Re: tlsproxy: TLS handshake failed for service=smtp

2021-03-29 Thread Tomas Habarta
On Mon, Mar 29, 2021 at 04:06:51PM -0400, Viktor Dukhovni wrote: > > On Mar 29, 2021, at 3:45 PM, Tomas Habarta wrote: > > > > 6663]: recvmsg(128, {msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\0", > > iov_len=1}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_CTRUNC}, 0) = 1 > > [7141]: re

Re: tlsproxy: TLS handshake failed for service=smtp

2021-03-29 Thread Viktor Dukhovni
> On Mar 29, 2021, at 3:45 PM, Tomas Habarta wrote: > > 6663]: recvmsg(128, {msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\0", > iov_len=1}], msg_iovlen=1, msg_controllen=0, msg_flags=MSG_CTRUNC}, 0) = 1 > [7141]: recvmsg(128, {msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\0", > iov_l

Re: tlsproxy: TLS handshake failed for service=smtp

2021-03-29 Thread Tomas Habarta
On Mon, Mar 29, 2021 at 01:22:38PM -0400, Wietse Venema wrote: > Tomas Habarta: > > Hello, > > > > I would like to ask about the following encountered during selinux testing: > > * currently running 3.5.8 self-compiled (no vendor packaging), centos8 > > (selinux disabled) > > * target platform ce

Re: tlsproxy: TLS handshake failed for service=smtp

2021-03-29 Thread Wietse Venema
Tomas Habarta: > Hello, > > I would like to ask about the following encountered during selinux testing: > * currently running 3.5.8 self-compiled (no vendor packaging), centos8 > (selinux disabled) > * target platform centos8 (same configuration but selinux enabled) Best bet is to strace the tls

Re: tlsproxy: TLS handshake failed for service=smtp

2021-03-29 Thread Viktor Dukhovni
On Mon, Mar 29, 2021 at 06:36:10PM +0200, Tomas Habarta wrote: > selinux enabled: > transaction fails with: > > tlsproxy[23256]: warning: tlsp_get_fd_event: receive remote SMTP peer file > descriptor: Success > tlsproxy[23256]: TLS handshake failed for service=smtp peer=[10.25.41.35]:25 > tlspro