I ended up with the configuration you mentioned: OpenACS delivers to localhost:25, where a Postfix that is configured as a "satellite" forwards it to an SMTP server.
(I did not manage to get tcllib/tlctls to work with the client's mailserver, most probably because of issues with their "custom" certificate chain; connection testing via openssl and gnutls did work in the end, but only when pointing them to the right certificate etc... Anyhow, as using Postfix with all its bells and whistles seemed to me as the more convenient option anyway (one can easily inspect the mailqueue, has nice logging of the mailserver-communication, etc...), I decided to not go further down the tcllib road.)
Thank you all for your input!