From bcfba987e41db1a34d9900b777f16677357f82bb Mon Sep 17 00:00:00 2001 From: aartoni Date: Fri, 29 Dec 2023 16:39:06 +0100 Subject: [PATCH] Short-term workaround to prevent SMTP smuggling --- emailwiz.sh | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/emailwiz.sh b/emailwiz.sh index ce8e1f5..c7d952f 100644 --- a/emailwiz.sh +++ b/emailwiz.sh @@ -308,6 +308,10 @@ postconf -e 'smtpd_milters = inet:localhost:12301' postconf -e 'non_smtpd_milters = inet:localhost:12301' postconf -e 'mailbox_command = /usr/lib/dovecot/deliver' +# Short-term workaround to prevent SMTP smuggling +postconf -e 'smtpd_forbid_unauth_pipelining = yes' +postconf -e 'smtpd_discard_ehlo_keywords = chunking' + # A fix for "Opendkim won't start: can't open PID file?", as specified here: https://serverfault.com/a/847442 /lib/opendkim/opendkim.service.generate systemctl daemon-reload