Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

24 Apr, 2024: Testing a new version of the Overboard here. If you have an issue post about it to rocksolid.nodes.help (I know. Everyone on Usenet has issues)


computers / comp.mail.sendmail / Re: dh key too small

SubjectAuthor
* dh key too smallNone
+* Re: dh key too smallClaus Aßmann
|`* Re: dh key too smallNone
| `* Re: dh key too smallClaus Aßmann
|  `* Re: dh key too smallNone
|   `* Re: dh key too smallClaus Aßmann
|    `* Re: dh key too smallNone
|     `* Re: dh key too smallClaus Aßmann
|      `* Re: dh key too smallNone
|       `* Re: dh key too smallClaus Aßmann
|        `- Re: dh key too smallNone
`* Re: dh key too smallClaus Aßmann
 `- Re: dh key too smallNone

1
dh key too small

<tjom10$guni$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=618&group=comp.mail.sendmail#618

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: hzcnjkx...@tormails.com (None)
Newsgroups: comp.mail.sendmail
Subject: dh key too small
Date: Mon, 31 Oct 2022 15:26:23 +0100
Organization: A noiseless patient Spider
Lines: 16
Message-ID: <tjom10$guni$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 31 Oct 2022 14:27:44 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="80ec9890f793f14eb1044e44683a6233";
logging-data="555762"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19yvREJSNlMao7CKN2XorJDgDqBJL6euI/nO19QLZQ5DQ=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.5.1
Cancel-Lock: sha1:w1QFqeHS3+bqSFxOfmFCDfIlbz8=
Content-Language: en-US
 by: None - Mon, 31 Oct 2022 14:26 UTC

I have recently upgraded to centos9stream and removed the

LOCAL_CONFIG
O CipherList=HIGH
O ServerSSLOptions=+SSL_OP_NO_SSLv2 +SSL_OP_NO_SSLv3
+SSL_OP_CIPHER_SERVER_PREFERENCE

Assuming that the 8.16 has a better default configuration, yet I am
seeing still a few "dh key too small" errors in the logs.

The key has been generated with

openssl dhparam -out dhparams.pem 2048

Should I still force ciphers, or is there something wrong with a key of
2048?

Re: dh key too small

<tjosu1$r2r$1@news.misty.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=619&group=comp.mail.sendmail#619

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!.POSTED.veps.esmtp.org!not-for-mail
From: INVALID_...@esmtp.org (Claus Aßmann)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Mon, 31 Oct 2022 12:25:37 -0400 (EDT)
Organization: MGT Consulting
Sender: <ml+sendmail(-no-copies-please)@esmtp.org>
Message-ID: <tjosu1$r2r$1@news.misty.com>
References: <tjom10$guni$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 31 Oct 2022 16:25:37 -0000 (UTC)
Injection-Info: news.misty.com; posting-host="veps.esmtp.org:155.138.203.148";
logging-data="27739"; mail-complaints-to="abuse@misty.com"
Mail-Copies-To: never
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: ca@x2.esmtp.org (Claus Assmann)
 by: Claus Aßmann - Mon, 31 Oct 2022 16:25 UTC

None wrote:

> Assuming that the 8.16 has a better default configuration, yet I am
> seeing still a few "dh key too small" errors in the logs.

Please post a log entry: is it your system or the other side
that's complaining?

AFAIR some Linux distributions use ... "uncommon" settings
in the OpenSSL compilation -- check the archive for other
postings about this problem.

--
Note: please read the netiquette before posting. I will almost never
reply to top-postings which include a full copy of the previous
article(s) at the end because it's annoying, shows that the poster
is too lazy to trim his article, and it's wasting the time of all readers.

Re: dh key too small

<tjp8j4$ieaq$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=620&group=comp.mail.sendmail#620

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: hzcnjkx...@tormails.com (None)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Mon, 31 Oct 2022 20:44:35 +0100
Organization: A noiseless patient Spider
Lines: 26
Message-ID: <tjp8j4$ieaq$1@dont-email.me>
References: <tjom10$guni$1@dont-email.me> <tjosu1$r2r$1@news.misty.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 31 Oct 2022 19:44:36 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="80ec9890f793f14eb1044e44683a6233";
logging-data="604506"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/gTHKO20GyUHNlrNxqAiK8uwpOQ5nVssZFdtmBJP0GXg=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.5.1
Cancel-Lock: sha1:3JteJ+2lz/NJpCucv5M0x/2z78E=
Content-Language: en-US
In-Reply-To: <tjosu1$r2r$1@news.misty.com>
 by: None - Mon, 31 Oct 2022 19:44 UTC

>> Assuming that the 8.16 has a better default configuration, yet I am
>> seeing still a few "dh key too small" errors in the logs.
>
> Please post a log entry: is it your system or the other side
> that's complaining?

