Koozali.org: home of the SME Server

TLS error

Offline Mouse

  • *
  • 13
  • +0/-0
TLS error
« on: July 11, 2024, 07:40:56 PM »
Hi.

One server can't send e-mail to one state server.
I test my server, and it also can't.
some week ago all works.
Time/date I checked - all ok.

this is what is in logs in both servers:

TLS_connect_failed:_error:14077410:SSL_routines:SSL23_GET_SERVER_HELLO:sslv3_alert_handshake_failure;_connected_to_195.13.215.166./STARTTLS_proto=TLSv1.2;_cipher=(NONE);/
2024-07-11 20:25:09.553116500 delivery 418: deferral:

Please give some advice where to dig.


p.s. When I put email delivery thru internet provider smtp server - all goes out.
« Last Edit: July 11, 2024, 08:03:30 PM by Mouse »

Offline ReetP

  • *
  • 3,931
  • +6/-0
Re: TLS error
« Reply #1 on: July 12, 2024, 04:08:54 AM »
Server version?
Update status?
Debug logs?
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation

Offline Mouse

  • *
  • 13
  • +0/-0
Re: TLS error
« Reply #2 on: July 12, 2024, 10:31:43 AM »
Hi

Version 10.1
all updates on

mails stand in Qmail message queue.

only error is -
2024-07-11 12:49:34.134670500 starting delivery 12463: msg 3222590988 to remote ******@lvm.lv
2024-07-11 12:49:51.667942500 delivery 12463: deferral: TLS_connect_failed:_error:14077410:SSL_routines:SSL23_GET_SERVER_HELLO:sslv3_alert_handshake_failure;_connected_to_195.13.215.166./STARTTLS_proto=TLSv1.2;_cipher=(NONE);/



Offline Jean-Philippe Pialasse

  • *
  • 2,903
  • +11/-0
  • aka Unnilennium
    • http://smeserver.pialasse.com
Re: TLS error
« Reply #3 on: July 14, 2024, 02:33:04 AM »
please give output of

config show modSSL

config show qmail


the message says your server was not able to negociate a cipher with the remote server. 

Offline Mouse

  • *
  • 13
  • +0/-0
Re: TLS error
« Reply #4 on: July 14, 2024, 11:51:34 AM »
[root@server ~]# config show modSSL
modSSL=service
    CertificateChainFile=/home/e-smith/ssl.crt/chain.pem
    TCPPort=443
    access=public
    crt=/home/e-smith/ssl.crt/*******.crt
    key=/home/e-smith/ssl.key/*******.key
    status=enabled

[root@server ~]# config show qmail
qmail=service
    MaxMessageSize=99000000
    status=enabled

Offline Mouse

  • *
  • 13
  • +0/-0
Re: TLS error
« Reply #5 on: July 14, 2024, 12:13:22 PM »
Hi

This error is only sending to one site.
All other works. Also gmail accepts without problems.

They admin says that only from us not working. All other are sending to them without problem.

And this error is at least on 2 SME servers to this site.

SSL certificate is PositiveSSL from Sectigo Limited