Bug#591261: exim4: Certificate based verification does not work.

2010-08-04 Thread Andreas Metzler
On 2010-08-02 Andreas Metzler ametz...@downhill.at.eu.org wrote: [...] Anyway, the behavior of the two TLS implementation used in exim4 seems to differ when none of the certificates available are listed as acceptable by the server. (In the respective handshake for X-509 certs the server

Bug#591261: exim4: Certificate based verification does not work.

2010-08-03 Thread Andreas Metzler
On 2010-08-02 Jon Westgate j...@fsck.tv wrote: [...] I noticed that the CJSM server was sending back 550 you must send a certificate error responses when I tested. Could you tell us which smtp server you are connecting to? thanks, cu andreas -- To UNSUBSCRIBE, email to

Bug#591261: exim4: Certificate based verification does not work.

2010-08-03 Thread Jon Westgate
Yes, but sadly its not going to do you much good :( The server in question is smtp.cjsm.net Its locked down by IP as well as cert. I think it is a version of exim running, but its government run so not much chance of doing anything with it. One of the engineers who was assigned to help me says

Bug#591261: exim4: Certificate based verification does not work.

2010-08-02 Thread Andreas Metzler
On 2010-08-01 Jon Westgate j...@fsck.tv wrote: On 01/08/10 17:35, Andreas Metzler wrote: On 2010-08-01 Jon Westgateo...@fsck.tv wrote: Package: exim4 Version: 4.72-1 Severity: important Tags: upstream I have been asked to setup an exim4 server for use with CJSM. https://www.cjsm.net

Bug#591261: exim4: Certificate based verification does not work.

2010-08-02 Thread Jon Westgate
Andreas, I just used openssl with pretty much the default settings to generate my cert request, CJSM sent me back a signed x509 cert (pem) which I installed according to the docs at exim.org with maybe a slight modification to the locations, I put them in /etc/exim4/certs. Its got

Bug#591261: exim4: Certificate based verification does not work.

2010-08-01 Thread Jon Westgate
Package: exim4 Version: 4.72-1 Severity: important Tags: upstream I have been asked to setup an exim4 server for use with CJSM. https://www.cjsm.net This requires that a server (acting as a smart host in this case) encrypt and sign all emails headed for CJSM. This is something that according to

Bug#591261: exim4: Certificate based verification does not work.

2010-08-01 Thread Andreas Metzler
On 2010-08-01 Jon Westgate o...@fsck.tv wrote: Package: exim4 Version: 4.72-1 Severity: important Tags: upstream I have been asked to setup an exim4 server for use with CJSM. https://www.cjsm.net This requires that a server (acting as a smart host in this case) encrypt and sign all emails

Bug#591261: exim4: Certificate based verification does not work.

2010-08-01 Thread Jon Westgate
Hi Andreas, I have this as my config. tls_certificate = /etc/exim4/mail.fsck.tv-cert.pem tls_privatekey = /etc/exim4/mail.fsck.tv-key.pem log_selector = +tls_peerdn tls_dhparam = /etc/exim4/dh.key tls_advertise_hosts = * #auth_advertise_hosts = ${if eq {$tls_cipher}{}{}{*}} auth_advertise_hosts