Help with TLS and certs
Posted: Thu Feb 01, 2018 3:22 pm
I'm having a little trouble getting the email at 100% on checktls.com. For the record, I'm running vesta on vesta.website.com, and plan to have the main site set up on website.com. I'm not sure what to put as an MX record but it appears to work without one, just says "No Mail eXchangers found; will try TLS directly to host". Alternatively using one set to "website.com handled by vesta.website.com" doesn't seem to make much difference.
Initially the TLS was totally failing, but a quick google suggested setting the certificate permissions to root:Debian-exim (at /home/admin/conf/web/ssl.vesta.website.com.*) and that fixed it as it was unable to read them under the default Vesta settings.
Now that's working, it's failing at certificates, and I'm wondering if anyone knows how to fix it? They are correct on website.com and vesta.website.com in the browser, but for some reason not correct on email.
Here's the cert fail part from checktls.com:
In mxtoolbox.com it gives this:
Not sure where that dc-c3e7106d6d7b comes from. It's different depending on if you do @website.com or @vesta.website.com.
Initially the TLS was totally failing, but a quick google suggested setting the certificate permissions to root:Debian-exim (at /home/admin/conf/web/ssl.vesta.website.com.*) and that fixed it as it was unable to read them under the default Vesta settings.
Now that's working, it's failing at certificates, and I'm wondering if anyone knows how to fix it? They are correct on website.com and vesta.website.com in the browser, but for some reason not correct on email.
Here's the cert fail part from checktls.com:
Code: Select all
[000.624] Cert VALIDATION ERROR(S): unable to get local issuer certificate, unable to verify the first certificate
[000.625] This may help: What Is An Intermediate Certificate
[000.625] So email is encrypted but the recipient domain is not verified
[000.625] Cert Hostname DOES NOT VERIFY (dc-c3e7106d6d7b.website.com != vesta.website.com | DNS:vesta.website.com)
[000.625] So email is encrypted but the host is not verified
Code: Select all
smtp dc-c3e7106d6d7b.website.com 6.233 seconds - Warning on Connection time
smtp dc-c3e7106d6d7b.website.com 9.057 seconds - Not good! on Transaction Time