On Mon Sep 28, 2026 at 01:54 Viktor Dukhovni wrote: > You really do need to fix the first problem. The second happens when > STARTTLS is > actually attempted, but the TLS handshake fails. > > If you're unable to post the configuration details, help will be quite > limited.
Yes and no. I now recorded packages at my local mail server and its bastion server in the internet while connecting to two destinations. The two are connected via a VPN (wireguard) with limited MTU. The recording on the bastion host shows TLS packets of length beyond 1500 bytes with the IP don“t fragment bit set. My bastion host sends ICMP fragmentation required, but they are not delivered to or not honored by the destination. In fact, the MSS during connection establishments if honored would have been sufficient as well. Root source could be, that OpenSSL allows to generate large frames and it is up to the developer to set a limit obtained from TCP MSS or interface MTU. I already contacted one of the destinations but did not receive an answer yet, will contact the other as well. Workaround is to set none as TLS policy for the specific destinations. Regards, Joachim _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
