Hi folks, at first: thanks very much for the great piece of software!

Coming from Ubuntu I'm now at Arch Linux on my home server. In the fine Arch 
wiki I found opensmtpd as alternative to postfix - with much clearer config 
strategy 


My problem:

Running opensmtpd with an RSA 2048 key for the pki certificate+key is *no* 
problem.

With an elliptic key opensmtpd won't start. I have attached the config, the 
debug output and my used EC cert+key attached (both are only self signed test 
certs).

I would kindly ask, if someone has some time to give me a hint, what's wrong 
with an EC key.

Thanks very much,
best regards,
Martin,




sudo nano /etc/smtpd/smtpd.conf
table aliases file:/etc/smtpd/aliases
table creds   "/etc/smtpd/creds"
pki kk.fritz.box certificate "/etc/smtpd/ec_smtpd.crt"
pki kk.fritz.box key         "/etc/smtpd/ec_smtpd.key"
ciphers EECDH+AES128:EECDH+AES 
curve secp384r1
listen on enp0s10 inet4 port 465 smtps pki kk.fritz.box auth <creds>
accept alias <aliases> deliver to maildir



$ sudo smtpd -dv
debug: init ssl-tree
info: loading pki information for kk.fritz.box
debug: init ca-tree
info: OpenSMTPD 5.7.3p2 starting
debug: bounce warning after 4h
debug: using "fs" queue backend
debug: using "ramqueue" scheduler backend
debug: using "ram" stat backend
info: startup [debug mode]
debug: init ssl-tree
info: loading pki keys for kk.fritz.box
filter: building simple chains...
filter: building complex chains...
filter: done building complex chains
libevent 2.0.22-stable (epoll)
debug: parent_send_config_ruleset: reloading
debug: parent_send_config: configuring pony process
debug: parent_send_config: configuring ca process
debug: init private ssl-tree
debug: ca_engine_init: using RSA privsep engine
debug: smtp: listen on 192.168.0.203 port 465 flags 0x44a pki "kk.fritz.box" ca 
""
debug: queue: done loading queue into scheduler
debug: SSL library error: ssl_ctx_create: error:0607907F:digital envelope 
routines:EVP_PKEY_get1_RSA:expecting an rsa key
debug: SSL library error: ssl_ctx_create: error:140AE006:SSL 
routines:SSL_CTX_use_PrivateKey:EVP lib
fatal: ssl_ctx_create: could not fake private key
warn: ca -> pony: pipe closed
warn: control -> pony: pipe closed
warn: parent -> pony: pipe closed
warn: lka -> pony: pipe closed
warn: queue -> pony: pipe closed
warn: scheduler -> control: pipe closed




-----BEGIN EC PARAMETERS-----
BgUrgQQAIg==
-----END EC PARAMETERS-----
-----BEGIN EC PRIVATE KEY-----
MIGkAgEBBDB4ShhlgEMphHWpsgT4IExLYpRHlctjJDFxPhRPICljpP8IVCbUm9br
SekPl28mFKSgBwYFK4EEACKhZANiAARnWhi/DIcgVdZ5kC4So7FBFRdkq17mGKX1
SSQseyegiVeuxSByzyQ4mPi34026iqssqr7tvVVW0eMN2YK2mImUAqJuUN3Mlu3O
ZtEHKi3Yh09zNpQndpsGSMwRnRKHkO0=
-----END EC PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
MIICvzCCAkagAwIBAgIJAIADOUhl/X5VMAoGCCqGSM49BAMEMIGdMQswCQYDVQQG
EwJERTEVMBMGA1UECAwMa2suZnJpdHouYm94MRUwEwYDVQQHDAxray5mcml0ei5i
b3gxFTATBgNVBAoMDGtrLmZyaXR6LmJveDEVMBMGA1UECwwMa2suZnJpdHouYm94
MRUwEwYDVQQDDAxray5mcml0ei5ib3gxGzAZBgkqhkiG9w0BCQEWDGtrLmZyaXR6
LmJveDAeFw0xNjA0MTMxNzQyNTVaFw0yMTEwMDQxNzQyNTVaMIGdMQswCQYDVQQG
EwJERTEVMBMGA1UECAwMa2suZnJpdHouYm94MRUwEwYDVQQHDAxray5mcml0ei5i
b3gxFTATBgNVBAoMDGtrLmZyaXR6LmJveDEVMBMGA1UECwwMa2suZnJpdHouYm94
MRUwEwYDVQQDDAxray5mcml0ei5ib3gxGzAZBgkqhkiG9w0BCQEWDGtrLmZyaXR6
LmJveDB2MBAGByqGSM49AgEGBSuBBAAiA2IABGdaGL8MhyBV1nmQLhKjsUEVF2Sr
XuYYpfVJJCx7J6CJV67FIHLPJDiY+LfjTbqKqyyqvu29VVbR4w3ZgraYiZQCom5Q
3cyW7c5m0QcqLdiHT3M2lCd2mwZIzBGdEoeQ7aNQME4wHQYDVR0OBBYEFG+ghBw7
XUoc9yKloxH2+AEFQ4BwMB8GA1UdIwQYMBaAFG+ghBw7XUoc9yKloxH2+AEFQ4Bw
MAwGA1UdEwQFMAMBAf8wCgYIKoZIzj0EAwQDZwAwZAIwVVgUIubVdGjEFKJ6I7JW
yWY5jJ3Kgsj7cwjxovQLpmhW7P02TuE261NwoMawk1+PAjBd5So5aO0VgKmEXmBr
AQsHinY8i4LAdTXnvgwSDyRr/6zJV6MkJMylcnHWp0oUX08=
-----END CERTIFICATE-----


-- 
You received this mail because you are subscribed to [email protected]
To unsubscribe, send a mail to: [email protected]

Reply via email to