Am 09.10.2013 21:06, schrieb Dan Langille:
> On Oct 6, 2013, at 5:06 PM, Reindl Harald wrote:
>> and is working even with *self signed* certificates and dovecot 2.2
>> you only have to accept / import the certificate
>> proven by a testserver all day long
> It seems that the test server is not testing this particular situation.

it is not the servers job to accept the cert
the particular server makes it even harder as defaults

ssl_cipher_list =
ssl_prefer_server_ciphers = yes

>> so i assume the problem exists between chair and keyboard
> Turns out, this assumption is incorrect.
> Just saying

imap-login: OK:,, CRAM-MD5, TLSv1 with 
cipher DHE-RSA-AES256-SHA

* dovecot 2.2.6 / openssl-1.0.1e
* self signed certificate
* 4096 Bit (recently changed from 2048 bit and had to be again accepted by the 
* Apple OSX

it's not the job of the server to accept the cert

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to