Mike Brudenell
2006-May-09 08:41 UTC
[Dovecot] Dovecot 1.0beta7: STARTTLS/SSL not wanting to start
Greetings - I have been looking at Dovecot with a view to migrating us to it from the Washington IMAP server on our Sun systems. To start our testing we first of all installed the pre-built version of Dovecot from the Blastwave (blastwave.org) community supported packaged software site. This was Dovecot 0.99.10.4 and we successfully got it working in our test environment: at first just with regular IMAP, then with STARTTLS too. For the latter we installed a properly signed certificate and it works fine: mail clients can connect, use STARTTLS and then use the encrypted connection. I then downloaded the source code for Dovecot 1.0beta7 and built this myself from source, against the OpenSSL 0.9.8 libraries. I configured Dovecot to use the same certificate and key files as had been used for the earlier version we had just tried out. Whilst 1.0beta7 works fine for regular IMAP it just does not want to start SSL using STARTTLS at all. The error that is getting logged in the syslog file is: <date etc> ... dovecot: [ID 107833 mail.warning] imap-login: SSL_accept() failed: error:140D308A:SSL routines:TLS1_SETUP_KEY_BLOCK:cipher or hash unavailable [ddd.ddd.ddd.ddd] I see in the archived for the list archives that this same problem was asked about for 1.0beta3 but without a solution I could see. Could someone offer any insight/help, please? Cheers, Mike Brudenell -- The Computing Service, University of York, Heslington, York Yo10 5DD, UK Tel:+44-1904-433811 FAX:+44-1904-433740 * Unsolicited commercial e-mail is NOT welcome at this e-mail address. *
Charles Marcus
2006-May-09 10:45 UTC
[Dovecot] Dovecot 1.0beta7: STARTTLS/SSL not wanting to start
On 5/9/2006 Mike Brudenell wrote:> This was Dovecot 0.99.10.4 and we successfully got it working in our > test environment: at first just with regular IMAP, then with STARTTLS > too. For the latter we installed a properly signed certificate and > it works fine: mail clients can connect, use STARTTLS and then use > the encrypted connection.Which mail client(s)? STARTTLS support is broken in Thunderbird, per a recent thread with subject 'START + TLS' -- Best regards, Charles
Timo Sirainen
2006-Jun-11 22:36 UTC
[Dovecot] Dovecot 1.0beta7: STARTTLS/SSL not wanting to start
On Tue, 2006-05-09 at 09:41 +0100, Mike Brudenell wrote:> <date etc> ... dovecot: [ID 107833 mail.warning] imap-login: > SSL_accept() failed: error:140D308A:SSL > routines:TLS1_SETUP_KEY_BLOCK:cipher or hash unavailable [ddd.ddd.ddd.ddd] > > I see in the archived for the list archives that this same problem was > asked about for 1.0beta3 but without a solution I could see. Could someone > offer any insight/help, please?Did you figure this out yet? I can't think of a reason why something in Dovecot's code could cause it. Maybe you had Dovecot 0.99 linked against a different version of OpenSSL or something? -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 191 bytes Desc: This is a digitally signed message part Url : dovecot.org/pipermail/dovecot/attachments/20060611/d088846a/attachment.pgp