Re: PATCH #2: connection_reuse

2020-08-19 Thread Thorsten Habich
On 8/14/2020 8:22 PM, Viktor Dukhovni wrote: > On Fri, Aug 14, 2020 at 02:30:03PM +0300, Thorsten Habich wrote: > >> the certificate verification with TA file option still occasionally fails: > How is the use of a TA file relevant here? It only happens with the domains configur

Re: PATCH #3 (Postfix 3.4 + 3.5): TLS connection_reuse with "tafile"

2020-08-22 Thread Thorsten Habich
On 8/22/2020 7:02 AM, Viktor Dukhovni wrote: > On Fri, Aug 21, 2020 at 05:38:42PM -0400, Wietse Venema wrote: > >> thorsten.hab...@findichgut.net: >>> Any chance to backport the patch to 3.4/3.5? >> This is more change than is allowed in a stable release. Postfix >> 3.6 drops support for OpenSSL

Re: PATCH #2: connection_reuse

2020-08-20 Thread Thorsten Habich
On 8/20/2020 2:38 PM, Wietse Venema wrote: > Thorsten Habich: >> On 8/19/2020 4:31 PM, Viktor Dukhovni wrote: >>> Do *resumed* sessions always fail to validate? Or is that intermittent? >> As far as I could see resumed sessions that failed keep failing > That's not

Re: PATCH #2: connection_reuse

2020-08-20 Thread Thorsten Habich
On 8/20/2020 2:38 PM, Wietse Venema wrote: > Thorsten Habich: >> On 8/19/2020 4:31 PM, Viktor Dukhovni wrote: >>> Do *resumed* sessions always fail to validate? Or is that intermittent? >> As far as I could see resumed sessions that failed keep failing > That's not

Re: PATCH #2: connection_reuse

2020-08-20 Thread Thorsten Habich
On 8/19/2020 4:31 PM, Viktor Dukhovni wrote: > > Do *resumed* sessions always fail to validate? Or is that intermittent? As far as I could see resumed sessions that failed keep failing (probably until the session cache expires) but I had to restart the Postfix most times before that happened.

connection_reuse

2020-06-17 Thread Thorsten Habich
Hello, unfortunatelly I ran into a but when trying to use the connection_reuse parameter in a TLS policy maps file. Attached you can find a patch, to get this option running. Kind regards Thorsten P.S.: I think smtp_tls_connection_reuse=yes in combination with tafile is broken. ---

Re: PATCH: connection_reuse

2020-06-20 Thread Thorsten Habich
On 6/19/2020 7:33 PM, Wietse Venema wrote: > Thorsten Habich: >> This happens with tafile option in tls policy map or >> smtp_tls_trust_anchor_file set in main.cf and smtp_tls_connection_reuse >> = yes >> >> 2020-06-18T09:20:41.644109+02:00 servername pos

Re: connection_reuse

2020-06-18 Thread Thorsten Habich
On 6/17/2020 6:37 PM, Wietse Venema wrote: > If you could share some logging or other symptoms that would speed > up the resolution. > > Wietse This happens with tafile option in tls policy map or smtp_tls_trust_anchor_file set in main.cf and smtp_tls_connection_reuse = yes

Re: PATCH #2: connection_reuse

2020-08-14 Thread Thorsten Habich
validation problems but mails are being delivered on the next attempt. We are now using Postfix 3.5.4 on our side. Any further information I can provide on this? Kind regards Thorsten On 6/22/2020 4:44 PM, Wietse Venema wrote: > Thorsten Habich: >> On 6/20/2020 10:15 PM, Wietse Venema wrote:

Re: PATCH #2: connection_reuse

2020-08-14 Thread Thorsten Habich
validation problems but mails are being delivered on the next attempt. We are now using Postfix 3.5.4 on our side. Any further information I can provide on this? Kind regards Thorsten On 6/22/2020 4:44 PM, Wietse Venema wrote: > Thorsten Habich: >> On 6/20/2020 10:15 PM, Wietse Venema wrote: