• sendmail snapshot 8.19.0.2 is available

    From Claus =?iso-8859-1?Q?A=DFmann?=@INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org to comp.mail.sendmail on Sun Jun 28 01:42:30 2026
    From Newsgroup: comp.mail.sendmail

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    sendmail snapshot 8.19.0.2 is available for testing. It has two new
    FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
    log key-exchange algorithm (TLS) and also a new option: TLSEC.

    SHA256 (sendmail.8.19.0.2.tar.gz) = f3f2456be0534dec17096a4d94cf6b5487d79f21ab90ef0ce734c2c56ba6a312
    SHA256 (sendmail.8.19.0.2.tar.gz.sig) = 9f98666d9e13e27a94719838f746cd5684fd459fbca08181f47512de2c82658d

    Available at:
    https://ftp.sendmail.org/snapshots/sendmail.8.19.0.2.tar.gz https://ftp.sendmail.org/snapshots/sendmail.8.19.0.2.tar.gz.sig
    -----BEGIN PGP SIGNATURE-----

    iQIcBAEBAgAGBQJqQCWjAAoJEMApzDDVddAnfrEQAIcRKBKUzfoQ5lic8ENX0hW4 D71o26+/iqa00zE18YJApWIf7cntSBdQzBhA8XOUFXRrg94vBxuCz4fB5NfrQusT U3itWOIvBmevEG3YNri7IaMkeVwhJ2wtZ+n92iuvMQcxGPnp+yEqQj/1y7w1RuL4 4O9I4L+mnJvy2vfmXZkTQ+Ul9XaQfOmY7lmI3Rt2BiWX4x8QeVXHcVBaaull76Ek gWxH/cOnOkuxD+Fq1UcCmjy2J+dtVrStcTy2x2NtML8unw/KummqrDkafJ7zfB2r 9hrsKxltYX5i/RoknTnJud8hmXKFBoL88V7sraA38Siy/olK11ktBuRWfzxCHNcl rhix4IJTdi826YeSXE5yWqS0Q/CUwFwP3Ski6+lkJTRpaLAGJcPlW/6oFI6t/Yqy 046/bnJmzTO05a5GyH/BTepEXgteNq8tJiYvmAO4wdo9C9hIxD0KoILn6zUFdL3V 2KxqkHjdFCu7urNHcgyhqQ/RKZwI8GqWU8diub7HcRtUyqktDyf/iuB0YFGyg+SN G+7Lsj5s8PJ2+dxmZyei85ZJsYDyfntnBC27gb9brclfDVLpUzRmG5xTvahswlWg 3TO4/2w6tcTKsmnJWu+f2BgKLcvZKWZpiQ5V2GyIw/GSso0BxcJiUsRluaLIMB/J W58jxqfRKbjHESal2d8I
    =2+9l
    -----END PGP SIGNATURE-----
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Wed Jul 1 17:54:57 2026
    From Newsgroup: comp.mail.sendmail

    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
    sendmail snapshot 8.19.0.2 is available for testing. It has two new
    FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
    log key-exchange algorithm (TLS) and also a new option: TLSEC.

    I used Fedora Linux 44 RPM sendmail.spec with modifications:

    1) Removed applying all patches since they were for 8.18.2.
    Since the switch to ISO C function definitions, none of
    the Red Hat patches apply any more.

    2) Added -D_FFR_EKU_NOCLIENTAUTH and -D_FFR_KEX


    ~ $ rpm -qi gcc|head -3
    Name : gcc
    Version : 16.1.1
    Release : 2.fc44


    Sendmail 8.19.0.2 compiles with some warnings, most of
    them being deprecations of certain functions since OpenSSL
    3.0. However, these might be worth checking:

    In function rCysm_strlcpyrCO,
    inlined from rCysm_errstringrCO at err.c:1238:9:
    ../libsm/strl.c:70:28: warning: rCystrlenrCO reading 1 or more bytes from a region of size 0 [-Wstringop-overread]
    70 | return i + strlen(src + i);
    | ^
    In function rCysm_strlcpyrCO,
    inlined from rCysafedirpathrCO at ../libsmutil/safefile.c:556:10: ../libsm/strl.c:70:28: warning: rCystrlenrCO reading 1 or more bytes from a region of size 0 [-Wstringop-overread]
    70 | return i + strlen(src + i);
    | ^

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Wed Jul 1 19:13:55 2026
    From Newsgroup: comp.mail.sendmail

    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
    sendmail snapshot 8.19.0.2 is available for testing. It has two new
    FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
    log key-exchange algorithm (TLS) and also a new option: TLSEC.

