Skip to content

Document how to fully disable outgoing TLS policy checks - #974

Open
dragoangel wants to merge 1 commit into
mailcow:masterfrom
dragoangel:add-info-about-disabling-tlspol
Open

Document how to fully disable outgoing TLS policy checks#974
dragoangel wants to merge 1 commit into
mailcow:masterfrom
dragoangel:add-info-about-disabling-tlspol

Conversation

@dragoangel

Copy link
Copy Markdown
Contributor

The TLS-Policy override guide only explained how to change the policy for a single destination. Where a firewall with SMTP inspection or an intercepting relay removes STARTTLS from the EHLO response, no per-domain entry helps and mail piles up in the queue.

Add a section to the English and German guide describing the extra.cf overrides that drop the postfix-tlspol socketmap and fall back to opportunistic TLS, including the scope of the change and the security implications.

The TLS-Policy override guide only explained how to change the policy
for a single destination. Where a firewall with SMTP inspection or an
intercepting relay removes STARTTLS from the EHLO response, no
per-domain entry helps and mail piles up in the queue.

Add a section to the English and German guide describing the extra.cf
overrides that drop the postfix-tlspol socketmap and fall back to
opportunistic TLS, including the scope of the change and the security
implications.

Signed-off-by: Dmytro Alieksieiev <1865999+dragoangel@users.noreply.github.com>
@dragoangel

Copy link
Copy Markdown
Contributor Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant