SSL_accept error / lost connection after STARTTLS

Pegasus

Renowned Member
Aug 29, 2013
61
1
73
California, USA
Hello.

I've been running PMG for awhile (currently on v8.1.8) and it's been working well until about 6 months ago when I can no longer get mail from certain places like LuxSci, PayPal or Synchrony Bank. For any of these, the log shows:
2025-02-26T20:15:34.771123-05:00 smaRTmail1b postfix/postscreen[841]: CONNECT from [162.142.76.156]:57402 to [192.168.88.91]:25
2025-02-26T20:15:34.771225-05:00 smaRTmail1b postfix/postscreen[841]: PASS OLD [162.142.76.156]:57402
2025-02-26T20:15:34.771566-05:00 smaRTmail1b postfix/smtpd[842]: connect from rs6016.luxsci.com[162.142.76.156]
2025-02-26T20:15:44.708300-05:00 smaRTmail1b postfix/smtpd[842]: SSL_accept error from rs6016.luxsci.com[162.142.76.156]: lost connection
2025-02-26T20:15:44.708467-05:00 smaRTmail1b postfix/smtpd[842]: lost connection after STARTTLS from rs6016.luxsci.com[162.142.76.156]
2025-02-26T20:15:44.708533-05:00 smaRTmail1b postfix/smtpd[842]: disconnect from rs6016.luxsci.com[162.142.76.156] ehlo=1 starttls=0/1 co
mmands=1/2

Note that there is a 10-second delay between the connect and SSL_accept error messages. What could be the problem? I am getting TLS mail from Google and many other places just fine. I am using a Let's Encrypt certificate set up inside PMG and it is current.

The last time this happened, simply upgrading PMG helped, but the problem is back again.

CheckTLS.com succeeds while https://luxsci.com/smtp-tls-checker fails with a timeout message.

Thank you for any help you can provide!
 
Last edited:
If it's working with TLS from some domains/mailservers, but timing out from others then maybe the issue is not on PMG, but on some firewall/proxy/... between PMG and the internet that terminates the connections

I hope this helps!
 
This issue seems similar to mine. In our country, some incoming channels pass through Russia. When the upstream provider routed packets through these channels (for example, my country → Russia → America), I observed similar problems. I assume this is related to Deep Packet Inspection during cross-border transmission through Russia.