TLS Negotiation
-
We're doing business with a firm in the Czech Republic. When sending an email, and the negotiation for TLS happens, I see this in the logs:
Tue 2026-01-06 10:59:54.017: 05: Waiting for protocol to start...
Tue 2026-01-06 10:59:54.152: 02: <-- 220 mail.company.cz ESMTP MTA
Tue 2026-01-06 10:59:54.154: 03: --> EHLO mail.ourcompany.com
Tue 2026-01-06 10:59:54.297: 02: <-- 250-abcd.company.local
Tue 2026-01-06 10:59:54.297: 02: <-- 250-PIPELINING
Tue 2026-01-06 10:59:54.297: 02: <-- 250-SIZE 20971520
Tue 2026-01-06 10:59:54.297: 02: <-- 250-STARTTLS
Tue 2026-01-06 10:59:54.297: 02: <-- 250-ENHANCEDSTATUSCODES
Tue 2026-01-06 10:59:54.297: 02: <-- 250 8BITMIME
Tue 2026-01-06 10:59:54.297: 03: --> STARTTLS
Tue 2026-01-06 10:59:54.443: 02: <-- 220 2.0.0 Ready to start TLS
Tue 2026-01-06 10:59:54.736: 01: SSL negotiation successful (TLS 1.2, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384)
Tue 2026-01-06 10:59:54.739: 01: SSL certificate is not valid (not signed by recognized CA)
Tue 2026-01-06 10:59:54.739: 03: --> EHLO mail.ourcompany.com
Tue 2026-01-06 10:59:54.883: 02: <-- 250-abcd.company.local
Tue 2026-01-06 10:59:54.883: 02: <-- 250-PIPELINING
Tue 2026-01-06 10:59:54.883: 02: <-- 250-SIZE 20971520
Tue 2026-01-06 10:59:54.883: 02: <-- 250-ENHANCEDSTATUSCODES
Tue 2026-01-06 10:59:54.883: 02: <-- 250 8BITMIMESo, my question is, is TLS still being used, even though MDaemon doesn't recognize the CA? Or is it dropping encryption entirely? How can I discover what the issue is, or rectify it?
Thanks,
Dave
-
-