Index: [Article Count Order] [Thread]

Date:  Thu, 28 Sep 2006 23:13:44 +0100
From:  "Vapor" <bluequartz (at mark) vaporised.com>
Subject:  [coba-e:07284] Re: Dovecot SSL warning (not error) [update2]
To:  coba-e (at mark) bluequartz.org
Message-Id:  <20060928220614.M17922 (at mark) vaporised.com>
In-Reply-To:  <451C043E.1738.15D6CC2@localhost>
References:  <20060928135227.M4521 (at mark) vaporised.com> <451C043E.1738.15D6CC2 (at mark) localhost>
X-Mail-Count: 07284

> If you move a certificate from one server to another you may have 
> to get a new one re-issued.
> 
> Certificate security is pretty tight to prevent fraud sights wrongly 
> being identified as kosher sites.

I'm very familiar with Thawte SSL certs in a web context but not others and can say 
that Thawtes can be moved without issue as long as the domain used upon is as issued.

I just didn't imagine that something as simple as encrypting email using SSL/TLS would 
be so problematic, certainly not needing yet more commericial certificates, what a 
shame. I will be transferring many SSL certs to this box when it's stable with all 
issues resolved hence my persistance.

Well, it's technically doable at least with self signed certs so I'm half happy. Just 
need to work out how to get dovecot to use certs for the domain in question rather than 
just the one pointed to in the conf file. Maybe dovecot.conf allows environmental vars 
so certs could be referred to with local relative paths to a users/domains "home"?

At least we have the functionality to play with with dovecot, thank you Hisao! :)

Kindest

Brett