TLS question

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

TLS question

Postby deftech » Nov 11 06 10:22 am

When I set wingate to use TLS if avaliable, it won't download email from my webserver running QMAIL for smtp, and COURIER for pop3. It downloads email fine if I uncheck the "use tls if available".

ANy ideas :)

Should I give it some candy? Heres an excerpt from pop3 log.
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: +OK Hello there. <16087.1163201198@localhost.localdomain>
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com C=>: CAPA
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: +OK Here's what I can do:
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: STLS
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: USER
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: LOGIN-DELAY 10
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: UIDL
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: IMPLEMENTATION Courier Mail Server
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: .
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com C=>: STLS
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Debug: ricardo@rings-things.com@chib.rings-things.com <=S: +OK Begin SSL/TLS negotiation now.
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Traffic 12 195 0 0 3s
11/10/06 13:24:44 127.0.0.2 <system> 0000013811 Terminated exit code 0
I love Wingate, and it loves me!
deftech
 
Posts: 91
Joined: Mar 02 06 12:40 pm
Location: USA

Postby adrien » Nov 11 06 11:18 pm

Looks like it is terminating as soon as the other side tells it to go ahead and negotiate a TLS session.

This indicates some sort of problem in the TLS negotiation, which can be things like SSL certificates etc.

Do you know what is being logged on the server you're trying to connect to?

When you watch the POP3 collection job, does it show "unhandled error processing server data" ?

Otherwise it looks like the server is closing the connection.

Adrien
adrien
Qbik Staff
 
Posts: 5448
Joined: Sep 03 03 2:54 pm
Location: Auckland

Howdy Adrien

Postby deftech » Nov 14 06 6:34 am

Hows it goin! Thanks for the reply.

I'm new to the mta on our new server, so I have no idea what the logs are saying at this point in time.

Yes, the pop3 collection says "unhandled error processing server data" when I have the "use tls if available" option selected.

I'm thinking it may be the certificate, since it's just a self signed default server certificate. Would that generate the error you asked about?

3 Cheers to New Zealand!

6 cheers to Jessica Simpson!
I love Wingate, and it loves me!
deftech
 
Posts: 91
Joined: Mar 02 06 12:40 pm
Location: USA

Postby deftech » Nov 17 06 1:03 pm

I was curious to see if anyone had anymore ideas to get this too work? I am sinking fast into a severe depression because I can't get tls or ssl to work.

Sinking....fast....help...gurgle....glub...glub....

:D
I love Wingate, and it loves me!
deftech
 
Posts: 91
Joined: Mar 02 06 12:40 pm
Location: USA

Postby adrien » Nov 18 06 6:09 pm

Hi

do you know if the server requires client-certificates? this could be the reason, normally WinGate doesn't care about the server certificate.

Adrien
adrien
Qbik Staff
 
Posts: 5448
Joined: Sep 03 03 2:54 pm
Location: Auckland

Postby deftech » Nov 29 06 9:04 am

Well it turned out to be the certificate on my webserver. I just had to create it right.

ALso I wanted to mention another problem that I had already fixed. The problem was my pop3 daemon Courier, was causing Wingate pop3 collection to lock up on a random account, eventually causing pop3 collection to just stop completely.

I had to set courier's MAXPERIP=100. It's default is 4!

After changing that in Courier, all is well with Wingate.

Just wanted to share.
I love Wingate, and it loves me!
deftech
 
Posts: 91
Joined: Mar 02 06 12:40 pm
Location: USA


Return to WinGate

Who is online

Users browsing this forum: No registered users and 1 guest

cron