Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

SMTP TLS Error. 503 Bad Sequence..Please Help.

Status
Not open for further replies.

rwieting

Technical User
Nov 5, 2003
15
US
I need to encrypt emails between myself and a client. I have added a new smtp connector for their domain. After enabling the TLS encryption, I cannot send an email to them. I get an NDR 503 Bad Sequence of commands error. They can send to me. We are using Exchange 2000 behind a PIX firewall. Is this an issue on the clients side?
Any help would be appreciated.
Here is the log:



2005-08-31 17:12:07 - OutboundConnectionResponse SMTPSVC1 *** - 0 - - 220+mail.Client.com+ESMTP+Service+ready 0 0 37 0 16 SMTP - - - -

2005-08-31 17:12:07 mail.Client.com OutboundConnectionCommand SMTPSVC1 *** - 0 EHLO - mail.ME.com 0 0 4 0 16 SMTP - - - -

2005-08-31 17:12:07 mail.Client.com OutboundConnectionResponse SMTPSVC1 *** - 0 - - 250-mail.Client.com+Hello 0 0 23 0 47 SMTP - - - -

2005-08-31 17:12:07 mail.Client.com OutboundConnectionCommand SMTPSVC1 *** - 0 STARTTLS - - 0 0 8 0 47 SMTP - - - -

2005-08-31 17:12:07 mail.Client.com OutboundConnectionResponse SMTPSVC1 *** - 0 - - 220+Ready+to+begin+TLS+Service+ready 0 0 36 0 63 SMTP - - -

2005-08-31 17:12:07 mail.Client.com OutboundConnectionCommand SMTPSVC1 *** - 0 MAIL - FROM:<Myself@ME.com>+SIZE=1888 0 0 4 0 141 SMTP - - - -

2005-08-31 17:12:11 mail.Client.com OutboundConnectionResponse SMTPSVC1 *** - 0 - - 503+Bad+sequence+of+commands 0 0 28 0 4360 SMTP - - - -

2005-08-31 17:12:11 mail.Client.com OutboundConnectionCommand SMTPSVC1 *** - 0 QUIT - - 0 0 4 0 4360 SMTP - - - -
2
005-08-31 17:12:11 mail.Client.com OutboundConnectionResponse SMTPSVC1 *** - 0 - - 221+mail.Client.com+Service+closing+connection 0 0 44 0 4391 SMTP - - - -
 
I've read throught the RFC's that you provided. I've also read through RFC 24879 ( In 2487 it looks like we never get to the TLS negotiation. If this is correct, how do I correct this? Is there a way to force the TLS negotiation?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top