Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-28 Thread Viktor Dukhovni
On Mon, Oct 28, 2013 at 04:17:13PM +, Viktor Dukhovni wrote: > > What else info I need to supply, to figure out what is wrong? > > tls_policy: > # opportunistic, season to taste > trialtolatvia.lv may exclude=3DES:aNULL > > main.cf: > indexed = ${default_database_ty

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-28 Thread Viktor Dukhovni
On Mon, Oct 28, 2013 at 05:54:51PM +0200, KSB wrote: > Hello! > Have the similar problem: It is exactly the same problem, with exactly the same solution. > Oct 22 17:12:12 awtech postfix/smtp[17586]: warning: TLS library > problem: 17586:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong > versio

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-28 Thread KSB
Hello! Have the similar problem: Oct 22 17:12:12 awtech postfix/smtp[17586]: warning: TLS library problem: 17586:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number:s3_pkt.c:337: Oct 22 17:12:12 awtech postfix/smtp[17586]: 034C0B14237: lost connection with mail.trialtolatvia.lv[109

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-16 Thread Viktor Dukhovni
On Wed, Oct 16, 2013 at 10:29:21AM +0200, Michael B?ker wrote: > > Add "exclude=3DES" to the entry table for this server, and you'll likely > > be fine. You probably don't need to tweak the protocols. > > Adding "exclude=3DES" or "exclude=DES-CBC3-SHA" to the smtp_tls_policy_maps > file didn't

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-16 Thread DTNX Postmaster
On Oct 16, 2013, at 10:29, Michael Büker wrote: > Now, everything works. Phew. > > I might still combine the sender_dependent_default_transport_maps with my > sender_dependent_relayhost_maps so I don't have to maintain both files. Come > to > think of it: Couldn't I combine the single line in

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-16 Thread Michael Büker
On Wed 16.10.13 10:29:21 Michael Büker wrote: > I might still combine the sender_dependent_default_transport_maps with my > sender_dependent_relayhost_maps so I don't have to maintain both files. Come > to think of it: Couldn't I combine the single line in smtp_tls_policy_maps > into the transpor

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-16 Thread Michael Büker
On Tue 15.10.13 15:18:06 Viktor Dukhovni wrote: > The server in question is a Microsoft Exchange server with buggy 3DES > ciphersuites (IIRC found in Windows XP, and perhaps Windows Server 2003). > > Add "exclude=3DES" to the entry table for this server, and you'll likely > be fine. You probably

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-15 Thread DTNX Postmaster
On Oct 15, 2013, at 17:18, Viktor Dukhovni wrote: > On Tue, Oct 15, 2013 at 12:21:28PM +0200, Michael B?ker wrote: > >>> Oct 15 02:30:04 asterix postfix/smtp[4458]: warning: TLS library problem: >>> 4458:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version >>> number:s3_pkt.c:337: >>> >>>

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-15 Thread Viktor Dukhovni
On Tue, Oct 15, 2013 at 12:21:28PM +0200, Michael B?ker wrote: > > Oct 15 02:30:04 asterix postfix/smtp[4458]: warning: TLS library problem: > > 4458:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version > > number:s3_pkt.c:337: > > > > Oct 15 02:30:04 asterix postfix/smtp[4458]: 42E021A0F44:

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-15 Thread Michael Büker
On Tue 15.10.13 01:48:57 Viktor Dukhovni wrote: > Obfuscating the target domain and IP address makes it much harder > to help you. At the very least you MUST obfuscate using a 1-to-1 > function, so that each distinct domain or IP address is mapped to > a distinct obfuscated value. I see the probl

Re: TLS library problem - SSL routines:SSL3_GET_RECORD - wrong version number

2013-10-14 Thread Viktor Dukhovni
On Tue, Oct 15, 2013 at 03:20:13AM +0200, Michael B?ker wrote: > > postfix/smtp[9689]: warning: TLS library problem: 9689:error:1408F10B:SSL > > routines:SSL3_GET_RECORD:wrong version number:s3_pkt.c:337: > > postfix/smtp[9689]: 033661A108A: to=, > > relay=server[X.X.X.X]:587, delay=0.51, delays