Name: postfix Distribution: openSUSE Leap 42.1
Version: 2.11.6 Vendor: openSUSE
Release: 3.1 Build date: Mon Apr 25 18:06:04 2016
Group: Productivity/Networking/Email/Servers Build host: cloud125
Size: 5018383 Source RPM: postfix-2.11.6-3.1.src.rpm
Summary: A fast, secure, and flexible mailer
Postfix aims to be an alternative to the widely-used sendmail program.






* Fri Mar 25 2016
  - bnc#972346 /usr/sbin/SuSEconfig.postfix is wrong
* Wed Nov 25 2015
  - bnc#947707 mail generated by Amavis being prevented from being re-adressed by /etc/postfix/virtual
  - bnc#947519 SuSEconfig.postfix should enforce umask 022
* Wed Sep 23 2015
  - Update to upstream version 2.11.6:
    * Bugfix: sender_dependent_relayhost_maps ignored the relayhost
      setting in the case of a DUNNO lookup result.
    * Robustness: don't segfault due to excessive recursion after a
      faulty configuration runs into the virtual_alias_recursion_limit.
    * Bugfix: core dump when smtp_policy_maps specifies an invalid
      TLS level.
    * Bugfix: qmqpd null pointer bug when it logs a lost connection
      while not in a mail transaction.
    * Bugfix (introduced: Postfix 2.11): with connection caching
      enabled (the default), recipients could be given to the wrong
      mail server. (bsc#944722)
    * Security: opportunistic TLS by default uses "medium" or
      stronger ciphers instead of "export" or stronger.
    * Security: Postfix TLS support by default no longer uses
      SSLv2 or SSLv3.
  - Remove references to SuSEconfig.postfix from sysconfig docs.
  - Adapt postfix-linux4.patch and rename to postfix-linux45.patch
* Thu Jul 02 2015
  - postfix-linux4.patch: handle Linux 4.x and Linux 5.x (used by aarch64)
* Wed Apr 29 2015
  - postfix-no-md5.patch: use sha1 as default fingerprint method. bsc#928885
* Thu Jan 22 2015
  - bnc#914086 syntax error in config.postfix
  - bnc#911806 config.postfix does not set up correct saslauthd socket directory for chroot
  - bnc#910265 config.postfix does not upgrade the chroot
  - Remove keyring and things as it is md5 based one no longer
    accepted by gpg 2.1
* Thu Dec 18 2014
  -  bnc#908003 wrong access rights on /usr/sbin/postdrop causes
    permission denied when trying to send a mail as non root user
* Fri Jun 27 2014
  - fix typo in postfix-SuSE/update_chroot.systemd
  - fix config.postfix
    * 'insserv amavis' -> 'chkconfig amavis on'
  - rework patch
    * fix virtual stuff
    * add some dovecot stuff
  - rework patch
    * add some dovecot stuff
  - config.postfix
    * add support for submission (587)
    * rework support for smtps
  - Rebase pathces
* Mon Jun 23 2014
  - The included postfix-mysql.tar.bz2 was using a MySQL 4.1 style of
    table engine specification. Modified so that the sql uses
    'ENGINE=' instead of 'TYPE=' for creating tables.
* Mon Jun 23 2014
  - bnc#816769 - config.postfix issues warnings about missing
* Tue Jun 10 2014
  - bnc#882033 - Package postfix has changed files according to rpm
  - bnc#855688 - possible systemd bug: postfix & cifs dependency confict
* Mon Jun 09 2014
  - bnc#863350 - SuSEconfig.postfix complains about modified /etc/postfix/ after updating postfix
* Wed Feb 12 2014
  - bnc#862662 - Unable to configure postfix SMTP with forced TLS using YaST2
  - Update to 2.11.0
    * TLS
      o Support for PKI-less TLS server certificate verification, where
      the CA public key or the server certificate is identified via DNSSEC lookup
    * LMDB database support
    * master
      o The master_service_disable parameter value syntax has changed:
      use "service/type" instead of "service.type".
    * postconf:
      o Support for advanced query and update operations.
      This was implemented primarily to support automated system management tools.
      o The postconf command produces more warnings
    * relay safety
      New smtpd_relay_restrictions parameter built-in default settings:
      smtpd_relay_restrictions =
    * postscreen whitelisting
      Allow a remote SMTP client to skip postscreen(8) tests based on
      its postscreen_dnsbl_sites score.
* Fri Oct 11 2013
  - Ignore errors in %pre/%post.
* Thu Oct 03 2013
  - two improvements for 13.1 and factory
    * postfix-opensslconfig.patch call openSSL_config
    so postfix respects the system's openssl configuration
    * postfix-SuSE/postfix.service since a few months there
    is no, units must be ordered
    after a list of smtpd implementations instead.
* Fri Sep 20 2013
  - Proc is not needed in chroot anymore
* Tue Jul 30 2013
  - remove duplicate entry for inet_protocols
* Mon Jun 17 2013
  - fix for warning
    * unused parameter: virtual_create_maildirsize=yes
    * unused parameter: virtual_mailbox_extended=yes
    * rework
  - fix rcpostfix for sysvinit systems
    * /etc/postfix/system/update_postmaps: No such file or directory
  - rebase patches
    * vda-v11-2.9.5 -> vda-v11-2.9.6
  - fix file postfix-SuSE.tar.gz
    * made a tar.gz
* Sun Jun 16 2013
  - postfix.spec forces the use of SSL and SASL libraries,
    so make sure the BuildRequires are there
* Fri Jun 14 2013
  - Add postfix-db6.diff to fix compile abort with libdb-6.0
* Mon Apr 22 2013
  - Add Source URL, see
  - Add GPG verification
* Sat Apr 20 2013
  -  postfix-SuSE/postfix.service do not Require or
    order after as it no longer exists
    postfix will fail to start in the next systemd version.
* Sat Feb 23 2013
  - Install postfix.service accordingly (/usr/lib/systemd for 12.3
    and up or /lib/systemd for older versions).
* Wed Feb 06 2013
  - update to 2,9.6
    Bugfix: the local(8) delivery agent dereferenced a null pointer
    while delivering to null command (for example, "|" in a .forward file).
    Bugfix: memory leak in program initialization. tls/tls_misc.c.
    Bugfix: he undocumented OpenSSL X509_pubkey_digest() function is
    unsuitable for computing certificate PUBLIC KEY fingerprints.
    Postfix now provides a correct procedure that accounts for
    the algorithm and parameters in addition to the key data.  Specify
    "tls_legacy_public_key_fingerprints = yes" if you need backwards compatibility.
* Thu Jan 17 2013
  - bnc#796162 - script to assign path elements not working in postfix install Build-0284(iso)
* Thu Jan 10 2013
  - rebase patches
    * vda-v10-2.8.12 -> vda-v11-2.9.5 (and to be a p0)
    * main, master, post-instal, ssl-release-buffers (remove version)
    * dynamic_maps, dynamic_maps_pie, pointer_to_literals
* Thu Jan 10 2013
  - update to 2,9.5
    * tls support:
      Support to turn off the TLSv1.1 and TLSv1.2 protocols:
      To temporarily turn off problematic protocols globally:
      smtp_tls_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
      smtp_tls_mandatory_protocols = !SSLv2, !TLSv1.1, !TLSv1.2
      However, it may be better to temporarily turn off problematic
      protocols for broken sites only:
      smtp_tls_policy_maps = hash:/etc/postfix/tls_policy
      /etc/postfix/tls_policy:         may protocols=!SSLv2:!TLSv1.1:!TLSv1.2
    * 20111012 To simplify integration with third-party
      applications, the Postfix sendmail command now always transforms
      all input lines ending in <CR><LF> into UNIX format (lines ending
      in <LF>). Specify "sendmail_fix_line_endings = strict" to restore
      historical Postfix behavior (i.e. convert all input lines ending
      in <CR><LF> only if the first line ends in <CR><LF>).
