Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.mail.sendmail > #8331 > unrolled thread
| Started by | Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> |
|---|---|
| First post | 2026-06-28 01:42 -0400 |
| Last post | 2026-07-01 19:22 +0000 |
| Articles | 19 — 2 participants |
Back to article view | Back to comp.mail.sendmail
sendmail snapshot 8.19.0.2 is available Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> - 2026-06-28 01:42 -0400
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-01 17:54 +0000
Re: sendmail snapshot 8.19.0.2 is available Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> - 2026-07-03 02:03 -0400
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 13:47 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-01 19:13 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-02 23:22 +0000
Re: sendmail snapshot 8.19.0.2 is available Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> - 2026-07-03 13:50 -0400
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 18:33 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 19:19 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 22:44 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 23:10 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-04 00:27 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-04 01:11 +0000
Re: sendmail snapshot 8.19.0.2 is available Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> - 2026-07-07 03:37 -0400
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-09 13:24 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-09 14:11 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-09 17:51 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-09 20:38 +0000
Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-01 19:22 +0000
| From | Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> |
|---|---|
| Date | 2026-06-28 01:42 -0400 |
| Subject | sendmail snapshot 8.19.0.2 is available |
| Message-ID | <111qc86$tmt$1@news.misty.com> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 sendmail snapshot 8.19.0.2 is available for testing. It has two new FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX: log key-exchange algorithm (TLS) and also a new option: TLSEC. SHA256 (sendmail.8.19.0.2.tar.gz) = f3f2456be0534dec17096a4d94cf6b5487d79f21ab90ef0ce734c2c56ba6a312 SHA256 (sendmail.8.19.0.2.tar.gz.sig) = 9f98666d9e13e27a94719838f746cd5684fd459fbca08181f47512de2c82658d Available at: https://ftp.sendmail.org/snapshots/sendmail.8.19.0.2.tar.gz https://ftp.sendmail.org/snapshots/sendmail.8.19.0.2.tar.gz.sig -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJqQCWjAAoJEMApzDDVddAnfrEQAIcRKBKUzfoQ5lic8ENX0hW4 D71o26+/iqa00zE18YJApWIf7cntSBdQzBhA8XOUFXRrg94vBxuCz4fB5NfrQusT U3itWOIvBmevEG3YNri7IaMkeVwhJ2wtZ+n92iuvMQcxGPnp+yEqQj/1y7w1RuL4 4O9I4L+mnJvy2vfmXZkTQ+Ul9XaQfOmY7lmI3Rt2BiWX4x8QeVXHcVBaaull76Ek gWxH/cOnOkuxD+Fq1UcCmjy2J+dtVrStcTy2x2NtML8unw/KummqrDkafJ7zfB2r 9hrsKxltYX5i/RoknTnJud8hmXKFBoL88V7sraA38Siy/olK11ktBuRWfzxCHNcl rhix4IJTdi826YeSXE5yWqS0Q/CUwFwP3Ski6+lkJTRpaLAGJcPlW/6oFI6t/Yqy 046/bnJmzTO05a5GyH/BTepEXgteNq8tJiYvmAO4wdo9C9hIxD0KoILn6zUFdL3V 2KxqkHjdFCu7urNHcgyhqQ/RKZwI8GqWU8diub7HcRtUyqktDyf/iuB0YFGyg+SN G+7Lsj5s8PJ2+dxmZyei85ZJsYDyfntnBC27gb9brclfDVLpUzRmG5xTvahswlWg 3TO4/2w6tcTKsmnJWu+f2BgKLcvZKWZpiQ5V2GyIw/GSso0BxcJiUsRluaLIMB/J W58jxqfRKbjHESal2d8I =2+9l -----END PGP SIGNATURE-----
[toc] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-01 17:54 +0000 |
| Message-ID | <1123k9h$21rfk$1@dont-email.me> |
| In reply to | #8331 |
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> sendmail snapshot 8.19.0.2 is available for testing. It has two new
> FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
> log key-exchange algorithm (TLS) and also a new option: TLSEC.
