Re: TLS untrusted/trusted

2012-01-11 Thread Dennis Guhl
On Wed, Jan 11, 2012 at 06:14:35PM +, Viktor Dukhovni wrote: > On Wed, Jan 11, 2012 at 07:08:30PM +0100, Dennis Guhl wrote: > > On Wed, Jan 11, 2012 at 04:15:17PM +0100, Stefan wrote: > > > Hello list, > > > > > mail.example.com[aaa.bbb.ccc.ddd]:25: TLSv1 with cipher > > > ADH-CAMELLIA256-S

Re: TLS untrusted/trusted

2012-01-11 Thread Viktor Dukhovni
On Wed, Jan 11, 2012 at 07:08:30PM +0100, Dennis Guhl wrote: > On Wed, Jan 11, 2012 at 04:15:17PM +0100, Stefan wrote: > > Hello list, > > > mail.example.com[aaa.bbb.ccc.ddd]:25: TLSv1 with cipher ADH-CAMELLIA256-SHA > > This is an anonymous cipher. With > > smtpd_tls_mandatory_exclude

Re: TLS untrusted/trusted

2012-01-11 Thread Viktor Dukhovni
On Wed, Jan 11, 2012 at 04:15:17PM +0100, Stefan wrote: > I've set up clientside TLS with postfix 2.7.1 as follows: > > smtp_tls_CApath = /etc/ssl/certs > smtp_tls_loglevel = 1 > smtp_tls_security_level = may For all destinations, except any listed in policy_maps at a security level of "verify

Re: TLS untrusted/trusted

2012-01-11 Thread Dennis Guhl
On Wed, Jan 11, 2012 at 04:15:17PM +0100, Stefan wrote: > Hello list, > mail.example.com[aaa.bbb.ccc.ddd]:25: TLSv1 with cipher ADH-CAMELLIA256-SHA This is an anonymous cipher. With smtpd_tls_mandatory_exclude_ciphers = aNULL or smtpd_tls_exclude_ciphers = aNULL you can di

TLS untrusted/trusted

2012-01-11 Thread Stefan
Hello list, I've set up clientside TLS with postfix 2.7.1 as follows: smtp_tls_CApath = /etc/ssl/certs smtp_tls_loglevel = 1 smtp_tls_security_level = may smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache smtp_tls_policy_maps = hash:/etc/postfix/tls_policy /etc/postfix/