    It builds on OmniOS latest stable (Open Solaris descendant based on
    illumos kernel):

    ~/src/3/sendmail-8.19.0.2@omnios $ uname -a
    SunOS omnios 5.11 omnios-r151058-c1eded413b i86pc i386 i86pc

    ~/src/3/sendmail-8.19.0.2@omnios $ gcc --version
    gcc (OmniOS 151058/15.2.0-il-0) 15.2.0
    Copyright (C) 2025 Free Software Foundation, Inc.
    This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

    ~/src/3/sendmail-8.19.0.2@omnios $ cat devtools/Site/site.config.m4 define(`confMAPDEF', `-DNEWDB -DMAP_REGEX -DSOCKETMAP -DNAMED_BIND=1 -I/opt/ooce/include/ -L/opt/ooce/lib -L/opt/ooce/lib/sasl2 -L/opt/ooce/lib/amd64')dnl
    define(`confINCDIRS', `-I/opt/ooce/include/')dnl APPENDDEF(`conf_sendmail_ENVDEF', `-DSTARTTLS -D_FFR_TLS_1 -DTLS_EC -D_FFR_TLS_USE_CERTIFICATE_CHAIN_FILE -DDANE -D_FFR_EKU_NOCLIENTAUTH -D_FFR_KEX -DHASUNSETENV')dnl
    APPENDDEF(`confLIBDIRS', `-L/opt/ooce/lib/amd64 -R/opt/ooce/lib/amd64')dnl APPENDDEF(`conf_sendmail_LIBS', `-lssl -lcrypto -ldb -lsasl2')dnl APPENDDEF(`confENVDEF', `-DSASL=2 -I/opt/ooce/include/')dnl APPENDDEF(`conf_sendmail_ENVDEF', `-DMILTER')dnl

    ~/src/3/sendmail-8.19.0.2@omnios $ obj.SunOS.5.11.i86pc/sendmail/sendmail -bt -d0.1</dev/null
    Version 8.19.0.2
    Compiled with: DANE HAVE_SSL_CTX_dane_enable MAX_TLSA_RR=64 DNSMAP
    IPV6_FULL LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8 MIME8TO7
    NAMED_BIND NETINET NETINET6 NETUNIX NEWDB=5.3 PIPELINING SASLv2
    SCANF SOCKETMAP STARTTLS MTA_HAVE_TLSv1_3 TLS_EC= 1
    TLS_VRFY_PER_CTX USERDB XDEBUG
    /etc/mail/sendmail.cf: line 0: cannot open: No such file or directory
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Wed Jul 1 19:22:43 2026
    From Newsgroup: comp.mail.sendmail

    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
    sendmail snapshot 8.19.0.2 is available for testing. It has two new
    FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
    log key-exchange algorithm (TLS) and also a new option: TLSEC.

    It builds on FreeBSD 15.1:

    fbsd15:~/c/sendmail-8.19.0.2 $ obj.FreeBSD.15.1-RELEASE.amd64/sendmail/sendmail -bt -d0.1</dev/null
    Version 8.19.0.2
    Compiled with: DANE HAVE_SSL_CTX_dane_enable MAX_TLSA_RR=64 DNSMAP
    IPV6_FULL LDAPMAP LDAP_NETWORK_TIMEOUT SM_CONF_LDAP_INITIALIZE
    SM_CONF_LDAP_MEMFREE LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8
    MIME8TO7 NAMED_BIND NETINET NETUNIX NEWDB=5.3 CDB=1 NIS
    PICKY_HELO_CHECK PIPELINING SASLv2 SCANF SOCKETMAP STARTTLS
    MTA_HAVE_TLSv1_3 TCPWRAPPERS TLS_EC= 2 TLS_VRFY_PER_CTX USERDB
    USE_LDAP_INIT XDEBUG
    /etc/mail/sendmail.cf: line 91: LDAP map: cannot open secret /etc/mail/ldap-secret: Permission denied

