Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

SMTP with SSL completely broken after iOS 8.4 update

Hello,


I'm an admin for a 500 user email system, about 200 of which are iPhones. All users who have updated to 8.4 are unable to connect to our secure SMTP server. This has never been an issue on previous iOS versions (server unchanged since 2011).


The server uses SMTP over SSL, MD5 Ch/Resp on port 587.


The sendmail server is logging the following on connection attempts:


Jul 3 10:30:36 mail1 sm-mta[23928]: STARTTLS=server, error: accept failed=0, SSL_error=5, errno=0, retry=-1

Jul 3 10:30:36 mail1 sm-mta[23928]: t63FUZlI023928: [***IP***] did not issue MAIL/EXPN/VRFY/ETRN during connection to MSA

iOS 8.4

Posted on Jul 3, 2015 8:35 AM

Reply
Question marked as Best reply

Posted on Jul 4, 2015 3:20 AM

I had this too (1 iPhone and iPad). Workaround: switch off the Handoff feature did the trick for me.

17 replies

Jul 6, 2015 7:21 AM in response to NuclearMedia

This from our email provider (Easyspace) has resolved the issue for our team:


Auto detect account settings: off

Outgoing server: smtp.iomartmail.com (this is the easyspace smtp server so you should insert your own)

Outgoing server port: 587

SSL: Off (up until this point iOS 8.4 we always had to have SSL "ON")

Authentication: Password

Allow insecure authentication: on (this isn't an option so we have used password and the same settings as email)

Username: Full email address (this again is how easyspace run usernames so yours might be different)

Password: *********




Kind regards


Martin

Jul 6, 2015 7:50 AM in response to Mjbowdler

Of course I want my email to work, and I have advised my clients of their options and of the risks. But the fact remains that, if indeed Apple has caused many users to turn off their SSL, even temporarily, they have made the users' information vulnerable and it is therefore a major security flaw. Not to mention, due to the widespread nature of this problem, it's not exactly going to be a secret from those who wish to exploit it.


Eventually, after speaking with two Apple support reps, the issue was elevated to engineering. Hopefully I'll have good news for us all "in the next 2 business days".

Jul 7, 2015 7:10 AM in response to gymsok99

You need to check with your pop email provider as the settings available to you - whether your email will function with SSL off and what other settings need to be selected to allow this (assuming your provider will allow). Our provider (Easyspace) allows the functionality but others may restrict because of the security risk that NuclearMedia has highlighted.


We're all in workaround mode awaiting a proper fix.

Jul 7, 2015 9:55 AM in response to GBat

Apple provided this update: Use modern cryptographic practices when setting up SSL and TLS services on your server - Apple Support


"To ensure security and privacy for your users, and interoperability with Apple products, server administrators should use a group size of 2048 bits or greater when using Diffie-Hellman key exchange. ...devices no longer connect to servers or webpages that are set up using weaker Diffie-Hellman encryption"


If only someone had just shut out IE lt 9 this swiftly.

Jul 8, 2015 3:52 PM in response to drednaught_admin

Easier said than done. I've attempted to follow the instructions from weakdh.org on our authenticated sendmail SMTP relay, total failure. Nothing seems to help with the Apple devices, although following the instructions from weakdh.org restored SMTP for recent Thunderbird and Android clients.


On the off chance that my failure may have been caused by the age of the OS and sendmail that we have been using for years, I threw up a brand new VM (CentOS-7) and tried to configure it using either sendmail or postfix with a new 2048-bit DH key. No luck there either.


So if any sendmail/postfix admins have a clue how to deal with this, please share!

SMTP with SSL completely broken after iOS 8.4 update

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.