<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>www.ritlabs.com [Topic: SSL with SMTP/IMAP not working]</title>
		<link>http://www.ritlabs.com</link>
		<description>New posts in SSL with SMTP/IMAP not working of  forum at www.ritlabs.com [www.ritlabs.com]</description>
		<language>en</language>
		<docs>http://backend.userland.com/rss2</docs>
		<lastBuildDateTag>Tue, 26 Oct 2004 18:19:46 +0300</lastBuildDateTag>		<item>
			<title>SSL with SMTP/IMAP not working</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic382/message1479/">SSL with SMTP/IMAP not working</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			found it!<br /><br />you MUST NOT use any subject alternate names!<br />and some mail clients accept the domain name only as CN. &nbsp;RFC 2487 gives the advice to only use the domain name and not the FQDN as CN. &nbsp;this is wrong for TB. &nbsp;use the FQDN!<br /><br />don't ask me why...<br /><br />-closed-<br /><br /> <br />
			<i>26 October 2004 18:19:46, <a href="http://www.ritlabs.com/en/forums/">Ruppert von Teutul</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic382/message1479/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic382/message1479/</guid>
			<pubDate>Tue, 26 Oct 2004 18:19:46 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>SSL with SMTP/IMAP not working</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic382/message1473/">SSL with SMTP/IMAP not working</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			to make it easier:<br /><br />who has a working openssl self-signed certificate for his servers and uses it with TB?<br />how did you generate it?<br />there seems to be something special in case of TB!<br /><br /> <br />
			<i>26 October 2004 14:12:29, <a href="http://www.ritlabs.com/en/forums/">Ruppert von Teutul</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic382/message1473/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic382/message1473/</guid>
			<pubDate>Tue, 26 Oct 2004 14:12:29 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>SSL with SMTP/IMAP not working</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic382/message1454/">SSL with SMTP/IMAP not working</a></b> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			-SUDDENLY MY POSTING DISAPPEARED-<br /><br />Hi, <br /><br />did anybody succeed in using openssl self-signed certificates with TB (v2.x)? <br /><br />Some time ago we set up a mail server with TLS support. We give the CA's certificate to anybody using our mail server for import into the WinXP root certificate store. Everything worked fine for all mail clients (there are Outlook and one other I don't remember). <br /><br />Now we have one person using TB. He is unable to connect to our mail server. He is unable to send mail (SMTP) and unable to receive mail (IMAP). We are using TLS directly from the start (no STARTTLS needed). <br /><br />He gets messages like this in his TB log: <br />26.10.2004, 11:37:01: IMAP - Initiating TLS handshake <br />!26.10.2004, 11:37:01: IMAP - TLS handshake failure. Unsupported certificate <br />!26.10.2004, 11:37:01: IMAP - Could not connect to the server <br />26.10.2004, 11:37:29: SEND - sending mail messages - 1 messages in queue <br />26.10.2004, 11:37:29: SEND - Initiating TLS handshake <br />!26.10.2004, 11:37:29: SEND - TLS handshake failure. Unsupported certificate <br />26.10.2004, 11:37:29: SEND - connection finished - 0 messages sent <br />26.10.2004, 11:37:29: SEND - Some messages were not sent - check the log for details <br /><br />The certificate we use is for no special purpose. That means we use general purpose certificates. <br />I already added the root cert into the address book. Did not help. I tried to add the mail server's cert into the address book but the address book told me that it is corrupted or not an s/mime certificate. <br />hmmm... it has no specific purpose. Where can I tell openssl to generate the correct certificate? And a certificate that works with all the other mail clients, too? Did we do something wrong when generating our certificate? <br /><br />Any help is really welcome! <br /><br />Thanks! <br />-rgvt- <br /><br />An addition to that. I have an ssldump output attached. I think it comes from the server's certificate that is not accepted by TB: <br />1 1 0.0012 (0.0012) C&gt;S Handshake <br />ClientHello <br />Version 3.1 <br />cipher suites <br />Unknown value 0x35 <br />Unknown value 0x2f <br />TLS_RSA_WITH_RC4_128_SHA <br />TLS_RSA_WITH_3DES_EDE_CBC_SHA <br />compression methods <br />NULL <br />1 2 0.0159 (0.0146) S&gt;C Handshake <br />ServerHello <br />Version 3.1 <br />cipherSuite TLS_RSA_WITH_RC4_128_SHA <br />compressionMethod NULL <br />1 3 0.0159 (0.0000) S&gt;C Handshake <br />Certificate <br />1 4 0.0159 (0.0000) S&gt;C Handshake <br />ServerHelloDone <br />1 5 0.0180 (0.0020) C&gt;S Alert <br />level fatal <br />value unsupported_certificate<br /><br /> <br />
			<i>26 October 2004 11:20:01, <a href="http://www.ritlabs.com/en/forums/">Ruppert von Teutul</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic382/message1454/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic382/message1454/</guid>
			<pubDate>Tue, 26 Oct 2004 11:20:01 +0300</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
	</channel>
</rss>
