Re: trusted vs. verified TLS connection

2014-12-10 Thread Viktor Dukhovni
On Wed, Dec 10, 2014 at 01:13:22PM +0100, A. Schulze wrote: > while checking TLS to a destination domain I noticed a difference. > posttls-finger say "Verified" but log say (only) "Trusted". The posttls-finger(1) utility defaults to the "dane" security level when TLSA records are present and "sec

trusted vs. verified TLS connection

2014-12-10 Thread A. Schulze
Hello, while checking TLS to a destination domain I noticed a difference. posttls-finger say "Verified" but log say (only) "Trusted". # posttls-finger -c -F /etc/ssl/mail/trusted_cas.pem avira.com posttls-finger: mx1.c01.avira.com[212.79.247.134]:25: subjectAltName: mx.ames.avira.net postt