Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-05 Thread Viktor Dukhovni via Exim-users
On Wed, Sep 05, 2018 at 03:56:55PM +0100, Klaus Ethgen via Exim-users wrote: > > I suppose your Exim is also linked to GnuTLS? > > Sure, it is the common debian version and Debian is always linking > against gnutls. You can rebuild the source deb against OpenSSL: https://wiki.debian.org/PkgEx

Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-05 Thread Klaus Ethgen via Exim-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Folks, Am Mi den 5. Sep 2018 um 14:41 schrieb Michael Westerburg via Exim-users: > On 09/05/2018 01:00 PM, exim-users-requ...@exim.org wrote: > > After I enabled (themporarily) the random CA they use, I got a > > successfull delivery with the lo

Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-05 Thread Michael Westerburg via Exim-users
Hello Klaus, On 09/05/2018 01:00 PM, exim-users-requ...@exim.org wrote: > After I enabled (themporarily) the random CA they use, I got a > successfull delivery with the log file saying that it was validated via > DANE. thank you very much for sharing your observation. I suppose your Exim is also

Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-05 Thread Michael Westerburg via Exim-users
Hello Viktor, On 09/05/2018 01:00 PM, exim-users-requ...@exim.org wrote: > My advice to the user would be to use a version of Exim that > is linked with OpenSSL and NOT GnuTLS. The Exim DANE support > in combination with GnuTLS is not nearly as well tested or > supported. thank you very much for

Re: [exim] DANE(TA) doesn't work with self signed certificates

2018-09-05 Thread Viktor Dukhovni via Exim-users
> On Sep 5, 2018, at 1:56 AM, Klaus Ethgen via Exim-users > wrote: > > I had the same problem some days ago. > > I do not trust any CA, so no CA is in my truststore. However, some days > ago, I posted to lists.gentoo.org. They have a valid TLSA entry but exim > told me that it can't be valid