Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.mail.sendmail > #8331 > unrolled thread

sendmail snapshot 8.19.0.2 is available

Started byClaus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org>
First post2026-06-28 01:42 -0400
Last post2026-07-01 19:22 +0000
Articles 19 — 2 participants

Back to article view | Back to comp.mail.sendmail


Contents

  sendmail snapshot 8.19.0.2 is available Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> - 2026-06-28 01:42 -0400
    Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-01 17:54 +0000
      Re: sendmail snapshot 8.19.0.2 is available Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> - 2026-07-03 02:03 -0400
        Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 13:47 +0000
    Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-01 19:13 +0000
      Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-02 23:22 +0000
        Re: sendmail snapshot 8.19.0.2 is available Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> - 2026-07-03 13:50 -0400
          Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 18:33 +0000
          Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 19:19 +0000
            Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 22:44 +0000
              Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-03 23:10 +0000
                Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-04 00:27 +0000
                  Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-04 01:11 +0000
                    Re: sendmail snapshot 8.19.0.2 is available Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> - 2026-07-07 03:37 -0400
                      Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-09 13:24 +0000
                        Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-09 14:11 +0000
                          Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-09 17:51 +0000
                            Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-09 20:38 +0000
    Re: sendmail snapshot 8.19.0.2 is available kalevi@kolttonen.fi (Kalevi Kolttonen) - 2026-07-01 19:22 +0000

#8331 — sendmail snapshot 8.19.0.2 is available

FromClaus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org>
Date2026-06-28 01:42 -0400
Subjectsendmail snapshot 8.19.0.2 is available
Message-ID<111qc86$tmt$1@news.misty.com>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

sendmail snapshot 8.19.0.2 is available for testing. It has two new
FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
log key-exchange algorithm (TLS) and also a new option: TLSEC.

SHA256 (sendmail.8.19.0.2.tar.gz) = f3f2456be0534dec17096a4d94cf6b5487d79f21ab90ef0ce734c2c56ba6a312
SHA256 (sendmail.8.19.0.2.tar.gz.sig) = 9f98666d9e13e27a94719838f746cd5684fd459fbca08181f47512de2c82658d

Available at:
https://ftp.sendmail.org/snapshots/sendmail.8.19.0.2.tar.gz
https://ftp.sendmail.org/snapshots/sendmail.8.19.0.2.tar.gz.sig
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJqQCWjAAoJEMApzDDVddAnfrEQAIcRKBKUzfoQ5lic8ENX0hW4
D71o26+/iqa00zE18YJApWIf7cntSBdQzBhA8XOUFXRrg94vBxuCz4fB5NfrQusT
U3itWOIvBmevEG3YNri7IaMkeVwhJ2wtZ+n92iuvMQcxGPnp+yEqQj/1y7w1RuL4
4O9I4L+mnJvy2vfmXZkTQ+Ul9XaQfOmY7lmI3Rt2BiWX4x8QeVXHcVBaaull76Ek
gWxH/cOnOkuxD+Fq1UcCmjy2J+dtVrStcTy2x2NtML8unw/KummqrDkafJ7zfB2r
9hrsKxltYX5i/RoknTnJud8hmXKFBoL88V7sraA38Siy/olK11ktBuRWfzxCHNcl
rhix4IJTdi826YeSXE5yWqS0Q/CUwFwP3Ski6+lkJTRpaLAGJcPlW/6oFI6t/Yqy
046/bnJmzTO05a5GyH/BTepEXgteNq8tJiYvmAO4wdo9C9hIxD0KoILn6zUFdL3V
2KxqkHjdFCu7urNHcgyhqQ/RKZwI8GqWU8diub7HcRtUyqktDyf/iuB0YFGyg+SN
G+7Lsj5s8PJ2+dxmZyei85ZJsYDyfntnBC27gb9brclfDVLpUzRmG5xTvahswlWg
3TO4/2w6tcTKsmnJWu+f2BgKLcvZKWZpiQ5V2GyIw/GSso0BxcJiUsRluaLIMB/J
W58jxqfRKbjHESal2d8I
=2+9l
-----END PGP SIGNATURE-----

[toc] | [next] | [standalone]


#8333

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-01 17:54 +0000
Message-ID<1123k9h$21rfk$1@dont-email.me>
In reply to#8331
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> sendmail snapshot 8.19.0.2 is available for testing. It has two new
> FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
> log key-exchange algorithm (TLS) and also a new option: TLSEC.

