[Pkg-openssl-devel] Bug#843603: Bug#843603: openssl fails on sid version to handshake with tls_1.2 to postfix echos ssl_errors

sternasky sternasky at gmx.de
Fri Nov 11 18:21:26 UTC 2016


Hello,

after some analysis i found infos about php security changes after
5.6,7.0.12.2

Self Signed Certs like

SSLCertificateFile    /etc/ssl/certs/ssl-cert-snakeoil.pem
SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key

which are set to CN localhost are blocked by postfix from PHP Mailers
like Roundcube.. Errors often are seen:

.. ssl cert not accepted or SSLv3 Error..

Thanks..
www.linuxonlinehelp.de

On Tue, 8 Nov 2016 22:28:41 +0100 Kurt Roeckx <kurt at roeckx.be> wrote:
> On Tue, Nov 08, 2016 at 04:04:56AM +0100, support at opensource-systems.com wrote:
> > Package: openssl
> > Version: 1.0.2j-1
> > Severity: important
> > 
> >  openssl of Sid fails handshake with postfix and echos ssl_error on mail.log, no mail
> >  can be send with TLS_1.2 on Port 465
> 
> I can not reproduce your problem. Postfix is working fine for me.
> 
> I can connect to it both using the 1.0.2 and 1.1.0 version.
> Postfix itself still seems to use 1.0.2 and not really changed
> recently.
> 
> 
> Kurt
> 
> 
> 



More information about the Pkg-openssl-devel mailing list