Lukas Erlacher:
> Something goes wrong with establishing the SSL session:
>
> Aug 31 09:52:47 mail postfix-from-user/smtpd[2416]: connect from
> a-mua.informatik.tu-muenchen.de[xxx.xxx.42.153]
The HaProxy hand-over succeeds: Postfix gets a client name and address.
> Aug 31 09:52:49 mail postfix-from-user/smtpd[2416]: SSL_accept error from
> mailclient[xxx.xxx.42.153]: lost connection
> Aug 31 09:52:49 mail postfix-from-user/smtpd[2416]: lost connection after
> CONNECT from mailclient[xxx.xxx.42.153]
> Aug 31 09:52:49 mail postfix-from-user/smtpd[2416]: disconnect from
> mailclient[xxx.xxx.42.153]
I suspect that when the TLS hello becomes appended to the HaProxy server data,
the Postfix HaProxy client reads part of the TLS hello.
Fixing that would require setting the input read buffer size to 1:
in the HaProxy client before reading input:
vstream_control(state->client,
VSTREAM_CTL_BUFSIZE, 1,
VSTREAM_CTL_END);
And before returning:
vstream_control(state->client,
VSTREAM_CTL_BUFSIZE, VSTREAM_BUFSIZE,
VSTREAM_CTL_END);
Wietse