I used Fedora Linux 44 RPM sendmail.spec with modifications:
1) Removed applying all patches since they were for 8.18.2.
Since the switch to ISO C function definitions, none of
the Red Hat patches apply any more.
2) Added -D_FFR_EKU_NOCLIENTAUTH and -D_FFR_KEX
~ $ rpm -qi gcc|head -3
Name : gcc
Version : 16.1.1
Release : 2.fc44
Sendmail 8.19.0.2 compiles with some warnings, most of
them being deprecations of certain functions since OpenSSL
3.0. However, these might be worth checking:
In function ‘sm_strlcpy’,
inlined from ‘sm_errstring’ at err.c:1238:9:
../libsm/strl.c:70:28: warning: ‘strlen’ reading 1 or more bytes from a region of size 0 [-Wstringop-overread]
70 | return i + strlen(src + i);
| ^
In function ‘sm_strlcpy’,
inlined from ‘safedirpath’ at ../libsmutil/safefile.c:556:10:
../libsm/strl.c:70:28: warning: ‘strlen’ reading 1 or more bytes from a region of size 0 [-Wstringop-overread]
70 | return i + strlen(src + i);
| ^
br,
KK
[toc] | [prev] | [next] | [standalone]
| From | Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> |
|---|---|
| Date | 2026-07-03 02:03 -0400 |
| Message-ID | <1127jar$1th$1@news.misty.com> |
| In reply to | #8333 |
Kalevi Kolttonen wrote:
> In function ‘sm_strlcpy’,
> inlined from ‘sm_errstring’ at err.c:1238:9:
> ../libsm/strl.c:70:28: warning: ‘strlen’ reading 1 or more bytes from
> a region of size 0 [-Wstringop-overread]
> 70 | return i + strlen(src + i);
Seems like a bogus warning.
if (src[i] == '\0')
return i;
else
return i + strlen(src + i);
In the "else" case src[i] is not '\0',
hence there is at least one non-NUL char in src+i.
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-03 13:47 +0000 |
| Message-ID | <1128ehp$3e9qs$1@dont-email.me> |
| In reply to | #8337 |
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote: > Kalevi Kolttonen wrote: > >> In function â??sm_strlcpyâ??, >> inlined from â??sm_errstringâ?? at err.c:1238:9: >> ../libsm/strl.c:70:28: warning: â??strlenâ?? reading 1 or more bytes from >> a region of size 0 [-Wstringop-overread] >> 70 | return i + strlen(src + i); > > Seems like a bogus warning. > > if (src[i] == '\0') > return i; > else > return i + strlen(src + i); > > In the "else" case src[i] is not '\0', > hence there is at least one non-NUL char in src+i. Yes, indeed. br, KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-01 19:13 +0000 |
| Message-ID | <1123otj$237l0$1@dont-email.me> |
| In reply to | #8331 |
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> sendmail snapshot 8.19.0.2 is available for testing. It has two new
> FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
> log key-exchange algorithm (TLS) and also a new option: TLSEC.
It builds on OmniOS latest stable (Open Solaris descendant based on
illumos kernel):
~/src/3/sendmail-8.19.0.2@omnios $ uname -a
SunOS omnios 5.11 omnios-r151058-c1eded413b i86pc i386 i86pc
~/src/3/sendmail-8.19.0.2@omnios $ gcc --version
gcc (OmniOS 151058/15.2.0-il-0) 15.2.0
Copyright (C) 2025 Free Software Foundation, Inc.
