Topic: cannot load Certificate Authority data: Disabling TLS support
============ Required information ====
- iRedMail version (check /etc/iredmail-release): 0.9.7 MARIADB edition.
- Linux/BSD distribution name and version: CentOS Linux 7 (Core)
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): Mysql
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
Basically I'm trying to send an email from gmail to one of my email addresses that I've setup with iredmail.
I'm getting a message back in the postmaster account telling me:
In: STARTTLS
Out: 454 4.7.0 TLS not available due to local problem
I've previously setup opendkim with opendmarc manually but I've removed them later on since it was giving mitter issues with postfix. After that I've setup amavisd with opendkim. Anyhow that shouldn't be what's causing this issue. So the most important part is basically where it says cannot load Certificate Authority data. Because of this, any mail I'm recieving from gmail gets rejected.. And I'm still not quite sure why...
Does anyone have any idea what I can do to fix the issue?
Here is the mail log of today (I truncated the log because it was way too large):
Oct 16 11:41:24 server postfix/postscreen[11456]: CONNECT from [175.139.253.93]:59606 to [149.210.238.212]:25
Oct 16 11:41:24 server postfix/dnsblog[11458]: addr 175.139.253.93 listed by domain zen.spamhaus.org as 127.0.0.11
Oct 16 11:41:24 server postfix/dnsblog[11458]: addr 175.139.253.93 listed by domain zen.spamhaus.org as 127.0.0.4
Oct 16 11:41:24 server postfix/dnsblog[11457]: addr 175.139.253.93 listed by domain b.barracudacentral.org as 127.0.0.2
Oct 16 11:41:30 server postfix/postscreen[11456]: DNSBL rank 5 for [175.139.253.93]:59606
Oct 16 11:41:31 server postfix/postscreen[11456]: DISCONNECT [175.139.253.93]:59606
Oct 16 11:43:33 server postfix/postscreen[11477]: CONNECT from [2607:f8b0:400d:c0d::236]:43898 to [2a01:7c8:aabb:218:5054:ff:feac:2e4f]:25
Oct 16 11:43:39 server postfix/postscreen[11477]: PASS OLD [2607:f8b0:400d:c0d::236]:43898
Oct 16 11:43:39 server postfix/smtpd[11480]: cannot load Certificate Authority data: disabling TLS support
Oct 16 11:43:39 server postfix/smtpd[11480]: connect from mail-qt0-x236.google.com[2607:f8b0:400d:c0d::236]
Oct 16 11:43:40 server postfix/smtpd[11480]: lost connection after STARTTLS from mail-qt0-x236.google.com[2607:f8b0:400d:c0d::236]
Oct 16 11:43:40 server postfix/cleanup[11483]: 1634D240049: message-id=<20171016094340.1634D240049@server.systematex.nl>
Oct 16 11:43:40 server postfix/smtpd[11480]: disconnect from mail-qt0-x236.google.com[2607:f8b0:400d:c0d::236]
Oct 16 11:43:40 server postfix/qmgr[1604]: 1634D240049: from=<double-bounce@server.systematex.nl>, size=884, nrcpt=1 (queue active)
Oct 16 11:43:40 server postfix/cleanup[11483]: 1E1F8240065: message-id=<20171016094340.1634D240049@server.systematex.nl>
Oct 16 11:43:40 server postfix/qmgr[1604]: 1E1F8240065: from=<double-bounce@server.systematex.nl>, size=1033, nrcpt=1 (queue active)
Oct 16 11:43:40 server postfix/local[11486]: 1634D240049: to=<postmaster@server.systematex.nl>, relay=local, delay=0.05, delays=0.03/0.01/0/0.01, dsn=2.0.0, status=sent (forwarded as 1E1F8240065)
Oct 16 11:43:40 server postfix/qmgr[1604]: 1634D240049: removed
Oct 16 11:43:40 server postfix/pipe[11487]: 1E1F8240065: to=<postmaster@systematex.nl>, relay=dovecot, delay=0.1, delays=0/0.01/0/0.08, dsn=2.0.0, status=sent (delivered via dovecot service)
Oct 16 11:43:40 server postfix/qmgr[1604]: 1E1F8240065: removed
Oct 16 11:43:49 server postfix/postscreen[11477]: CONNECT from [202.52.254.125]:51920 to [149.210.238.212]:25
Oct 16 11:43:49 server postfix/dnsblog[11478]: addr 202.52.254.125 listed by domain zen.spamhaus.org as 127.0.0.4
Oct 16 11:43:49 server postfix/dnsblog[11479]: addr 202.52.254.125 listed by domain b.barracudacentral.org as 127.0.0.2
Oct 16 11:43:55 server postfix/postscreen[11477]: DNSBL rank 5 for [202.52.254.125]:51920
Oct 16 11:43:56 server postfix/postscreen[11477]: DISCONNECT [202.52.254.125]:51920
Oct 16 11:45:57 server clamd[1005]: SelfCheck: Database status OK.
Oct 16 11:46:15 server postfix/postscreen[11529]: CONNECT from [61.69.110.138]:61692 to [149.210.238.212]:25
Oct 16 11:46:15 server postfix/dnsblog[11530]: addr 61.69.110.138 listed by domain zen.spamhaus.org as 127.0.0.4
Oct 16 11:46:21 server postfix/postscreen[11529]: DNSBL rank 3 for [61.69.110.138]:61692
Oct 16 11:46:22 server postfix/postscreen[11529]: DISCONNECT [61.69.110.138]:61692
Oct 16 11:47:00 server postfix/anvil[11482]: statistics: max connection rate 1/60s for (smtpd:2607:f8b0:400d:c0d::236) at Oct 16 11:43:39
Oct 16 11:47:00 server postfix/anvil[11482]: statistics: max connection count 1 for (smtpd:2607:f8b0:400d:c0d::236) at Oct 16 11:43:39
Oct 16 11:47:00 server postfix/anvil[11482]: statistics: max cache size 1 at Oct 16 11:43:39
Oct 16 11:48:46 server postfix/postscreen[11554]: CONNECT from [200.105.200.11]:24798 to [149.210.238.212]:25
Oct 16 11:48:46 server postfix/dnsblog[11555]: addr 200.105.200.11 listed by domain zen.spamhaus.org as 127.0.0.4
Oct 16 11:48:52 server postfix/postscreen[11554]: DNSBL rank 3 for [200.105.200.11]:24798
Oct 16 11:48:53 server postfix/postscreen[11554]: DISCONNECT [200.105.200.11]:24798
Oct 16 11:51:09 server postfix/postscreen[11635]: CONNECT from [122.249.243.105]:57828 to [149.210.238.212]:25
Oct 16 11:51:09 server postfix/dnsblog[11636]: addr 122.249.243.105 listed by domain zen.spamhaus.org as 127.0.0.4
Oct 16 11:51:15 server postfix/postscreen[11635]: DNSBL rank 3 for [122.249.243.105]:57828
Oct 16 11:51:16 server postfix/postscreen[11635]: DISCONNECT [122.249.243.105]:57828
Oct 16 11:51:42 server postfix/postscreen[11635]: CONNECT from [2607:f8b0:400d:c0d::22e]:45059 to [2a01:7c8:aabb:218:5054:ff:feac:2e4f]:25
Oct 16 11:51:42 server postfix/postscreen[11635]: PASS OLD [2607:f8b0:400d:c0d::22e]:45059
Oct 16 11:51:42 server postfix/smtpd[11663]: cannot load Certificate Authority data: disabling TLS support
Oct 16 11:51:42 server postfix/smtpd[11663]: connect from mail-qt0-x22e.google.com[2607:f8b0:400d:c0d::22e]
Oct 16 11:51:42 server postfix/smtpd[11663]: lost connection after STARTTLS from mail-qt0-x22e.google.com[2607:f8b0:400d:c0d::22e]
Oct 16 11:51:42 server postfix/cleanup[11666]: 8286A240059: message-id=<20171016095142.8286A240059@server.systematex.nl>
Oct 16 11:51:42 server postfix/qmgr[1604]: 8286A240059: from=<double-bounce@server.systematex.nl>, size=884, nrcpt=1 (queue active)
Oct 16 11:51:42 server postfix/smtpd[11663]: disconnect from mail-qt0-x22e.google.com[2607:f8b0:400d:c0d::22e]
Oct 16 11:51:42 server postfix/cleanup[11666]: 89FE52400E4: message-id=<20171016095142.8286A240059@server.systematex.nl>
Oct 16 11:51:42 server postfix/qmgr[1604]: 89FE52400E4: from=<double-bounce@server.systematex.nl>, size=1033, nrcpt=1 (queue active)
Oct 16 11:51:42 server postfix/local[11669]: 8286A240059: to=<postmaster@server.systematex.nl>, relay=local, delay=0.04, delays=0.02/0.01/0/0.01, dsn=2.0.0, status=sent (forwarded as 89FE52400E4)
Oct 16 11:51:42 server postfix/qmgr[1604]: 8286A240059: removed
Oct 16 11:51:42 server postfix/pipe[11670]: 89FE52400E4: to=<postmaster@systematex.nl>, relay=dovecot, delay=0.11, delays=0.01/0.01/0/0.1, dsn=2.0.0, status=sent (delivered via dovecot service)
Oct 16 11:51:42 server postfix/qmgr[1604]: 89FE52400E4: removed
Oct 16 11:55:02 server postfix/anvil[11665]: statistics: max connection rate 1/60s for (smtpd:2607:f8b0:400d:c0d::22e) at Oct 16 11:51:42
Oct 16 11:55:02 server postfix/anvil[11665]: statistics: max connection count 1 for (smtpd:2607:f8b0:400d:c0d::22e) at Oct 16 11:51:42
Oct 16 11:55:02 server postfix/anvil[11665]: statistics: max cache size 1 at Oct 16 11:51:42
I'd very much appreciate any help you can give me.
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.