Re: Client cert based relaying setup not working

2020-03-11 Thread Adam Cecile
On 3/11/20 3:59 PM, Viktor Dukhovni wrote: On Wed, Mar 11, 2020 at 10:46:03AM -0400, Wietse Venema wrote: I think Postfix doc could be improved, mentioning "smtpd_tls_ask_ccert" here http://www.postfix.org/postconf.5.html#permit_tls_clientcerts would have been helpful. Feel free to post a patc

Re: Client cert based relaying setup not working

2020-03-11 Thread Viktor Dukhovni
On Wed, Mar 11, 2020 at 10:46:03AM -0400, Wietse Venema wrote: > > > I think Postfix doc could be improved, mentioning "smtpd_tls_ask_ccert" > > > here http://www.postfix.org/postconf.5.html#permit_tls_clientcerts would > > > have been helpful. > > > > Feel free to post a patch. The relevant s

Re: Client cert based relaying setup not working

2020-03-11 Thread Wietse Venema
Viktor Dukhovni: > > I think Postfix doc could be improved, mentioning "smtpd_tls_ask_ccert" > > here http://www.postfix.org/postconf.5.html#permit_tls_clientcerts would > > have been helpful. > > Feel free to post a patch. The relevant source file is > "proto/postconf.proto", from which both t

Re: Client cert based relaying setup not working

2020-03-11 Thread Viktor Dukhovni
On Wed, Mar 11, 2020 at 10:49:32AM +0100, Adam Cecile wrote: > On 3/10/20 10:33 PM, Viktor Dukhovni wrote: > > On Tue, Mar 10, 2020 at 03:33:44PM +0100, Adam Cecile wrote: > > > >> submission inet  n   -   y   -   -   smtpd > >>     -o syslog_name=postfix/submission > >>   

Re: Client cert based relaying setup not working

2020-03-11 Thread Adam Cecile
On 3/10/20 10:33 PM, Viktor Dukhovni wrote: On Tue, Mar 10, 2020 at 03:33:44PM +0100, Adam Cecile wrote: submission inet  n   -   y   -   -   smtpd     -o syslog_name=postfix/submission     -o smtpd_tls_security_level=encrypt     -o smtpd_sasl_auth_enable=yes -

Re: Client cert based relaying setup not working

2020-03-10 Thread Viktor Dukhovni
On Tue, Mar 10, 2020 at 03:33:44PM +0100, Adam Cecile wrote: > submission inet  n   -   y   -   -   smtpd >     -o syslog_name=postfix/submission >     -o smtpd_tls_security_level=encrypt >     -o smtpd_sasl_auth_enable=yes > -o smtpd_tls_fingerprint_digest=sha1 >    

Client cert based relaying setup not working

2020-03-10 Thread Adam Cecile
Hello, Here is my submission definition on *server* master.cf: submission inet  n   -   y   -   -   smtpd     -o syslog_name=postfix/submission     -o smtpd_tls_security_level=encrypt     -o smtpd_sasl_auth_enable=yes #    -o smtpd_tls_fingerprint_digest=sha1 #    -o relay_c