Re: dovecot sometimes sends non-default SSL cert if IMAP client won't send SNI

2018-07-24 Thread Aki Tuomi
sends non-default SSL cert if IMAP client   won't send SNI Sure, and thanks for trying to help! These are the two correct answers when SNI is included. The certificates are fully chained. Both certificates carry the same subject mail.cs.sbg.ac.at but differ in Subject Alternative Name (SAN). X

Re: dovecot sometimes sends non-default SSL cert if IMAP client won't send SNI

2018-07-24 Thread Martin Johannes Dauser
Sure, and thanks for trying to help! These are the two correct answers when SNI is included. The certificates are fully chained. Both certificates carry the same subject mail.cs.sbg.ac.at but differ in Subject Alternative Name (SAN). X509v3 Subject Alternative Name:    DNS:mail.cs.sbg.ac.at, DNS:

Re: dovecot sometimes sends non-default SSL cert if IMAP client won't send SNI

2018-07-23 Thread Aki Tuomi
Can you provide some details on what those openssl commands returned? Aki On 20.07.2018 12:14, Martin Johannes Dauser wrote: > Hi, > > I recognised some funny behaviour on my server. IMAP clients which > won't send an Server Name Indication (SNI) sometimes get the wrong > certificate. I would ex

dovecot sometimes sends non-default SSL cert if IMAP client won't send SNI

2018-07-20 Thread Martin Johannes Dauser
Hi, I recognised some funny behaviour on my server. IMAP clients which won't send an Server Name Indication (SNI) sometimes get the wrong certificate. I would expect that those clients always get the default certificate (of my new domain), instead in about 20 to 50% of connections the certificat