    * 20120114 Logfile-based alerting systems may need to be
      updated to look for "error" messages in addition to "fatal" messages.
      Specify "daemon_table_open_error_is_fatal = yes" to get the historical
      behavior (immediate termination with "fatal" message).
    * enable_long_queue_ids Postfix 2.9 introduces support for non-repeating queue IDs (also
      used as queue file names). These names are encoded in a mix of upper
      case, lower case and decimal digit characters.  Long queue IDs are
      disabled by default to avoid breaking tools that parse logfiles and
      that expect queue IDs with the smaller [A-F0-9] character set.
    * 20111209 memcache lookup and update support. This provides
      a way to share postscreen(8) or verify(8) caches between Postfix
      instances.  See MEMCACHE_README and memcache_table(5) for details
      and limitations.
    * 20111218 To support external SASL authentication, e.g.,
      in an NGINX proxy daemon, the Postfix SMTP server now always checks
      the smtpd_sender_login_maps table, even without having
      "smtpd_sasl_auth_enable = yes" in
    * ipv6
      o The default inet_protocols value is now "all" instead of "ipv4",
      meaning use both IPv4 and IPv6.
      o The default smtp_address_preference value is now "any" instead
      of "ipv6", meaning choose randomly between IPv6 and IPv4. With
      this the Postfix SMTP client will have more success delivering
      mail to sites that have problematic IPv6 configurations.
* Sat Dec 15 2012
  - update to 2.8.13
    * 20121029
      Workaround: strip datalink suffix from IPv6 addresses
      returned by the system getaddrinfo() routine.  Such suffixes
      mess up the default mynetworks value, host name/address
      verification and possibly more. This change obsoletes the
      20101108 change that removes datalink suffixes in the SMTP
      and QMQP servers, but we leave that code alone.  File:
    * 20121013
      Cleanup: to compute the LDAP connection cache lookup key,
      join the numeric fields with null, just like string fields.
      Viktor Dukhovni. File: global/dict_ldap.c.
    * 20121010
      Bugfix (introduced: Postfix 2.5): memory leak in program
      initialization. Reported by Coverity. File: tls/tls_misc.c.
      Bugfix (introduced: Postfix 2.3): memory leak in the unused
      oqmgr program. Reported by Coverity. File: oqmgr/qmgr_message.c.
    * 20121003
      Bugfix: the postscreen_access_list feature was case-sensitive
      in the first character of permit, reject, etc. Reported by
      Feancis Picabia. File: global/server_acl.c.
  - rebase dynamic_maps_pie patch
  - rpmlint
    * invalid-suse-version-check 1140
    * obsolete-suse-version-check 920 (changes file)
* Fri Dec 14 2012
  - bnc#790141 - Command SuSEconfig.postfix reports ERROR -
    "can not find /lib/YaST/SuSEconfig.functions!!"
* Thu Nov 08 2012
  - bnc#782048 - postfix uses /sbin/conf.d
  - bnc#784659 - remove SuSEconfig calls from yast2-mail
* Fri Aug 10 2012
  - update to 2.8.12
    * 20120730
      Bugfix (introduced: 20000314): AUTH is not allowed after
      MAIL. Timo Sirainen.  File: smtpd/smtpd_sasl_proto.c.
