(In reply to Freek de Kruijf from comment #2) > (In reply to Freek de Kruijf from comment #0) > > postfix gives warnings about deprecated parameters > > In principle "$POSTFIX_SMTP_TLS_CLIENT" == "must" should not be expanded in > > $PCONF -e "smtp_tls_security_level = encrypt". This is a global definition. > > It should be expanded in smtp_tls_policy_maps = lmdb:/etc/postfix/tls_policy > > and only for specific destinations in /etc/postfix/tls_policy. > > So the possibility "must" should be accompanied by specific destinations. > > Setting this parameter to this value also results in amavis not able to > deliver messages back to postfix. Only after resetting the value to "may" > gets these messages again processed by postfix. It is the reverse, postfix can't deliver the message to amavis, because it requires amavis to present STARTTLS.