This is free software; see the source for copying conditions. There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
~/src/3/sendmail-8.19.0.2@omnios $ cat devtools/Site/site.config.m4
define(`confMAPDEF', `-DNEWDB -DMAP_REGEX -DSOCKETMAP -DNAMED_BIND=1 -I/opt/ooce/include/ -L/opt/ooce/lib -L/opt/ooce/lib/sasl2 -L/opt/ooce/lib/amd64')dnl
define(`confINCDIRS', `-I/opt/ooce/include/')dnl
APPENDDEF(`conf_sendmail_ENVDEF', `-DSTARTTLS -D_FFR_TLS_1 -DTLS_EC -D_FFR_TLS_USE_CERTIFICATE_CHAIN_FILE -DDANE -D_FFR_EKU_NOCLIENTAUTH -D_FFR_KEX -DHASUNSETENV')dnl
APPENDDEF(`confLIBDIRS', `-L/opt/ooce/lib/amd64 -R/opt/ooce/lib/amd64')dnl
APPENDDEF(`conf_sendmail_LIBS', `-lssl -lcrypto -ldb -lsasl2')dnl
APPENDDEF(`confENVDEF', `-DSASL=2 -I/opt/ooce/include/')dnl
APPENDDEF(`conf_sendmail_ENVDEF', `-DMILTER')dnl
~/src/3/sendmail-8.19.0.2@omnios $ obj.SunOS.5.11.i86pc/sendmail/sendmail -bt -d0.1</dev/null
Version 8.19.0.2
Compiled with: DANE HAVE_SSL_CTX_dane_enable MAX_TLSA_RR=64 DNSMAP
IPV6_FULL LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8 MIME8TO7
NAMED_BIND NETINET NETINET6 NETUNIX NEWDB=5.3 PIPELINING SASLv2
SCANF SOCKETMAP STARTTLS MTA_HAVE_TLSv1_3 TLS_EC= 1
TLS_VRFY_PER_CTX USERDB XDEBUG
/etc/mail/sendmail.cf: line 0: cannot open: No such file or directory
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-02 23:22 +0000 |
| Message-ID | <1126rrg$30po9$1@dont-email.me> |
| In reply to | #8334 |
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote: > Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote: >> sendmail snapshot 8.19.0.2 is available for testing. It has two new >> FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX: >> log key-exchange algorithm (TLS) and also a new option: TLSEC. > > It builds on OmniOS latest stable (Open Solaris descendant based on > illumos kernel): It has been running flawlessly since I installed it and imported it under SMF control. br, KK
[toc] | [prev] | [next] | [standalone]
| From | Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> |
|---|---|
| Date | 2026-07-03 13:50 -0400 |
| Message-ID | <1128sp9$k7k$1@news.misty.com> |
| In reply to | #8336 |
Kalevi Kolttonen wrote: > It has been running flawlessly since I installed it and Thanks for the info! Do you see any PQC key_exchange algorithm in your logs (e.g., X25519MLKEM768)? Have you enabled overriding EKU restrictions? Does it work as expected?
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-03 18:33 +0000 |
| Message-ID | <1128v9k$3jp27$1@dont-email.me> |
| In reply to | #8339 |
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote: > Kalevi Kolttonen wrote: > >> It has been running flawlessly since I installed it and > > Thanks for the info! > > Do you see any PQC key_exchange algorithm in your logs > (e.g., X25519MLKEM768)? > > Have you enabled overriding EKU restrictions? > Does it work as expected? No, this is just an internal LAN centralized mail server and it has no TLS enabled. br, KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-03 19:19 +0000 |
| Message-ID | <11291vg$3kmbk$1@dont-email.me> |
| In reply to | #8339 |
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote: > Do you see any PQC key_exchange algorithm in your logs > (e.g., X25519MLKEM768)? > > Does it work as expected? I created a self-signed cert and enabled STARTTLS advertsing. I then used swaks: fedora-local$ swaks -tls --to=kalevi@omnios.local --server omnios.local This is what I see on OmniOS /var/log/syslog: Jul 3 22:11:28 localhost sendmail[21671]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE Jul 3 22:11:28 localhost sendmail[21671]: [ID 801593 mail.info] 663JBSWB021671: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260703221123.605813@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154] Jul 3 22:11:28 localhost sendmail[21673]: [ID 801593 mail.info] 663JBSWB021671: to=<kalevi@omnios.local>, delay=00:00:00, xdelay=00:00:00, mailer=cyrusv2, pri=120268, relay=localhost, dsn=2.1.5, stat=Sent > Have you enabled overriding EKU restrictions? How do I do it? I have compiled with the required _FFR. br, KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-03 22:44 +0000 |
| Message-ID | <1129e05$3o88m$1@dont-email.me> |
| In reply to | #8341 |
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
>
>> Have you enabled overriding EKU restrictions?
