(I'll re-add the list to the cc, because this is the third time I get the same suggestion. Please bear with me ;) On Tue, Jul 03, 2007 at 09:05:37AM +0200, Michael Menge wrote: > one awy could be to add cnames in the field subjectalternatename, > or use wildcards like *.mappi.helsinki.fi in the certificate Thanks for the suggestion. Yes, this would be a very good way to do this. But we don't trust that the diversity of IMAP/SSL clients out there know how to handle wildcard certificates correctly. Perhaps in a couple of years time... ;) (People at the university seem to be very conservative about how they read their email. We still haven't got rid of our unix mail spool based email system; there is a vocal minority using it instead of our IMAP service... On the other hand, supporting legacy systems is something of a matter of pride (i.e. a bit extra work for IT staff against a lot of (albeit one-time) learning work for many others...)) --Janne -- Janne Peltonen <janne.peltonen@xxxxxxxxxxx> ---- Cyrus Home Page: http://cyrusimap.web.cmu.edu/ Cyrus Wiki/FAQ: http://cyrusimap.web.cmu.edu/twiki List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html