Bug#591261: exim4: Certificate based verification does not work.

2010-08-04 Thread Andreas Metzler
On 2010-08-02 Andreas Metzler wrote: [...] > Anyway, the behavior of the two TLS implementation used in exim4 seems > to differ when none of the certificates available are listed as > acceptable by the server. (In the respective handshake for X-509 certs > the server basically says "Please show me

Bug#591261: exim4: Certificate based verification does not work.

2010-08-03 Thread Jon Westgate
Yes, but sadly its not going to do you much good :( The server in question is "smtp.cjsm.net" Its locked down by IP as well as cert. I think it is a version of exim running, but its government run so not much chance of doing anything with it. One of the engineers who was assigned to help me say

Bug#591261: exim4: Certificate based verification does not work.

2010-08-03 Thread Andreas Metzler
On 2010-08-02 Jon Westgate wrote: [...] > I noticed that the CJSM server was sending back "550 you must send a > certificate" error responses when I tested. Could you tell us which smtp server you are connecting to? thanks, cu andreas -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@l

Bug#591261: exim4: Certificate based verification does not work.

2010-08-02 Thread Jon Westgate
Andreas, I just used openssl with pretty much the default settings to generate my cert request, CJSM sent me back a signed x509 cert (pem) which I installed according to the docs at exim.org with maybe a slight modification to the locations, I put them in /etc/exim4/certs. Its got Debian-exim

Bug#591261: exim4: Certificate based verification does not work.

2010-08-02 Thread Andreas Metzler
On 2010-08-01 Jon Westgate wrote: > On 01/08/10 17:35, Andreas Metzler wrote: >> On 2010-08-01 Jon Westgate wrote: >>> Package: exim4 >>> Version: 4.72-1 >>> Severity: important >>> Tags: upstream >>> I have been asked to setup an exim4 server for use with CJSM. >>> https://www.cjsm.net This r

Bug#591261: exim4: Certificate based verification does not work.

2010-08-01 Thread Jon Westgate
Hi Andreas, I have this as my config. tls_certificate = /etc/exim4/mail.fsck.tv-cert.pem tls_privatekey = /etc/exim4/mail.fsck.tv-key.pem log_selector = +tls_peerdn tls_dhparam = /etc/exim4/dh.key tls_advertise_hosts = * #auth_advertise_hosts = ${if eq {$tls_cipher}{}{}{*}} auth_advertise_hosts

Bug#591261: exim4: Certificate based verification does not work.

2010-08-01 Thread Andreas Metzler
On 2010-08-01 Jon Westgate wrote: > Package: exim4 > Version: 4.72-1 > Severity: important > Tags: upstream > I have been asked to setup an exim4 server for use with CJSM. > https://www.cjsm.net This requires that a server (acting as a smart > host in this case) encrypt and sign all emails headed

Bug#591261: exim4: Certificate based verification does not work.

2010-08-01 Thread Jon Westgate
Package: exim4 Version: 4.72-1 Severity: important Tags: upstream I have been asked to setup an exim4 server for use with CJSM. https://www.cjsm.net This requires that a server (acting as a smart host in this case) encrypt and sign all emails headed for CJSM. This is something that according to