Re: getmail and weakdh.org ssl issue

Charles Cazabon <[email protected]>
Newsgroups gmane.mail.getmail.user
Message-ID <[email protected]>
Stefan U. Hegner <[email protected]> wrote:
> 
> ... first a happy new year to you and your loved ones!

Thanks.  And to all on the mailing list from me as well.

> Am 01.01.20 um 06:16 schrieb Charles Cazabon:
>
> > I'm not positive but I think this is complaining about the server's
> > key/certificate.  Are you specifying a client certificate in your config,
> > or a custom certificate chain for verification?

[snip: no client SSL config options]

I'm 99% certain then that this is because of the server's certificate.  I
can't check myself because you've anonymized it.

> What comes closest to showing a problem is the following:
> 
>     Protocol Support:
>     TLSv1.2, TLSv1.1, TLSv1.0
> 
> ... wasn't this weak dh something that showed only in TLSv2.0 and above?

I don't think so.  Newer OpenSSL versions dropped support for some insecure
protocols, but I believe also for some insecure key sizes of other protocols.
Upgrading to buster got you the newer, more secure OpenSSL.  You may be able
to configure OpenSSL to allow this certificate (not sure, haven't done it),
but the best way forward is probably to get the server operator to upgrade
their certificate.

Charles
-- 
-----------------------------------------------------------------------
Charles Cazabon
GPL'ed software available at:               http://pyropus.ca/software/
-----------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.