On Wed, Sep 23, 2026 at 10:18:33AM +0000, patpro--- via Postfix-users wrote:
> Thank you. I’ll evaluate later if I go the wireguard road to secure a
> point-to-point tunnel or I go «on the open» with TLS restrictions. The
> tunnel can fail, but it’s agostic about what’s going through.
>
> Secure-channel TLS is a config inside Postfix but probably less prone
> to failure in the long run.
Yes, the tunnel involves additional moving parts, with a Postfix secure
channel you just need to ensure that each side knows the other's public
key:
tls_policy:
relay.example fingerprint
# Current server public key fingerprint
match=XX:XX:...:XX:XX
# Soon to be deployed server public key fingerprint
match=YY:YY:...:YY:YY
tls_access:
# Current client public key fingerprint
AA:AA:...:AA:AA permit
# Soon to be deployed client public key fingerprint
BB:BB:...:BB:BB permit
The client uses "tls_policy" as its "smtp_tls_policy_maps" table.
The server uses "tls_access" as its "check_ccert_access" access(5)
table.
Make sure "smtp_tls_fingerprint_digest" and
"smtpd_tls_fingerprint_digest" are set correctly, matching the
digests recorded in the tables.
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]