Re: TLS 1.3 and SNI; test script included
Daniel Kahn Gillmor <[email protected]>
| Newsgroups | gmane.mail.getmail.user |
|---|---|
| Message-ID | <[email protected]> |
On Mon 2019-02-11 09:45:50 -0600, Charles Cazabon wrote: >> Connecting to mail.fsf.org:993 >> TLS 1.3, no SNI - connection failed ([SSL: UNSUPPORTED_PROTOCOL] unsupported >> protocol (_ssl.c:727)) >> TLS 1.3, with SNI - connection failed ([SSL: UNSUPPORTED_PROTOCOL] >> unsupported protocol (_ssl.c:727)) > > Interesting, but not related to SNI. Dunno why the FSF server is failing to > support TLS v.1.3. looks like mail.fsf.org is running a very old version of courier-imap and exim4. It negotiates TLS 1.0 using RSA key exchange, and announces itself as Exim 4.69 (apparently debian lenny https://sources.debian.org/src/exim4/) and Courier-IMAP with copyright years 1998-2008 (also appears to be roughly debian lenny: https://sources.debian.org/src/courier/0.60.0-2/imap/imaplogin.c/#L458) I'd say this mailserver needs some additional love/maintenance -- no one should be running debian lenny on the public Internet in 2019 -- but any failures related to that out-of-date software is not getmail's responsibility. i've cc'ed [email protected] on this message based on their listing at https://www.fsf.org/about/contact/email; hopefully this mailserver can get upgraded. all the best, --dkg
signature.asc
(application/pgp-signature, 227 B)
-----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQTJDm02IAobkioVCed2GBllKa5f+AUCXGHNHAAKCRB2GBllKa5f +JyrAP9bl5my5Fsu+lyEx6h4f/9Ygivu2MpukxAvoEOMOTsYoAD/f7mU1DKWnCM0 JtPPutDdvKif2+O0iOiZIVj9+vYwNQE= =MNzU -----END PGP SIGNATURE-----