Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 125921 - http://www.gentoo.org/doc/en/virt-mail-howto.xml does not apply tls to outgoing mail
Summary: http://www.gentoo.org/doc/en/virt-mail-howto.xml does not apply tls to outgoi...
Status: RESOLVED FIXED
Alias: None
Product: [OLD] Docs on www.gentoo.org
Classification: Unclassified
Component: New Documentation (show other bugs)
Hardware: All All
: High trivial (vote)
Assignee: nm (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-03-12 05:01 UTC by Eero Volotinen
Modified: 2006-03-13 11:40 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Eero Volotinen 2006-03-12 05:01:03 UTC
Looks like this guide does not enable outgoing smtp-tls?

following lines need to be added to /etc/postfix/main.cf and
tls (startssl) works outgoing mails too..

# enable postfix to send outgoing mail with tls, if server supports startssl
smtp_use_tls = yes
smtp_tls_enforce_peername = no

If guide enables ssl in to client mail, it should also send outgoing mails with ssl? maybe.
Comment 1 nm (RETIRED) gentoo-dev 2006-03-12 06:29:21 UTC
(In reply to comment #0)
> Looks like this guide does not enable outgoing smtp-tls?

Yes, it does. Please read bug #108317 and re-read the example main.cnf:

(The next two options enable outgoing encryption.)
smtp_tls_note_starttls_offer = yes
smtpd_use_tls = yes

The "smtp_tls_enforce_peername = no" is a much more optional setting that some users might not want to include for security or other reasons.
Comment 2 Jakub Moc (RETIRED) gentoo-dev 2006-03-12 07:44:31 UTC
(In reply to comment #1)
> (The next two options enable outgoing encryption.)
> smtp_tls_note_starttls_offer = yes
> smtpd_use_tls = yes

No, they don't. See http://www.postfix.org/TLS_README.html#client_tls_enable

smtp_use_tls != smtpd_use_tls

- smtp_tls_note_starttls_offer merely makes a note whether the remote server offers STARTTLS or not.

- smtpd_use_tls = yes enables TLS for postfix server side, not client side.
Comment 3 nm (RETIRED) gentoo-dev 2006-03-13 11:40:57 UTC
Fixed in CVS. Thanks for reporting, and thanks to jakub for clearing a few things up.