Community Discussions and Support
SSL Configuration question

[quote user="Reece"]The connection to the Mercury server from the main (relay) server is also SSL, so that all outgoing mail is over an SSL connection in the first instance. If the receiving server doesn't accept SSL then I want to send it via the relay server, not Mercury.[/quote]

The only way to guarantee a SSL/TLS connection from your server is to send everything through a suitable relay server.  Although, as Thomas says, what you gain by this strategy is unclear.

<P>[quote user="Reece"]The connection to the Mercury server from the main (relay) server is also SSL, so that all outgoing mail is over an SSL connection in the first instance. If the receiving server doesn't accept SSL then I want to send it via the relay server, not Mercury.[/quote]</P> <P>The only way to guarantee a SSL/TLS connection from your server is to send everything through a suitable relay server.  Although, as Thomas says, what you gain by this strategy is unclear.</P>

I am trying to set up Mercury so that it delivers direct to the mail recipient using SSL if it is available (at the recipients end) and if not, to deliver via another (relay) server.

I can't seem to find a way to do this. Am I asking for too much or am I just stupid?

 

Cheers,

Reece

<P>I am trying to set up Mercury so that it delivers direct to the mail recipient using SSL if it is available (at the recipients end) and if not, to deliver via another (relay) server.</P> <P>I can't seem to find a way to do this. Am I asking for too much or am I just stupid?</P> <P mce_keep="true"> </P> <P>Cheers,</P> <P>Reece</P>

Not sure what you are asking.  Are you wanting to guarantee SSL type transmissions all the way to the end user?  If you do, that's not possible.  For example, if a receiving node does not do SSL then yuor passing it to a relay host via SSL to deliver to this same node does nothing since it will have to deliver without SSL.  I might be missing what you are looking for though.

 

<p>Not sure what you are asking.  Are you wanting to guarantee SSL type transmissions all the way to the end user?  If you do, that's not possible.  For example, if a receiving node does not do SSL then yuor passing it to a relay host via SSL to deliver to this same node does nothing since it will have to deliver without SSL.  I might be missing what you are looking for though. </p><p> </p>

Hi Thomas,

Sorry for not being clear.

I want to guarantee SSL type transmissions from this machine. If it can't be to the end recipient then is gets relayed (using SSL) to my main server.

 

Reece

<P>Hi Thomas,</P> <P>Sorry for not being clear.</P> <P>I want to guarantee SSL type transmissions from this machine. If it can't be to the end recipient then is gets relayed (using SSL) to my main server.</P> <P mce_keep="true"> </P> <P>Reece</P>

[quote user="Reece"]

Hi Thomas,

Sorry for not being clear.

I want to guarantee SSL type transmissions from this machine. If it can't be to the end recipient then is gets relayed (using SSL) to my main server.

Reece

[/quote]

 

But what does this gain when the main server is going to connect to this server using a non-SSL connection to deliver the mail since the receiving system does not do SSL.  Unless I'm missing something either your server or the relay host will deliver the mail to the non-SSL server via a normal unencrypted connection.

 

[quote user="Reece"]<p>Hi Thomas,</p> <p>Sorry for not being clear.</p> <p>I want to guarantee SSL type transmissions from this machine. If it can't be to the end recipient then is gets relayed (using SSL) to my main server.</p> <p>Reece</p><p>[/quote]</p><p> </p><p>But what does this gain when the main server is going to connect to this server using a non-SSL connection to deliver the mail since the receiving system does not do SSL.  Unless I'm missing something either your server or the relay host will deliver the mail to the non-SSL server via a normal unencrypted connection. </p><p> </p>

[quote user="Thomas R. Stephenson"][quote user="Reece"]

Hi Thomas,

Sorry for not being clear.

I want to guarantee SSL type transmissions from this machine. If it can't be to the end recipient then is gets relayed (using SSL) to my main server.

Reece

[/quote]

 

But what does this gain when the main server is going to connect to this server using a non-SSL connection to deliver the mail since the receiving system does not do SSL.  Unless I'm missing something either your server or the relay host will deliver the mail to the non-SSL server via a normal unencrypted connection.

 

[/quote]

The connection to the Mercury server from the main (relay) server is also SSL, so that all outgoing mail is over an SSL connection in the first instance. If the receiving server doesn't accept SSL then I want to send it via the relay server, not Mercury.

[quote user="Thomas R. Stephenson"][quote user="Reece"] <P>Hi Thomas,</P> <P>Sorry for not being clear.</P> <P>I want to guarantee SSL type transmissions from this machine. If it can't be to the end recipient then is gets relayed (using SSL) to my main server.</P> <P>Reece</P> <P>[/quote]</P> <P mce_keep="true"> </P> <P>But what does this gain when the main server is going to connect to this server using a non-SSL connection to deliver the mail since the receiving system does not do SSL.  Unless I'm missing something either your server or the relay host will deliver the mail to the non-SSL server via a normal unencrypted connection. </P> <P mce_keep="true"> </P> <P>[/quote] </P> <P>The connection to the Mercury server from the main (relay) server is also SSL, so that all outgoing mail is over an SSL connection in the first instance. If the receiving server doesn't accept SSL then I want to send it via the relay server, not Mercury.</P>
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft