D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] SMTP authorisatio by certificates - Theo?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thursday 13 November 2003 9:06 pm, Simon Waters wrote:
> Okay, I want to do some funky things with email......

the more funky you make things, the more clients it breaks :/

> Been playing with SMTP over SSL (SSMTP).
>
> So far discovered you need to patch Outlook 2002 :(

yup, there is an SSL bug in windows iirc, one the the win2k or office SPs fix 
it (forgot which one now).

> Although what they were doing with an unpatched copy of Outlook.

customers, customers ;)  we still have cutomers using win95 with outlook 
dispress god_knows_what_version.  really.

"It works for me" is the answer when we tell them UPGRADDEEeE!

> Mozilla only wants to talk TLS, not SSL :(

mm, never played with it.

> Kmail and OE play along nicely. Anyone else know any others?

I don't know of any that don't, to be honest (that support SSL).  I use eudora 
on my palm, that works well, and whatever mail client mac monkeys use these 
days - that works, too.

infact, i've not heard of any with problems, except OE/Outlook really.

> Whilst we'll probably go SMTP Auth in the longer term, I'm fairy sure
> Theo mentioned authorising people by Certificates for sending SMTP. This
> would be handy for some transitional stuff we are doing.
>
> However I couldn't see a way to specify which certificate the client
> shoud present with SSL (if you ignore using stunnel to effect a VPN), so
> is this with TLS? Did I miss something?

I wasn't talking about end users, but about ISP to ISP mail for verification. 
End users are on our network, and fully traceable.

although, i can see no reason why you can't use client certificates for 
sending mail, in windows, this should be handled directly by windows, and at 
in KDE by using the cetificate manager in kcontrol.  never tried it though, 
but see no reason why it wont!

 ~ Theo

- -- 
Theo Zourzouvillys
<theo@xxxxxxxxxxxxxxxx>
<http://theo.me.uk/>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)

iD8DBQE/tEBW448CrwpTn6YRAq/QAKDsA6kUkroMIVSIAZOLkRf2eJfy4QCgxgUr
bfPwpEKqouLQ8U/mTytzk0Q=
=GlXf
-----END PGP SIGNATURE-----


--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe.


Lynx friendly