| To: | qmail@list.cr.yp.to |
|---|---|
| Subject: | Re: Dozens of qmail-smtpd processes eating 100% of CPU |
| From: | Kyle Wheeler <kyle-qmail@memoryhole.net> |
| Date: | Fri, 18 May 2007 15:15:07 -0600 |
| Comment: | DomainKeys? See http://antispam.yahoo.com/domainkeys |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | gmail-qmail@securepoint.com |
| Delivered-to: | sp.com.list@gmail.com |
| Delivered-to: | mailing list qmail@list.cr.yp.to |
| Dkim-signature: | v=0.5; a=rsa-sha1; c=relaxed; d=memoryhole.net; h=received:comment:domainkey-signature:received:received:date:from:to:subject:message-id:mail-followup-to:references:mime-version:content-type:content-disposition:in-reply-to:user-agent; q=dns/txt; s=default; bh=U2l3yU4iaYEPg4QGYmj5i/sKjAU=; b=i7Y6oY81aojSUe051On1ZmAnOLRQmi+6UaHTKkt4+6fNsgMjHU56nxGw8Zs3utV2TyHQGhqch3uz6uRvRvOFJL5DDpWttfG8ClJi4JgXuJ7RJnLonQQUT9jEMfEn2XDVhcYxTtxhAkS8Vp6ZSQqU8FVZcuHQSAyRcXagB6XeOyM= |
| Domainkey-signature: | a=rsa-sha1; q=dns; c=nofws; s=default; d=memoryhole.net; b=LsX7xKY182+f8v3X1ITrlXEuQhqrR+tG5EJo710HOw6HMf9dijxOdl9qlxcBHwteXpar1X9QzyCkyPc//OunD649VxSxztTFQgdlcHVUkOqEzM/ln8TlDnN0brsxAhHLncA5ZP8xf2lvdv1bTLsdAcAPMBn1JO83BiH92eXEAiw= ; |
| Domainkey-status: | good |
| In-reply-to: | <464E0C5C.1000400@sourcefire.com> |
| Mail-followup-to: | qmail@list.cr.yp.to |
| Mailing-list: | contact qmail-help@list.cr.yp.to; run by ezmlm |
| References: | <464DBC1B.30204@sourcefire.com> <20070518163703.GH29250@marvin.we-be-smart.org> <464DE3E0.8070200@sourcefire.com> <20070518175145.GA18422@caesar.cse.nd.edu> <924f29280705181128l286d84fdia4de414a7df6f2a1@mail.gmail.com> <20070518184604.GD18422@caesar.cse.nd.edu> <464E02AC.7000908@sourcefire.com> <20070518195903.GF18422@caesar.cse.nd.edu> <464E0C5C.1000400@sourcefire.com> |
| User-agent: | Mutt/1.5.15cvs (2007-05-02) |
On Friday, May 18 at 04:28 PM, quoth Alex Kirk: Aha! That's definitely it! <whew!> Good! 'cuz if it wasn't, then we were in some pretty deep water. Thank you so much for continuing to work with me on this. I *greatly* appreciate it. Glad I can help! Meanwhile, for posterity's take, I got dh1024.pem and dh512.pem out of /usr/src/lib/libssl/src/apps/ on my OpenBSD 3.8 system (you may not have to generate them, just copy them from somewhere like I did). No, you *really* need to generate them, and more specifically, you *really* need to re-generate them periodically. The problem with permanent SSL certificates (as I understand it, and I'm no guru on SSL) is that given enough connections, which are all very regular (for example, you know that the greeting is the same each time, and you know the general structure of an SMTP conversation) you can begin to figure out what the certificate is. The way to solve this problem is to add a little extra to the encryption, that will be (partialy?) exchanged with the client as part of the diffie-hellman key-exchange process, and this makes it so that figuring out the contents of the SSL certificate are safe even though most SMTP conversations are roughly identical. That "little extra" is what the dh1024.pem and dh512.pem files are for. And it's fine to regenerate them as infrequently as once-a-week, but you really shouldn't use someone else's, and you really should regenerate them at least once a week. I'm going to go look at the docs for the starttls patch, because it's unlike me to have skipped a step like this. Hopefully either I was an idiot when I installed the patch, or I can submit a doc patch to spare other people this hassle in the future. Good luck! (In this case, the docs are inconveniently placed at the beginning of the patch file, so they're easy to skip and/or not notice.)
~Kyle
--
History will be kind to me, for I intend to write it.
-- Winston Churchill
|
| Previous by Date: | Re: Dozens of qmail-smtpd processes eating 100% of CPU, Kyle Wheeler |
|---|---|
| Next by Date: | Re: Dozens of qmail-smtpd processes eating 100% of CPU, Sami Farin |
| Previous by Thread: | Re: Dozens of qmail-smtpd processes eating 100% of CPU, Alex Kirk |
| Next by Thread: | Re: Dozens of qmail-smtpd processes eating 100% of CPU, Sami Farin |
| Indexes: | [Date] [Thread] [Top] [All Lists] |