Re: Patch for TLS 1.2 DHE* cipher support in uwimap/panda?
David B Funk <[email protected]> Wed, 5 Apr 2017 18:52:08 -0500 (CDT)
| Newsgroups | gmane.mail.imap.uw.c-client |
|---|---|
| Message-ID | <[email protected]> |
A couple of years ago I started working on exactly this feature (when the SSL v3 storm hit). I extended the env_unix.c module to add config file parsing options for a 'SSLCipherSuite' parameter that works the same as the Apache version and started work on a 'DHParameters' parameter that would work the same as the sendmail version. I got the SSLCipherSuite code working in ssl_unix.c but never completed the DHParameters implementation. Dave On Wed, 5 Apr 2017, Neal Horman wrote: > I have already applied the "ssl cipher and protocol options patch" from http://www.freebsd.cz/~dan/patch-DAN-SETSSLCIPHER to my panda fork at > github.com/nkhorman/panda-imap/tree/ssloptions, and submitted a pull-request to jonabbey/panda-imap a year ago, that is still open. > > You may find it useful. > > Regards > Neal Horman > > On 4/5/17 5:23 PM, Erik Kangas, Ph.D. wrote: > > Thanks. > > > > We already pre-generate the DH parameters for sendmail and have them sitting around in a dhparms.pem file unique to the server. I wonder if anyone has > > created a patch that allows UW IMAP to read such a file and supply the parameters? > > > > -Erik Kangas > > On April 5, 2017 06:07:15 pm EDT, "Dan Lukes" <[email protected]> wrote: > > > > > > Erik Kangas, Ph.D. wrote: > > > Has anyone found a way to get the Diffie Hellman TLS v1.2 ciphers (e.g.. > > > DHE-RSA-AES256-GCM-SHA384) to work with UW IMAP / Panda IMAP? > > > > In order to perform a DH key exchange the server must use a DH group (DH > > parameters) and generate a DH key. > > > > UW IMAP neither generate DH parameters on the fly nor supply the > > parameters - thus no DHE can be negotiated. > > > > You may patch the code and use SSL_CTX_set_options(3) to set > > SSL_OP_SINGLE_DH_USE option, but generating DH parameters on the fly is > > extremely time consuming. > > > > > > Dan > > > >