[FAQ] Migration up from versions before BETA 1.3.23.130

Heiko Studt <[email protected]>
Newsgroups gmane.network.hamster
Message-ID <[email protected]>
Hi,

You can comment this FAQ and give it out in the english-Hamster-groups and so
on. Use it as you wish.

---http://www.goldpool.org/projekte/MigrSSLTrans.txt
         ______________________________________________
           Hamster-Update  <1.3.23.130 to 1.3.23.140>
         ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

Due to the integration of native SSL-functionality in Hamster Classic 
1.3.23.140 there are changes in the commands HamFetchMail and 
HamSendMail(Auth), which affect many Hamster users.



What to do?
##########

1. *All* Users:
     This part is also important for users who don't use SSL at all.


Every script using one of the commands "HamFetchMail" or "HamSendMail(Auth)" 
have to be checked for parameters _after_ "<LeaveOnServer>" resp. 
"<from-select>".
Those scripts have to be updated.


The new syntax of these commands is:
-----------------------------------

HamFetchMail   ( <server>, <port>, <user>, <pass>, <destuser>, <filter>,
                 <LeaveOnServer>, <SSLMode>, <SSLVerify>, <SSLCaFile> )

HamSendMail    ( <server>, <port>, <from-select>, <to-select>, <SSLMode>,
                 <SSLVerify>, <SSLCaFile> )

HamSendMailAuth( <server>, <port>, <user>, <pass>, <from-select>, 
                 <to-select>, <SSLMode>, <SSLVerify>, <SSLCaFile> )


Important: Not only the count of parameter has changed but also the format!
¯¯¯¯¯¯¯¯¯

    SSLMode:   Integer [0..3]
    SSLVerify: Integer [0..3]
    SSLCaFile: String

That means the full given paramters without using SSL looks like this:

HamFetchMail   ( "pop3-server", "110", "user", "pass", "admin", "", 0, 0, 0, "" )
HamSendMail    ( "smtp-server", "25", ".*", ".*", 0, 0, ""  )
HamSendMailAuth( "smtp-server", "25", "", "", ".*", ".*", 0, 0, "" )



2. For users who had used Stunnel or now want to use SSL:
   ------------------------------------------------------

Most useful to read is the SSL-FAQ (not yet translated) by Phillip Wendler 
and Martin Germann:
http://sites.inka.de/ximera/hamster-ssl-faq.txt

It's also included in the German helpfile of Joern Weber:
http://home.t-online.de/home/joern_weber/HAMSTER_HLP_DE_BETA.ZIP


Some important notes:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

For using SSL two additional dll-files are needed. 
Those couldn't be given with Hamster because of cryptographic (import-)
limitations in some states.

1. libssl32.dll
2. libeay32.dll

Version openssl-0-9-6b and newer is required.

Download (for example):
  http://sites.inka.de/ximera/openssl_dlls.zip


These DLLs have to be copied into main Hamster-Directory or to a 
path included in the windows-%PATH%-Variable.
On starting Hamster it will find these libaries automatically.

After this the main configuration can be found in 
Configuration|General Settings|SSL.


There are two possibilities to save the certificates:
You can use both in addition.

1. In "Path to certificates for verification" you can give a path 
   where all certificates are saved as single files. The names of 
   these files are in the format (as said in SSL-FAQ.):
     "<Hash_of_certificate>.0"
2. In "File with certificates for verification" you can give a 
   PEM-file where you can include all certificates. (according to SSL-FAQ!)


Take in account that all SSL-Settings in 'General Settings' are used as 
default for all SSL-related actions of Hamster whether in menu or 
script-commands. You can override them by configurations in the 
single server-configuration or by the parameters of the script-commands.


2.2  Hamster als Server (lokale Server):
---------------------------------------
 
For using SSL with the local servers you need a certificate with 
private key. If you try to start without such a key-pair Hamster generates 
an error-message, but in older BETAs it starts the server without
SSL. (!)
 
Details about building and installation of certificates can be found 
in the SSL-FAQ.
 


Purging the old SSL-entries
##########################

If you know that the old method of using Stunnel will *never* be 
used anymore, you can delete those entrys:


server.ini: (all)
| UseSSL
| SSL-Port
| sTunnelOption


hamster.ini
| SSLWrapperNotClose
| SSLProg
| SSLStartTimeout
| SSLlocalStartTimeout
| SSLKeyFile
| STunnelOption




Version of document
###################

German:                Mathias Berle <[email protected]>
  22.3.2002
English (Translation): Heiko Studt <[email protected]>
  20.5.2002


-- 
Heiko Studt <[email protected]>
Last Update: 20.5.2002
---

MFG

-- 
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.