Re: Patch for TLS 1.2 DHE* cipher support in uwimap/panda?

David B Funk <[email protected]> Wed, 5 Apr 2017 18:52:08 -0500 (CDT)
Newsgroups gmane.mail.imap.uw.c-client
Message-ID <[email protected]>
A couple of years ago I started working on exactly this feature (when the SSL v3 
storm hit).

I extended the env_unix.c module to add config file parsing options for a 
'SSLCipherSuite' parameter that works the same as the Apache version and started 
work on a 'DHParameters' parameter that would work the same as the sendmail 
version.

I got the SSLCipherSuite code working in ssl_unix.c but never completed the 
DHParameters implementation.

Dave

On Wed, 5 Apr 2017, Neal Horman wrote:

> I have already applied the "ssl cipher and protocol options patch" from http://www.freebsd.cz/~dan/patch-DAN-SETSSLCIPHER to my panda fork at
> github.com/nkhorman/panda-imap/tree/ssloptions, and submitted a pull-request to jonabbey/panda-imap a year ago, that is still open.
>
> You may find it useful.
>
> Regards
> Neal Horman
>
> On 4/5/17 5:23 PM, Erik Kangas, Ph.D. wrote:
> > Thanks.
> >
> > We already pre-generate the DH parameters for sendmail and have them sitting around in a dhparms.pem file unique to the server.  I wonder if anyone has
> > created a patch that allows UW IMAP to read such a file and supply the parameters?
> >
> > -Erik Kangas
> > On April 5, 2017 06:07:15 pm EDT, "Dan Lukes" <[email protected]> wrote:
> >
> >
> > Erik Kangas, Ph.D. wrote:
> > > Has anyone found a way to get the Diffie Hellman TLS v1.2 ciphers (e.g..
> > > DHE-RSA-AES256-GCM-SHA384) to work with UW IMAP / Panda IMAP?
> >
> > In order to perform a DH key exchange the server must use a DH group (DH
> > parameters) and generate a DH key.
> >
> > UW IMAP neither generate DH parameters on the fly nor supply the
> > parameters - thus no DHE can be negotiated.
> >
> > You may patch the code and use SSL_CTX_set_options(3) to set
> > SSL_OP_SINGLE_DH_USE option, but generating DH parameters on the fly is
> > extremely time consuming.
> >
> >
> > Dan
> >
> >