Error Sending Mail from Postfix: 'Must Issue a STARTTLS Command First' Due to Cisco PIX Relay Device
Issue
-
Users are facing an
errorwhen attempting tosendemails through thePostfixmail server, receiving the message:"530 #5.7.0 Must issue a STARTTLS command first." -
Due to the error 530
#5.7.0 Must issue a STARTTLS command first, thePostfixmail server is unable to establishsecureconnections, causing outgoing emails tofailand resulting in communicationdisruptions. -
The server returns the error
530 #5.7.0 Must issue a STARTTLS command first., this indicates that the server is unable to initiate a secure connection. -
The
Postfixlogs show entries indicating that theCisco PIX deviceis interfering with theSMTPcommunication, leading to the failure of theSTARTTLScommand.Oct 29 15:05:12 mailserver postfix/smtp[1005411]: EB05C8076XX: enabling PIX workarounds: disable_esmtp for relay.example.com[1.2.3.4]:25 Oct 29 15:05:12 mailserver postfix/smtp[1005383]: EA8C48076XX: to=<ganeshp@example.com>, relay=relay.example.com[1.2.3.4]:25, delay=0.13, delays=0/0/0.13/0, dsn=5.0.0, status=bounced (host relay.example.com[1.2.3.4] refused to talk to me: 530 #5.7.0 Must issue a STARTTLS command first) Oct 29 15:05:12 mailserver postfix/qmgr[3052490]: EA8C48076XX: removed
Environment
- Red Hat Enterprise Linux 8
- Postfix
- CISCO PIX
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.