主题: Cannot start TLS: handshake failure

==== 必填信息。没有填写将不予回复 ====
- iRedMail 版本号:0.8.7
- 使用哪个数据库存储用户帐号(OpenLDAP,MySQL,PostgreSQL):ldap
- 使用的 Linux/BSD 发行版名称及版本号:
- 与您的问题相关的日志信息:
====
1   Jan 12 16:12:00 mail postfix/smtp[58954]: 3F0883C00FC: Cannot start TLS: handshake failure
        1   Jan 12 09:43:27 mail postfix/smtp[33072]: CB78A3C00C3: Cannot start TLS: handshake failure
        1   Jan 12 17:33:00 mail postfix/smtp[11063]: D71AB3C0090: Cannot start TLS: handshake failure
        1   Jan 12 16:12:30 mail postfix/smtp[58958]: 419F33C00CE: Cannot start TLS: handshake failure
        1   Jan 12 14:15:26 mail postfix/smtp[29352]: 7335B3C0102: Cannot start TLS: handshake failure
        1   Jan 12 16:12:00 mail postfix/smtp[58954]: SSL_connect error to mail.vst.com.hk[175.45.41.61]:25: Connection timed out

回复: Cannot start TLS: handshake failure

反馈问题请帖***完整***的smtp会话的日志,不是仅仅那一句包含错误信息的日志,因为没法帮忙排错。

回复: Cannot start TLS: handshake failure

ZhangHuangbin 写道:

反馈问题请帖***完整***的smtp会话的日志,不是仅仅那一句包含错误信息的日志,因为没法帮忙排错。

Jan 13 13:45:43 mail postfix/smtpd[62669]: 07EA13C00FE: client=mail.test.com[127.0.0.1]
Jan 13 13:45:43 mail postfix/cleanup[62641]: 07EA13C00FE: message-id=<201501131345322965212@test.com>
Jan 13 13:45:43 mail postfix/qmgr[58580]: 07EA13C00FE: from=<szgikf@test.com>, size=292994, nrcpt=1 (queue active)
Jan 13 13:45:43 mail amavis[61630]: (61630-04) Passed CLEAN {RelayedInternal}, MYUSERS LOCAL [218.18.19.209]:39777 [218.18.19.209] <szgikf@test.com> -> <zhanghong@aigo.com>, Queue-ID: 949A23C007C, Message-ID: <201501131345322965212@test.com>, mail_id: SkzWCkvF6y6s, Hits: -, size: 291951, queued_as: 07EA13C00FE, dkim_new=dkim:test.com, 213 ms
Jan 13 13:45:43 mail postfix/smtp[62398]: 949A23C007C: to=<zhanghong@aigo.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=11, delays=10/0/0.01/0.22, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 07EA13C00FE)
Jan 13 13:48:27 mail postfix/smtp[62715]: 07EA13C00FE: Cannot start TLS: handshake failure
Jan 13 13:48:29 mail postfix/smtp[62715]: 07EA13C00FE: to=<zhanghong@aigo.com>, relay=mail.aigo.com[211.94.188.245]:25, delay=167, delays=0.02/0.01/164/2.4, dsn=2.0.0, status=sent (250 ok 1421128102 qp 142112810118349 (eqmail))
Jan 13 13:48:29 mail postfix/qmgr[58580]: 07EA13C00FE: removed

回复: Cannot start TLS: handshake failure

在这个邮件投递阶段出现 tls handshake failure 比较奇怪,你是否修改过 Postfix 和 Amavisd 的配置?

回复: Cannot start TLS: handshake failure

ZhangHuangbin 写道:

在这个邮件投递阶段出现 tls handshake failure 比较奇怪,你是否修改过 Postfix 和 Amavisd 的配置?

只有发给这个客户的邮件才会有这种情况呢。
postfix取消了强制tls验证
smtp_tls_CAfile = $smtpd_tls_CAfile
smtp_tls_loglevel = 0
smtp_tls_note_starttls_offer = yes
smtpd_tls_auth_only = no
#smtpd_end_of_data_restrictions = check_policy_service inet:127.0.0.1:10031
smtpd_tls_security_level = may
smtpd_tls_loglevel = 0
smtpd_tls_key_file = /etc/pki/tls/private/iRedMail.key
smtpd_tls_cert_file = /etc/pki/tls/certs/iRedMail_CA.pem
smtpd_tls_CAfile = /etc/pki/tls/certs/iRedMail_CA.pem
tls_random_source = dev:/dev/urandom
smtpd_data_restrictions = reject_unauth_pipelining
smtpd_reject_unlisted_recipient = yes
smtpd_reject_unlisted_sender = yes

dovecot中修改如下
#ssl = required
ssl = yes

amavisd只是修改了子进程数

回复: Cannot start TLS: handshake failure

还有这种错误
an 16 18:29:15 mail postfix/smtp[23271]: SSL_connect error to mail.vst.com.hk[175.45.41.61]:25: Connection timed out
        1   Jan 16 11:43:21 mail postfix/smtp[60465]: SSL_connect error to mail.vst.com.hk[175.45.41.61]:25: Connection timed out