Koozali.org: home of the SME Server

SME 7.1 and TLS - moving from 3.0 to 3.1

slepmog

SME 7.1 and TLS - moving from 3.0 to 3.1
« on: March 03, 2007, 12:57:16 PM »
We recently upgraded to SME 7.1 and enabled POP3 and IMAP via SSL.
After that some of the server clients reported they cannot access their mail. The problem is that client software starts TLS procedure and then refuses to continue because "This server uses TLS v3.0 which is considered obsolete and insecure. The server must use TLS v3.1 or above."

How do we non-techie set up the server to use TLS 3.1?
Had a look at the manual, but the screenshots didn't seem useful :(

Offline byte

  • *
  • 2,183
  • +2/-0
Re: SME 7.1 and TLS - moving from 3.0 to 3.1
« Reply #1 on: March 03, 2007, 11:13:23 PM »
Quote from: "slepmog"
We recently upgraded to SME 7.1 and enabled POP3 and IMAP via SSL.
After that some of the server clients reported they cannot access their mail. The problem is that client software starts TLS procedure and then refuses to continue because "This server uses TLS v3.0 which is considered obsolete and insecure. The server must use TLS v3.1 or above."


Please report bugs and potential bugs in the bug tracker - Thanks!
--[byte]--

Have you filled in a Bug Report over @ http://bugs.contribs.org ? Please don't wait to be told this way you help us to help you/others - Thanks!

slepmog

SME 7.1 and TLS - moving from 3.0 to 3.1
« Reply #2 on: March 04, 2007, 05:48:42 AM »
Um... I didn't think using another version of TLS was a bug :roll:
It's just sort of incompatibility between the server and its clients, and I thought it was a matter of one missed checkbox or something... but ok, I'll check the bugtracker.

Offline byte

  • *
  • 2,183
  • +2/-0
Re: SME 7.1 and TLS - moving from 3.0 to 3.1
« Reply #3 on: March 04, 2007, 02:33:04 PM »
Quote from: "slepmog"
"This server uses TLS v3.0 which is considered obsolete and insecure. The server must use TLS v3.1 or above."


Slepmog,

This is the reason why it needs to be logged as a bug because if we using something considered to be obsolete and insecure we need to look at it to do something about it.

Thanks!
--[byte]--

Have you filled in a Bug Report over @ http://bugs.contribs.org ? Please don't wait to be told this way you help us to help you/others - Thanks!