[問題] Postfix TLS 詭異問題

作者: tomsawyer (安安)   2020-08-24 17:39:41
問題: gsuite 無法把信傳送回自己的主機,gsuite後端則告訴我 TLS error
系統:Debian GNU/Linux 10 (buster) Postfix 3.4.14 Dovecot 2.3.4.1
備注: hostname:relayb.xxx.tw mydestination = $myhostname, $mydomain
註2:從一台正常運行的centos 7的main.cf複製過來的postfix 但是後端換成了
dovecot-lda跟mdbox
詳細log在 https://pastebin.com/5Sc1BSUw
說明:
可以從gmail以比如[email protected] 收到信
也可以用帳密以dovecot-sasl連上postfix:submission(587)/smtp(25)傳信到google,也
顯示有TLS加密
但是在使用smtps(wrapper_mode=yes)則無法連上
在利用gsuite雙重寄信的功能( https://support.google.com/a/answer/9228551 )回傳
給這台postfix時,則顯示TLS失敗
目的為備份[email protected]收到的信(xxx.tw的mx已到gsuite上),且同樣使用centos7備份,
就沒有奇怪的問題
失敗情況:google 傳送 220 2.0.0 Ready to start TLS之後收到smtp_get: EOF 然後就
顯示例如
Aug 24 17:10:51 relayb postfix/smtpd[29497]: Anonymous TLS connection
established from mail-wm1-f70.google.com[209.85.128.70]: TLSv1.3 with cipher
TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature
RSA-PSS (2048 bits) server-digest SHA256
Aug 24 17:10:51 relayb postfix/smtpd[29497]: lost connection after STARTTLS
from mail-wm1-f70.google.com[209.85.128.70]
但是正常若是直接從gmail寄/收 [email protected]的信
Aug 24 17:10:39 relayb postfix/smtpd[29497]: connect from
mail-wm1-f41.google.com[209.85.128.41]
ug 24 17:10:40 relayb postfix/smtpd[29497]: Anonymous TLS connection
established from mail-wm1-f41.google.com[209.85.128.41]: TLSv1.3 with cipher
TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature
RSA-PSS (2048 bits) server-digest SHA256
Aug 24 17:10:40 relayb postfix/smtpd[29497]: C614AA1187:
client=mail-wm1-f41.google.com[209.85.128.41]
Aug 24 17:10:40 relayb postfix/cleanup[29503]: C614AA1187:
message-id=<[email protected]>
Aug 24 17:10:40 relayb postfix/qmgr[29488]: C614AA1187:
from=<[email protected]>, size=2556, nrcpt=1 (queue active)
Aug 24 17:10:40 relayb postfix/local[29504]: C614AA1187:
to=<[email protected]>, relay=local, delay=0.08, delays=0.01/0.01/0/0.06,
dsn=2.0.0, status=sent (delivered to command: /usr/lib/dovecot/dovecot-lda -d
"$USER" -f "$SENDER" -a "$RECIPIENT")
作者: bitlife (BIT一生)   2020-08-25 11:43:00
雖然我沒用過,但用你那個lost connection...那段去google,有人有同樣問題,自己找到答案: MTA_STS policy was toblame. 祝好運

Links booklink

Contact Us: admin [ a t ] ucptt.com