> On Nov 27, 2017, at 12:24 PM, Jeremy Harris <jgh@???> wrote:
>
> b)
> Fire up wireshark, grab from the interface corresponding to the expected
> inbound, filtering by that IP (for either src or dest).
Definitely warrants a PCAP capture. Can Exim do [more] verbose logging
based on the peer's IP address? In this case possibly including decrypted
SMTP traffic?
> Wait until a retry has appeared, then stop the capture. Have a look at
> the tail end of the conversation; possibly the sequence there may
> help. No certainty.
It could be tricky. Seems like a GnuTLS issue, possibly related to:
https://groups.google.com/forum/#!topic/linux.debian.bugs.dist/foTr_BYgXRA
--
Viktor.