    * 20120702
      Bugfix (introduced: 19990127): the BIFF client leaked an
      unprivileged UDP socket. Fix by Jaroslav Skarvada.  File:
    * 20120621
      Bugfix (introduced: Postfix 2.8): the unused "pass" trigger
      client could close the wrong file descriptors.  File:
  - fix for bnc#771303
    * add 'version = 3' to
  - rebase patches
    * main, master, post-install: 2.8.3 -> 2.8.12
    * ssl-release-buffers: 2.8.5 -> 2.8.12
    * vda-v10: 2.8.9 -> 2.8.12
    * dynamic_maps, dynamic_maps_pie, ipv6_disabled, pointer_to_literals
  - fix changes file
* Thu Jul 19 2012
  - bnc#771811 - postfix update does not regenerate the maps
* Mon Jun 11 2012
  - update to 2.8.11
    * 20120520
    - Bugfix (introduced Postfix 2.4): the event_drain() function
      was comparing bitmasks incorrectly causing the program to
      always wait for the full time limit. This error affected
      the unused postkick command, but only after s/fifo/unix/
      in  File: util/events.c.
    - Cleanup: laptop users have always been able to avoid
      unnecessary disk spin-up by doing s/fifo/unix/ in
      (this is currently not supported on Solaris systems).
      However, to make this work reliably, the "postqueue -f"
      command must wait until its requests have reached the pickup
      and qmgr servers before closing the UNIX-domain request
      sockets.  Files: postqueue/postqueue.c, postqueue/
* Wed May 09 2012
  - bnc#753910 - {name} instead of %{name} in postfix .spec
  - bnc#756452 - VUL-1: postfix: VRFY allows enumerating users
* Thu May 03 2012
  - update to 2.8.10
    * 20120401
      Bitrot: shut up useless warnings about Cyrus SASL call-back
      function pointer type mis-matches. Files: xsasl/xsasl_cyrus.h,
      xsasl/xsasl_cyrus_server.c, xsasl/xsasl_client.c.
    * 20120422
      Bit-rot: OpenSSL 1.0.1 introduces new protocols. Update the
      known TLS protocol list so that protocols can be turned off
      selectively to work around implementation bugs.  Based on
      a patch by Victor Duchovni.  Files: proto/TLS_README.html,
      proto/postconf.proto, tls/tls.h, tls/tls_misc.c, tls/tls_client.c,
  - update to 2.8.9
    * 20120217
      Cleanup: missing #include statement for bugfix code added
      20111226. File: local/unknown.c.
    * 20120214
      Bugfix (introduced: Postfix 2.4): extraneous null assignment
      caused core dump when postlog emitted the "usage" message.
      Reported by Kant (fnord.hammer). File: postlog/postlog.c.
    * 20120202
      Bugfix (introduced: Postfix 2.3): the "change header" milter
      request could replace the wrong header. A long header name
      could match a shorter one, because a length check was done
      on the wrong string.  Reported by Vladimir Vassiliev.  File:
  - use latest VDA patch (2.8.9)
* Thu Apr 12 2012
  - bnc#756450 - postfix: remove version from banner
* Mon Apr 09 2012
  - add port 587 smtp-auth submission to postfix-fw bnc#756289
* Mon Apr 02 2012
  - set exit code explicitely in cond_slp, systemd checks for it
* Tue Mar 13 2012
  - Documentation for bnc#751994 - SuSEconfig module postfix does not exist
* Wed Mar 07 2012
  - rcpostfix now updates the aliases too
* Mon Feb 27 2012
  - update to 2.8.8
    tlsproxy(8) stored TLS sessions with a serverID of
      "tlsproxy" instead of "smtpd", wasting an opportunity for
      session reuse.  File: tlsproxy/tlsproxy.c.
    missing lookup table entry and terminator, causing
      proxymap server segfault when postscreen(8) or verify(8)
      attempted to access their cache via the proxymap server.
      This could never have worked anyway, because the Postfix
      2.8 proxymap protocol does not support cache cleanup.  File
    the Postfix client sqlite
      quoting routine returned the unquoted result instead of the
      quoted text.  The opportunities for misuse are limited,
      because Postfix sqlite files are usually owned by root, and
      Postfix daemons usually run with non-root privileges so
      they can't corrupt the database. Problem reported by Rob
      McGee (rob0).  File: global/dict_sqlite.c.
    the trace service did not
      distinguish between notifications for a non-bounce or a
      bounce message. This code pre-dates DSN support and should
      have been updated when it was re-purposed to handle DSN
      SUCCESS notifications. Problem reported by Sabahattin
      Gucukoglu.  File: bounce/bounce_trace_service.c.
