You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Exim4 GnuTLS握手异常:突发TLS功能失效问题求助

Fixing Exim4 GnuTLS Handshake Failure ("Unexpected TLS Packet")

It sounds like your Exim4 setup with GnuTLS suddenly broke its TLS functionality even though your SSL cert checks out, and you haven't touched any configurations. The connection drops after EHLO on port 465 or after STARTTLS on port 587, with the log error gnutls_handshake: An unexpected TLS packet was received. Let's walk through the most likely fixes step by step:

1. Check GnuTLS Library Version Compatibility

Sudden TLS handshake issues often stem from system library updates that clash with your installed Exim version. Since your service worked 5 days ago, a recent GnuTLS package update is a prime suspect.

  • First, check your current GnuTLS version:
    gnutls-cli -v
    
  • Then verify which GnuTLS version Exim was compiled against:
    exim -bV | grep -i gnutls
    
  • If the versions don't align, roll back GnuTLS to a previous stable release. On Ubuntu, you can list available old versions with:
    apt-cache showpkg gnutls-bin
    
    Then install the older version with:
    apt install gnutls-bin=<old-version-number>
    

2. Validate Your Certificate Chain

Even if you confirmed the certificate itself is valid, a broken intermediate or root CA cert could cause handshake failures.

  • Use GnuTLS to inspect your full certificate chain:
    gnutls-cli --x509cafile /etc/ssl/certs/ca-certificates.crt --certfile /path/to/your/exim/cert.pem --keyfile /path/to/your/exim/key.pem localhost:587
    
    Replace the cert/key paths with your actual files, and look for any errors related to chain validation in the output.

3. Audit Exim's TLS Configuration Details

Sometimes system updates can overwrite config snippets, or subtle permission issues creep in without manual changes.

  • Check your TLS config sections (usually in /etc/exim4/exim4.conf.template or /etc/exim4/conf.d/main/03_exim4-config_tls):
    • Ensure tls_certificate and tls_privatekey point to the correct files, with permissions set to root:Debian-exim and mode 640 (Exim needs read access to both).
    • Update your cipher suite list to avoid deprecated protocols—try setting:
      tls_require_ciphers = NORMAL:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1
      
  • Regenerate the Exim config and restart the service:
    update-exim4.conf
    systemctl restart exim4
    

4. Rule Out System-Level Interference

  • Check if firewall rules, AppArmor, or SELinux have been updated to block TLS traffic. For AppArmor, you can temporarily stop it to test:
    systemctl stop apparmor
    
    If TLS starts working after this, you'll need to adjust your AppArmor profile to allow Exim access to your certificate files.
  • Scan system logs (/var/log/syslog or /var/log/messages) for additional GnuTLS-related errors, like failed library loads or permission denials.

5. Test GnuTLS Directly (Bypass Exim)

To confirm if the issue is with GnuTLS itself or Exim's integration:

  • Test STARTTLS directly with GnuTLS:
    gnutls-cli --starttls-smtp localhost:587
    
  • Test SMTPS directly:
    gnutls-cli localhost:465
    

If these tests fail too, the problem lies with your GnuTLS installation or system config, not Exim.

Start with the GnuTLS version check first—this is the most common culprit for sudden, unconfigured TLS failures like yours.

内容的提问来源于stack exchange,提问作者Mohamed Hassan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 13:22:49