Gao writes:

Hi list,

We use SSL cert purchased from GoDaddy and it is time to renew. I installed the new certificates on my mail server (CentOS7+Postfix+Courier). When I check the maillog I see this error:

DecĀ  5 09:13:03 zeta imapd-ssl: couriertls: accept: error:14094416:SSL routines:SSL3_READ_BYTES:sslv3 alert certificate unknown
DecĀ  5 09:13:03 zeta imapd-ssl: Connection, ip=[::ffff:72.143.235.44]

The error happen almost every 15-20 minutes. So far the mail server works fine. We don't have many users and no one has report and problem yet since I load the new cert. I am not sure what cause the error in the maillog. There is no such error before I load the new cert.

If you Google this error message, you will find out that this error occurs when the client sends an optional client certificate and the server rejects it.

Even if you do not require a client certificate for logins, a client can offer its certificate during SSL negotiation.

Not sure why you started seeing this happen when you installed a new server certificate.

Attachment: pgpxQMfHzofrZ.pgp
Description: PGP signature

------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today.http://sdm.link/xeonphi
_______________________________________________
Courier-imap mailing list
Courier-imap@lists.sourceforge.net
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-imap

Reply via email to