I used Fedora Linux 44 RPM sendmail.spec with modifications:

1) Removed applying all patches since they were for 8.18.2.
   Since the switch to ISO C function definitions, none of
   the Red Hat patches apply any more.

2) Added -D_FFR_EKU_NOCLIENTAUTH and -D_FFR_KEX


~ $ rpm -qi gcc|head -3
Name        : gcc
Version     : 16.1.1
Release     : 2.fc44


Sendmail 8.19.0.2 compiles with some warnings, most of
them being deprecations of certain functions since OpenSSL
3.0. However, these might be worth checking:

In function ‘sm_strlcpy’,
    inlined from ‘sm_errstring’ at err.c:1238:9:
../libsm/strl.c:70:28: warning: ‘strlen’ reading 1 or more bytes from a region of size 0 [-Wstringop-overread]
   70 |                 return i + strlen(src + i);
      |                            ^
In function ‘sm_strlcpy’,
    inlined from ‘safedirpath’ at ../libsmutil/safefile.c:556:10:
../libsm/strl.c:70:28: warning: ‘strlen’ reading 1 or more bytes from a region of size 0 [-Wstringop-overread]
   70 |                 return i + strlen(src + i);
      |                            ^

br,
KK

[toc] | [prev] | [next] | [standalone]


#8337

FromClaus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org>
Date2026-07-03 02:03 -0400
Message-ID<1127jar$1th$1@news.misty.com>
In reply to#8333
Kalevi Kolttonen wrote:

> In function ‘sm_strlcpy’,
>     inlined from ‘sm_errstring’ at err.c:1238:9:
> ../libsm/strl.c:70:28: warning: ‘strlen’ reading 1 or more bytes from
> a region of size 0 [-Wstringop-overread]
>    70 |                 return i + strlen(src + i);

Seems like a bogus warning.

        if (src[i] == '\0')
                return i;
        else
                return i + strlen(src + i);

In the "else" case src[i] is not '\0',
hence there is at least one non-NUL char in src+i.

[toc] | [prev] | [next] | [standalone]


#8338

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-03 13:47 +0000
Message-ID<1128ehp$3e9qs$1@dont-email.me>
In reply to#8337
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> Kalevi Kolttonen wrote:
> 
>> In function â??sm_strlcpyâ??,
>>     inlined from â??sm_errstringâ?? at err.c:1238:9:
>> ../libsm/strl.c:70:28: warning: â??strlenâ?? reading 1 or more bytes from
>> a region of size 0 [-Wstringop-overread]
>>    70 |                 return i + strlen(src + i);
> 
> Seems like a bogus warning.
> 
>         if (src[i] == '\0')
>                 return i;
>         else
>                 return i + strlen(src + i);
> 
> In the "else" case src[i] is not '\0',
> hence there is at least one non-NUL char in src+i.

Yes, indeed.

br,
KK

[toc] | [prev] | [next] | [standalone]


#8334

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-01 19:13 +0000
Message-ID<1123otj$237l0$1@dont-email.me>
In reply to#8331
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> sendmail snapshot 8.19.0.2 is available for testing. It has two new
> FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
> log key-exchange algorithm (TLS) and also a new option: TLSEC.

It builds on OmniOS latest stable (Open Solaris descendant based on
illumos kernel):

~/src/3/sendmail-8.19.0.2@omnios $ uname -a
SunOS omnios 5.11 omnios-r151058-c1eded413b i86pc i386 i86pc

~/src/3/sendmail-8.19.0.2@omnios $ gcc --version
gcc (OmniOS 151058/15.2.0-il-0) 15.2.0
Copyright (C) 2025 Free Software Foundation, Inc.
This is free software; see the source for copying conditions.  There is NO
warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

