Hello RedLeg,

   On Sun, 28 Sep 2003 16:45:56 -0500 (29.09.2003 03:45 my local time)
   you wrote about "Big post on SSL/TLS frustration...",
   at least in part:

R> I have this huge post that I've been stirring with since sending to
R> TBUDL where no one seemed to know the answer. The problem is with
R> encrypted (SSL and/or TLS) pop/imap/smtp where the certificate and
R> the server name don't exactly match or may be their own CA or one not
R> recognized globally as a CA.
Well, I'll answer

Big and main problem is lame, brain-damaged admins of such servers,
which think, that everybody everywhere uses only OE with it's "strange"
security policy - accept any ciphers, outdated protocols, any
certificates...

Yes, The Bat _have_ some limitations (only one cipher, reject of
wildcarded certificates), but there aren't _critical_ in case of
normal configured and correctly maintained e-mail infrastructure in
common

More detailed (I couldn't test yet mentioned you _all_ servers, but I
will can do it)

Cotse can't handle work with single The Bat TLS-cipher DES-CBC3-SHA

> More about my ultra-frustrating problem <g> On AKO I can finally direct
> connect to pop and imap, not sure what happened here to allow this, but
> I cannot send SMTP secure... I really need the dialog box that pops up
> and asks to trust this cert to have an enabled 'add to trusted' button.
You'll get it, _if_ problem only with certificate, but before it you can
pass TLS-handshake state... Give me name of this SMTP for exploration

> I really need the dialog box that pops up
> and asks to trust this cert to have an enabled 'add to trusted' button.
> TB continues to complain of the certificate heirarchy...
You'll get it _if_ response from server contain missing certificate in
chain (but usually only own certificate used in session)... If The Bat
can't see missing certificate, that it must offer to add???

> On COTSE, neither the pop nor the smtp work, the failure is during the
> TLS handshake and again is silent- no user prompt to accept nor add to
> trusted.
You have problem _before_ it, problem not in certificate or missing
certificate, more earlier

> Is there really any reason this process has not been made simple to the
> point of fool proof?
No reasons, but there are alot of possible errors and variations

TLS isn't excellent yet, but rather good and - _really_ secure... And
any protection create some additional discomfort
-- 
Best regards,
 Alexander Leschinsky

Powered by The Bat! 2.00.18
Weakened by Windows 98 4.10.2222 A 

- MOTD:
Be wary of the man who urges an action in which he himself incurs no risk.
Joaquin Setanti


________________________________________________________
 Current beta is 2.00.18 | "Using TBBETA" information:
http://www.silverstones.com/thebat/TBUDLInfo.html

Reply via email to