Hello Taylor,
I detail the inconvenience that I am having.
When I set up a certificate signed by a certifying entity so that my mailings go out with TLS in my system logs, it shows me the message:
stat = Deferred: Connection refused by [127.0.0.1]
To discard that my problem is for the SSL certificate, I have proceeded to create a local certificate and configure it in my mc file to compile it later.
When sending tests, I notice in the mail header that the TLS protocol is visible but not verified (this is because it is a local certificate)
Received: from
smtp.escondatagate.com.pe (localhost [127.0.0.1]) by
smtp.escondatagate.com.pe (8.15.1 + Sun / 8.15.1) with ESMTPS id x3Q5BQib021106 (version = TLSv1.2 cipher = DHE -RSA-AES256-GCM-SHA384 bits = 256 verify = NO) for <
kcar...@esconcorp.com>; Fri, 26 Apr 2019 00:11:26 -0500 (PET)
With this I am deducting that my problem goes through an issue of the acquired SSL certificate and not the configuration of the sendmail, what do you think?
I am sending you the result of executing the openssl command (this test was done with the SSL certificate of SSL2BUY)
oot@mail2:/etc/mail/cf/cf# openssl s_client -host
smtp.escondatagate.com.pe -port 465
CONNECTED(00000004)
depth=1 C = BE, O = GlobalSign nv-sa, CN = AlphaSSL CA - SHA256 - G2
verify error:num=20:unable to get local issuer certificate
verify return:0
---
Certificate chain
0 s:/C=PE/OU=Domain Control Validated/CN=
smtp.escondatagate.com.pe
i:/C=BE/O=GlobalSign nv-sa/CN=AlphaSSL CA - SHA256 - G2
1 s:/C=BE/O=GlobalSign nv-sa/CN=AlphaSSL CA - SHA256 - G2
i:/OU=GlobalSign Root CA - R3/O=GlobalSign/CN=GlobalSign
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIF+zCCBOOgAwIBAgIMPMZ0U3B1Z1X2YhZtMA0GCSqGSIb3DQEBCwUAMEwxCzAJ
BgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSIwIAYDVQQDExlB
bHBoYVNTTCBDQSAtIFNIQTI1NiAtIEcyMB4XDTE5MDQxNjAzMDcxN1oXDTIwMDQx
NjAzMDcxN1owVDELMAkGA1UEBhMCUEUxITAfBgNVBAsTGERvbWFpbiBDb250cm9s
IFZhbGlkYXRlZDEiMCAGA1UEAxMZc210cC5lc2NvbmRhdGFnYXRlLmNvbS5wZTCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKM2359/ROzLvkqAthwyC2tn
a5GIFp3UNJrLce/o52R3RFipb8wxZ1u7rSj8GUR2LpYJ3joKoAR6twCoWXXqJ/PC
FX8lFPlBufa6R6Ils6oZp2BZWouKQxXmrSQKRCsE+h9/DDiYPXwINp4BCI88FPsA
yOsd9uBmngE8iTKDb6sk8c0lrxJVSQJRAmLztpwKLnw/bzSWtFk180n4b+KGq5uH
iB1kR2fL6852hYqxQtsaKUj8Z8IS7aByzlL/xpe3yDrgSNFe0GyXlURNu4u9F7iw
fCe4Ft3pjAkoF8eVYHTR3aqtGTA1fUX1uoAJ8qLwn05+2yrppCzXbI8SpeY2ucMC
AwEAAaOCAtMwggLPMA4GA1UdDwEB/wQEAwIFoDCBiQYIKwYBBQUHAQEEfTB7MEIG
CCsGAQUFBzAChjZodHRwOi8vc2VjdXJlMi5hbHBoYXNzbC5jb20vY2FjZXJ0L2dz
YWxwaGFzaGEyZzJyMS5jcnQwNQYIKwYBBQUHMAGGKWh0dHA6Ly9vY3NwMi5nbG9i
YWxzaWduLmNvbS9nc2FscGhhc2hhMmcyMFcGA1UdIARQME4wQgYKKwYBBAGgMgEK
CjA0MDIGCCsGAQUFBwIBFiZodHRwczovL3d3dy5nbG9iYWxzaWduLmNvbS9yZXBv
