LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 02-20-2017, 10:15 AM   #1
timsoft
Member
 
Registered: Oct 2004
Location: scotland
Distribution: slackware 15.0 64bit, 14.2 64 and 32bit and arm, ubuntu and rasbian
Posts: 495

Rep: Reputation: 144Reputation: 144
Question starttls stopped working on sendmail


I have a server running slackware 13.1 with sendmail and dovecot, which has been happy for 5 years or so. incoming emails (receiving) which get sent to dovecot are coming in just fine, but for some strange reason, starttls is no longer being advertised by sendmail, so outgoing (sending) emails are being blocked.
running
Code:
telnet localhost 25
ehlo localhost
quit
shows that 250-STARTTLS is not in the list shown, which it used to be. I have updated ssl certificates (self certified ca and cert) as the previous self cert's had expired in 2015 (dovecot uses it's own ones in a different place, also self certified) and as that is the only thing that is changed, that is my suspect, but I'm not sure how to check if that is why sendmail is not advertising STARTTLS anymore. any tips or pointers would be appreciated. I can post sendmail.cf or config.mc or other config files if it would help.
 
Old 02-20-2017, 08:25 PM   #2
dijetlo
Senior Member
 
Registered: Jan 2009
Location: RHELtopia....
Distribution: Solaris 11.2/Slackware/RHEL/
Posts: 1,491
Blog Entries: 2

Rep: Reputation: Disabled
If the issue is a bad cert and the resulting failed connect attempts that should be in the log files.
Running grep -i 'TTLS' across every log file I can find (/var/log/[maillog|dmesg|secure|dovecot|sendmail] at the very least) is often the best place to start with mystery issues. I'd tell you to regen your certs and restart your mail server but I think you've probably already done that...
 
1 members found this post helpful.
Old 02-21-2017, 03:07 AM   #3
timsoft
Member
 
Registered: Oct 2004
Location: scotland
Distribution: slackware 15.0 64bit, 14.2 64 and 32bit and arm, ubuntu and rasbian
Posts: 495

Original Poster
Rep: Reputation: 144Reputation: 144
thank you dijetlo. that was a life saver. the problem turned out to be very simple. I needed to change the permissions of /etc/mail/smtp.key.pem to 600 and then, low and behold, everything worked. With having a busy server as far as incoming mail into the log and not knowing what to look for, I was getting desperate.

the error message that the grep of /var/log/messages (you suggested) showed was
blah bla blah:STARTTLS=server: file /etc/mail/certs/smtp.key.pem unsafe: Group readable file
 
Old 02-21-2017, 07:04 AM   #4
dijetlo
Senior Member
 
Registered: Jan 2009
Location: RHELtopia....
Distribution: Solaris 11.2/Slackware/RHEL/
Posts: 1,491
Blog Entries: 2

Rep: Reputation: Disabled
Hey Tim,
OUTSTANDING!
Suggestion: File that away in your "Administrative Tools" mental directory, I've used that trick more times than I can count and it almost always gives you some direction as to what the actual problem is.
Be good
 
  


Reply

Tags
sendmail, slackware



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Sendmail STARTTLS error bitfuzzy Linux - Server 2 11-21-2016 04:46 AM
starttls & sendmail doubt fortez Linux - Server 1 03-10-2011 09:51 AM
sendmail stopped working telerover Red Hat 4 02-14-2007 03:41 PM
sendmail stopped working Alf829 Linux - Networking 2 07-29-2003 09:12 AM
Sendmail STARTTLS Manuel-H Linux - General 0 04-11-2003 08:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 08:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration