18 KiB
Changelog
v10.2.0
- You no longer need to maintain a copy of
setup.shmatching your version release from v10.2 ofdocker-mailserveronwards. Version specific functionality ofsetup.shhas moved into the container itself, whilesetup.shremains as a convenient wrapper to:docker exec -it <container name> setup <command>. ONE_DIRnow defaults to enabled (1).- For anyone relying on internal location of certificates (internal copy of mounted files at startup), the Postfix and Dovecot location of
/etc/postfix/sslhas changed to/etc/dms/tls. This may affect any third-partyuser-patches.shscripts that depended on this path to update certs. - The Let's Encrypt section of our SSL / TLS docs has been brought up to date.
Bigger scripts-related improvements
- [scripts] update
setup.shto now use a running container first if one exists #2134 - [scripts] included
setup.shfunctionality inside the container to be version independent again #2174 - [scripts]
HOSTNAMEandDOMAINNAMEsetup improved #2175 - [scripts]
delmailusercan now delete mailboxed without TLD #2172 - [scripts] properly exit on failure (#2199 in conjunction with #2196)
- [scripts] make
setup.shcompletely non-interactive for Podman users #2201
Security
Some internal refactoring and fixes happened this release cycle in #2196:
- [improve] The Postfix and Dovecot location of
/etc/postfix/sslhas changed to/etc/dms/tls - [improve] An invalid
SSL_TYPEor a valid value with an invalid configuration will now panic, exiting the container and emitting a fatal error to the logs - [fix] An unconfigured/empty
SSL_TYPEENV now correctly disables SSL support for Dovecot and general Postfix configurations. A reminder that this is unsupported officially, and is only intended for tests and troubleshooting. Use only a validSSL_TYPE(letsencryptandmanualare recommended) for production deployments - [fix]
TLS_LEVEL=intermediatenow modifies the system (container)openssl.cnfconfig to set the minimum protocol to TLS 1.0 (from 1.2) and cipher-suite support toDEFAULT@SECLEVEL=1(from2). This change is required for Dovecot in upcoming Debian Bullseye upgrade, to be compatible with theTLS_LEVEL=intermediatecipher-suite profile. It may affect other software within the container that relies on this openssl config, should you extend the Docker image #2193 - [fix] Provide DH parameters (default: RFC 7919 group
ffdhe406.pem) at build-time, instead of during startup. Custom DH parameters regardless ofONE_DIRare now only detected when mounted to/tmp/docker-mailserver/dhparams.pem#2192 - [docs] Revise the Let's Encrypt section of our SSL / TLS docs #2209
Miscellaneous small additions and changes
- [ci] improved caching #2197
- [ci] refactored spam tests and introduced common container setup template #2198
- [fix] update Fail2Ban wrapper to propagate errors to user #2170
- [fix] Dockerfile
sed's are now checked #2158 - [general] Updated default value of
ONE_DIRto1#2148 - [docs] updated Kubernetes documentation #2111
- [docs] introduced dedicated Podman documentation #2179
- [docs] miscellaneous documentation improvements
- [misc] introduced GitHub issue forms for issue templates #2160
- [misc] Removed the internal
mkcert.shscript for Dovecot as it is no longer needed #2196
v10.1.2
This is bug fix release. It reverts a regression introduced with #2104.
v10.1.1
This release mainly improves on v10.1.0 with small bugfixes/improvements and dependency updates
- [feat] Add logwatch maillog.conf file to support /var/log/mail/ (#2112)
- [docs]
CONTRIBUTORS.mdnow also shows every code contributor from the past (#2143) - [improve] Avoid chmod +x when not needed (#2127)
- [improve] check-for-changes: performance improvements (#2104)
- [dependency] Update various dependencies through docs and base image
- [security] This release contains also security fixes for OpenSSL
v10.1.0
This release mainly improves on v10.0.0 with many bugfixes.
- [docs] Various documentation updates (#2105, #2045, #2043, #2035, #2001)
- [misc] Fixed a lot of small bugs, updated dependencies and improved functionality (#2095, #2047, #2046, #2041, #1980, #2030, #2024, #2001, #2000, #2059)
- [feat] Added dovecot-fts-xapian (#2064)
- [security] Switch GPG keyserver (#2051)
v10.0.0
This release improves on 9.1.0 in many aspect, including general fixes, Fail2Ban, LDAP and documentation. This release contains breaking changes.
- [general] Fixed many prose errors (spelling, grammar, indentation).
- [general] Documentation is better integrated into the development process and it's visibility within the project increased (#1878).
- [general] Added
stop_grace_period:to example Compose file and supervisord (#1896 #1945) - [general]
./setup.sh email listwas enhanced, now showing information neatly (#1898) - [general] Added update check and notification (#1976, #1951)
- [general] Moved environment variables to the documentation and improvements (#1948, #1947, #1931)
- [security] Major Fail2Ban improvements (cleanup, update and breaking changes, see below)
- [fix]
./setup.sh email del ...now works properly - [code] Added color variables to
setup.shand improved the script as a whole (#1879, #1886) - [ldap] Added
LDAP_QUERY_FILTER_SENDERS(#1902) - [ldap] Use dovecots LDAP
urisconnect option instead ofhosts(#1901) - [ldap] Complete rework of LDAP documentation (#1921)
- [docs] PRs that contain changes to docs will now be commented with a preview link (#1988)
Breaking Changes
- [security] Fail2Ban adjustments:
- Fail2ban v0.11.2 is now used (#1965).
- The previous F2B config (from an old Debian release) has been replaced with the latest default config for F2B shipped by Debian 10.
