Re: TLS1.0 and 1.1 with Cyrus (Debian Buster)

2020-05-08 Thread Roman Medina-Heigl Hernandez
Gracias Alberto. Now it's solved (it has been a little bit tricky). My final config: * /etc/imapd.conf tls_ciphers: TLSv1.2:TLSv1:HIGH:!aNULL:@STRENGTH tls_versions: tls1_0 tls1_1 tls1_2 tls1_3 * /etc/ssl/openssl.cnf MinProtocol = TLSv1.0 CipherString = DEFAULT@SECLEVEL=2 Still don't know how t

Re: TLS1.0 and 1.1 with Cyrus (Debian Buster)

2020-05-08 Thread Alberto Gonzalez Iniesta
Hi, It's probably due to new defaults in libssl. Try adding: MinProtocol = None CipherString = DEFAULT To: /etc/ssl/openssl.cnf Regards, Alberto On Fri, May 08, 2020 at 09:07:31PM +0200, Roman Medina-Heigl Hernandez wrote: > Hi, > > I upgraded from Jessie to Buster (thru Stretch) and noticed t

TLS1.0 and 1.1 with Cyrus (Debian Buster)

2020-05-08 Thread Roman Medina-Heigl Hernandez
Hi, I upgraded from Jessie to Buster (thru Stretch) and noticed that Cyrus (imaps & pop3s) stopped negotiating TLS 1.0 and 1.1 protocols (I know they're not recommended but I need them for older clients). I tried several combinations of tls_ciphers and tls_versions in /etc/imapd.conf (even very pe

Re: rkhunter finds something suspicious

2020-05-08 Thread Elmar Stellnberger
You should execute the commands below when you install a new system. Closing unnecessary ports makes your system less susceptible to cracking, rootkit infection and/or malware infection. Am 08.05.20 um 14:33 schrieb Elmar Stellnberger:  I always use > netstat -atupn That shows all open tcp

Re: rkhunter finds something suspicious

2020-05-08 Thread Elmar Stellnberger
Take care when you try to analyze the rootkit: You should install new into another partition/ boot from live cd first and then look at the files without executing them (otherwise your new system may get infected). The rootkit may be altered, removed or your activity may be monitored and/or in

Re: rkhunter finds something suspicious

2020-05-08 Thread Elmar Stellnberger
Am 07.05.20 um 19:14 schrieb shirish शिरीष: Dear all, Today my system was slowing much more than ever. Hence decided to run rkhunter. It seems to have found some issues, could somebody take a look and see if these are false positives or what ? I don't know the hash sums it quotes are current o

Re: rkhunter finds something suspicious

2020-05-08 Thread Elmar Stellnberger
I always use > netstat -atupn That shows all open tcp and udp ports. Invoke this before you start Firefox. The list should be empty or only contain sockets on the loopback network interface (127.0.0.*, ::1). To disable unnecessary network daemons use: > systemctl disable avahi-daemon/other-da

Re: rkhunter finds something suspicious

2020-05-08 Thread shirish शिरीष
at bottom :- On 07/05/2020, shirish शिरीष wrote: > Dear all, > > Today my system was slowing much more than ever. Hence decided to run > rkhunter. It seems to have found some issues, could somebody take a > look and see if these are false positives or what ? > > > I don't know the hash sums it qu