Nothing advertises the legacy protocols while they are off (LP-7)
While the switch is off, the answers that tell a mail app where to connect stop offering what the switch closed, so a new phone or desktop app is not sent to a port that is shut or a sign-in that will be refused: - Thunderbird-style autoconfig (/mail/config-v1.1.xml and its other paths) and Outlook autodiscover leave out IMAP, POP3 and SMTP submission. - PACC (/.well-known/user-agent-configuration.json) offers JMAP, CalDAV, CardDAV and WebDAV, and no IMAP, POP3, SMTP or ManageSieve. The document is rendered once per configuration load, so the JMAP-only version is rendered beside it and chosen per request; the _ua-auto-config digest in the suggested zone follows, since it hashes the same document. - The suggested zone publishes _imap, _imaps, _pop3, _pop3s, _submission and _submissions with target "." -- "not offered", RFC 6186 section 3.4 -- the spec's decision, rather than dropping them: a client that looks is told, and an automatically managed zone replaces the old records instead of leaving them behind. - It also drops the TLSA records for ports 993 and 995. A TLS pin for a port the switch has closed advertises a service that is not there. Submission's 465 keeps its record: the SMTP lock keeps that port open. The switch is read per answer, as sign-in reads it, so every node agrees the moment it turns. Inbound mail, MX records and the JMAP, CalDAV and CardDAV answers are untouched. tests/e2e/legacy_protocols.py checks all four on a running server: with the switch on they offer IMAP, POP3 and SMTP (the control); while it is off they offer none of them and every legacy SRV name has target "."; and once it is back on, autoconfig and the zone read as they did before. All checks pass.
This commit is contained in:
@@ -2,9 +2,15 @@
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||
*/
|
||||
|
||||
use crate::{Server, config::network::Pacc, network::dkim::generate_dkim_dns_record};
|
||||
use crate::{
|
||||
Server,
|
||||
config::network::Pacc,
|
||||
network::{dkim::generate_dkim_dns_record, legacy::is_legacy_service},
|
||||
};
|
||||
use ahash::{AHashMap, AHashSet};
|
||||
use base64::{Engine, engine::general_purpose};
|
||||
use dns_update::{
|
||||
@@ -33,6 +39,8 @@ impl Server {
|
||||
let mut records = Vec::new();
|
||||
let network = &self.core.network;
|
||||
let default_host = network.server_name.as_str();
|
||||
// inbuxa: legacy-protocols LP-7
|
||||
let legacy_off = self.legacy_protocols_off().await?;
|
||||
let domain_name = domain.name.as_str();
|
||||
let domain_name_suffix = format!(".{domain_name}");
|
||||
|
||||
@@ -193,6 +201,25 @@ impl Server {
|
||||
ServiceProtocol::Smtp => [("submission", 587), ("submissions", 465)],
|
||||
};
|
||||
|
||||
// inbuxa: legacy-protocols LP-7. While they are off, every
|
||||
// name says "not offered" -- target "." (RFC 6186 section
|
||||
// 3.4) -- rather than vanishing, so a client that looks
|
||||
// is told, and an old record left in the zone is replaced.
|
||||
if legacy_off && is_legacy_service(protocol) {
|
||||
for (service_name, _) in services {
|
||||
records.push(NamedDnsRecord {
|
||||
name: format!("_{service_name}._tcp.{domain_name}."),
|
||||
record: DnsRecord::SRV(SRVRecord {
|
||||
target: ".".to_string(),
|
||||
priority: 0,
|
||||
weight: 0,
|
||||
port: 0,
|
||||
}),
|
||||
});
|
||||
}
|
||||
continue;
|
||||
}
|
||||
|
||||
for (is_tls, (service_name, port)) in services.into_iter().enumerate() {
|
||||
if is_tls == 1 || service.cleartext {
|
||||
records.push(NamedDnsRecord {
|
||||
@@ -277,6 +304,14 @@ impl Server {
|
||||
for (protocol, service) in &network.info.services {
|
||||
let hostname = service.hostname.as_deref().unwrap_or(default_host);
|
||||
if hostname.ends_with(&domain_name_suffix) || hostname == domain_name {
|
||||
// inbuxa: legacy-protocols LP-7. No TLS pin for a port
|
||||
// the switch has closed. Submission's port stays open
|
||||
// (the SMTP lock), so its record stays.
|
||||
if legacy_off
|
||||
&& matches!(protocol, ServiceProtocol::Imap | ServiceProtocol::Pop3)
|
||||
{
|
||||
continue;
|
||||
}
|
||||
let port = match protocol {
|
||||
ServiceProtocol::Imap => 993,
|
||||
ServiceProtocol::Pop3 => 995,
|
||||
@@ -382,6 +417,12 @@ impl Server {
|
||||
}
|
||||
|
||||
pub async fn get_pacc_for_domain(&self, domain_name: &str) -> trc::Result<String> {
|
||||
// inbuxa: legacy-protocols LP-7
|
||||
let pacc = if self.legacy_protocols_off().await? {
|
||||
&self.core.network.info.pacc_jmap_only
|
||||
} else {
|
||||
&self.core.network.info.pacc
|
||||
};
|
||||
self.get_directory_for_domain(domain_name)
|
||||
.await
|
||||
.caused_by(trc::location!())
|
||||
@@ -390,15 +431,9 @@ impl Server {
|
||||
.and_then(|directory| {
|
||||
directory
|
||||
.oidc_discovery_document()
|
||||
.map(|doc| self.core.network.info.pacc.build(&doc.url))
|
||||
})
|
||||
.unwrap_or_else(|| {
|
||||
self.core
|
||||
.network
|
||||
.info
|
||||
.pacc
|
||||
.build(&self.core.network.http.url_https)
|
||||
.map(|doc| pacc.build(&doc.url))
|
||||
})
|
||||
.unwrap_or_else(|| pacc.build(&self.core.network.http.url_https))
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user