Community Discussions and Support
Using STARTTLS for SMTP submissions

Thanks Paul, I'll just avoid using the laptop with Thunderbird on anything but the home network until 4.80 is available. From other posts it looks like I could use stunnel but I have enough to do at the moment without learning new software!


<p>Thanks Paul, I'll just avoid using the laptop with Thunderbird on anything but the home network until 4.80 is available. From other posts it looks like I could use stunnel but I have enough to do at the moment without learning new software!</p><p> </p>

I'm trying to set up encryption for mail sent from my clients to my MercuryS SMTP server. I've understood from other posts (and I find the same) that SSL/TLS doesn't work for MercuryS, but that STARTTLS does.

I enabled SSL/TLS on both normal and alternate ports in MercuryS.  I can send mail using STARTTLS from a Nokia e71 phone, and and Android tablet, but if I try to send from Thunderbird it times out immediately and I get an error logged in Mercury:

  Error -32 activating SSL session (locus 0, type 0, code 0, 'Invalid TLS extension list item header'

Background detail; I am using AUTH, with a common password for all clients and a certificate generated by Mercury. There's no problem using Thunderbird with no encryption, so I don't think there's any problem with this, and on all three clients the only thing I've changed is use of STARTTLS.

I found a thread here where this error was occurring when gmail was sending mail to MercuryS but the solution is a workaround for gmail rather than a fix. I needed to apply this, now I've enabled SSL, but I couldn't find the settings in gmail - it also looks like a poor solution as mail direct from other gmail users would still fail. I've now disabled SSL/TLS on the normal port (25) so that incoming mail is unaffected and left it on the alternate (587) since that's what I use to submit outgoing mail through.

My main reason for wanting encryption is to avoid exposing my AUTH password when using shared networks such as hotel wifi - for which the main clients will be phone or tablet; Thunderbird is mostly used on my local network, so it's not too serious (I think?) if I can't encrypt it, it just limits the choice of mobile clients.

Thanks for any advice!

 


<p>I'm trying to set up encryption for mail sent from my clients to my MercuryS SMTP server. I've understood from other posts (and I find the same) that SSL/TLS doesn't work for MercuryS, but that STARTTLS does.</p><p>I enabled SSL/TLS on both normal and alternate ports in MercuryS.  I can send mail using STARTTLS from a Nokia e71 phone, and and Android tablet, but if I try to send from Thunderbird it times out immediately and I get an error logged in Mercury: </p><blockquote><p>  Error -32 activating SSL session (locus 0, type 0, code 0, 'Invalid TLS extension list item header'</p></blockquote><p>Background detail; I am using AUTH, with a common password for all clients and a certificate generated by Mercury. There's no problem using Thunderbird with no encryption, so I don't think there's any problem with this, and on all three clients the only thing I've changed is use of STARTTLS.</p><p>I found a thread <a href="/forums/thread/35553.aspx" mce_href="/forums/thread/35553.aspx">here</a> where this error was occurring when gmail was sending mail to MercuryS but the solution is a workaround for gmail rather than a fix. I needed to apply this, now I've enabled SSL, but I couldn't find the settings in gmail - it also looks like a poor solution as mail direct from other gmail users would still fail. I've now disabled SSL/TLS on the normal port (25) so that incoming mail is unaffected and left it on the alternate (587) since that's what I use to submit outgoing mail through. </p><p>My main reason for wanting encryption is to avoid exposing my AUTH password when using shared networks such as hotel wifi - for which the main clients will be phone or tablet; Thunderbird is mostly used on my local network, so it's not too serious (I think?) if I can't encrypt it, it just limits the choice of mobile clients.</p><p>Thanks for any advice! </p><p> </p><p> </p>

There is a fundamental problem using some clients with Mercury's older SSL libraries (both StartTLS and direct SSL).  A new version with modern (OpenSSL) libraries will be released which deals with these issues.

For Thunderbird on your local network, enter your local IP addresses as 'allow' and that will prevent the need for authorisation.

<P>There is a fundamental problem using some clients with Mercury's older SSL libraries (both StartTLS and direct SSL).  A new version with modern (OpenSSL) libraries will be released which deals with these issues.</P> <P>For Thunderbird on your local network, enter your local IP addresses as 'allow' and that will prevent the need for authorisation.</P>
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft