On Wed, Sep 23, 2026 at 02:25:00AM -0700, Mel P via Postfix-users wrote:
> > I’m intriged. Can you elaborate on that?
>
> Secure-channel TLS adds checks on the remote server's TLS identity,
> restricting who postfix will relay to.
>
> Client certificate verification adds checks on the remote client's TLS
> identity, restricting who can relay to postfix.
>
> The TLS_README covers both:
>
> Secure-channel TLS
> https://www.postfix.org/TLS_README.html#client_tls_secure
>
> Client certificate verification
> https://www.postfix.org/TLS_README.html#server_vrfy_client
Speaking of TLS, both your email domain and the domain of its MX hosts
are DNSSEC-signed, but no TLSA records are as yet published:
bluerosetech.com. IN MX 10 echo.brtsvcs.net. ; NOERROR AD=1
bluerosetech.com. IN MX 20 foxtrot.brtsvcs.net. ; NOERROR AD=1
echo.brtsvcs.net. IN A 208.111.40.118 ; NOERROR AD=1
echo.brtsvcs.net. IN AAAA 2607:f740:c::4ae ; NOERROR AD=1
_25._tcp.echo.brtsvcs.net. IN TLSA ? ; NXDOMAIN AD=1
foxtrot.brtsvcs.net. IN A 192.73.240.122 ; NOERROR AD=1
foxtrot.brtsvcs.net. IN AAAA 2607:f740:14::c13 ; NOERROR AD=1
_25._tcp.foxtrot.brtsvcs.net. IN TLSA ? ; NXDOMAIN AD=1
You can get some value from the DNSSEC deployment by first implementing
the requisite monitoring (of TLSA record presence and correctness w.r.t.
the live certs), and then publish TLSA records for the MX hosts:
$ posttls-finger -lencrypt -Lsummary -cC "[echo.brtsvcs.net]" |
openssl x509 -noout -pubkey |
openssl pkey -pubin -outform DER |
openssl dgst -sha256 -binary |
xxd -p -c32; echo "${PIPESTATUS[@]}"
e30e1a2fa542475a52865a6aaca47cac8c93b6dac34f52afecc70f3bb7de9a88
0 0 0 0 0
$ posttls-finger -lencrypt -Lsummary -cC "[foxtrot.brtsvcs.net]" |
openssl x509 -noout -pubkey |
openssl pkey -pubin -outform DER |
openssl dgst -sha256 -binary |
xxd -p -c32; echo "${PIPESTATUS[@]}"
314d6e589bda180c8a1123ce054f72d1177ac66277c121315ae47ecdbbbc63b4
0 0 0 0 0
TLSA records matching the current certificates would be:
_25._tcp.echo.brtsvcs.net IN TLSA 3 1 1
e30e1a2fa542475a52865a6aaca47cac8c93b6dac34f52afecc70f3bb7de9a88
_25._tcp.foxtrot.brtsvcs.net IN TLSA 3 1 1
314d6e589bda180c8a1123ce054f72d1177ac66277c121315ae47ecdbbbc63b4
If the server has multiple certificate chains (say both RSA and ECDSA),
you'll need a separate "3 1 1" record for each algorithm.
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]