Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2008-01-16 Thread Sebastian Hagedorn
-- [EMAIL PROTECTED] is rumored to have mumbled on 16. Januar 2008 18:03:50 +0100 regarding Re: 2.3.11 STARTTLS broken if tls_ca_file is defined: It works on SSL (port 993). It doesn't works on port 143 with TLS. That makes sense, because AFAIK port 143 is for TLSv1 only. If the c

Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2008-01-16 Thread jc . duss59
ssage du 15/01/08 19:15 > De : "Patrick Boutilier" > A : "Cyrus IMAP" > Copie à : > Objet : Re: 2.3.11 STARTTLS broken if tls_ca_file is defined > > Sebastian Hagedorn wrote: > > Hi, > > > > please don't write to me personally but keep t

Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2008-01-15 Thread Patrick Boutilier
Sebastian Hagedorn wrote: Hi, please don't write to me personally but keep this on the list instead. --On 15. Januar 2008 10:32:16 +0100 [EMAIL PROTECTED] wrote: Here is my log, when i try to open a connection in TLS. Jan 15 10:29:54 imaptest master[1024]: about to exec /usr/local/cyrus/bin/

Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2008-01-15 Thread Sebastian Hagedorn
Hi, please don't write to me personally but keep this on the list instead. --On 15. Januar 2008 10:32:16 +0100 [EMAIL PROTECTED] wrote: Here is my log, when i try to open a connection in TLS. Jan 15 10:29:54 imaptest master[1024]: about to exec /usr/local/cyrus/bin/imapd Jan 15 10:29:54 imapt

Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2008-01-03 Thread Sebastian Hagedorn
-- [EMAIL PROTECTED] is rumored to have mumbled on 2. Januar 2008 17:46:11 +0100 regarding 2.3.11 STARTTLS broken if tls_ca_file is defined: Since I upgraded to 2.3.11, It's seems i've got the same problem. I can use TLS via SSL via imaps on port 993 when i disable the tls_ca_fi

2.3.11 STARTTLS broken if tls_ca_file is defined

2008-01-03 Thread [EMAIL PROTECTED]
Hy all, I wish you an happy new year for 2k8. I've readden this bug on the mailing list, but could not reply cause i removed it. Since I upgraded to 2.3.11, It's seems i've got the same problem. I can use TLS via SSL via imaps on port 993 when i disable the tls_ca_file : imaps[45635]: TLS

Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2008-01-03 Thread Janne Peltonen
I don't know whether this is related, but when I tried to upgrade my frontends to 2.3.11 (from Simon's RPM) yesterday, I ran into quite a mess. After abt half an hour of normal-looking operation, the imapproxy in my Webmail server could no longer negotiate starttls: --clip-- -n 2 17:24:48 pcn5.ma

Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2007-12-17 Thread Sebastian Hagedorn
--On 16. Dezember 2007 15:08:46 +0100 Wolfgang Breyha <[EMAIL PROTECTED]> wrote: I always had tls_ca_file: /etc/pki/tls/certs/ca-bundle.crt defined in my imapd.conf. FWIW: I have a tls_ca_file defined as well. Since I updated to 2.3.11 yesterday STARTTLS didn't work anymore because negotiat

Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2007-12-16 Thread Wolfgang Breyha
Jure Pečar wrote: > Interesting ... works for me with 2.3.11rc1 and sylpheed. Using imaps on > port 993 only. As I mentioned ... IMAPS works for me too. Using STARTTLS on port 143 doesn't work. Regards, Wolfgang -- Wolfgang Breyha <[EMAIL PROTECTED]> | http://www.blafasel.at/ Vienna University C

Re: 2.3.11 STARTTLS broken if tls_ca_file is defined

2007-12-16 Thread Jure Pečar
On Sun, 16 Dec 2007 15:08:46 +0100 Wolfgang Breyha <[EMAIL PROTECTED]> wrote: > Hi! > > I always had > tls_ca_file: /etc/pki/tls/certs/ca-bundle.crt > defined in my imapd.conf. > > Since I updated to 2.3.11 yesterday STARTTLS didn't work anymore because > negotiation failed and timed out. Inte

2.3.11 STARTTLS broken if tls_ca_file is defined

2007-12-16 Thread Wolfgang Breyha
Hi! I always had tls_ca_file: /etc/pki/tls/certs/ca-bundle.crt defined in my imapd.conf. Since I updated to 2.3.11 yesterday STARTTLS didn't work anymore because negotiation failed and timed out. $CLIENT was waiting for more packets from server AFAIS in a tcpdump, where $CLIENT is Thunderbird, gn