Re: tls_ca_path and tls_ca_file

2006-10-12 Thread Goetz Babin-Ebell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Leena Heino schrieb: Hello Leena, >> Somewhere in bugzilla.mozilla.org is a feature request >> from me asking for that feature. >> But it was turned down in favor of a planned general overhaul >> of the authentication framework >> (from which I also n

Re: tls_ca_path and tls_ca_file

2006-10-12 Thread Leena Heino
Somewhere in bugzilla.mozilla.org is a feature request from me asking for that feature. But it was turned down in favor of a planned general overhaul of the authentication framework (from which I also never heard again...) I've locally implemented a config switch tls_request_cert, which turns of

Re: tls_ca_path and tls_ca_file

2006-10-11 Thread Goetz Babin-Ebell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andreas Benzing schrieb: > Hello Goetz, Hello Andreas, > After some more research I finally found out that Thunderbird should not > yet try to authenticate with certs anyway. The whole thing is not > completely implemented but cannot be switched off,

Re: tls_ca_path and tls_ca_file

2006-10-11 Thread Andreas Benzing
Hello Goetz, Goetz Babin-Ebell wrote: Andreas Benzing schrieb: Hello once more, Hello Andreas, Goetz Babin-Ebell wrote: Andreas Benzing schrieb: the tls_ca_path directory is used in certificate verification: of the issuer dn of the cert to verify is a checksum calculated, this 32 bit value

Re: tls_ca_path and tls_ca_file

2006-10-10 Thread Goetz Babin-Ebell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andreas Benzing schrieb: > Hello once more, Hello Andreas, > Goetz Babin-Ebell wrote: >> Andreas Benzing schrieb: >> >> the tls_ca_path directory is used in certificate verification: >> of the issuer dn of the cert to verify is a checksum calculated,

Re: tls_ca_path and tls_ca_file

2006-10-10 Thread Andreas Benzing
Hello once more, Goetz Babin-Ebell wrote: Andreas Benzing schrieb: Hello, Hello Andreas, could please somebody tell me what tls_ca_path is good for if it is somehow ignored in the config file? For other servers putting the different CA-certs in one directory is enough but cyrus needs an extr

Re: tls_ca_path and tls_ca_file

2006-10-10 Thread Goetz Babin-Ebell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andreas Benzing schrieb: > Hello, Hello Andreas, > could please somebody tell me what tls_ca_path is good for if it is > somehow ignored in the config file? For other servers putting the > different CA-certs in one directory is enough but cyrus needs

Re: tls_ca_path and tls_ca_file

2006-10-10 Thread Warren Turkal
On Tuesday 10 October 2006 10:50, Andreas Benzing wrote: > could please somebody tell me what tls_ca_path is good for if it is > somehow ignored in the config file? For other servers putting the > different CA-certs in one directory is enough but cyrus needs an extra > file with all of them in a si

tls_ca_path and tls_ca_file

2006-10-10 Thread Andreas Benzing
Hello, could please somebody tell me what tls_ca_path is good for if it is somehow ignored in the config file? For other servers putting the different CA-certs in one directory is enough but cyrus needs an extra file with all of them in a single file. Shouldn't this be the sense of tls_ca_path?