Re: disable tls1.3 for a specific destination domain
Athanasius via Exim-users <[email protected]> Thu, 25 Jun 2026 15:47:01 +0100
| Newsgroups | gmane.mail.exim.user |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Jun 25, 2026 at 03:58:00PM +0200, Cyborg via Exim-users wrote:
> This results in a problem with PROOFEPOINT Mailgateway < version 8.22 :
>
> theire tls 1.3 is defective once you use openssl >= 3.5.0
>
> Thats most likely caused by introducing the security tls padding extension
> RFC 7685.
Just in case you've mis-diagnosed this.
I was diagnosing an issue with TLS to some sites, and went down a
rabbithole of trying to diagnose if inclusion of PQC in the TLS Client
Hello was the issue... and it turned out to be because *over IPv6* I
had a path MTU issue. I'd been clamping IPv4 MSS to a known good value
for years, but neglected to do the same for IPv6. After applying that
change everything started working again.
--
- Athanasius (he/him) = Athanasius(at)miggy.org / https://miggy.org/
GPG/PGP Key: https://miggy.org/gpg-key
"And it's me who is my enemy. Me who beats me up.
Me who makes the monsters. Me who strips my confidence." Paula Cole - ME
--
## subscription configuration (requires account):
## https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/
## unsubscribe (doesn't require an account):
## [email protected]
## Exim details at https://www.exim.org/
## Please use the Wiki with this list - https://code.exim.org/exim/wiki/wiki