  - use latest VDA patch (2.8.5)
* Wed Jan 25 2012
  - bnc#743369 - yast2 mail module does not open the firewall
  - Set MD5DIR in SuSEconfig.postfix to avoid warnings
* Tue Jan 17 2012
  - bnc738693 - upgrade from 11.4 enables mysql service for systemd
* Thu Jan 12 2012
  - Add postmap rebuild script to systemv init script too
* Wed Jan 11 2012
  - bnc#738900 - cyrus-imapd not receiving mail from postfix
* Tue Dec 13 2011
  -  Move the post map rebuild script into the start script
* Tue Dec 06 2011
  - Fix the last change in %post
* Fri Dec 02 2011
  - bnc#728308 - warning output after update the postfix package
* Wed Nov 09 2011
  - update to 2.8.7
    smtpd(8) did not sanitize newline characters in cleanup(8)
      REJECT messages, causing them to be sent out via SMTP as bare newline characters.
    smtpd(8) sent multi-line responses from a before-queue content filter as text with
      bare <LF> instead of <CR><LF>.
    Workaround: postscreen sent non-compliant SMTP responses (220- followed by 421)
      when it could not give a connection to a real smtpd process, causing some
      remote SMTP clients to bounce mail.
* Thu Nov 03 2011
  - Use the systemd macros in the spec file
* Fri Oct 14 2011
  - only fix files that exists in %post
* Sun Oct 09 2011
  - Use SSL_MODE_RELEASE_BUFFERS if available, see
    SSL_CTX_set_mode man page and
    for the full details.
* Tue Sep 06 2011
  - update to 2.8.5
    * Bugfix: allow for Milters that send an SMTP server reply
      without RFC 3463 enhanced status code. Reported by Vladimir
      Vassiliev.  File: milter/milter8.c.
* Mon Aug 22 2011
  - bnc#684304 - server:mail/postfix: Bugs in SuSEconfig chroot setup script
  - Aplly SASL_SOCKET_DIR patch
* Thu Aug 18 2011
  - Move SuSEconfig.postfix into /usr/sbin/
    (FATE#311272: Do not rewrite via SuSEconfig)
    SuSEconfig.postfix will be executed only once after installation
    automaticaly. Afterwards only you can start it manually or via
    yast2 mail module.
* Fri Aug 12 2011
  - Just the first strep forward to systemd, please test out
    and also fill out the missing description.
* Tue Aug 09 2011
  - rework SuSE patch
    * add missing SASL stuff in rc.postfix
* Mon Jul 25 2011
  - when chrooted and using SASL
    o mount -o bind SASL_SOCKET_DIR into postfix CHROOT
* Mon Jul 11 2011
  - update to 2.8.4
    o Linux kernel version 3 support.
    for more info see ChangeLog
* Wed Jul 06 2011
  - bnc#686436 - postfix bounces messages with improper use of 8-bit data in message body
  - Apply patch
* Fri Jul 01 2011
  - rework patch
    o fix receive_override_options line
  - rework SuSE patch
    o sysconfig: remove POSTFIX_WITH_POP_BEFORE_SMTP
    o SuSEconfig: fix receive_override_options line
* Thu Jun 30 2011
  - replace vda patch
    o 2.8.1 -> 2.8.3
  - fix files doc
    o remove 'doc auxiliary'
      instead cp to pf_docdir
* Sat May 28 2011
  - fix spec for building on all repos
* Tue May 24 2011
  - bnc#679187 - suseconfig/postfix: missing dependency
* Tue May 17 2011
  - fix
    o fix missing
    - amavis    unix  -       -       n       -       4       smtp
    - localhost:10025 inet   n       -       n       -       -       smtpd
    o add patch
  - rework patches
    o (add two missing sasl vars)
    o postfix-SuSE (SuSEconfig, cleanup those vars,...)
