Re: sendmail STARTTLS

Previous thread: Re: pf openbsd 4.2 machine stopped responding by Stuart Henderson on Monday, July 14, 2008 - 2:14 am. (2 messages)

Next thread: acer aspire m1610 by sonjaya on Monday, July 14, 2008 - 3:40 am. (1 message)
From: Stuart Henderson
Date: Monday, July 14, 2008 - 3:27 am

I would go through starttls(8) again from scratch, it does work.

I think the only thing it doesn't _explicitly_ say is to type
your hostname in as the Common Name in the certificate (though
the prompts from openssl should suggest that it's needed).

From: GVG GVG
Date: Monday, July 14, 2008 - 5:06 am

On Mon, Jul 14, 2008 at 12:27 PM, Stuart Henderson <stu@spacehopper.org>
I think I found it! Well the problem was due to the following error:

-------------------
STARTTLS=server: file /etc/mail/CA/key.pem unsafe: Group readable file
--------------------

in the /var/log/maillog file!

Up to now, I didn't get that error cause the debugging option I had defined
wasn't sufficient!

In:

------------------
http://www.sendmail.org/~ca/email/starttls.html
------------------

is stated:

------------------
If this doesn't reveal any problems, increase the LogLevel to 14 and try
again
-----------------

After doing the above modifications I do get '250-STARTTLS' when doing
'telnet localhost 25' etc.

Thanks all of you for your support

From: Hugo Villeneuve
Date: Wednesday, July 16, 2008 - 1:46 am

Maybe I fail at sendmail administration, but I could never make
a DSA certificate work with any product made by Microsoft.

I did try to follow starttls(8) once or twice. But I ended making
RSA certs for sendmail to buy peace. Instruction are in ssl(8).

I know starttls(8) was written in the rsa patent era but I still
do not agree with the DSA certificate recommendation.

Althought, maybe things have changed. I'm an old dog, slow to pick
new tricks.


-- 
Hugo Villeneuve <hugo@EINTR.net>
http://EINTR.net/ 

Previous thread: Re: pf openbsd 4.2 machine stopped responding by Stuart Henderson on Monday, July 14, 2008 - 2:14 am. (2 messages)

Next thread: acer aspire m1610 by sonjaya on Monday, July 14, 2008 - 3:40 am. (1 message)