Re: Problems connecting to imap after upgrade of openssl to v3

"Kristian Duus Østergaard" <[email protected]>
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
Sam Varshavchik writes:

> Kristian Duus Østergaard writes:
>
>> Thanks Sam,
>>
>> After reenabling the legacy and weak algorithms IPv4 will connect.
>>
>> But as my server is dual-stack and prefers IPv6 i get a new error.
>>
>> When I run the following command :
>> # openssl s_client --connect mail.kristian-duus.dk:143 -starttls imap
>>>
>>> removed long listing with the found certificates
>>>
>> ---
>> read R BLOCK
>> 40B73AAA527F0000:error:0A00010B:SSL routines:ssl3_get_record:wrong version  
>> number:../openssl-3.0.11/ssl/record/ssl3_record.c:358:
>
> In the past this is caused generally by one of three reasons.
>
> 1) Non-default TLS settings in the imapd-ssl, pop3d-ssl, or esmtpd-ssl  
> configuration file. Specifically TLS_PROTOCOL, TLS_CIPHER_LIST, and  
> TLS_STARTTLS protocol. If there's something set for them, remove the  
> settings and restart.
>
> 2) Even though the legacy support is now enabled, there's still something in  
> the certificate that causes OpenSSL to keel over.
>
> 3) You're testing OpenSSL from a different machine it might be necessary to  
> enable legacy support on it, too.
>
> However you indicate that only IPv6 appears to have an issue. There's  
> nothing in Courier regarding IPv4 of IPv6 when it comes to using OpenSSL. It  
> takes care of setting up the socket and hands it over to OpenSSL.
>
> The only thing in Courier that's in any way related is certificate file  
> lookups. Different certificates can be set up, ${TLS_CERTFILE}.domain1, and $ 
> {TLS_CERTFILE}.domain2. IP addresses can also be used here; however I would  
> think you'd mention this exotic configuration, were it to be the case with  
> you.
>

I should probably have mentioned that my configuration is very advanced for  
my tiny server. I am hosting three domains having separate internal and  
external IPv6 addresses for each and a shared external IPv4 address. Each  
has it's own Lets Encrypt cert and basically using most of the tricks  
Courier has regarding IP's and certs. So I have <imapd|esmtpd>.pem.<domain| 
ip> as well as <me|ipout|defaultdomain|vhost>.<ip>, but none of this have  
changed the past 6 months.

But I have not changed Couriers configuration when I upgraded openssl this  
configuration worked with openssl-1.1.1u 3 days ago and have been running  
like this for years.

As for the three questions.
1) pop3 have always been disabled. TLS_PROTOCOL, TLS_CIPHER_LIST, and  
TLS_STARTTLS are default for imapd-ssl. For esmtpd I reduced the  
TLS_CIPHER_LIST years ago to make it more secure. And for esmtpd-ssl the  
TLS_PROTOCOL="TLSv1".

2) True - but I was hoping some of the bright minds in here had an I  
idea :-) . The only thing I can come up with is that openssl have changed  
something in the way that it parses ipv6 adressses.

3) The openssl command specified above was run on the server using the  
installed openssl. As for the IPv4 test I was done from my cellphone  
connecting to the internal wifi and I could see the phone's IPv4 address in  
my mail.log.

-- 
Mvh.
  Kristian Duus Østergaard
  M 2211 4772
  E [email protected]


_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.