f.johan.beisser jan at caustic.org
Tue Dec 10 00:23:31 PST 2002

On Tue, 10 Dec 2002, Jerry Asher wrote:

> That's certainly what it looks like.  Now I have never told qmail to use
> only TLS, and I haven't told it to prefer TLS, but I can imagine it
> being coded to do so.

the only way to know is to check the code.

djb's license won't allow you to change it, though.

> Can you tell me what it might be about weak.org, or between any two MTAs
> that might cause my installation of qmail to try a TLS connection
> between the two sites?

probably attempting to negotiate "ehlo" vs just "helo". seeing TLS as an
option makes the OS attempt it. you might be better served just creating
your own certificates and going on from there.

> I mean, I'm suspecting it's something in the initial protocol
> negotiation, and if I can get a handle on that, then I can test that
> against my version of qmail.

look up the info on how TLS is negotiated.

it's in an RFC, somewhere.

