September 23, 2026 at 11:25, "Mel P via Postfix-users" <[email protected] mailto:[email protected]?to=%22Mel%20P%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E > wrote:
> Secure-channel TLS adds checks on the remote server's TLS identity, > restricting who postfix will relay to. > > Client certificate verification adds checks on the remote client's TLS > identity, restricting who can relay to postfix. > > The TLS_README covers both: > > Secure-channel TLS > https://www.postfix.org/TLS_README.html#client_tls_secure > > Client certificate verification > https://www.postfix.org/TLS_README.html#server_vrfy_client > > You can't do any of this on the MX port 25 or the MUA submission/smtps > ports, so MX and home MTA both need separate inbound and outbound smtpd > transports. Thank you. I’ll evaluate later if I go the wireguard road to secure a point-to-point tunnel or I go «on the open» with TLS restrictions. The tunnel can fail, but it’s agostic about what’s going through. Secure-channel TLS is a config inside Postfix but probably less prone to failure in the long run. patrick _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
