P.NORMAND schrieb am Mittwoch, den 21. März 2007:

> Package: postfix
> Version: 2.3.8-2
> Severity: critical
> Justification: breaks the whole system

> After the posfix package update this morning (before, all was ok ) :
> It seem that the new libpostfix-tls.so.1 file don't work correctly
> whith ssl .
> 
> I' had to replace it whith the old one to make our secure mailServer
> working again.

Same problem here after upgrading from 2.3.7-3 to 2.3.8-2.
After the upgrade, smtpd doesn't work any longer but writes the
following into logfile:

Mar 21 13:20:35 foo postfix/master[5576]: warning: process 
/usr/lib/postfix/smtpd pid 5597 exit status 127
Mar 21 13:20:35 foo postfix/master[5576]: warning: /usr/lib/postfix/smtpd: bad 
command startup -- throttling
Mar 21 13:21:35 foo postfix/master[5576]: warning: process 
/usr/lib/postfix/smtpd pid 5630 exit status 127
Mar 21 13:21:35 foo postfix/master[5576]: warning: /usr/lib/postfix/smtpd: bad 
command startup -- throttling
Mar 21 13:22:35 foo postfix/master[5576]: warning: process 
/usr/lib/postfix/smtpd pid 5631 exit status 127
Mar 21 13:22:35 foo postfix/master[5576]: warning: /usr/lib/postfix/smtpd: bad 
command startup -- throttling
Mar 21 13:23:35 foo postfix/master[5576]: warning: process 
/usr/lib/postfix/smtpd pid 5635 exit status 127
Mar 21 13:23:35 foo postfix/master[5576]: warning: /usr/lib/postfix/smtpd: bad 
command startup -- throttling
Mar 21 13:24:35 foo postfix/master[5576]: warning: process 
/usr/lib/postfix/smtpd pid 5637 exit status 127
Mar 21 13:24:35 foo postfix/master[5576]: warning: /usr/lib/postfix/smtpd: bad 
command startup -- throttling

Trying to connect the SMTP port, I don't see a greeting and nothing
happens.

Downgrading to 2.3.7-3 works around the problem.


The problematic lines from the main.cf seem to be:

smtpd_tls_cert_file=/etc/ssl/certs/foo.cert.pem
smtpd_tls_key_file=/etc/ssl/private/foo.privkey.pem
smtpd_use_tls=yes
smtpd_tls_session_cache_database = sdbm:/etc/postfix/smtpd_scache

If I comment them out, the greeting works again, but TLS isn't
supported any more.

Tschoeeee

        Roland

Reply via email to