which openssl options are used by exim for a tls connection

Cyborg via Exim-users <[email protected]>
Newsgroups gmane.mail.exim.user
Message-ID <[email protected]>
Hi,

interessting situation:

Exim returns:

TLS session: (SSL_connect): error:0A00018A:SSL routines::dh key too small

when connecting with s_client to that server, a wired connection is 
established:

New, TLSv1.2, Cipher is AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE

TLS 1.3 Cipher, but TLS 1.2 protocol => should not even work, but it 
does in s_client.

Which settings are given to openssl by exim, that the connection does 
not accept the tls 1.3 cipher in the tls 1.2 protocol?

I want to have those in the openssl s_client test too, to better 
reproduce this.

best regards,
Cyborg


-- 
## subscription configuration (requires account):
##   https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/
## unsubscribe (doesn't require an account):
##   [email protected]
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
OpenPGP_0x048770A738345DD3.asc (application/pgp-keys, 920 B)
-----BEGIN PGP PUBLIC KEY BLOCK-----

xjMEYNCgKxYJKwYBBAHaRw8BAQdArodafJTXkIv7/P3ZTZS54icoOPq8yd6WKZLH
RovvhLXNHUN5Ym9yZyA8Y3lib3JnMkBiZW5kZXJpcmMuZGU+wpEEExYIADkWIQRj
wwZDcb5ODhI6BhkEh3CnODRd0wUCYNCgKwUJCWYBgAIbAwULCQgHAgYVCAkKCwIF
FgIDAQAACgkQBIdwpzg0XdO0oQEA6OSSsKVmPNngRgL4o1avbAO9L9iOxbCK5YrF
+kF+Qf0BAK3cXzNRCe3scFS6049g1KXllfDgmcqFt82xdPoq6kIEzTFNYXJpdXMg
U2Nod2FyeiAoRXhpbSBUZWFtKSA8Y3lib3JnMkBiZW5kZXJpcmMuZGU+wpYEExYI
AD4WIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCYOhQDgIbAwUJCWYBgAULCQgHAgYV
CgkICwIEFgIDAQIeAQIXgAAKCRAEh3CnODRd01OlAQDbEiFQCTnWYotjUCIbfNZG
3FSJcW6XT5Y3lPUgAXAH8QEApbuKaQ/smdE/rkmD4podYCx3jWH/vGxNn98tSoil
bALOOARg0KArEgorBgEEAZdVAQUBAQdA3q3BHLyIBKM795R7euJegjlZdb1/VlXY
rv1a55TeyDUDAQgHwn4EGBYIACYWIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCYNCg
KwUJCWYBgAIbDAAKCRAEh3CnODRd03hmAPsGanHWXMW+4TDbQwav8/5RuoUGS/Jh
+KIv+f6tV+TdBgD9Fy2zQAfyidW3xB/PslnCKDB62CcIq67mDJdKtkYVdgg=
=LhE8
-----END PGP PUBLIC KEY BLOCK-----
OpenPGP_signature.asc (application/pgp-signature, 236 B)
-----BEGIN PGP SIGNATURE-----

wnsEABYIACMWIQRjwwZDcb5ODhI6BhkEh3CnODRd0wUCaEKatwUDAAAAAAAKCRAEh3CnODRd067j
AP96rsEQHtP6gP9VbQFtdiWJnaoyhHW3xi2WGbVrkuay4QD+MtYgoulbHPgaCIsJiYaswsPxqMz7
qiX12fkiqWnnGQI=
=swy5
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.