TLS ciphers

2014-08-02 Thread Ihsan Dogan
Hi, I've noticed, that my Postfix installation does select in some caes (especially if Postfix is running on both ends) AECDH-AES256-SHA instead of ECDHE-RSA-AES256-GCM-SHA384. The receiving Postfix does support ECDHE-RSA-AES256-GCM-SHA384 and connections with that cipher are possible. But if Pos

Re: TLS ciphers

2014-08-02 Thread Viktor Dukhovni
On Sat, Aug 02, 2014 at 11:53:45AM +0200, Ihsan Dogan wrote: > I've noticed, that my Postfix installation does select in some > caes (especially if Postfix is running on both ends) > AECDH-AES256-SHA instead of ECDHE-RSA-AES256-GCM-SHA384. The > receiving Postfix does support ECDHE-RSA-AES256-GCM-

Re: TLS ciphers

2014-08-02 Thread Ihsan Dogan
Hi Viktor, On Saturday, 02 Aug 2014 15:32 +, Viktor Dukhovni wrote: > > I've noticed, that my Postfix installation does select in some > > caes (especially if Postfix is running on both ends) > > AECDH-AES256-SHA instead of ECDHE-RSA-AES256-GCM-SHA384. The > > receiving Postfix does support E

intermittent untrusted TLS despite DANE

2014-08-02 Thread Peter Palfrader
[Please CC me on replies.] Hi, running 2.11.1 on Debian wheezy, I noticed the following in my mail.log today: weasel@eugeni:~$ grep mx02.posteo.de /var/log/mail.log | grep 'connection est' } Aug 1 09:59:59 s_local@eugeni postfix/smtp[22481]: Untrusted TLS connection established to mx02.posteo.

Re: intermittent untrusted TLS despite DANE

2014-08-02 Thread Viktor Dukhovni
On Sat, Aug 02, 2014 at 08:14:04PM +0200, Peter Palfrader wrote: > running 2.11.1 on Debian wheezy, I noticed the following in my mail.log today: > > weasel@eugeni:~$ grep mx02.posteo.de /var/log/mail.log | grep 'connection est' > } Aug 1 09:59:59 s_local@eugeni postfix/smtp[22481]: Untrusted TL

Re: intermittent untrusted TLS despite DANE

2014-08-02 Thread Robert Schetterer
Am 02.08.2014 um 20:14 schrieb Peter Palfrader: > [Please CC me on replies.] > > Hi, > > running 2.11.1 on Debian wheezy, I noticed the following in my mail.log today: > > weasel@eugeni:~$ grep mx02.posteo.de /var/log/mail.log | grep 'connection est' > } Aug 1 09:59:59 s_local@eugeni postfix/sm

Re: intermittent untrusted TLS despite DANE

2014-08-02 Thread Peter Palfrader
On Sat, 02 Aug 2014, Viktor Dukhovni wrote: > > } Aug 1 09:59:59 s_local@eugeni postfix/smtp[22481]: Untrusted TLS > > connection established to mx02.posteo.de[89.146.194.165]:25: TLSv1.2 with > > cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits) > > For what recipient domains. You need to fi

Re: intermittent untrusted TLS despite DANE

2014-08-02 Thread Viktor Dukhovni
On Sat, Aug 02, 2014 at 08:54:18PM +0200, Robert Schetterer wrote: > sorry too short in time for more debug Could you alert someone the fragile DNS state of posteo.de? They really should not be dependent on just a single sys4.de nameserver for any length of time. -- Viktor.

Re: intermittent untrusted TLS despite DANE

2014-08-02 Thread Robert Schetterer
Am 02.08.2014 um 21:16 schrieb Viktor Dukhovni: > On Sat, Aug 02, 2014 at 08:54:18PM +0200, Robert Schetterer wrote: > >> sorry too short in time for more debug > > Could you alert someone the fragile DNS state of posteo.de? They > really should not be dependent on just a single sys4.de nameserve