Re: [exim] 8192 length SSL keys

2021-04-12 Thread The Doctor via Exim-users
On Mon, Apr 12, 2021 at 10:53:46PM +0100, Jeremy Harris via Exim-users wrote: > On 12/04/2021 21:39, The Doctor via Exim-users wrote: > > Does Exim support 8192 bit SSL keys? > > Nothing works until it's been tried, and I've not > personally tested 8k (or even 4k) keys in certs. > The regression

Re: [exim] 8192 length SSL keys

2021-04-12 Thread Jeremy Harris via Exim-users
On 12/04/2021 21:39, The Doctor via Exim-users wrote: Does Exim support 8192 bit SSL keys? Nothing works until it's been tried, and I've not personally tested 8k (or even 4k) keys in certs. The regression tests use 2k key for RSA and (it looks like) a nistp521 key for EC. I can't comment on

Re: [exim] 8192 length SSL keys

2021-04-12 Thread Viktor Dukhovni via Exim-users
On Mon, Apr 12, 2021 at 02:39:41PM -0600, The Doctor via Exim-users wrote: > Does Exim support 8192 bit SSL keys? Even 4096-bit RSA keys are noticeably slow/bulky, none of the public CAs are using anything stronger than 4096-bit RSA keys and most are using 2048. Why on earth would you want 8192

[exim] 8192 length SSL keys

2021-04-12 Thread The Doctor via Exim-users
Does Exim support 8192 bit SSL keys? IF so why is Thunderbird choking? -- Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising! Look at Psalms 14 and 53 on Atheism

Re: [exim] "allow_insecure_tainted_data = yes" - was: tainted data issues

2021-04-12 Thread Heiko Schlittermann via Exim-users
Hi Andreas, the problem isn't caused by the new allow_insecure_tainted_data, but these warnings trigger the issue. We're in progress fixing it. -- Heiko signature.asc Description: PGP signature -- ## List details at https://lists.exim.org/mailman/listinfo/exim-users ## Exim details at