Re: [mailop] Apple, iPhone setup, attempts SSL on port 587

2015-08-03 Thread Michelle Sullivan
John Levine wrote: Ouch! Someone needs a refresher :) Someone might benefit from rereading RFC 6409, particularly section 3.3. Port 587 should ALWAYS be using AUTH, full email address, with TLS enabled.. Then you have a MUA-MTA connection (submission) Nope. For one

Re: [mailop] Apple, iPhone setup, attempts SSL on port 587

2015-08-02 Thread John Levine
require credentials if you're submitting email to local users, but will require it for relay... Maybe I'm misreading something, but doesn't that turn it into a MTA port instead of an MSA port? That would seem to totally defeat the purpose of using a MSA port at all, no? Not necessarily.

Re: [mailop] Apple, iPhone setup, attempts SSL on port 587

2015-08-02 Thread Michael Peddemors
On 15-08-02 03:46 PM, John Levine wrote: require credentials if you're submitting email to local users, but will require it for relay... Maybe I'm misreading something, but doesn't that turn it into a MTA port instead of an MSA port? That would seem to totally defeat the purpose of using a

Re: [mailop] Apple, iPhone setup, attempts SSL on port 587

2015-08-02 Thread John Levine
Ouch! Someone needs a refresher :) Someone might benefit from rereading RFC 6409, particularly section 3.3. Port 587 should ALWAYS be using AUTH, full email address, with TLS enabled.. Then you have a MUA-MTA connection (submission) Nope. For one thing, it's an MSA, not an MTA. For another,

Re: [mailop] Apple, iPhone setup, attempts SSL on port 587

2015-07-31 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Robert Mueller wrote: Are you absolutely sure this is happening on port 587? Yes. Is there anything else logged before or after this from the same IP (maybe get a tcpdump)? Does it actually attempt plaintext + STARTTLS upgrade after the direct

Re: [mailop] Apple, iPhone setup, attempts SSL on port 587

2015-07-30 Thread Robert Mueller
A client with a new iPhone (not sure what model), attempts to setup imap/smtp using starttls. As part of the setup, the iPhone apparently probes the smtp server on port 587 with an SSL handshake: Jul 29 21:31:34 ns1 sendmail[20641]: t6U4VYQL020641: rejecting commands from

Re: [mailop] Apple, iPhone setup, attempts SSL on port 587

2015-07-30 Thread Michelle Sullivan
Franck Martin wrote: 465 has been deprecated, IANA has got this port registered for another protocol than SMTPS. I stand corrected (and learned something new today) However recently at IETF, as part of Universal TLS in Application (UTA), it was discussed that using STARTTLS is may be not as

Re: [mailop] Apple, iPhone setup, attempts SSL on port 587

2015-07-30 Thread Dave Warren
On 2015-07-30 18:33, Robert Mueller wrote: A client with a new iPhone (not sure what model), attempts to setup imap/smtp using starttls. As part of the setup, the iPhone apparently probes the smtp server on port 587 with an SSL handshake: Jul 29 21:31:34 ns1 sendmail[20641]: t6U4VYQL020641: