Re: [Dovecot] disbale to responded to an unrequested SSL Certificate

2008-10-02 Thread Steffen Kaiser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue, 30 Sep 2008, Andre Hübner wrote: I may sound like a total ox, but I wonder if the client _requests_ a certificate at all? Till now I thought that the client starts the TLS handshake and the server responses with a certificate, if

Re: [Dovecot] disbale to responded to an unrequested SSL Certificate

2008-09-30 Thread Andre Hübner
Hi List, Hi dovecot-list, just a easy question today ;) Customer did on Server a PCI-Test to test security to fit worldpay requirements. They found a critical risk at pop3s. (and some other things) This is the Textmesage: Family: Remote Shell Access Critical 993/tcp 11875

Re: [Dovecot] disbale to responded to an unrequested SSL Certificate

2008-09-30 Thread Christopher J. Buckley
Andre Hübner wrote: Hi dovecot-list, just a easy question today ;) Customer did on Server a PCI-Test to test security to fit worldpay requirements. NB: PCI is not to fit Worldpay's requirements; but rather the body of PCI-DSS (Visa Mastercard). 1. What was the scanning tool? Qualys? 2.