Comments on: Setup Postfix with SMTP-AUTH and TLS on CentOS https://blog.tinned-software.net/setup-postfix-with-smtp-auth-and-tls-on-centos/ Tinned-Software Blog Fri, 21 Jan 2022 15:08:40 +0000 hourly 1 https://wordpress.org/?v=6.4.3 By: Gerhard https://blog.tinned-software.net/setup-postfix-with-smtp-auth-and-tls-on-centos/#comment-27 Wed, 04 Nov 2015 20:00:28 +0000 http://blog.tinned-software.net/?p=1159#comment-27 Thanks Iain for contacting me with the comment below. Even though I have also described steps to Harden the SSL configuration of your mailserver, it is always good to have information from more then one source. Thanks for providing those links.


I’ve been tinkering with CentOS for a year or so, having used Ubuntu previously. I’ve tried to set up secure server (a VM at home) and came to the point where I wanted to add mail provision. There are countless online tutorials and, whilst most of them got me to 95% of where I wanted to be, it wasn’t until I stumbled upon your series (with the detailed testing processes) that I nailed secure Postfix! The only thing I had to add was the creation of a self-signed certificate and, fortunately, I had found a very good article which supplemented yours and covered this in detail. I haven’t had chance to do anything with Dovecot yet but am confident that your article will hold my hand down that path!

As well as congratulating you, the other reason for writing is to mention the recently publicised Logjam attack. I seem to recall somewhere on your site you mentioned that comments had been disabled because of the amount of spam, otherwise I would have posted there. I don’t know if you might consider an addendum to one of the mailserver articles (maybe the one dealing with hardening the SSL configuration) or a separate article dealing with the Logjam attack and how to mitigate against it. Here are some links that I found:

Weak Diffie-Hellman and the Logjam Attack
Guide to Deploying Diffie-Hellman for TLS

I’ll keep an eye on your blog as the articles are well written and relevant to my interests.

Iain

]]>