Re: SNI on STARTTLS in mailfront
"John R. Levine" <[email protected]> 7 Feb 2019 20:08:52 -0500
| Newsgroups | gmane.comp.sysutils.bgware |
|---|---|
| Message-ID | <[email protected]> |
Hard to say. It works fine on my FreeBSD system, and I can't think of any obvious differences between BSD and Centos. I assume you've checked the directory and file permissions, and your mailfront daemon can read both the .crt and the .key files? > I used your starttls-gnutls.c and encountered problems when TLS_CERTDIR is > set and regardless SNI cert/key file exists will show the following errors: > > The below error suppose to use the default TLS_CERTFILE and TLS_KEYFILE when > SNI cert/key files not found: > > @ 400000005c5bdf89185de07c mailfront[20072]: Starting TLS handshake > @ 400000005c5bdf89185df7ec mailfront[20072]: No SNI in request, using > default certificate > @ 400000005c5bdf89185dffbc mailfront[20072]: TLS handshake failed: Could > not negotiate a supported cipher suite. > > The below error suppose to use the SNI cert/key files (when exists) when > TLS_CERTDIR is set. I patched your starttls-gnutls.c to show the SNI key/cert > files: > > @ 400000005c5bdf91377adf8c mailfront[20075]: Starting TLS handshake > @ 400000005c5bdf9137d23ad4 mailfront[20075]: Using SNI cert/key file for > rat.choon.net > @ 400000005c5bdf9137d24a74 mailfront[20075]: SNI certfile > /var/qmail/ssl/rat.choon.net/rat.choon.net.crt for rat.choon.net > @ 400000005c5bdf9137d25244 mailfront[20075]: SNI keyfile > /var/qmail/ssl/rat.choon.net/rat.choon.net.key for rat.choon.net > @ 400000005c5bdf9137d25a14 mailfront[20075]: TLS handshake failed: Could > not negotiate a supported cipher suite. > > If TLS_CERTDIR not set then everything working to use TLS_CERTFILE and > TLS_KEYFILE. > > System is CentOS 7. openssl version/release is 1.0.2k-16.el7 and gnutls > version/release is 3.3.29-8.el7. > > Thanks for file and any suggestions I can get to make SNI work in my system. > > Kindest regards, > Giam Teck Choon > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > > > Regards, John Levine, [email protected], Primary Perpetrator of "The Internet for Dummies", Please consider the environment before reading this e-mail. https://jl.ly