Bug#873824: offlineimap: Offlineimap needs to call SSL_set_min_proto_version() for openssl

Ilias Tsitsimpis iliastsi at debian.org
Wed Sep 6 16:38:06 BST 2017


Control: notfound 873824 offlineimap/7.1.2+dfsg1-2

On Mon, Sep 04, 2017 at 07:56PM, ael wrote:
> On Thu, Aug 31, 2017 at 06:38:46PM +0300, Ilias Tsitsimpis wrote:
> [...]
> > If I understand correctly, you tested the above with the latest openssl
> > (1.1.0f-5), is that right? If so, could you please try and set the
> > `ssl_version` in offlineimap.conf file to tls1_1 or tls1, accordingly?
> > This should force offlineimap to use the specified version.
> 
> Sorry for the delay. Yes, those options worked. Thank you.

Glad it worked out!

> I do find the documentation about the tls/ssl options in
> /usr/share/doc/offlineimap/examples/offlineimap.conf.gz
> pretty confusing, and had tried various configurations that I thought
> should have worked.

The documentation reads:

    Set SSL version to use (optional).
    
    It is best to leave this unset, in which case the correct version will be
    automatically detected. In rare cases, it may be necessary to specify a
    particular version from: tls1, tls1_1, tls1_2, ssl3, ssl23.
    
I find the above to be quite easy to understand. Could you please
elaborate on what confuses you so that we can improve the wording?

-- 
Ilias




More information about the OfflineIMAP-project mailing list