{
    "mode": "man",
    "parameter": "tlsmgr",
    "section": "8postfix",
    "url": "https://www.chedong.com/phpMan.php/man/tlsmgr/8postfix/json",
    "generated": "2026-10-09T13:05:28Z",
    "synopsis": "tlsmgr [generic Postfix daemon options]",
    "sections": {
        "NAME": {
            "content": "tlsmgr - Postfix TLS session cache and PRNG manager\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "tlsmgr [generic Postfix daemon options]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "The  tlsmgr(8) manages the Postfix TLS session caches.  It stores and retrieves cache entries\non request by smtpd(8) and smtp(8) processes, and periodically removes entries that have  ex‐\npired.\n\nThe tlsmgr(8) also manages the PRNG (pseudo random number generator) pool. It answers queries\nby the smtpd(8) and smtp(8) processes to seed their internal PRNG pools.\n\nThe  tlsmgr(8)'s PRNG pool is initially seeded from an external source (EGD, /dev/urandom, or\nregular file).  It is updated at configurable pseudo-random intervals with data from the  ex‐\nternal  source.  It is updated periodically with data from TLS session cache entries and with\nthe time of day, and is updated with the time of day whenever a  process  requests  tlsmgr(8)\nservice.\n\nThe tlsmgr(8) saves the PRNG state to an exchange file periodically and when the process ter‐\nminates, and reads the exchange file when initializing its PRNG.\n",
            "subsections": []
        },
        "SECURITY": {
            "content": "The  tlsmgr(8)  is  not security-sensitive. The code that maintains the external and internal\nPRNG pools does not \"trust\" the data that it manipulates, and the code that maintains the TLS\nsession cache does not touch the contents of the cached entries, except for seeding  its  in‐\nternal PRNG pool.\n\nThe  tlsmgr(8)  can  be run chrooted and with reduced privileges.  At process startup it con‐\nnects to the entropy source and exchange file, and creates or truncates the optional TLS ses‐\nsion cache files.\n\nWith Postfix version 2.5 and later, the tlsmgr(8) no longer uses root privileges when opening\ncache files. These files should now be stored under the Postfix-owned datadirectory.   As  a\nmigration aid, an attempt to open a cache file under a non-Postfix directory is redirected to\nthe Postfix-owned datadirectory, and a warning is logged.\n",
            "subsections": []
        },
        "DIAGNOSTICS": {
            "content": "Problems and transactions are logged to syslogd(8) or postlogd(8).\n",
            "subsections": []
        },
        "BUGS": {
            "content": "There  is  no automatic means to limit the number of entries in the TLS session caches and/or\nthe size of the TLS cache files.\n",
            "subsections": []
        },
        "CONFIGURATION PARAMETERS": {
            "content": "Changes to main.cf are not  picked  up  automatically,  because  tlsmgr(8)  is  a  persistent\nprocesses.  Use the command \"postfix reload\" after a configuration change.\n\nThe  text below provides only a parameter summary. See postconf(5) for more details including\nexamples.\n",
            "subsections": []
        },
        "TLS SESSION CACHE": {
            "content": "",
            "subsections": [
                {
                    "name": "lmtp_tls_loglevel (0)",
                    "content": "The LMTP-specific version of the smtptlsloglevel configuration parameter.\n"
                },
                {
                    "name": "lmtp_tls_session_cache_database (empty)",
                    "content": "The LMTP-specific version of the smtptlssessioncachedatabase configuration parame‐\nter.\n"
                },
                {
                    "name": "lmtp_tls_session_cache_timeout (3600s)",
                    "content": "The LMTP-specific version of the smtptlssessioncachetimeout configuration  parame‐\nter.\n"
                },
                {
                    "name": "smtp_tls_loglevel (0)",
                    "content": "Enable additional Postfix SMTP client logging of TLS activity.\n"
                },
                {
                    "name": "smtp_tls_session_cache_database (empty)",
                    "content": "Name of the file containing the optional Postfix SMTP client TLS session cache.\n"
                },
                {
                    "name": "smtp_tls_session_cache_timeout (3600s)",
                    "content": "The expiration time of Postfix SMTP client TLS session cache information.\n"
                },
                {
                    "name": "smtpd_tls_loglevel (0)",
                    "content": "Enable additional Postfix SMTP server logging of TLS activity.\n"
                },
                {
                    "name": "smtpd_tls_session_cache_database (empty)",
                    "content": "Name of the file containing the optional Postfix SMTP server TLS session cache.\n"
                },
                {
                    "name": "smtpd_tls_session_cache_timeout (3600s)",
                    "content": "The expiration time of Postfix SMTP server TLS session cache information.\n"
                }
            ]
        },
        "PSEUDO RANDOM NUMBER GENERATOR": {
            "content": "",
            "subsections": [
                {
