Re: How to disable tls 1 and tls 1.1

Cyborg via Exim-users <[email protected]>
Newsgroups gmane.mail.exim.user
Message-ID <[email protected]>
Am 29.05.25 um 12:04 schrieb Kai Bojens via Exim-users:
> On Sonntag, 25. Mai 2025 13:54:29 Mitteleuropäische Sommerzeit Mike Cardwell
> via Exim-users wrote:
>
>> I don't know what the generally accepted config is for SMTP TLS these
>> days, but bare in mind that a connecting MTA may decide to fall back to
>> plain text if it can't agree a protocol/cipher with you. I'd rather
>> have mail sent over TLS 1 than over plain text.
> In theory that's right. And then your customer tells you that he has this
> shiny "cyber insurance" and their insurance company sends a port scan and
> complains about those old TLS versions …

.. and you can simply rejecting plain text delivery, which is nowadays 
the same, as using tls 1.0/1.1.

If it helps making a decision:

For the EU, as a company or organization of any form, you have to 
enforce tls 1.2+ (§32 gdpr -> state of the art and has no costs), 
because it's impossible to know before hand, if someone is sending you 
personal data or not and the law says, that the transport of personal 
data has to be protected. This makes unencrypted traffic only possible 
for technical data. But, it's more effort to exclude some servers/mail 
addresses from the tls enforcement, than actually enabling tls at the 
sender.

Because you can't be clairvoyant who sends it, tls is enforced for any 
none-eu sender as well by eu companies if they are lawful and not 
willing to maintain two servers in- and outside of the eu. If none-eu 
people like it or not, the eu raised the bar in mail transport security 
to a meaning full level for anyone and the rest of the world would be 
well advised to follow the lead.

A quick scan on our cluster shows only spam as source for unencrpyted 
mails. There is simply no sense in accepting unencrypted mails anymore.

best regrads,
Cyborg


-- 
## subscription configuration (requires account):
##   https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/
## unsubscribe (doesn't require an account):
##   [email protected]
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
OpenPGP_0x048770A738345DD3.asc (application/pgp-keys, 920 B)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xjMEYNCgKxYJKwYBBAHaRw8BAQdArodafJTXkIv7/P3ZTZS54icoOPq8yd6WKZLH
RovvhLXNHUN5Ym9yZyA8Y3lib3JnMkBiZW5kZXJpcmMuZGU+wpEEExYIADkWIQRj
wwZDcb5ODhI6BhkEh3CnODRd0wUCYNCgKwUJCWYBgAIbAwULCQgHAgYVCAkKCwIF
FgIDAQAACgkQBIdwpzg0XdO0oQEA6OSSsKVmPNngRgL4o1avbAO9L9iOxbCK5YrF
+kF+Qf0BAK3cXzNRCe3scFS6049g1KXllfDgmcqFt82xdPoq6kIEzTFNYXJpdXMg
U2Nod2FyeiAoRXhpbSBUZWFtKSA8Y3lib3JnMkBiZW5kZXJpcmMuZGU+wpYEExYI
AD4WIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCYOhQDgIbAwUJCWYBgAULCQgHAgYV
CgkICwIEFgIDAQIeAQIXgAAKCRAEh3CnODRd01OlAQDbEiFQCTnWYotjUCIbfNZG
3FSJcW6XT5Y3lPUgAXAH8QEApbuKaQ/smdE/rkmD4podYCx3jWH/vGxNn98tSoil
bALOOARg0KArEgorBgEEAZdVAQUBAQdA3q3BHLyIBKM795R7euJegjlZdb1/VlXY
rv1a55TeyDUDAQgHwn4EGBYIACYWIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCYNCg
KwUJCWYBgAIbDAAKCRAEh3CnODRd03hmAPsGanHWXMW+4TDbQwav8/5RuoUGS/Jh
+KIv+f6tV+TdBgD9Fy2zQAfyidW3xB/PslnCKDB62CcIq67mDJdKtkYVdgg=
=LhE8
-----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCaDys5wUDAAAAAAAKCRAEh3CnODRd00cM
AQCC3bXj5hy+P1PTCpFHID0kUY9nal5/dkRFCdGBVZOs2AD/RBEAEcwGnJe2l3evruH5TL4G3R+J
+iGdyKvlRHObXA8=
=Tvek
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.