- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Server TLS issue
Hi,
i am unable to recieve an email from specific domain, upon troubleshooitng i found the following error :
STARTTLS=server, error: accept failed=-1, reason=unknown, SSL_error=5, errno=104, retry=-1, relay=somedomain.com [1.1.1.1]
is it could be because of TLS profile or do i have increase the cipher level ?
am unable to understand the error message here .
FCSNP 5, JNCIS-FW,JNCIA-SSL ,MCSE, ITIL.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have a TLS profile for sending?
Are you enable for TLS for receiving ?
But yes if you are some one is trying to use TLS and the system are not compatible, the MTA will fallback or even deny mail as determine the policy ( required or preferred )
Ken
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi am not using TLS profile for sending and didnt enable it for receiving , do i have to for both ?
FCSNP 5, JNCIS-FW,JNCIA-SSL ,MCSE, ITIL.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes you need delivery rule to use TLS outbound. Typically you write it as *.somdomain.com and set the TLS and method.
Download the fortimail cli and administration guide for your version of FML and follow the guidelines. Keep in mind that NOT all MX support TLS or even have it enable.
Ken
PCNSE
NSE
StrongSwan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i think i found the issue, am using on my fortimail the following cipher : TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
but when i checked the the ciphers used by the other domain am having an issue with i found that none of the matching the one am using, would this be an issue for connection error am getting .
FCSNP 5, JNCIS-FW,JNCIA-SSL ,MCSE, ITIL.