[SOLVED] Disabling TLS 1.0 and 1.1

Oct 28, 2013
308
47
93
www.nadaka.de
Hi there,

we are trying to disable TLS 1.0 and 1.1 for our PMG/Postfix. Therefore we put smtpd_tls_mandatory_protocols = >=TLSv1.2 to our /etc/pmg/templates/main.cf.in and commit the change via pmgconfig sync --restart 1.

Then we tested it from another machine with openssl s_client -connect ourpmg.example.com:25 -tls1 -starttls smtp, and unfortunately -tls1 and -tls1_1 still responds with Secure Renegotiation IS supported. Our expectation is that only -tls1_2 works. Did we miss something? Are we testing wrong?

Thanks and greets!
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!