Re: [exim] exim 4.43 and GnuTLS: How to control cipher negot…

Top Page
Delete this message
Reply to this message
Author: Philip Hazel
Date:  
To: Marc Haber, John W. Baxter
CC: exim-users
Subject: Re: [exim] exim 4.43 and GnuTLS: How to control cipher negotiation?
On Wed, 1 Dec 2004, John W. Baxter wrote:

> >> Nikos Mavroyanopoulos provided GnuTLS proof of concept code;


> > Thanks for that idea. Even with tls_require_ciphers = AES : 3DES,
> > messages go out with X=TLS-1.0:RSA_ARCFOUR_SHA:16.
> >
> > So either I have done something wrong, or there is something wrong
> > with my exim binary.
>
> There are both general section tls_require_ciphers (for incoming) and smtp
> transport tls_require_ciphers (for outgoing) options.
>
> Just to keep me sane*, you did use the one on the transport (and the right
> transport, at that), correct?


Good point, John. I'd forgotten to make that point. Thanks. If Marc has
used the wrong one, I will give a sigh of relief. If he has used the
right one (in the transport), it suggests that there may be a problem in
the Exim code. I'm awaiting his reply...

Regards,
Philip

-- 
Philip Hazel            University of Cambridge Computing Service,
ph10@???      Cambridge, England. Phone: +44 1223 334714.