On Sun, Sep 27, 2026 at 12:03:14PM +0200, Joachim Lindenberg via Postfix-users
wrote:
> On Sun Sep 27, 2026 at 10:56 AM Victor wrote:
> > Thanks, makes sense and a relief there's nothing more problematic
> > involved.
>
> I am encountering "client TLS configuration problem" on my mailcow
> with two peers the last days.
This problem report is much too short on detail.
https://www.postfix.org/DEBUG_README.html#mail
https://www.postfix.org/DEBUG_README.html#logging
However, you may be lucky, because if that particular message is logged
by your Postfix software, the only context in which that's likely is
a syntactic or semantic problem in your TLS policy table:
src/smtp/smtp_proto.c-388- /*
src/smtp/smtp_proto.c-389- * If the policy table specifies a bogus
TLS security level, fail
src/smtp/smtp_proto.c-390- * now.
src/smtp/smtp_proto.c-391- */
src/smtp/smtp_proto.c-392-#ifdef USE_TLS
src/smtp/smtp_proto.c-393- if (state->tls->level == TLS_LEV_INVALID)
src/smtp/smtp_proto.c-394- /* Warning is already logged. */
src/smtp/smtp_proto.c-395- return (smtp_site_fail(state,
DSN_BY_LOCAL_MTA,
src/smtp/smtp_proto.c-396-
SMTP_RESP_FAKE(&fake, "4.7.0"),
src/smtp/smtp_proto.c:397: "client TLS
configuration problem"));
src/smtp/smtp_proto.c-398-#endif
src/smtp/smtp_proto.c-399-
src/smtp/smtp_proto.c-400- /*
src/smtp/smtp_proto.c-401- * XXX Some PIX firewall versions require
flush before ".<CR><LF>" so
src/smtp/smtp_proto.c-402- * it does not span a packet boundary. This
hurts performance so it
src/smtp/smtp_proto.c-403- * is not on by default.
src/smtp/smtp_proto.c-404- */
src/smtp/smtp_proto.c-405- if (resp->str[strspn(resp->str, "20
*\t\n")] == 0) {
src/smtp/smtp_proto.c-406- /* Best effort only. Ignore errors. */
--
src/smtp/smtp_tls_policy.c-231-{
src/smtp/smtp_tls_policy.c-232- const char *name =
str_tls_level(tls_level);
src/smtp/smtp_tls_policy.c-233-
src/smtp/smtp_tls_policy.c-234- if (name == 0)
src/smtp/smtp_tls_policy.c-235- name = "unknown";
src/smtp/smtp_tls_policy.c-236- return name;
src/smtp/smtp_tls_policy.c-237-}
src/smtp/smtp_tls_policy.c-238-
src/smtp/smtp_tls_policy.c-239-#define MARK_INVALID(why, levelp) do { \
src/smtp/smtp_tls_policy.c:240: dsb_simple((why), "4.7.5", "client TLS
configuration problem"); \
src/smtp/smtp_tls_policy.c-241- *(levelp) = TLS_LEV_INVALID; } while (0)
src/smtp/smtp_tls_policy.c-242-
src/smtp/smtp_tls_policy.c-243-/* tls_site_lookup - look up per-site TLS
security level */
src/smtp/smtp_tls_policy.c-244-
src/smtp/smtp_tls_policy.c-245-static void tls_site_lookup(SMTP_TLS_POLICY
*tls, int *site_level,
src/smtp/smtp_tls_policy.c-246- const char
*site_name, const char *site_class)
src/smtp/smtp_tls_policy.c-247-{
src/smtp/smtp_tls_policy.c-248- const char *lookup;
src/smtp/smtp_tls_policy.c-249-
> Can this have the same cause? What configuration can I change temporarily to
> allow delivery?
No, nothing in this thread is remotely like the problem you're
reporting. Check the TLS policy table for malformed or invalid data.
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]