@@ -229,7 +229,7 @@ func_postfix () {
229229 postconf -e " masquerade_domains = \$ mydomain"
230230 # harden postfix
231231 postconf -e " tls_preempt_cipherlist = yes"
232- postconf -e " tls_high_cipherlist = ECDSA+AESGCM:ECDH+AESGCM:DH+AESGCM:ECDSA+AES:ECDH+AES:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS"
232+ postconf -e " tls_medium_cipherlist = ECDSA+AESGCM:ECDH+AESGCM:DH+AESGCM:ECDSA+AES:ECDH+AES:DH+AES:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+3DES:!aNULL:!MD5:!DSS"
233233 # other configuration files
234234 newaliases
235235 touch /etc/postfix/transport
@@ -251,7 +251,8 @@ func_postfix () {
251251 # Logjam Vulnerability #188 - #update for v3.0.2.5 for new cipher suite
252252 openssl dhparam -out /etc/postfix/ssl/dhparam.pem 2048
253253 postconf -e " smtpd_tls_dh1024_param_file = /etc/postfix/ssl/dhparam.pem"
254- postconf -e " smtpd_tls_ciphers = high"
254+ # Set to medium (default) not high for tls compatibility
255+ postconf -e " smtpd_tls_ciphers = medium"
255256
256257 echo " pwcheck_method: auxprop" > /usr/lib64/sasl2/smtpd.conf
257258 echo " auxprop_plugin: sasldb" >> /usr/lib64/sasl2/smtpd.conf
@@ -1147,12 +1148,7 @@ func_dcc () {
11471148 sed -i " s/#loadplugin Mail::SpamAssassin::Plugin::DCC/loadplugin Mail::SpamAssassin::Plugin::DCC/g" /etc/mail/spamassassin/v310.pre
11481149
11491150 # remove old servers
1150- /usr/local/bin/cdcc " delete dcc1.dcc-servers.net"
1151- /usr/local/bin/cdcc " delete dcc2.dcc-servers.net"
1152- /usr/local/bin/cdcc " delete dcc3.dcc-servers.net"
1153- /usr/local/bin/cdcc " delete dcc4.dcc-servers.net"
1154- /usr/local/bin/cdcc " delete dcc5.dcc-servers.net"
1155- /usr/local/bin/cdcc " delete dcc.nova53.net"
1151+ /usr/local/bin/cdcc " delete dcc.nova53.net" > /dev/null 2>&1
11561152 # add new EFA servers
11571153 /usr/local/bin/cdcc " add dcc1.nova53.net"
11581154 /usr/local/bin/cdcc " add dcc2.nova53.net"
0 commit comments