It is theirs, this is an outgoing, mostly this trendmicro, but also some
facebook smtpin

sendmail[95017]: STARTTLS=client, error: connect failed=-1, reason=dh
key too small, SSL_error=1, errno=0, retry=-1
sendmail[95017]: ruleset=tls_server, arg1=SOFTWARE,
relay=in.hes.trendmicro.eu, reject=403 4.7.0 TLS handshake failed.
sendmail[95017]: 29RFGr81082301: to=<xxxxxxx>, delay=2+11:17:23,
xdelay=00:00:00, mailer=esmtp, pri=5613815, relay=in.hes.trendmicro.eu.
[52.58.62.239], dsn=4.0.0, stat=Deferred: 403 4.7.0 TLS handshake failed.

> AFAIR some Linux distributions use ... "uncommon" settings
> in the OpenSSL compilation -- check the archive for other
> postings about this problem.
>

I did not expect that in 2022 there still can't be some cipher
successfully negotiated.

Re: dh key too small

<tjqeh3$nir$1@news.misty.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=621&group=comp.mail.sendmail#621

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!.POSTED.veps.esmtp.org!not-for-mail
From: INVALID_...@esmtp.org (Claus Aßmann)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Tue, 1 Nov 2022 02:32:03 -0400 (EDT)
Organization: MGT Consulting
Sender: <ml+sendmail(-no-copies-please)@esmtp.org>
Message-ID: <tjqeh3$nir$1@news.misty.com>
References: <tjom10$guni$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Tue, 1 Nov 2022 06:32:03 -0000 (UTC)
Injection-Info: news.misty.com; posting-host="veps.esmtp.org:155.138.203.148";
logging-data="24155"; mail-complaints-to="abuse@misty.com"
Mail-Copies-To: never
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: ca@x2.esmtp.org (Claus Assmann)
 by: Claus Aßmann - Tue, 1 Nov 2022 06:32 UTC

None wrote:
> I have recently upgraded to centos9stream and removed the

Which sendmail version and which openssl version?
sendmail -bt -d0.14 </dev/null

> Should I still force ciphers, or is there something wrong with a key of
> 2048?

No, but it depends on the versions of sendmail, the library, and
compile time options - hence the request for more info.

Moreover, check whether your cf file actually references
the generated data.

--
Note: please read the netiquette before posting. I will almost never
reply to top-postings which include a full copy of the previous
article(s) at the end because it's annoying, shows that the poster
is too lazy to trim his article, and it's wasting the time of all readers.

Re: dh key too small

<tjqvba$p2qt$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=622&group=comp.mail.sendmail#622

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!news.nntp4.net!weretis.net!feeder8.news.weretis.net!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: hzcnjkx...@tormails.com (None)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Tue, 1 Nov 2022 12:19:04 +0100
Organization: A noiseless patient Spider
Lines: 53
Message-ID: <tjqvba$p2qt$1@dont-email.me>
References: <tjom10$guni$1@dont-email.me> <tjqeh3$nir$1@news.misty.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 1 Nov 2022 11:19:06 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="afca75f8825ad133325acfb79a66ed08";
logging-data="822109"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX186QnAHc4mEONolWBAJL1xiC2m+Sz2YcsnqS8XvjqfG4A=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.5.1
Cancel-Lock: sha1:qrdBKrEj0o9YDlHBxboW8s6KvRU=
Content-Language: en-US
In-Reply-To: <tjqeh3$nir$1@news.misty.com>
 by: None - Tue, 1 Nov 2022 11:19 UTC

> Which sendmail version and which openssl version?
> sendmail -bt -d0.14 </dev/null
>

