3 msgServer configuration Error
1 msgrelay_transport
1 msgCatch-all mailbox
4 msgTrouble with HTC S710 device and SMTPS
3 msgpsotfix server TLS failed
3 msgfailed-delivery message notifications setup
2 msgproxy_interfaces understanding
1 msgwarning: transport virtual failure
2 msghow to relay for most recipients and forward fo...
2 msgRewriting outbound addresses
2 msgvirtual mailboxes/domains and aliases
3 msgEnforced TLS Success?
1 msgPostfix 2.5 RC2 and snapshot release

Problem with Postfix and LDAP (SSL / TLS)
\ Artur Muecke (16 Jan 2008)
. \ (Wietse Venema) (16 Jan 2008)
. . \ Artur Muecke (16 Jan 2008)
. . . \ (Wietse Venema) (16 Jan 2008)
. . . \ (Wietse Venema) (16 Jan 2008)
. . . . \ Artur Muecke (17 Jan 2008)
. . . . . \ (Wietse Venema) (17 Jan 2008)
. . . . . . \ Victor Duchovni (17 Jan 2008)
. . . \ Victor Duchovni (16 Jan 2008)
. . . . \ Artur Mücke (16 Jan 2008)
. . . . . \ Victor Duchovni (16 Jan 2008)

4 msgMore on Enforced TLS
3 msgdelivery reciept
4 msgHow to repeat delay_warning_time messages ?
2 msgsender notification
5 msgUsing 'nolisting' to reduce spam
1 msgmail priority by sender
Subject:Re: Problem with Postfix and LDAP (SSL / TLS)
Group:Postfix-users
From:Victor Duchovni
Date:17 Jan 2008


 
On Thu, Jan 17, 2008 at 09:27:09AM -0500, Wietse Venema wrote:

> Artur Muecke:
> > The problem was, that postfix cant access the random files (/dev/[u]random)
> > from the chroot environment.
>
> GNU TLS terminates with exit status 2 when /dev/*random is unavailable.
> This is the widely known problem with GNU TLS that everyone has
> been telling you about. I hope the problem is clear now.
>

For the record, the problem is with the underlying libgcrypt, rather than
the TLS layer. The libgcrypt maintainers steadfastly refuse to accept
that applications may legitimately elect to fall back to unencrypted
communication if encryption is not available or handle the failure in
a more graceful way.

The excuse is that "some" applications will not handle the error
correctly, so exit() or abort() are their view the only options.
I strongly disagree, but there's not much I can do about it.


--
Viktor.

Disclaimer: off-list followups get on-list replies or get ignored.
Please do not ignore the "Reply-To" header.

To unsubscribe from the postfix-users list, visit
http://www.postfix.org/lists.html or click the link below:
<mailto:majordomo?body=unsubscribe%20postfix-users>

If my response solves your problem, the best way to thank me is to not
send an "it worked, thanks" follow-up. If you must respond, please put
"It worked, thanks" in the "Subject" so I can delete these quickly.


© 2004-2008 readlist.com