Bug 1254878

Summary: [RFE] Add DANE support
Product: Red Hat Enterprise Linux 7 Reporter: Frank Büttner <bugzilla>
Component: postfixAssignee: Jaroslav Škarvada <jskarvad>
Status: CLOSED WONTFIX QA Contact: qe-baseos-daemons
Severity: medium Docs Contact:
Priority: low    
Version: 7.1CC: david.voit, ggiesen+redhat, jeharris, lefty1978, lmiksik, martin, mkolaja, ovasik, thozza
Target Milestone: rcKeywords: FutureFeature, Rebase
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-11-27 12:34:11 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1400961, 1472751, 1534569    

Description Frank Büttner 2015-08-19 07:40:51 UTC
Description of problem:
The postfix version which is included (2.10) don't support DANE aka TLSA.
The support for it was added for 2.11 

Version-Release number of selected component (if applicable):
postfix-2.10.1-6.el7.x86_64


Will it possible to upgrade it for RHEL 7.2?

Comment 2 Jaroslav Škarvada 2015-08-19 10:01:13 UTC
It's too late for 7.2, but maybe in 7.3. If it is critical for you, please escalate it through support channel.

Comment 3 Jaroslav Škarvada 2015-08-19 14:02:13 UTC
It's too complex for backporting, better (and more safe) is to rebase.

Comment 4 Gary T. Giesen 2016-05-17 08:57:36 UTC
Would love to see it as well, as it can help with MITM TLS downgrade attacks. 2.11 also includes support for multiple recipient delimiter characters (which is a huge win as many sites don't accept the "+" char).

Comment 6 Bjoern 2017-01-04 15:33:40 UTC
Why not going to 3.1.* ?

Comment 9 Gary T. Giesen 2018-03-21 17:44:32 UTC
Postfix 2.11 received its final update in January 2018, and the entire 2.x branch is no longer supported upstream. I agree at this point it would probably be better to rebase to 3.2.

Comment 10 Tomáš Hozza 2018-11-27 12:34:03 UTC
Thank you for taking the time to report this issue to us. We appreciate the feedback and use reports such as this one to guide our efforts at improving our products. That being said, this bug tracking system is not a mechanism for requesting support, and we are not able to guarantee the timeliness or suitability of a resolution.

If this issue is critical or in any way time sensitive, please raise a ticket through the regular Red Hat support channels to ensure it receives the proper attention and prioritization to assure a timely resolution. 

For information on how to contact the Red Hat production support team, please visit:
    https://www.redhat.com/support/process/production/#howto

Comment 11 Red Hat Bugzilla Rules Engine 2018-11-27 12:34:11 UTC
Development Management has reviewed and declined this request. You may appeal this decision by reopening this request.