On Sun, Sep 27, 2026 at 12:03:14PM +0200, Joachim Lindenberg via Postfix-users 
wrote:

> On Sun Sep 27, 2026 at 10:56 AM Victor wrote:
> > Thanks, makes sense and a relief there's nothing more problematic
> > involved.
> 
> I am encountering "client TLS configuration problem" on my mailcow
> with two peers the last days.

This problem report is much too short on detail.

    https://www.postfix.org/DEBUG_README.html#mail
    https://www.postfix.org/DEBUG_README.html#logging

However, you may be lucky, because if that particular message is logged
by your Postfix software, the only context in which that's likely is
a syntactic or semantic problem in your TLS policy table:

    src/smtp/smtp_proto.c-388-      /*
    src/smtp/smtp_proto.c-389-       * If the policy table specifies a bogus 
TLS security level, fail
    src/smtp/smtp_proto.c-390-       * now.
    src/smtp/smtp_proto.c-391-       */
    src/smtp/smtp_proto.c-392-#ifdef USE_TLS
    src/smtp/smtp_proto.c-393-      if (state->tls->level == TLS_LEV_INVALID)
    src/smtp/smtp_proto.c-394-          /* Warning is already logged. */
    src/smtp/smtp_proto.c-395-          return (smtp_site_fail(state, 
DSN_BY_LOCAL_MTA,
    src/smtp/smtp_proto.c-396-                                 
SMTP_RESP_FAKE(&fake, "4.7.0"),
    src/smtp/smtp_proto.c:397:                                 "client TLS 
configuration problem"));
    src/smtp/smtp_proto.c-398-#endif
    src/smtp/smtp_proto.c-399-
    src/smtp/smtp_proto.c-400-      /*
    src/smtp/smtp_proto.c-401-       * XXX Some PIX firewall versions require 
flush before ".<CR><LF>" so
    src/smtp/smtp_proto.c-402-       * it does not span a packet boundary. This 
hurts performance so it
    src/smtp/smtp_proto.c-403-       * is not on by default.
    src/smtp/smtp_proto.c-404-       */
    src/smtp/smtp_proto.c-405-      if (resp->str[strspn(resp->str, "20 
*\t\n")] == 0) {
    src/smtp/smtp_proto.c-406-          /* Best effort only. Ignore errors. */
    --
    src/smtp/smtp_tls_policy.c-231-{
    src/smtp/smtp_tls_policy.c-232-    const char *name = 
str_tls_level(tls_level);
    src/smtp/smtp_tls_policy.c-233-
    src/smtp/smtp_tls_policy.c-234-    if (name == 0)
    src/smtp/smtp_tls_policy.c-235- name = "unknown";
    src/smtp/smtp_tls_policy.c-236-    return name;
    src/smtp/smtp_tls_policy.c-237-}
    src/smtp/smtp_tls_policy.c-238-
    src/smtp/smtp_tls_policy.c-239-#define MARK_INVALID(why, levelp) do { \
    src/smtp/smtp_tls_policy.c:240:     dsb_simple((why), "4.7.5", "client TLS 
configuration problem"); \
    src/smtp/smtp_tls_policy.c-241-     *(levelp) = TLS_LEV_INVALID; } while (0)
    src/smtp/smtp_tls_policy.c-242-
    src/smtp/smtp_tls_policy.c-243-/* tls_site_lookup - look up per-site TLS 
security level */
    src/smtp/smtp_tls_policy.c-244-
    src/smtp/smtp_tls_policy.c-245-static void tls_site_lookup(SMTP_TLS_POLICY 
*tls, int *site_level,
    src/smtp/smtp_tls_policy.c-246-                       const char 
*site_name, const char *site_class)
    src/smtp/smtp_tls_policy.c-247-{
    src/smtp/smtp_tls_policy.c-248-    const char *lookup;
    src/smtp/smtp_tls_policy.c-249-

> Can this have the same cause? What configuration can I change temporarily to 
> allow delivery?

No, nothing in this thread is remotely like the problem you're
reporting.  Check the TLS policy table for malformed or invalid data.

-- 
    Viktor.  🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to