Re: Self-signed TLS client certificates

2019-06-16 Thread Marvin Gülker via dovecot
Am 16. Juni 2019 um 15:53 Uhr +0300 schrieb Aki Tuomi via dovecot: >You will save yourself from world of hurt if you use a dummy ca to sign >you smartcard cert. You can try without generating a CRL. I see. I've done that now, but the effort required seems to be disproportionate. I'm just a

Self-signed TLS client certificates

2019-06-16 Thread Marvin Gülker via dovecot
Dear List, I self-host my e-mail and run Dovecot since ever I do that. Dovecot version is 2.3.4.1 (f79e8e7e4), running on Debian testing. Now I am trying to configure Dovecot for client TLS certificates. I have a self-signed certificate whose private key resides on a smartcard (Yubikey, to be exa