On Mon, Sep 28, 2026 at 08:04:16PM +0200, Joachim Lindenberg via Postfix-users
wrote:
> On Mon Sep 28, 2026 at 01:54 Viktor Dukhovni wrote:
> > You really do need to fix the first problem. The second happens when
> > STARTTLS is
> > actually attempted, but the TLS handshake fails.
> >
> > If you're unable to post the configuration details, help will be quite
> > limited.
>
> Yes and no. I now recorded packages at my local mail server and its
> bastion server in the internet while connecting to two destinations.
> The two are connected via a VPN (wireguard) with limited MTU.
Sounds like you have broken path MTU discovery.
> The recording on the bastion host shows TLS packets of length beyond
> 1500 bytes with the IP don´t fragment bit set. My bastion host sends
> ICMP fragmentation required, but they are not delivered to or not
> honored by the destination. In fact, the MSS during connection
> establishments if honored would have been sufficient as well.
The DF bits is an expected part of path MTU discovery, it sounds like it
is not the "destination" that needs to honour those ICMP messages. If
you're sending large packets, your machine needs to reduce the TCP MSS
for the destination.
> Root source could be, that OpenSSL allows to generate large frames and
> it is up to the developer to set a limit obtained from TCP MSS or
> interface MTU.
No. OpenSSL is not the TCP/IP stack. OpenSSL just writes bytes to a
TCP socket. It is your kernel's TCP stack that chooses the TCP MSS,
deals with path MTU discovery, ...
You may also need to check for hardware TCP offload on the sending
machine, and adjust if necessary, sometimes the network card will
consolidate TCP segments.
> I already contacted one of the destinations but did not receive an
> answer yet, will contact the other as well. Workaround is to set none
> as TLS policy for the specific destinations.
You still have not shared any configuration info, or "tshark" decodes,
though if the problem is at the TCP/IP layer, the full decode may be
needed, not just the TLS part.
If you have TCP path MTU issues, you'll likely also encounter some
lost connection problems with messages sent in the clear, when the
message payload is sufficiently long to fill a full frame.
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]