[pfx] Re: LDAP with TLS or SSL: postmap: "Unable to bind to server" openldap: "TLS negotiation failure"
Viktor Dukhovni via Postfix-users <[email protected]> Wed, 6 May 2026 20:58:54 +1000
| Newsgroups | gmane.mail.postfix.user |
|---|---|
| Message-ID | <[email protected]> |
On Tue, May 05, 2026 at 12:34:33PM -0400, Tom via Postfix-users wrote:
> postmap: cfg_get_str: /etc/postfix/virtual_mailbox_domains.cf: tls_ca_cert_file = /etc/letsencrypt/live/cor.redacted.com/fullchain.pem
What do you expect the above to mean, and why?
> postmap: cfg_get_str: /etc/postfix/virtual_mailbox_domains.cf: bind = yes
> postmap: cfg_get_str: /etc/postfix/virtual_mailbox_domains.cf: bind_dn = cn=postfix,ou=apps,dc=redacted,dc=com
> postmap: cfg_get_str: /etc/postfix/virtual_mailbox_domains.cf: bind_pw = redacted
...
> postmap: cfg_get_str: /etc/postfix/virtual_mailbox_domains.cf: tls_cert = /etc/letsencrypt/live/cor.redacted.com/cert.pem
> postmap: cfg_get_str: /etc/postfix/virtual_mailbox_domains.cf: tls_key = /etc/letsencrypt/live/cor.redacted.com/privkey.pem
Does the server request client certificates, or does it use a
password-based login? The "bind" settings suggest the later...
> postmap: dict_ldap_connect: Binding to server ldaps://ldap.redacted.com with dn cn=postfix,ou=apps,dc=redacted,dc=com
> postmap: warning: dict_ldap_connect: Unable to bind to server ldaps://ldap.redacted.com with dn cn=postfix,ou=apps,dc=redacted,dc=com: -1 (Can't contact LDAP server)
> postmap: fatal: table ldap:/etc/postfix/virtual_mailbox_domains.cf: query error: Application error
Well, can't get far without making a TCP connection.
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]