    ============ SYSTEM IDENTITY (after readcf) ============
    (short domain name) $w = fbsd15
    (canonical domain name) $j = fbsd15.local
    (subdomain name) $m = local
    (node name) $k = fbsd15.local ========================================================

    ADDRESS TEST MODE (ruleset 3 NOT automatically invoked)
    Enter <ruleset> <address>

    fbsd15:~/c/sendmail-8.19.0.2 $ cc --version
    FreeBSD clang version 19.1.7 (https://github.com/llvm/llvm-project.git llvmorg-19.1.7-0-gcd708029e0b2)
    Target: x86_64-unknown-freebsd15.1
    Thread model: posix
    InstalledDir: /usr/bin
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Thu Jul 2 23:22:24 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
    sendmail snapshot 8.19.0.2 is available for testing. It has two new
    FFRs: _FFR_EKU_NOCLIENTAUTH: override cert restrictions and _FFR_KEX:
    log key-exchange algorithm (TLS) and also a new option: TLSEC.

    It builds on OmniOS latest stable (Open Solaris descendant based on
    illumos kernel):

    It has been running flawlessly since I installed it and
    imported it under SMF control.

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Claus =?iso-8859-1?Q?A=DFmann?=@INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org to comp.mail.sendmail on Fri Jul 3 02:03:07 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen wrote:

    In function rCysm_strlcpyrCO,
    inlined from rCysm_errstringrCO at err.c:1238:9:
    ../libsm/strl.c:70:28: warning: rCystrlenrCO reading 1 or more bytes from
    a region of size 0 [-Wstringop-overread]
    70 | return i + strlen(src + i);

    Seems like a bogus warning.

    if (src[i] == '\0')
    return i;
    else
    return i + strlen(src + i);

    In the "else" case src[i] is not '\0',
    hence there is at least one non-NUL char in src+i.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Fri Jul 3 13:47:37 2026
    From Newsgroup: comp.mail.sendmail

    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
    Kalevi Kolttonen wrote:

    In function |o??sm_strlcpy|o??,
    inlined from |o??sm_errstring|o?? at err.c:1238:9:
    ../libsm/strl.c:70:28: warning: |o??strlen|o?? reading 1 or more bytes from >> a region of size 0 [-Wstringop-overread]
    70 | return i + strlen(src + i);

    Seems like a bogus warning.

    if (src[i] == '\0')
    return i;
    else
    return i + strlen(src + i);

    In the "else" case src[i] is not '\0',
    hence there is at least one non-NUL char in src+i.

    Yes, indeed.

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Claus =?iso-8859-1?Q?A=DFmann?=@INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org to comp.mail.sendmail on Fri Jul 3 13:50:33 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen wrote:

    It has been running flawlessly since I installed it and

    Thanks for the info!

    Do you see any PQC key_exchange algorithm in your logs
    (e.g., X25519MLKEM768)?

    Have you enabled overriding EKU restrictions?
    Does it work as expected?
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Fri Jul 3 18:33:24 2026
    From Newsgroup: comp.mail.sendmail

    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
    Kalevi Kolttonen wrote:

    It has been running flawlessly since I installed it and

    Thanks for the info!

    Do you see any PQC key_exchange algorithm in your logs
    (e.g., X25519MLKEM768)?

    Have you enabled overriding EKU restrictions?
    Does it work as expected?

    No, this is just an internal LAN centralized mail
    server and it has no TLS enabled.

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Fri Jul 3 19:19:12 2026
    From Newsgroup: comp.mail.sendmail

    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
    Do you see any PQC key_exchange algorithm in your logs
    (e.g., X25519MLKEM768)?

    Does it work as expected?

