August 19, 2019 08:48AM
Hello list,

We've setup a nginx reverse smtp proxy to load balance incoming access to our mailservers.
Everything is fine... until

Some remote sites have broken tls setups and can't deliver mails anymore. Some didn't accept Let's Encrypt as CA for instance.
Now I'm searching a way to not provide STARTTLS to them.
The AUTH Methode is to late here because it will be started after "rcpto to:".
Is there way to call an "Auth Script" after Client-Helo and decide whether dto send STARTTLS Option or not?

I know i can do some redirect with the firewall but i would like to add some logic to the desition to provide STARTTLS or not.

Tnx for reading .
/ramber
Subject Author Posted

SMTP Proxy - STARTTLS offer on per IP base

ramber August 19, 2019 08:48AM

Re: SMTP Proxy - STARTTLS offer on per IP base

Maxim Dounin August 20, 2019 05:54AM

Re: SMTP Proxy - STARTTLS offer on per IP base

ramber August 21, 2019 06:30AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 210
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready