Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"Blocked due to using client certificate" error

Until recently we were using a self-signed certificate for SMTP email connections on our mail server. Yesterday we changed to a Letsencrypt certificate and started getting delivery failures to some but not all recipients.

When we looked at our mail server we were getting:

Wed 2021-07-28 13:23:16: SSL negotiation failed, error code 0x80090327
Wed 2021-07-28 13:23:16: An unknown error occurred while processing the certificate. (-2146893017)
Wed 2021-07-28 13:23:16: SMTP session terminated (Bytes in/out: 358/41)

When we looked at the SSL/TLS XG log for these connections we were seeing "Blocked due to using client certificate".

I can't find any reference to this error message. It is doubly strange that we had no issues with a self-signed certificate but failures with a proper certificate. This is at a customers site; we have the same setup and it has been running for a few months without the same issue. The only thing I have tried is to deselect 'Block invalid certificates' in General settings. I didn't expect it to make any difference and it didn't!

Can anybody explain this error and offer a solution?



This thread was automatically locked due to age.
Parents
  • I started seeing the same thing today out of the blue.  Like you, my SMTP server has a legitimate third party signed certificate, and like you, it only fails to certain domains (outlook.com, gmail.com, several others).  I had forgotten that I had left a DPI engine inspection rule enabled for my servers after I turned it off for everybody else due to all the other problems it causes.  Once I disabled it, everything started working perfectly again.  Like you, I could find no reference to the message anywhere.

    So frustrating when things just break out of nowhere.  

Reply
  • I started seeing the same thing today out of the blue.  Like you, my SMTP server has a legitimate third party signed certificate, and like you, it only fails to certain domains (outlook.com, gmail.com, several others).  I had forgotten that I had left a DPI engine inspection rule enabled for my servers after I turned it off for everybody else due to all the other problems it causes.  Once I disabled it, everything started working perfectly again.  Like you, I could find no reference to the message anywhere.

    So frustrating when things just break out of nowhere.  

Children