Yves Goergen writes:

On 22.07.2008 00:23 CE(S)T, Sam Varshavchik wrote:
Yves Goergen writes:
Have there been any changes between Courier-IMAP 4.1.0 and 4.4.1 and Courier-authlib 0.58 and 0.61.0 that affect SSL support?

Yes -- this was documented in ChangeLog and release notes. You should reset TLS_PROTOCOL and TLS_STARTTLS_PROTOCOL to their default values.

Can you please tell me where in the ChangeLog this can be found and what exactly was changed? I wasn't able to find it even as I looked for it. And what is "TLS_PROTOCOL and TLS_STARTTLS_PROTOCOL"? Configuration settings? Where can I find that?

In the imapd-ssl configuration file. The relevant bits from the changelog:

2008-03-12  Gordon Messmer <[EMAIL PROTECTED]>

      •tcpd/libcouriertls.c (tls_create): Default TLS_PROTOCOL=SSL23,
      TLS_CIPHER_LIST=SSLv3:TLSv1:!SSLv2:HIGH:!LOW:!MEDIUM:!EXP:[EMAIL 
PROTECTED]

2008-03-07  Bernd Wurst <[EMAIL PROTECTED]>

      •many: update description of SSL/TLS-related settings in several
       configuration files.

Additionally, in the release notes:

http://sourceforge.net/project/shownotes.php?release_id=64395&group_id=5404

* Update default SSL/TLS settings to be more liberal by default. Affects new installs only, will not touch existing configuration on upgrade.

This was also included in the release announcement.

Attachment: pgpZHi7FyKE19.pgp
Description: PGP signature

-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
_______________________________________________
Courier-imap mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-imap

Reply via email to