Re: warning TLS 1.2 postfix 2.11

2014-03-26 Thread Robert Schetterer
Am 26.03.2014 16:25, schrieb Viktor Dukhovni: > On Wed, Mar 26, 2014 at 10:58:12AM +0100, Robert Schetterer wrote: > >> Hi, on ubuntu lucid >> openssl is 0.9x >> >> with self compiled postfix 2.11 > > This combination of ancient OpenSSL and bleeding edge Postfix is > suboptimal from a TLS perspec

Re: warning TLS 1.2 postfix 2.11

2014-03-26 Thread Viktor Dukhovni
On Wed, Mar 26, 2014 at 10:58:12AM +0100, Robert Schetterer wrote: > Hi, on ubuntu lucid > openssl is 0.9x > > with self compiled postfix 2.11 This combination of ancient OpenSSL and bleeding edge Postfix is suboptimal from a TLS perspective. Most of the newer features in Postfix TLS support re

Re: warning TLS 1.2 postfix 2.11

2014-03-26 Thread Robert Schetterer
Am 26.03.2014 13:22, schrieb Andreas Schulze: > > Robert Schetterer: > >> warning: TLS library problem: error:1409442E:SSL >> routines:SSL3_READ_BYTES:tlsv1 alert protocol version:s3_pkt.c:1099:SSL >> alert number 70: > > your smtpd do not support TLS1.1/1.2 so you cannot disable it's usage. >

Re: warning TLS 1.2 postfix 2.11

2014-03-26 Thread Andreas Schulze
Robert Schetterer: warning: TLS library problem: error:1409442E:SSL routines:SSL3_READ_BYTES:tlsv1 alert protocol version:s3_pkt.c:1099:SSL alert number 70: your smtpd do not support TLS1.1/1.2 so you cannot disable it's usage. But you cannot avoid other smtp clients trying to speek to you t

warning TLS 1.2 postfix 2.11

2014-03-26 Thread Robert Schetterer
Hi, on ubuntu lucid openssl is 0.9x with self compiled postfix 2.11 and smtpd tls log level 1 a warning apear like warning: TLS library problem: error:1409442E:SSL routines:SSL3_READ_BYTES:tlsv1 alert protocol version:s3_pkt.c:1099:SSL alert number 70: with i.e test openssl s_client -connect