~/src/3/sendmail-8.19.0.2@omnios $ cat devtools/Site/site.config.m4
define(`confMAPDEF', `-DNEWDB -DMAP_REGEX -DSOCKETMAP -DNAMED_BIND=1 -I/opt/ooce/include/ -L/opt/ooce/lib -L/opt/ooce/lib/sasl2 -L/opt/ooce/lib/amd64')dnl
define(`confINCDIRS', `-I/opt/ooce/include/')dnl
APPENDDEF(`conf_sendmail_ENVDEF', `-DSTARTTLS -D_FFR_TLS_1 -DTLS_EC -D_FFR_TLS_USE_CERTIFICATE_CHAIN_FILE -DDANE -D_FFR_EKU_NOCLIENTAUTH -D_FFR_KEX -DHASUNSETENV')dnl
APPENDDEF(`confLIBDIRS', `-L/opt/ooce/lib/amd64 -R/opt/ooce/lib/amd64')dnl
APPENDDEF(`conf_sendmail_LIBS', `-lssl -lcrypto -ldb -lsasl2')dnl
APPENDDEF(`confENVDEF', `-DSASL=2 -I/opt/ooce/include/')dnl
APPENDDEF(`conf_sendmail_ENVDEF', `-DMILTER')dnl

~/src/3/sendmail-8.19.0.2@omnios $ obj.SunOS.5.11.i86pc/sendmail/sendmail -bt -d0.1</dev/null 
Version 8.19.0.2
 Compiled with: DANE HAVE_SSL_CTX_dane_enable MAX_TLSA_RR=64 DNSMAP
                IPV6_FULL LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8 MIME8TO7
                NAMED_BIND NETINET NETINET6 NETUNIX NEWDB=5.3 PIPELINING SASLv2
                SCANF SOCKETMAP STARTTLS MTA_HAVE_TLSv1_3 TLS_EC= 1
                TLS_VRFY_PER_CTX USERDB XDEBUG
/etc/mail/sendmail.cf: line 0: cannot open: No such file or directory

[toc] | [prev] | [next] | [standalone]


#8336

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-02 23:22 +0000
Message-ID<1126rrg$30po9$1@dont-email.me>
In reply to#8334
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
>> sendmail snapshot 8.19.0.2 is available for testing. It has two new
>> FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
>> log key-exchange algorithm (TLS) and also a new option: TLSEC.
> 
> It builds on OmniOS latest stable (Open Solaris descendant based on
> illumos kernel):

It has been running flawlessly since I installed it and
imported it under SMF control.

br,
KK

[toc] | [prev] | [next] | [standalone]


#8339

FromClaus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org>
Date2026-07-03 13:50 -0400
Message-ID<1128sp9$k7k$1@news.misty.com>
In reply to#8336
Kalevi Kolttonen wrote:

> It has been running flawlessly since I installed it and

Thanks for the info!

Do you see any PQC key_exchange algorithm in your logs
(e.g., X25519MLKEM768)?

Have you enabled overriding EKU restrictions?
Does it work as expected?

[toc] | [prev] | [next] | [standalone]


#8340

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-03 18:33 +0000
Message-ID<1128v9k$3jp27$1@dont-email.me>
In reply to#8339
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> Kalevi Kolttonen wrote:
> 
>> It has been running flawlessly since I installed it and
> 
> Thanks for the info!
> 
> Do you see any PQC key_exchange algorithm in your logs
> (e.g., X25519MLKEM768)?
> 
> Have you enabled overriding EKU restrictions?
> Does it work as expected?

No, this is just an internal LAN centralized mail
server and it has no TLS enabled.

br,
KK

[toc] | [prev] | [next] | [standalone]


#8341

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-03 19:19 +0000
Message-ID<11291vg$3kmbk$1@dont-email.me>
In reply to#8339
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> Do you see any PQC key_exchange algorithm in your logs
> (e.g., X25519MLKEM768)?
> 
> Does it work as expected?

I created a self-signed cert and enabled STARTTLS advertsing.
I then used swaks:

fedora-local$ swaks -tls --to=kalevi@omnios.local --server omnios.local


This is what I see on OmniOS /var/log/syslog:

Jul  3 22:11:28 localhost sendmail[21671]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE
Jul  3 22:11:28 localhost sendmail[21671]: [ID 801593 mail.info] 663JBSWB021671: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260703221123.605813@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]
Jul  3 22:11:28 localhost sendmail[21673]: [ID 801593 mail.info] 663JBSWB021671: to=<kalevi@omnios.local>, delay=00:00:00, xdelay=00:00:00, mailer=cyrusv2, pri=120268, relay=localhost, dsn=2.1.5, stat=Sent

> Have you enabled overriding EKU restrictions?

