pki dhparams

2017-01-30 Thread opensmtpd
Hello, was there any special reason to remove the pki parameter dhparams? On my systems I try to create the dhfile.pem by myselve and now I can't use it any more on opensmtpd. cheers wof -- You received this mail because you are subscribed to misc@opensmtpd.org To unsubscribe, send a mail to:

Re: OpenSmtpd not RFC compliant ?

2017-01-30 Thread Mik J
Thank you Gilles for this clarification > Le Lundi 30 janvier 2017 9h35, Gilles Chehade a écrit : > > On Sun, Jan 29, 2017 at 08:12:21PM +, Mik J wrote: >> Hello Gilles, >> Thank you for your answer. >> For the first point I have this ruletable domains file:/etc/mail/domains >> table

Re: tls-require not working as expected

2017-01-30 Thread Jason Mann
Noted. I did wonder if it applied to FreeBSD as it wasn't mentioned in the man page, but I just tried it to see and it appeared to work. Changed to 'bce0' but no difference to the TLS (or lack thereof) behaviour. Regards, Jason On 30 January 2017 at 16:29, Dima Panov wrote: > 30.01.17 20:28,

Re: tls-require not working as expected

2017-01-30 Thread Jason Mann
Here it is: --- smtpd.conf --- ca mail.mydomain.net certificate "/usr/local/etc/letsencrypt/archive/ mydomain.net/chain1.pem" pki mail.mydomain.net certificate "/usr/local/etc/letsencrypt/archive/ mydomain.net/cert1.pem" pki mail.mydomain.net key "/usr/local/etc/letsencrypt/archive/ mydomain.net/p

Re: tls-require not working as expected

2017-01-30 Thread Gilles Chehade
On Fri, Jan 27, 2017 at 02:41:47PM +, Jason Mann wrote: > Hello list. > > I'm trying to configure OpenSMTPD 5.9.2 on a FreeBSD server but I'm seeing > anomalous behaviour with one of my listen directives. > > The directive in question is: > > listen on egress tls-require hostname mail.mydo

Re: tls-require not working as expected

2017-01-30 Thread Jason Mann
The tracing didn't reveal any clues. No mention of TLS at all. smtp: 0x8027726c0: connected to listener 0x802653000 [hostname= mail.mydomain.net, port=25, tag=] smtp: 0x8027726c0: STATE_NEW -> STATE_CONNECTED smtp: 0x8027726c0: >>> 220 mail.mydomain.net ESMTP OpenSMTPD smtp: 0x8027726c0: <<< HELO

Re: OpenSmtpd not RFC compliant ?

2017-01-30 Thread Gilles Chehade
On Sun, Jan 29, 2017 at 08:12:21PM +, Mik J wrote: > Hello Gilles, > Thank you for your answer. > For the first point I have this ruletable domains file:/etc/mail/domains > table users file:/etc/mail/users > accept tagged CLAM_IN for domain virtual deliver to maildir > "/var/mail/vmail/%{rcp