On Wed, Sep 23, 2026 at 10:18:33AM +0000, patpro--- via Postfix-users wrote:

> Thank you. I’ll evaluate later if I go the wireguard road to secure a
> point-to-point tunnel or I go «on the open» with TLS restrictions. The
> tunnel can fail, but it’s agostic about what’s going through.
>
> Secure-channel TLS is a config inside Postfix but probably less prone
> to failure in the long run. 

Yes, the tunnel involves additional moving parts, with a Postfix secure
channel you just need to ensure that each side knows the other's public
key:

    tls_policy:
        relay.example fingerprint
            # Current server public key fingerprint
            match=XX:XX:...:XX:XX
            # Soon to be deployed server public key fingerprint
            match=YY:YY:...:YY:YY

    tls_access:
        # Current client public key fingerprint
        AA:AA:...:AA:AA     permit
        # Soon to be deployed client public key fingerprint
        BB:BB:...:BB:BB     permit
        
The client uses "tls_policy" as its "smtp_tls_policy_maps" table.
The server uses "tls_access" as its "check_ccert_access" access(5)
table.

Make sure "smtp_tls_fingerprint_digest" and
"smtpd_tls_fingerprint_digest" are set correctly, matching the
digests recorded in the tables.

-- 
    Viktor.  🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to