How do I do it? I have compiled with the required _FFR.

br,
KK

[toc] | [prev] | [next] | [standalone]


#8342

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-03 22:44 +0000
Message-ID<1129e05$3o88m$1@dont-email.me>
In reply to#8341
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> 
>> Have you enabled overriding EKU restrictions?
> 
> How do I do it? I have compiled with the required _FFR.

Okay, here's what I got so far: EKU = Extended Key Usage
for certificates. Here specifically I guess we are interested
in Server Authentication and client Authentication.

If I understood correct, the new FFR is for making exceptions
in the receiving server when the sender is using Server
Authentication certificate.

Fedora 44 is my client and I have created a self-signed cert
with:

~/tmp/eku $ openssl x509 -in fedora-serverauth.crt -noout -text | grep -A1 "Extended Key Usage"
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication

fedora$ swaks --tls-cert=fedora-serverauth.crt --tls-key=fedora-serverauth.key -tls --to=kalevi@kolttonen.fi --server omnios.local

<-  220 2.0.0 Ready to start TLS
=== TLS started with cipher TLSv1.3:TLS_AES_256_GCM_SHA384:256
=== TLS client certificate requested and sent
=== TLS client[0] subject=[/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local]
===               commonName=[fedora.local], subjectAltName=[DNS:fedora.local] notAfter=[2036-06-30T21:57:43Z]
=== TLS peer[0]   subject=[/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=omnios.local]
===               commonName=[omnios.local], subjectAltName=[] notAfter=[2036-06-30T18:36:01Z]
=== TLS peer certificate failed CA verification (self-signed certificate), passed host verification (using host omnios.local to verify)
 ~> EHLO fedora.local
<~  250-omnios.local Hello fedora.local [192.168.1.154], pleased to meet you
<~  250-ENHANCEDSTATUSCODES
<~  250-PIPELINING
<~  250-EXPN
<~  250-VERB
<~  250-8BITMIME
<~  250-SIZE
<~  250-DSN
<~  250-ETRN
<~  250-AUTH DIGEST-MD5 CRAM-MD5
<~  250-DELIVERBY
<~  250 HELP
 ~> MAIL FROM:<kalevi@fedora.local>
<~  250 2.1.0 <kalevi@fedora.local>... Sender ok
 ~> RCPT TO:<kalevi@kolttonen.fi>
<~* 550 5.7.1 <kalevi@kolttonen.fi>... Relaying denied
 ~> QUIT
<~  221 2.0.0 omnios.local closing connection

omnios mail log:

Jul  4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] tls_srv_features=empty, stat=0, relay=fedora.local [192.168.1.154]
Jul  4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS: TLS cert verify: depth=0 /C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, state=0, reason=unsuitable certificate purpose
Jul  4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=FAIL, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE
Jul  4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=unsuitable certificate purpose
Jul  4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5
Jul  4 01:24:25 localhost sendmail[23344]: [ID 801593 mail.notice] 663MOPb1023344: ruleset=check_rcpt, arg1=<kalevi@kolttonen.fi>, relay=fedora.local [192.168.1.154], reject=550 5.7.1 <kalevi@kolttonen.fi>... Relaying denied
Jul  4 01:24:26 localhost sendmail[23344]: [ID 801593 mail.info] 663MOPb1023344: from=<kalevi@fedora.local>, size=0, class=0, nrcpts=0, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]

It looks good "reason=unsuitable certificate purpose" so Sendmail 8.19.0.2
does not accept this cert because it is for server authentication.

Relaying using a different cert with no EKU works and relaying is
accepted by OmniOS.

