Mailing List Archive

Exim 4.88 released
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

I have uploaded Exim 4.88 to:
ftp://ftp.exim.org/pub/exim/exim4/

The following features are REMOVED (configurations using them will
require updating):

- - The obsolete acl condition "demime" is removed (finally, after ten
years of being deprecated). The replacements are the ACLs
acl_smtp_mime and acl_not_smtp_mime.

- - Retire gnutls_require_mac et.al. These were nonfunctional since 4.80
and logged a warning sing 4.83; now they are a configuration file
error.

This release contains the following enhancements and bugfixes:

- The new perl_taintmode option allows to run the embedded perl
interpreter in taint mode.

- New log_selector: dnssec, adds a "DS" tag to acceptance and delivery
lines.

- Speculative debugging, via a "kill" option to the "control=debug" ACL
modifier.

- New expansion item ${sha3:<string>} / ${sha3_<N>:<string>}.
N can be 224, 256 (default), 384, 512.
With GnuTLS 3.5.0 or later, only.

- Facility for named queues: A commandline argument can specify
the queue name for a queue operation, and an ACL modifier can set
the queue to be used for a message. A $queue_name variable gives
visibility.

- New expansion operators base32/base32d.

- The CHUNKING ESMTP extension from RFC 3030. May give some slight
performance increase and network load decrease. Main config option
chunking_advertise_hosts, and smtp transport option
hosts_try_chunking for control.

- LMDB lookup support, as Experimental.

- Expansion operator escape8bit, like escape but not touching newline
etc..

- - Feature macros, generated from compile options.

- - Integer values for options can take a "G" multiplier.

- - defer=pass option for the ACL control cutthrough_delivery, to reflect
4xx returns from the target back to the initiator, rather than
spooling the message.

- - Use SIZE on MAIL FROM in a cutthrough connection, if the destination
supports it and a size is available (ie. the sending peer gave us
one).

- - Upgrade security requirements imposed for hosts_try_dane

- - If main configuration option tls_certificate is unset, generate a
selfsigned certificate for inbound TLS connections.

- - Support ${sha256:} applied to a string (as well as the previous
certificate).

- - Assorted fixes and enhancements to cutthrough delivery.

- - Fakereject: previously logged as a normal message arrival "<="; now
distinguished as "(=".

- - Support Radius libraries that return REJECT_RC.

- - Send DMARC forensic reports for reject and quarantine
results, even for a "none" policy.

- - Enable {spool,log} filesystem space and inode checks as default.
Main config options check_{log,spool}_{inodes,space} are now
100 inodes, 10MB unless set otherwise in the configuration.

- - A new transport, queuefile, for interfacing with some
types of external mail scanners

- - TCP Fast Open (RFC 7413) support

- - Speedups in main-process startup, and TCP connection startup.

- - New syslog_pid logging option



Security-related changes:

- - Fix CVE-2016-9963 - Info leak from DKIM. When signing DKIM, if either
LMTP or PRDR was used for delivery, the key could appear in logs.
Additionally, if the experimental feature "DSN_INFO" was used, it
could appear in DSN messages (and be sent offsite).

Packages for a patched 4.87.1 with just this fix have been placed in
ftp://ftp.exim.org/pub/exim/exim4/old

- - Fix a possible security hole, wherein a process operating with the
Exim UID can gain a root shell. Credit to http://www.halfdog.net/ for
discovery and writeup. Ubuntu bug 1580454.

- - Changed default Diffie-Hellman parameters to be Exim-specific, created
by PDP. Added RFC7919 DH primes as an alternative.

- - Fix use of OCSP stapling with LetsEncrypt certificates

- - Build with OpenSSL 1.1 fixed (OCSP proof validation and DANE)

- - For builds with OpenSSL the tls_eccurve main option now defaults
to 'auto'. For OpenSSL versions at or newer than 1.0.2 this lets
the library choose. For older versions it selects 'prime256v1',
which was the previous default.



The ChangeLog/NewStuff are packaged with the exim
tarball or can be reviewed online at:

http://git.exim.org/exim.git/blob/exim-4_88:/doc/doc-txt/ChangeLog
http://git.exim.org/exim.git/blob/exim-4_88:/doc/doc-txt/NewStuff

The release files for 4.88 are signed with the PGP key 0xE41F32DF,
which has a uid "Jeremy Harris (none) <jgh@wizmail.org>". Please use
your own discretion in assessing what trust paths you might have to
this uid.

