On Fri, Aug 07, 2026 at 04:17:46PM +0000, Claus Assmann via Postfix-users wrote:

> Let's Encrypt certs are now useless as client certs, right?
>             X509v3 Extended Key Usage: 
>                 TLS Web Server Authentication

Though, for the record, as I know Claus is well aware, Postfix has
an optional work-around to accept these from clients.

    https://www.postfix.org/postconf.5.html#tls_trust_server_ccerts

so if Postfix is on the receiving end, one might still attempt to use
these, though almost always something selfsigned, known the receiving
end by fingerprint, is far more useful.

-- 
    Viktor.  🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to