cyradm and TLS 1.2

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi All,

We're hoping to find some help on the list...

We are running Cyrus-IMAP on RHEL7, using an RPM pkg (cyrus-imapd-2.4.17-13.el7) built from the Red Hat SRC RPM.  We also have SASL, Utils, devel etc pkgs all from RH.

Now we're looking to finally move Cyrus completely off insecure TLS versions.  But now there is a lingering issue...

We removed tls1_0 from impad.conf, and the CYRADM shell stopped working.  We can no longer connect at all:

cyradm -u cyrus <server>
[ SSL_connect error -1 ]
[ SSL session removed ]
[ TLS negotiation did not succeed ]
cyradm: cannot authenticate to server with as cyrus

cyradm -u cyrus --notls <server>
[ SSL_connect error -1 ]
[ SSL session removed ]
[ TLS negotiation did not succeed ]
cyradm: cannot authenticate to server with as cyrus

The presumption is (as cyradm is just a wrapper script) any PERL scripts calling Cyrus::IMAP::Admin over a STARTTLS connection could likewise be broken (?) if we block TLS 1.0. 

cyradm is using TLSv1 per maillog:

imaps[14096]: starttls: TLSv1 with cipher <snip>

Our MAN page for cyradm shows a "--notls" option, which does not work/changes nothing.  Oddly, the cyradm help flag does NOT show this option, yet cyradm doesn't bark when it's passed:

Usage: cyradm [args] server
--user <user> Connect as <user> (authentication name)
--authz <user> Authorize as <user>
--[no]rc (Do not) load the configuration files
--systemrc <file> Use system-wide configuration <file>
--userrc <file> Use user configuration <file>
--port <port> Connect to server on <port>
--auth <mechanism> Authenticate with <mechanism>

A web search reveals the MAN page for cyradm in Cyrus v.3, and it shows notls as an option to AUTHENTICATE, after a server connection is made, so its unclear to me what's going on... 

Does anyone have cyradm working with TLS1.2?
 
Regards & THANKS in advance for any assistance or suggestions offered.
 
--
John
----
Cyrus Home Page: http://www.cyrusimap.org/
List Archives/Info: http://lists.andrew.cmu.edu/pipermail/info-cyrus/
To Unsubscribe:
https://lists.andrew.cmu.edu/mailman/listinfo/info-cyrus

[Index of Archives]     [Cyrus SASL]     [Squirrel Mail]     [Asterisk PBX]     [Video For Linux]     [Photo]     [Yosemite News]     [gtk]     [KDE]     [Gimp on Windows]     [Steve's Art]

  Powered by Linux