Re: [Dovecot] SSL issues on separate IPs - resolved

2010-12-02 Thread Tim Traver
Timo (and others), It turns out that we had a different set of chain and root ca certs from godaddy than was required for the proper chain. It seemed to work for apache, but failed for dovecot... I really dislike godaddy... thanks for the help, Tim. >> I guess I will go and make sure the chai

Re: [Dovecot] SSL issues on separate IPs

2010-12-02 Thread Tom Talpey
On 12/3/2010 12:46 AM, Tim Traver wrote: Timo, ok, I have more info from your suggestion to use the openssl test client connect. I do have about a dozen more configs on different IP's, and they seem to work. I just didn't include them. I get the following error when trying to connect to that I

Re: [Dovecot] SSL issues on separate IPs

2010-12-02 Thread Timo Sirainen
On 3.12.2010, at 5.55, Tim Traver wrote: >> Dec 03 07:51:09 imap-login: Disconnected (no auth attempts): >> rip=81.193.158.104, lip=80.83.4.5, TLS handshaking: Disconnected >> Dec 03 07:51:19 imap-login: Disconnected (no auth attempts): >> rip=81.193.158.104, lip=80.83.4.5, TLS handshaking: SSL_

Re: [Dovecot] SSL issues on separate IPs

2010-12-02 Thread Tim Traver
On 12/2/2010 9:52 PM, Timo Sirainen wrote: > On 3.12.2010, at 5.46, Tim Traver wrote: > >> So, I guess I'm not sure if it is dovecot or not yet, although it is >> kind of strange that nothing is written in the logs about the handshake >> failing. > Dovecot should log something in the disconnect m

Re: [Dovecot] SSL issues on separate IPs

2010-12-02 Thread Timo Sirainen
On 3.12.2010, at 5.46, Tim Traver wrote: > So, I guess I'm not sure if it is dovecot or not yet, although it is > kind of strange that nothing is written in the logs about the handshake > failing. Dovecot should log something in the disconnect message. For example: Dec 03 07:51:09 imap-login: Di

Re: [Dovecot] SSL issues on separate IPs

2010-12-02 Thread Tim Traver
Timo, ok, I have more info from your suggestion to use the openssl test client connect. I do have about a dozen more configs on different IP's, and they seem to work. I just didn't include them. I get the following error when trying to connect to that IP : [r...@mta2]# openssl s_client -connect

Re: [Dovecot] SSL issues on separate IPs

2010-12-02 Thread Timo Sirainen
On 3.12.2010, at 2.15, Tim Traver wrote: > local 209.132.xx.4 { > ssl_cert = ssl_key = } > > I have several of these, and there appears to be a problem with one in > particular that is dropping connections, and I'm not sure why. Your doveconf output has two and here you say several. So are the

[Dovecot] SSL issues on separate IPs

2010-12-02 Thread Tim Traver
Hi Timo, I have set up 2.07 to answer on several different IP's with different SSL certs, like the following : local 209.132.xx.4 { ssl_cert =