* Sun May 15 2011
  - rework TLS stuff
    o reworked patch
    o added postfix-SuSE patch
    o added post-install patch
      Editing /etc/postfix/, adding missing entry for tlsmgr service
      add only if it really does not exist
  - removed Author from description
  - updated vda patch
    o vda-2.7.1 > vda-v10-2.8.1
  - fix build for SLE_10
    o no fdupes ;)
* Wed May 11 2011
  - remove document paths from postfix-files to avoid error messages
    when postfix-doc is not installed
* Tue May 10 2011
  - update to 2.8.3 - VUL-0: postfix memory corruption
* Sun Apr 10 2011
  - bnc#641271 - postfix-2.7.1: init script cannot properly stop
    multi-instance configurations
* Wed Mar 30 2011
  - update to 2.8.2
      o Support for address patterns in DNS blacklist and whitelist lookup results.
      o The Postfix SMTP server now supports DNS-based whitelisting with several safety features
    * Support for read-only sqlite database access.
    * Alias expansion:
      o Postfix now reports a temporary delivery error when the result
      of virtual alias expansion would exceed the virtual_alias_recursion_limit
      or virtual_alias_expansion_limit.
      o To avoid repeated delivery to mailing lists with pathological
      nested alias configurations, the local(8) delivery agent now keeps
      the owner-alias attribute of a parent alias, when delivering mail
      to a child alias that does not have its own owner alias.
    * The Postfix SMTP client no longer appends the local domain when
      looking up a DNS name without ".".
    * The SMTP server now supports contact information that is appended
      to "reject" responses: smtpd_reject_footer
    * Postfix by default no longer adds a "To: undisclosed-recipients:;"
      header when no recipient specified in the message header.
    * tls support:
      o The Postfix SMTP server now always re-computes the SASL mechanism
      list after successful completion of the STARTTLS command.
      o The smtpd_starttls_timeout default value is now stress-dependent.
      o Postfix no longer appends the system-supplied default CA certificates
      to the lists specified with *_tls_CAfile or with *_tls_CApath.
    * New feature: Prototype postscreen(8) server that runs a number
      of time-consuming checks in parallel for all incoming SMTP connections,
      before clients are allowed to talk to a real Postfix SMTP server.
      It detects clients that start talking too soon, or clients that appear
      on DNS blocklists, or clients that hang up without sending any command.
* Thu Feb 10 2011
  - bnc#667299 - Postfix LICENSE not marked as documentation
* Mon Jan 17 2011
  - add some min LDAP support for virtual LDAP-users
    o sysconfig "WITH_LDAP"
    o add
    o SuSEconfig.postfix
      virtual_alias_maps = ... ldap:/etc/postfix/
* Tue Jan 04 2011
  - update to 2.7.2
    * Bugfix (introduced Postfix 2.2): Postfix no longer appends
      the system default CA certificates to the lists specified
      with *_tls_CAfile or with *_tls_CApath.  This prevents
      third-party certificates from getting mail relay permission
      with the permit_tls_all_clientcerts feature.  Unfortunately
      this may cause compatibility problems with configurations
      that rely on certificate verification for other purposes.
      To get the old behavior, specify "tls_append_default_CA =
      yes".  Files: tls/tls_certkey.c, tls/tls_misc.c,
      global/mail_params.h.  proto/postconf.proto, mantools/postlink.
    * Compatibility with Postfix < 2.3: fix 20061207 was incomplete
      (undoing the change to bounce instead of defer after
      pipe-to-command delivery fails with a signal). Fix by Thomas
      Arnett. File: global/pipe_command.c.
    * Bugfix: the milter_header_checks parser provided only the
      actions that change the message flow (reject, filter,
      discard, redirect) but disabled the non-flow actions (warn,
      replace, prepend, ignore, dunno, ok).  File:
    * Performance: fix for poor smtpd_proxy_filter TCP performance
      over loopback ( connections. Problem reported by
      Mark Martinec.  Files: smtpd/smtpd_proxy.c.
