Re: many domains fail dkim sig check

2014-11-09 Thread shm...@riseup.net
Wietse Venema: > shm...@riseup.net: >> i saw robert's sys4.de link and also >> >> http://www.postfix.org/announcements/postfix-2.11.3.html >> >> recently mail_version = 2.11.3 arrived into debian jessie >> >> i still unfortunately receive dkim si

Re: many domains fail dkim sig check

2014-11-09 Thread shm...@riseup.net
i saw robert's sys4.de link and also http://www.postfix.org/announcements/postfix-2.11.3.html recently mail_version = 2.11.3 arrived into debian jessie i still unfortunately receive dkim sig errors for essentially the same domains prior to the update, that are certain of good sigs including htt

Re: many domains fail dkim sig check

2014-10-12 Thread shm...@riseup.net
Robert Schetterer wrote: > double check your dmarc milter setup, it s very tricky with postfix, > make sure mail is not altered on its way ( which might brake dkim ) > > > Best Regards > MfG Robert Schetterer could you please provide some examples from your experience ?

many domains fail dkim sig check

2014-10-12 Thread shm...@riseup.net
i wrote to the relevant dkim/dmarc lists but still i find the following errors from opendkim/opendmarc consistently with every message could somebody please suggest which settings, if there are any within postfix, that may alleviate these failures ? overall, on the other hand, i see many successf

possible Berkeley DB bug

2014-09-26 Thread shm...@riseup.net
when i receive mail from some MTA's (there seems to be no pattern as to which ones) and this msg is logged, no STARTTLS is established and i receive the mail in the clear the file verify_cache.db does exist is it ok to delete this, restart postfix and see what happens next time? -rw-r--r-- 1 po

Re: 3x lost connection while performing the EHLO handshake -> Connection refused -> clear text delivery ok -> automated reply ESMTPS ok

2014-09-18 Thread shm...@riseup.net
thank you sir, Viktor Dukhovni wrote: > On Fri, Sep 19, 2014 at 01:40:34AM +1000, shm...@riseup.net wrote: > >> I have difficulty with messagelabs MTA's >> >> below is 1 example >> >> i don't understand the strace debug log & i don't

3x lost connection while performing the EHLO handshake -> Connection refused -> clear text delivery ok -> automated reply ESMTPS ok

2014-09-18 Thread shm...@riseup.net
i have difficulty with messagelabs MTA's below is 1 example i don't understand the strace debug log & i don't have it now regardless of the low/medium/high cipherlist in which medium is in use and low/high are inactive & irrelevant messagelabs problems prevail i use 2 certs assistance is muc

Re: ECDSA ciphers & MTA's

2014-09-15 Thread shm...@riseup.net
Viktor Dukhovni wrote: > On Tue, Sep 16, 2014 at 12:00:33AM +1000, shm...@riseup.net wrote: > >> Viktor Dukhovni wrote: >>> On Mon, Sep 15, 2014 at 05:16:19PM +1000, shm...@riseup.net wrote: >>> >>>> if i have an EC mail server cert and if an MTA setu

Re: ECDSA ciphers & MTA's

2014-09-15 Thread shm...@riseup.net
Viktor Dukhovni wrote: > On Mon, Sep 15, 2014 at 05:16:19PM +1000, shm...@riseup.net wrote: > >> if i have an EC mail server cert and if an MTA setup to send/receive >> gives the following: > > Always configure at least some sort of RSA certificate along with > any E

Re: ECDSA ciphers & MTA's

2014-09-15 Thread shm...@riseup.net
Dennis L wrote: >> if i have an EC mail server cert and if an MTA setup to send/receive? >> gives the following: > >> $ openssl s_client -cipher ECDH -starttls smtp -connect >> medusa.blackops.org:25 >> CONNECTED(0003) >> 139821090178704:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:ssl

Re: ECDSA ciphers & MTA's

2014-09-15 Thread shm...@riseup.net
A. Schulze wrote: > > shmick: > >> CONNECTED(0003) >> 139821090178704:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 >> alert handshake failure:s23_clnt.c:762: > medusa.blackops.org smtp *SERVER* just doesn't support the selected cipher. > >> does that mean it cannot connect *to*

ECDSA ciphers & MTA's

2014-09-15 Thread shm...@riseup.net
if i have an EC mail server cert and if an MTA setup to send/receive gives the following: $ openssl s_client -cipher ECDH -starttls smtp -connect medusa.blackops.org:25 CONNECTED(0003) 139821090178704:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure:s23_clnt.c:

tlsv1 alert decode error

2014-09-15 Thread shm...@riseup.net
hi postfix 2.11.1-1 from debian jessie amd64 this server is using an EC cert not RSA eventually, the email gets sent in the clear any help appreciated openssl on the server reports ok: OpenSSL 1.0.1i 6 Aug 2014 $ openssl s_client -cipher SSLv3 -starttls smtp -connect igwx10.cba.com.au:25