How to disable TLS 1.0 & TLS 1.1

fte

New Member
Jan 16, 2023
3
0
1
Hi @ALL,
can anybody explain me please, how to disable TLS 1.0 & TLS 1.1 for inbound Mails?
It's PMG v7.2
THX a lot
Frank
 
Last edited:
Isn't tls1/1.1 disabled anyway? Because PVE7.2 is based on Deb11 and it's openssl.conf has set
Code:
MinProtocol = TLSv1.2

Hmm, it looks, postfix doesn't honor openssl configuration.
Code:
SOMEHOST:~$ openssl s_client -connect PMG:25 -tls1
CONNECTED(00000003)
140408873498256:error:1408F10B:SSL routines:SSL3_GET_RECORD:wrong version number:s3_pkt.c:348:
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 5 bytes and written 7 bytes
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
SSL-Session:
    Protocol  : TLSv1
    Cipher    : 0000
    Session-ID: 
    Session-ID-ctx: 
    Master-Key: 
    Key-Arg   : None
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1674658928
    Timeout   : 7200 (sec)
    Verify return code: 0 (ok)
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!