Re: getmail and weakdh.org ssl issue
"Stefan U. Hegner" <[email protected]>
| Newsgroups | gmane.mail.getmail.user |
|---|---|
| Message-ID | <[email protected]> |
Hi Charles, ... first a happy new year to you and your loved ones! Am 01.01.20 um 06:16 schrieb Charles Cazabon: > Stefan U. Hegner <[email protected]> wrote: >> getmailrc-xxx: socket error ([SSL: DH_KEY_TOO_SMALL] dh key too >> small (_ssl.c:727)) > I'm not positive but I think this is complaining about the server's > key/certificate. Are you specifying a client certificate in your config, or a > custom certificate chain for verification? The config looks as follows: [retriever] type = SimplePOP3SSLRetriever server = mail.xxx.xx username = [email protected] password = xxxxx delete_dup_msgids = yes [destination] type = MDA_external path = /usr/sbin/sendmail arguments = ("-i", "-bm", "[email protected]) unixfrom = true [options] verbose = 1 delete_after = 31 read_all = no ... and that's been working for a couple of years ... > Can you run an SSL certificate verification/info tool against the server's > certificate to dump it? I tried a few web-based checker. What comes closest to showing a problem is the following: Protocol Support: TLSv1.2, TLSv1.1, TLSv1.0 ... wasn't this weak dh something that showed only in TLSv2.0 and above? However, I still got no clue what to do. Are there options for the config file I might want to try (except switching of SSL, of course)? Cheers, Stefan. -- Stefan U. Hegner <[email protected]> * * * D-32584 Löhne --- good ole Germany internet: http://www.hegner-web.de * * * GPG-Key | 048D 7F64 0BEB 73B1 2725 F-Print | C05E 4F77 9674 EF11 55FE
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEAREIAB0WIQT+GGitkDFcADNIW0vJL5J2DCWe2AUCXgzJAgAKCRDJL5J2DCWe 2P62AP9oUA6U+AW51sL6OoH7d+eBp4W+SSdA9tl7Q1R8O+WyXQEAv2ETwFq/G+6J SDE+LN8WTpB+iu+3tNv618BwNXZRL+4= =PjUd -----END PGP SIGNATURE-----