Qmail
[Top] [All Lists]

Re: mess822 TLS patch

To: qmail list <qmail@list.cr.yp.to>
Subject: Re: mess822 TLS patch
From: John L <johnl@iecc.com>
Date: Mon, 11 Dec 2006 17:53:41 -0500 (EST)
Cleverness: None detected
Delivered-to: sp-com-lists@consult.net
Delivered-to: gmail-qmail@securepoint.com
Delivered-to: sp.com.list@gmail.com
Delivered-to: mailing list qmail@list.cr.yp.to
In-reply-to: <19EBB6C5-26A1-4FE9-82D6-247DCEC16F52@tancred.com>
Mailing-list: contact qmail-help@list.cr.yp.to; run by ezmlm
References: <19EBB6C5-26A1-4FE9-82D6-247DCEC16F52@tancred.com>
I've combined John Levine's ofmipd AUTH patch [1] with stuff from
Scott Gifford's UCSPI-TLS [2]. With these changes, ofmipd now supports
the use of TLS by means of the sslserver program from UCSPI-TLS.

The AUTH patch is fine, at least once you comment out a line that pointlessly dup's fd1 onto fd2, but on FreeBSD 6.1, sslserver doesn't work. It compiles fine, but the SSL or TLS handshake always fails. I asked the guy who wrote sslserver and the answer boiled down to "dunno, it worked the last time I tried it" so there is presumably some obscure interface problem with openssl. I tried it with both 0.9.7 and 0.9.8, equally broken.

On the other hand, the popular AUTH+TLS patch for netqmail works just fine. Before I start cutting and pasting, anyone already adapted it from qmail-smtpd to ofmipd? Tnx.

Regards,
John Levine, johnl@iecc.com, Primary Perpetrator of "The Internet for Dummies",
Information Superhighwayman wanna-be, http://johnlevine.com, Mayor
"I dropped the toothpaste", said Tom, crestfallenly.

<Prev in Thread] Current Thread [Next in Thread>
  • Re: mess822 TLS patch, John L <=