Re: which openssl options are used by exim for a tls connection

Andrew C Aitchison via Exim-users <[email protected]>
Newsgroups gmane.mail.exim.user
Message-ID <[email protected]>
On Fri, 6 Jun 2025, Cyborg via Exim-users wrote:

> Hi,
>
> interessting situation:
>
> Exim returns:
>
> TLS session: (SSL_connect): error:0A00018A:SSL 
> routines::dh key too small
>
> when connecting with s_client to that server, a wired 
> connection is established:
>
> New, TLSv1.2, Cipher is AES256-GCM-SHA384
> Server public key is 2048 bit
> Secure Renegotiation IS supported
> Compression: NONE
> Expansion: NONE
>
> TLS 1.3 Cipher, but TLS 1.2 protocol => should not even 
> work, but it does in s_client.
>
> Which settings are given to openssl by exim, that the 
> connection does not accept the tls 1.3 cipher in the tls 
> 1.2 protocol?
>
> I want to have those in the openssl s_client test too, 
> to better reproduce this.

SWAKS might also give clues.

-- 
Andrew C. Aitchison                      Kendal, UK
                    [email protected]

-- 
## subscription configuration (requires account):
##   https://lists.exim.org/mailman3/postorius/lists/exim-users.lists.exim.org/
## unsubscribe (doesn't require an account):
##   [email protected]
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.