On Wed, Oct 22, 2008 at 10:23:33AM -0500, Noel Jones wrote: > Yes, the clients have the CA cert and do properly validate the > server certificate. > > That raises the question why the server logs the TLS > connection as Anonymous. Maybe because postfix doesn't ask > for a client certificate (smtpd_tls_ask_ccert = no; > smtpd_tls_req_ccert = no)?
Oops, sorry, I confused "anonymous" ciphers with anonymous clients. The client being anonymous (no client cert) is just fine. Brain in neutral for a moment, sorry about that. -- Viktor. Disclaimer: off-list followups get on-list replies or get ignored. Please do not ignore the "Reply-To" header. To unsubscribe from the postfix-users list, visit http://www.postfix.org/lists.html or click the link below: <mailto:[EMAIL PROTECTED]> If my response solves your problem, the best way to thank me is to not send an "it worked, thanks" follow-up. If you must respond, please put "It worked, thanks" in the "Subject" so I can delete these quickly.