#1082187 If tls-on-connect is enabled, it makes no sense to complain that STARTTLS is not offered inside the (now-encrypted) session

#1082187#5
Date:
2024-09-19 07:23:47 UTC
From:
To:
eg. connecting to an SSMTPA on port 465:

   swaks -a -tlsc --server submission.example.com --to michael@example.com

Successfully connects on port 465, negotiates SSL, but then bombs out
complaining that STARTTLS is not advertised (names changed to protect the
innocent):

   === Trying submission.example.com:465...
   === Connected to submission.example.com.
   === TLS started with cipher TLSv1.3:TLS_AES_256_GCM_SHA384:256
   === TLS client certificate not requested and not sent
   === TLS no client certificate set
   === TLS peer[0]   subject=[/CN=*.example.com]
   ===               commonName=[*.example.com], subjectAltName=[DNS:*.example.com, DNS:example.com] notAfter=[2024-11-12T02:14:49Z]
   === TLS peer[1]   subject=[/C=US/O=Let's Encrypt/CN=R10]
   ===               commonName=[R10], subjectAltName=[] notAfter=[2027-03-12T23:59:59Z]
   === TLS peer certificate passed CA verification, passed host verification (using host submission.example.com to verify)
   <~  220 mailfish.example.com ESMTP
    ~> EHLO joyola
   <~  250-mailfish.example.com
   <~  250-PIPELINING
   <~  250-SIZE 50720000
   <~  250-ETRN
   <~  250-AUTH LOGIN PLAIN
   <~  250-AUTH=LOGIN PLAIN
   <~  250-ENHANCEDSTATUSCODES
   <~  250-8BITMIME
   <~  250-DSN
   <~  250-SMTPUTF8
   <~  250 CHUNKING
   *** Host did not advertise STARTTLS
    ~> QUIT
   <~  221 2.0.0 Bye
   === Connection closed with remote host.

I think --tls-on-connect should imply something similar to --tls-optional (I
would argue that advertising STARTTLS here would actually be a configuration
error).

Versions of packages swaks depends on:
ii  perl  5.38.2-5

Versions of packages swaks recommends:
ii  libio-socket-inet6-perl  2.73-1
pn  libnet-dns-perl          <none>
ii  libnet-ssleay-perl       1.94-1+b1

Versions of packages swaks suggests:
pn  libauthen-ntlm-perl  <none>
ii  libauthen-sasl-perl  2.1600-3
ii  perl-doc             5.38.2-5

#1082187#10
Date:
2024-09-19 17:16:27 UTC
From:
To:
[...]

Hello,

That behavior does not make sense, I cannot it reproduce though. :-(

ametzler@argenau:~$ swaks -tlsc --server localhost  --to ametzler@bebt.de -q rcpt
=== Trying localhost:465...
=== Connected to localhost.
=== TLS started with cipher TLSv1.3:TLS_AES_256_GCM_SHA384:256
=== TLS client certificate not requested and not sent
[...]
=== TLS peer certificate failed CA verification (self-signed certificate), passed host verification (using host localhost to verify)
<~  220 argenau.bebt.de ESMTP Exim 4.98 Thu, 19 Sep 2024 19:12:57 +0200
 ~> EHLO argenau.bebt.de
<~  250-argenau.bebt.de Hello localhost [::1]
<~  250-SIZE 52428800
<~  250-LIMITS MAILMAX=1000 RCPTMAX=50000
<~  250-8BITMIME
<~  250-PIPELINING
<~  250-PIPECONNECT
<~  250-AUTH CRAM-MD5
<~  250-CHUNKING
<~  250-PRDR
<~  250 HELP
 ~> MAIL FROM:<ametzler@argenau.bebt.de>
<~  250 OK
 ~> RCPT TO:<ametzler@bebt.de>
<~  250 Accepted
 ~> QUIT
<~  221 argenau.bebt.de closing connection

cu Andreas

#1082187#15
Date:
2024-09-20 02:46:43 UTC
From:
To:
Ah, this is the result of forgetting that .swaksrc is a thing, which (in my
case) was attempting to be helpful by enabling --tls by default.  Perhaps
swaks ought to do something sensible when both --tls and --tls-on-connect
are supplied...

#1082187#20
Date:
2024-09-19 17:16:27 UTC
From:
To:
[...]

Hello,

That behavior does not make sense, I cannot it reproduce though. :-(

ametzler@argenau:~$ swaks -tlsc --server localhost  --to ametzler@bebt.de -q rcpt
=== Trying localhost:465...
=== Connected to localhost.
=== TLS started with cipher TLSv1.3:TLS_AES_256_GCM_SHA384:256
=== TLS client certificate not requested and not sent
[...]
=== TLS peer certificate failed CA verification (self-signed certificate), passed host verification (using host localhost to verify)
<~  220 argenau.bebt.de ESMTP Exim 4.98 Thu, 19 Sep 2024 19:12:57 +0200
 ~> EHLO argenau.bebt.de
<~  250-argenau.bebt.de Hello localhost [::1]
<~  250-SIZE 52428800
<~  250-LIMITS MAILMAX=1000 RCPTMAX=50000
<~  250-8BITMIME
<~  250-PIPELINING
<~  250-PIPECONNECT
<~  250-AUTH CRAM-MD5
<~  250-CHUNKING
<~  250-PRDR
<~  250 HELP
 ~> MAIL FROM:<ametzler@argenau.bebt.de>
<~  250 OK
 ~> RCPT TO:<ametzler@bebt.de>
<~  250 Accepted
 ~> QUIT
<~  221 argenau.bebt.de closing connection

cu Andreas

#1082187#25
Date:
2024-09-21 12:16:20 UTC
From:
To:
Control: forwarded -1 https://github.com/jetmore/swaks/issues/104
Control: retitle -1 warn/err on conflicting tls-on-connect/tls options

Hello,

thanks for clearing this up, I have forwarded the issue upstream.

cu Andreas