    * Cleanup: don't apply reject_rhsbl_helo to non-domain forms
      such as network addresses.  This would cause false positives
      with  File: smtpd/smtpd_check.c.
    * Bugfix: the "421" reply after Milter error was overruled
      by Postfix 1.1 code that replied with "503" for RFC 2821
      compliance. We now make an exception for "final" replies,
      as permitted by RFC. Solution by Victor Duchovni. File:
* Sat Dec 11 2010
  - update vda patch
    o remove 2.6.1-vda-ng.patch
    o remove 2.6.1-vda-ng-64bit.patch
    o add vda-2.7.1.patch
  - rework
    o remove
    o add
* Tue Dec 07 2010
  - prereq init scripts network and syslog
* Thu Aug 12 2010
  - Remove obsolate postscripts
  - bnc#625657 - SuSEconfig.postfix and smtp_use_tls
  - bnc#622873 - postfix doesn't start if ipv6 is disabled
* Tue Jul 06 2010
  - reworked bnc#606251 stuff (not checked in to Factory)
    o used my_print_defaults command for parsing of /etc/my.cnf
    o using quotation marks: "$PF_CHROOT"
    o added sysconfig option POSTFIX_MYSQL_CONN=(socket,tcp)
* Wed Jun 16 2010
  - bnc#606251 - postfix chrooted mysql.sock lost on mysql restart
    o Now MYSQL_SOCK_DIR is mounted with '-o bind' to postfix CHROOT
* Thu Jun 10 2010
  - update to 2.7.1
    * Bugfix (introduced Postfix 2.6) in the XFORWARD implementation,
      which sends remote SMTP client attributes through SMTP-based content filters.
      The Postfix SMTP client did not skip "unknown" SMTP client attributes,
      causing a syntax error when sending an "unknown" client PORT attribute.
    * Robustness: skip LDAP queries with non-ASCII search strings, instead of failing with a database lookup error.
    * Safety: Postfix processes now log a warning when a matchlist has
      a #comment at the end of a line (for example mynetworks or relay_domains).
    * Portability: OpenSSL 1.0.0 changes the priority of anonymous cyphers.
    * Portability: Berkeley DB 5.x is now supported.
* Thu May 20 2010
  - fix obviously lost POSTFIX_MYHOSTNAME in SuSEconfig.postfix
* Wed Apr 07 2010
  - New file check_mail_queue. This script checks if there are some
    mails in the queue and starts postfix if necessary. After delivering
    the mails postfix will be stoped.
* Thu Apr 01 2010
  - bnc#559145 - Changed Domain name not reflected when sending mail
    First /var/run/dhcp-hostname will be evaluated
  - Now POSTFIX_SMTP_TLS_CLIENT is ternary : no yes must
* Sun Feb 28 2010
  - update to 2.7.0
    * performance
    - Periodic cache cleanup for the verify(8) cache database.
    - Improved before-queue filter performance.
    * sender reputation
    - The FILTER action in access maps or header/body_checks now supports sender
      reputation schemes that dynamically choose the SMTP source IP address.
    * address verification
    - The verify(8) service now uses a persistent cache by default.
    * content filter
    - The meaning of an empty filter next-hop destination has changed.
    - The FILTER action in access maps or header/body_checks now supports sender
      reputation schemes that dynamically choose the SMTP source IP address.
    * milter
    - Support for header checks on Milter-generated message headers.
    Please read /usr/share/doc/packages/postfix/RELEASE_NOTES for details.
* Thu Feb 11 2010
  - revert the change to PreReq openldap-devel, this increases the
    default installation several MBs
* Tue Feb 02 2010
  - bnc#567569 - Postfix: move ldap support to a separate package
  - bnc#557239 - postfix delivers mail to user's home instead of /var/spool/mail
* Tue Jan 05 2010
  - rpmlint fixes
    o init-script-undefined-dependency $network-remotefs
  - fix for SuSEconfig.postfix
    o if use_amavis eq "yes"
      then content_filter "amavis:[]:10024]" is defined,
      so removed "-o content_filter=smtp:[]:10024" for smtp
  - s#ldconfig#/sbin/ldconfig#
* Tue Dec 22 2009
  - Add support for dovecot as MDA to SuSEconfig.
* Wed Dec 16 2009
  - Package documentation as noarch
* Thu Dec 10 2009
  - Remove postfixs update script. This does not work now.
* Tue Dec 08 2009
  - Fix the %post section add missed %{fillup_only -an mail}
* Mon Nov 16 2009
  - bnc#555814 – VUL-0: SMTPD_LISTEN_REMOTE="yes" by default
  - bnc#555732 - Invalid $(hostname -i) usage SuSEconfig.postfix
  - bnc#547928 – Postfix does not start during boot process
  - Avoid append relay multiple times in POSTFIX_MAP_LIST
* Mon Oct 26 2009
  - bnc#549612 – SuSEconfig.postfix
* Mon Sep 28 2009
  - bnc#540538 – postfix-2.6.1-10.1 installs new files in /etc/postfix and does not generate <file>.db
  - bnc#519438 - Postfix: Running chrooted lets qmgr loosing his syslog-socket
  - remove obsolate version tests from SuSEconfig.postfix
* Mon Sep 28 2009
  - bnc#525825 - when using cyrus in a chroot environment Suseconfig does not
    create socket /var/lib/imap/socket/lmtp
* Mon Sep 14 2009
  - spec
    o fdupes if >= 1100
* Thu Sep 10 2009
  - update to 2.6.1
    o merge home:varkoly:Factory and o:F
  - spec mods
    o use of getent
  - rpmlint
    o remove unneeded dists from examples/chroot-setup/
    o postin-without-ldconfig
    o files-duplicate /usr/share/doc/packages/postfix-doc/html/
    o files-duplicate /usr/share/man/man?
* Mon Apr 13 2009
  - added VDA patch
    o Mailbox / Maildir size limit, known also as "soft quota",
      to avoid user take all you disk space
    o Customizable "limit" message when the soft quota limit is reached.
      NOTE: message is sent to senders, but NOT to the owner of the mailbox.
    o Limit only 'INBOX', because some people use IMAP and don't want
      the same limit in IMAP folder that are differents from INBOX.
    o Support for 'Courier' style Maildir, usefull for people that
      use courier as pop3/imap server and to get fast soft quota summary.
      Note that it is also compatible with qmail maildir per default.
    o Supports for Courier 'maildirsize' file in Maildir folder that
      is used to read quotas quickly. Note that this option is not
      actived per default and can be dangerous on some NFS client
      (like for example Solaris that cache some filesystem operations).
    o Customisable suffix for Maildir support, when share same external
      dict between postfix and pop3/imap server sometime "Maildir/" suffix
      is needed to avoid extra database handling (eg LDAP, MySQL...).
  - some improvements of SuSEconfig.postfix
    o POSTFIX_LISTEN: Comma separated list of IP's
    o POSTFIX_INET_PROTO: ipv4, ipv6, all
    o POSTFIX_WITH_MYSQL: when using MySQL as backend
      you can now define your own rules
  - added helo_access for helo checks
  - added relay for relaying domain
  - added MySQL stuff when using MySQL as backend (virtuser)
    o you should consider postfixAdmin as mgmnt interface
    o when runninng postfix chrooted:
      you have to run SUSEconfig each time when you have restarted MySQL
      because of linking mysql.sock
* Sun Mar 29 2009
  - bnc#439287 - not all POSTFIX_ADD_* values are properly handled
      by SuSEconfig.postfix
  - bnc#483208 - Postfix configuration trashed after update
  - bnc#488268 - SuSEconfig.postfix chroot setup misses /etc/ssl/certs



