Package: dovecot-common
Version: 1.0.rc15-2etch1

The version of Dovecot included in Debian does not present the list of
valid CAs for peer certificates.  Clients such as Thunderbird/Icedove
do not send over the client certificate, causing the connection to hang
until the MUA decides to kill the connection.

This bug was fixed upstream in:

 changeset:   5528:bad62bc7bafc
 user:        Timo Sirainen <[EMAIL PROTECTED]>
 date:        Fri Apr 06 12:30:03 2007 +0300
 summary:     Send list of CA names to client when using 
ssl_verify_client_cert=yes.

The first upstream release with this fix was 1.0.rc30.

Would backporting this fix into stable be a viable option?  If not, stunnel
can be used as a workaround, so it's not too big a deal, but it does make
client certificate usage non-functional for applications that expect a list
of valid CAs.

System is Debian/etch on x86_64 with the volatile archives added.

-- DN
Daniel



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to