    I created a self-signed cert and enabled STARTTLS advertsing.
    I then used swaks:

    fedora-local$ swaks -tls --to=kalevi@omnios.local --server omnios.local


    This is what I see on OmniOS /var/log/syslog:

    Jul 3 22:11:28 localhost sendmail[21671]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE
    Jul 3 22:11:28 localhost sendmail[21671]: [ID 801593 mail.info] 663JBSWB021671: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260703221123.605813@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]
    Jul 3 22:11:28 localhost sendmail[21673]: [ID 801593 mail.info] 663JBSWB021671: to=<kalevi@omnios.local>, delay=00:00:00, xdelay=00:00:00, mailer=cyrusv2, pri=120268, relay=localhost, dsn=2.1.5, stat=Sent

    Have you enabled overriding EKU restrictions?

    How do I do it? I have compiled with the required _FFR.

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Fri Jul 3 22:44:21 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:

    Have you enabled overriding EKU restrictions?

    How do I do it? I have compiled with the required _FFR.

    Okay, here's what I got so far: EKU = Extended Key Usage
    for certificates. Here specifically I guess we are interested
    in Server Authentication and client Authentication.

    If I understood correct, the new FFR is for making exceptions
    in the receiving server when the sender is using Server
    Authentication certificate.

    Fedora 44 is my client and I have created a self-signed cert
    with:

    ~/tmp/eku $ openssl x509 -in fedora-serverauth.crt -noout -text | grep -A1 "Extended Key Usage"
    X509v3 Extended Key Usage:
    TLS Web Server Authentication

    fedora$ swaks --tls-cert=fedora-serverauth.crt --tls-key=fedora-serverauth.key -tls --to=kalevi@kolttonen.fi --server omnios.local

    <- 220 2.0.0 Ready to start TLS
    === TLS started with cipher TLSv1.3:TLS_AES_256_GCM_SHA384:256
    === TLS client certificate requested and sent
    === TLS client[0] subject=[/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local] === commonName=[fedora.local], subjectAltName=[DNS:fedora.local] notAfter=[2036-06-30T21:57:43Z]
    === TLS peer[0] subject=[/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=omnios.local] === commonName=[omnios.local], subjectAltName=[] notAfter=[2036-06-30T18:36:01Z]
    === TLS peer certificate failed CA verification (self-signed certificate), passed host verification (using host omnios.local to verify)
    EHLO fedora.local
    <~ 250-omnios.local Hello fedora.local [192.168.1.154], pleased to meet you
    <~ 250-ENHANCEDSTATUSCODES
    <~ 250-PIPELINING
    <~ 250-EXPN
    <~ 250-VERB
    <~ 250-8BITMIME
    <~ 250-SIZE
    <~ 250-DSN
    <~ 250-ETRN
    <~ 250-AUTH DIGEST-MD5 CRAM-MD5
    <~ 250-DELIVERBY
    <~ 250 HELP
    MAIL FROM:<kalevi@fedora.local>
    <~ 250 2.1.0 <kalevi@fedora.local>... Sender ok
    RCPT TO:<kalevi@kolttonen.fi>
    <~* 550 5.7.1 <kalevi@kolttonen.fi>... Relaying denied
    QUIT
    <~ 221 2.0.0 omnios.local closing connection

    omnios mail log:

    Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] tls_srv_features=empty, stat=0, relay=fedora.local [192.168.1.154]
    Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS: TLS cert verify: depth=0 /C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, state=0, reason=unsuitable certificate purpose
    Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=FAIL, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE
    Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=unsuitable certificate purpose
    Jul 4 01:24:25 localhost sendmail[23344]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5
    Jul 4 01:24:25 localhost sendmail[23344]: [ID 801593 mail.notice] 663MOPb1023344: ruleset=check_rcpt, arg1=<kalevi@kolttonen.fi>, relay=fedora.local [192.168.1.154], reject=550 5.7.1 <kalevi@kolttonen.fi>... Relaying denied
    Jul 4 01:24:26 localhost sendmail[23344]: [ID 801593 mail.info] 663MOPb1023344: from=<kalevi@fedora.local>, size=0, class=0, nrcpts=0, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]

    It looks good "reason=unsuitable certificate purpose" so Sendmail 8.19.0.2
    does not accept this cert because it is for server authentication.