Again, If I understood correctly, using 'O' should make exceptions
for clients that offer server EKU cert. This is what I have in my
access.db:

root@omnios:/etc/mail# cat access
TLS_Srv_Features:192.168.1.154  O
TLS_Srv_Features:fedora.local   O
Srv_Features:192.168.1.154      v
CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local    RELAY

But OmniOS denies relaying just the same and logs show "tls_srv_features=empty"

However, if I enable it globally using option:

root@omnios:/etc/mail# grep -i tlssrv sendmail.cf 
O TLSSrvOptions=O

then EKU exception works and relaying is allowed using server cert:

Jul  4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] tls_srv_features=empty, stat=0, relay=fedora.local [192.168.1.154]
Jul  4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE, eku=overrode_no_client_auth
Jul  4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=ok
Jul  4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 EXTERNAL OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5
Jul  4 01:39:18 localhost sendmail[23452]: [ID 801593 mail.info] 663MdIM4023452: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260704013913.652411@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]

I omitted the rest of the mail log because my OmniOS has no access to
outside world so messages destined to kalevi@kolttonen.fi end up queued
and will bounce. But the thing is, relaying worked!

So it seems to me that access.db method is buggy somehow?

br,
KK

[toc] | [prev] | [next] | [standalone]


#8343

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-03 23:10 +0000
Message-ID<1129fi0$3ojd0$1@dont-email.me>
In reply to#8342
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> Again, If I understood correctly, using 'O' should make exceptions
> for clients that offer server EKU cert. This is what I have in my
> access.db:
> 
> root@omnios:/etc/mail# cat access
> TLS_Srv_Features:192.168.1.154  O
> TLS_Srv_Features:fedora.local   O
> Srv_Features:192.168.1.154      v
> CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local    RELAY

Well, I guess the sendmail.cf expects 'TLS_Srv' and
not 'TLS_Srv_Features':

root@omnios:/etc/mail# grep -i tls_s sendmail.cf 
###  tls_server: is connection with server "good" enough?
Stls_server
R$*             $: $1 $| $>D <$&{server_name}> <?> <! "TLS_Srv"> <>
R$* $| <?>$*    $: $1 $| $>A <$&{server_addr}> <?> <! "TLS_Srv"> <>
R$* $| <?>$*    $: $1 $| <$(access "TLS_Srv": $: ? $)>

So I modified my access.db:

root@omnios:/etc/mail# cat access
TLS_Srv:192.168.1.154   O
TLS_Srv:fedora.local    O
Srv_Features:192.168.1.154      v
CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local    RELAY

and rebuilt the DB. But still relaying denied...

br,
KK

[toc] | [prev] | [next] | [standalone]


#8344

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-04 00:27 +0000
Message-ID<1129k2a$3pps6$1@dont-email.me>
In reply to#8343
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
>> Again, If I understood correctly, using 'O' should make exceptions
>> for clients that offer server EKU cert. This is what I have in my
>> access.db:
>> 
>> root@omnios:/etc/mail# cat access
>> TLS_Srv_Features:192.168.1.154  O
>> TLS_Srv_Features:fedora.local   O
>> Srv_Features:192.168.1.154      v
>> CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local    RELAY
> 
> Well, I guess the sendmail.cf expects 'TLS_Srv' and
> not 'TLS_Srv_Features':
> 
> root@omnios:/etc/mail# grep -i tls_s sendmail.cf 
> ###  tls_server: is connection with server "good" enough?
> Stls_server
> R$*             $: $1 $| $>D <$&{server_name}> <?> <! "TLS_Srv"> <>
> R$* $| <?>$*    $: $1 $| $>A <$&{server_addr}> <?> <! "TLS_Srv"> <>
> R$* $| <?>$*    $: $1 $| <$(access "TLS_Srv": $: ? $)>
> 
> So I modified my access.db:
> 
> root@omnios:/etc/mail# cat access
> TLS_Srv:192.168.1.154   O
> TLS_Srv:fedora.local    O
> Srv_Features:192.168.1.154      v
> CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local    RELAY
> 
> and rebuilt the DB. But still relaying denied...

No! I was missing FEATURE(`tls_session_features'), now I can
see the ruleset Stls_srv_features and as far as I can tell, it
queries access.db using 'TLS_Srv_Features'. So I am back where
I started:

root@omnios:/etc/mail# cat access
TLS_Srv_Features:192.168.1.154  O
TLS_Srv_Features:fedora.local   O
Srv_Features:192.168.1.154      v
CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local    RELAY

Still, relaying denied. I am giving up for tonight.

br,
KK

[toc] | [prev] | [next] | [standalone]


#8345

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-04 01:11 +0000
Message-ID<1129mju$3qaqt$1@dont-email.me>
In reply to#8344
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> No! I was missing FEATURE(`tls_session_features'), now I can
> see the ruleset Stls_srv_features and as far as I can tell, it
> queries access.db using 'TLS_Srv_Features'. So I am back where
> I started:
> 
> root@omnios:/etc/mail# cat access
> TLS_Srv_Features:192.168.1.154  O
> TLS_Srv_Features:fedora.local   O
> Srv_Features:192.168.1.154      v
> CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local    RELAY
> 
> Still, relaying denied. I am giving up for tonight.

