I have a test server that is working with the bogus pop3d.pem and imapd.pem files that came with courier.  The certificates are working but the client (using Outlook or Outlook Express) gets the error asking if the user wants to continue using the server.  They want to use a real certificate so this will not be an issue.

 

I used the following command to generate a request file for Verisign.

 

openssl req –new –nodes –keyout private.key –out public.csr

 

I then went to Verisign and used the stuff in the public.csr file to generate a 14 day test certificate.  The certificate was sent to me as text in an email but now I don’t know what to do with it.

 

I have been using QVCS-guide for most of my setup.  That guide instructs the following:

 

10.1 SSL support for IMAP and POP3

Your clients might ask you for this feature. It is enabled by default, but the SSL

certificates that come with the default installation of courier-imap are bogus.

The passwords will be protected, but all e-mail clients will throw major fits

before they accept the connection.

Obtain a valid SSL certificate for your domain from a Certificate Authority

like Thawte or Verisign and put it in /usr/lib/courier-imap/share, replacing

the files imapd.pem and pop3d.pem.

 

I took the certificate from my email and pasted it into a blank document pop3d.pem and overwrote the old pop3d.pem and imapd.pem.  That didn’t work. 

I noticed that the bogus certificates had three sections.  ---Begin RSA Private Key--- ---Begin Certificate--- and  ---Begin DH Parameters---.  That gave me the idea that I might need to combine a few files into one.  The certificate I got from Verisign had the section ---Begin Certificate--- and the file private.key had a section called ---Begin RSA Private Key---.  I put those together but with no luck.

 

Any Ideas? I’d love to see this work.

Thank you,

Mark

Reply via email to