# mailserver tls

**URL:** https://meta.it-syndikat.org/t/mailserver-tls/1255
**Category:** Projects
**Tags:** infra
**Created:** [March 7, 2018, 11:07am UTC](https://meta.it-syndikat.org/t/mailserver-tls/1255 "2018-03-07T11:07:57Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![robelix](https://meta.it-syndikat.org/user_avatar/meta.it-syndikat.org/robelix/32/22_2.png) [@robelix](https://meta.it-syndikat.org/u/robelix)
#### Post date: [March 7, 2018, 11:07am UTC](https://meta.it-syndikat.org/t/mailserver-tls/1255/1 "2018-03-07T11:07:57Z")

</div>

bin gerade mal auf diese TLS-Testseite gestossen, die auch SMTP testet:

> **[Hardenize: Comprehensive web site configuration test](https://www.hardenize.com/?host=it-syndikat.org&ec=not_available)**
>
> Hardenize provides a comprehensive and free assessment of web site network and security configuration.

gibt noch Optimierungspotential - wüsste wie man’s beim postfix einstellt, bei exim aber nicht.

---

<div class="post-metadata">

### Author: ![dxld](https://meta.it-syndikat.org/user_avatar/meta.it-syndikat.org/dxld/32/109_2.png) [@dxld](https://meta.it-syndikat.org/u/dxld)
#### Post date: [March 7, 2018, 6:01pm UTC](https://meta.it-syndikat.org/t/mailserver-tls/1255/2 "2018-03-07T18:01:14Z")

</div>

Ah, cool such schon länger nach so nem ding für SMTP. Ich guck mal bei gelegenheit wie das geht.

---

<div class="post-metadata">

### Author: ![hex-m](https://meta.it-syndikat.org/user_avatar/meta.it-syndikat.org/hex-m/32/2710_2.png) [@hex-m](https://meta.it-syndikat.org/u/hex-m)
#### Post date: [March 8, 2018, 1:13pm UTC](https://meta.it-syndikat.org/t/mailserver-tls/1255/3 "2018-03-08T13:13:09Z")

</div>

Wenn wir hier links sammeln sei [Mozilla Observatory](https://observatory.mozilla.org/analyze.html?host=it-syndikat.org) und [MXToolBox](https://mxtoolbox.com/SuperTool.aspx) auch erwähnt. Ersteres hat allerdings nichts mit SMTP zu tun. 🤔

---

<div class="post-metadata">

### Author: ![dxld](https://meta.it-syndikat.org/user_avatar/meta.it-syndikat.org/dxld/32/109_2.png) [@dxld](https://meta.it-syndikat.org/u/dxld)
#### Post date: [March 8, 2018, 9:05pm UTC](https://meta.it-syndikat.org/t/mailserver-tls/1255/4 "2018-03-08T21:05:08Z")

</div>

Hab jetzt mal nachgerüstet:

```auto
tls_require_ciphers = \
	${if =={$received_port}{25} \
		{NORMAL:%COMPAT} \
		{PFS:%SERVER_PRECEDENCE}}

```

aufm `submission` port sind nur perfect forward secrecy (PFS) cypher suites erlaubt und der server wählt die suite (SERVER\_PRECEDENCE). @robelix meinst I sollt auf 25 auch die starken settings nehmen?

---

<div class="post-metadata">

### Author: ![alex](https://meta.it-syndikat.org/user_avatar/meta.it-syndikat.org/alex/32/2703_2.png) [@alex](https://meta.it-syndikat.org/u/alex)
#### Post date: [March 13, 2018, 6:56pm UTC](https://meta.it-syndikat.org/t/mailserver-tls/1255/5 "2018-03-13T18:56:50Z")

</div>

Für die Enumeration welche TLS Ciphers/welche TLS Version unterstützt wird:

- sslscan - [GitHub - DinoTools/sslscan: SSLScan tests SSL/TLS enabled services to discover supported cipher suites](https://github.com/DinoTools/sslscan/)
- nmap - nmap --script ssl-enum-ciphers -p 25,465,587 -v

---

<div class="post-metadata">

### Author: ![alex](https://meta.it-syndikat.org/user_avatar/meta.it-syndikat.org/alex/32/2703_2.png) [@alex](https://meta.it-syndikat.org/u/alex)
#### Post date: [March 13, 2018, 7:17pm UTC](https://meta.it-syndikat.org/t/mailserver-tls/1255/6 "2018-03-13T19:17:06Z")

</div>

Zur parabox, Port 587/submission | 64-bit block cipher 3DES vulnerable to SWEET32 attack | Broken cipher RC4 is deprecated by RFC 7465 | Ciphersuite uses MD5 for message integrity | Key exchange (secp192r1) of lower strength than certificate key

---

<div class="post-metadata">

### Author: ![robelix](https://meta.it-syndikat.org/user_avatar/meta.it-syndikat.org/robelix/32/22_2.png) [@robelix](https://meta.it-syndikat.org/u/robelix)
#### Post date: [March 14, 2018, 12:08am UTC](https://meta.it-syndikat.org/t/mailserver-tls/1255/7 "2018-03-14T00:08:56Z")

</div>

nmap kann sowas also auch inzwischen… 🤗

Was das [hardenize.com](http://hardenize.com) ankreidet ist imho nur der 192bit ECDH und das fehlende SERVER\_PRECEDENCE.

ich hatte Ähnliches - aber durch - 1024 bit DH und server preference ist’s jetz da grünn:

> **[Hardenize: Comprehensive web site configuration test](https://www.hardenize.com/?host=robelix.com&ec=not_available)**
>
> Hardenize provides a comprehensive and free assessment of web site network and security configuration.

Im Postfix war’s:

```
tls_preempt_cipherlist = yes
smtpd_tls_dh1024_param_file=${config_directory}/dh2048.pem
smtpd_tls_eecdh_grade = strong

```

btw noch Anmerkung zum hardenize: die scheinen die Ergebnisse eine ganze Woche zu cachen - zum schnell mal schauen ob sich eine Änderung bemerkbar macht nicht so toll…