> [@~]# sendmail -bt -d0.14 -bt < /dev/null
Version 8.16.1
Compiled with: DANE DNSMAP HES_GETMAILHOST IPV6_FULL LDAPMAP
LDAP_NETWORK_TIMEOUT LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8
MIME8TO7 NAMED_BIND NETINET NETINET6 NETUNIX NEWDB=5.3 CDB=1
PIPELINING SASLv2 SCANF SOCKETMAP STARTTLS TLS_EC
TLS_VRFY_PER_CTX USERDB USE_LDAP_INIT
OS Defines: ADDRCONFIG_IS_BROKEN HASFCHOWN HASFCHMOD
HASGETDTABLESIZE HAS_GETHOSTBYNAME2 HASINITGROUPS HASLSTAT
HASNICE HASRANDOM HASRRESVPORT HASSETREGID HASSETREUID
HASSETRLIMIT HASSETSID HASSETVBUF HASURANDOMDEV HASSTRERROR
HASUNAME HASUNSETENV HASWAITPID IDENTPROTO NEEDSGETIPNODE
REQUIRES_DIR_FSYNC SFS_VFS USE_DOUBLE_FORK USE_SIGLONGJMP
Kernel symbols: /boot/vmlinux
Conf file: /etc/mail/submit.cf (default for MSP)
Conf file: /etc/mail/sendmail.cf (default for MTA)
Pid file: /var/run/sendmail.pid (default)
libsm Defines: SM_CONF_LDAP_INITIALIZE SM_CONF_LDAP_MEMFREE
SM_CONF_LONGLONG SM_CONF_MEMCHR SM_CONF_MSG SM_CONF_SEM
SM_CONF_SIGSETJMP SM_CONF_SHM SM_CONF_SSIZE_T SM_CONF_STDBOOL_H
SM_CONF_STDDEF_H SM_CONF_SYS_CDEFS_H SM_CONF_UID_GID
DO_NOT_USE_STRCPY SM_HEAP_CHECK SM_OS=sm_os_linux SM_VA_STD
FFR Defines: _FFR_MILTER_CHECK_REJECTIONS_TOO _FFR_QOS
_FFR_TLS_USE_CERTIFICATE_CHAIN_FILE
OpenSSL: compiled 0x30000000
OpenSSL: linked 0x30000010

Conf file: /etc/mail/sendmail.cf (selected)
Pid file: /var/run/sendmail.pid (selected)

>> Should I still force ciphers, or is there something wrong with a key of
>> 2048?
>
> No, but it depends on the versions of sendmail, the library, and
> compile time options - hence the request for more info.
>
> Moreover, check whether your cf file actually references
> the generated data.
>

Yes I have even the complete path in sendmail.mc
define(`confDH_PARAMETERS',`/etc/mail/dhparams.pem')dnl

Re: dh key too small

<tkbarr$aem$1@news.misty.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=636&group=comp.mail.sendmail#636

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!.POSTED.veps.esmtp.org!not-for-mail
From: INVALID_...@esmtp.org (Claus Aßmann)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Mon, 7 Nov 2022 11:13:47 -0500 (EST)
Organization: MGT Consulting
Sender: <ml+sendmail(-no-copies-please)@esmtp.org>
Message-ID: <tkbarr$aem$1@news.misty.com>
References: <tjom10$guni$1@dont-email.me> <tjosu1$r2r$1@news.misty.com> <tjp8j4$ieaq$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 7 Nov 2022 16:13:47 -0000 (UTC)
Injection-Info: news.misty.com; posting-host="veps.esmtp.org:155.138.203.148";
logging-data="10710"; mail-complaints-to="abuse@misty.com"
Mail-Copies-To: never
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: ca@x2.esmtp.org (Claus Assmann)
 by: Claus Aßmann - Mon, 7 Nov 2022 16:13 UTC

None wrote:

> sendmail[95017]: STARTTLS=client, error: connect failed=-1, reason=dh
> key too small, SSL_error=1, errno=0, retry=-1

Do you know how to use openssl s_client to test this?

H=in.hes.trendmicro.eu
openssl s_client -connect $H -state -debug -crlf -starttls smtp

My guess is this might trigger the same error
which points to the openssl version/setup on your host,
it rejects the dh key offered by the server.

Please post the result(s)!

--
Note: please read the netiquette before posting. I will almost never
reply to top-postings which include a full copy of the previous
article(s) at the end because it's annoying, shows that the poster
is too lazy to trim his article, and it's wasting the time of all readers.

