Re: [Exim] TLS and Intermediate (root) certificates

Góra strony
Delete this message
Reply to this message
Autor: Sheldon Hearn
Data:  
Dla: Philip Hazel
CC: William Gerken, exim-users
Stare tematy: Re: [Exim] TLS and Intermediate (root) certificates
Temat: Re: [Exim] TLS and Intermediate (root) certificates

On Wed, 14 Nov 2001 11:12:28 GMT, Philip Hazel wrote:

> > This worked very smoothly expect for the small detail that the
> > clients are being prompted to verify the certificate, with a message
> > along the lines of "A certificate chain processed correctly, but
> > terminated in a root certificate which is not trusted by the trust
> > provider".


> That's because I'm extremely ignorant about SSL and how certificates
> work. The code for TLS support in Exim was originally implemented by
> somebody who gave it to me for incorporating and tidying. I seem to
> recall that the documentation for OpenSSL was not very helpful, so I
> just implemented something that appeared to work.


I've done a bit of research and found at least one 3rd party support
article that claims IE6+OutlookExpress6 has a problem with self-signed
certificates.

I get the same behaviour from OutlookExpress6 with both my POP3S server
and with Exim.

So I'm not sure that this is definitely Exim's fault, although it's
possible the POP3S server's making the same mistake as Exim.

Did you have any feedback to your call for SSL experts? (I am not one
of these)

Ciao,
Sheldon.