On Sun, 17 Apr 2016 09:59:07 -0700, Gilles Chehade <[email protected]> wrote:

With an elliptic key opensmtpd won't start. I have attached the config, the debug output and my used EC cert+key attached (both are only self signed test certs).

I would kindly ask, if someone has some time to give me a hint, what's wrong with an EC key.


To prevent private keys from leaking in case of a security issue in the
network facing process, OpenSMTPD keeps keys in a separate process and
does some magic to hand over the crypto operations to that process.

Problem is that we don't have the code for EC yet.

I opened a related ticket for relayd that you might want to keep an eye on. [1]

If memory serves correctly OpenSMTPD was going to import that ECC code once it's complete.

[1] https://github.com/reyk/relayd/issues/8

--
You received this mail because you are subscribed to [email protected]
To unsubscribe, send a mail to: [email protected]

Reply via email to