[pfx] Re: DANE and DNSSEC

2023-05-19 Thread raf via Postfix-users
On Thu, May 18, 2023 at 09:11:41AM -0400, Viktor Dukhovni via Postfix-users wrote: > On Thu, May 18, 2023 at 09:22:34PM +0900, Byung-Hee HWANG via Postfix-users > wrote: > > > And now i added TLSA record for only *outbond* smtp server, > > . > > It is also your secondary MX host: > > htt

[pfx] Re: DANE and DNSSEC

2023-05-19 Thread raf via Postfix-users
On Thu, May 18, 2023 at 08:54:16PM +0200, Joachim Lindenberg via Postfix-users wrote: > For Letsencrypt certificates I´d definitely go with 2 1 1 > 8D02536C887482BC34FF54E41D2BA659BF85B341A0A20AFADB5813DCFBCF286D and > optionally the R4 derivate and add their successors when these are about to

[pfx] Re: DANE and DNSSEC

2023-05-19 Thread Byung-Hee HWANG via Postfix-users
Benny Pedersen via Postfix-users writes: > Byung-Hee HWANG via Postfix-users skrev den 2023-05-19 04:26: > >> Thanks for advice! >> >>>[renewalparams] >>>reuse_key = True >>>preferred_chain = ISRG Root X1 > >> And >> I can't say anything yet. I need some test for long tim

[pfx] Re: DANE and DNSSEC

2023-05-19 Thread Benny Pedersen via Postfix-users
Byung-Hee HWANG via Postfix-users skrev den 2023-05-19 04:26: Thanks for advice! [renewalparams] reuse_key = True preferred_chain = ISRG Root X1 And I can't say anything yet. I need some test for long time. If i am sure what DANE is, posttls-finger example.org, basic