Re: ssl client certificates

2008-09-10 Thread Wesley Craig
Yes, the code lacks at least the ability to specify aspects of the schema. I also noticed that it's using obsolete APIs, tho I'm not sure that's actually a problem. I'd be happy to work with you to get an acceptable patch committed for this code path. :wes On 10 Sep 2008, at 07:48, Johann

Re: ssl client certificates

2008-09-10 Thread Johannes Rußek
Hello Wesley, thanks for the information. I managed to find the code in tls.c and imapd.c and it seems as if it you were right :) which is good news! but it's bad news that we use the UID attribute for the "username", and CN for the actual name (like Johannes Russek in my case). :/ it also doesn't

Re: ssl client certificates

2008-09-09 Thread Wesley Craig
I haven't tried it, but it's certainly meant to. The name of the user should be in the CN attribute of the subject certificate. :wes On 09 Sep 2008, at 08:58, Johannes Rußek wrote: > so cyrus does support ssl client certificates (otherwise there > wouldn't > be errors such as "TLS server eng