проблемка вот возникла.. не могу прикрутить к постфиксу никак TLS
система: FreeBSD 6.2, Postfix 2.3.3[root@freebsd /usr/local/etc/postfix]# postconf -n
alias_database = hash:/usr/local/etc/postfix/aliases
alias_maps = $alias_database
broken_sasl_auth_clients = yes
command_directory = /usr/local/sbin
config_directory = /usr/local/etc/postfix
daemon_directory = /usr/local/libexec/postfix
debug_peer_level = 2
disable_vrfy_command = yes
header_checks = regexp:/usr/local/etc/postfix/headers_checks
html_directory = no
inet_interfaces = all
invalid_hostname_reject_code = 550
mail_owner = postfix
mailbox_size_limit = 52428800
mailq_path = /usr/local/bin/mailq
manpage_directory = /usr/local/man
message_size_limit = 10485760
mydestination = $myhostname, localhost.$mydomain, localhost, $mydomain
mydomain = #########
myhostname = #########
mynetworks = 192.168.0.0/24, 127.0.0.0/8
myorigin = $mydomain
newaliases_path = /usr/local/bin/newaliases
non_fqdn_reject_code = 550
queue_directory = /var/spool/postfix
readme_directory = no
relay_domains =
sample_directory = /usr/local/etc/postfix
sendmail_path = /usr/local/sbin/sendmail
setgid_group = maildrop
smtpd_banner = $myhostname ESMTP $mail_name ($mail_version)
smtpd_client_restrictions =
smtpd_delay_reject = yes
smtpd_helo_required = yes
smtpd_helo_restrictions =
smtpd_recipient_restrictions = permit_mynetworks,     permit_sasl_authenticated,     permit_tls_clientcerts,     reject_unauth_destination,     reject_unauth_pipelining,     check_client_access hash:/usr/local/etc/postfix/access_client,     check_client_access pcre:/usr/local/etc/postfix/access_client.pcre,     reject_unknown_client_hostname,     check_helo_access hash:/usr/local/etc/postfix/access_helo,     reject_invalid_helo_hostname,     reject_non_fqdn_helo_hostname,     reject_unknown_helo_hostname,     check_sender_access hash:/usr/local/etc/postfix/access_sender,     reject_non_fqdn_sender,     reject_unknown_sender_domain,     reject_unverified_sender,     reject_non_fqdn_recipient,     reject_unknown_recipient_domain,     reject_unverified_recipient,     reject_rbl_client cbl.abuseat.org,     reject_rbl_client combined.njabl.org,     reject_rbl_client dnsbl.njabl.org,     reject_rbl_client dul.ru,     reject_rbl_client dynablock.njabl.org,     reject_rbl_client opm.blitzed.org,     reject_rhsbl_client blackhole.securitysage.com,     reject_rhsbl_client rhsbl.sorbs.net,     reject_rhsbl_sender blackhole.securitysage.com,     reject_rhsbl_sender rhsbl.sorbs.net,     permit
smtpd_sasl_auth_enable = yes
smtpd_sasl_local_domain =
smtpd_sasl_path = smtpd
smtpd_sasl_security_options = noanonymous
smtpd_sender_restrictions = permit_sasl_authenticated, permit_mynetworks
strict_rfc821_envelopes = yes
unknown_address_reject_code = 550
unknown_client_reject_code = 550
unknown_hostname_reject_code = 550
unknown_local_recipient_reject_code = 550
unverified_recipient_reject_code = 550
unverified_sender_reject_code = 550
master.cf
smtp      inet  n       -       n       -       -       smtpd -v
#submission inet n       -       n       -       -       smtpd
#  -o smtpd_enforce_tls=yes
#  -o smtpd_sasl_auth_enable=yes
#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
smtps     inet  n       -       n       -       -       smtpd
  -o smtpd_tls_wrappermode=yes
  -o smtpd_sasl_auth_enable=yes
#  -o smtpd_client_restrictions=permit_sasl_authenticated,reject
smtpd.conf
pwcheck_method: saslauthd
mech_list: PLAIN LOGIN
если все, что связано с TLS закомментить, то
[root@freebsd /usr/local/lib/sasl2]# telnet localhost 25
Trying ::1...
Trying 127.0.0.1...
Connected to ########.
Escape character is '^]'.
220 ######## ESMTP Postfix (2.3.3)
EHLO foo
250-########
250-PIPELINING
250-SIZE 10485760
250-ETRN
250-AUTH LOGIN PLAIN
250-AUTH=LOGIN PLAIN
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN
расскомментил, выдает
[root@freebsd /usr/local/etc/postfix]# telnet localhost 25
Trying ::1...
Trying 127.0.0.1...
Connected to #########.
Escape character is '^]'.
220 ######## ESMTP Postfix (2.3.3)
EHLO foo
250-#######
250-PIPELINING
250-SIZE 10485760
250-ETRN
250-STARTTLS
250-ENHANCEDSTATUSCODES
250-8BITMIME
250 DSN
я так понимаю, после STARTTLS чего то не то происходит
искал в инете про TLS и т.д. может канеш мало искал, ничего не нашел :)