Re: Postfix 3.1 and TLS Cert Files

2016-03-19 Thread Wietse Venema
Tom Browder: > What minimum additional Postfix settings on the remote server do I > need to use that connection so that the remote server can than send > mail to the wild internet? http://www.postfix.org/SASL_README.html#server_sasl_authz Wietse

Re: Postfix 3.1 and TLS Cert Files

2016-03-19 Thread Tom Browder
On Fri, Mar 11, 2016 at 7:04 AM, Tom Browder wrote: > On Wednesday, March 9, 2016, Curtis Villamizar > wrote: >> In message >> > ... >> ps - maybe this will help get you started. > ... Okay, I now have a successful start, but need some advice to get farther: On my local server I can successf

Re: Postfix 3.1 and TLS Cert Files

2016-03-11 Thread Tom Browder
On Wednesday, March 9, 2016, Curtis Villamizar wrote: > > In message > ... > > > You need to instances of smtpd. One on port 587 (MSA) and a mail > > > transfer agent (MTA) on port 25 which is where the MX record point to. ... > What an MSA does is well defined in RFC 6409 "Message Submission f

Re: OT: TLS and SNI (was Re: Postfix 3.1 and TLS Cert Files)

2016-03-09 Thread Curtis Villamizar
In message <56e0ccb4.6010...@spectralmud.org> Richard James Salts writes: > > On 10/03/16 09:32, Curtis Villamizar wrote: > > In message <56dfcd11.5010...@spectralmud.org> > > Richard James Salts writes: > > > >> On 09/03/16 06:44, Viktor Dukhovni wrote: > On Mar 8, 2016, at 2:31 PM, Curtis V

Re: OT: TLS and SNI (was Re: Postfix 3.1 and TLS Cert Files)

2016-03-09 Thread Richard James Salts
On 10/03/16 09:32, Curtis Villamizar wrote: In message <56dfcd11.5010...@spectralmud.org> Richard James Salts writes: On 09/03/16 06:44, Viktor Dukhovni wrote: On Mar 8, 2016, at 2:31 PM, Curtis Villamizar wrote: With HTTP the server cert is provided after HTTP identifies which virtual host

OT: TLS and SNI (was Re: Postfix 3.1 and TLS Cert Files)

2016-03-09 Thread Curtis Villamizar
In message <56dfcd11.5010...@spectralmud.org> Richard James Salts writes: > On 09/03/16 06:44, Viktor Dukhovni wrote: > >> On Mar 8, 2016, at 2:31 PM, Curtis Villamizar > >> wrote: > >> > >> With HTTP the server cert is provided after HTTP identifies which > >> virtual host it thinks its talkin

Re: Postfix 3.1 and TLS Cert Files

2016-03-09 Thread Curtis Villamizar
In message Tom Browder writes: > On Tuesday, March 8, 2016, Curtis Villamizar wrote: > > Tom, > > > > I've been following this thread and also not clear on your > > objectives. See inline. > > As Viktor pointed out, look at the examples. Your home machine is a > > "null client". Your remote

Re: Postfix 3.1 and TLS Cert Files

2016-03-09 Thread Tom Browder
On Tuesday, March 8, 2016, Curtis Villamizar wrote: > Tom, > > I've been following this thread and also not clear on your > objectives. See inline. > As Viktor pointed out, look at the examples. Your home machine is a > "null client". Your remote server is not a "null client" but if set > up th

Re: Postfix 3.1 and TLS Cert Files

2016-03-08 Thread Richard James Salts
On 09/03/16 06:44, Viktor Dukhovni wrote: On Mar 8, 2016, at 2:31 PM, Curtis Villamizar wrote: With HTTP the server cert is provided after HTTP identifies which virtual host it thinks its talking to. The IP address along gives no clue. That connection is then used only for that virtual host

Re: Postfix 3.1 and TLS Cert Files

2016-03-08 Thread Tom Browder
On Tue, Mar 8, 2016 at 1:31 PM, Curtis Villamizar wrote: > Tom, > > I've been following this thread and also not clear on your > objectives. See inline. ... > Fine so far but you haven't said what you expect the postfix MX to do > with received mail. You have a few choices. > > Relay it per dom

