Skip to content

Commit

Permalink
Quickfix against SMTP smuggling
Browse files Browse the repository at this point in the history
  • Loading branch information
tonioo committed Dec 22, 2023
1 parent 7097e15 commit e7995ad
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions modoboa_installer/scripts/files/postfix/main.cf.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,11 @@ smtpd_tls_exclude_ciphers = aNULL, MD5 , DES, ADH, RC4, PSD, SRP, 3DES, eNULL
# Enable elliptic curve cryptography
smtpd_tls_eecdh_grade = strong

# SMTP Smuggling prevention
# See https://www.postfix.org/smtp-smuggling.html
smtpd_data_restrictions = reject_unauth_pipelining
smtpd_forbid_unauth_pipelining = yes

# Use TLS if this is supported by the remote SMTP server, otherwise use plaintext.
smtp_tls_CApath = /etc/ssl/certs
smtp_tls_security_level = may
Expand Down

0 comments on commit e7995ad

Please sign in to comment.