c2l0b3J5LzAIBgZngQwBAgEwCQYDVR0TBAIwADA+BgNVHR8ENzA1MDOgMaAvhi1o
dHRwOi8vY3JsMi5hbHBoYXNzbC5jb20vZ3MvZ3NhbHBoYXNoYTJnMi5jcmwwJAYD
VR0RBB0wG4IZc210cC5lc2NvbmRhdGFnYXRlLmNvbS5wZTAdBgNVHSUEFjAUBggr
BgEFBQcDAQYIKwYBBQUHAwIwHQYDVR0OBBYEFAX7K0c9EyIvgT5WUvy9U3smL6bO
MB8GA1UdIwQYMBaAFPXN1TwIUPlqTzq3l9pWg+Zp0mj3MIIBBgYKKwYBBAHWeQIE
AgSB9wSB9ADyAHcAu9nfvB+KcbWTlCOXqpJ7RzhXlQqrUugakJZkNo4e0YUAAAFq
JBz12AAABAMASDBGAiEA/ItIEVHrDMIxXPS8DX79q7J5vhZ2uukGr68z1GF6afUC
IQCRL2sCGqvuykRxRwBvSynKrONIx67qTiSvxQrMnBv8KQB3AG9Tdqwx8DEZ2JkA
pFEV/3cVHBHZAsEAKQaNsgiaN9kTAAABaiQc9YcAAAQDAEgwRgIhAOAGUEwyTPaz
QvSE/jQ3ztxjQA6xoLiswOF4euuCHcQWAiEAvJkgjfkXTOJWxDa285cnUCmE35a1
93bnyAEkdeO0Nm8wDQYJKoZIhvcNAQELBQADggEBAKBVe6NL+Fx9YKBeLDmPJ7mC
XtMP/BGh+BIfUGhU0FPEWdHh7ndi3Z6GiPbcb9yFECJHNQcAwicIsi0YuRgGvueQ
q7tmafgEiq5wJpZ40stpsMN0tisfuVvhQm7k1y3ANhQsga/tC6k9F7QfM09Srs8n
OIg2CSOCUUfNeB9ImHHGjBQU8CLqpB7czZLZdDToFSPXJWFIDgKgMBrkecYceBT/
Oqe+cdb0D3UZGVeBN83J1oLsPCbyn7ZOM2cSo3rpLmkdKXuFShkMntEmI6lcS/Si
2HKKh9XTilFpaE8+AjeGEbm4NSIqwSvYECm0Bso/aMsj7ZpZErHr7meWbWhFaVs=
-----END CERTIFICATE-----
subject=/C=PE/OU=Domain Control Validated/CN=
smtp.escondatagate.com.pe
issuer=/C=BE/O=GlobalSign nv-sa/CN=AlphaSSL CA - SHA256 - G2
---
Acceptable client certificate CA names
/C=BE/O=GlobalSign nv-sa/CN=AlphaSSL CA - SHA256 - G2
/C=BE/O=GlobalSign nv-sa/OU=Root CA/CN=GlobalSign Root CA
---
SSL handshake has read 3817 bytes and written 353 bytes
---
New, TLSv1/SSLv3, Cipher is DHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
Protocol : TLSv1.2
Cipher : DHE-RSA-AES256-GCM-SHA384
Session-ID: 2106113511D49F87C95FE2353C7437B439A24B380CDCCFB1251C7D2B01EF2005
Session-ID-ctx:
Master-Key: E73A6150914E72AAE72DE8CF78EAEB113EE12CD446A46BD6535C962CB843AB6D47D4AE95C35523C02D2AFF5C8AC3E07F
Key-Arg : None
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 1 (seconds)
TLS session ticket:
0000 - e4 b5 c8 52 99 4e c9 4a-2d b7 b9 9f 3d 42 dc 26 ...R.N.J-...=B.&
0010 - d5 96 6b f5 9e 52 f4 ee-40 33 9a 74 b1 7f 91 34 ..k..R..@3.t...4
0020 - 18 32 31 27 9b 21 2d ac-a1 eb 52 a0 18 2d d1 76 .21'.!-...R..-.v
0030 - e6 75 50 03 ff e2 59 5f-f7 39 f7 34 dd af db ea .uP...Y_.9.4....
0040 - 68 9d b1 47 9c f7 b5 d0-55 6b 8b 92 50 ba 29 30 h..G....Uk..P.)0
0050 - ed ed 3f 37 15 c8 3e 0b-23 43 5d d4 d9 40 31 23 ..?7..>.#C]..@1#
0060 - fc 45 3f f7 dd 81 45 39-ab dc fe c9 a8 97 61 6a .E?...E9......aj
0070 - 65 8c fb 90 2e a6 f6 fd-65 c3 9e fb 68 7b 19 2b e.......e...h{.+
0080 - eb 7d 62 49 75 5d c9 9d-6b ec 2f 6b 09 af fe 8c .}bIu]..k./k....
0090 - ec 4e 34 36 c0 44 d1 7f-af cb b7 94 6d 41 0c 1d .N46.D......mA..
Start Time: 1556251384
Timeout : 300 (sec)
Verify return code: 20 (unable to get local issuer certificate)
---
220
smtp.escondatagate.com.pe ESMTP Sendmail 8.15.1+Sun/8.15.1; Thu, 25 Apr 2019 23:03:04 -0500 (PET)