- The new default blocktype is now
DROP, notREJECT(#1914). - A ban now applies to all ports (
iptables-allports), not just the ones that were "attacked" (#1914). - Fail2ban 0.11 is totally compatible to 0.10, but the database got some new tables and fields (auto-converted during the first start), so once updated to DMS 10.0.0, you have to remove the database
mailstate:/lib-fail2ban/fail2ban.sqlite3if you would need to downgrade to DMS 9.1.0 for some reason.
- [ldap] Removed
SASLAUTHD_LDAP_SSL. Instead provide a protocol inSASLAUTHD_LDAP_SERVERand adjustSASLAUTHD_LDAP_default values (#1989). - [general] Removed
stablerelease tag (#1975):- Scheduled builds are now based off
edge. - Instead of
stable, please use the latest version tag available (or thelatesttag). - The
stableimage tag will be removed from DockerHub in the near future.
- Scheduled builds are now based off
- [setup] Removed
./setup config sslcommand (deprecated since v9).SSL_TYPE=self-signedremains supported however. (dc8f49de, #2021)
v9.1.0
This release marks the breakpoint where the wiki was transferred to a reworked documentation
- [feat] Introduce ENABLE_AMAVIS env (#1866)
- [docs] Move wiki to gh-pages (#1826) - Special thanks to @polarathene 👨🏻💻
- You can edit the docs now directly with your code changes
- Documentation is now versioned related to docker image versions and viewable here: https://docker-mailserver.github.io/docker-mailserver/edge/
v9.0.1
A small update on the notification function which was made more stable as well as minor fixes.
- [fix]
_notifycannot fail anymore - non-zero returns lead to unintended behavior in the past whenDMS_DEBUGwas not set or0 - [refactor]
check-for-changes.shnow uses_notify
v9.0.0
- [feat] Support extra
user_attributesin accounts configuration (#1792) - [feat] Add possibility to use a custom dkim selector (#1811)
- [feat] TLS: Dual (aka hybrid) certificate support! (eg ECDSA certificate with an RSA fallback for broader compatibility) (#1801).
- This feature is presently only for
SSL_TYPE=manual, all you need to do is provide your fallback certificate to theSSL_ALT_CERT_PATHandSSL_ALT_KEY_PATHENV vars, just like your primary certificate would be setup for manual mode.
- This feature is presently only for
- [security] TLS: You can now use ECDSA certificates! (#1802)
- Warning: ECDSA may not be supported by legacy systems (most pre-2014). You can provide an RSA certificate as a fallback.
- [fix] TLS: For some docker-compose setups when restarting the docker-mailserver container, internal config state may have been persisted despite making changes that should reconfigure TLS (eg changing
SSL_TYPEor replacing the certificate file) (#1801). - [refactor] Split
start-mailserver.sh(#1820) - [fix] Linting now uses local path to remove the sudo dependency (#1831).
Breaking Changes
- [security] TLS:
TLS_LEVEL=modernhas changed the server-side preference order to 128-bit before 256-bit encryption (#1802).- NOTE: This is still very secure but may result in misleading lower scores/grades from security audit websites.
- [security] TLS:
TLS_LEVEL=modernremoved support for AES-CBC cipher suites and follows best practices by supporting only AEAD cipher suites (#1802).- NOTE: As TLS 1.2 is the minimum required for modern already, AEAD cipher suites should already be supported and preferred.
- [security] TLS:
TLS_LEVEL=intermediatehas removed support for cipher suites using RSA for key exchange (only available with an RSA certificate) (#1802).- NOTE: This only affects Dovecot which supported 5 extra cipher suites using AES-CBC and AES-GCM. Your users MUA clients should be unaffected, preferring ECDHE or DHE for key exchange.
- [refactor] Complete refactoring of opendkim script (#1812).
- NOTE: Use
./setup.sh config dkim helpto see the new syntax.
- NOTE: Use
v8.0.1
This release is a hotfix for #1781.
- [spam]
bl.spamcop.netwas removed from the list of spam lists since the domain expired and became unusable
v8.0.0
The transfer of the old repository to the new organization has completed. This release marks the new starting point for docker-mailserver in the docker-mailserver organization. Various improvements were made, small bugs fixed and the complete CI was transferred.
- [general] transferred the whole repository to
docker-mailserver/docker-mailserver - [general] adjusted
README.mdand split offENVIRONMENT.md - [ci] usage of the GitHub Container Registry
- [ci] switched from TravisCI to GitHub Actions for CI/CD
- now building images for
amd64andarm/v7andarm/64 - integrated stale issues action to automatically close stale issues
- adjusted issue templates
- now building images for
- [build] completely refactored and improved the
Dockerfile - [build] improved the
Makefile - [image improvement] added a proper init process
- [image improvement] improved logging significantly
- [image improvement] major LDAP improvements
- [bugfixes] miscellaneous bug fixes and improvements
Breaking changes of release 8.0.0
- [image improvement] log-level now defaults to
warn - [image improvement] DKIM default key size now 4096
- [general] the
:latesttag is now the latest release and:edgerepresents the latest push onmaster - [general] URL changed from
tomav/...todocker-mailserver/...
v7.2.0
- [scripts] refactored
target/bin/ - [scripts] redesigned environment variable use
- [general] added Code of Conduct
- [general] added missing Dovecot descriptions
- [tests] enhanced and refactored all tests
v7.1.0
- [scripts] use of default variables has changed slightly (consult environment variables)
- [scripts] Added coherent coding style and linting
- [scripts] Added option to use non-default network interface
- [general] new contributing guidelines were added
- [general] SELinux is now supported