Same issue. gnutls-cli works fine:
$ gnutls-cli <host> -p 993 Processed 168 CA certificate(s). Resolving '<host>'... Connecting to '2600:3c01::f03c:91ff:feae:9cce:993'... - Certificate type: X.509 - Got a certificate list of 3 certificates. - Certificate[0] info: - Certificate[1] info: ... - Certificate[2] info: ... - Status: The certificate is trusted. - Description: (TLS1.2)-(ECDHE-RSA-SECP384R1)-(AES-128-GCM) - Session ID: 4D:F2:43:C7:C1:AE:25:38:79:6E:1E:EB:7A:68:6A:1B:48:AE:0B:4B:C3:22:0F:BB:FE:5F:9F:C0:BE:6D:1D:AE - Ephemeral EC Diffie-Hellman parameters - Using curve: SECP384R1 - Curve size: 384 bits - Version: TLS1.2 - Key Exchange: ECDHE-RSA - Server Signature: RSA-SHA256 - Cipher: AES-128-GCM - MAC: AEAD - Compression: NULL - Handshake was completed - Simple Client Mode: * OK [CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE IDLE AUTH=PLAIN] Dovecot ready. a000 CAPABILITY * CAPABILITY IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE IDLE AUTH=PLAIN a000 OK Pre-login capabilities listed, post-login capabilities have more. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org