{"id":8923,"date":"2018-09-20T19:17:41","date_gmt":"2018-09-21T02:17:41","guid":{"rendered":"http:\/\/blog.networkpresence.co\/?p=8923"},"modified":"2018-09-20T19:17:41","modified_gmt":"2018-09-21T02:17:41","slug":"tuning-cpanel-tls-for-smtp-incoming-email-reception","status":"publish","type":"post","link":"http:\/\/blog.networkpresence.co\/?p=8923","title":{"rendered":"Tuning cPanel TLS for SMTP incoming email reception"},"content":{"rendered":"<p>Newer versions of the WHM\/cPanel software often has default SSL\/TLS settings in its Exim based mail server that will reject connections from some Internet hosts on the standard SMTP port (port 25) with an error like:<\/p>\n<p>TLS error on connection from &#8230; (SSL_accept): error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol<\/p>\n<p>If this is happening, you can &#8220;dial down&#8221; the default SSL\/TLS settings of cPanel&#8217;s Exim mail server through logging into your WHM site as its &#8216;root&#8217; user, going to WHM -> Service configuration -> Exim Configuration Manager page and in the Find: field type &#8220;ssl&#8221;.<br \/>\nYou&#8217;ll then see some items in the Security section of this configuration and you should set the following:<\/p>\n<p>Allow weak SSL\/TLS ciphers = On<\/p>\n<p>Require clients to connect with SSL or issue the STARTTLS command before they are allowed to authenticate with the server = Off<\/p>\n<p>Options for OpenSSL = +no_sslv2 +no_sslv3<\/p>\n<p>And then Save those updates.<\/p>\n<p>This returns cPanel&#8217;s Exim mail server to older settings more compatible with much of the Internet&#8217;s email traffic.<\/p>\n<p>FYI,<br \/>\nRichard.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Newer versions of the WHM\/cPanel software often has default SSL\/TLS settings in its Exim based mail server that will reject connections from some Internet hosts on the standard SMTP port (port 25) with an error like: TLS error on connection &hellip; <a href=\"http:\/\/blog.networkpresence.co\/?p=8923\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,70],"tags":[82,9],"class_list":["post-8923","post","type-post","status-publish","format-standard","hentry","category-network-presence","category-sales","tag-cpanel","tag-vps"],"_links":{"self":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/8923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8923"}],"version-history":[{"count":1,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/8923\/revisions"}],"predecessor-version":[{"id":8924,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=\/wp\/v2\/posts\/8923\/revisions\/8924"}],"wp:attachment":[{"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8923"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.networkpresence.co\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}