x509 -new -key pqkey.pem -subj / \
-not_after 99991231235959Z >> pqss.pem
$ openssl x509 -in pqss.pem -noout -text -certopt
no_header,no_sigdump,no_pubkey
Version: 3 (0x2)
Serial Number:
70:13:e1:a8:56:5e:a0:e6:cf:e5:5b:33:39:d7:fe:60:52:92:3c:dc
Signature Algorithm: ML-DSA-44
Issuer:
Validity
Not Before: Sep 23 12:36:12 2026 GMT
Not After : Dec 31 23:59:59 9999 GMT
Subject:
X509v3 extensions:
X509v3 Subject Key Identifier:
80:1B:84:3A:B6:12:C5:52:02:4A:8A:DB:C6:DB:D6:F6:6B:79:58:5F
X509v3 Authority Key Identifier:
80:1B:84:3A:B6:12:C5:52:02:4A:8A:DB:C6:DB:D6:F6:6B:79:58:5F
X509v3 Basic Constraints: critical
CA:TRUE
With "fingerprint" as the security level and "smtpd_tls_enable_rpk = yes",
the certificate is never sent on the wire, only the raw public key is sent
in each direction.
> Don't get me wrong, Postfix is the best mail server I know of, but
> from my point of view it's key to keep complexity and failure points
> low in this case.
A Postfix secure channel, with fixed keys is not difficult to set up,
and requires no active maintenance. There's no need for a separate
WireGuard tunnel.
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]