Re: [exim] DANE(TA) doesn't work with self signed certificate

2018-09-09 Thread Klaus Ethgen via Exim-users
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, for my installation I can assure that exim is linked to gnutls (libgnutls-dane0 + libgnutls30, currently installed with version 3.5.8). After installing gnutls-bin (and for the undocumented dependencies dns-root-data) and disabling of the root

Re: [exim] DANE(TA) doesn't work with self signed certificates

2018-09-09 Thread Jeremy Harris via Exim-users
On 9/4/18 1:26 PM, Michael Westerburg via Exim-users wrote: > shortly we introduced DANE but soon afterwards we detected problems > sending mails to domains using DANE(TA) with self signed certificates. > Using Exim 4.91 with GnuTLS 3.5.18 (Ubuntu 18.04) here is our setting: > According to the

Re: [exim] DANE(TA) doesn't work with self signed certificates

2018-09-09 Thread Viktor Dukhovni via Exim-users
> On Sep 4, 2018, at 8:26 AM, Michael Westerburg via Exim-users > wrote: > > Hello Exim-users-list, > > shortly we introduced DANE but soon afterwards we detected problems > sending mails to domains using DANE(TA) with self signed certificates. > Using Exim 4.91 with GnuTLS 3.5.18 (Ubuntu

Re: [exim] DANE(TA) doesn't work with self signed certificates

2018-09-09 Thread Viktor Dukhovni via Exim-users
> On Sep 9, 2018, at 10:47 AM, Jeremy Harris via Exim-users > wrote: > > I've managed to reproduce the situation in the Exim testsuite. > With the current master branch, built with OpenSSL it works fine; > built with GnuTLS (v 3.6.3 on Fedora 28) it does not. I did not expect DANE-TA(2)