TLS/SSL config updates to Sendmail for recent OpenSSL versions

Recent SSL updates to the OpenSSL package have removed old DH parameters which are built into Sendmail mail server software, so the following are configuration updates to Sendmail (sendmail.cf) to enable the use of a longer DH Parameter to TLS/SSL activity of Sendmail.

First, create a longer DH Parameter file with:

openssl dhparam -out /etc/pki/tls/certs/dhparams.pem 1024

Then configure the use of this dhparams.pem file into sendmail.cf with the following added to the ‘Options’ section of your sendmail.cf file:

O DHParameters=/etc/pki/tls/certs/dhparams.pem

And then restart sendmail after making that sendmail.cf update.

This should remove TLS/SSL based email sending errors, which have maillog entries like:

STARTTLS=server: 1867:error:14094417:SSL routines:SSL3_READ_BYTES:sslv3 alert illegal parameter:s3_pkt.c:1092:SSL alert number 47

FYI,
Richard.

Posted in Network Presence | Tagged , , , | Comments Off on TLS/SSL config updates to Sendmail for recent OpenSSL versions

Get your own fast cPanel VPS with dual IP Addresse…

Get your own fast cPanel VPS with dual IP Addresses & setup help. networkpresence.com.au/hosting/cpanel…</a#NetPreses

Posted in Tweets | 1 Comment

Minecraft world reconstruction using MayaVi &…

Minecraft world reconstruction using MayaVi & Bukkit mods with SQL. tylerfisher.org/painting-you-a…

Posted in Tweets | Comments Off on Minecraft world reconstruction using MayaVi &…

Startups like Yeloha were forecast in the book “Th…

Startups like Yeloha were forecast in the book “The Zero Marginal Cost Society”. fastcoexist.com/3047758/with-t…</a#IoTo#endstageCapitalismsm

Posted in Tweets | 1 Comment

Box describes how they use the Facebook open-sourc…

Box describes how they use the Facebook open-source HHVM for more performance from their PHP codebase. code.facebook.com/posts/16079076…

Posted in Tweets | Comments Off on Box describes how they use the Facebook open-sourc…

scriptster is a Ruby gem for running Bash scripts…

scriptster is a Ruby gem for running Bash scripts in Ruby programs. radek.io/2015/07/13/rub…

Posted in Tweets | Comments Off on scriptster is a Ruby gem for running Bash scripts…

RT @ozbargain: netpres: Sydney KVM & Xen SSD V…

RT @ozbargain: netpres: Sydney KVM & Xen SSD VPS – 15% off ozb.me/Z9C

Posted in Tweets | Comments Off on RT @ozbargain: netpres: Sydney KVM & Xen SSD V…

All #NetPres VPS customers can get themselves one…

All #NetPres VPS customers can get themselves one of our Free VPN Services at our new Shopfront, see shop.networkpresence.com.au/cart.php?a=con…

Posted in Tweets | Comments Off on All #NetPres VPS customers can get themselves one…

We agree with @superloopnet’s CEO “in Singapore, t…

We agree with @superloopnet‘s CEO “in Singapore, they’ve stopped producing white papers, they’re actually executing” itnews.com.au/News/406631,su…

Posted in Tweets | Comments Off on We agree with @superloopnet’s CEO “in Singapore, t…

Great prices & quick auto-provisioning after y…

Great prices & quick auto-provisioning after your Paypal Subscription’s 1st payment at our new Shopfront. shop.networkpresence.com.au/cart.php #NetPres

Posted in Tweets | Comments Off on Great prices & quick auto-provisioning after y…