From Newsgroup: comp.mail.sendmail
Hi Team,
I am trying to get everything as clean as possible on my sendmail server
as our domain is currently barred by gmail "due to a poor reputation".
Using postmaster tools on google it suggested I needed to fix reverse
/forward dns for my MX records which I have done. All that remains is my certificate error.
I am running ubuntu 20.04 (LAMP) server.
The error from checktls.com is as follows
[006.618] Connection converted to SSL/TLS
SSLVersion in use: TLSv1_3
Cipher in use: TLS_AES_256_GCM_SHA384
Perfect Forward Secrecy: yes
Session Algorithm in use: P-256(256 bits)
Certificate #1 of 1 (sent by MX):
Cert VALIDATION ERROR(S): self-signed certificate
So email is encrypted but the recipient domain is not verified
Cert Hostname VERIFIED (ikserver2.goodnewsbig.com =
ikserver2.goodnewsbig.com)
cert not revoked by OCSP
Not Valid Before: Apr 15 18:05:29 2026 GMT
Not Valid After: Apr 12 18:05:29 2036 GMT
Seconds Until Expired: 315178821
subject: /O=Sendmail/OU=Sendmail Server/CN=ikserver2.goodnewsbig.com/EMAIL=
admin@ikserver2.goodnewsbig.com issuer: /O=Sendmail/OU=Sendmail Server/CN=ikserver2.goodnewsbig.com/EMAIL=
admin@ikserver2.goodnewsbig.com
Now I have spotted one issue and that is we do not have an "admin" user
on our server currently, but I cannot see how to rebuild the certifcates?
I can see sendmail-{server|client}.cfg files in /etc/mail/tls but have
no clue on how to use them.
I tried reloading sendmail which cured the previous "Cert Hostname"
value being incorrect, but this problem remains.
Can anyone advise or help me please?
Thx Paul
--- Synchronet 3.21f-Linux NewsLink 1.2