Hi Community,
wir haben kürzlich unseren Exchange 2010 für verschlüsselte Kommunikation eingestellt und bin echt überrascht wieviele Mailserver dieses Angebot auch nutzen können. Was mich allerdings noch etwas grübeln lässt, ist die Frage warum bei STARTTLS die Verbindung zweimal aufgebaut wird?
,08D18F3FB77DBA54,0, 192.168.1.1:25,14.173.150.209:43182,+,, ,08D18F3FB77DBA54,1, 192.168.1.1:25,14.173.150.209:43182,*,SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders,Set Session Permissions ,08D18F3FB77DBA54,2, 192.168.1.1:25,14.173.150.209:43182,>,"220 mail.ourdomain.de Microsoft ESMTP MAIL Service ready at Wed, 3 Sep 2014 02:58:11 +0200", ,08D18F3FB77DBA54,3, 192.168.1.1:25,14.173.150.209:43182,<,EHLO s81.mail.info, ,08D18F3FB77DBA54,4, 192.168.1.1:25,14.173.150.209:43182,>,250-mail.ourdomain.de Hello [14.173.150.209], ,08D18F3FB77DBA54,5, 192.168.1.1:25,14.173.150.209:43182,>,250-SIZE, ,08D18F3FB77DBA54,6, 192.168.1.1:25,14.173.150.209:43182,>,250-PIPELINING, ,08D18F3FB77DBA54,7, 192.168.1.1:25,14.173.150.209:43182,>,250-DSN, ,08D18F3FB77DBA54,8, 192.168.1.1:25,14.173.150.209:43182,>,250-ENHANCEDSTATUSCODES, ,08D18F3FB77DBA54,9, 192.168.1.1:25,14.173.150.209:43182,>,250-STARTTLS, ,08D18F3FB77DBA54,10, 192.168.1.1:25,14.173.150.209:43182,>,250-AUTH LOGIN, ,08D18F3FB77DBA54,11, 192.168.1.1:25,14.173.150.209:43182,>,250-8BITMIME, ,08D18F3FB77DBA54,12, 192.168.1.1:25,14.173.150.209:43182,>,250-BINARYMIME, ,08D18F3FB77DBA54,13, 192.168.1.1:25,14.173.150.209:43182,>,250 CHUNKING, ,08D18F3FB77DBA54,14, 192.168.1.1:25,14.173.150.209:43182,<,STARTTLS, ,08D18F3FB77DBA54,15, 192.168.1.1:25,14.173.150.209:43182,>,220 2.0.0 SMTP server ready, ,08D18F3FB77DBA54,16, 192.168.1.1:25,14.173.150.209:43182,*,,Sending certificate ,08D18F3FB77DBA54,17, 192.168.1.1:25,14.173.150.209:43182,*,"CN=mail.ourdomain.de, OU=PositiveSSL, OU=Domain Control Validated",Certificate subject ,08D18F3FB77DBA54,18, 192.168.1.1:25,14.173.150.209:43182,*,"CN=PositiveSSL CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB",Certificate issuer name ,08D18F3FB77DBA54,19, 192.168.1.1:25,14.173.150.209:43182,*,144ADF6F4F798460D13AA689A9AAA630,Certificate serial number ,08D18F3FB77DBA54,20, 192.168.1.1:25,14.173.150.209:43182,*,538EB8AAB76D67AFFA413E7BD41AA656FCEFB3D7,Certificate thumbprint ,08D18F3FB77DBA54,21, 192.168.1.1:25,14.173.150.209:43182,*,mail.ourdomain.de;www.mail.ourdomain.de,Certificate alternate names ,08D18F3FB77DBA54,22, 192.168.1.1:25,14.173.150.209:43182,<,EHLO s81.mail.info, ,08D18F3FB77DBA54,23, 192.168.1.1:25,14.173.150.209:43182,*,,TlsDomainCapabilities='None'; Status='NoRemoteCertificate' ,08D18F3FB77DBA54,24, 192.168.1.1:25,14.173.150.209:43182,>,250-mail.ourdomain.de Hello [14.173.150.209], ,08D18F3FB77DBA54,25, 192.168.1.1:25,14.173.150.209:43182,>,250-SIZE, ,08D18F3FB77DBA54,26, 192.168.1.1:25,14.173.150.209:43182,>,250-PIPELINING, ,08D18F3FB77DBA54,27, 192.168.1.1:25,14.173.150.209:43182,>,250-DSN, ,08D18F3FB77DBA54,28, 192.168.1.1:25,14.173.150.209:43182,>,250-ENHANCEDSTATUSCODES, ,08D18F3FB77DBA54,29, 192.168.1.1:25,14.173.150.209:43182,>,250-AUTH LOGIN, ,08D18F3FB77DBA54,30, 192.168.1.1:25,14.173.150.209:43182,>,250-8BITMIME, ,08D18F3FB77DBA54,31, 192.168.1.1:25,14.173.150.209:43182,>,250-BINARYMIME, ,08D18F3FB77DBA54,32, 192.168.1.1:25,14.173.150.209:43182,>,250 CHUNKING, ,08D18F3FB77DBA54,33, 192.168.1.1:25,14.173.150.209:43182,<,MAIL FROM:<root@architects.com> BODY=8BITMIME, ,08D18F3FB77DBA54,34, 192.168.1.1:25,14.173.150.209:43182,*,08D18F3FB77DBA54;2014-09-03T00:58:11.832Z;1,receiving message ,08D18F3FB77DBA54,35, 192.168.1.1:25,14.173.150.209:43182,>,250 2.1.0 Sender OK, ,08D18F3FB77DBA54,36, 192.168.1.1:25,14.173.150.209:43182,<,RCPT TO:<user@ourdomain.de>, ,08D18F3FB77DBA54,37, 192.168.1.1:25,14.173.150.209:43182,>,250 2.1.5 Recipient OK, ,08D18F3FB77DBA54,38, 192.168.1.1:25,14.173.150.209:43182,<,DATA, ,08D18F3FB77DBA54,39, 192.168.1.1:25,14.173.150.209:43182,>,354 Start mail input; end with <CRLF>.<CRLF>, ,08D18F3FB77DBA54,40, 192.168.1.1:25,14.173.150.209:43182,*,Tarpit for '0.00:00:02.168' due to 'DelayedAck',Delivered ,08D18F3FB77DBA54,41, 192.168.1.1:25,14.173.150.209:43182,>,250 2.6.0 <195d18e3909e9e788ca256a7d23722be@localhost.localdomain> [InternalId=455687] Queued mail for delivery, ,08D18F3FB77DBA54,42, 192.168.1.1:25,14.173.150.209:43182,-,,Remote
Eigentlich sollte doch STARTTLS genau das verhindern. Kann den zweiten Verbindungsaufbau jemand erklären?
Thx & Bye Tom