    Relaying using a different cert with no EKU works and relaying is
    accepted by OmniOS.

    Again, If I understood correctly, using 'O' should make exceptions
    for clients that offer server EKU cert. This is what I have in my
    access.db:

    root@omnios:/etc/mail# cat access
    TLS_Srv_Features:192.168.1.154 O
    TLS_Srv_Features:fedora.local O
    Srv_Features:192.168.1.154 v CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY

    But OmniOS denies relaying just the same and logs show "tls_srv_features=empty"

    However, if I enable it globally using option:

    root@omnios:/etc/mail# grep -i tlssrv sendmail.cf
    O TLSSrvOptions=O

    then EKU exception works and relaying is allowed using server cert:

    Jul 4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] tls_srv_features=empty, stat=0, relay=fedora.local [192.168.1.154]
    Jul 4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE, eku=overrode_no_client_auth
    Jul 4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=ok
    Jul 4 01:39:18 localhost sendmail[23452]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 EXTERNAL OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5
    Jul 4 01:39:18 localhost sendmail[23452]: [ID 801593 mail.info] 663MdIM4023452: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260704013913.652411@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]

    I omitted the rest of the mail log because my OmniOS has no access to
    outside world so messages destined to kalevi@kolttonen.fi end up queued
    and will bounce. But the thing is, relaying worked!

    So it seems to me that access.db method is buggy somehow?

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Fri Jul 3 23:10:57 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    Again, If I understood correctly, using 'O' should make exceptions
    for clients that offer server EKU cert. This is what I have in my
    access.db:

    root@omnios:/etc/mail# cat access
    TLS_Srv_Features:192.168.1.154 O
    TLS_Srv_Features:fedora.local O
    Srv_Features:192.168.1.154 v CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY

    Well, I guess the sendmail.cf expects 'TLS_Srv' and
    not 'TLS_Srv_Features':

    root@omnios:/etc/mail# grep -i tls_s sendmail.cf
    ### tls_server: is connection with server "good" enough?
    Stls_server
    R$* $: $1 $| $>D <$&{server_name}> <?> <! "TLS_Srv"> <>
    R$* $| <?>$* $: $1 $| $>A <$&{server_addr}> <?> <! "TLS_Srv"> <>
    R$* $| <?>$* $: $1 $| <$(access "TLS_Srv": $: ? $)>

    So I modified my access.db:

    root@omnios:/etc/mail# cat access
    TLS_Srv:192.168.1.154 O
    TLS_Srv:fedora.local O
    Srv_Features:192.168.1.154 v CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY

    and rebuilt the DB. But still relaying denied...

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Sat Jul 4 00:27:54 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    Again, If I understood correctly, using 'O' should make exceptions
    for clients that offer server EKU cert. This is what I have in my
    access.db:

    root@omnios:/etc/mail# cat access
    TLS_Srv_Features:192.168.1.154 O
    TLS_Srv_Features:fedora.local O
    Srv_Features:192.168.1.154 v
    CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY

    Well, I guess the sendmail.cf expects 'TLS_Srv' and
    not 'TLS_Srv_Features':

    root@omnios:/etc/mail# grep -i tls_s sendmail.cf
    ### tls_server: is connection with server "good" enough?
    Stls_server
    R$* $: $1 $| $>D <$&{server_name}> <?> <! "TLS_Srv"> <>
    R$* $| <?>$* $: $1 $| $>A <$&{server_addr}> <?> <! "TLS_Srv"> <>
    R$* $| <?>$* $: $1 $| <$(access "TLS_Srv": $: ? $)>

    So I modified my access.db:

    root@omnios:/etc/mail# cat access
    TLS_Srv:192.168.1.154 O
    TLS_Srv:fedora.local O
    Srv_Features:192.168.1.154 v CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY

    and rebuilt the DB. But still relaying denied...

    No! I was missing FEATURE(`tls_session_features'), now I can
    see the ruleset Stls_srv_features and as far as I can tell, it
    queries access.db using 'TLS_Srv_Features'. So I am back where
    I started:

    root@omnios:/etc/mail# cat access
    TLS_Srv_Features:192.168.1.154 O
    TLS_Srv_Features:fedora.local O
    Srv_Features:192.168.1.154 v CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY

    Still, relaying denied. I am giving up for tonight.

