
I seem to be unable to use postfix to send outgoing email to my accounts on outlook.office365.com: Jun 3 13:39:46 xx postfix/smtp[27582]: 428CB46005E: SASL authentication failed; cannot authenticate to server outlook.office365.com[52.98.3.178]: invalid parameter supplied Jun 3 13:39:46 xx postfix/smtp[27582]: connect to outlook.office365.com[2603:1016:200:21::2]:587: Network is unreachable Jun 3 13:39:46 xx postfix/smtp[27582]: 428CB46005E: SASL authentication failed; cannot authenticate to server outlook.office365.com[40.100.151.242]: invalid parameter supplied Jun 3 13:39:46 xx postfix/smtp[27582]: connect to outlook.office365.com[2603:1016:402:815::2]:587: Network is unreachable Jun 3 13:39:46 xx postfix/smtp[27582]: 428CB46005E: to=<brian@linuxpenguins.xyz>, relay=outlook.office365.com[52.98.5.194]:587, delay=17157, delays=17157/0.02/0.42/0, dsn=4.7.0, status=deferred (SASL authentication failed; cannot authenticate to server outlook.office365.com[52.98.5.194]: invalid parameter supplied) If I try to connect manually, it seems OK, but then hangs, if I issue any commands such as "quit" or "ehlo" # openssl s_client -starttls smtp -connect outlook.office365.com:587 CONNECTED(00000003) depth=2 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root CA verify return:1 depth=1 C = US, O = DigiCert Inc, CN = DigiCert Cloud Services CA-1 verify return:1 depth=0 C = US, ST = Washington, L = Redmond, O = Microsoft Corporation, CN = outlook.com verify return:1 --- Certificate chain 0 s:C = US, ST = Washington, L = Redmond, O = Microsoft Corporation, CN = outlook.com i:C = US, O = DigiCert Inc, CN = DigiCert Cloud Services CA-1 1 s:C = US, O = DigiCert Inc, CN = DigiCert Cloud Services CA-1 i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root CA --- Server certificate -----BEGIN CERTIFICATE----- MIII7zCCB9egAwIBAgIQByFh3FvgpIHh+zg3Pb6byjANBgkqhkiG9w0BAQsFADBL MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMSUwIwYDVQQDExxE aWdpQ2VydCBDbG91ZCBTZXJ2aWNlcyBDQS0xMB4XDTE5MDEyMzAwMDAwMFoXDTIx MDEyMzEyMDAwMFowajELMAkGA1UEBhMCVVMxEzARBgNVBAgTCldhc2hpbmd0b24x EDAOBgNVBAcTB1JlZG1vbmQxHjAcBgNVBAoTFU1pY3Jvc29mdCBDb3Jwb3JhdGlv bjEUMBIGA1UEAxMLb3V0bG9vay5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw ggEKAoIBAQDeSMqGxMKrdT5apue8gGt/wSbBs2y3ATuuAhUQtABlYRfFZ+Dc/t6A Ph7y/F8WB3XUYDSX1eLDcUz5C8c1dwyirBjpCd6TlEbXrHWr1+9SHk8oNfxxGsvK RADAZ1k41qfv0A0sCSPM2aItYc1NVAW6xkAdjEUUYLC+8UaO3HWsjTicqctXoDhe G0CqKaKvyi+E/fvXAcP6vLA43sULl95vCmO6MOwIrm5wYlOyM51MAgINKLOWGmCv +x9CrDBEete1+A+6N/GbgbRtVlgIHoz2jtFBcTflk/yVCaawT2UukcFPEQKML7NK XNnqfwLPWjRRhama6JzDIo6qUxmSetyLAgMBAAGjggWuMIIFqjAfBgNVHSMEGDAW gBTdUdCiMXOpc66PtAF+XYxXy5/w9zAdBgNVHQ4EFgQUx4DrZ3bxbeV0Yt5yJf2m PBUhp1QwggJKBgNVHREEggJBMIICPYIWKi5jbG8uZm9vdHByaW50ZG5zLmNvbYIW Ki5ucmIuZm9vdHByaW50ZG5zLmNvbYINKi5ob3RtYWlsLmNvbYIWKi5pbnRlcm5h bC5vdXRsb29rLmNvbYIKKi5saXZlLmNvbYIMKi5vZmZpY2UuY29tgg8qLm9mZmlj ZTM2NS5jb22CDSoub3V0bG9vay5jb22CFyoub3V0bG9vay5vZmZpY2UzNjUuY29t ghthdHRhY2htZW50Lm91dGxvb2subGl2ZS5uZXSCHWF0dGFjaG1lbnQub3V0bG9v ay5vZmZpY2UubmV0giBhdHRhY2htZW50Lm91dGxvb2sub2ZmaWNlcHBlLm5ldIId Y2NzLmxvZ2luLm1pY3Jvc29mdG9ubGluZS5jb22CIWNjcy1zZGYubG9naW4ubWlj cm9zb2Z0b25saW5lLmNvbYILaG90bWFpbC5jb22CFm1haWwuc2VydmljZXMubGl2 ZS5jb22CDW9mZmljZTM2NS5jb22CC291dGxvb2suY29tghJvdXRsb29rLm9mZmlj ZS5jb22CFHN1YnN0cmF0ZS5vZmZpY2UuY29tghhzdWJzdHJhdGUtc2RmLm9mZmlj ZS5jb22CFmF0dGFjaG1lbnRzLm9mZmljZS5uZXSCFyouZnAubWVhc3VyZS5vZmZp Y2UuY29tghphdHRhY2htZW50cy1zZGYub2ZmaWNlLm5ldIIfb3V0bG9vay1zZGYu Z3JhcGgubWljcm9zb2Z0LmNvbTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYI KwYBBQUHAwEGCCsGAQUFBwMCMIGNBgNVHR8EgYUwgYIwP6A9oDuGOWh0dHA6Ly9j cmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydENsb3VkU2VydmljZXNDQS0xLWcxLmNy bDA/oD2gO4Y5aHR0cDovL2NybDQuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0Q2xvdWRT ZXJ2aWNlc0NBLTEtZzEuY3JsMEwGA1UdIARFMEMwNwYJYIZIAYb9bAEBMCowKAYI KwYBBQUHAgEWHGh0dHBzOi8vd3d3LmRpZ2ljZXJ0LmNvbS9DUFMwCAYGZ4EMAQIC MHwGCCsGAQUFBwEBBHAwbjAlBggrBgEFBQcwAYYZaHR0cDovL29jc3B4LmRpZ2lj ZXJ0LmNvbTBFBggrBgEFBQcwAoY5aHR0cDovL2NhY2VydHMuZGlnaWNlcnQuY29t L0RpZ2lDZXJ0Q2xvdWRTZXJ2aWNlc0NBLTEuY3J0MAwGA1UdEwEB/wQCMAAwggF/ BgorBgEEAdZ5AgQCBIIBbwSCAWsBaQB2APZclC/RdzAiFFQYCDCUVo7jTRMZM7/f DC8gC8xO8WTjAAABaHgd6jwAAAQDAEcwRQIgF1Z02okCNMdfAA/wMDeKbKhdydzS dkSsnH8rpBGWXzUCIQDufqGk5/2Thy3HapRsQEh5BF3iDTJVR4WLP3eqxczzdgB2 AId1v+dZfPiMQ5lfvfNu/1aNR1Y2/0q1YMG06v9eoIMPAAABaHgd6tMAAAQDAEcw RQIhAJVln/k+Ukm+bViwEOCqXpkKjPz/LhPSD9PDwtWUmzHBAiBFlqcTJBPTHxkv QurqaKiBYy/faZtk/XYLe1VNrKPbJgB3AG9Tdqwx8DEZ2JkApFEV/3cVHBHZAsEA KQaNsgiaN9kTAAABaHgd64QAAAQDAEgwRgIhAIbkgAlupAAX/L5jIdF55DQiOlrn C/GeuSll9ECeBl1KAiEA8xD05xAJEXEq1uaM7vg0+UtubBrZdfrp14hCJnTrv/ow DQYJKoZIhvcNAQELBQADggEBAA4GFn/7XCf3v6DlAR1AqFebPKz6tawcRcWNqpO2 1e/2aso+3iPa2A5K5UHSRHfGHpDVtX5DidxB0CvUxRTQsIMWG27x3ADrngzbGVS4 usWOXUg0uXCIM5EtVKJO1XFfntE0CsjjkPgy8IvkdqvvnEMEqVu/UyAlTpu02qoZ wrEXATXijvBLo23arDUrM427a7jCO9co0aq0Bzgy9rEACcqE91HiuW/Wmj4yfvsb FzEAG6f68S3OFvV/EFlsnPAnQeHiuRPJsapZGLMHCbl95Vf+sICuSZ0tLY2WXn/y da+aUIZk/bxgwnckDXQAieqDS/G38ZYBr9qKJUc4XDdSlOs= -----END CERTIFICATE----- subject=C = US, ST = Washington, L = Redmond, O = Microsoft Corporation, CN = outlook.com issuer=C = US, O = DigiCert Inc, CN = DigiCert Cloud Services CA-1 --- No client certificate CA names sent Client Certificate Types: RSA sign, DSA sign, ECDSA sign Requested Signature Algorithms: RSA+SHA256:RSA+SHA384:ECDSA+SHA256:ECDSA+SHA384:RSA+SHA512:ECDSA+SHA512 Shared Requested Signature Algorithms: RSA+SHA256:RSA+SHA384:ECDSA+SHA256:ECDSA+SHA384:RSA+SHA512:ECDSA+SHA512 Peer signing digest: SHA256 Peer signature type: RSA Server Temp Key: ECDH, P-256, 256 bits --- SSL handshake has read 4322 bytes and written 484 bytes Verification: OK --- New, TLSv1.2, Cipher is ECDHE-RSA-AES256-GCM-SHA384 Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES256-GCM-SHA384 Session-ID: 88020000683BC082F9307432AB5C52CD83D20B3F5CBA0B9739C5D5240B189D33 Session-ID-ctx: Master-Key: 1B1D5771C727B9BFA2DE2F23B2A46C2FB9139F5382D4A872AADF093BEB38A8B913436520343BC21A68488BA22063367B PSK identity: None PSK identity hint: None SRP username: None Start Time: 1559535616 Timeout : 7200 (sec) Verify return code: 0 (ok) Extended master secret: yes --- 250 SMTPUTF8 quit Eventually I get an error: 451 4.7.0 Timeout waiting for client input [ME1PR01CA0097.ausprd01.prod.outlook.com] read:errno=0 I get similar results if I try to connect to their port 25, with and without ssl. Is this my fault or their fault? Happened now on two different computers. Recently upgraded to Debian buster, not sure if that is relevant or not. Regards