>
> How do I do it? I have compiled with the required _FFR.
Okay, here's what I got so far: EKU = Extended Key Usage
for certificates. Here specifically I guess we are interested
in Server Authentication and client Authentication.
If I understood correct, the new FFR is for making exceptions
in the receiving server when the sender is using Server
Authentication certificate.
Fedora 44 is my client and I have created a self-signed cert
with:
~/tmp/eku $ openssl x509 -in fedora-serverauth.crt -noout -text | grep -A1 "Extended Key Usage"
X509v3 Extended Key Usage:
TLS Web Server Authentication
fedora$ swaks --tls-cert=fedora-serverauth.crt --tls-key=fedora-serverauth.key -tls --to=kalevi@kolttonen.fi --server omnios.local
<- 220 2.0.0 Ready to start TLS
=== TLS started with cipher TLSv1.3:TLS_AES_256_GCM_SHA384:256
=== TLS client certificate requested and sent
=== TLS client[0] subject=[/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local]
=== commonName=[fedora.local], subjectAltName=[DNS:fedora.local] notAfter=[2036-06-30T21:57:43Z]
=== TLS peer[0] subject=[/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=omnios.local]
=== commonName=[omnios.local], subjectAltName=[] notAfter=[2036-06-30T18:36:01Z]
=== TLS peer certificate failed CA verification (self-signed certificate), passed host verification (using host omnios.local to verify)
~> EHLO fedora.local
<~ 250-omnios.local Hello fedora.local [192.168.1.154], pleased to meet you
<~ 250-ENHANCEDSTATUSCODES
<~ 250-PIPELINING
<~ 250-EXPN
<~ 250-VERB
<~ 250-8BITMIME
<~ 250-SIZE
<~ 250-DSN
<~ 250-ETRN
<~ 250-AUTH DIGEST-MD5 CRAM-MD5
<~ 250-DELIVERBY
<~ 250 HELP
~> MAIL FROM:<kalevi@fedora.local>
<~ 250 2.1.0 <kalevi@fedora.local>... Sender ok
~> RCPT TO:<kalevi@kolttonen.fi>
<~* 550 5.7.1 <kalevi@kolttonen.fi>... Relaying denied
~> QUIT
<~ 221 2.0.0 omnios.local closing connection
omnios mail log:
Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] tls_srv_features=empty, stat=0, relay=fedora.local [192.168.1.154]
Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS: TLS cert verify: depth=0 /C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, state=0, reason=unsuitable certificate purpose
Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=FAIL, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE
Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=unsuitable certificate purpose
Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5
Jul 4 01:24:25 localhost sendmail[23344]: [ID 801593 mail.notice] 663MOPb1023344: ruleset=check_rcpt, arg1=<kalevi@kolttonen.fi>, relay=fedora.local [192.168.1.154], reject=550 5.7.1 <kalevi@kolttonen.fi>... Relaying denied
Jul 4 01:24:26 localhost sendmail[23344]: [ID 801593 mail.info] 663MOPb1023344: from=<kalevi@fedora.local>, size=0, class=0, nrcpts=0, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]
It looks good "reason=unsuitable certificate purpose" so Sendmail 8.19.0.2
does not accept this cert because it is for server authentication.
Relaying using a different cert with no EKU works and relaying is
accepted by OmniOS.
