Re: tls-1.0 and cyrus-imaps-3.0.8

2018-11-26 Thread Patrick Boutilier
On 11/26/18 12:08 PM, James B. Byrne via Info-cyrus wrote: On Mon, November 26, 2018 10:28, Ken Murchison wrote: I can't reproduce your issue and I don't see where the sslscan output states that TLS1.0 is being advertised.  Can you actually connect using TLS1.0 protocol? No, we cannot.

Re: tls-1.0 and cyrus-imaps-3.0.8

2018-11-26 Thread James B. Byrne via Info-cyrus
On Mon, November 26, 2018 10:28, Ken Murchison wrote: > I can't reproduce your issue and I don't see where the sslscan output > states that TLS1.0 is being advertised.  Can you actually connect > using TLS1.0 protocol? > No, we cannot. I will pass the results of our test to the powers thast

Re: tls-1.0 and cyrus-imaps-3.0.8

2018-11-26 Thread Ken Murchison
I can't reproduce your issue and I don't see where the sslscan output states that TLS1.0 is being advertised.  Can you actually connect using TLS1.0 protocol? openssl s_client -tls1 -connect 215.185.71.17:993 On 11/26/18 10:11 AM, James B. Byrne via Info-cyrus wrote: We have this setting in

tls-1.0 and cyrus-imaps-3.0.8

2018-11-26 Thread James B. Byrne via Info-cyrus
We have this setting in imapd.conf: tls_versions: tls1_1 tls1_2 tls1_3 tls_prefer_server_ciphers: 1 tls_ciphers:HIGH:!aNULL:!MD5:!RC4 We have received notice that port 993 on our IMAP service supports TLS-1.0. When we run sslscan we get this result: # sslscan