Re: dh key too small

<tkeknp$p31$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=642&group=comp.mail.sendmail#642

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: hzcnjkx...@tormails.com (None)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Tue, 8 Nov 2022 23:20:39 +0100
Organization: A noiseless patient Spider
Lines: 25
Message-ID: <tkeknp$p31$1@dont-email.me>
References: <tjom10$guni$1@dont-email.me> <tjosu1$r2r$1@news.misty.com>
<tjp8j4$ieaq$1@dont-email.me> <tkbarr$aem$1@news.misty.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 8 Nov 2022 22:20:41 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="f0328016aff8a7d11365968e223db882";
logging-data="25697"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX181IOHVAZKJHj6xtcRCB2ysHiVoYpxkgUOnHRJxRE6BUw=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.5.1
Cancel-Lock: sha1:Ktl1YTW9n+jscs1EzEER4/mkC9I=
Content-Language: en-US
In-Reply-To: <tkbarr$aem$1@news.misty.com>
 by: None - Tue, 8 Nov 2022 22:20 UTC

>> sendmail[95017]: STARTTLS=client, error: connect failed=-1, reason=dh
>> key too small, SSL_error=1, errno=0, retry=-1
>
> Do you know how to use openssl s_client to test this?
>
> H=in.hes.trendmicro.eu
> openssl s_client -connect $H -state -debug -crlf -starttls smtp

[@]# openssl s_client -connect in.hes.trendmicro.eu -state -debug -crlf
-starttls smtp

809BD080237F0000:error:8000006E:system library:BIO_connect:Connection
timed out:crypto/bio/bio_sock2.c:125:calling connect()
809BD080237F0000:error:10000067:BIO routines:BIO_connect:connect
error:crypto/bio/bio_sock2.c:127:
809BD080237F0000:error:8000006E:system library:BIO_connect:Connection
timed out:crypto/bio/bio_sock2.c:125:calling connect()
809BD080237F0000:error:10000067:BIO routines:BIO_connect:connect
error:crypto/bio/bio_sock2.c:127:

Re: dh key too small

<tkfakh$5m8$1@news.misty.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=643&group=comp.mail.sendmail#643

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!.POSTED.veps.esmtp.org!not-for-mail
From: INVALID_...@esmtp.org (Claus Aßmann)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Tue, 8 Nov 2022 23:34:25 -0500 (EST)
Organization: MGT Consulting
Sender: <ml+sendmail(-no-copies-please)@esmtp.org>
Message-ID: <tkfakh$5m8$1@news.misty.com>
References: <tjom10$guni$1@dont-email.me> <tjp8j4$ieaq$1@dont-email.me> <tkbarr$aem$1@news.misty.com> <tkeknp$p31$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Wed, 9 Nov 2022 04:34:25 -0000 (UTC)
Injection-Info: news.misty.com; posting-host="veps.esmtp.org:155.138.203.148";
logging-data="5832"; mail-complaints-to="abuse@misty.com"
Mail-Copies-To: never
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: ca@x2.esmtp.org (Claus Assmann)
 by: Claus Aßmann - Wed, 9 Nov 2022 04:34 UTC

Sorry, you need to add the port:
openssl s_client -connect in.hes.trendmicro.eu:25 -state -debug -crlf -starttls smtp
see also the man page for info.

Re: dh key too small

<tkg6ql$7gk5$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=644&group=comp.mail.sendmail#644

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: hzcnjkx...@tormails.com (None)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Wed, 9 Nov 2022 13:35:32 +0100
Organization: A noiseless patient Spider
Lines: 86
Message-ID: <tkg6ql$7gk5$1@dont-email.me>
References: <tjom10$guni$1@dont-email.me> <tjp8j4$ieaq$1@dont-email.me>
<tkbarr$aem$1@news.misty.com> <tkeknp$p31$1@dont-email.me>
<tkfakh$5m8$1@news.misty.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 9 Nov 2022 12:35:33 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="1d9c390d8b883745b2942c37e06e285a";
logging-data="246405"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19RoeR811J2lEM7AX8lsaaRt+ApCS2nKKFuO7I+cdRsKw=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.5.1
Cancel-Lock: sha1:L5PpFbv/bdmr43m1dZO6dfe6IzQ=
Content-Language: en-US
In-Reply-To: <tkfakh$5m8$1@news.misty.com>
 by: None - Wed, 9 Nov 2022 12:35 UTC

> openssl s_client -connect in.hes.trendmicro.eu:25 -state -debug -crlf -starttls smtp
> see also the man page for info.
>

This is the output, but I am not really sure how this is comparable as
the dhparams.pem file is only in the /etc/mail/ folder and sendmail is
configured for this.

