Re: DANE issue with postfix 3.4.0-RC2

2019-02-17 Thread Viktor Dukhovni
On Sun, Feb 17, 2019 at 10:31:05PM +0100, A. Schulze wrote: > ok, so I start silent testing ... > > https://andreasschulze.de/tmp/reuse_on.txt > https://andreasschulze.de/tmp/reuse_off.txt Thanks, these get us much closer to the source of the problem. Something about the way the way that chain v

Re: DANE issue with postfix 3.4.0-RC2

2019-02-17 Thread Wietse Venema
Wietse Venema: > A. Schulze: > > https://andreasschulze.de/tmp/reuse_on.txt > > https://andreasschulze.de/tmp/reuse_off.txt > > These deliver to different server IP addresses, therefore the > results may differ. One is: Feb 17 22:11:53 mail postfix/smtp[23428]: sys1.mmini.de[2a01:4f8:162:32ac:

Re: DANE issue with postfix 3.4.0-RC2

2019-02-17 Thread A. Schulze
Am 17.02.19 um 22:40 schrieb Wietse Venema: > A. Schulze: >> https://andreasschulze.de/tmp/reuse_on.txt >> https://andreasschulze.de/tmp/reuse_off.txt > > These deliver to different server IP addresses, therefore the > results may differ. the destination MX has IPv4 and IPv6 working. Depends

Re: DANE issue with postfix 3.4.0-RC2

2019-02-17 Thread Wietse Venema
A. Schulze: > https://andreasschulze.de/tmp/reuse_on.txt > https://andreasschulze.de/tmp/reuse_off.txt These deliver to different server IP addresses, therefore the results may differ. Wietse

Re: DANE issue with postfix 3.4.0-RC2

2019-02-17 Thread A. Schulze
Am 17.02.19 um 21:24 schrieb Viktor Dukhovni: Hello Viktor, > If you performed a "reload" to get that to take effect, that would > also have flushed the TLS session cache. And perhaps disabling > connection re-use is a distraction. It may well have been sufficient > to just "postfix reload".

Re: DANE issue with postfix 3.4.0-RC2

2019-02-17 Thread Viktor Dukhovni
On Sun, Feb 17, 2019 at 02:41:27PM +0100, A. Schulze wrote: > I updated to postfix 3.4.0-RC2 and enabled "smtp_tls_connection_reuse" Now > I notice delivery problems to "gervers.com". The DNS configuration for this domain is: gervers.com. IN MX 10 sys1.mmini.de. ; NoError AD=1 sys1.mmini

Re: DANE issue with postfix 3.4.0-RC2

2019-02-17 Thread Wietse Venema
A. Schulze: > Hello, > > I updated to postfix 3.4.0-RC2 and enabled "smtp_tls_connection_reuse" > Now I notice delivery problems to "gervers.com". DANE setup looks OK. > https://dane.sys4.de/smtp/gervers.com > > "posttls-finger gervers.com" also show > posttls-finger: Verified TLS connection est