                    "name": "tls_random_source (see 'postconf -d' output)",
                    "content": "The external entropy source for the in-memory tlsmgr(8) pseudo random number generator\n(PRNG) pool.\n"
                },
                {
                    "name": "tls_random_bytes (32)",
                    "content": "The  number of bytes that tlsmgr(8) reads from $tlsrandomsource when (re)seeding the\nin-memory pseudo random number generator (PRNG) pool.\n"
                },
                {
                    "name": "tls_random_exchange_name (see 'postconf -d' output)",
                    "content": "Name of the pseudo random number generator (PRNG) state file  that  is  maintained  by\ntlsmgr(8).\n"
                },
                {
                    "name": "tls_random_prng_update_period (3600s)",
                    "content": "The  time  between attempts by tlsmgr(8) to save the state of the pseudo random number\ngenerator (PRNG) to the file specified with $tlsrandomexchangename.\n"
                },
                {
                    "name": "tls_random_reseed_period (3600s)",
                    "content": "The maximal time between attempts by tlsmgr(8) to re-seed the in-memory pseudo  random\nnumber generator (PRNG) pool from external sources.\n"
                }
            ]
        },
        "MISCELLANEOUS CONTROLS": {
            "content": "",
            "subsections": [
                {
                    "name": "config_directory (see 'postconf -d' output)",
                    "content": "The default location of the Postfix main.cf and master.cf configuration files.\n"
                },
                {
                    "name": "data_directory (see 'postconf -d' output)",
                    "content": "The  directory  with  Postfix-writable  data files (for example: caches, pseudo-random\nnumbers).\n"
                },
                {
                    "name": "daemon_timeout (18000s)",
                    "content": "How much time a Postfix daemon process may take to handle a request before it is  ter‐\nminated by a built-in watchdog timer.\n"
                },
                {
                    "name": "process_id (read-only)",
                    "content": "The process ID of a Postfix command or daemon process.\n"
                },
                {
                    "name": "process_name (read-only)",
                    "content": "The process name of a Postfix command or daemon process.\n"
                },
                {
                    "name": "syslog_facility (mail)",
                    "content": "The syslog facility of Postfix logging.\n"
                },
                {
                    "name": "syslog_name (see 'postconf -d' output)",
                    "content": "A  prefix  that is prepended to the process name in syslog records, so that, for exam‐\nple, \"smtpd\" becomes \"prefix/smtpd\".\n\nAvailable in Postfix 3.3 and later:\n"
                },
                {
                    "name": "service_name (read-only)",
                    "content": "The master.cf service name of a Postfix daemon process.\n"
                }
            ]
        },
        "SEE ALSO": {
            "content": "smtp(8), Postfix SMTP client\nsmtpd(8), Postfix SMTP server\npostconf(5), configuration parameters\nmaster(5), generic daemon options\nmaster(8), process manager\npostlogd(8), Postfix logging\nsyslogd(8), system logging\n",
            "subsections": []
        },
        "README FILES": {
            "content": "Use \"postconf readmedirectory\" or \"postconf htmldirectory\" to locate this information.\nTLSREADME, Postfix TLS configuration and operation\n",
            "subsections": []
        },
        "LICENSE": {
            "content": "The Secure Mailer license must be distributed with this software.\n",
            "subsections": []
        },
        "HISTORY": {
            "content": "This service was introduced with Postfix version 2.2.\n\nAUTHOR(S)\nLutz Jaenicke\nBTU Cottbus\nAllgemeine Elektrotechnik\nUniversitaetsplatz 3-4\nD-03044 Cottbus, Germany\n\nAdapted by:\nWietse Venema\nIBM T.J. Watson Research\nP.O. Box 704\nYorktown Heights, NY 10598, USA\n\nWietse Venema\nGoogle, Inc.\n111 8th Avenue\nNew York, NY 10011, USA\n\nTLSMGR(8postfix)",
            "subsections": []
        }
    },
    "summary": "tlsmgr - Postfix TLS session cache and PRNG manager",
    "flags": [],
    "examples": [],
    "see_also": [
        {
            "name": "smtp",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/smtp/8/json"
        },
        {
            "name": "smtpd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/smtpd/8/json"
        },
        {
            "name": "postconf",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/postconf/5/json"
        },
        {
            "name": "master",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/master/5/json"
        },
        {
            "name": "master",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/master/8/json"
        },
        {
            "name": "postlogd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/postlogd/8/json"
        },
        {
            "name": "syslogd",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/syslogd/8/json"
        }
    ]
}