Re: SNI on STARTTLS in mailfront

"John R. Levine" <[email protected]> 10 Feb 2019 13:36:49 -0500
Newsgroups gmane.comp.sysutils.bgware
Message-ID <[email protected]>
> Sorry, forgot to str_free for snicertfile and snikeyfile so attached is the 
> updated file.

I tried it, works fine.  I see you also fixed a few minor bugs in my code.

I don't know why the callback you're using works better than the one I was 
using, but I don't see any reason not to use yours if you say it works 
better on your system.

R's,
John

> On 2019-02-10 21:03, Giam Teck Choon wrote:
>>  Hi John,
>>
>>  Many thanks for your kind assistance and precious time.
>>
>>  I have made the SNI work by using
>>  gnutls_handshake_set_post_client_hello_function() instead.  Attached
>>  is my modified starttls-gnutls.c for your review and comments (if
>>  any).
>>
>>  Greatly appreciated!
>>
>>  Once again, thanks.
>>
>>  Kindest regards,
>>  Giam Teck Choon
>>
>>
>>  On 2019-02-08 09:27, Giam Teck Choon wrote:
>>>  Hi John,
>>>
>>>  Thanks a lot for taking time to reply.
>>>
>>>  On 2019-02-08 09:08, John R. Levine wrote:
>>>>  Hard to say.  It works fine on my FreeBSD system, and I can't think of
>>>>  any obvious differences between BSD and Centos.  I assume you've
>>>>  checked the directory and file permissions, and your mailfront daemon
>>>>  can read both the .crt and the .key files?
>>>
>>>  There is no permission and/or ownership issues related to those
>>>  .crt/.key files as one of my testing is to set
>>>  TLS_CERTFILE/TLS_KEYFILE to the same SNI cert/keyfile.
>>>
>>>  Once again, thanks.
>>>
>>>  Kindest regards,
>>>  Giam Teck Choon
>>>
>>>>
>>>>>  I used your starttls-gnutls.c and encountered problems when TLS_CERTDIR
>>>>>  is set and regardless SNI cert/key file exists will show the following
>>>>>  errors:
>>>>>
>>>>>  The below error suppose to use the default TLS_CERTFILE and TLS_KEYFILE
>>>>>  when SNI cert/key files not found:
>>>>> 
>>>>> @  400000005c5bdf89185de07c mailfront[20072]: Starting TLS handshake
>>>>> @  400000005c5bdf89185df7ec mailfront[20072]: No SNI in request,
>>>>>  using default certificate
>>>>> @  400000005c5bdf89185dffbc mailfront[20072]: TLS handshake failed:
>>>>>  Could not negotiate a supported cipher suite.
>>>>>
>>>>>  The below error suppose to use the SNI cert/key files (when exists)
>>>>>  when TLS_CERTDIR is set. I patched your starttls-gnutls.c to show the
>>>>>  SNI key/cert files:
>>>>> 
>>>>> @  400000005c5bdf91377adf8c mailfront[20075]: Starting TLS handshake
>>>>> @  400000005c5bdf9137d23ad4 mailfront[20075]: Using SNI cert/key file
>>>>>  for rat.choon.net
>>>>> @  400000005c5bdf9137d24a74 mailfront[20075]: SNI certfile
>>>>>  /var/qmail/ssl/rat.choon.net/rat.choon.net.crt for rat.choon.net
>>>>> @  400000005c5bdf9137d25244 mailfront[20075]: SNI keyfile
>>>>>  /var/qmail/ssl/rat.choon.net/rat.choon.net.key for rat.choon.net
>>>>> @  400000005c5bdf9137d25a14 mailfront[20075]: TLS handshake failed:
>>>>>  Could not negotiate a supported cipher suite.
>>>>>
>>>>>  If TLS_CERTDIR not set then everything working to use TLS_CERTFILE and
>>>>>  TLS_KEYFILE.
>>>>>
>>>>>  System is CentOS 7. openssl version/release is 1.0.2k-16.el7 and gnutls
>>>>>  version/release is 3.3.29-8.el7.
>>>>>
>>>>>  Thanks for file and any suggestions I can get to make SNI work in my
>>>>>  system.
>>>>>
>>>>>  Kindest regards,
>>>>>  Giam Teck Choon
>>>>>
>>>>>  ---------------------------------------------------------------------
>>>>>  To unsubscribe, e-mail: [email protected]
>>>>>  For additional commands, e-mail: [email protected]
>>>>>
>>>>>
>>>>>
>>>>
>>>>  Regards,
>>>>  John Levine, [email protected], Primary Perpetrator of "The Internet for
>>>>  Dummies",
>>>>  Please consider the environment before reading this e-mail.
>>>>  https://jl.ly
>>>>
>>>>  ---------------------------------------------------------------------
>>>>  To unsubscribe, e-mail: [email protected]
>>>>  For additional commands, e-mail: [email protected]
>>>
>>>  ---------------------------------------------------------------------
>>>  To unsubscribe, e-mail: [email protected]
>>>  For additional commands, e-mail: [email protected]
>>
>>
>>  ---------------------------------------------------------------------
>>  To unsubscribe, e-mail: [email protected]
>>  For additional commands, e-mail: [email protected]
>

Regards,
John Levine, [email protected], Primary Perpetrator of "The Internet for Dummies",
Please consider the environment before reading this e-mail. https://jl.ly