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Sat Jul 4 01:11:26 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    No! I was missing FEATURE(`tls_session_features'), now I can
    see the ruleset Stls_srv_features and as far as I can tell, it
    queries access.db using 'TLS_Srv_Features'. So I am back where
    I started:

    root@omnios:/etc/mail# cat access
    TLS_Srv_Features:192.168.1.154 O
    TLS_Srv_Features:fedora.local O
    Srv_Features:192.168.1.154 v CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY

    Still, relaying denied. I am giving up for tonight.

    I could not stop so now after reading the code, I finally got
    it to work with access.db:

    root@omnios:/etc/mail# cat access
    TLS_Srv_Features:192.168.1.154 flags=O
    TLS_Srv_Features:fedora.local flags=O
    Srv_Features:192.168.1.154 v CertIssuer:/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local RELAY

    and the maillog shows "eku=overrode_no_client_auth":

    Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] tls_srv_features=flags=O, relay=fedora.local [192.168.1.154]
    Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.debug] tls_srv_features=parsed, flags=O, relay=fedora.local [192.168.1.154]
    Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=ECDHE, eku=overrode_no_client_auth
    Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] STARTTLS=server, cert-subject=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, cert-issuer=/C=FI/ST=Uusimaa/L=Helsinki/O=Home/CN=fedora.local, verifymsg=ok
    Jul 4 04:06:38 localhost sendmail[24503]: [ID 702911 mail.info] AUTH: available mech=SCRAM-SHA-512 SCRAM-SHA-384 SCRAM-SHA-256 SCRAM-SHA-224 SCRAM-SHA-1 DIGEST-MD5 EXTERNAL OTP CRAM-MD5 PLAIN LOGIN ANONYMOUS, allowed mech=EXTERNAL GSSAPI KERBEROS_V4 DIGEST-MD5 CRAM-MD5
    Jul 4 04:06:39 localhost sendmail[24503]: [ID 801593 mail.info] 66416cjO024503: from=<kalevi@fedora.local>, size=268, class=0, nrcpts=1, msgid=<20260704040633.691177@fedora.local>, proto=ESMTPS, daemon=MTA, relay=fedora.local [192.168.1.154]


    Time to go to sleep, it is over 4 o'clock in the morning.

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Claus =?iso-8859-1?Q?A=DFmann?=@INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org to comp.mail.sendmail on Tue Jul 7 03:37:24 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen wrote:

    STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256,
    key_exchange=ECDHE, eku=overrode_no_client_auth

    Thanks for giving this a try, sorry for not providing (better)
    documentation (yet).

    Which OpenSSL version do you use?
    With 3.5ff you should get something like
    key_exchange=X25519MLKEM768
    (PQC)
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Thu Jul 9 13:24:59 2026
    From Newsgroup: comp.mail.sendmail

    Claus A|fmann <INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org> wrote:
    Kalevi Kolttonen wrote:

    STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3,
    verify=OK, cipher=TLS_AES_256_GCM_SHA384, bits=256/256,
    key_exchange=ECDHE, eku=overrode_no_client_auth

    Thanks for giving this a try, sorry for not providing (better)
    documentation (yet).

    Which OpenSSL version do you use?
    With 3.5ff you should get something like
    key_exchange=X25519MLKEM768
    (PQC)

    root@omnios:~# openssl version -a
    OpenSSL 3.6.3 9 Jun 2026 (Library: OpenSSL 3.6.3 9 Jun 2026)
    built on: Thu Jun 11 23:19:59 2026 UTC
    platform: solaris64-x86_64-gcc
    options: bn(64,64)
    compiler: gcc -fPIC -m64 -O2 -fno-omit-frame-pointer -fno-aggressive-loop-optimizations -fstack-protector-strong -gdwarf-4 -gstrict-dwarf -m64 -Wa,--noexecstack -Wall -O3 -DFILIO_H -DL_ENDIAN -DOPENSSL_PIC -D_REENTRANT -DOPENSSL_BUILDING_OPENSSL -DZLIB -DNDEBUG
    OPENSSLDIR: "/usr/ssl"
    ENGINESDIR: "/usr/lib/amd64/engines-3"
    MODULESDIR: "/usr/lib/amd64/ossl-modules"
    Seeding source: os-specific
    CPUINFO: OPENSSL_ia32cap=0x7ffaf3ffffebffff:0x00000000029c6fbf:0x00000000bc002e00:0x0000000000000000:0x0000000000000000

