store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sat May 18, 2013 9:22 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 11 posts ] 
Author Message
 Post subject: Plesk 10 / Imap SSL
Unread postPosted: Thu Feb 16, 2012 10:05 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
Hi Guys.

Imap wont work on SSL and I just got from ossec the error paster below. Any ideas ?

Code:
 imapd-ssl: couriertls: accept: error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1 alert unknown ca

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Thu Feb 16, 2012 10:23 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
el4 by any chance?


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Fri Feb 17, 2012 9:20 am 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
scott wrote:
el4 by any chance?


el4 ?

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Fri Feb 17, 2012 3:50 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
EL4 = Enterprise Linux 4 = Red Hat Enterprise Linux 4, or a compatible distribution like CentOS 4.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Fri Feb 17, 2012 3:57 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
Nope. I am using CentOS 5.x with ASL installed.

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Fri Feb 17, 2012 5:15 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
there goes that idea... el4 has an older certificate issue.


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Fri Feb 17, 2012 6:21 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Mar 28, 2009 6:58 pm
Posts: 802
Location: Germany
try to convert your CA certificate to PEM format and set TLS_TRUSTCERTS in the imapd-ssl config file to point to your PEM CA file.


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Fri Feb 17, 2012 6:26 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
This Parallels knowledge base article explains how to configure SSL for SMTP/IMAP/POP3: http://kb.parallels.com/1062

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Mon Apr 02, 2012 11:22 pm 
Offline
Forum Regular
Forum Regular

Joined: Sun Mar 29, 2009 6:52 pm
Posts: 348
Sorry for the delayed response. It was permissions issue after all ... Changed them like the other files to 755 restarted the mail services and worked like a charm.

And now I come to another big question.

Ok, you can encrypt messages that come in and out of the servers when you are a user. But when the mailserber itself "passes by" a mail message to another mail server on the internet this isn't encrypted right ? Is there a way to make qmail to request other mail servers to start an encrypted session so all messages can be recieved - delivered securely ?

_________________
Hello IT.
Phone : Blah Blah ....
Have you tried turning it on and off again ?
Phone : Blah Blah ....
....
I'm sorry, are you from the Past ?!
http://www.youtube.com/watch?v=-E4fm4Wqego


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Tue Apr 03, 2012 4:40 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1843
Qmail will encrypt by default when talking to another qmail server. I don't think this is anything to do with qmail itself -- it is part of the SMTP protocol, I think, so it would work with any server.

The key thing is that receiving server will advertise its capabilities, and the sending server will use them or not as it sees fit (and as its configuration/default tells it to do).

I have no idea where these things might be adjusted, although I seem to remember there were some things you could do in smtp[s]_psa in terms of incoming mail.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Plesk 10 / Imap SSL
Unread postPosted: Fri Apr 20, 2012 6:38 am 
Offline
Forum User
Forum User

Joined: Tue Apr 20, 2010 2:49 am
Posts: 74
I think its these files that govern what will be advertised in terms of encryption offered as a server, and encryption that will be used when connecting server to server :

root@vz1038 control]# cat tlsserverciphers
ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:!SSLv2:RC4+RSA:+HIGH:!MEDIUM
[root@vz1038 control]# cat tlsclientciphers
ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:!SSLv2:RC4+RSA:+HIGH:!MEDIUM
[root@vz1038 control]# pwd
/var/qmail/control
[root@vz1038 control]#


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 11 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group