Again, If I understood correctly, using 'O' should make exceptions
for clients that offer server EKU cert. This is what I have in my
access.db:
root@omnios:/etc/mail# cat access
TLS_Srv_Features:192.168.1.154 O
TLS_Srv_Features:fedora.local O
Srv_Features:192.168.1.154 v
CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY
But OmniOS denies relaying just the same and logs show "tls_srv_features=empty"
However, if I enable it globally using option:
root@omnios:/etc/mail# grep -i tlssrv sendmail.cf
O TLSSrvOptions=O
then EKU exception works and relaying is allowed using server cert:
Jul 4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] tls_srv_features=empty, stat=0, relay=fedora.local [192.168.1.154]
Jul 4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE, eku=overrode_no_client_auth
Jul 4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=ok
Jul 4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 EXTERNAL OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5
Jul 4 01:39:18 localhost sendmail[23452]: [ID 801593 mail.info] 663MdIM4023452: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260704013913.652411@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]
I omitted the rest of the mail log because my OmniOS has no access to
outside world so messages destined to kalevi@kolttonen.fi end up queued
and will bounce. But the thing is, relaying worked!
So it seems to me that access.db method is buggy somehow?
br,
KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-03 23:10 +0000 |
| Message-ID | <1129fi0$3ojd0$1@dont-email.me> |
| In reply to | #8342 |
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> Again, If I understood correctly, using 'O' should make exceptions
> for clients that offer server EKU cert. This is what I have in my
> access.db:
>
> root@omnios:/etc/mail# cat access
> TLS_Srv_Features:192.168.1.154 O
> TLS_Srv_Features:fedora.local O
> Srv_Features:192.168.1.154 v
> CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY
Well, I guess the sendmail.cf expects 'TLS_Srv' and
not 'TLS_Srv_Features':
root@omnios:/etc/mail# grep -i tls_s sendmail.cf
### tls_server: is connection with server "good" enough?
Stls_server
R$* $: $1 $| $>D <$&{server_name}> <?> <! "TLS_Srv"> <>
R$* $| <?>$* $: $1 $| $>A <$&{server_addr}> <?> <! "TLS_Srv"> <>
R$* $| <?>$* $: $1 $| <$(access "TLS_Srv": $: ? $)>
So I modified my access.db:
root@omnios:/etc/mail# cat access
TLS_Srv:192.168.1.154 O
TLS_Srv:fedora.local O
Srv_Features:192.168.1.154 v
CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY
and rebuilt the DB. But still relaying denied...
br,
KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-04 00:27 +0000 |
| Message-ID | <1129k2a$3pps6$1@dont-email.me> |
| In reply to | #8343 |
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
>> Again, If I understood correctly, using 'O' should make exceptions
>> for clients that offer server EKU cert. This is what I have in my
>> access.db:
>>
>> root@omnios:/etc/mail# cat access
>> TLS_Srv_Features:192.168.1.154 O
>> TLS_Srv_Features:fedora.local O
>> Srv_Features:192.168.1.154 v
>> CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY
>
> Well, I guess the sendmail.cf expects 'TLS_Srv' and
> not 'TLS_Srv_Features':
>
> root@omnios:/etc/mail# grep -i tls_s sendmail.cf
> ### tls_server: is connection with server "good" enough?
> Stls_server
> R$* $: $1 $| $>D <$&{server_name}> <?> <! "TLS_Srv"> <>
> R$* $| <?>$* $: $1 $| $>A <$&{server_addr}> <?> <! "TLS_Srv"> <>
> R$* $| <?>$* $: $1 $| <$(access "TLS_Srv": $: ? $)>
>
> So I modified my access.db:
>
> root@omnios:/etc/mail# cat access
> TLS_Srv:192.168.1.154 O
> TLS_Srv:fedora.local O
> Srv_Features:192.168.1.154 v
> CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY
>
> and rebuilt the DB. But still relaying denied...
No! I was missing FEATURE(`tls_session_features'), now I can
see the ruleset Stls_srv_features and as far as I can tell, it
queries access.db using 'TLS_Srv_Features'. So I am back where
I started:
root@omnios:/etc/mail# cat access
TLS_Srv_Features:192.168.1.154 O
TLS_Srv_Features:fedora.local O
Srv_Features:192.168.1.154 v
CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY
Still, relaying denied. I am giving up for tonight.
