Viktor Dukhovni wrote Sun Sep, 27 13:04:
> On Sun, Sep 27, 2026 at 12:03:14PM +0200, Joachim Lindenberg via Postfix-users
> wrote:
> 
> > On Sun Sep 27, 2026 at 10:56 AM Victor wrote:
> > > Thanks, makes sense and a relief there's nothing more problematic
> > > involved.
> >
> > I am encountering "client TLS configuration problem" on my mailcow
> > with two peers the last days.
> 
> This problem report is much too short on detail.

Understood and thanks for the pointers.

Actually I now noticed that the errors are alternating between "client TLS 
configuration problem" and "Cannot start TLS: handshake failure". Mailcow uses 
a (non-standard) tls-policy-agent, no idea whether it returned an erroneous 
value, but I then hardwired the policy to "dane-only" and then captured network 
traffic with tcpdump. One shows a Hello Retry Request, the other plenty of 
retransmissions. I was able to deliver both messages using a policy "none". 
Therefore I don“t know but suspect it might be related to OpenSSL changes, as I 
previously was able to deliver to both destinations.

What information might help to clarify? The network traces I obtained? 
Postfinger, but then what options?

Thanks,
Joachim


_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to