Wednesday, May 22, 2002, 3:46:59 PM, you wrote:

PP> StartTLS can't be done using 'stunnel', as 'stunnel' itself expects
PP> SSL/TLS-encrypted communication starting with establishing the TCP
PP> connection itself.
PP> On the other side 'STARTTLS' opens a 'normal plain text' connection
PP> and requests the other party by issuing this command to _Switch_ to
PP> SSL-encryption.

On the contrary, Stunnel can do STARTTLS. Started with the '-n smtp'
flag stunnel will mimic a SMTP server up until STARTTLS is negotiated
and will then pass traffic to the SMTP service either through redirect
or direct launching of the daemon. It's pretty cool actually.

My problem, as I stated earlier, is that TB! doesn't send EHLO before
sending STARTTLS and stunnel sticks to the RFC pretty closely in
defining how to enable STARTTLS as an SMTP extension.

Thanks for that block on the certs It answered another question I had.

Chris


______________________________________________________
Archives   : http://tbtech.thebat.dutaint.com
Moderators : mailto:[EMAIL PROTECTED]
Unsubscribe: mailto:[EMAIL PROTECTED]

Reply via email to