[Exim] problem with TLS tls_verify_certificate

Top Page
Delete this message
Reply to this message
Author: Marek Majchrowski
Date:  
To: exim-users
Subject: [Exim] problem with TLS tls_verify_certificate
Hi,

I upgrade from exim3 to exim4. I use verifying client certificates.

If i've uncommented line :
tls_verify_certificates = /etc/exim4/certs

When I connect with STARTTLS I have error:

2003-11-25 22:23:42 SMTP connection from [10.1.100.2]:42907 (TCP/IP
connection count = 1)
2003-11-25 22:23:42 TLS error on connection from marek.majcom
[10.1.100.2]:42907 (setup_certs): Certificate parsing error.
2003-11-25 22:23:42 SMTP connection from marek.majcom [10.1.100.2]:42907
closed by QUIT

This directory contain clients certs:

[root@neptun:~]$ ll /etc/exim4/certs/
razem 16
drwxr-x---    2 root     mail         4096 2003-11-24 23:47 ./
drwxr-x---    4 root     mail         4096 2003-11-25 22:28 ../
lrwxrwxrwx    1 root     mail           25 2003-11-24 22:53 49e5f521.0 ->
CA-MajCom-Certificate.pem
lrwxrwxrwx    1 root     mail           21 2003-11-24 22:53 5346b7eb.0 ->
smtp-marek.majcom.pem
-rw-r-----    1 root     mail         1359 2003-10-18 23:42
CA-MajCom-Certificate.pem
-rw-r-----    1 root     mail         1428 2003-11-24 23:47
smtp-marek.majcom.pem



If I comment line: tls_verify_cert... it work fine with STARTLS, but my
machine can not send mail through the server with exim4 using client
certificates.

This work fine with exim3, but with exim4 with GnuTLS it doesn't work.

Can you help me?

Sorry for my english.


--
Marek Maj(c)herek Majchrowski            tel: (503) 034 553
E-mail: majherek@???
E-mail: M.Majchrowski@???
UIN#: 18207917      GG#: 207055     Linux Counter reg#:147586