Re: [SM-USERS] Problem with STARTTLS

2018-05-02 Thread Paul Lesniewski
On Mon, April 30, 2018 7:57 pm, James B. Byrne wrote: > > On Mon, April 30, 2018 13:22, Paul Lesniewski wrote: > >>> Verify return code: 19 (self signed certificate in certificate >>> chain) >> >> That's likely your problem - SquirrelMail needs the homebrewed CA or you need to adjust the veri

Re: [SM-USERS] Problem with STARTTLS

2018-05-02 Thread Paul Lesniewski
On Mon, April 30, 2018 7:57 pm, James B. Byrne wrote: > > On Mon, April 30, 2018 13:22, Paul Lesniewski wrote: > >>> Verify return code: 19 (self signed certificate in certificate >>> chain) >> >> That's likely your problem - SquirrelMail needs the homebrewed CA or >> you need to adjust the v

Re: [SM-USERS] Problem with STARTTLS

2018-04-30 Thread James B. Byrne via squirrelmail-users
On Mon, April 30, 2018 13:22, Paul Lesniewski wrote: >> Verify return code: 19 (self signed certificate in certificate >> chain) > > That's likely your problem - SquirrelMail needs the homebrewed CA or > you need to adjust the verify options. > That message is completely misleading. Every C

Re: [SM-USERS] Problem with STARTTLS

2018-04-30 Thread Paul Lesniewski
On Mon, April 30, 2018 3:46 pm, James B. Byrne wrote: > > On Sat, April 28, 2018 14:45, Paul Lesniewski wrote: > >> >> Off the top of my head, I'd suggest trying to write a small POC >> script to see if you can make the connection without any other >> code in the way. But it does seem clear that

Re: [SM-USERS] Problem with STARTTLS

2018-04-30 Thread James B. Byrne via squirrelmail-users
On Sat, April 28, 2018 14:45, Paul Lesniewski wrote: > > Off the top of my head, I'd suggest trying to write a small POC > script to see if you can make the connection without any other > code in the way. But it does seem clear that the IMAP server does > not in fact have the CA's certificate, de

Re: [SM-USERS] Problem with STARTTLS

2018-04-28 Thread Paul Lesniewski
On 2018年04月26日 13:21, James B. Byrne via squirrelmail-users wrote: > We have a currently running Squirremail (1.4.22-5.el6) (SM) running on > Apache-2.2.15 all hosted on a CentOS-6.9 x64 box. It connects via TLS > (:993) to a Cyrus_IMAP-2.3.16 service running on a different > CentOS-6.9 x64 host

[SM-USERS] Problem with STARTTLS

2018-04-26 Thread James B. Byrne via squirrelmail-users
We have a currently running Squirremail (1.4.22-5.el6) (SM) running on Apache-2.2.15 all hosted on a CentOS-6.9 x64 box. It connects via TLS (:993) to a Cyrus_IMAP-2.3.16 service running on a different CentOS-6.9 x64 host. Both services employ X509 certificates issued by our own CA. All of the va