Exim4 GnuTLS握手异常:突发TLS功能失效问题求助
It sounds like your Exim4 setup with GnuTLS suddenly broke its TLS functionality even though your SSL cert checks out, and you haven't touched any configurations. The connection drops after EHLO on port 465 or after STARTTLS on port 587, with the log error gnutls_handshake: An unexpected TLS packet was received. Let's walk through the most likely fixes step by step:
1. Check GnuTLS Library Version Compatibility
Sudden TLS handshake issues often stem from system library updates that clash with your installed Exim version. Since your service worked 5 days ago, a recent GnuTLS package update is a prime suspect.
- First, check your current GnuTLS version:
gnutls-cli -v - Then verify which GnuTLS version Exim was compiled against:
exim -bV | grep -i gnutls - If the versions don't align, roll back GnuTLS to a previous stable release. On Ubuntu, you can list available old versions with:
Then install the older version with:apt-cache showpkg gnutls-binapt install gnutls-bin=<old-version-number>
2. Validate Your Certificate Chain
Even if you confirmed the certificate itself is valid, a broken intermediate or root CA cert could cause handshake failures.
- Use GnuTLS to inspect your full certificate chain:
Replace the cert/key paths with your actual files, and look for any errors related to chain validation in the output.gnutls-cli --x509cafile /etc/ssl/certs/ca-certificates.crt --certfile /path/to/your/exim/cert.pem --keyfile /path/to/your/exim/key.pem localhost:587
3. Audit Exim's TLS Configuration Details
Sometimes system updates can overwrite config snippets, or subtle permission issues creep in without manual changes.
- Check your TLS config sections (usually in
/etc/exim4/exim4.conf.templateor/etc/exim4/conf.d/main/03_exim4-config_tls):- Ensure
tls_certificateandtls_privatekeypoint to the correct files, with permissions set toroot:Debian-eximand mode640(Exim needs read access to both). - Update your cipher suite list to avoid deprecated protocols—try setting:
tls_require_ciphers = NORMAL:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1
- Ensure
- Regenerate the Exim config and restart the service:
update-exim4.conf systemctl restart exim4
4. Rule Out System-Level Interference
- Check if firewall rules, AppArmor, or SELinux have been updated to block TLS traffic. For AppArmor, you can temporarily stop it to test:
If TLS starts working after this, you'll need to adjust your AppArmor profile to allow Exim access to your certificate files.systemctl stop apparmor - Scan system logs (
/var/log/syslogor/var/log/messages) for additional GnuTLS-related errors, like failed library loads or permission denials.
5. Test GnuTLS Directly (Bypass Exim)
To confirm if the issue is with GnuTLS itself or Exim's integration:
- Test STARTTLS directly with GnuTLS:
gnutls-cli --starttls-smtp localhost:587 - Test SMTPS directly:
gnutls-cli localhost:465
If these tests fail too, the problem lies with your GnuTLS installation or system config, not Exim.
Start with the GnuTLS version check first—this is the most common culprit for sudden, unconfigured TLS failures like yours.
内容的提问来源于stack exchange,提问作者Mohamed Hassan

