Re: SSL version question

2021-02-17 Thread Viktor Dukhovni
On Wed, Feb 17, 2021 at 07:04:54PM +0100, Jeff Abrahamson wrote: > But the man page makes a good argument for setting this to medium.  > I'd originally set smtpd_tls_mandatory_ciphers = high, I've switched > it to medium. You can set it back to "high". Perhaps that should even be the new

Re: SSL version question

2021-02-17 Thread Jeff Abrahamson
On 16/02/2021 21:34, Viktor Dukhovni wrote: >> On Feb 16, 2021, at 3:57 PM, Dominic Raferd wrote: >> >>> In what way does that improve your security over the default, which >>> allows 1.0 and 1.1? >> As stated this is for auth clients i.e. our own people, using SMTPS or >> STARTTLS. There is no

Re: SSL version question

2021-02-17 Thread Dominic Raferd
On 17/02/2021 14:49, Vincent Lefevre wrote: On 2021-02-16 18:34:32 -0200, Viktor Dukhovni wrote: On Feb 16, 2021, at 3:57 PM, Dominic Raferd wrote: In what way does that improve your security over the default, which allows 1.0 and 1.1? As stated this is for auth clients i.e. our own

Re: SSL version question

2021-02-17 Thread Vincent Lefevre
On 2021-02-16 18:34:32 -0200, Viktor Dukhovni wrote: > > On Feb 16, 2021, at 3:57 PM, Dominic Raferd wrote: > > > >> In what way does that improve your security over the default, which > >> allows 1.0 and 1.1? > > As stated this is for auth clients i.e. our own people, using SMTPS or > >

Re: SSL version question

2021-02-16 Thread Viktor Dukhovni
> On Feb 16, 2021, at 3:57 PM, Dominic Raferd wrote: > >> In what way does that improve your security over the default, which >> allows 1.0 and 1.1? > As stated this is for auth clients i.e. our own people, using SMTPS or > STARTTLS. There is no problem for us in enforcing it for them, they

Re: SSL version question

2021-02-16 Thread Dominic Raferd
On 16/02/2021 17:41, Bill Cole wrote: On 16 Feb 2021, at 5:46, Dominic Raferd wrote: On 16/02/2021 10:28, Jeff Abrahamson wrote: I have a client that's triggering these errors in my logs (and is therefore unable to send even though he can read mail ok):

Re: SSL version question

2021-02-16 Thread Bill Cole
On 16 Feb 2021, at 5:46, Dominic Raferd wrote: On 16/02/2021 10:28, Jeff Abrahamson wrote: I have a client that's triggering these errors in my logs (and is therefore unable to send even though he can read mail ok): postfix/submission/smtpd[310140]: connect from [...]

Re: SSL version question

2021-02-16 Thread Jeff Abrahamson
On 16/02/2021 11:46, Dominic Raferd wrote: > > On 16/02/2021 10:28, Jeff Abrahamson wrote: >> >> I have a client that's triggering these errors in my logs (and is >> therefore unable to send even though he can read mail ok): >> >>     [...] >> >> [...] >> >> I'd like to do what I can to

Re: SSL version question

2021-02-16 Thread Dominic Raferd
On 16/02/2021 10:28, Jeff Abrahamson wrote: I have a client that's triggering these errors in my logs (and is therefore unable to send even though he can read mail ok): postfix/submission/smtpd[310140]: connect from [...] postfix/submission/smtpd[310140]: SSL_accept error from

SSL version question

2021-02-16 Thread Jeff Abrahamson
I have a client that's triggering these errors in my logs (and is therefore unable to send even though he can read mail ok): postfix/submission/smtpd[310140]: connect from [...] postfix/submission/smtpd[310140]: SSL_accept error from [...]: -1 postfix/submission/smtpd[310140]: