Так, сертификаты я сгенирировал, вроде бы всё прекрасно.Thunderbird и The Bat! почту через мой сервак с использование сертификатов отправить могут. Догадайтесь, какой MUA не может? - Outlook.
Ниже привожу логи при отсылке каждого клиента:
++++++++++++OUTLOOK++++++++++++++++++++++
==================================
Aug 7 18:23:32 email postfix/smtpd[5144]: warning: hostname localhost does not resolve to address 192.168.0.133
Aug 7 18:23:32 email postfix/smtpd[5144]: connect from unknown[192.168.0.133]
Aug 7 18:24:49 email postfix/smtpd[5144]: SSL_accept error from unknown[192.168.0.133]: lost connection
Aug 7 18:24:49 email postfix/smtpd[5144]: lost connection after CONNECT from unknown[192.168.0.133]
Aug 7 18:24:49 email postfix/smtpd[5144]: disconnect from unknown[192.168.0.133]
==================================
+++++++++++++THUNDERBIRD++++++++++++++++++++
==================================
Aug 7 18:25:39 email postfix/smtpd[5150]: warning: hostname localhost does not resolve to address 192.168.0.133
Aug 7 18:25:39 email postfix/smtpd[5150]: connect from unknown[192.168.0.133]
Aug 7 18:25:39 email postfix/smtpd[5150]: 63F105DF4DF: client=unknown[192.168.0.133], sasl_method=PLAIN, sasl_username=test@mydomain.ru
Aug 7 18:25:39 email postfix/cleanup[5152]: 63F105DF4DF: message-id=<502133C3.1010608@mydomain.ru>
Aug 7 18:25:39 email postfix/qmgr[5142]: 63F105DF4DF: from=<test@mydomain.ru>, size=653, nrcpt=1 (queue active)
Aug 7 18:25:39 email postfix/smtpd[5150]: disconnect from unknown[192.168.0.133]
Aug 7 18:25:53 email postfix/smtp[5153]: 63F105DF4DF: to=<ЛИЧНАЯ_ПОЧТА@mail.ru>, relay=mxs.mail.ru[94.100.176.20]:25, delay=14, delays=0.02/0.02/0.05/14, dsn=2.0.0, status=sent (250 OK id=1Sykj8-0005wG-By)
Aug 7 18:25:53 email postfix/qmgr[5142]: 63F105DF4DF: removed
==================================
++++++++++++THE BAT!++++++++++++++++++++++
Aug 7 18:29:03 email postfix/smtpd[5144]: warning: hostname localhost does not resolve to address 192.168.0.133
Aug 7 18:29:03 email postfix/smtpd[5144]: connect from unknown[192.168.0.133]
Aug 7 18:29:06 email postfix/smtpd[5144]: warning: unknown[192.168.0.133]: SASL CRAM-MD5 authentication failed: authentication failure
Aug 7 18:29:06 email postfix/smtpd[5144]: 7DF7D5DF4DF: client=unknown[192.168.0.133], sasl_method=PLAIN, sasl_username=test@mydomain.ru
Aug 7 18:29:06 email postfix/cleanup[5158]: 7DF7D5DF4DF: message-id=<555897833.20120807183024@mydomain.ru>
Aug 7 18:29:06 email postfix/qmgr[5142]: 7DF7D5DF4DF: from=<test@mydomain.ru>, size=770, nrcpt=1 (queue active)
Aug 7 18:29:06 email postfix/smtp[5159]: error: open database /usr/local/etc/postfix/sasl/sasl_passwd.db: No such file or directory
Aug 7 18:29:06 email postfix/smtpd[5144]: disconnect from unknown[192.168.0.133]
Aug 7 18:29:07 email postfix/smtp[5159]: 7DF7D5DF4DF: to=<ЛИЧНАЯ_ПОЧТА69@mail.ru>, relay=mxs.mail.ru[94.100.176.20]:25, delay=0.7, delays=0.01/0.02/0.05/0.62, dsn=2.0.0, status=sent (250 OK id=1SykmS-0007Ov-Mf)
Aug 7 18:29:07 email postfix/qmgr[5142]: 7DF7D5DF4DF: removed
==================================
Полагаю, что Outlook не хочет принимать сертификат, - что ему не нравится, ума не приложу. Ранее, он еще в лог пихал ошибку:
SSL_accept:before/accept initialization
Решил проверить сертификат:
#openssl s_client -showcerts -cert cert.pem -key key.pem -starttls smtp -CAfile CAcert.cer -connect localhost:25
Получил ответ:
==================================
.............
New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-SHA
Server public key is 1024 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1
Cipher : DHE-RSA-AES256-SHA
Session-ID: 4FD69A64FB99C2FE7F26775FA6F7C9086768A5F00D652B2B2D6482DFB39B327E
Session-ID-ctx:
Master-Key: 153C7674447A114D3475881B155203AC38FB2E0AB18EBA7ADEC8E03B61C1698D28CCCFC059B11EE86D82515F68F32E76
Key-Arg : None
Start Time: 1344350215
Timeout : 300 (sec)
Verify return code: 19 (self signed certificate in certificate chain)
---
250 DSN
==================================
Вопрос: что не нравится аутлуку?