Browse Subversion Repository
Contents of /CHANGES.md
Parent Directory
| Revision Log
Revision 23 -
( show annotations)
( download)
Sun Mar 8 07:18:55 2020 UTC
(4 years, 2 months ago)
by elge
File size: 1508 byte(s)
openssldir=/etc/ssl
| 1 |
## shot3 |
| 2 |
|
| 3 |
- stage 1 iprev - wait 3 seconds instead of the default 5 (udp) or 10 (tcp) seconds |
| 4 |
|
| 5 |
## shot2 |
| 6 |
|
| 7 |
_second shot for Feb 2020_ |
| 8 |
|
| 9 |
- stage 1 iprev - better ip address splitting with ip??? instead of x?? x???? files |
| 10 |
- stage 2 smtp gets done against ALL PTRs, not only IPREV hosts |
| 11 |
- stage 2 smtp - timeout 1m+5s, yes that is slow bug some nasty mxen like to play that way and we wouldn't like to discard them (see Postfix Postscreen Howto) |
| 12 |
|
| 13 |
The order is as follows |
| 14 |
|
| 15 |
- stage 1 iprev - look for PTR vs IPREV resolving hosts |
| 16 |
- stage 2 smtp - |
| 17 |
|
| 18 |
## shot1 |
| 19 |
|
| 20 |
_initial version, for Jan 2020_ |
| 21 |
|
| 22 |
The order was as follows |
| 23 |
|
| 24 |
- mass seek of 25/tcp & raw split into x?? x???? (no uniq nor ip field) |
| 25 |
- checkiprev - ptr/iprev check into separate .ptr files |
| 26 |
- checksan - san check into .nossl .nocert .validcn .wrongcn |
| 27 |
- checkvalid - verify check into .validcn.return |
| 28 |
- (then came the problem of dealing with DANE/TLSA records, we needed to lookup true MX records to start with, hence the need for domains to start with) |
| 29 |
- checkdomains - domains/ - deferencing domain names |
| 30 |
- checkmx - domains/mx/ - got mx record? |
| 31 |
- checkssl - domains/mx/dane/ - valid cert? looking for 'Cipher is|Verify return code' against mx records |
| 32 |
* .ssl |
| 33 |
* .ssl.issuer |
| 34 |
* .ssl.cipher |
| 35 |
- checkdane - valid dane? |
| 36 |
* .dane $NF notlsa // timeout // ... |
| 37 |
* .dane.results |
| 38 |
* .dane.weird |
| 39 |
- checksmtp - starttls enforced? |
| 40 |
* stdout .starttls full session |
| 41 |
* stderr .starttls.enforce $NF connect-bad-dns // ... |
| 42 |
- count.ksh - parsing results and producing stats |
| 43 |
|
|