Re: Testing DANE-enabled smtp client

2014-11-15 Thread Tom Hendrikx
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 15-11-14 00:00, Viktor Dukhovni wrote: > On Fri, Nov 14, 2014 at 10:58:08PM +0100, Tom Hendrikx wrote: > >> Nov 14 22:55:56 hostname postfix-out/smtp[11505]: Verified TLS >> connection established to mail.sys4.de[2001:1578:400:111::7]:25: >> TLS

Re: Testing DANE-enabled smtp client

2014-11-14 Thread Viktor Dukhovni
On Fri, Nov 14, 2014 at 10:58:08PM +0100, Tom Hendrikx wrote: > Nov 14 22:55:56 hostname postfix-out/smtp[11505]: Verified TLS > connection established to mail.sys4.de[2001:1578:400:111::7]:25: TLSv1 > with cipher ECDHE-RSA-AES256-SHA (256/256 bits) > Nov 14 22:55:57 hostname postfix-out/smtp[1150

Re: Testing DANE-enabled smtp client

2014-11-14 Thread Tom Hendrikx
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 14-11-14 22:27, Viktor Dukhovni wrote: > On Fri, Nov 14, 2014 at 10:01:02PM +0100, Tom Hendrikx wrote: > >> One notable difference between posttls-finger and postfix (as >> described in the documentation) is that postfix would only use >> the TL

Re: Testing DANE-enabled smtp client

2014-11-14 Thread Viktor Dukhovni
On Fri, Nov 14, 2014 at 10:01:02PM +0100, Tom Hendrikx wrote: > One notable difference between posttls-finger and postfix (as > described in the documentation) is that postfix would only use the > TLSA record for deciding on a "verified" connection when the resolver > is running on localhost, whil

Re: Testing DANE-enabled smtp client

2014-11-14 Thread Wietse Venema
Tom Hendrikx: -- Start of PGP signed section. > Hi, > > I configured my mailserver to use DANE for outbound mail whenever > possible, but I am having a hard time in verifying that this actually > works. > > When I use posttls-finger from the machine, it indicates "Verified TLS > connection establ

Re: Testing DANE-enabled smtp client

2014-11-14 Thread Patrick Ben Koetter
* Tom Hendrikx : > I configured my mailserver to use DANE for outbound mail whenever > possible, but I am having a hard time in verifying that this actually > works. > > When I use posttls-finger from the machine, it indicates "Verified TLS > connection established" when i point to a few mxen that