Package: postfix
Version: 2.10.0-1
Severity: important

I use TLS keys to authenticate and allow relaying of mail
from trusted clients, using relay_clientcerts. 

Upgrading broke it:

Mar  9 10:23:26 wren postfix/smtpd[14341]: connect from 
dialup-4.154.6.204.Dial1.Atlanta1.Level3.net[4.154.6.204]
Mar  9 10:23:29 wren postfix/smtpd[14341]: Trusted TLS connection established 
from dialup-4.154.6.204.dial1.atlanta1.level3.net[4.154.6.204]: TLSv1.2 with 
cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Mar  9 10:23:31 wren postfix/smtpd[14341]: NOQUEUE: reject: RCPT from 
dialup-4.154.6.204.Dial1.Atlanta1.Level3.net[4.154.6.204]: 554 5.7.1 
<jo...@debian.org>: Relay access denied; from=<j...@gnu.kitenet.net> 
to=<jo...@debian.org> proto=ESMTP helo=<gnu.kitenet.net>
Mar  9 10:23:32 wren postfix/smtpd[14341]: disconnect from 
dialup-4.154.6.204.Dial1.Atlanta1.Level3.net[4.154.6.204]

I downgraded back to 2.9.3-2.1 and relaying once again works.

Relevant parts of my config:

relay_clientcerts = hash:/etc/postfix/relay_clientcerts

Which contains:

37:F6:75:70:7A:CB:A7:91:8B:2A:39:4E:24:4E:9B:F9 gnu

-- 
see shy jo

Attachment: signature.asc
Description: Digital signature

Reply via email to