Re: How to disable tls 1 and tls 1.1
Cyborg via Exim-users <[email protected]>
| Newsgroups | gmane.mail.exim.user |
|---|---|
| Message-ID | <[email protected]> |
Am 29.05.25 um 12:04 schrieb Kai Bojens via Exim-users: > On Sonntag, 25. Mai 2025 13:54:29 Mitteleuropäische Sommerzeit Mike Cardwell > via Exim-users wrote: > >> I don't know what the generally accepted config is for SMTP TLS these >> days, but bare in mind that a connecting MTA may decide to fall back to >> plain text if it can't agree a protocol/cipher with you. I'd rather >> have mail sent over TLS 1 than over plain text. > In theory that's right. And then your customer tells you that he has this > shiny "cyber insurance" and their insurance company sends a port scan and > complains about those old TLS versions … .. and you can simply rejecting plain text delivery, which is nowadays the same, as using tls 1.0/1.1. If it helps making a decision: For the EU, as a company or organization of any form, you have to enforce tls 1.2+ (§32 gdpr -> state of the art and has no costs), because it's impossible to know before hand, if someone is sending you personal data or not and the law says, that the transport of personal data has to be protected. This makes unencrypted traffic only possible for technical data. But, it's more effort to exclude some servers/mail addresses from the tls enforcement, than actually enabling tls at the sender. Because you can't be clairvoyant who sends it, tls is enforced for any none-eu sender as well by eu companies if they are lawful and not willing to maintain two servers in- and outside of the eu. If none-eu people like it or not, the eu raised the bar in mail transport security to a meaning full level for anyone and the rest of the world would be well advised to follow the lead. A quick scan on our cluster shows only spam as source for unencrpyted mails. There is simply no sense in accepting unencrypted mails anymore. best regrads, Cyborg -- ## subscription configuration (requires account): ## https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/ ## unsubscribe (doesn't require an account): ## [email protected] ## Exim details at http://www.exim.org/ ## Please use the Wiki with this list - http://wiki.exim.org/
OpenPGP_0x048770A738345DD3.asc
(application/pgp-keys, 920 B)
-----BEGIN PGP PUBLIC KEY BLOCK----- xjMEYNCgKxYJKwYBBAHaRw8BAQdArodafJTXkIv7/P3ZTZS54icoOPq8yd6WKZLH RovvhLXNHUN5Ym9yZyA8Y3lib3JnMkBiZW5kZXJpcmMuZGU+wpEEExYIADkWIQRj wwZDcb5ODhI6BhkEh3CnODRd0wUCYNCgKwUJCWYBgAIbAwULCQgHAgYVCAkKCwIF FgIDAQAACgkQBIdwpzg0XdO0oQEA6OSSsKVmPNngRgL4o1avbAO9L9iOxbCK5YrF +kF+Qf0BAK3cXzNRCe3scFS6049g1KXllfDgmcqFt82xdPoq6kIEzTFNYXJpdXMg U2Nod2FyeiAoRXhpbSBUZWFtKSA8Y3lib3JnMkBiZW5kZXJpcmMuZGU+wpYEExYI AD4WIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCYOhQDgIbAwUJCWYBgAULCQgHAgYV CgkICwIEFgIDAQIeAQIXgAAKCRAEh3CnODRd01OlAQDbEiFQCTnWYotjUCIbfNZG 3FSJcW6XT5Y3lPUgAXAH8QEApbuKaQ/smdE/rkmD4podYCx3jWH/vGxNn98tSoil bALOOARg0KArEgorBgEEAZdVAQUBAQdA3q3BHLyIBKM795R7euJegjlZdb1/VlXY rv1a55TeyDUDAQgHwn4EGBYIACYWIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCYNCg KwUJCWYBgAIbDAAKCRAEh3CnODRd03hmAPsGanHWXMW+4TDbQwav8/5RuoUGS/Jh +KIv+f6tV+TdBgD9Fy2zQAfyidW3xB/PslnCKDB62CcIq67mDJdKtkYVdgg= =LhE8 -----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc
(application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE----- wnsEABYIACMWIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCaDys5wUDAAAAAAAKCRAEh3CnODRd00cM AQCC3bXj5hy+P1PTCpFHID0kUY9nal5/dkRFCdGBVZOs2AD/RBEAEcwGnJe2l3evruH5TL4G3R+J +iGdyKvlRHObXA8= =Tvek -----END PGP SIGNATURE-----