Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Markus Fritz
Am 09.05.2012 22:40, schrieb Ken Stevenson: > On 2012-05-08 14:17, Markus Fritz wrote: >> Hello, >> >> the error is still present: >> May 8 19:47:18 opsys dovecot: imap-login: Disconnected (no auth >> attempts): rip=82.113.119.140, lip=78.46.216.126 >> >> Whenever I start a session with openssl to

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Ken Stevenson
On 2012-05-08 14:17, Markus Fritz wrote: Hello, the error is still present: May 8 19:47:18 opsys dovecot: imap-login: Disconnected (no auth attempts): rip=82.113.119.140, lip=78.46.216.126 Whenever I start a session with openssl to STARTTTL (Server: mail.opsys.de) the handshake is successfull.

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Janne Snabb
On 2012-05-10 03:29, Markus Fritz wrote: > The key still has (when I do openssl x509 -in ssl.crt -noout -text) > X509v3 Basic Constraints: > CA:FALSE I believe this only means that you can not use the certificate as a CA certificate and issue sub-certificates of that certificate.

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Markus Fritz
Am 09.05.2012 18:50, schrieb Janne Snabb: > On 2012-05-09 22:48, Markus Fritz wrote: >> Thanks! That might help, yes I got the sub.class1.server.ca.pem file. >> How I include this to my ssl.crt file now? > Just append the intermediate CA certificate in the same file AFTER your > own certificate. As

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Janne Snabb
On 2012-05-09 22:48, Markus Fritz wrote: > Thanks! That might help, yes I got the sub.class1.server.ca.pem file. > How I include this to my ssl.crt file now? Just append the intermediate CA certificate in the same file AFTER your own certificate. As in: # cat sub.class1.server.ca.pem >> ssl.crt

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Markus Fritz
Am 09.05.2012 17:07, schrieb Bill Cole: > On 9 May 2012, at 9:51, Markus Fritz wrote: > >> Am 09.05.2012 15:42, schrieb Bill Cole: >>> On 9 May 2012, at 9:05, Markus Fritz wrote: >>> -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Am 09.05.2012 14:32, schrieb Ken Stevenson: >>

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Bill Cole
On 9 May 2012, at 9:51, Markus Fritz wrote: Am 09.05.2012 15:42, schrieb Bill Cole: On 9 May 2012, at 9:05, Markus Fritz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Am 09.05.2012 14:32, schrieb Ken Stevenson: I got only this keys. Can you explain me what exactly you mean with ad

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Markus Fritz
Am 09.05.2012 15:42, schrieb Bill Cole: > On 9 May 2012, at 9:05, Markus Fritz wrote: > >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> Am 09.05.2012 14:32, schrieb Ken Stevenson: I got only this keys. Can you explain me what exactly you mean with adding chains? And I

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Bill Cole
On 9 May 2012, at 9:05, Markus Fritz wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Am 09.05.2012 14:32, schrieb Ken Stevenson: I got only this keys. Can you explain me what exactly you mean with adding chains? And I wonder why this error only occurs in Thunderbird, not in openssl.

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Markus Fritz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Am 09.05.2012 14:32, schrieb Ken Stevenson: >> >> I got only this keys. Can you explain me what exactly you mean with >> adding chains? >> And I wonder why this error only occurs in Thunderbird, not in openssl. >> > > Never mind, I don't think my fir

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Ken Stevenson
I got only this keys. Can you explain me what exactly you mean with adding chains? And I wonder why this error only occurs in Thunderbird, not in openssl. Never mind, I don't think my first guess was correct. I wonder if it has to do with the error 27 reported in the verify by openssl. Acco

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-09 Thread Markus Fritz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Am 08.05.2012 20:58, schrieb Ken Stevenson: > I'm just learning about this, but I was able to get it working recently. Also I haven't read your earlier posts. > > Did you receive intermediate certificates from StartCom? When I got my certificate, I h

Re: [Dovecot] Thunderbird STARTTLS error

2012-05-08 Thread Ken Stevenson
I'm just learning about this, but I was able to get it working recently. Also I haven't read your earlier posts. Did you receive intermediate certificates from StartCom? When I got my certificate, I had to concatenate together the contents of the domain_name.crt file and the gd_bundle.crt file

[Dovecot] Thunderbird STARTTLS error

2012-05-08 Thread Markus Fritz
Hello, the error is still present: May 8 19:47:18 opsys dovecot: imap-login: Disconnected (no auth attempts): rip=82.113.119.140, lip=78.46.216.126 Whenever I start a session with openssl to STARTTTL (Server: mail.opsys.de) the handshake is successfull. Also I am able to login to my account