Re: [exim] GnuTLS vs OpenSSL

Top Page
Delete this message
Reply to this message
Author: Viktor Dukhovni
Date:  
To: Sabahattin Gucukoglu via Exim-users
New-Topics: [exim] DNSSEC+DANE vs MTA-STS was GnuTLS vs OpenSSL
Subject: Re: [exim] GnuTLS vs OpenSSL
> On 30 Sep 2021, at 6:32 pm, Sabahattin Gucukoglu via Exim-users <exim-users@???> wrote:
>
> Courier Mail Server fetches MTA-STS policy documents. I’d consider this a good reason to do MTA-STS as well as DANE, even though I suspect the base of Courier users will be small. Interesting too is that Debian compiles their couriertls against GnuTLS (but I won’t be using that).


The primary use-case for MTA-STS at present is gmail.com, otherwise
it is basically unused. I am not a fan of propping up Google's walled
garden, so generally discourage its adoption. Below is a response to
the USG's call for public comment on an architecture that includes MTA-STS:

https://www.isi.edu/~hardaker/news/2021-09-20-DANE-vs-STS.html

-- 
    Viktor.