I've successfully sent mail over SSL/TLS between two test servers,
both running exim 3.164 and openssl 0.9.5a. Clients used were Netscape
4.75 and Outlook 2000.
Here's an excerpt of the headers from sending a message through Outlook 2000
to server #1 which forwarded on through a couple of systems running sendmail:
Received: from zeus.dmacc.cc.ia.us (zeus.dmacc.cc.ia.us [161.210.216.101])
by max.ollie.clive.ia.us (8.9.3/8.9.3) with ESMTP id OAA18718
for <jcollie@???>; Thu, 5 Oct 2000 14:11:05 -0500
Received: from pc11066.dmacc.cc.ia.us (IDENT:root@???
[161.210.6.199])
by zeus.dmmacc.cc.ia.us (8.9.3/8.9.3) with ESMTP id OAA18276
for <jcollie@???>; Thu, 5 Oct 2000 14:11:05 -0500
Received: from [161.210.6.174] (helo=pc02811)
by pc11066.dmacc.cc.ia.us with smtp (TLSv1:RC4-MD5:128)
(Exim 3.164 #1)
id 13hGQ5-00086c-00
for jcollie@???; Thu, 05 Oct 2000 14:11:05 -0500
Here's an excerpt of the headers from sending a message from Netscape 4.75
to server #1 which relayed to server #2:
Received: from pc11066.dmacc.cc.ia.us ([161.210.6.199] ident=root)
by pc10800.dmacc.cc.ia.us with esmtp (TLSv1:EDH-RSA-DES-CBC3-SHA:168)
(Exim 3.164 #1)
id 13hI5q-0000XS-00
for jcollie@???; Thu, 05 Oct 2000 15:58:18 -0500
Received: from [161.210.6.174] (helo=dmacc.cc.ia.us)
by pc11066.dmacc.cc.ia.us with esmtp (SSLv3:RC4-MD5:128)
(Exim 3.164 #1)
id 13hI2L-00086m-00
for jcollie@???; Thu, 05 Oct 2000 15:54:41 -0500
I plan on doing some more testing next week with openssl 0.9.6.
Jeff
On Thu, Oct 05, 2000 at 05:05:54PM +0100, Philip Hazel wrote:
> I've fixed a couple of problems that came up in the TLS testing (data
> byte x'ff' causing trouble, and lack of timeouts on the TLS negoation
> process), so I've put a new snapshot in
>
> ftp://ftp.csx.cam.ac.uk/pub/software/email/exim/Testing/exim-snapshot.tar.gz
>
> Testers, please note that I have also changed the default setting of
> tls_advertise_hosts from "*" to "", so you must set it on a server if
> you want it to advertise TLS.
>
> This release is 3.164. Other things have been going on too, so the bug
> fixes are not the only changes. I have, for example, added support for
> the new A6 DNS records. As usual, consult doc/ChangeLog and doc/Newstuff
> for details.