Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread chaouche yacine
Interesting. Is there any particular benefit in having only one file for both certificate and private key ? I find that putting private key in a separate file feels more secure. Bastian, how could two identical certificates be processed differently by Thunderbid ? how did you check the differe

Re: Sieve not filtering

2017-02-17 Thread Doug Hardie
> On 17 February 2017, at 08:24, Ben wrote: > > Hi, > > I have copied accross a known-good sieve file from a working server and its > not filtering. Everything just gets chucked into INBOX. What I did when encountering a similar issue was to take one of the messages from INBOX that should h

Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread Shawn Heisey
On 2/17/2017 2:38 PM, chaouche yacine wrote: > Seems wrong to me too, Robert. If you put your private key inside your > certificate, won't it be sent to the client along with it ? The private key should not be sent to the connecting client, even if it is contained in the same place as the certifi

Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread Bastian Sebode
Hey. Thanks again for your help. I took the "dovecot -n" while the StartSSL Certificate was active, so the chain.pem was correct. Finally I found the issue! :-) But I still have no idea why the problem happens with Thunderbird. I used dehydrated to fetch the certificates from Let's Encrypt and a

Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread Christian Kivalo
On 2017-02-17 22:38, chaouche yacine wrote: Seems wrong to me too, Robert. If you put your private key inside your certificate, won't it be sent to the client along with it ? This is one way of supplying cert + key to a daemon and no, the key is not sent to the client. While it is normaly true

Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread chaouche yacine
Seems wrong to me too, Robert. If you put your private key inside your certificate, won't it be sent to the client along with it ? Bastian, are you using an old version of thunderbird ? googling for "SSL alert number 42" gave me two results indicating a bug in thunderbird versions 31,32 and 33.

Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread Aki Tuomi
Usually with LE, the filename is fullchain.pem, not chain.pem. Can you please doublecheck this? Also, try openssl s_client -connect hostname:143 -starttls imap Aki > On February 17, 2017 at 10:31 PM Bastian Sebode > wrote: > > > Hey Robert, > > thanks for your reply. > > Am 17.02.2017 um

Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread KSB
On 2017.02.17. 22:31, Bastian Sebode wrote: Hey Robert, thanks for your reply. Am 17.02.2017 um 19:28 schrieb Robert L Mathews: Looking at your dovecot -n, you're using two different files here: ssl_cert = Are You sure, chain.pem contains your cert + immediate? By default certbot in chain.

Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread Bastian Sebode
Hey Robert, thanks for your reply. Am 17.02.2017 um 19:28 schrieb Robert L Mathews: > Looking at your dovecot -n, you're using two different files here: > > ssl_cert = ssl_key = > Are you sure these two files match, and contain the right things in the > right order? > Yes, unfortunately I'm

Replication Troubles

2017-02-17 Thread Wolfgang Hennerbichler
Hi Dovecot Users, I’ve configured dovecot dsync replication and I see troubles in the logs and get user complaints which I can’t explain. I found similar threads on this mailinglist, but I couldn’t find a solution anywhere. Does anybody have dsync running without problems on a high volume mail

Re: Problem with Let's Encrypt Certificate

2017-02-17 Thread Robert L Mathews
On 2/17/17 8:58 AM, Bastian Sebode wrote: > I uploaded two Wireshark tracefiles, further logs and dovecot -n Looking at your dovecot -n, you're using two different files here: ssl_cert = http://www.tigertech.net/

Problem with Let's Encrypt Certificate

2017-02-17 Thread Bastian Sebode
Hello Folks, my StartCom SSL-Certificate expires soon and so I wanted to switch to Let's Encrypt Certificates instead. Unfortunatelly Thunderbird seems not to like it, although all -tested- other Clients work without any problems. When I connect with Thunderbird it sends an "Encrypted Alert" dire

Re: fts_solr and connection via https://

2017-02-17 Thread Jan Vonde
Am 17.02.2017 um 11:45 schrieb Stephan Bosch: Op 8-2-2017 om 21:07 schreef Jan Vonde: Am 07.02.2017 um 12:29 schrieb Stephan Bosch: Op 31-1-2017 om 6:33 schreef Jan Vonde: Am 31.01.2017 um 00:04 schrieb Stephan Bosch: Op 1/22/2017 om 12:01 PM schreef Stephan Bosch: Op 1/22/2017 om 10:01 AM s

Sieve not filtering

2017-02-17 Thread Ben
Hi, I have copied accross a known-good sieve file from a working server and its not filtering. Everything just gets chucked into INBOX. doveconf-n at the bottom of this mail Feb 17 16:05:20 server postfix/smtpd[51562]: 7FA5E12CBBC: client=unknown[192.168.167.57] Feb 17 16:05:23 server post

Re: Sieve removeflag Action

2017-02-17 Thread Stephan Bosch
Op 19-1-2017 om 10:43 schreef Thomas Leuxner: * Stephan Bosch 2017.01.19 10:32: Could you provide a more detailed example? Sure. Personal script v /var/vmail/domains/leuxner.net/tlx/.dovecot.sieve: require ["include","copy","fileinto","imap4flags","vacation"]; include :global "global"; -

Re: fts_solr and connection via https://

2017-02-17 Thread Stephan Bosch
Op 8-2-2017 om 21:07 schreef Jan Vonde: Am 07.02.2017 um 12:29 schrieb Stephan Bosch: Op 31-1-2017 om 6:33 schreef Jan Vonde: Am 31.01.2017 um 00:04 schrieb Stephan Bosch: Op 1/22/2017 om 12:01 PM schreef Stephan Bosch: Op 1/22/2017 om 10:01 AM schreef Jan Vonde: I tried adding the follow