9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
* (no subject)
@ 2020-10-21  0:17 Steve Simon
  2020-10-21  3:45 ` [9fans] Lucio De Re
  0 siblings, 1 reply; 2+ messages in thread
From: Steve Simon @ 2020-10-21  0:17 UTC (permalink / raw)
  To: 9fans

Hi people,

I have had to renew my certificate for tls and am getting a strange error from imap4d
when trying to collect email from my iphone.

	tls reports failed: factotum_rsa_open: no key matches proto=rsa service=tls role=client 

Which does not make sense to me as my factotum has my new ras key in it:

	key proto=rsa service=tls role=client owner=* size=2048 ek=10001 !dk=...

I have also put the same key in bootes factotum so it can be used for smtp outgoing mail, and rebooted to populate bootes factotum.

I have updated /sys/lib/tls/mail.pem, I even remembered to import the PEM
certificate (profile as apple calls it) into my phone.

What have I missed? why can't tlssrv find my key in my factotum?

-Steve


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [9fans]
  2020-10-21  0:17 Steve Simon
@ 2020-10-21  3:45 ` Lucio De Re
  0 siblings, 0 replies; 2+ messages in thread
From: Lucio De Re @ 2020-10-21  3:45 UTC (permalink / raw)
  To: 9fans

On 10/21/20, Steve Simon <steve@quintile.net> wrote:
> Hi people,
>
> I have had to renew my certificate for tls and am getting a strange error
> from imap4d
> when trying to collect email from my iphone.
>
>         tls reports failed: factotum_rsa_open: no key matches proto=rsa
> service=tls role=client
>
> Which does not make sense to me as my factotum has my new ras key in it:
>
Steve,

I found that a key size of 4096 didn't work and your diagnostic
message is what I remember seeing. I'm sure 1024 was OK and I never
got to try 2048 (or identify and fix the 4096 issue).

Don't give too much weight to the above, the problem may well be
elsewhere, but you may want to try 1024 bits first.

I have yet to get ssh to work adequately on my network; there are so
many factors involved it is just easier to use Linux. Which I find
unfortunate. If you make some progress or need me to help in some way,
please let me know.

Lucio.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2020-10-21  3:45 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-10-21  0:17 Steve Simon
2020-10-21  3:45 ` [9fans] Lucio De Re

9fans - fans of the OS Plan 9 from Bell Labs

This inbox may be cloned and mirrored by anyone:

	git clone --mirror http://inbox.vuxu.org/9fans

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V1 9fans 9fans/ http://inbox.vuxu.org/9fans \
		9fans@9fans.net
	public-inbox-index 9fans

Example config snippet for mirrors.
Newsgroup available over NNTP:
	nntp://inbox.vuxu.org/vuxu.archive.9fans


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git