Re: E-mail problem

2020-11-14 Thread Stuart Henderson
On 2020-11-13, Berkay Tuncel  wrote:
> Hi all,
>
>
>
> We need an advice for our e-mail traffic with openbsd.org
>
>
> When I sent an e-mail to openbsd.org which is rhs, from 160.75.0.0/16, I
> got a TLS handshake error. On the other hand, when I tried from another
> subnet, there was no problem.

It would help to include the logs from your MTA (including timestamps)
and the exact text of the error message.

"tried from another subnet" - is that the same machine using a different
source address - or a different machine on another subnet?

> Nevertheless, our mta has not a problem like this with any other mta.
> That's why, I think it can be a network related issue but still we need
> some help :)

Maybe network related, maybe TLS stack.




Re: E-mail problem

2020-11-13 Thread Ashlen
On 20/11/13 11:26, Berkay Tuncel wrote:
> Hi all,
>
>
>
> We need an advice for our e-mail traffic with openbsd.org
>
>
> When I sent an e-mail to openbsd.org which is rhs, from 160.75.0.0/16, I
> got a TLS handshake error. On the other hand, when I tried from another
> subnet, there was no problem.
>
>
> Nevertheless, our mta has not a problem like this with any other mta.
> That's why, I think it can be a network related issue but still we need
> some help :)
>
>
> Thanks.
>
> Berkay

I'm no expert on smtpd(8); that said, it's essential to post an
appropriate amount of information to troubleshoot the problem. In your
case, that means including what's inside smtpd.conf(5) and pf.conf(5)
(as it could be related to packet filtering), as well as output from
/var/log/maillog and dmesg(8).

I might be forgetting something, in which case someone else can chime in
with additions, but these are the obvious inclusions in my mind.

--
https://amissing.link



Re: E-mail problem

2020-11-13 Thread Berkay Tuncel
Hi Tom,

Firstly thanks for your response.

I am sending it from itu.edu.tr

Yes, we have spf records and also other smtp precautions such as dkim and
so on.

We use sendmail, so we have sendmail conf and macro. Also, we have cipher
restrictions.

Nevertheless, the cipher which has successful communication with
mail.openbsd.org is allowed on our mta. Meanwhile this cipher
is ECDHE-RSA-AES256-GCM-SHA384.

Thanks.
Berkay

Tom Smyth , 13 Kas 2020 Cum, 15:27 tarihinde
şunu yazdı:

> Do u have an spf record for your domain and what domain are you sending
> from?
>
> What is your opensmtpd.conf
> Do u have restrictions onciphers supported by your mta
>
> On Friday, 13 November 2020, Berkay Tuncel  wrote:
>
>> Hi all,
>>
>>
>>
>> We need an advice for our e-mail traffic with openbsd.org
>>
>>
>> When I sent an e-mail to openbsd.org which is rhs, from 160.75.0.0/16, I
>> got a TLS handshake error. On the other hand, when I tried from another
>> subnet, there was no problem.
>>
>>
>> Nevertheless, our mta has not a problem like this with any other mta.
>> That's why, I think it can be a network related issue but still we need
>> some help :)
>>
>>
>> Thanks.
>>
>> Berkay
>>
>
>
> --
> Kindest regards,
> Tom Smyth.
>


-- 
Berkay TUNCEL


Re: E-mail problem

2020-11-13 Thread Tom Smyth
Do u have an spf record for your domain and what domain are you sending
from?

What is your opensmtpd.conf
Do u have restrictions onciphers supported by your mta

On Friday, 13 November 2020, Berkay Tuncel  wrote:

> Hi all,
>
>
>
> We need an advice for our e-mail traffic with openbsd.org
>
>
> When I sent an e-mail to openbsd.org which is rhs, from 160.75.0.0/16, I
> got a TLS handshake error. On the other hand, when I tried from another
> subnet, there was no problem.
>
>
> Nevertheless, our mta has not a problem like this with any other mta.
> That's why, I think it can be a network related issue but still we need
> some help :)
>
>
> Thanks.
>
> Berkay
>


-- 
Kindest regards,
Tom Smyth.


E-mail problem

2020-11-13 Thread Berkay Tuncel
Hi all,



We need an advice for our e-mail traffic with openbsd.org


When I sent an e-mail to openbsd.org which is rhs, from 160.75.0.0/16, I
got a TLS handshake error. On the other hand, when I tried from another
subnet, there was no problem.


Nevertheless, our mta has not a problem like this with any other mta.
That's why, I think it can be a network related issue but still we need
some help :)


Thanks.

Berkay