Re: [exim] SSL SMTP

Top Page
Delete this message
Reply to this message
Author: Tony Finch
Date:  
To: Ron McKeating
CC: Exim-Users \(E-mail\)
Subject: Re: [exim] SSL SMTP
On Fri, 3 Dec 2004, Ron McKeating wrote:
>
> Tony thanks for this it explains quite a lot. So in our case having
>
> daemon_smtp_ports = 25 : 465 : 587
> tls_on_connect_ports = 465
>
> in the config file is erroneous and should be changed to
>
> daemon_smtp_ports = 25 : 587
> tls_on_connect_ports = 465


No, the former is correct. tls_on_connect_ports must be a subset of
daemon_smtp_ports.

> Our problem comes in advising outlook users, some user of outlook where
> the client reports as "Microsoft Office Outlook", work fine on port 465
> but give the "protocol violation: synchronization error (input sent
> without waiting for greeting)" if they try to use port 587.


That is expected. Outlook will only do tls-on-connect if the port is not
25, so it must be configured to use port 465.

> Other versions of Outlook where the client reports as "Microsoft
> Outlook" work fine on port 587 but do not work on port 465.


I wasn't aware that these exist.

> It would seem we are going to have to advise Outlook users to try one
> port or the other.


If you do that, it's best to advise people to try port 587 first, in order
to avoid the timeout problem which is particularly irritating for the
user.

Tony.
--
f.a.n.finch <dot@???> http://dotat.at/
MALIN HEBRIDES: NORTHEAST 4 OR 5 INCREASING 6. RAIN LATER. GOOD BECOMING
MODERATE.