[pfx] Re: Some TLS connections untrusted in postfix but trusted with posttls-finger

2023-11-30 Thread Viktor Dukhovni via Postfix-users
On Thu, Nov 30, 2023 at 03:37:02PM +0100, Alexander Leidinger via Postfix-users wrote: > > > Nov 30 11:18:40 mailgate postfix/tlsproxy[98300]: server certificate > > > verification failed for in-9.smtp.github.com[140.82.112.31]:25: > > > num=62:hostname mismatch > > > > That is the error. Indee

[pfx] Re: Some TLS connections untrusted in postfix but trusted with posttls-finger

2023-11-30 Thread Wietse Venema via Postfix-users
Alexander Leidinger via Postfix-users: > What is wrong here that [tlsproxy] doesn't establish a trusted connection > to the github mailservers when posttls-finger is able to do that with > the same cert store? Because there are differences between tlsproxy and posttls-finger. 1) Different execu

[pfx] Re: Some TLS connections untrusted in postfix but trusted with posttls-finger

2023-11-30 Thread Alexander Leidinger via Postfix-users
Am 2023-11-30 15:03, schrieb Bill Cole via Postfix-users: On 2023-11-30 at 08:03:09 UTC-0500 (Thu, 30 Nov 2023 14:03:09 +0100) Alexander Leidinger via Postfix-users is rumored to have said: My main.cf contains the same certs-path for smtp and smtpd TLS connections: ---snip--- # grep CApath m

[pfx] Re: gmail failing SPF/DKIM

2023-11-30 Thread Linkcheck via Postfix-users
Thanks for all your help, guys. Appreciated! ___ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org

[pfx] Re: Some TLS connections untrusted in postfix but trusted with posttls-finger

2023-11-30 Thread Bill Cole via Postfix-users
On 2023-11-30 at 08:03:09 UTC-0500 (Thu, 30 Nov 2023 14:03:09 +0100) Alexander Leidinger via Postfix-users is rumored to have said: Hi, There is something strange with delivering mail from my mailserver to github, it complains about the github server certificate not verified on an outgoing T

[pfx] Some TLS connections untrusted in postfix but trusted with posttls-finger

2023-11-30 Thread Alexander Leidinger via Postfix-users
Hi, There is something strange with delivering mail from my mailserver to github, it complains about the github server certificate not verified on an outgoing TLS connection. My main.cf contains the same certs-path for smtp and smtpd TLS connections: ---snip--- # grep CApath main.cf smtp_tl