Bug#314296: Re: Bug#314296: exim4 NOT verifying server certificate

2005-06-19 Thread Marc Haber
On Sun, Jun 19, 2005 at 03:45:21PM +0800, Wenzhuo Zhang wrote: > Quoting Marc Haber <[EMAIL PROTECTED]>: > > Take a look at the bug reports against exim4, and see what scenarios > > we have to worry about. Roommates sharing a mail server, using > > differnet freemailers which all of them demand tha

Bug#314296: Re: Bug#314296: exim4 NOT verifying server certificate

2005-06-19 Thread Wenzhuo Zhang
Quoting Marc Haber <[EMAIL PROTECTED]>: > Take a look at the bug reports against exim4, and see what scenarios > we have to worry about. Roommates sharing a mail server, using > differnet freemailers which all of them demand that their addresses > get relayed through their smarthosts are quite com

Bug#314296: Re: Bug#314296: exim4 NOT verifying server certificate

2005-06-19 Thread Marc Haber
Hi, On Sun, Jun 19, 2005 at 08:23:57AM +0800, Wenzhuo Zhang wrote: > On Sun, Jun 19, 2005 at 01:29:57AM +0200, Marc Haber wrote: > > SMTP AUTH over TLS with actual verification of the server certificate > > is not very common nowadays. > > Most MUA programs will verify the server certificate if y

Bug#314296: Re: Bug#314296: exim4 NOT verifying server certificate

2005-06-18 Thread Wenzhuo Zhang
On Sun, Jun 19, 2005 at 01:29:57AM +0200, Marc Haber wrote: > SMTP AUTH over TLS with actual verification of the server certificate > is not very common nowadays. Most MUA programs will verify the server certificate if you ever enable TLS. > Where should the package automatically obtain the CA ce

Bug#314296: Re: Bug#314296: exim4 NOT verifying server certificate

2005-06-18 Thread Marc Haber
On Sun, Jun 19, 2005 at 07:05:06AM +0800, Wenzhuo Zhang wrote: > On Sat, Jun 18, 2005 at 10:59:37AM +0200, Marc Haber wrote: > > As Andreas spotted correctly, conf.d/main/03_exim4-config_tlsoptions > > only controls verification of the client certificates. For server > > certificate checking, you n

Bug#314296: Re: Bug#314296: exim4 NOT verifying server certificate

2005-06-18 Thread Wenzhuo Zhang
On Sat, Jun 18, 2005 at 10:59:37AM +0200, Marc Haber wrote: > As Andreas spotted correctly, conf.d/main/03_exim4-config_tlsoptions > only controls verification of the client certificates. For server > certificate checking, you need to add the configuration option to the > SMTP transport. > > I am

Bug#314296: Re: Bug#314296: exim4 NOT verifying server certificate

2005-06-18 Thread Marc Haber
Hi, On Thu, Jun 16, 2005 at 11:29:15AM +0800, Wenzhuo Zhang wrote: > On Thu, Jun 16, 2005 at 01:04:30AM +0200, Marc Haber wrote: > > > Isn't tls_verify_certificates supposed to verify the server certificate > > > as well? > > > > It should. However, that code is not very well tested. Can you give