no dane support

Bug #1828810 reported by bjo
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
exim4 (Ubuntu)
Fix Released
Undecided
Unassigned
Bionic
Triaged
Wishlist
Unassigned
Cosmic
Fix Released
Undecided
Unassigned
Disco
Fix Released
Undecided
Unassigned

Bug Description

Please backport 4.92 to bionic, as 4.90 does not support dane yet:
https://github.com/Exim/exim/blob/master/doc/doc-txt/OptionLists.txt

ProblemType: Bug
DistroRelease: Ubuntu 18.04
Package: exim4

Revision history for this message
bjo (bjo81) wrote :
tags: added: bionic
removed: disco
description: updated
Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Thanks for filing this bug in Ubuntu.

This does sound like an interesting feature to have. For reference, the changes between 4.90 and 4.92 can be seen here: https://github.com/Exim/exim/blob/master/src/README.UPDATING

The SRU policy permits such an update to a stable release, but we will have to balance the risk and the amount of work needed.

I'll accept the bug, and put it in our backlog, but we don't have an estimate for this. Any help would be welcomed, of course. In particular, filing out the SRU template https://wiki.ubuntu.com/StableReleaseUpdates#SRU_Bug_Template for this bug. Having a good test case, and solid arguments for this update, will go a long way.

I'll also mark this as fix released for cosmic, disco and eoan. I couldn't find a trivial way to check if exim was built with dane support, but ldd in the exim main binary seems good enough. It shows the binary linked with libgnutls-dane on cosmic and later, but not on bionic.

Changed in exim4 (Ubuntu Cosmic):
status: New → Fix Released
Changed in exim4 (Ubuntu Disco):
status: New → Fix Released
Changed in exim4 (Ubuntu):
status: New → Fix Released
Changed in exim4 (Ubuntu Bionic):
status: New → Triaged
importance: Undecided → Wishlist
Revision history for this message
bjo (bjo81) wrote :

[Impact]

 * exim < 4.91 has no DANE support, e.g. the guidance Cyber Security 098 of the Federal Office for Information Security can not ne fulfilled.
*
[Test Case]

 * try to use e.g. "hosts_try_dane" as a config option

[Regression Potential]

Except moving DANE/SPF-support from experimental to stable,
https://github.com/Exim/exim/blob/master/src/README.UPDATING mentions the removal of the WITH_OLD_CLAMAV_STREAM build option, which (I assume) is not used anyways.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.