From 0abe71af12ac88eed440bb7f5e6324e679ac5cf5 Mon Sep 17 00:00:00 2001 From: Laurent Bercot Date: Sat, 18 Apr 2026 13:49:06 +0000 Subject: Update deps; update qmail-remote's doc for tls --- doc/index.html | 10 +++++++++- doc/qmail-remote.html | 15 ++++++++++----- doc/upgrade.html | 2 +- 3 files changed, 20 insertions(+), 7 deletions(-) (limited to 'doc') diff --git a/doc/index.html b/doc/index.html index d2a3ef9..3121361 100644 --- a/doc/index.html +++ b/doc/index.html @@ -25,6 +25,14 @@ inetd-like mail servers that do not already support it.

+

+ It comes with a chainloading binary implementing server-side +STARTTLS, as well as a full-featured modern replacement for +qmail's +qmail-remote +SMTP client. +

+

Installation

@@ -44,7 +52,7 @@ library. 2.4.1.2 or later. It's a build-time requirement. It's also a run-time requirement if you link against the shared version of the s6-dns library.
  • s6-networking version -2.7.3.0 or later. It's a build-time and run-time requirement.
  • +2.8.0.0 or later. It's a build-time and run-time requirement.

    Licensing

    diff --git a/doc/qmail-remote.html b/doc/qmail-remote.html index fd8a395..cde8643 100644 --- a/doc/qmail-remote.html +++ b/doc/qmail-remote.html @@ -95,7 +95,9 @@ certificate validation. If the path ends with a slash, like /etc/ssl/certs/< then it is interpreted as a directory containing hashes to the certificates. If it does not, like /etc/ssl/cert.pem, then it is interpreted as a big PEM file containing all the trust anchors. If the file is nonexistent or empty, -or only contains a newline, then STARTTLS is not attempted. +or only contains a newline, then STARTTLS is not attempted. Note that the +trust anchor list is only useful when tlsstrictness is 2 (see below), +but you still need a non-empty list in order to attempt STARTTLS.
    clientcert
    If this file exists and is nonempty, it must contain the path to a client @@ -118,7 +120,10 @@ STARTTLS command fails. 1 means that qmail-remote will attempt to find a server that supports STARTTLS in order to transmit its e-mail, but will fallback to cleartext if it cannot find any. 2 means that qmail-remote will flat out refuse to send e-mail to servers that do not -support STARTTLS or fail to set it up.
    +support STARTTLS or fail to set it up. It will also properly verify certificates, +whereas a value lower than 2 doesn't care if the certificate chain does not begin +with a trusted anchor (since it would eventually fall back on an insecure +transport anyway).

    Implementation notes

    @@ -163,10 +168,10 @@ exchange is actually handled by a separate binary: shows a qmail-remote-io process under qmail-rspawn instead of the regular qmail-remote, that is normal, it means that qmail-remote has found a suitable server and is transmitting its -data. If there is a +data. If qmail-remote has a qmail-remote-io +child that itself has a s6-tlsc-io -process running as the child of qmail-remote-io, it means that the -connection is happening under TLS. +child, it means that the transfer is happening under TLS. diff --git a/doc/upgrade.html b/doc/upgrade.html index 7ee8df0..6968ffa 100644 --- a/doc/upgrade.html +++ b/doc/upgrade.html @@ -29,7 +29,7 @@ dependency bumped to 2.15.0.0 dependency bumped to 2.15.0.0
  • New dependency: s6-dns 2.4.1.2
  • s6-networking -dependency bumped to 2.7.3.0 and made mandatory.
  • +dependency bumped to 2.8.0.0 and made mandatory.

    in 0.0.2.1

    -- cgit v1.3.1