[Eisfair] mail 1.12.9 - SSL verify

Juergen Edner juergen at eisfair.org
Di Okt 11 11:55:46 CEST 2016


Hallo Silas,

> Einstellungen sind wie folgt:
> 
> ¦ SMTP_SMARTHOST_N               =  1
> ¦   SMTP_SMARTHOST_1_HOST        =  mail.unitybox.de
> ¦   SMTP_SMARTHOST_1_AUTH_TYPE   =  login
> ¦   SMTP_SMARTHOST_1_ADDR        =  foo at bar.de
> ¦   SMTP_SMARTHOST_1_DOMAIN      =
> ¦   SMTP_SMARTHOST_1_USER        =  foo at bar.de
> ¦   SMTP_SMARTHOST_1_PASS        =  ************
> ¦   SMTP_SMARTHOST_1_FORCE_AUTH  =  yes
> ¦   SMTP_SMARTHOST_1_FORCE_TLS   =  yes
> ¦   SMTP_SMARTHOST_1_PORT        =  

wie sind die Parameter SMTP_SERVER_TLS_VERIFY_HOSTS und
SMTP_SERVER_TLS_TRY_VERIFY_HOSTS bei Dir gesetzt? Folgender
Auszug aus der Exim-Dokumentation könnte den Effekt erklären:

  If the tls_verify_certificates option is set on the smtp
  transport, it specifies a collection of expected server
  certificates. These may be the system default set (depending
  on library version), a file or, depending on library version,
  a directory, must name a file or, for OpenSSL only (not
  GnuTLS), a directory. The client verifies the server's
  certificate against this collection, taking into account any
  revoked certificates that are in the list defined by tls_crl.

> Failure to verify fails the TLS connection unless either of
> the tls_verify_hosts or tls_try_verify_hosts options are set.

Gruß Jürgen
-- 
Mail: juergen at eisfair.org


Mehr Informationen über die Mailingliste Eisfair