OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Problems using Postfix and TLS
« previous next »
  • Print
Pages: [1]

Author Topic: Problems using Postfix and TLS  (Read 1837 times)

RalfOE

  • Newbie
  • *
  • Posts: 30
  • Karma: 2
    • View Profile
Problems using Postfix and TLS
« on: May 03, 2022, 09:03:43 am »
I tried to configure Postfix and TLS, but got lost connection messages:

postfix/smtpd[22661]   disconnect from mail-ej1-f53.google.com[209.85.218.53] ehlo=1 starttls=0/1 commands=1/2   
postfix/smtpd[22661]   lost connection after STARTTLS from mail-ej1-f53.google.com[209.85.218.53]   
postfix/smtpd[22661]   connect from mail-ej1-f53.google.com[209.85.218.53]

Messages sent from Gmail got the info: 454 4.7.0 TLS not available due to local problem

I think it's an issue by the certificate, but I can't find info, how to configure right.
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Problems using Postfix and TLS
« Reply #1 on: May 04, 2022, 08:05:32 am »
You can see which certificate postfix is using with:

openssl s_client -debug -starttls smtp -crlf -connect firewall:25 > postfix.txt

replace 'firewall' with the hostname or IP address of your firewall. You should get a 2xx reply (e.g. 250 chunking).

You could go through a full SMTP conversation, but if you only want to know the cert, just type quit and examine the text file.

Bart...
Logged

RalfOE

  • Newbie
  • *
  • Posts: 30
  • Karma: 2
    • View Profile
Re: Problems using Postfix and TLS
« Reply #2 on: May 04, 2022, 05:33:34 pm »
Hi Bart,

thank you. It seems, that we had problems with the Let's Encrypt certificate. I used another certificate and since then it works.

Ralf
Logged

dawc21

  • Newbie
  • *
  • Posts: 4
  • Karma: 0
    • View Profile
Re: Problems using Postfix and TLS
« Reply #3 on: August 10, 2022, 11:11:10 pm »
In my case I had to reload and re-select my ROOT CA chain within the Postfix configuration.  The odd part is that the root CA cert I re-uploaded had the same serial numbers etc... A bit of a head scratcher but it got it all going....
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Problems using Postfix and TLS
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2