Sending mail from Postfix via Gmail: unable to get local issuer certificate, certificate not trusted, No worthy mechs found
- CentOS 5.5
- Postfix 2.3.3
I’ve been following Configure Postfix to send/relay emails Gmail (smtp.gmail.com) via port 587 to try and get the connection between Postfix and Gmail to work properly. The instructions are clear. After doing what the chosen answer says, I get this error in my maillog:
Dec 12 08:45:00 stiltify postfix/smtp: certificate verification failed for smtp.gmail.com: num=20:unable to get local issuer certificate Dec 12 08:45:00 stiltify postfix/smtp: certificate verification failed for smtp.gmail.com: num=27:certificate not trusted Dec 12 08:45:00 stiltify postfix/smtp: warning: SASL authentication failure: No worthy mechs found Dec 12 08:45:00 stiltify postfix/smtp: 6BC962B58006: to=<firstname.lastname@example.org>, relay=smtp.gmail.com[184.108.40.206]:587, delay=0.27, delays=0.05/0.01/0.21/0, dsn=4.7.0, status=deferred (SASL authentication failed; cannot authenticate to server smtp.gmail.com[220.127.116.11]: no mechanism available)
Similar problems out there
Searching for a similar scenario, I found Postfix “SASL authentication failure: No worthy mechs found”, but looking at the details of the chosen answer, it was slightly different and I think it means that the sending server doesn’t trust Gmail’s certificate:
untrusted issuer /C=US/O=Equifax/OU=Equifax Secure Certificate Authority
So here I am, stuck at a mailing problem once again, and need your help.
Thanks in advance!
It sounds like potentially 2 different issues potentially at hand. Now I’m the one that provided the answer for the question regarding forwarding through Gmail and mine was done on an Ubuntu laptop configuration not CentOS and I unfortunately don’t have a CentOS machine handy to test this on.
It sounds to me like the following may be causing the problems.
Check to ensure that the SASL binaries and libraries are installed. On my Ubuntu/Debian machines this would be including the
libsasl2-modulespackages. The later actually provides the SO SASL modules while the former provides the SASL DB libraries.
Check to see if you have a trusted CA root chain certificate installed. On my Ubuntu/Debian machines I install the
ca-certificatepackage which installs the known root level CA certificates and allows me to establish a CA cert chain that validates certificates signed by known CA’s.
Updating to add after checking my Ubuntu laptop… The certificate issue is actually a non-critical issue so item #2 is likely not at fault as I get the same entries myself but mail is sent successfully which would lean more to item #1 being cause for failures to send.
Dec 12 07:51:56 solitare postfix/smtp: setting up TLS connection to smtp.gmail.com[18.104.22.168]:587 Dec 12 07:51:56 solitare postfix/smtp: certificate verification failed for smtp.gmail.com[22.214.171.124]:587: untrusted issuer /C=US/O=Equifax/OU=Equifax Secure Certificate Authority Dec 12 07:51:56 solitare postfix/smtp: Untrusted TLS connection established to smtp.gmail.com[126.96.36.199]:587: TLSv1 with cipher RC4-MD5 (128/128 bits) Dec 12 07:51:58 solitare postfix/smtp: 41C7212823B: to=<root@****>, orig_to=<root>, relay=smtp.gmail.com[188.8.131.52]:587, delay=2.4, delays=0.22/0.01/0.62/1.5, dsn=2.0.0, status=sent (250 2.0.0 OK 1292158318 b27sm3067589ana.28)
Fired up a CentOS 5.4 instance on Amazon EC2 and had a look around… In conjunction with item #1 on CentOS I would look to see if you have the following packages installed at a minimum:
cyrus-sasl… There are other
cyrus-sasl-* packages providing separate SASL modules if you should need them but the
-plain should be the bare basics needed.
Leave a comment
- Windows File Permissions and Attributes
- What is the easiest way to upgrade my existing Perl 5.14 to Perl 5.16 on FreeBSD 9 using the ports system?
- Know if mysql has done its job
- Redirect https .com to https .co.uk without a valid SSL cert on .com without DNS change
- Why is it a bad idea to use customer email as from address