I could not stop so now after reading the code, I finally got
it to work with access.db:

root@omnios:/etc/mail# cat access
TLS_Srv_Features:192.168.1.154  flags=O
TLS_Srv_Features:fedora.local   flags=O
Srv_Features:192.168.1.154      v
CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local    RELAY

and the maillog shows "eku=overrode_no_client_auth":

Jul  4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] tls_srv_features=flags=O, relay=fedora.local [192.168.1.154]
Jul  4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.debug] tls_srv_features=parsed, flags=O, relay=fedora.local [192.168.1.154]
Jul  4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE, eku=overrode_no_client_auth
Jul  4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=ok
Jul  4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 EXTERNAL OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5
Jul  4 04:06:39 localhost sendmail[24503]: [ID 801593 mail.info] 66416cjO024503: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260704040633.691177@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]


Time to go to sleep, it is over 4 o'clock in the morning.

br,
KK

[toc] | [prev] | [next] | [standalone]


#8346

FromClaus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org>
Date2026-07-07 03:37 -0400
Message-ID<112iabk$3pt$1@news.misty.com>
In reply to#8345
Kalevi Kolttonen wrote:

> STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3,
> verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256,
> key_exchange=ECDHE, eku=overrode_no_client_auth

Thanks for giving this a try, sorry for not providing (better)
documentation (yet).

Which OpenSSL version do you use?
With 3.5ff you should get something like
key_exchange=X25519MLKEM768
(PQC)

[toc] | [prev] | [next] | [standalone]


#8347

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-09 13:24 +0000
Message-ID<112o7fa$dq7b$1@dont-email.me>
In reply to#8346
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> Kalevi Kolttonen wrote:
> 
>> STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3,
>> verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256,
>> key_exchange=ECDHE, eku=overrode_no_client_auth
> 
> Thanks for giving this a try, sorry for not providing (better)
> documentation (yet).
> 
> Which OpenSSL version do you use?
> With 3.5ff you should get something like
> key_exchange=X25519MLKEM768
> (PQC)

root@omnios:~# openssl version -a
OpenSSL 3.6.3 9 Jun 2026 (Library: OpenSSL 3.6.3 9 Jun 2026)
built on: Thu Jun 11 23:19:59 2026 UTC
platform: solaris64-x86_64-gcc
options:  bn(64,64)
compiler: gcc -fPIC -m64 -O2 -fno-omit-frame-pointer -fno-aggressive-loop-optimizations -fstack-protector-strong -gdwarf-4 -gstrict-dwarf  -m64 -Wa,--noexecstack -Wall -O3 -DFILIO_H -DL_ENDIAN -DOPENSSL_PIC -D_REENTRANT -DOPENSSL_BUILDING_OPENSSL -DZLIB -DNDEBUG
OPENSSLDIR: "/usr/ssl"
ENGINESDIR: "/usr/lib/amd64/engines-3"
MODULESDIR: "/usr/lib/amd64/ossl-modules"
Seeding source: os-specific
CPUINFO: OPENSSL_ia32cap=0x7ffaf3ffffebffff:0x00000000029c6fbf:0x00000000bc002e00:0x0000000000000000:0x0000000000000000

