On Thu, Apr 14, 2016 at 07:13:27PM +0200, Martin wrote:
> Hi folks, at first: thanks very much for the great piece of software!
>
> Coming from Ubuntu I'm now at Arch Linux on my home server. In the fine Arch 
> wiki I found opensmtpd as alternative to postfix - with much clearer config 
> strategy 
> 

good to hear ;)


> My problem:
> 
> Running opensmtpd with an RSA 2048 key for the pki certificate+key is *no* 
> problem.
> 
> With an elliptic key opensmtpd won't start. I have attached the config, the 
> debug output and my used EC cert+key attached (both are only self signed test 
> certs).
> 
> I would kindly ask, if someone has some time to give me a hint, what's wrong 
> with an EC key.
> 

To prevent private keys from leaking in case of a security issue in the
network facing process, OpenSMTPD keeps keys in a separate process and
does some magic to hand over the crypto operations to that process.

Problem is that we don't have the code for EC yet.


-- 
Gilles Chehade

https://www.poolp.org                                          @poolpOrg

-- 
You received this mail because you are subscribed to [email protected]
To unsubscribe, send a mail to: [email protected]

Reply via email to