Results 1 to 2 of 2

Thread: Server-to-server TLS howto?

  1. #1
    Join Date
    Sep 2008
    Rep Power

    Default Server-to-server TLS howto?


    I've got my Zimbra 5 server running on Ubuntu 6.06, and it works like a charm. I've got TLS enabled for all the desktop clients, mail comes in and goes out, no problem. Everything works.

    And, of course, now I want to change that.

    I want to enable TLS between my Zimbra server and other mail servers on the internet - basically, when it relays mail, I want it to make a TLS connection rather than a standard unencrypted one, either to everyone who has TLS enabled (with failover to nonencrypted if the recipient server rejects the TLS handshake) or at least setting it to always and only use TLS to a specific list of domains, while using non-TLS for the internet at large.

    Anyone got a link to a howto on setting this up, or some tips on where to get started?

  2. #2
    Join Date
    Sep 2008
    Rep Power



    Using zmlocalconfig to increase the SMTPD TLS logging level just logs clients who handshake with the server, it doesn't log the server's handshakes with other servers.

    I added
    POSTCONF smtp_use_tls yes
    to and restarted. I now get certificate errors logged when I connect to machines with bad certificates, but I can't confirm that I'm getting a proper TLS connection to machines that *have* good certificates, and I don't exactly have a second mail server that I can watch the logs on, on the recipient side. Does anyone think that might get my job done?

Similar Threads

  1. How to: cold standby server (no cluster)
    By fisch09 in forum Installation
    Replies: 50
    Last Post: 02-18-2014, 09:51 AM
  2. Zimbra fails after working for 2 weeks
    By Linsys in forum Administrators
    Replies: 10
    Last Post: 10-07-2008, 12:42 AM
  3. Error loading on Mac OS X 10.4.10 server PPC
    By qprcanada in forum Installation
    Replies: 7
    Last Post: 10-26-2007, 06:25 AM
  4. [SOLVED] Server migration/move for OS steps I used
    By newmember in forum Migration
    Replies: 0
    Last Post: 09-06-2007, 10:57 PM
  5. 5.0 Beta Test Server Install - Sanity Check
    By soxfan in forum Installation
    Replies: 3
    Last Post: 06-07-2007, 10:53 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts