# Unable to disable TLS

**URL:** <https://community.passbolt.com/t/unable-to-disable-tls/4084>\
**Category:** Installation Issues\
**Created:** [July 19, 2021, 9:12am UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084 "2021-07-19T09:12:55Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 19, 2021, 9:12am UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/1 "2021-07-19T09:12:55Z")

</div>

* * *

## Debug email shell

## Email configuration

## Host: xxxxxxxxxxxxxx Port: 26 Username: Password: \*\*\*\*\*\*\*\*\* TLS: true Sending email from: Passbolt [passbolt@xxxxxxxxx](mailto:passbolt@xxxxxxxxx) Sending email to: ron@xxxxxxxxxxxxx

Trace  
[220] xxxxxxxxxxxxxxxxx ESMTP xxxxxxxxxxxxxxxx

> EHLO localhost  
> [250] xxxxxxxxxxxxxxxxxxxx  
> [250] PIPELINING  
> [250] SIZE 10485760  
> [250] VRFY  
> [250] ETRN  
> [250] ENHANCEDSTATUSCODES  
> [250] 8BITMIME  
> [250] DSN  
> [250] SMTPUTF8  
> [250] CHUNKING  
> Could not send the test email.  
> Error: SMTP server did not accept the connection or trying to connect to non TLS SMTP server using TLS.  
> root@7938369eae56:/usr/share/php/passbolt# echo $EMAIL\_TRANSPORT\_DEFAULT\_TLS  
> false  
> root@7938369eae56:/usr/share/php/passbolt#

For some reason using the CE Docker image I am unable to disable TLS  
Running: [3.2.0] (latest) but noticed the same in the previous version.

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [July 19, 2021, 12:13pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/2 "2021-07-19T12:13:52Z")

</div>

Try this [EMAIL\_TRANSPORT\_DEFAULT\_TLS seemingly ignored](https://community.passbolt.com/t/email-transport-default-tls-seemingly-ignored/2961)

Null instead of false.

---

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 19, 2021, 1:50pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/3 "2021-07-19T13:50:32Z")

</div>

Tried that but did not change a thing

## Open source password manager for teams

## Debug email shell

## Email configuration

## Host:xxxxxxxxxxxxxxx Port: 26 Username: Password: \*\*\*\*\*\*\*\*\* TLS: true Sending email from: Passbolt [passbolt@xxxxxxxxxxxx](mailto:passbolt@xxxxxxxxxxxx) Sending email to: ron@xxxxxxxxxxxxxx

Trace  
[220] xxxxxxxxxxxxxxxxxxx ESMTP xxxxxxxxxx

> EHLO localhost  
> [250] xxxxxxxxxxxxxxxxxx  
> [250] PIPELINING  
> [250] SIZE 10485760  
> [250] VRFY  
> [250] ETRN  
> [250] ENHANCEDSTATUSCODES  
> [250] 8BITMIME  
> [250] DSN  
> [250] SMTPUTF8  
> [250] CHUNKING  
> Could not send the test email.  
> Error: SMTP server did not accept the connection or trying to connect to non TLS SMTP server using TLS.  
> root@af4858aece8d:/usr/share/php/passbolt# echo $EMAIL\_TRANSPORT\_DEFAULT\_TLS  
> null  
> root@af4858aece8d:/usr/share/php/passbolt#

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [July 19, 2021, 6:45pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/4 "2021-07-19T18:45:01Z")

</div>

Where are you setting the environment variable? It seems your changes are not being respected.

---

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 20, 2021, 5:11am UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/5 "2021-07-20T05:11:03Z")

</div>

Hi Garrett,

I set them in the docker-compose file, the container understands them as you can see in the last command. If I do an echo of the environment variable it is there but Passbolt does not use it for the email send function.

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [July 20, 2021, 6:49pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/6 "2021-07-20T18:49:54Z")

</div>

You could try using the env files that are referenced in the stock docker-compose.yml file.

---

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 20, 2021, 7:15pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/7 "2021-07-20T19:15:51Z")

</div>

I tried that too, same result. The container understands the variable, otherwise it would not show with the echo command. The passbolt config file is missing the variable somewhere I guess.

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [July 20, 2021, 7:17pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/8 "2021-07-20T19:17:55Z")

</div>

If you look in the container’s /etc/passbolt you can find some of those config files that should use the variable.

---

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 21, 2021, 9:37am UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/9 "2021-07-21T09:37:26Z")

</div>

I changed the config files but the result is the same, the send mail still shows the same error that it tries to send mail using TLS.

---

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 21, 2021, 12:34pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/10 "2021-07-21T12:34:00Z")

</div>

If I disable TLS in /usr/share/php/passbolt/vendor/cakephp/cakephp/src/Mailer/Transport/SmtpTransport.php

It works by commenting out the part  
try {  
$this-\>\_smtpSend(“EHLO {$host}”, ‘250’);  
/\* if ($config[‘tls’]) {  
$this-\>\_smtpSend(‘STARTTLS’, ‘220’);  
$this-\>\_socket()-\>enableCrypto(‘tls’);  
$this-\>\_smtpSend(“EHLO {$host}”, ‘250’);  
}  
\*/ }

This value “$config[‘tls’]” is probably not functioning correctly.

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [July 22, 2021, 7:12pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/11 "2021-07-22T19:12:49Z")

</div>

@R0N And it’s weird also because the default value is null, I believe. Did you try not including it at all?

---

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 22, 2021, 8:59pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/12 "2021-07-22T20:59:54Z")

</div>

Yes, same result.  
The default is ‘null’ but the “if ($config[‘tls’])” is always true and therefor it always sends the STARTTLS command.

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [July 23, 2021, 12:06am UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/13 "2021-07-23T00:06:37Z")

</div>

@R0N It appears that [cakephp uses ‘false’](https://github.com/cakephp/cakephp/blob/22a41e446904648a8fb8bc6a5f1ab078f264387c/src/Mailer/Transport/SmtpTransport.php#L42) for default value.

[This user](https://github.com/passbolt/passbolt_docker/issues/151#issue-792890305) had to change to null in the old version to make it work.

I’m not clear why it does not work with the environment variable but it must be catching that the variable is set, rather than checking it’s true.

Do other variables in `/env/passbolt.env` work? If not, maybe docker-compose.yml should have `./env/passbolt.env` instead of `env/passbolt.env`.

Instead of commenting out the cakephp source code, try changing the passbolt config file line of tls from:

```php
'tls' => env('EMAIL_TRANSPORT_DEFAULT_TLS', null),

```

to:

```php
'tls' => filter_var(env('EMAIL_TRANSPORT_DEFAULT_TLS', false), FILTER_VALIDATE_BOOLEAN),

```

and also remove this variable from the passbolt.env file, and see if that works.

---

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 23, 2021, 8:18am UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/14 "2021-07-23T08:18:41Z")

</div>

I made the change and that seems to do the trick.  
Now it works as expected.

---

<div class="post-metadata">

**Author:** ![garrett](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/garrett/32/545_2.png) [@garrett](https://community.passbolt.com/u/garrett)\
**Post date:** [July 23, 2021, 12:44pm UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/15 "2021-07-23T12:44:15Z")

</div>

Thanks for the feedback, this helps. I will put in a PR to have this reviewed.

---

<div class="post-metadata">

**Author:** ![R0N](https://avatars.discourse-cdn.com/v4/letter/r/51bf81/32.png) [@R0N](https://community.passbolt.com/u/R0N)\
**Post date:** [July 24, 2021, 7:22am UTC](https://community.passbolt.com/t/unable-to-disable-tls/4084/16 "2021-07-24T07:22:03Z")

</div>

Thanks for your help, hope there is a fix in the next version 🙂
