Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"Blocked due to using client certificate" error

Until recently we were using a self-signed certificate for SMTP email connections on our mail server. Yesterday we changed to a Letsencrypt certificate and started getting delivery failures to some but not all recipients.

When we looked at our mail server we were getting:

Wed 2021-07-28 13:23:16: SSL negotiation failed, error code 0x80090327
Wed 2021-07-28 13:23:16: An unknown error occurred while processing the certificate. (-2146893017)
Wed 2021-07-28 13:23:16: SMTP session terminated (Bytes in/out: 358/41)

When we looked at the SSL/TLS XG log for these connections we were seeing "Blocked due to using client certificate".

I can't find any reference to this error message. It is doubly strange that we had no issues with a self-signed certificate but failures with a proper certificate. This is at a customers site; we have the same setup and it has been running for a few months without the same issue. The only thing I have tried is to deselect 'Block invalid certificates' in General settings. I didn't expect it to make any difference and it didn't!

Can anybody explain this error and offer a solution?



This thread was automatically locked due to age.
Parents
  • "Blocked due to using client certificate" ... could show you the problem ...
    Possible the peer has incorrect content within the certificates and deactivating 'Block invalid certificates' may help.
    I would try it.
    Otherwise, you can capture the peer certificate and compare content.

  • This isn't the peer certificate, it is changing our own (to be precise, the customers) certificate from a self-signed certificate to a Letsencrypt certificate that has caused this issue. It also only affects certain email recipients (always the same ones) most continue to work fine. The certificate itself appears fine but we did re-issue it just in case.

    We've been using the same setup ourselves for several months without any issues.

    Deactivating 'Block invalid certificates' made no difference.

    The XG is running SFOS 18.0.5 MR-5-Build586

Reply
  • This isn't the peer certificate, it is changing our own (to be precise, the customers) certificate from a self-signed certificate to a Letsencrypt certificate that has caused this issue. It also only affects certain email recipients (always the same ones) most continue to work fine. The certificate itself appears fine but we did re-issue it just in case.

    We've been using the same setup ourselves for several months without any issues.

    Deactivating 'Block invalid certificates' made no difference.

    The XG is running SFOS 18.0.5 MR-5-Build586

Children
No Data