Hi folks, at first: thanks very much for the great piece of software! Coming from Ubuntu I'm now at Arch Linux on my home server. In the fine Arch wiki I found opensmtpd as alternative to postfix - with much clearer config strategy
My problem: Running opensmtpd with an RSA 2048 key for the pki certificate+key is *no* problem. With an elliptic key opensmtpd won't start. I have attached the config, the debug output and my used EC cert+key attached (both are only self signed test certs). I would kindly ask, if someone has some time to give me a hint, what's wrong with an EC key. Thanks very much, best regards, Martin, sudo nano /etc/smtpd/smtpd.conf table aliases file:/etc/smtpd/aliases table creds "/etc/smtpd/creds" pki kk.fritz.box certificate "/etc/smtpd/ec_smtpd.crt" pki kk.fritz.box key "/etc/smtpd/ec_smtpd.key" ciphers EECDH+AES128:EECDH+AES curve secp384r1 listen on enp0s10 inet4 port 465 smtps pki kk.fritz.box auth <creds> accept alias <aliases> deliver to maildir $ sudo smtpd -dv debug: init ssl-tree info: loading pki information for kk.fritz.box debug: init ca-tree info: OpenSMTPD 5.7.3p2 starting debug: bounce warning after 4h debug: using "fs" queue backend debug: using "ramqueue" scheduler backend debug: using "ram" stat backend info: startup [debug mode] debug: init ssl-tree info: loading pki keys for kk.fritz.box filter: building simple chains... filter: building complex chains... filter: done building complex chains libevent 2.0.22-stable (epoll) debug: parent_send_config_ruleset: reloading debug: parent_send_config: configuring pony process debug: parent_send_config: configuring ca process debug: init private ssl-tree debug: ca_engine_init: using RSA privsep engine debug: smtp: listen on 192.168.0.203 port 465 flags 0x44a pki "kk.fritz.box" ca "" debug: queue: done loading queue into scheduler debug: SSL library error: ssl_ctx_create: error:0607907F:digital envelope routines:EVP_PKEY_get1_RSA:expecting an rsa key debug: SSL library error: ssl_ctx_create: error:140AE006:SSL routines:SSL_CTX_use_PrivateKey:EVP lib fatal: ssl_ctx_create: could not fake private key warn: ca -> pony: pipe closed warn: control -> pony: pipe closed warn: parent -> pony: pipe closed warn: lka -> pony: pipe closed warn: queue -> pony: pipe closed warn: scheduler -> control: pipe closed -----BEGIN EC PARAMETERS----- BgUrgQQAIg== -----END EC PARAMETERS----- -----BEGIN EC PRIVATE KEY----- MIGkAgEBBDB4ShhlgEMphHWpsgT4IExLYpRHlctjJDFxPhRPICljpP8IVCbUm9br SekPl28mFKSgBwYFK4EEACKhZANiAARnWhi/DIcgVdZ5kC4So7FBFRdkq17mGKX1 SSQseyegiVeuxSByzyQ4mPi34026iqssqr7tvVVW0eMN2YK2mImUAqJuUN3Mlu3O ZtEHKi3Yh09zNpQndpsGSMwRnRKHkO0= -----END EC PRIVATE KEY----- -----BEGIN CERTIFICATE----- MIICvzCCAkagAwIBAgIJAIADOUhl/X5VMAoGCCqGSM49BAMEMIGdMQswCQYDVQQG EwJERTEVMBMGA1UECAwMa2suZnJpdHouYm94MRUwEwYDVQQHDAxray5mcml0ei5i b3gxFTATBgNVBAoMDGtrLmZyaXR6LmJveDEVMBMGA1UECwwMa2suZnJpdHouYm94 MRUwEwYDVQQDDAxray5mcml0ei5ib3gxGzAZBgkqhkiG9w0BCQEWDGtrLmZyaXR6 LmJveDAeFw0xNjA0MTMxNzQyNTVaFw0yMTEwMDQxNzQyNTVaMIGdMQswCQYDVQQG EwJERTEVMBMGA1UECAwMa2suZnJpdHouYm94MRUwEwYDVQQHDAxray5mcml0ei5i b3gxFTATBgNVBAoMDGtrLmZyaXR6LmJveDEVMBMGA1UECwwMa2suZnJpdHouYm94 MRUwEwYDVQQDDAxray5mcml0ei5ib3gxGzAZBgkqhkiG9w0BCQEWDGtrLmZyaXR6 LmJveDB2MBAGByqGSM49AgEGBSuBBAAiA2IABGdaGL8MhyBV1nmQLhKjsUEVF2Sr XuYYpfVJJCx7J6CJV67FIHLPJDiY+LfjTbqKqyyqvu29VVbR4w3ZgraYiZQCom5Q 3cyW7c5m0QcqLdiHT3M2lCd2mwZIzBGdEoeQ7aNQME4wHQYDVR0OBBYEFG+ghBw7 XUoc9yKloxH2+AEFQ4BwMB8GA1UdIwQYMBaAFG+ghBw7XUoc9yKloxH2+AEFQ4Bw MAwGA1UdEwQFMAMBAf8wCgYIKoZIzj0EAwQDZwAwZAIwVVgUIubVdGjEFKJ6I7JW yWY5jJ3Kgsj7cwjxovQLpmhW7P02TuE261NwoMawk1+PAjBd5So5aO0VgKmEXmBr AQsHinY8i4LAdTXnvgwSDyRr/6zJV6MkJMylcnHWp0oUX08= -----END CERTIFICATE----- -- You received this mail because you are subscribed to [email protected] To unsubscribe, send a mail to: [email protected]
