<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail — Upcoming LetsEncrypt Changes]]></title>
		<link>https://forum.iredmail.org/topic20890-upcoming-letsencrypt-changes.html</link>
		<atom:link href="https://forum.iredmail.org/feed-rss-topic20890.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in Upcoming LetsEncrypt Changes.]]></description>
		<lastBuildDate>Sat, 17 May 2025 20:59:22 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Upcoming LetsEncrypt Changes]]></title>
			<link>https://forum.iredmail.org/post90859.html#p90859</link>
			<description><![CDATA[<p>iredmail doesn&#039;t use client auth</p>]]></description>
			<author><![CDATA[null@example.com (Cthulhu)]]></author>
			<pubDate>Sat, 17 May 2025 20:59:22 +0000</pubDate>
			<guid>https://forum.iredmail.org/post90859.html#p90859</guid>
		</item>
		<item>
			<title><![CDATA[Re: Upcoming LetsEncrypt Changes]]></title>
			<link>https://forum.iredmail.org/post90858.html#p90858</link>
			<description><![CDATA[<p>After a bit more reading it seems that postfix does not by default require validation of client certificates, although it can be configured that way (don&#039;t know if iRedMail does so). However sendmail does check.</p><p>Some say that a failed validation just creates a warning in the headers, but even if that&#039;s true, the spam detection algorithms might then downgrade the authenticity rating of the message, resulting in more false positive spam detection.</p><p>But if I understand correctly, this is not about how our postfix is configured but rather how the receiving partner MTA is configured (which could be postfix, or exchange, or whatever).</p><p>Is that right?</p>]]></description>
			<author><![CDATA[null@example.com (evenmoreconfused)]]></author>
			<pubDate>Sat, 17 May 2025 14:49:00 +0000</pubDate>
			<guid>https://forum.iredmail.org/post90858.html#p90858</guid>
		</item>
		<item>
			<title><![CDATA[Upcoming LetsEncrypt Changes]]></title>
			<link>https://forum.iredmail.org/post90857.html#p90857</link>
			<description><![CDATA[<p>LetsEncrypt have announced that their certificates will stop including the client-side bit starting in 2026: <a href="https://letsencrypt.org/2025/05/14/ending-tls-client-authentication/">https://letsencrypt.org/2025/05/14/endi … ntication/</a></p><p>The general use case for LetsEncrypt is for web servers, which only need the server-side bit, but several people have already protested that SMTP using TLS needs this client part of the cert (see the discussion at <a href="https://community.letsencrypt.org/t/do-not-remove-tls-client-auth-eku/237427/5">https://community.letsencrypt.org/t/do- … u/237427/5</a> ).</p><p>I am wondering if this will affect iRedMail installations, and, if so, can we expect that the necessary changes will be part of the regular update stream? The required changes seem a bit daunting to we amateurs!</p><p>Thanks as always for all help,<br />Paul</p>]]></description>
			<author><![CDATA[null@example.com (evenmoreconfused)]]></author>
			<pubDate>Sat, 17 May 2025 14:35:14 +0000</pubDate>
			<guid>https://forum.iredmail.org/post90857.html#p90857</guid>
		</item>
	</channel>
</rss>
