Develop and Download Open Source Software

Browse Subversion Repository

Contents of /CHANGES.md

Parent Directory Parent Directory | Revision Log Revision Log


Revision 23 - (show annotations) (download)
Sun Mar 8 07:18:55 2020 UTC (4 years, 2 months ago) by elge
File size: 1508 byte(s)
openssldir=/etc/ssl

1 ## shot3
2
3 - stage 1 iprev - wait 3 seconds instead of the default 5 (udp) or 10 (tcp) seconds
4
5 ## shot2
6
7 _second shot for Feb 2020_
8
9 - stage 1 iprev - better ip address splitting with ip??? instead of x?? x???? files
10 - stage 2 smtp gets done against ALL PTRs, not only IPREV hosts
11 - stage 2 smtp - timeout 1m+5s, yes that is slow bug some nasty mxen like to play that way and we wouldn't like to discard them (see Postfix Postscreen Howto)
12
13 The order is as follows
14
15 - stage 1 iprev - look for PTR vs IPREV resolving hosts
16 - stage 2 smtp -
17
18 ## shot1
19
20 _initial version, for Jan 2020_
21
22 The order was as follows
23
24 - mass seek of 25/tcp & raw split into x?? x???? (no uniq nor ip field)
25 - checkiprev - ptr/iprev check into separate .ptr files
26 - checksan - san check into .nossl .nocert .validcn .wrongcn
27 - checkvalid - verify check into .validcn.return
28 - (then came the problem of dealing with DANE/TLSA records, we needed to lookup true MX records to start with, hence the need for domains to start with)
29 - checkdomains - domains/ - deferencing domain names
30 - checkmx - domains/mx/ - got mx record?
31 - checkssl - domains/mx/dane/ - valid cert? looking for 'Cipher is|Verify return code' against mx records
32 * .ssl
33 * .ssl.issuer
34 * .ssl.cipher
35 - checkdane - valid dane?
36 * .dane $NF notlsa // timeout // ...
37 * .dane.results
38 * .dane.weird
39 - checksmtp - starttls enforced?
40 * stdout .starttls full session
41 * stderr .starttls.enforce $NF connect-bad-dns // ...
42 - count.ksh - parsing results and producing stats
43

Back to OSDN">Back to OSDN
ViewVC Help
Powered by ViewVC 1.1.26