On Sun, 17 Apr 2016 09:59:07 -0700, Gilles Chehade <[email protected]>
wrote:
With an elliptic key opensmtpd won't start. I have attached the config,
the debug output and my used EC cert+key attached (both are only self
signed test certs).
I would kindly ask, if someone has some time to give me a hint, what's
wrong with an EC key.
To prevent private keys from leaking in case of a security issue in the
network facing process, OpenSMTPD keeps keys in a separate process and
does some magic to hand over the crypto operations to that process.
Problem is that we don't have the code for EC yet.
I opened a related ticket for relayd that you might want to keep an eye
on. [1]
If memory serves correctly OpenSMTPD was going to import that ECC code
once it's complete.
[1] https://github.com/reyk/relayd/issues/8
--
You received this mail because you are subscribed to [email protected]
To unsubscribe, send a mail to: [email protected]