Re: does 'permit_tls_clientcerts' work with self-signed certificates?

2022-10-05 Thread Michael
viktor, thank you for pointing me in the right direction. i started out with smtpd_tls_ask_ccert = yes but was irritated about the 'Untrusted TLS connection', b/c the client established a 'Verified TLS connection' with smtp_tls_security_level = fingerprint smtp_tls_f

Re: does 'permit_tls_clientcerts' work with self-signed certificates?

2022-10-05 Thread Viktor Dukhovni
On Wed, Oct 05, 2022 at 10:08:29AM +0200, Michael wrote: > I started out with > > smtpd_tls_ask_ccert = yes > > but was irritated about the 'Untrusted TLS connection', b/c the client > established a 'Verified TLS connection' with > > smtp_tls_security_level = fingerprint > sm

regulating legitimate mail traffic

2022-10-05 Thread juan smitt
Hi, It's written in the doc that "smtpd_client_connection_count_limit" is about the number of simultaneous connections from a client, but it's also written that "It must not be used to regulate legitimate mail traffic." If this is not the way, then how can one regulate the simultaneous connectio

Re: regulating legitimate mail traffic

2022-10-05 Thread Viktor Dukhovni
On Wed, Oct 05, 2022 at 05:46:39PM +0200, juan smitt wrote: > It's written in the doc that "smtpd_client_connection_count_limit" is > about the number of simultaneous connections from a client, but it's > also written that "It must not be used to regulate legitimate mail > traffic." In other word

Re: no shared cipher revisited

2022-10-05 Thread chakl
> OpenBSD used a 4096 bits one on top of Let's Encrypt, at least May I call this plain BS? Thanks Olaf

Re: regulating legitimate mail traffic

2022-10-05 Thread Wietse Venema
juan smitt: [using smtpd_client_connection_count_limit for traffic management] > Unfortunately the service (which is made of 4 servers) is behind a > firewall which hides the real client IPs so these 4 servers see only 1 > client (the firewall) and the expected mail count is 4+ million per > day.

Re: no shared cipher revisited

2022-10-05 Thread Viktor Dukhovni
On Wed, Oct 05, 2022 at 08:26:26PM +0200, ch...@syscall.de wrote: > > OpenBSD used a 4096 bits one on top of Let's Encrypt, at least > > May I call this plain BS? Thanks This is not a constructive way to disagree. Can you point at some evidence to the contrary, or minimally explain what altern