{"id":6937,"date":"2015-07-21T18:28:16","date_gmt":"2015-07-22T01:28:16","guid":{"rendered":"http:\/\/blog.networkpresence.co\/?p=6937"},"modified":"2015-07-21T18:28:16","modified_gmt":"2015-07-22T01:28:16","slug":"tlsssl-config-updates-to-sendmail-for-recent-openssl-versions","status":"publish","type":"post","link":"http:\/\/blog.networkpresence.co\/?p=6937","title":{"rendered":"TLS\/SSL config updates to Sendmail for recent OpenSSL versions"},"content":{"rendered":"<p>Recent SSL updates to the OpenSSL package have removed old DH parameters which are built into Sendmail mail server software, so the following are configuration updates to Sendmail (sendmail.cf) to enable the use of a longer DH Parameter to TLS\/SSL activity of Sendmail.<\/p>\n<p>First, create a longer DH Parameter file with:<\/p>\n<p><code>openssl dhparam -out \/etc\/pki\/tls\/certs\/dhparams.pem 1024<br \/>\n<\/code><br \/>\nThen configure the use of this dhparams.pem file into sendmail.cf with the following added to the &#8216;Options&#8217; section of your sendmail.cf file:<\/p>\n<p><code>O DHParameters=\/etc\/pki\/tls\/certs\/dhparams.pem<br \/>\n<\/code><br \/>\nAnd then restart sendmail after making that sendmail.cf update.<\/p>\n<p>This should remove TLS\/SSL based email sending errors, which have maillog entries like:<\/p>\n<p><code>STARTTLS=server: 1867:error:14094417:SSL routines:SSL3_READ_BYTES:sslv3 alert illegal parameter:s3_pkt.c:1092:SSL alert number 47<br \/>\n<\/code><\/p>\n<p>FYI,<br \/>\nRichard.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recent SSL updates to the OpenSSL package have removed old DH parameters which are built into Sendmail mail server software, so the following are configuration updates to Sendmail (sendmail.cf) to enable the use of a longer DH Parameter to TLS\/SSL &hellip; <a href=\"http:\/\/blog.networkpresence.co\/?p=6937\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[18,42,84,78],"class_list":["post-6937","post","type-post","status-publish","format-standard","hentry","category-network-presence","tag-linux","tag-sendmail","tag-ssl","tag-sysadmin"],"_links":{"self":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/6937","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6937"}],"version-history":[{"count":1,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/6937\/revisions"}],"predecessor-version":[{"id":6938,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/6937\/revisions\/6938"}],"wp:attachment":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6937"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6937"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6937"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}