Re: How to setup Postfix to Store/Forward Multi-domain + SSL to another Postfix instance?

2011-03-31 Thread Victor Duchovni
On Thu, Mar 31, 2011 at 07:15:58PM +0200, Reindl Harald wrote: > Am 31.03.2011 18:39, schrieb dchil...@bestmail.us: > > > Just for reference for other users, I've 'real' wildcard SSL certs for > > $99/yr from Comodo. > > throw them away, another two CA's from them are compromised and the > naiv

Re: How to setup Postfix to Store/Forward Multi-domain + SSL to another Postfix instance?

2011-03-31 Thread Reindl Harald
Am 31.03.2011 18:39, schrieb dchil...@bestmail.us: > Just for reference for other users, I've 'real' wildcard SSL certs for > $99/yr from Comodo. throw them away, another two CA's from them are compromised and the naive CTO says "... but what we had not done was adequately consider the new (to

Re: How to setup Postfix to Store/Forward Multi-domain + SSL to another Postfix instance?

2011-03-31 Thread dchilton
Hi Wietse, Viktor, Thanks for the references/links. On Thu, 31 Mar 2011 12:19 -0400, "Victor Duchovni" wrote: > > So, in addition to the SSL certs for mynet{1,2,3}.net I have a wildcard > > for *.mydomain.net. > > Whatever single certificate works for you. Wildcard certs from real > CAs used t

Re: How to setup Postfix to Store/Forward Multi-domain + SSL to another Postfix instance?

2011-03-31 Thread Victor Duchovni
On Wed, Mar 30, 2011 at 10:12:40PM -0700, dchil...@bestmail.us wrote: > I was beginning to get that idea :-( I actually just read a coupld of > post that you'd commented on about SNI (?), and that unless the clients > are SNI-aware, not gonna help much. Also DNSSEC as an option > (someday?), but

Re: How to setup Postfix to Store/Forward Multi-domain + SSL to another Postfix instance?

2011-03-31 Thread Wietse Venema
dchil...@bestmail.us: > > Postfix queues mail by default when the destination is down. > > I didn't understand that from reading. So, what triggers the redeliver > attempt? I'm guessing some timer/cron function in master/main config? As required by RFC 5321 (the SMTP protocol). http://tools.ie

Re: How to setup Postfix to Store/Forward Multi-domain + SSL to another Postfix instance?

2011-03-30 Thread dchilton
Hi Viktor, On Thu, 31 Mar 2011 00:59 -0400, "Victor Duchovni" wrote: > On Wed, Mar 30, 2011 at 09:37:31PM -0700, dchil...@bestmail.us wrote: > > > I plan to host mail for 3 domains, > > > > mynet1.net > > mynet2.net > > mynet3.net > > > > and have SSL certs for each domain. > > Sorry, n

Re: How to setup Postfix to Store/Forward Multi-domain + SSL to another Postfix instance?

2011-03-30 Thread Victor Duchovni
On Wed, Mar 30, 2011 at 09:37:31PM -0700, dchil...@bestmail.us wrote: > I plan to host mail for 3 domains, > > mynet1.net > mynet2.net > mynet3.net > > and have SSL certs for each domain. Sorry, not possible to have "SSL certs for each domain". You can have one cert that lists all three d

How to setup Postfix to Store/Forward Multi-domain + SSL to another Postfix instance?

2011-03-30 Thread dchilton
Hi, I plan to host mail for 3 domains, mynet1.net mynet2.net mynet3.net and have SSL certs for each domain. I have 2 servers -- one hosted with StaticIPs facing the 'net, the other behind a dynamic IP on my LAN. the two MX for each of my mail domains point at the two static IPs on the ho