Re: submission vs smtp

Michael Richardson <[email protected]> Thu, 05 Jun 2025 23:00:14 -0400
Newsgroups gmane.mail.nmh.devel
Message-ID <[email protected]>
Ken Hornstein <[email protected]> wrote:
    >> > Fair enough; I'm not saying that the protocol doesn't exist, it just
    >> > seems like it's extremely uncommon.  BTW, does that require the TLS
    >> > client EKU in the client certificate?  It seems like that's going
    >> away > from certificates issued by most public CAs, at least ones that
    >> want to > be part of the Chrome root certificate program.
    >>
    >> I don't care, I pin the certificate on the SMTP relay via fingerprint.

    > Actually, I think you MIGHT need to care; by default the OpenSSL
    > library will reject a client certificate presented in a TLS exchange
    > unless it contains the TLS client certificate EKU.  You need to write a

It's hasn't bit me yet.
Viktor K works on both OpenSSL and Postfix... so if anyone could bash it
right, I think he could...

dyas-[/etc/postfix](3.1.3) mcr 4814 %vc dooku.crt

        X509v3 extensions:
            X509v3 Basic Constraints:
                CA:FALSE
            X509v3 Key Usage:
                Digital Signature, Non Repudiation, Key Encipherment

No EKUs. No EKU extension means no restrictions :-)
signature.asc (application/pgp-signature, 511 B)
-----BEGIN PGP SIGNATURE-----

iQFFBAEBCgAvFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmhCWb4RHG1jckBzYW5k
ZWxtYW4uY2EACgkQgItw+93Q3WVhVgf8C6rK/aon0LauxH2KzHeWGeDk8kjTAOdy
M7gChnJM4OQ6J4BwFtKN3UZkDlj6Z6eOLdj05vldQAeEOUFXbG6N3rfSiywSAOuV
PDsnzPCVS7IMS+nriWjZ2AFPyUNr4KQHZ1KS6rkx3KkXJ4aFny15YUodMeXEECek
yx+1cIHwlVaA/nBpGCS71xW3d4MkS02vyHEVGOuLUtDr+0TRRXSwESnIDpt0+xyQ
/Uj5ICHPxJ3kXR04q1d5ivmK229JzIt5DYRmms2wGwm2t5BKnRDiA8uXkLCEhzxr
s5z3SD+yNCUzus76YgDpel792vFnt/1RrvTrEF0z3BnFk87i679yXw==
=pcoH
-----END PGP SIGNATURE-----