Re: IBM SMTP Sever SSL CA Issue

Brad Stone <[email protected]> Thu, 16 Jul 2026 12:46:59 -0500
Newsgroups gmane.comp.hardware.ibm.midrange
Message-ID <CAAGV8OdkQC=PUDPP6u-feQU15F3AAOZC+a4JDR-QUyAy9+=v6w@mail.gmail.com>
I think I figured it out.  For some reason they had 5 different CAs
assigned to the SMTP client application in DCM.  I removed all but the 2
really needed and things seem to be flowing again.

That's so weird.  I never assign CAs to a client application... they also
have a certificate assigned to it for some reason too.  *shrug*

On Thu, Jul 16, 2026 at 12:19 PM Brad Stone <[email protected]> wrote:

> I am helping a customer with an email issue.  They are using the SPOOLMAIL
> and apparently the emails are sent with the IBM SMTP server.
>
> when I use WRKSMTPEMM I see the emails as non deliverable.  I see in the
> log this error:
>
> Secure socket init failed:6000(Certificate is not signed by a trusted
> certificate authority.)
>
> I used openssl to get the certificate of the server and imported the
> chain.  I stopped and restarted SMTP server and tried to resend.  Got the
> same error.
>
> I also tried using MAILTOOL and turned on settings to not ignore "not
> trusted" errors and have no issue there at all.  It's not complaining at
> all.  It's using GSK APIs.. not sure what IBM is using.
>
> any ideas?
>
> Bradley V. Stone
> www.bvstools.com
> Native IBM i e-Mail solutions for Microsoft Office 365, Gmail, or any
> Cloud Provider!
>
-- 
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: [email protected]
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: [email protected]
Before posting, please take a moment to review the archives
at https://archive.midrange.com/midrange-l.

Please contact [email protected] for any subscription related questions.