[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-18 Thread ChristianEhrhardt
Hi Antonio, IMHO as I eventually understood the case it was essentially a misconfiguration (dropping the includes which made none of the conf.d file enabling ciphers have any effect). The correct state for this is invalid (there is no "close" state unfortunately - it is eventually either

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-17 Thread Antonio J. de Oliveira
Hello Cristian, this is not an invalid bug, in spite it was solved. Either you close it as invalid and I will conduct no more investigation or I will do it and discover which parameter combination was causing it. The bug is real and exists. -- You received this bug notification because you are a

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-13 Thread ChristianEhrhardt
Thanks for the feedback, setting the actual bug to invalid to be closed. ** Changed in: dovecot (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1748245

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread Antonio J. de Oliveira
Current installation is working as expected, no flaws. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1748245 Title: dovecot version 2.2.22 does not honor ssl_cipher_list To manage notifications

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread Antonio J. de Oliveira
Hi, Christian, again Finished setup and ported the installation to the production server. Attached you will find confs I will now try to replicate the bug on the mirror server so as to to spot what is causing this. Have a nice weekend ** Attachment added: "clean config"

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread Antonio J. de Oliveira
Hi, Christian, thanks again. I used a backup server as a test system, with a mirror of postfix-dovecot confon it. Still working on it, purged all dovecot modules, installed from scratch and removed mail-stack-exchange, making all dovecot configuration from scratch. It seems to work as expected.

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread ChristianEhrhardt
Hi Antionio, interesting ... I'm on the same version you reported - 1:2.2.22-1ubuntu2.6 And this is a test system already, I just installed it in a lxd container and it worked right away. Seems we have to find why it doesn't for you. I replaced my config with your tarball. Then I changed your

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread Antonio J. de Oliveira
errata: where above is: I tried on dovecot-sql.conf.ext same result should be: I tried ssl_cipher = HIGH on dovecot-sql.conf.ext same result -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1748245

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread Antonio J. de Oliveira
Thanks Christian for your effort. In fact I was already aware that multiple files had the same configuration in the conf.d folder and had all relevant content changed. In my case: grep -Hrn ssl_cipher_list /etc/dovecot/ /etc/dovecot/conf.d/01-mail-stack-delivery.conf:10:ssl_cipher_list =

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread Antonio J. de Oliveira
somehow the attachment didn't got through, here it is ** Attachment added: "current configuration" https://bugs.launchpad.net/ubuntu/+source/dovecot/+bug/1748245/+attachment/5051743/+files/dovecot.tar.xz -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread ChristianEhrhardt
Thank you for taking the time to report this bug and helping to make Ubuntu better. Since it seems likely to me that this is a local configuration problem, rather than a bug in Ubuntu, I'm marking this bug as Incomplete. Or if you believe that this is really a bug we'd be grateful if you would

[Bug 1748245] Re: dovecot version 2.2.22 does not honor ssl_cipher_list

2018-02-09 Thread ChristianEhrhardt
Hi, prior to the version we have prepped for Bionic the ssl/crypto setup is a bit split (also stopped setting a now outdated cipher list there which makes the default more secure and the config be in one place). So I've seen it happen that late config files overrule early ones and thereby