September 23, 2026 at 11:25, "Mel P via Postfix-users" 
<[email protected] 
mailto:[email protected]?to=%22Mel%20P%20via%20Postfix-users%22%20%3Cpostfix-users%40postfix.org%3E
 > wrote:

> Secure-channel TLS adds checks on the remote server's TLS identity, 
> restricting who postfix will relay to.
> 
> Client certificate verification adds checks on the remote client's TLS 
> identity, restricting who can relay to postfix.
> 
> The TLS_README covers both:
> 
> Secure-channel TLS
> https://www.postfix.org/TLS_README.html#client_tls_secure
> 
> Client certificate verification
> https://www.postfix.org/TLS_README.html#server_vrfy_client
> 
> You can't do any of this on the MX port 25 or the MUA submission/smtps 
> ports, so MX and home MTA both need separate inbound and outbound smtpd 
> transports.


Thank you. I’ll evaluate later if I go the wireguard road to secure a 
point-to-point tunnel or I go «on the open» with TLS restrictions. The tunnel 
can fail, but it’s agostic about what’s going through. Secure-channel TLS is a 
config inside Postfix but probably less prone to failure in the long run. 

patrick
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to