Skip to Content.
Sympa Menu

cacert-devel - Re: AW: Make SHA2-512 optional

Subject: CAcert Code Development list.

List archive

Re: AW: Make SHA2-512 optional


Chronological Thread 
  • From: TJ <thorbenj-cacert AT eryri.ch>
  • To: Marcus Mängel <m.maengel AT inopiae.de>
  • Cc: 'Benny Baumann' <benbe AT cacert.org>, cacert-support AT lists.cacert.org, cacert-devel AT lists.cacert.org
  • Subject: Re: AW: Make SHA2-512 optional
  • Date: Sun, 23 Mar 2014 14:18:01 +0100

Hi Marcus,

I can send email from my gmail account to both root AT test.eryri.ch and hostmaster AT test.eryri.ch. Feel free to send an email yourself if you wish.
NB There is no A record, but there a MX record and that should be enough.

anything@*.eryri.ch really goes to thing AT eryri.ch. I just don't want to add my main domain into the test system, that's why I chose to add test.eryri.ch.

Regards,

Thorben


On 2014-03-23 13:39, Marcus Mängel wrote:
Hi Thorben,

is the domain test.eryri.ch existing?
Are the email addresses
postmaster AT test.eryri.ch
or root@
test.eryri.ch existing.

Normally it works with any existing public domain.

BR

Marcus

-----Ursprüngliche Nachricht-----
Von:
cacert-devel-request AT lists.cacert.org
[mailto:cacert-devel-request AT lists.cacert.org]
Im Auftrag von TJ
Gesendet: Sonntag, 23. März 2014 12:50
An: Benny Baumann
Cc:
cacert-support AT lists.cacert.org;

cacert-devel AT lists.cacert.org
Betreff: Re: Make SHA2-512 optional

Hi Benny,

On 2014-03-21 01:55, Benny Baumann wrote:
Hi TJ,

Am 17.03.2014 13:24, schrieb TJ:
Hi Benny,

Thank you for taking the time to reply to this.

...
Is there way to get a certificate with another cypher than sha512?
Currently not. But we are working on the issue. If you want to speed
things up you can help with creating (or testing) a patch as soon as
it comes available.

I am not sure if I know enough about your setup to help with
creating, but if you have something to try I'd be happy to test it.
A proposed patch has been merged to the testserver at test.cacert.org.
Would you like to have a look at the patch and test if it works as
intended?

Contrary to what is written in the bug description of bug 807 you can
find some notes about the implementation Michael and I have choosen in
https://bugs.cacert.org/view.php?id=807#c4665 which boils down to: The
signature in the CSR is ignored and instead you select the algorithm
provided in the HTML form.

As a tester your job is to try to break the patch so it does things
that don't match up with the intention of the patch. Good luck :P

I managed to create an account for myself (using the management system
to pass the email check). However I have been unable to add a domain
to my account. I tried the following:

1. Add a domain in the normal way (test.eryri.ch)

I selected
hostmaster AT test.eryri.ch,
and got the following error:

"""""
Email Address given was invalid, or a test connection couldn't be made
to your server, or the server rejected the email address as invalid

Failed to make a connection to the mail server """""

I also checked the management system for an email, as well as my own email.

2. Looked around the management system for a way to manipulate my
account and add the domain. (Expected some add domain form)

3. Wandered around the wiki to see if I could find information on
how to add domains. (I see all outbound email is blocked and should be
redirected to the management system)


So I've already broken the test system, or I missed some important
point on adding domains to accounts.

Regards,

Thorben


-----
E-Mail ist virenfrei.
Von AVG überprüft - www.avg.de
Version: 2014.0.4336 / Virendatenbank: 3722/7233 - Ausgabedatum: 22.03.2014



Archive powered by MHonArc 2.6.18.

Top of Page