The release files for 4.87.1 are signed with the PGP key 0xF69376CE,
which has a uid "Heiko Schlittermann (HS12-RIPE)
<hs@schlittermann.de>". Please use your own discretion in assessing
what trust paths you might have to this uid.

Checksums are below. Detached PGP signatures in .asc files are available
alongside the tarballs.

Please report issues by replying to this email on exim-users.

Thank you for your patronage,
- --
Jeremy Harris, pp The Exim Maintainers

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYX5yhAAoJELzljIzkHzLfApAH/iB5aT3705R5mkJT6PLS3n14
8I1kH1QmFH7x+Qn1y52fvAlUoNaHzUoFGo/j/meTIvxinxvQzKIxR62SSnC65Q1u
3QfEDVFLZ1GUhM8AsD1PLdm9h+SOILqy4FRjC2/nVohcu33sJFpebKQcKju2DWGT
gW/WHyE3/mm0DNclvmWb9Z7+CLUtgBhDqP4SbthaL4B2TQlCWJWcEIHX2GqkY/jb
7XeLVSuqXai/YyOrpbW5+DBZ1J0mG3BBOgfW2jTsyKeGYg2HNWMvzEIarAR/cJpq
iME2h9hejCiYHk3ouXOIz96Vvfl7YkavLmRlotLt5mQL+zMdaojdYyeBEctJhqY=
=x+UY
-----END PGP SIGNATURE-----

--
## List details at https://lists.exim.org/mailman/listinfo/exim-announce Exim details at http://www.exim.org/ ##
Re: Exim 4.88 released [ In reply to ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 25/12/16 10:17, Jeremy Harris wrote:
> I have uploaded Exim 4.88 to: ftp://ftp.exim.org/pub/exim/exim4/

> Checksums are below.

Except they weren't.


824e9158efa99ca53ab22ea915f99b1dce6b90b1f73c78eac32035a5af3ee5f9
exim-4.88.tar.gz
6df1b0fb032d12b980a61e49427f73643116b3abbf449bb11daaab3c98138de9
exim-html-4.88.tar.gz
82aa94ef213f4cad91dfc11a252ebab9be47d03dd4e414247972d056f6c8c3d2
exim-pdf-4.88.tar.gz
b7d2cd01fb2843b0e27498df5bb599776f735b1faec1faf165a4b4a91f918758
exim-postscript-4.88.tar.gz
119d5fd7e31fc224e84dfa458fe182f200856bae7adf852a8287c242161f8a2d
exim-4.88.tar.bz2
afae7d298e7571026635d6377b26eb0849b27c28b1490cc2f1ac424937e90521
exim-html-4.88.tar.bz2
33736fafb45c5922fcbc0def7626f46cb74927987b78943aa26949ef30789574
exim-pdf-4.88.tar.bz2
a932809a80657195f3163f889512eb1f705c7e41e061150ae41561ac6d86cb4c
exim-postscript-4.88.tar.bz2


Apologies, and thanks to KM for pointing it out.
- --
Jeremy
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYX8viAAoJELzljIzkHzLfvSoIAKWq7a9evQAMOfAZt2/Nd2La
AB84ijCB2fJPzGglmbJX8mHe9YlCCbd8iZ8a+dBB0hlCG/xiaChr/d/546OxyDHH
cddShP1gbfBXDcBCCRGizE6GKCDiNTdyXyHUfAo37dLSG/IcAUElxAwCe+Db0Mz2
I38R+/m52xUFBRCkoYbvhqO4v9CkEU8/TVuZrj9eJgOGOOFdDm91nvNmXRX3WMeA
rZj4zN/wsVNnt5Q2/g6uVc35l0BfK7hKSoils3Ws+Zq/a5VIMr/iItkvX0Zngeoj
B1jkTDSuDEsc85B1ScWxe5Mz+DHtB2PvOa0Y+1MNAi5uV0UDFJSmcY/+iuy0EXo=
=FooY
-----END PGP SIGNATURE-----

--
## List details at https://lists.exim.org/mailman/listinfo/exim-announce Exim details at http://www.exim.org/ ##