Gordon Messmer wrote:
What firewalls/proxies/gateways lie between you and the Courier server?
Anywhere from 0 to 2, depending - this has tested with multiple network
connections, including two hosts on a single hub with nothing but 'net
between them. That's not really an issue, though, because I've verified
with tcpdump that the "STARTTLS" command just isn't leaving the client PC
and going onto the network.
I was jumping down the "must be a random hotfix" path earlier and
upgraded my "working" XP box, but couldn't break it. Tinfoil looking better
and better as we go.
Telnet and tcpdump logs, along with other thoughts, are available at
http://www.swynwyr.com/xpssl/ if anyone wants to look.
It seems like someone recently noticed that some commands were reaching
his courier server as XXXXXXX because a gateway was modifying the
commands on the wire to "protect" the SMTP server.
Sounds like Cisco PIX with "fixup smtp" in the config. PIX is a great
firewall... if you leave the fixup stuff off.