At smtpd_tls_loglevel=2
I get ALL of this in my logs Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:before SSL initialization Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:before SSL initialization Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS read client hello Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS write server hello Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS write certificate Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS write key exchange Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS write server done Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS write server done Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS read client key exchange Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS read change cipher spec Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS read finished Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: em-sj-88.mktroute.com[199.15.215.88]: Issuing session ticket, key expiration: 1501689808 Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS write session ticket Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS write change cipher spec Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: SSL_accept:SSLv3/TLS write finished Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: Anonymous TLS connection established from em-sj-88.mktroute.com[199.15.215.88]: TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits) At smtpd_tls_loglevel=1 I get none of it. Is there a Postfix setting to get a sort of "loglevel= 1 1/2" so I get ONLY the Aug 2 03:19:26 maryland postfix/handoff/smtpd[40383]: Anonymous TLS connection established from em-sj-88.mktroute.com[199.15.215.88]: TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits) If not I can play with rsyslog scripting. Which I'm already looking at *anyway* to get at effective per-domain TLS verbose logging. It would be handy to have both of those just in Postfix setup. Rob