Re: [exim] DANE(TA) doesn't work with self signed certificat…

Top Page
Delete this message
Reply to this message
Author: Viktor Dukhovni
Date:  
To: exim-users
Subject: Re: [exim] DANE(TA) doesn't work with self signed certificate
On Wed, Sep 05, 2018 at 03:56:55PM +0100, Klaus Ethgen via Exim-users wrote:

> > I suppose your Exim is also linked to GnuTLS?
>
> Sure, it is the common debian version and Debian is always linking
> against gnutls.


You can rebuild the source deb against OpenSSL:

https://wiki.debian.org/PkgExim4UserFAQ#Building_against_OpenSSL

but some care is required to avoid having the resulting package
automatically replaced by a later Debian version linked against
GnuTLS. You can change the generation number, or rename the
package, specifying a conflict with the original package name.

Perhaps call it exim4-openssl. Ideally, someone should curate
detailed build instructions that take care of all the loose ends.
Perhaps that's already been done...

-- 
    Viktor.