cal's sieve leg never had a chance: dovecot wants STARTTLS first #113
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "sieve-starttls"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
follow-up review of #112 - the sieve leg was wrong on arrival, plus two hardening bits it left on the table.
SOGoSieveServergets?tls=YESand moves onto the service name:sieve://mail.lament.gay:4190. dovecot runsssl = requiredhere, so 4190 advertises"SASL" ""until the connection upgrades - a plainsieve://URL connects fine and then has nothing to authenticate withtlsVerifyModeescape hatchenableTCPIP->settings.listen_addresses, scoped to loopback + the host's own WG address. the bare flag is a*bind, which hadpostgres.appslistening on a residential LAN for an instance whose every tenant is a unix socketmkForce- the nixpkgs module writes that key itself offenableTCPIP, at normal prioritysogorole password stops ridingpsql -cand goes in on stdin - an argv leaks it through/procand intopg_stat_activityrestartUnitson bothidentitysecrets -sogo.service'srestartTriggersonly watch the config template, whose text doesn't move when a secret rotatesCLAUDE.md:postgres->postgres.{apps,identity}, and the services registry description picks upproxyConfig/assetsleft for later: sieve is unverified live - needs a deploy to verdandi plus a click through Mail Filters to confirm the handshake actually lands.
cal's sieve leg never had a chance: dovecot wants STARTTLS first