    root@fedora:~# $ openssl version -a
    OpenSSL 3.5.7 9 Jun 2026 (Library: OpenSSL 3.5.7 9 Jun 2026)
    built on: Wed Jun 10 00:00:00 2026 UTC
    platform: linux-x86_64
    options: bn(64,64)
    compiler: gcc -fPIC -pthread -m64 -Wa,--noexecstack -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -mtls-dialect=gnu2 -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Wno-complain-wrong-lang -Werror=format-security -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -mtls-dialect=gnu2 -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -Wa,--noexecstack -Wa,--generate-missing-build-notes=yes -specs=/usr/lib/rpm/redhat/redhat-hardened-ld -specs=/usr/lib/rpm/redhat/redhat-hardened-ld-errors -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -specs=/usr/lib/rpm/redhat/redhat-package-notes -DOPENSSL_USE_NODELETE -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_BUILDING_OPENSSL -DZLIB -DNDEBUG -D_GNU_SOURCE -DPURIFY -DDEVRANDOM="\\"/dev/urandom\\"" -DOPENSSL_PEDANTIC_ZEROIZATION -DREDHAT_FIPS_VENDOR="\\"Red Hat Enterprise Linux OpenSSL FIPS Provider\\"" -DREDHAT_FIPS_VERSION="\\"3.5.7-9c2719932f8ae75e\\"" -DSYSTEM_CIPHERS_FILE="/etc/crypto-policies/back-ends/opensslcnf.config"
    OPENSSLDIR: "/etc/pki/tls"
    ENGINESDIR: "/usr/lib64/engines-3"
    MODULESDIR: "/usr/lib64/ossl-modules"
    Seeding source: os-specific
    CPUINFO: OPENSSL_ia32cap=0x7ed8320b078bffff:0x00400004219c91a9:0x0000000000000000:0x0000000000000000:0x0000000000000000

    root@omnios:~# openssl list -tls-groups secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024

    root@fedora:~# openssl list -tls-groups secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024


    Using this command:

    openssl s_client -starttls smtp -connect omnios.local:25 -groups X25519MLKEM768

    Server log is:

    Jul 9 16:23:12 localhost sendmail[14522]: [ID 702911 mail.warning] STARTTLS=server, error: accept failed=-1, reason=no suitable key share, SSL_error=1, errno=0, retry=-1, relay=fedora.local [192.168.1.154]
    Jul 9 16:23:12 localhost sendmail[14522]: [ID 702911 mail.warning] STARTTLS=server: error:0A000065:SSL routines::no suitable key share:ssl/statem/extensions.c:1412:



    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Thu Jul 9 14:11:00 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    root@omnios:~# openssl list -tls-groups secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024

    root@fedora:~# openssl list -tls-groups secp256r1:secp384r1:secp521r1:x25519:x448:brainpoolP256r1tls13:brainpoolP384r1tls13:brainpoolP512r1tls13:ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192:MLKEM512:MLKEM768:MLKEM1024:SecP256r1MLKEM768:X25519MLKEM768:SecP384r1MLKEM1024

    I ran OpenSSL server on OmniOS:

    root@omnios:/etc/mail/certs# cat f
    openssl s_server -accept 8443 -key omnios.local.key -cert omnios.local.crt

    Connected to it with:

    openssl s_client -connect omnios.local:8443 -groups X25519MLKEM768

    Connection worked, so maybe this has something to do with Sendmail configuration or code.

    br,
    KK

    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Thu Jul 9 17:51:28 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    I ran OpenSSL server on OmniOS:

    root@omnios:/etc/mail/certs# cat f
    openssl s_server -accept 8443 -key omnios.local.key -cert omnios.local.crt

    Connected to it with:

    openssl s_client -connect omnios.local:8443 -groups X25519MLKEM768

    Connection worked, so maybe this has something to do with Sendmail configuration or code.

    I tested a small patch:

    =============================================================================== diff -urN sendmail-8.19.0.2/sendmail/tls.c sendmail-8.19.0.2-patch/sendmail/tls.c
    --- sendmail-8.19.0.2/sendmail/tls.c 2026-07-09 20:47:18.544514740 +0300
    +++ sendmail-8.19.0.2-patch/sendmail/tls.c 2026-07-09 20:47:26.068638009 +0300
    @@ -1692,6 +1692,11 @@
    if (kf2 != NULL)
    *--kf2 = ',';

    + if (!SSL_CTX_set1_groups_list(*tls_ctx, "X25519MLKEM768:X25519")) {
    + abort();
    + }
    + sm_syslog(LOG_INFO, NOQID, "SSL_CTX_set1_groups_list() success");
    +
    return ok;
    }

    ===============================================================================

    After that PQC key exchange worked with s_client:

    root@omnios:/opt/site/sbin# grep success /var/log/syslog
    Jul 9 20:43:51 localhost sendmail[27872]: [ID 702911 mail.info] SSL_CTX_set1_groups_list() success
    root@omnios:/opt/site/sbin# grep X25519MLKEM768 /var/log/syslog
    Jul 9 20:44:07 localhost sendmail[27877]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=X25519MLKEM768

    I guess this proves that Sendmail 8.19.0.2 OpenSSL initialization code
    is to blame, but I do not know the proper fix.

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From kalevi@kalevi@kolttonen.fi (Kalevi Kolttonen) to comp.mail.sendmail on Thu Jul 9 20:38:34 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen <kalevi@kolttonen.fi> wrote:
    I tested a small patch:

    ===============================================================================
    diff -urN sendmail-8.19.0.2/sendmail/tls.c sendmail-8.19.0.2-patch/sendmail/tls.c
    --- sendmail-8.19.0.2/sendmail/tls.c 2026-07-09 20:47:18.544514740 +0300 +++ sendmail-8.19.0.2-patch/sendmail/tls.c 2026-07-09 20:47:26.068638009 +0300
    @@ -1692,6 +1692,11 @@
    if (kf2 != NULL)
    *--kf2 = ',';

    + if (!SSL_CTX_set1_groups_list(*tls_ctx, "X25519MLKEM768:X25519")) {
    + abort();
    + }
    + sm_syslog(LOG_INFO, NOQID, "SSL_CTX_set1_groups_list() success");
    +
    return ok;
    }

    ===============================================================================

    I have been reading tls.c inittls() and isolated the problem to initec()
    call with TLS_EC compilation define enabled.

    Having TLS_EC=0 in conf_sendmail_ENVDEF in devtools/Site/site.config.m4
    fixes the problem and enables Sendmail to use OpenSSL defaults. Then PQC
    key exchange works:

    Jul 9 23:33:47 localhost sendmail[7555]: [ID 702911 mail.info] STARTTLS=server, relay=fedora.local [192.168.1.154], version=TLSv1.3, verify=NO, cipher=TLS_AES_256_GCM_SHA384, bits=256/256, key_exchange=X25519MLKEM768

    br,
    KK
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Claus =?iso-8859-1?Q?A=DFmann?=@INVALID_NO_CC_REMOVE_IF_YOU_DO_NOT_POST_ml+sendmail(-no-copies-please)@esmtp.org to comp.mail.sendmail on Mon Aug 24 07:25:50 2026
    From Newsgroup: comp.mail.sendmail

    Kalevi Kolttonen wrote:

    Having TLS_EC=0 in conf_sendmail_ENVDEF in devtools/Site/site.config.m4
    fixes the problem and enables Sendmail to use OpenSSL defaults. Then PQC
    key exchange works:

    Or set TLS_EC=2 or use TLSEC:
    New option TLSEC to select at run time what was previously
    specified at compile time with TLS_EC. For details see
    doc/op/op.me.
    --- Synchronet 3.22a-Linux NewsLink 1.2