01c0 - e9 d4 fc df 15 09 ab 9d-0c 82 b6 f0 1a cd 99 3f ...............?
01d0 - c3 e3 c6 bd 0b 1d 5d 2f-f3 4c e2 44 40 1d 58 54 ......]/.L.D@.XT
01e0 - 7b f5 cd 31 aa 93 5f 09-31 ac d1 b3 09 4e e0 15 {..1.._.1....N..
01f0 - 83 a9 5c b2 c9 07 98 0e-a4 0a 6f 9c c7 45 63 05 ..\.......o..Ec.
0200 - d3 7c 07 70 fd 83 70 60-6b 28 d7 b6 03 05 b4 .|.p..p`k(.....
write to 0x560e17932310 [0x560e17a1b480] (7 bytes => 7 (0x7))
0000 - 15 03 03 00 02 02 28 ......(
---
Certificate chain
0 s:C = US, ST = California, L = Cupertino, OU = BU, O = TREND MICRO
INCORPORATED, CN = *.hes.trendmicro.eu
i:C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Jan 6 12:59:48 2022 GMT; NotAfter: Feb 7 12:59:48
2023 GMT
1 s:C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
i:OU = GlobalSign Root CA - R3, O = GlobalSign, CN = GlobalSign
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Nov 21 00:00:00 2018 GMT; NotAfter: Nov 21 00:00:00
2028 GMT
2 s:OU = GlobalSign Root CA - R3, O = GlobalSign, CN = GlobalSign
i:OU = GlobalSign Root CA - R3, O = GlobalSign, CN = GlobalSign
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Mar 18 10:00:00 2009 GMT; NotAfter: Mar 18 10:00:00
2029 GMT
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIHcDCCBligAwIBAgIMbm7K6bCG3F4C+uZbMA0GCSqGSIb3DQEBCwUAMFAxCzAJ
BgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSYwJAYDVQQDEx1H
bG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODAeFw0yMjAxMDYxMjU5NDhaFw0y
MzAyMDcxMjU5NDhaMIGEMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5p
YTESMBAGA1UEBxMJQ3VwZXJ0aW5vMQswCQYDVQQLEwJCVTEhMB8GA1UEChMYVFJF

RoLweUxaHa8hEDQS1rJJn1hIhh2FTuiXoVLSiZ+GBlSqJo5WyQw9S5X9iQ1n/zN
WBhLVb91a20XHBcn3eIDxG4b2ps5t6IURVrX1fN6tX+lL74RttpC4G/SahpIaPgD
dCdDIzhmaxGRMz8cxtWTxhmeJnlqCABVbiqOk3wvDZ5IX698pGrPjpWINeRbTOFu
JsFRbZp4ISOf8CZpykGXXexXKGw5O2Q6Ue3k2CbV0H/7x6hGfhuiC+E8OINAaKJ+
tdlr8OIYpGk4RsrTbwD80DZEATMf2agb4CVfL1rwPAfhFSl8
-----END CERTIFICATE-----
subject=C = US, ST = California, L = Cupertino, OU = BU, O = TREND MICRO
INCORPORATED, CN = *.hes.trendmicro.eu
issuer=C = BE, O = GlobalSign nv-sa, CN = GlobalSign RSA OV SSL CA 2018
---
No client certificate CA names sent
---
SSL handshake has read 4727 bytes and written 364 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1.2
Cipher : 0000
Session-ID:
Session-ID-ctx:
Master-Key:
PSK identity: None
PSK identity hint: None
SRP username: None
Start Time: 1667996876
Timeout : 7200 (sec)
Verify return code: 0 (ok)
Extended master secret: no
---
read from 0x560e17932310 [0x560e17891260] (8192 bytes => 9 (0x9))
0000 - 16 03 03 00 04 0e 00 00-00 .........
read from 0x560e17932310 [0x560e17891260] (8192 bytes => 0)

Re: dh key too small

<tkij1u$5ea$1@news.misty.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=645&group=comp.mail.sendmail#645

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!.POSTED.veps.esmtp.org!not-for-mail
From: INVALID_...@esmtp.org (Claus Aßmann)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Thu, 10 Nov 2022 05:16:30 -0500 (EST)
Organization: MGT Consulting
Sender: <ml+sendmail(-no-copies-please)@esmtp.org>
Message-ID: <tkij1u$5ea$1@news.misty.com>
References: <tjom10$guni$1@dont-email.me> <tkeknp$p31$1@dont-email.me> <tkfakh$5m8$1@news.misty.com> <tkg6ql$7gk5$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Thu, 10 Nov 2022 10:16:30 -0000 (UTC)
Injection-Info: news.misty.com; posting-host="veps.esmtp.org:155.138.203.148";
logging-data="5578"; mail-complaints-to="abuse@misty.com"
Mail-Copies-To: never
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: ca@x2.esmtp.org (Claus Assmann)
 by: Claus Aßmann - Thu, 10 Nov 2022 10:16 UTC

None wrote:

> This is the output, but I am not really sure how this is comparable as
> the dhparams.pem file is only in the /etc/mail/ folder and sendmail is
> configured for this.

