Bron Gondwana wrote: DBR> <https://bugzilla.andrew.cmu.edu/show_bug.cgi?id=2642> BG> we use nginx in front of cyrus, so we don't use the built-in BG> tls engine at all. I wouldn't feel comfortable testing this BG> one. Is anyone running it on top of 2.3.14, or only on the BG> 2.2 series? Not yet. I'm going test it on the Sirius tree (and hence sort out interactions with https://bugzilla.andrew.cmu.edu/show_bug.cgi?id=3119 and https://bugzilla.andrew.cmu.edu/show_bug.cgi?id=3133 ) once I've merged 2.3.15 there and into Debian mainline. "tls_require_cert optional" would open the possibility of doing both cert-based auth FE-to-BE and still allowing referrals with non-cert clients... Cheers Duncan -- Duncan Gibb - Technical Director Sirius Corporation plc - control through freedom http://www.siriusit.co.uk/ || t: +44 870 608 0063 Debian Cyrus Team - https://alioth.debian.org/projects/pkg-cyrus-imapd/ ---- Cyrus Home Page: http://cyrusimap.web.cmu.edu/ Cyrus Wiki/FAQ: http://cyrusimap.web.cmu.edu/twiki List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html