-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello Richard,

Richard Levitte - VMS Whacker wrote:
> In message <[EMAIL PROTECTED]> on Thu, 15 Feb 2007 10:34:23 -0800,
> Kees Cook <[EMAIL PROTECTED]> said:
> 
> kees> 3 years ago, I wrote a patch[1] (and did the TSU[2]) for adding
> kees> these features to s_client.  Can this please be applied to CVS?
> 
> Yes.  Done.  Thank you, and sorry you had to wait 3 years for this to
> happen.

The problem (not only I have) with the patch is
that at least in SMTP and IMAP it is illegal
to start TLS before an initial protocol handshake is done:

* in SMTP doing a STARTTLS without previous EHLO
  will return a
  503 STARTTLS command used when not advertised
* in IMAP doing a STARTLS requires a
  . CAPABILITY
  first.

In both cases the server response should be parsed for
the string "STARTTLS"...

Bye

Goetz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org

iD8DBQFF1xsY2iGqZUF3qPYRAreLAJ9MF6ht6pP2nnzx5pL5x7kTwuOsuACeLyZb
QAA8Z0W0Wd6biFEb0K4D0SA=
=72Vc
-----END PGP SIGNATURE-----
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       openssl-dev@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to