[spamdyke-users] No TLS with openssl elliptic curve cipher suites / pfs perfect forward secrecy

2013-09-07 Thread Marc Gregel
Hi :-) These days where the NSA is watching us I decided to make my server as secure as possible. For qmail it means to use TLS with strong encryption - openssl with - ciphers EDHS:DE for example. The original QMAIL without spamdyke works fine: openssl s_client -starttls smtp -connect

Re: [spamdyke-users] No TLS with openssl elliptic curve cipher suites / pfs perfect forward secrecy

2013-09-09 Thread Marc Gregel
failure, you've probably selected a cipher the server doesn't support. -- Sam Clippinger On Sep 7, 2013, at 3:18 PM, Marc Gregel wrote: Hi :-) These days where the NSA is watching us I decided to make my server as secure as possible. For qmail it means to use TLS with strong encryption

Re: [spamdyke-users] No TLS with openssl elliptic curve cipher suites / pfs perfect forward secrecy

2013-09-10 Thread Marc Gregel
for finding that link, I don't think I would have even looked at a function with tmp in its name! -- Sam Clippinger On Sep 9, 2013, at 3:34 AM, Marc Gregel wrote: Hi Sam, is it possible that the problem is because of missing dh keys? I think (!) spamdyke don't use or call something like

Re: [spamdyke-users] So close and yet so far...

2013-10-22 Thread Marc Gregel
Im also running qmail with plesk and made a quick check: excatyl the same settings like @Arne wrote above! 2013/10/21 Sam Clippinger s...@silence.org I have some good news and some bad news... The good news: spamdyke version 5.0.0 is done, tested and ready. The biggest new feature is

[spamdyke-users] No TLS with 5.0.0

2014-02-03 Thread Marc Gregel
Hi there, after upgrading from 4.3.1 to 5.0.0 I can't use TLS anymore: (TLS-LEVEL=SMTP) No idea where to start the debug, because when I switch back to 4.3.1 everything works fine again. I tried the Version with MYSQL from @Haggy too - same problem, same error. That's the output: openssl

Re: [spamdyke-users] New version: spamdyke MySQL 5.0.0

2014-02-03 Thread Marc Gregel
I had the same problem... tar -xzvf spamdyke-mysql.tgz gzip: stdin: not in gzip format As workaround I unzipped the whole stuff on my windows machine with 7zip, then uploaded it again. 2014-02-04 Arne.Metzger mo...@foni.net: Hi, i get an error when i try to expand the tarfile from

Re: [spamdyke-users] No TLS with 5.0.0

2014-02-04 Thread Marc Gregel
. so it's not localhost:25 but mail.domain.com:25)? It works fine on my server on both port 25 (TLS) and port 465 (SSL), not that that helps. :) -- Sam Clippinger On Feb 3, 2014, at 3:05 PM, Marc Gregel m...@gregel.net wrote: Hi there, after upgrading from 4.3.1 to 5.0.0 I can't use

Re: [spamdyke-users] New version: spamdyke MySQL 5.0.0

2014-02-04 Thread Marc Gregel
Haggy, can you take a look to this error here: https://www.mail-archive.com/spamdyke-users@spamdyke.org/msg03991.html THX :-) 2014-02-03 Haggy i...@haggybear.de: Thanks a lot Sam for you great, great work !!! Based on Sams work the MySQL Version of 5.0.0 has been released:

Re: [spamdyke-users] No TLS with openssl elliptic curve cipher suites / pfs perfect forward secrecy

2014-02-05 Thread Marc Gregel
Just for the records: With Version 5.0.0 and the new option tls-dhparams-file everything works great, TLS uses the strong cipher suites now! Thank you :-) 2013-09-10 Marc Gregel m...@gregel.net: Looking forward to the Update :-) 2013/9/10 Sam Clippinger s...@silence.org I think you're

Re: [spamdyke-users] SMTP Auth Problem

2014-03-18 Thread Marc Gregel
Arne, maybe you can try to set log-level=debug an watch the mail-log for useful infos... 2014-03-18 10:02 GMT+01:00 Arne.Metzger mo...@foni.net: Ok, problem must be spamdyke. I removed spamdyke from smtp_psa and smtps_psa and auth works fine. So, where is my misconfiguration? Am

Re: [spamdyke-users] SMTP Auth Problem

2014-03-18 Thread Marc Gregel
-entry=zen.spamhaus.org reject-missing-sender-mx reject-empty-rdns reject-unresolvable-rdns reject-ip-in-cc-rdns reject-identical-sender-recipient Am 18.03.2014 11:18, schrieb Marc Gregel: Arne, maybe you can try to set log-level=debug an watch the mail-log for useful infos... 2014-03

Re: [spamdyke-users] No TLS with openssl elliptic curve cipher suites / pfs perfect forward secrecy

2014-03-28 Thread Marc Gregel
Eric, at the moment I use the same file the normal qmail installation use. spamdyke.conf: tls-dhparams-file=/var/qmail/control/dh1024.pem 2014-03-28 20:08 GMT+01:00 Eric Shubert e...@shubes.net: On 02/05/2014 06:34 AM, Marc Gregel wrote: Just for the records: With Version 5.0.0