root@fedora:~# $ openssl version -a
OpenSSL 3.5.7 9 Jun 2026 (Library: OpenSSL 3.5.7 9 Jun 2026)
built on: Wed Jun 10 00:00:00 2026 UTC
platform: linux-x86_64
options:  bn(64,64)
compiler: gcc -fPIC -pthread -m64 -Wa,--noexecstack -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1  -m64 -march=x86-64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -mtls-dialect=gnu2 -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer   -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Wno-complain-wrong-lang -Werror=format-security -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -mtls-dialect=gnu2 -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -Wa,--noexecstack -Wa,--generate-missing-build-notes=yes -specs=/usr/lib/rpm/redhat/redhat-hardened-ld -specs=/usr/lib/rpm/redhat/redhat-hardened-ld-errors -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -specs=/usr/lib/rpm/redhat/redhat-package-notes -DOPENSSL_USE_NODELETE -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_BUILDING_OPENSSL -DZLIB -DNDEBUG -D_GNU_SOURCE -DPURIFY -DDEVRANDOM="\\"/dev/urandom\\"" -DOPENSSL_PEDANTIC_ZEROIZATION -DREDHAT_FIPS_VENDOR="\\"Red Hat Enterprise Linux OpenSSL FIPS Provider\\"" -DREDHAT_FIPS_VERSION="\\"3.5.7-9c2719932f8ae75e\\"" -DSYSTEM_CIPHERS_FILE="/etc/crypto-policies/back-ends/opensslcnf.config"
OPENSSLDIR: "/etc/pki/tls"
ENGINESDIR: "/usr/lib64/engines-3"
MODULESDIR: "/usr/lib64/ossl-modules"
Seeding source: os-specific
CPUINFO: OPENSSL_ia32cap=0x7ed8320b078bffff:0x00400004219c91a9:0x0000000000000000:0x0000000000000000:0x0000000000000000

root@omnios:~# openssl list -tls-groups
secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024

root@fedora:~# openssl list -tls-groups
secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024


Using this command:

  openssl s_client -starttls smtp -connect omnios.local:25 -groups X25519MLKEM768

Server log is:

Jul  9 16:23:12 localhost sendmail[14522]: [ID 702911 mail.warning] STARTTLS=server, error: accept failed=-1, reason=no suitable key share, SSL_error=1, errno=0, retry=-1, relay=fedora.local [192.168.1.154]
Jul  9 16:23:12 localhost sendmail[14522]: [ID 702911 mail.warning] STARTTLS=server: error:0A000065:SSL routines::no suitable key share:ssl/statem/extensions.c:1412:



br,
KK

[toc] | [prev] | [next] | [standalone]


#8351

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-09 14:11 +0000
Message-ID<112oa5k$emd2$1@dont-email.me>
In reply to#8347
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> root@omnios:~# openssl list -tls-groups
> secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024
> 
> root@fedora:~# openssl list -tls-groups
> secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024

I ran OpenSSL server on OmniOS:

root@omnios:/etc/mail/certs# cat f
openssl s_server -accept 8443 -key omnios.local.key -cert omnios.local.crt

Connected to it with:

openssl s_client -connect omnios.local:8443 -groups X25519MLKEM768 

Connection worked, so maybe this has something to do with Sendmail
configuration or code.

br,
KK

[toc] | [prev] | [next] | [standalone]


#8352

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-09 17:51 +0000
Message-ID<112on30$ivv0$1@dont-email.me>
In reply to#8351
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> I ran OpenSSL server on OmniOS:
> 
> root@omnios:/etc/mail/certs# cat f
> openssl s_server -accept 8443 -key omnios.local.key -cert omnios.local.crt
> 
> Connected to it with:
> 
> openssl s_client -connect omnios.local:8443 -groups X25519MLKEM768 
> 
> Connection worked, so maybe this has something to do with Sendmail
> configuration or code.

I tested a small patch:

===============================================================================
diff -urN sendmail-8.19.0.2/sendmail/tls.c sendmail-8.19.0.2-patch/sendmail/tls.c
--- sendmail-8.19.0.2/sendmail/tls.c    2026-07-09 20:47:18.544514740 +0300
+++ sendmail-8.19.0.2-patch/sendmail/tls.c      2026-07-09 20:47:26.068638009 +0300
@@ -1692,6 +1692,11 @@
        if (kf2 != NULL)
                *--kf2 = ',';
 
+       if (!SSL_CTX_set1_groups_list(*tls_ctx, "X25519MLKEM768:X25519")) {
+               abort();
+       }
+       sm_syslog(LOG_INFO, NOQID, "SSL_CTX_set1_groups_list() success");
+
        return ok;
 }

