Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-14 Thread Leo Unglaub
Hey, On 14/01/2022 09:19, Stuart Henderson wrote: That hostname doesn't match the certificate, it should validate ok for storm-peaks.northrend.azeroth.wow-data.net (I also checked with -servername to send SNI). There's no difference between v4 and v6 for that though. thank you very much for

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-14 Thread Leo Unglaub
Hey, On 14/01/2022 08:31, Crystal Kolipe wrote: Reading the manual page for openssl, specifically the section on s_client would be a very good idea. thank you for the hint. I did not know about this behavour. It does not explain the initial bug, but certenly my testing of it. For the

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-14 Thread Stuart Henderson
On 2022-01-13, Crystal Kolipe wrote: > On Thu, Jan 13, 2022 at 05:25:41PM +, Stuart Henderson wrote: >> On 2022/01/13 18:05, Leo Unglaub wrote: >> > Hey, >> > >> > On 11/01/2022 21:28, Stuart Henderson wrote: >> > > I bet it is MTU related. Try lowering MTU on that interface (you >> > >

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-13 Thread Crystal Kolipe
On Fri, Jan 14, 2022 at 01:17:47AM +0100, Leo Unglaub wrote: > >RCPT TO: RENEGOTIATING > >139809772520832:error:1420410A:SSL routines:SSL_renegotiate:wrong ssl > >version:../ssl/ssl_lib.c:2142: > > Are the last two lines expected behavour? I get then on IPv4 and IPv6. > Someone else beeing so

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-13 Thread Leo Unglaub
Hey, On 1/13/22 19:18, Crystal Kolipe wrote: Well, I can connect to his server using: openssl s_client -starttls smtp -connect mail.unglaub.at:25 The handshake completes and I'm able to issue smtp commands. However smtpd always reports that opportunistic TLS failed, and downgrades to

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-13 Thread Crystal Kolipe
On Thu, Jan 13, 2022 at 05:25:41PM +, Stuart Henderson wrote: > On 2022/01/13 18:05, Leo Unglaub wrote: > > Hey, > > > > On 11/01/2022 21:28, Stuart Henderson wrote: > > > I bet it is MTU related. Try lowering MTU on that interface (you > > > cannot do it separately for IPv4 and IPv6 so it

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-13 Thread Stuart Henderson
On 2022/01/13 18:05, Leo Unglaub wrote: > Hey, > > On 11/01/2022 21:28, Stuart Henderson wrote: > > I bet it is MTU related. Try lowering MTU on that interface (you > > cannot do it separately for IPv4 and IPv6 so it will change both, > > but that's not likely to be a problem) and get someone who

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-13 Thread Leo Unglaub
Hey, On 11/01/2022 21:28, Stuart Henderson wrote: I bet it is MTU related. Try lowering MTU on that interface (you cannot do it separately for IPv4 and IPv6 so it will change both, but that's not likely to be a problem) and get someone who has seen the problems to re-test. thank you so much

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-11 Thread Stuart Henderson
On 2022-01-11, Leo Unglaub wrote: > i am running OpenBSD 7.0 with all patches applied. Some weeks ago i > noticed a very strange issue with my OpenSMTPd instance. People are > unable to use TLS when connecting via IPv6. This is not just my > observation, some people on misc@ told me so as

Re: OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-11 Thread Mike Fischer
Hi Leo, > Am 11.01.2022 um 19:10 schrieb Leo Unglaub : > > Hey friends, > i am running OpenBSD 7.0 with all patches applied. Some weeks ago i noticed a > very strange issue with my OpenSMTPd instance. People are unable to use TLS > when connecting via IPv6. This is not just my observation,

OpenSMTPd: Unable to use TLS/SSL over IPv6

2022-01-11 Thread Leo Unglaub
Hey friends, i am running OpenBSD 7.0 with all patches applied. Some weeks ago i noticed a very strange issue with my OpenSMTPd instance. People are unable to use TLS when connecting via IPv6. This is not just my observation, some people on misc@ told me so as well. I talked to gilles@ in