Re: TLS renegotiation issue (CVE-2011-1473) in Dovecot

2022-05-14 Thread Greg Earle
On 13 May 2022, at 19:38, Elisamuel Resto wrote: I believe this to be a configuration error, not a dovecot problem. The output of dovecot -n (as an attachment; look it over for any data you do not want publicized) would help to suggest changes to bring you back into compliance. Elisamuel,

TLS renegotiation issue (CVE-2011-1473) in Dovecot

2022-05-13 Thread Greg Earle
Hello, At work I'm running a Dovecot 2.3.15 server on a RHEL 7.9 system with OpenSSL 1.0.2k. Our IT Security people are threatening to shut it down because of this: We were notified of a possible TLS renegotiation vulnerability on [FQHN]. [Parent organization] ticket NNN is open to tra