br,
KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-04 01:11 +0000 |
| Message-ID | <1129mju$3qaqt$1@dont-email.me> |
| In reply to | #8344 |
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote: > No! I was missing FEATURE(`tls_session_features'), now I can > see the ruleset Stls_srv_features and as far as I can tell, it > queries access.db using 'TLS_Srv_Features'. So I am back where > I started: > > root@omnios:/etc/mail# cat access > TLS_Srv_Features:192.168.1.154 O > TLS_Srv_Features:fedora.local O > Srv_Features:192.168.1.154 v > CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY > > Still, relaying denied. I am giving up for tonight. I could not stop so now after reading the code, I finally got it to work with access.db: root@omnios:/etc/mail# cat access TLS_Srv_Features:192.168.1.154 flags=O TLS_Srv_Features:fedora.local flags=O Srv_Features:192.168.1.154 v CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY and the maillog shows "eku=overrode_no_client_auth": Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] tls_srv_features=flags=O, relay=fedora.local [192.168.1.154] Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.debug] tls_srv_features=parsed, flags=O, relay=fedora.local [192.168.1.154] Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE, eku=overrode_no_client_auth Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=ok Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 EXTERNAL OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5 Jul 4 04:06:39 localhost sendmail[24503]: [ID 801593 mail.info] 66416cjO024503: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260704040633.691177@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154] Time to go to sleep, it is over 4 o'clock in the morning. br, KK
[toc] | [prev] | [next] | [standalone]
| From | Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> |
|---|---|
| Date | 2026-07-07 03:37 -0400 |
| Message-ID | <112iabk$3pt$1@news.misty.com> |
| In reply to | #8345 |
Kalevi Kolttonen wrote: > STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, > verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, > key_exchange=ECDHE, eku=overrode_no_client_auth Thanks for giving this a try, sorry for not providing (better) documentation (yet). Which OpenSSL version do you use? With 3.5ff you should get something like key_exchange=X25519MLKEM768 (PQC)
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-09 13:24 +0000 |
| Message-ID | <112o7fa$dq7b$1@dont-email.me> |
| In reply to | #8346 |
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote: > Kalevi Kolttonen wrote: > >> STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, >> verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, >> key_exchange=ECDHE, eku=overrode_no_client_auth > > Thanks for giving this a try, sorry for not providing (better) > documentation (yet). > > Which OpenSSL version do you use? > With 3.5ff you should get something like > key_exchange=X25519MLKEM768 > (PQC) root@omnios:~# openssl version -a OpenSSL 3.6.3 9 Jun 2026 (Library: OpenSSL 3.6.3 9 Jun 2026) built on: Thu Jun 11 23:19:59 2026 UTC platform: solaris64-x86_64-gcc options: bn(64,64) compiler: gcc -fPIC -m64 -O2 -fno-omit-frame-pointer -fno-aggressive-loop-optimizations -fstack-protector-strong -gdwarf-4 -gstrict-dwarf -m64 -Wa,--noexecstack -Wall -O3 -DFILIO_H -DL_ENDIAN -DOPENSSL_PIC -D_REENTRANT -DOPENSSL_BUILDING_OPENSSL -DZLIB -DNDEBUG OPENSSLDIR: "/usr/ssl" ENGINESDIR: "/usr/lib/amd64/engines-3" MODULESDIR: "/usr/lib/amd64/ossl-modules" Seeding source: os-specific CPUINFO: OPENSSL_ia32cap=0x7ffaf3ffffebffff:0x00000000029c6fbf:0x00000000bc002e00:0x0000000000000000:0x0000000000000000 root@fedora:~# $ openssl version -a OpenSSL 3.5.7 9 Jun 2026 (Library: OpenSSL 3.5.7 9 Jun 2026) built on: Wed Jun 10 00:00:00 2026 UTC platform: linux-x86_64 options: bn(64,64) compiler: gcc -fPIC -pthread -m64 -Wa,--noexecstack -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -mtls-dialect=gnu2 -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Wno-complain-wrong-lang -Werror=format-security -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -mtls-dialect=gnu2 -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -Wa,--noexecstack -Wa,--generate-missing-build-notes=yes -specs=/usr/lib/rpm/redhat/redhat-hardened-ld -specs=/usr/lib/rpm/redhat/redhat-hardened-ld-errors -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -specs=/usr/lib/rpm/redhat/redhat-package-notes -DOPENSSL_USE_NODELETE -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_BUILDING_OPENSSL -DZLIB -DNDEBUG -D_GNU_SOURCE -DPURIFY -DDEVRANDOM="\\"/dev/urandom\\"" -DOPENSSL_PEDANTIC_ZEROIZATION -DREDHAT_FIPS_VENDOR="\\"Red Hat Enterprise Linux OpenSSL FIPS Provider\\"" -DREDHAT_FIPS_VERSION="\\"3.5.7-9c2719932f8ae75e\\"" -DSYSTEM_CIPHERS_FILE="/etc/crypto-policies/back-ends/opensslcnf.config" OPENSSLDIR: "/etc/pki/tls" ENGINESDIR: "/usr/lib64/engines-3" MODULESDIR: "/usr/lib64/ossl-modules" Seeding source: os-specific CPUINFO: OPENSSL_ia32cap=0x7ed8320b078bffff:0x00400004219c91a9:0x0000000000000000:0x0000000000000000:0x0000000000000000 root@omnios:~# openssl list -tls-groups secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024 root@fedora:~# openssl list -tls-groups secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024 Using this command: openssl s_client -starttls smtp -connect omnios.local:25 -groups X25519MLKEM768 Server log is: Jul 9 16:23:12 localhost sendmail[14522]: [ID 702911 mail.warning] STARTTLS=server, error: accept failed=-1, reason=no suitable key share, SSL_error=1, errno=0, retry=-1, relay=fedora.local [192.168.1.154] Jul 9 16:23:12 localhost sendmail[14522]: [ID 702911 mail.warning] STARTTLS=server: error:0A000065:SSL routines::no suitable key share:ssl/statem/extensions.c:1412: br, KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-09 14:11 +0000 |
| Message-ID | <112oa5k$emd2$1@dont-email.me> |
| In reply to | #8347 |
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote: > root@omnios:~# openssl list -tls-groups > secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024 > > root@fedora:~# openssl list -tls-groups > secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024 I ran OpenSSL server on OmniOS: root@omnios:/etc/mail/certs# cat f openssl s_server -accept 8443 -key omnios.local.key -cert omnios.local.crt Connected to it with: openssl s_client -connect omnios.local:8443 -groups X25519MLKEM768 Connection worked, so maybe this has something to do with Sendmail configuration or code. br, KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-09 17:51 +0000 |
| Message-ID | <112on30$ivv0$1@dont-email.me> |
| In reply to | #8351 |
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> I ran OpenSSL server on OmniOS:
>
> root@omnios:/etc/mail/certs# cat f
> openssl s_server -accept 8443 -key omnios.local.key -cert omnios.local.crt
>
> Connected to it with:
>
> openssl s_client -connect omnios.local:8443 -groups X25519MLKEM768
>
> Connection worked, so maybe this has something to do with Sendmail
> configuration or code.
I tested a small patch:
===============================================================================
diff -urN sendmail-8.19.0.2/sendmail/tls.c sendmail-8.19.0.2-patch/sendmail/tls.c
--- sendmail-8.19.0.2/sendmail/tls.c 2026-07-09 20:47:18.544514740 +0300
+++ sendmail-8.19.0.2-patch/sendmail/tls.c 2026-07-09 20:47:26.068638009 +0300
@@ -1692,6 +1692,11 @@
if (kf2 != NULL)
*--kf2 = ',';
+ if (!SSL_CTX_set1_groups_list(*tls_ctx, "X25519MLKEM768:X25519")) {
+ abort();
+ }
+ sm_syslog(LOG_INFO, NOQID, "SSL_CTX_set1_groups_list() success");
+
return ok;
}
===============================================================================
After that PQC key exchange worked with s_client:
root@omnios:/opt/site/sbin# grep success /var/log/syslog
Jul 9 20:43:51 localhost sendmail[27872]: [ID 702911 mail.info] SSL_CTX_set1_groups_list() success
root@omnios:/opt/site/sbin# grep X25519MLKEM768 /var/log/syslog
Jul 9 20:44:07 localhost sendmail[27877]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=X25519MLKEM768
I guess this proves that Sendmail 8.19.0.2 OpenSSL initialization code
is to blame, but I do not know the proper fix.
