Re: [exim] Expiriences with TLS 1.3

2019-01-29 Thread Phil Pennock via Exim-users
On 2019-01-28 at 15:09 +, Andrew C Aitchison via Exim-users wrote: > I see many header lines like: > > Received: from smtp.spodhuis.org ([2a02:898:31:0:48:4558:736d:7470]:34422 > helo=mx.spodhuis.org) > by hummus.csx.cam.ac.uk with esmtpsa (TLSv1.3:TLS_AES_256_GCM_SHA384:256) > (Exim 4.91)

Re: [exim] Expiriences with TLS 1.3

2019-01-29 Thread Max Kostikov via Exim-users
Viktor Dukhovni via Exim-users писал 2019-01-29 19:18: On Tue, Jan 29, 2019 at 06:53:33PM +0200, Max Kostikov via Exim-users wrote: Jeremy Harris via Exim-users писал 2019-01-28 13:56: > I've not seen any such connections in production yet. FreeBSD 12 have OpenSSL 1.1.1 in base system so I

Re: [exim] Expiriences with TLS 1.3

2019-01-29 Thread Viktor Dukhovni via Exim-users
On Tue, Jan 29, 2019 at 06:53:33PM +0200, Max Kostikov via Exim-users wrote: > Jeremy Harris via Exim-users писал 2019-01-28 13:56: > > I've not seen any such connections in production yet. > > FreeBSD 12 have OpenSSL 1.1.1 in base system so I see entries in the > Exim log. For the record, not

Re: [exim] Expiriences with TLS 1.3

2019-01-29 Thread Max Kostikov via Exim-users
Jeremy Harris via Exim-users писал 2019-01-28 13:56: I've not seen any such connections in production yet. FreeBSD 12 have OpenSSL 1.1.1 in base system so I see entries in the Exim log. Jan 29 08:30:44 beta exim[2522]: 1goMux-eg-Dq <= bugzilla-nore...@freebsd.org H=mx2.freebsd.org

Re: [exim] Expiriences with TLS 1.3

2019-01-29 Thread Jeremy Harris via Exim-users
On 28/01/2019 10:50, Cyborg via Exim-users wrote: > is anyone of you running TLS 1.3 already ? In other related news, iOS 12.2 (just out for developers) enables TLS 1.3 by default. -- Cheers, Jeremy -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Cyborg via Exim-users
Am 28.01.19 um 22:29 schrieb exim-users--- via Exim-users: > Hi, > > On 28.01.19 11:50, Cyborg via Exim-users wrote: >> is anyone of you running TLS 1.3 already ? > I am using it on stock Ubuntu 18.10 (Exim is version 4.91-6ubuntu1, > gnutls is 3.6.4-2ubuntu1) on a relatively low volume secondary

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread exim-users--- via Exim-users
Hi, On 28.01.19 11:50, Cyborg via Exim-users wrote: > is anyone of you running TLS 1.3 already ? I am using it on stock Ubuntu 18.10 (Exim is version 4.91-6ubuntu1, gnutls is 3.6.4-2ubuntu1) on a relatively low volume secondary MX. > If so, any problems ? Works fine, beside the fact that the

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Andreas Metzler via Exim-users
Cyborg via Exim-users wrote: [TLS 1.3] > So a stock 4.91 will work . Thanks for the info, i will try it out asap. For GnuTLS you will need exim 4.92(beta/rc). See #2359 cu Andreas -- `What a good friend you are to him, Dr. Maturin. His other friends are so grateful to you.' `I sew his ears on

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Cyborg via Exim-users
Am 28.01.19 um 17:55 schrieb Wolfgang Breyha via Exim-users: > On 28/01/2019 17:09, Jeremy Harris via Exim-users wrote: >> On 28/01/2019 15:43, Viktor Dukhovni via Exim-users wrote: >>> univie.ac.at >> Univie, at least, are claiming Exim 4.91 in their banner. I don't >> know if they run patches,

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Wolfgang Breyha via Exim-users
On 28/01/2019 17:09, Jeremy Harris via Exim-users wrote: > On 28/01/2019 15:43, Viktor Dukhovni via Exim-users wrote: >> univie.ac.at > > Univie, at least, are claiming Exim 4.91 in their banner. I don't > know if they run patches, but I do know that at least one person > there is an active

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Sebastian Nielsen via Exim-users
It could be a transparent reverse Proxy, or firewall that are responsible for the encryption in case Exim 4.91 does not support TLS 1.3. Den mån 28 jan. 2019 kl 17:16 skrev Jeremy Harris via Exim-users : > > On 28/01/2019 15:43, Viktor Dukhovni via Exim-users wrote: > > DANE domains with TLS

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Jeremy Harris via Exim-users
On 28/01/2019 15:43, Viktor Dukhovni via Exim-users wrote: > DANE domains with TLS 1.3 that exchange enough email > volume with Gmail to appear in Google's email transparency report include: > > univie.ac.at Univie, at least, are claiming Exim 4.91 in their banner. I don't know if they run

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Viktor Dukhovni via Exim-users
> On Jan 28, 2019, at 6:56 AM, Jeremy Harris via Exim-users > wrote: > >> is anyone of you running TLS 1.3 already ? > > It functions fine in the Exim regression-test suite, > on systems having suitable library support. > > I've not seen any such connections in production yet. As part of the

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Andrew C Aitchison via Exim-users
On Mon, 28 Jan 2019, Jeremy Harris via Exim-users wrote: On 28/01/2019 10:50, Cyborg via Exim-users wrote: is anyone of you running TLS 1.3 already ? It functions fine in the Exim regression-test suite, on systems having suitable library support. I've not seen any such connections in

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Andrew C Aitchison via Exim-users
On Mon, 28 Jan 2019, Jeremy Harris via Exim-users wrote: On 28/01/2019 10:50, Cyborg via Exim-users wrote: is anyone of you running TLS 1.3 already ? It functions fine in the Exim regression-test suite, on systems having suitable library support. I've not seen any such connections in

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Jeremy Harris via Exim-users
On 28/01/2019 14:13, Cyborg via Exim-users wrote: > is there any special exim version needed to test it? The yet-to-be-released 4.92 has significant changes supporting the more-recent TLS library versions required. 4.92-RC5 was just announced, or you can build from source using either the master

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Cyborg via Exim-users
Am 28.01.19 um 12:56 schrieb Jeremy Harris via Exim-users: > On 28/01/2019 10:50, Cyborg via Exim-users wrote: >> is anyone of you running TLS 1.3 already ? > It functions fine in the Exim regression-test suite, > on systems having suitable library support. > > I've not seen any such connections

Re: [exim] Expiriences with TLS 1.3

2019-01-28 Thread Jeremy Harris via Exim-users
On 28/01/2019 10:50, Cyborg via Exim-users wrote: > is anyone of you running TLS 1.3 already ? It functions fine in the Exim regression-test suite, on systems having suitable library support. I've not seen any such connections in production yet. -- Cheers, Jeremy -- ## List details at

[exim] Expiriences with TLS 1.3

2019-01-28 Thread Cyborg via Exim-users
Hi, is anyone of you running TLS 1.3 already ? If so, any problems ? best regards, Marius -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at http://www.exim.org/ ## Please use the Wiki with this list - http://wiki.exim.org/