Re: TLS support

2014-01-10 Thread Viktor Dukhovni
On Fri, Jan 10, 2014 at 01:52:17PM +, Viktor Dukhovni wrote: > There are also some DANE related parameters for the > TLS library: > > tls_dane_digest_agility = on > tls_dane_digests = sha512 sha256 > tls_dane_trust_anchor_digest_enable = yes Another

Re: TLS support

2014-01-10 Thread Wietse Venema
> > - Troubleshooting > > - Quick and Dirty configuration > > - Client in brief. > > DNS and SMTP agent settings. > tls policy table for exceptions: > - non-dane for emergencies (assuming not an MITM attack). > - dan

Re: TLS support

2014-01-10 Thread Viktor Dukhovni
On Fri, Jan 10, 2014 at 11:44:04AM +0100, Patrick Ben Koetter wrote: > Viktor, > > we're lucky to have Carsten Strotmann on our team (here at sys4). You may know > him for his expertise on DNS. Carsten offered to assist in writing the > DANE_README. Thanks. Very much appreciated. > I'd like yo

Re: TLS support

2014-01-10 Thread Patrick Ben Koetter
Viktor, we're lucky to have Carsten Strotmann on our team (here at sys4). You may know him for his expertise on DNS. Carsten offered to assist in writing the DANE_README. I'd like you/others to go over the following TOC to make sure we cover all necessary aspects: - What is DANE - Benefits of u