TLS 握手失败(STARTTLS required / certificate verify failed),怎么排查?
71
TLS 握手失败(STARTTLS required / certificate verify failed),怎么排查?
▼
症状
退信:530 5.7.0 Must issue STARTTLS / 554 5.7.5 TLS required / Server certificate SAN mismatch。
修复
1. Postfix 设 smtpd_tls_security_level = may 启用 TLS
2. Let's Encrypt 免费证书:sudo certbot certonly --standalone -d mail.domain.com
3. 配置 smtpd_tls_cert_file = fullchain.pem(含中间证书,不能用 cert.pem)
4. 证书 SAN 必须匹配域名,避免自签名证书
5. openssl s_client -connect host:25 -starttls smtp 检查链
参考:RFC 3207 SMTP STARTTLS · RFC 8461 MTA-STS · Let's Encrypt Certbot
