Re: [exim] SSL encryption rejected

Top Page
Delete this message
Reply to this message
Author: Heiko Schlittermann
Date:  
To: exim-users
Subject: Re: [exim] SSL encryption rejected
Jorge Listas via Exim-users <exim-users@???> (Mo 16 Sep 2019 22:05:47 CEST):
> days ago my hosting provider has updated exim without notifying me, from
> version 4.87_1 to 4.89
>
> It is installed on a server under CentOS release 5.11 and with openSSL 0.98e
>
> From that moment I have problems sending and receiving emails with SSL
> encryption, so my provider suggested adding
>
> hosts_avoid_tls = *


I would not recommend this, and I believe, Exim should fallback to
Non-TLS anyway, if setting up the encrypted connection does not work.

Are there other TLS related settings in your config?

I'm not sure how recent OpenSSL 0.98e is.

> Despite this modification in the config file, a large number of emails sent
> to my server are rejected with cause:
>
> STARTTLS command rejected


I do not see why Exim should reject STARTTLS. Maybe it would do so, if
the tls_advertise_hosts main config option is empty or doesn't match the
current connection.

Do you have more output from the logs?

    Best regards from Dresden/Germany
    Viele Grüße aus Dresden
    Heiko Schlittermann
--
 SCHLITTERMANN.de ---------------------------- internet & unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -
 ! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -