Date: Sun, 10 May 2015 23:10:10 -0400 From: Jon Radel <jon@radel.com> To: freebsd-questions@freebsd.org Cc: Ernie Luzar <luzar722@gmail.com> Subject: Re: Certificate error Message-ID: <55501D92.2020102@radel.com> In-Reply-To: <554FC878.7070401@gmail.com> References: <554FC878.7070401@gmail.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] On 5/10/15 5:07 PM, Ernie Luzar wrote: > Hello list; > Been trying to setup qpopper to use TLS. > I am stuck at getting a self signed certificate to work. > Running fetchmail on the host to get a good log of what is really > happening > as shown below. After that list is the script I use to build the > certificates. > Maybe some one can seen what I am doing wrong in the build cert script > based on the errors shown in the fetchmail list.. > Thanks A self-signed certificate and a certificate signed by your own CA aren't even remotely the same thing; I'm confused as to what you're trying to actually do. The list of openssl commands you give shouldn't result in a self-signed certificate. See section 4 of http://www.openssl.org/docs/HOWTO/certificates.txt for the incantation for a self-signed certificate. > > > fetchmail: Server certificate verification error: self signed certificate > fetchmail: Missing trust anchor certificate: > > As a result, I'm kind of confused as to why fetchmail is complaining about a missing trust anchor for a self-signed certificate. But that does lead to the question: Did you install the CA certificate, CA.cert, where fetchmail will use it for verifying certificates? You should also realize that if you want to use your own CA, you're much better off not creating a new one willy-nilly, as you need to install the CA cert for every client which you want to actually verify the certificates signed by that CA. See http://lists.ccil.org/pipermail/fetchmail-friends/2006-April/010051.html for more. --Jon Radel jon@radel.com [-- Attachment #2 --] 0 *H 010 + 0 *H 00 #SanzTgk!0 *H 0o10 USE10U AddTrust AB1&0$UAddTrust External TTP Network1"0 UAddTrust External CA Root0 141222000000Z 200530104838Z010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0"0 *H 0 zSNpRV&IQZI`zQBy"aNv# J n=ٺ.CRC|2PȦOZϓ%{0dV*$3DiFK3@@:*S= a<UNv%!)|qvO_T{5R"=,0-1YR73i-C֥wgQ'뼥8v8ߌIs:2:=F:WtaP@?⟢! 00U#0z4&&T$T0UakᢠOg£ 0U0U0 0U%0++0U 00U 0DU=0;09753http://crl.usertrust.com/AddTrustExternalCARoot.crl05+)0'0%+0http://ocsp.usertrust.com0 *H *nU:Uka+ #fjow^a } [jr AX&MX"cR6}Xޫ;cs{B#ʶM>K-ػBKiۦ74{:ǟO4ne6d)5ֱqC>2Svʆ4,Jؙ ␒ZBj#!eջ~ꌅ b:,Yř38zyJ&|00sT<}k `i 0 *H 010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0 150330000000Z 180329235959Z010 UUS10U2215010 UVA10USpringfield10U 6917 Ridgeway Dr.10U Jon T. Radel1200U)Issued through Jon T. Radel E-PKI Manager10UCorporate Secure Email10U Jon Radel10 *H jon@radel.com0"0 *H 0 aЩ@@g3eGރ͛; d#>q7&Hf :3vL"jV#Xݷ>U-H[$SUڻ{Ϝ,z¶IchO=rcyrn v.Vh7k;%ueYuӬnz6!| !Aȡ+,u+ CAպF-un#vjUJWnk%j] 2JPkl 00U#0akᢠOg£ 0UE|GDp/ʚB0U0U0 0U%0++0FU ?0=0;+10+0)+https://secure.comodo.net/CPS0]UV0T0RPNLhttp://crl.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crl0+00X+0Lhttp://crt.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crt0$+0http://ocsp.comodoca.com0U0 jon@radel.com0 *H KS `?H_D`8G߿VbĘ<tB-Ӈї|{'Ũݹg0Gp$%F(;*MO*gt$@ t6,?0|#ăz,&! {j2i[%b7ߪP+9G㲍["y<?8rZ'[UR6%L̤ w"=:L~Ƨ^jf36 OP1.}(e110-0010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k `i 0 + U0 *H 1 *H 0 *H 1 150511031010Z0# *H 1/ @ye0l *H 1_0]0 `He*0 `He0 *H 0*H 0 *H @0+0 *H (0 +710010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k `i 0*H 1010 UGB10UGreater Manchester10USalford10U COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k `i 0 *H )dh1kt.̾W澪1rR{ضl<{1* 4J LYwKy*L7rc<ɖ:)U9N@UFω1] H4Q&lBXU7DaH9Ph"2hғ GORoJ2 UHQivN8dȷ&7G|Ma
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?55501D92.2020102>