===============================================================================

After that PQC key exchange worked with s_client:

root@omnios:/opt/site/sbin# grep success /var/log/syslog
Jul  9 20:43:51 localhost sendmail[27872]: [ID 702911 mail.info] SSL_CTX_set1_groups_list() success
root@omnios:/opt/site/sbin# grep X25519MLKEM768 /var/log/syslog
Jul  9 20:44:07 localhost sendmail[27877]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=X25519MLKEM768

I guess this proves that Sendmail 8.19.0.2 OpenSSL initialization code
is to blame, but I do not know the proper fix.

br,
KK

[toc] | [prev] | [next] | [standalone]


#8354

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-09 20:38 +0000
Message-ID<112p0s9$mnqn$1@dont-email.me>
In reply to#8352
Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
> I tested a small patch:
> 
> ===============================================================================
> diff -urN sendmail-8.19.0.2/sendmail/tls.c sendmail-8.19.0.2-patch/sendmail/tls.c
> --- sendmail-8.19.0.2/sendmail/tls.c    2026-07-09 20:47:18.544514740 +0300
> +++ sendmail-8.19.0.2-patch/sendmail/tls.c      2026-07-09 20:47:26.068638009 +0300
> @@ -1692,6 +1692,11 @@
>         if (kf2 != NULL)
>                 *--kf2 = ',';
>  
> +       if (!SSL_CTX_set1_groups_list(*tls_ctx, "X25519MLKEM768:X25519")) {
> +               abort();
> +       }
> +       sm_syslog(LOG_INFO, NOQID, "SSL_CTX_set1_groups_list() success");
> +
>         return ok;
>  }
> 
> ===============================================================================

I have been reading tls.c inittls() and isolated the problem to initec()
call with TLS_EC compilation define enabled.

Having TLS_EC=0 in conf_sendmail_ENVDEF in devtools/Site/site.config.m4
fixes the problem and enables Sendmail to use OpenSSL defaults. Then PQC
key exchange works:

Jul  9 23:33:47 localhost sendmail[7555]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=X25519MLKEM768

br,
KK

[toc] | [prev] | [next] | [standalone]


#8335

Fromkalevi@kolttonen.fi (Kalevi Kolttonen)
Date2026-07-01 19:22 +0000
Message-ID<1123pe3$23em6$1@dont-email.me>
In reply to#8331
Claus Aßmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
> sendmail snapshot 8.19.0.2 is available for testing. It has two new
> FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
> log key-exchange algorithm (TLS) and also a new option: TLSEC.

It builds on FreeBSD 15.1:

fbsd15:~/c/sendmail-8.19.0.2 $ obj.FreeBSD.15.1-RELEASE.amd64/sendmail/sendmail -bt -d0.1</dev/null 
Version 8.19.0.2
 Compiled with: DANE HAVE_SSL_CTX_dane_enable MAX_TLSA_RR=64 DNSMAP
                IPV6_FULL LDAPMAP LDAP_NETWORK_TIMEOUT SM_CONF_LDAP_INITIALIZE
                SM_CONF_LDAP_MEMFREE LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8
                MIME8TO7 NAMED_BIND NETINET NETUNIX NEWDB=5.3 CDB=1 NIS
                PICKY_HELO_CHECK PIPELINING SASLv2 SCANF SOCKETMAP STARTTLS
                MTA_HAVE_TLSv1_3 TCPWRAPPERS TLS_EC= 2 TLS_VRFY_PER_CTX USERDB
                USE_LDAP_INIT XDEBUG
/etc/mail/sendmail.cf: line 91: LDAP map: cannot open secret /etc/mail/ldap-secret: Permission denied

============ SYSTEM IDENTITY (after readcf) ============
      (short domain name) $w = fbsd15
  (canonical domain name) $j = fbsd15.local
         (subdomain name) $m = local
              (node name) $k = fbsd15.local
========================================================

ADDRESS TEST MODE (ruleset 3 NOT automatically invoked)
Enter <ruleset> <address>

> fbsd15:~/c/sendmail-8.19.0.2 $ cc --version
FreeBSD clang version 19.1.7 (https://github.com/llvm/llvm-project.git llvmorg-19.1.7-0-gcd708029e0b2)
Target: x86_64-unknown-freebsd15.1
Thread model: posix
InstalledDir: /usr/bin

[toc] | [prev] | [standalone]


Back to top | Article view | comp.mail.sendmail


csiph-web