diff --git a/mail-server/postfix.nix b/mail-server/postfix.nix index d1c59b2..5d7f9a2 100644 --- a/mail-server/postfix.nix +++ b/mail-server/postfix.nix @@ -287,10 +287,12 @@ in smtp_tls_mandatory_exclude_ciphers = "MD5, DES, ADH, RC4, PSD, SRP, 3DES, eNULL, aNULL"; smtp_tls_exclude_ciphers = "MD5, DES, ADH, RC4, PSD, SRP, 3DES, eNULL, aNULL"; - tls_preempt_cipherlist = true; + # As long as all cipher suites are considered safe, let the client use its preferred cipher + tls_preempt_cipherlist = false; # Allowing AUTH on a non encrypted connection poses a security risk smtpd_tls_auth_only = true; + # Log only a summary message on TLS handshake completion smtp_tls_loglevel = "1"; smtpd_tls_loglevel = "1";