Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-112553

postfix accepts insecure TLS 1.0/1.1

Linking RHIVOS CVEs to...Migration: Automation ...RHELPRIO AssignedTeam ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • rhel-9.5
    • postfix
    • No
    • None
    • rhel-net-perf
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • Red Hat Enterprise Linux
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • x86_64
    • None

      With postfix installed using default settings (just dnf install postfix), then as per:

       

      nmap -sV --script ssl-enum-ciphers -p 25 localhost 

      we see it happily accepts TLS 1.0/1.1.

       

      This does not really line up with RedHat statement here:

      https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/securing_networks/planning-and-implementing-tls_securing-networks

      or does it?

      Seems like RHEL8/9 is affected.

      I think that postfix does not use any backends configured by the update-crypto-policies tool mentioned in the document above.

      I think it would be fair to either:

      • update man page for update-crypto-policies mentioning postfix ignores these settings
      • update postfix to use GnuTLS library

      Either case we would expect TLS1.0/1.1 is blocked by default - as of now, we need to disable it manually by:

      smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
      smtpd_tls_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
      smtp_tls_mandatory_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1
      smtp_tls_protocols = !SSLv2, !SSLv3, !TLSv1, !TLSv1.1 

      in main.cf

              jskarvad Jaroslav Škarvada
              ovalouse Ondrej Valousek (Inactive)
              Jaroslav Škarvada Jaroslav Škarvada
              Robin Hack Robin Hack
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: