On 2026-09-22 23:08, patpro--- via Postfix-users wrote:
September 23, 2026 at 07:17, "Mel P via Postfix-users" wrote:
On 2026-09-21 11:02, Patrick Proniewski via Postfix-users wrote:
[snip]>>> I’m running FreeBSD. I’ve created a Jail with Wireguard client, a VPN
  tunnel between the Jail and the Wireguard server on the VPS, but I could
  not find a way to use that setup properly.

FWIW, I do this with the TLS secure channel capabilities of Postfix
combined with certificate-based authentication, and separate inbound and
outbound transports.

I’m intriged. Can you elaborate on that?

Secure-channel TLS adds checks on the remote server's TLS identity, restricting who postfix will relay to.

Client certificate verification adds checks on the remote client's TLS identity, restricting who can relay to postfix.

The TLS_README covers both:

Secure-channel TLS
https://www.postfix.org/TLS_README.html#client_tls_secure

Client certificate verification
https://www.postfix.org/TLS_README.html#server_vrfy_client


You can't do any of this on the MX port 25 or the MUA submission/smtps ports, so MX and home MTA both need separate inbound and outbound smtpd transports.
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to