From owner-freebsd-questions@FreeBSD.ORG Sun May 3 16:13:28 2015 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 534C0A22 for ; Sun, 3 May 2015 16:13:28 +0000 (UTC) Received: from smtp.infracaninophile.co.uk (smtp6.infracaninophile.co.uk [IPv6:2001:8b0:151:1:3cd3:cd67:fafa:3d78]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "smtp.infracaninophile.co.uk", Issuer "ca.infracaninophile.co.uk" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id D54711CD5 for ; Sun, 3 May 2015 16:13:27 +0000 (UTC) Received: from liminal.local ([192.168.100.5]) (authenticated bits=0) by smtp.infracaninophile.co.uk (8.15.1/8.15.1) with ESMTPSA id t43GDKDi001796 (version=TLSv1.2 cipher=DHE-RSA-AES128-SHA bits=128 verify=NO) for ; Sun, 3 May 2015 17:13:21 +0100 (BST) (envelope-from matthew@FreeBSD.org) Authentication-Results: smtp.infracaninophile.co.uk; dmarc=none header.from=FreeBSD.org DKIM-Filter: OpenDKIM Filter v2.9.2 smtp.infracaninophile.co.uk t43GDKDi001796 Authentication-Results: smtp.infracaninophile.co.uk/t43GDKDi001796; dkim=none reason="no signature"; dkim-adsp=none; dkim-atps=neutral X-Authentication-Warning: lucid-nonsense.infracaninophile.co.uk: Host [192.168.100.5] claimed to be liminal.local Message-ID: <55464916.9030305@FreeBSD.org> Date: Sun, 03 May 2015 17:13:10 +0100 From: Matthew Seaman User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.6.0 MIME-Version: 1.0 To: freebsd-questions@freebsd.org Subject: Re: postfix with TLS References: <5546444B.2060002@gmail.com> In-Reply-To: <5546444B.2060002@gmail.com> Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="XPWBbSXnnEX1IPECnLPDPCfsIdmqd7dK0" X-Virus-Scanned: clamav-milter 0.98.6 at lucid-nonsense.infracaninophile.co.uk X-Virus-Status: Clean X-Spam-Status: No, score=-2.9 required=5.0 tests=ALL_TRUSTED,AWL,BAYES_00 autolearn=ham autolearn_force=no version=3.4.0 X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on lucid-nonsense.infracaninophile.co.uk X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 03 May 2015 16:13:28 -0000 This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --XPWBbSXnnEX1IPECnLPDPCfsIdmqd7dK0 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: quoted-printable On 03/05/2015 16:52, Ernie Luzar wrote: > pkg info postfix shows the TLS is enabled by default. > I know what TLS is, but I don't know what this means to postfix. >=20 > Does this mean that postfix has all the internal security library's > compiled in and > can function right out of the box as a email server communicating using= > TLS? Yes. This gives you the option that, subject to setting various configuration flags and supplying SSL keys and certs, in any SMTP dialogue, as a receiver postfix will offer 'STARTTLS' as an available command, and as a sender it will invoke STARTTLS when the other side offers it. So all your e-mail should be encrypted over the wire. I'm not entirely sure why this is even considered optional in this day and age... Cheers, Matthew --XPWBbSXnnEX1IPECnLPDPCfsIdmqd7dK0 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.20 (Darwin) iQJ8BAEBCgBmBQJVRkkdXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ2NTNBNjhCOTEzQTRFNkNGM0UxRTEzMjZC QjIzQUY1MThFMUE0MDEzAAoJELsjr1GOGkATI1MP/0hhD3P4bG6sEQKsriCMGKUs RSq70bS9PzYR7YCH6Wi47mRs4bRbhj3DDkge91iGaTUEmjOq1TMywSxxS88UjENc rksknFktocR9zKriE3v7USo/dATyM7PlfgxwR8yUiMraO/urfyk0ZM1zaV8yG7OD 7VAEmAGizTmhqm4Kd0XYLAuj1vRqTiY4H/nc5Hnrv70frmIDD+3cG7444QrnJqgj 4X0sNPqSpDN6orXDHKk4BoqNHfTivNCNbmXHyrbAY3K5/m8RKMlJvOe7liHDTGuf mqqhfHeMoyeSwcc/Np3zZyG7Msi8zyDlsSlUaGa2b+a41no7imUE4yFC2w7Vg1nz xePk9rzoPLbfH59FbPICnErnntwShoPgDL3kmcKmTbrNuFX8jgTClMKOdUvC20fh V3gzzbhHQ+EYF8/n43Vq+ZFt9LLmyjA4VuYxGpH0aLqCm4x1kyC/XQihi86FFkGG 4rZhVFrpG/GnhGiMe0sjPGTfGiWCiZBJaXr3ONknni5waTxp+jMxW15Tj3Q8UvJN Hds33Wpf9idpwMRpfsXAmtqzE+Oh7wmLQm3AZvRiRIJea3e7fQQXz4rkgBykTDzY Bc347p2i/mnPlS8Ul/wMRU1VsdUwMWCzsNzHytihvY1l4jtxhvunwPBCRc21xy9J AHBOmmGTFB+A9wciNFRo =oQ8Y -----END PGP SIGNATURE----- --XPWBbSXnnEX1IPECnLPDPCfsIdmqd7dK0--