You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since I found nothing in the issues/pull-requests tracker/readme I'm wondering whether they managed to contact you and whether current postfix-meta-sts-resolver is vulnerable (if it was a valid report, in the first place).
The text was updated successfully, but these errors were encountered:
Issue with check of domain name in subject certificate. postfix-mta-sts-resolver tells which domains names are allowed by MTA-STS, but it can't ensure domain name in certificate matches exactly to one which Postfix requested dialing SMTP TLS session. IMO it's a minor inconsistency with MTA-STS RFC, but hardly a security issue: if attacker is able to use certificate validating any MTA-STS authorized domain, security is already broken at this point.
I came across some traces of a CERT-Bund vulnerability report:
see also:
Since I found nothing in the issues/pull-requests tracker/readme I'm wondering whether they managed to contact you and whether current postfix-meta-sts-resolver is vulnerable (if it was a valid report, in the first place).
The text was updated successfully, but these errors were encountered: