Re: Multi-domain certificates and TLS

2010-08-24 Thread Victor Duchovni
On Tue, Aug 24, 2010 at 05:35:42PM -0400, Alex wrote: > > mail.messaging.microsoft.com[65.55.88.22]:25: Matched > > subject_CN=*.messaging.microsoft.com, issuer_CN=Cybertrust SureServer > > Standard Validation CA > ... > > What is your TLS policy for this destination? The wildcard Subject Alt Na

Re: Multi-domain certificates and TLS

2010-08-24 Thread Alex
Hi, > When the Subject Alternative Name extension is present in a server > certificate, Postfix will use the first domain listed in that extension > as the verified peer name, unless one of the other domains satisfies > the matching rules for the destination TLS policy. > >> Aug  6 09:44:20 smtp01

Re: Multi-domain certificates and TLS

2010-08-23 Thread Victor Duchovni
On Fri, Aug 20, 2010 at 10:30:48PM -0400, Alex wrote: > I posted a message a few days ago, and still haven't been able to > figure this out. I believe this is a result of the certificate having > multiple DNS names and my TLS configuration not properly supporting > that. Could that be the case? W

Re: Multi-domain certificates and TLS

2010-08-21 Thread Wietse Venema
Alex: > Aug 6 09:44:20 smtp01 postfix/smtp[24772]: setting up TLS connection > to mail.messaging.microsoft.com > Aug 6 09:44:20 smtp01 postfix/smtp[24772]: Peer verification: > CommonName in certificate does not match: > mail.global.frontbridge.com != mail.messaging.microsoft.com The certificate

Multi-domain certificates and TLS

2010-08-20 Thread Alex
Hi, I posted a message a few days ago, and still haven't been able to figure this out. I believe this is a result of the certificate having multiple DNS names and my TLS configuration not properly supporting that. Could that be the case? Aug 6 09:44:20 smtp01 postfix/smtp[24772]: setting up TLS