Re: submission vs smtp
Michael Richardson <[email protected]> Thu, 05 Jun 2025 23:00:14 -0400
| Newsgroups | gmane.mail.nmh.devel |
|---|---|
| Message-ID | <[email protected]> |
Ken Hornstein <[email protected]> wrote: >> > Fair enough; I'm not saying that the protocol doesn't exist, it just >> > seems like it's extremely uncommon. BTW, does that require the TLS >> > client EKU in the client certificate? It seems like that's going >> away > from certificates issued by most public CAs, at least ones that >> want to > be part of the Chrome root certificate program. >> >> I don't care, I pin the certificate on the SMTP relay via fingerprint. > Actually, I think you MIGHT need to care; by default the OpenSSL > library will reject a client certificate presented in a TLS exchange > unless it contains the TLS client certificate EKU. You need to write a It's hasn't bit me yet. Viktor K works on both OpenSSL and Postfix... so if anyone could bash it right, I think he could... dyas-[/etc/postfix](3.1.3) mcr 4814 %vc dooku.crt X509v3 extensions: X509v3 Basic Constraints: CA:FALSE X509v3 Key Usage: Digital Signature, Non Repudiation, Key Encipherment No EKUs. No EKU extension means no restrictions :-)
signature.asc
(application/pgp-signature, 511 B)
-----BEGIN PGP SIGNATURE----- iQFFBAEBCgAvFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmhCWb4RHG1jckBzYW5k ZWxtYW4uY2EACgkQgItw+93Q3WVhVgf8C6rK/aon0LauxH2KzHeWGeDk8kjTAOdy M7gChnJM4OQ6J4BwFtKN3UZkDlj6Z6eOLdj05vldQAeEOUFXbG6N3rfSiywSAOuV PDsnzPCVS7IMS+nriWjZ2AFPyUNr4KQHZ1KS6rkx3KkXJ4aFny15YUodMeXEECek yx+1cIHwlVaA/nBpGCS71xW3d4MkS02vyHEVGOuLUtDr+0TRRXSwESnIDpt0+xyQ /Uj5ICHPxJ3kXR04q1d5ivmK229JzIt5DYRmms2wGwm2t5BKnRDiA8uXkLCEhzxr s5z3SD+yNCUzus76YgDpel792vFnt/1RrvTrEF0z3BnFk87i679yXw== =pcoH -----END PGP SIGNATURE-----