Re: is TLS/SSL selection/connection ONLY via port 993?

2004-11-16 Thread OpenMacNews
hi henrique! On Mon, 15 Nov 2004, OpenMacNews wrote: SERVICES { # imap cmd=imapd listen=imap prefork=0 imaps cmd=imapd -s listen=imaps prefork=0 That's not what you want. snip aha. nice clear again. thx! but, why is imapd -s is for IMAP connections that are

Re: is TLS/SSL selection/connection ONLY via port 993?

2004-11-16 Thread Henrique de Moraes Holschuh
On Mon, 15 Nov 2004, OpenMacNews wrote: but, why is imapd -s is for IMAP connections that are externally wrapped by SSL -- considered BAD? Because TLS allows one to select which certificate to present, and SSL doesn't. SSLv3 is pretty much as good as TLSv1 otherwise (but I gather that TLSv1

Re: is TLS/SSL selection/connection ONLY via port 993?

2004-11-16 Thread OpenMacNews
hi again, but, why is imapd -s is for IMAP connections that are externally wrapped by SSL -- considered BAD? Because TLS allows one to select which certificate to present, and SSL doesn't. aha. SSLv2 should not be used at all if you can help it gone. i presume, then, that SSLvX *starts* encrypted

is TLS/SSL selection/connection ONLY via port 993?

2004-11-15 Thread OpenMacNews
hi all, on a MacOSX 10.3.6 sys with: cyrus-imap 2.2.8 cyrus-sasl 2.1.20 i've a canoncial server: testserver.internal.testdomain.com and a virtual domain: mail2.internal.testdomain.com i'm currently auth'ing PLAINTEXT via auxprop+sql (MySQL 4.1.7) i've setup cyrus.conf to LISTEN *only* on

Re: is TLS/SSL selection/connection ONLY via port 993?

2004-11-15 Thread Henrique de Moraes Holschuh
On Mon, 15 Nov 2004, OpenMacNews wrote: SERVICES { # imap cmd=imapd listen=imap prefork=0 imaps cmd=imapd -s listen=imaps prefork=0 That's not what you want. Enable both services, and configure sasl_minimum_layer to 128 (or is that 64? I forgot. See the SASL