br,
KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-09 20:38 +0000 |
| Message-ID | <112p0s9$mnqn$1@dont-email.me> |
| In reply to | #8352 |
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> I tested a small patch:
>
> ===============================================================================
> diff -urN sendmail-8.19.0.2/sendmail/tls.c sendmail-8.19.0.2-patch/sendmail/tls.c
> --- sendmail-8.19.0.2/sendmail/tls.c 2026-07-09 20:47:18.544514740 +0300
> +++ sendmail-8.19.0.2-patch/sendmail/tls.c 2026-07-09 20:47:26.068638009 +0300
> @@ -1692,6 +1692,11 @@
> if (kf2 != NULL)
> *--kf2 = ',';
>
> + if (!SSL_CTX_set1_groups_list(*tls_ctx, "X25519MLKEM768:X25519")) {
> + abort();
> + }
> + sm_syslog(LOG_INFO, NOQID, "SSL_CTX_set1_groups_list() success");
> +
> return ok;
> }
>
> ===============================================================================
I have been reading tls.c inittls() and isolated the problem to initec()
call with TLS_EC compilation define enabled.
Having TLS_EC=0 in conf_sendmail_ENVDEF in devtools/Site/site.config.m4
fixes the problem and enables Sendmail to use OpenSSL defaults. Then PQC
key exchange works:
Jul 9 23:33:47 localhost sendmail[7555]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=X25519MLKEM768
br,
KK
[toc] | [prev] | [next] | [standalone]
| From | kalevi@kolttonen.fi (Kalevi Kolttonen) |
|---|---|
| Date | 2026-07-01 19:22 +0000 |
| Message-ID | <1123pe3$23em6$1@dont-email.me> |
| In reply to | #8331 |
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> sendmail snapshot 8.19.0.2 is available for testing. It has two new
> FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
> log key-exchange algorithm (TLS) and also a new option: TLSEC.
It builds on FreeBSD 15.1:
fbsd15:~/c/sendmail-8.19.0.2 $ obj.FreeBSD.15.1-RELEASE.amd64/sendmail/sendmail -bt -d0.1</dev/null
Version 8.19.0.2
Compiled with: DANE HAVE_SSL_CTX_dane_enable MAX_TLSA_RR=64 DNSMAP
IPV6_FULL LDAPMAP LDAP_NETWORK_TIMEOUT SM_CONF_LDAP_INITIALIZE
SM_CONF_LDAP_MEMFREE LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8
MIME8TO7 NAMED_BIND NETINET NETUNIX NEWDB=5.3 CDB=1 NIS
PICKY_HELO_CHECK PIPELINING SASLv2 SCANF SOCKETMAP STARTTLS
MTA_HAVE_TLSv1_3 TCPWRAPPERS TLS_EC= 2 TLS_VRFY_PER_CTX USERDB
USE_LDAP_INIT XDEBUG
/etc/mail/sendmail.cf: line 91: LDAP map: cannot open secret /etc/mail/ldap-secret: Permission denied
============ SYSTEM IDENTITY (after readcf) ============
(short domain name) $w = fbsd15
(canonical domain name) $j = fbsd15.local
(subdomain name) $m = local
(node name) $k = fbsd15.local
========================================================
ADDRESS TEST MODE (ruleset 3 NOT automatically invoked)
Enter <ruleset> <address>
> fbsd15:~/c/sendmail-8.19.0.2 $ cc --version
FreeBSD clang version 19.1.7 (https://github.com/llvm/llvm-project.git llvmorg-19.1.7-0-gcd708029e0b2)
Target: x86_64-unknown-freebsd15.1
Thread model: posix
InstalledDir: /usr/bin
[toc] | [prev] | [standalone]
Back to top | Article view | comp.mail.sendmail
csiph-web