TLS cert smtp context, type

Discuss installation issues/solutions for Engarde

Moderators: scrumpy, Dave, leihog

TLS cert smtp context, type

Postby ram on Wed Sep 06, 2006 2:17 pm

I have setup smtp with TLS, in permissive mode all works fine, but it just hanges on connect in enforceing. The Problem seems to be the SE permisssions to the cert file which I placed in /etc/postfix/tls. I have tried several different types, roles and context for this file. Should the cert be placed in a different directory and what shoud the user, role and type be set to.
ram
 
Posts: 38
Joined: Thu Aug 17, 2006 12:33 am

RE: TLS cert smtp context, type

Postby eric on Thu Sep 07, 2006 12:43 pm

ram,

This is definitely a policy issue, but without recreating the situation on a test network, it is difficult to fix. It could either be a problem getting to the cert file or it could be an issue binding to the ssmtp port (465).

Can you open up a bug report (http://bugs.engardelinux.org/) and submit all the necessary information for us to reproduce it. Also please include the SELinux policy "permission denied" messages. Thanks.

Eric
eric
Site Admin
 
Posts: 234
Joined: Wed Jun 14, 2006 11:15 am
Location: New Jersey, USA

RE: TLS cert smtp context, type

Postby ram on Thu Sep 07, 2006 2:35 pm

Ok,
Before I open a bug report, I will rebuild this server, its only a test server atm. Just to make sure it wasnt something else I did, and to make it easier for you guys. I am not running it on the smtps port 465, it is still running on the standard smtp port 25 but gives the 250 STARTTLS option on a EHLO. Not sure if that makes any difference.

ram
ram
 
Posts: 38
Joined: Thu Aug 17, 2006 12:33 am

RE: TLS cert smtp context, type

Postby eric on Thu Sep 07, 2006 3:50 pm

ram,

It actually does make a difference. Since SELinux requires policies that allow for access to specific ports, There are no booleans that allow for postfix to bind to any other port besides 25. Therefore by you ensuring that postfix is only listening on port 25, that takes that variable out of the picture.

Eric
eric
Site Admin
 
Posts: 234
Joined: Wed Jun 14, 2006 11:15 am
Location: New Jersey, USA

RE: TLS cert smtp context, type

Postby ram on Fri Sep 08, 2006 1:22 pm

Ok,
I submitted the bug report, the main problem seems to be tlsmgr access to /dev/urandom but there are some other erros in the logs as well. Hope the report is understandable.
ram
 
Posts: 38
Joined: Thu Aug 17, 2006 12:33 am

RE: TLS cert smtp context, type

Postby eric on Mon Sep 11, 2006 12:49 pm

ram,

Thanks for the help. We will look into the issue as soon as possible and work to get it resolved.

Eric
eric
Site Admin
 
Posts: 234
Joined: Wed Jun 14, 2006 11:15 am
Location: New Jersey, USA


Return to Installation

Who is online

Users browsing this forum: No registered users and 2 guests

cron