Have circumvented the problem by adding "smtpd_tls_exclude_ciphers =
RC4-MD5" to my /etc/postfix/main.cf.

Google is now using RC4-SHA instead, and I've experienced no further
problems so far.

Obviously this may not be a postfix bug (it seems openssl-related issues
can even be cause by compiler optimization or other issues and it seems
likely in any case that the bug is in the openssl library that postfix
is using) but I am more than willing to help diagnose it, whatever
package it belongs in. It should be 100% reproducible if I stop the
cipher exclusion unless google changes something on their end.

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to postfix in Ubuntu.
https://bugs.launchpad.net/bugs/1001040

Title:
  "TLS library problem" drops incoming mail when sender uses RC4-MD5
  cipher

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/postfix/+bug/1001040/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs

Reply via email to