Re: getmail and weakdh.org ssl issue
Charles Cazabon <[email protected]>
| Newsgroups | gmane.mail.getmail.user |
|---|---|
| Message-ID | <[email protected]> |
Stefan U. Hegner <[email protected]> wrote: > > ... first a happy new year to you and your loved ones! Thanks. And to all on the mailing list from me as well. > Am 01.01.20 um 06:16 schrieb Charles Cazabon: > > > I'm not positive but I think this is complaining about the server's > > key/certificate. Are you specifying a client certificate in your config, > > or a custom certificate chain for verification? [snip: no client SSL config options] I'm 99% certain then that this is because of the server's certificate. I can't check myself because you've anonymized it. > What comes closest to showing a problem is the following: > > Protocol Support: > TLSv1.2, TLSv1.1, TLSv1.0 > > ... wasn't this weak dh something that showed only in TLSv2.0 and above? I don't think so. Newer OpenSSL versions dropped support for some insecure protocols, but I believe also for some insecure key sizes of other protocols. Upgrading to buster got you the newer, more secure OpenSSL. You may be able to configure OpenSSL to allow this certificate (not sure, haven't done it), but the best way forward is probably to get the server operator to upgrade their certificate. Charles -- ----------------------------------------------------------------------- Charles Cazabon GPL'ed software available at: http://pyropus.ca/software/ -----------------------------------------------------------------------