From owner-freebsd-security@FreeBSD.ORG Wed Apr 9 10:47:43 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 7D7AAB86 for ; Wed, 9 Apr 2014 10:47:43 +0000 (UTC) Received: from eu1sys200aog112.obsmtp.com (eu1sys200aog112.obsmtp.com [207.126.144.133]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id C8280143E for ; Wed, 9 Apr 2014 10:47:42 +0000 (UTC) Received: from mail-wi0-f173.google.com ([209.85.212.173]) (using TLSv1) by eu1sys200aob112.postini.com ([207.126.147.11]) with SMTP ID DSNKU0UlTP+GtytWmvy2Z9ZbTxLmiHyIwOwR@postini.com; Wed, 09 Apr 2014 10:47:42 UTC Received: by mail-wi0-f173.google.com with SMTP id z2so8632613wiv.0 for ; Wed, 09 Apr 2014 03:47:40 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:sender:date:from:message-id:to:subject:cc :reply-to:in-reply-to; bh=lxFbuU7NBAxZAp0dPc5uXn1klht4rWHYQDcmrErS2vo=; b=hY7rSeA1Qky0w0wMbPZ/rPCYsy+ExCakghfpiSPcPde10FJmJID8ipU2ISSxZsWhAs H//uUm8oJyS/9x9FWQ200HEo024PD3ES03AjjfVqQqRuiXxAE34Ocgkzbj5oMI3WjPBW S3OZX6NAd7NpXM5l5PJD080i495zFxZpl7L3UmOlywvEyMRwBSz2L3OxmG09fhNnNdRU OaAqq2YSvjA4+tVHuZFzJfq6VSSnLwdTtk7HP+Ao5s7sByg6Dx4q/I35gYcjLojvzymr auwx2wmkJdrvXYAm560a9jiQAortLDkrVZHGYlrRRO+PkeIk0NwnIFXUFgREt/c+E0LA DpSw== X-Received: by 10.194.20.65 with SMTP id l1mr8681106wje.39.1397038667798; Wed, 09 Apr 2014 03:17:47 -0700 (PDT) X-Gm-Message-State: ALoCoQljqv0nLsnJopLJbdBM5updQA+VmIOGbC7MNi4BsX8cJOaljfT54/L8Cv2WSCf0H4dXTPq3rwRnLawE2an4x8BQHLdbcvJR37b2R+hQewvTQZgautAbrg57z8bdvfm932CSnKmVmg4i8D8QKJZ4mssGWxxoqQ== X-Received: by 10.194.20.65 with SMTP id l1mr8681097wje.39.1397038667722; Wed, 09 Apr 2014 03:17:47 -0700 (PDT) Received: from mech-cluster241.men.bris.ac.uk (mech-cluster241.men.bris.ac.uk. [137.222.187.241]) by mx.google.com with ESMTPSA id hp5sm962018wjb.0.2014.04.09.03.17.46 for (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 09 Apr 2014 03:17:47 -0700 (PDT) Sender: Anton Shterenlikht Received: from mech-cluster241.men.bris.ac.uk (localhost [127.0.0.1]) by mech-cluster241.men.bris.ac.uk (8.14.8/8.14.6) with ESMTP id s39AHjaG024516 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO); Wed, 9 Apr 2014 11:17:45 +0100 (BST) (envelope-from mexas@mech-cluster241.men.bris.ac.uk) Received: (from mexas@localhost) by mech-cluster241.men.bris.ac.uk (8.14.8/8.14.6/Submit) id s39AHjhO024515; Wed, 9 Apr 2014 11:17:45 +0100 (BST) (envelope-from mexas) Date: Wed, 9 Apr 2014 11:17:45 +0100 (BST) From: Anton Shterenlikht Message-Id: <201404091017.s39AHjhO024515@mech-cluster241.men.bris.ac.uk> To: Lena@lena.kiev.ua, mexas@bris.ac.uk Subject: Re: FreeBSD Security Advisory FreeBSD-SA-14:06.openssl In-Reply-To: <20140409084809.GA2661@lena.kiev> Cc: freebsd-security@freebsd.org X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list Reply-To: mexas@bris.ac.uk List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 09 Apr 2014 10:47:43 -0000 >From Lena@lena.kiev.ua Wed Apr 9 10:43:40 2014 > >Port mail/sendmail-sasl (sendmail+tls+sasl2-8.14.8) depends on the >openssl port. You need to upgrade the security/openssl port to >openssl-1.0.1_10 and restart sendmail. I didn't know about this route of having authenticated sendmail. It's not mentioned in the handbook: http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/SMTP-Auth.html Are you saying mail/sendmail-sasl implements exactly the same functionality as rebuilding the base OS sendmail, as mentioned in the handbook? Thanks Anton