Qmail-remote TLS

Discussion in 'Help Desk' started by clouedin, Mar 29, 2018.

  1. clouedin

    clouedin New Email

    Joined:
    Mar 29, 2018
    Messages:
    4
    Likes Received:
    0
    Hi all,

    I've got a problem with the use of X.509 certificate with qmail-remote.

    I created /var/qmail/control/tlsdestinations file which contains only "*:"
    I created /var/qmail/control/servercert.pem file which contains my X.509 certificat, but each time my server try to use STARTTTLS to send mail I have this error in my qmail logs :

    deferral: Can't_load_X.509_certificate:_servercert.pem?._(#4.4.1)/

    Can anyboby help me to find what is wrong ?
     


  2. popowich

    popowich EQ Forum Admin Staff Member

    Joined:
    Aug 12, 2008
    Messages:
    9,262
    Likes Received:
    139
    Which directions did you follow to set this up? Do the necessary qmail processed have the proper dir and file permissions?
     

  3. clouedin

    clouedin New Email

    Joined:
    Mar 29, 2018
    Messages:
    4
    Likes Received:
    0
    Thank you for your reply.

    I followed this : Setting up an SMTP service

    and put the file permissions it told :
    -rw-r----- 1 root qmail 5758 29 mars 08:03 clientcert.pem
    -rw-r----- 1 root nofiles 5758 29 mars 08:03 servercert.pem
     
  4. clouedin

    clouedin New Email

    Joined:
    Mar 29, 2018
    Messages:
    4
    Likes Received:
    0
    Any Idea ?
     
  5. popowich

    popowich EQ Forum Admin Staff Member

    Joined:
    Aug 12, 2008
    Messages:
    9,262
    Likes Received:
    139
    Does your qmaild user (or the user listed in your run file) have access all the way through to read /var/qmail/control/servercert.pem ?
     
  6. clouedin

    clouedin New Email

    Joined:
    Mar 29, 2018
    Messages:
    4
    Likes Received:
    0
    I finally found where the probelm was : in my domaincert file, I didn't put the fully qualified path to severcert.pem (/var/qmail/control/servercert.pem).
    It works fine now.
    Thank you!
     

Want to reply or ask your own question?

It only takes a minute to sign up (and it's free!). Click the orange sign up button to choose a username and then you can ask your own questions on the forum.
Loading...