Page 1 of 1

AMS - TLS Recive Question

PostPosted: Wed Dec 19, 2007 12:55 am
by KrisC
Hi, ive been running the mail server for about 2 weeks now and most mail is coming through, but one of our clients is having trouble sending to use. Here's the message
"When we did we received a TLS reject handshake message: Dec 7 08:09:22 as2 sendmail[13187]: ruleset=tls_server, arg1=SOFTWARE, relay=mail.meta.com, reject=403 4.7.0 TLS handshake failed."

So is this mail server have TLS receiving capabilities, if so how do i go about turning this on.

Thanks
Kris

Re: AMS - TLS Recive Question

PostPosted: Wed Dec 19, 2007 12:30 pm
by rob
The mail server does indeed have support for TLS, and this can be enabled by firstly ensuring you have a certifcate created in the software (SSL Certificates section in the settings). Then on each service you want to enable SSL/TLS, you can enable the appropiate option. I should note that some clients actually use normally SSL inplace of TLS. In this case, each service as an additional option to use SSL 2/3 with TLS requests. I would recommend trying this option if you cannot get the TLS to work correctly.

Re: AMS - TLS Recive Question

PostPosted: Wed Dec 19, 2007 4:54 pm
by KrisC
Thanks for the info, I did that for the clients but the message i got was from another server admin, saying that his server is trying to send messages tls, but is failing to do so. Does AMS support sever to server TLS?

Thanks
Kris

Re: AMS - TLS Recive Question

PostPosted: Thu Dec 20, 2007 11:18 am
by rob
Any other mail server should act exactly the same as a client, and so shouldn't make any difference whether its a server or a client attempting to start TLS, its both the same protocol. Of course there are options to use SSL and so perhaps if you disable TLS, there is still the optino of secure connections via SSL mode. I should note that generally issues with SSL.

Re: AMS - TLS Recive Question

PostPosted: Thu Dec 20, 2007 6:37 pm
by KrisC
Thanks so much for the info! We got the issue worked around, i ended up checking the "Use SSL Version 2/3 mode with TLS" under the smtp services menu.