qmail doesn't support SMTP over TLS or SSL. How is that "secure"?
qmail doesn't support SMTP over TLS or SSL. How is that "secure"?
I did run qmail in 1998ish and it was quirky but rock solid. But that was coming from sendmail, which I'd never recommend. Now I'd say postfix is the way to go: quite secure and fully TLS capable.
qmail does not, strictly speaking, even support SMTP over TCP. This is because it relies upon UCSPI tools to do the actual transport layer setup. UCSPI-TCP does the TCP part for qmail. And one can equally well layer it over UCSPI-SSL.
People did. Erwin Hoffmann, one of the UCSPI-SSL authors, even wrote a lengthy article on the subject of SMTP over TSL/SSL with qmail.
[1]: https://www.tenable.com/plugins/index.php?view=single&id=102...
Indeed, many sysadmins of the time lauded qmail's lack of supporting "standard features" in the name of "security" which sadly was still a new concept on the Internet.
Something to consider: SMTP over TLS offers some privacy and confidentiality between two mail servers that have established a trust relationship, but it offers no protection against an upstream network (who can simply fake some DNS records and get a letsencrypt certificate) or a state actor (who simply threatens the CA). I think referring to "SMTP over TLS" as "secure" is dangerous because it leads us to equate "more code" as providing security.
I understand the concerns about trust, but why not make trust the extra step for now, and make encryption the standard. And in time we can standardize trust as well. (I know it's pretty standard already but I'm thinking about 'the average user')
"Well I can't trust the source so why bother with encryption" is what we have presently, and that's just ridiculous.