starttls doesn't work

Markus Gschwendt markus+debianexim at runout.at
Tue Jul 28 00:00:13 BST 2026


On Mon, 2026-07-27 at 12:31 -0700, Brian E. Lavender wrote:
>  /etc/letsencrypt/archive/bigbrie.com/*49.pem
> -rw-r--r-- 1 root root        1891 Jul  7 09:37
> /etc/letsencrypt/archive/bigbrie.com/cert49.pem
> -rw-r--r-- 1 root root        3870 Jul  7 09:37
> /etc/letsencrypt/archive/bigbrie.com/chain49.pem
> -rw-r--r-- 1 root root        5761 Jul  7 09:37
> /etc/letsencrypt/archive/bigbrie.com/fullchain49.pem
> -rw-r--r-- 1 root Debian-exim 1708 Jul  7 09:37
> /etc/letsencrypt/archive/bigbrie.com/privkey49.pem

If I remember correctly, for exim the
certificates should not be readable by 'others'. I have:

4 drwxr-x---  2 root Debian-exim 4096 27. Jul  06:30 .
4 drwxr-x--- 55 root Debian-exim 4096 27. Jul  06:30 ..
4 -rw-r-----  1 root Debian-exim 2143 27. Jul  06:30 cert.pem
4 -rw-r-----  1 root Debian-exim 3870 27. Jul  06:30 chain.pem
8 -rw-r-----  1 root Debian-exim 6013 27. Jul  06:30 fullchain.pem
4 -rw-r-----  1 root Debian-exim 3272 27. Jul  06:30 privkey.pem

This is the reason I copy the files from the letsencrypt dirs
so I can set permissions which are accepted by exim.



More information about the Pkg-exim4-users mailing list