Re: Postfix 3.1 and TLS Cert Files

2016-03-08 Thread Viktor Dukhovni
> On Mar 8, 2016, at 2:31 PM, Curtis Villamizar > wrote: > > With HTTP the server cert is provided after HTTP identifies which > virtual host it thinks its talking to. The IP address along gives no > clue. That connection is then used only for that virtual host. This > is why you can have a

Re: Postfix 3.1 and TLS Cert Files

2016-03-08 Thread Curtis Villamizar
Tom, I've been following this thread and also not clear on your objectives. See inline. In message Tom Browder writes: > > On Mon, Mar 7, 2016 at 10:57 PM, Viktor Dukhovni > wrote: > > On Mon, Mar 07, 2016 at 08:30:54PM -0600, Tom Browder wrote: > >> On Mon, Mar 7, 2016 at 5:13 PM, Viktor Duk

Re: Postfix 3.1 and TLS Cert Files

2016-03-08 Thread Tom Browder
On Tuesday, March 8, 2016, Viktor Dukhovni wrote: > On Tue, Mar 08, 2016 at 05:57:41AM -0600, Tom Browder wrote: ... > When working with Postfix, try to forget everything related to > Apache, essentially none of that is relevant to Postfix. Your > "virtual hosts" are just domains. You want an MX

Re: Postfix 3.1 and TLS Cert Files

2016-03-08 Thread Viktor Dukhovni
On Tue, Mar 08, 2016 at 05:57:41AM -0600, Tom Browder wrote: > I clearly was not even thinking about the > several types of virtual hosts. I am running multiple virtual hosts > on a single, real Apache server. I have a fair amount of experience > with TLS and Apache but none with TLS and Postfix

Re: Postfix 3.1 and TLS Cert Files

2016-03-08 Thread Tom Browder
On Mon, Mar 7, 2016 at 10:57 PM, Viktor Dukhovni wrote: > On Mon, Mar 07, 2016 at 08:30:54PM -0600, Tom Browder wrote: >> On Mon, Mar 7, 2016 at 5:13 PM, Viktor Dukhovni >> wrote: >> > On Mon, Mar 07, 2016 at 03:18:11PM -0600, Tom Browder wrote: >> >> I have a server with several vhosts. I am wo

Re: Postfix 3.1 and TLS Cert Files

2016-03-07 Thread Viktor Dukhovni
On Mon, Mar 07, 2016 at 08:30:54PM -0600, Tom Browder wrote: > On Mon, Mar 7, 2016 at 5:13 PM, Viktor Dukhovni > wrote: > > On Mon, Mar 07, 2016 at 03:18:11PM -0600, Tom Browder wrote: > > > >> I have a server with several vhosts. I am working on providing mail > >> services to each with TLS. I

Re: Postfix 3.1 and TLS Cert Files

2016-03-07 Thread Tom Browder
On Mon, Mar 7, 2016 at 5:13 PM, Viktor Dukhovni wrote: > On Mon, Mar 07, 2016 at 03:18:11PM -0600, Tom Browder wrote: > >> I have a server with several vhosts. I am working on providing mail >> services to each with TLS. I have server CA certs and unlocked keys >> for each individual vhost. > >

Re: Postfix 3.1 and TLS Cert Files

2016-03-07 Thread Viktor Dukhovni
On Mon, Mar 07, 2016 at 03:18:11PM -0600, Tom Browder wrote: > I have a server with several vhosts. I am working on providing mail > services to each with TLS. I have server CA certs and unlocked keys > for each individual vhost. When you say "vhost", what do you mean? > Is the right way to ha

Postfix 3.1 and TLS Cert Files

2016-03-07 Thread Tom Browder
I have a server with several vhosts. I am working on providing mail services to each with TLS. I have server CA certs and unlocked keys for each individual vhost. Is the right way to handle that to put ALL the cert and associated files in the "smtpd_tls_CApath" directory and run "c_rehash" on th