Because my guess is that it's a problem with the server key --
I get this from in.hes.trendmicro.eu:

Server Temp Key: DH, 1024 bits

which could be considered "too small" by some OpenSSL versions.

So the easiest is to keep the workarounds :-(

--
Note: please read the netiquette before posting. I will almost never
reply to top-postings which include a full copy of the previous
article(s) at the end because it's annoying, shows that the poster
is too lazy to trim his article, and it's wasting the time of all readers.

Re: dh key too small

<uchs25$1laac$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=781&group=comp.mail.sendmail#781

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: hzcnjkx...@tormails.com (None)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Mon, 28 Aug 2023 12:14:28 +0200
Organization: A noiseless patient Spider
Lines: 38
Message-ID: <uchs25$1laac$1@dont-email.me>
References: <tjom10$guni$1@dont-email.me> <tkeknp$p31$1@dont-email.me>
<tkfakh$5m8$1@news.misty.com> <tkg6ql$7gk5$1@dont-email.me>
<tkij1u$5ea$1@news.misty.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 28 Aug 2023 10:14:29 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="8306ba0f210bbf96dabe84891fc4fad2";
logging-data="1747276"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+N4sZn8ok6bB81YZNqBeEq86dG2btS71HasTg6zP89gQ=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.14.0
Cancel-Lock: sha1:olTc0MbISHIXyhUuWYQnR8DfzbM=
In-Reply-To: <tkij1u$5ea$1@news.misty.com>
Content-Language: en-US
 by: None - Mon, 28 Aug 2023 10:14 UTC

>
>> This is the output, but I am not really sure how this is comparable as
>> the dhparams.pem file is only in the /etc/mail/ folder and sendmail is
>> configured for this.
>
> Because my guess is that it's a problem with the server key --
> I get this from in.hes.trendmicro.eu:
>
> Server Temp Key: DH, 1024 bits
>
> which could be considered "too small" by some OpenSSL versions.
>

How do you get this dh key? If I do this on my server I get this

[]# openssl s_client -connect xxxxxxxxxx:25 -starttls smtp | grep -i 'key'
...
verify return:1
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA384
Server Temp Key: ECDH, prime256v1, 256 bits
Server public key is 2048 bit
250 HELP

and on

openssl s_client -connect in.hes.trendmicro.eu:25 -starttls smtp | grep
-i 'key'

verify return:1
807B24935D7F0000:error:0A00018A:SSL routines:tls_process_ske_dhe:dh key
too small:ssl/statem/statem_clnt.c:2092:
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
Server public key is 2048 bit
Master-Key:

Re: dh key too small

<uchtp3$er9$1@news.misty.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=782&group=comp.mail.sendmail#782

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!.POSTED.veps.esmtp.org!not-for-mail
From: INVALID_...@esmtp.org (Claus Aßmann)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Mon, 28 Aug 2023 06:43:47 -0400 (EDT)
Organization: MGT Consulting
Sender: <ml+sendmail(-no-copies-please)@esmtp.org>
Message-ID: <uchtp3$er9$1@news.misty.com>
References: <tjom10$guni$1@dont-email.me> <tkg6ql$7gk5$1@dont-email.me> <tkij1u$5ea$1@news.misty.com> <uchs25$1laac$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 28 Aug 2023 10:43:47 -0000 (UTC)
Injection-Info: news.misty.com; posting-host="veps.esmtp.org:155.138.203.148";
logging-data="15209"; mail-complaints-to="abuse@misty.com"
Mail-Copies-To: never
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: ca@x2.esmtp.org (Claus Assmann)
 by: Claus Aßmann - Mon, 28 Aug 2023 10:43 UTC

None wrote:

> > Server Temp Key: DH, 1024 bits

> How do you get this dh key? If I do this on my server I get this

> []# openssl s_client -connect xxxxxxxxxx:25 -starttls smtp | grep -i 'key'

Maybe you are using a different openssl version (or .cnf file)
or maybe the server configuration has been changed?

Does the original problem still exist?

--
Note: please read the netiquette before posting. I will almost never
reply to top-postings which include a full copy of the previous
article(s) at the end because it's annoying, shows that the poster
is too lazy to trim his article, and it's wasting the time of all readers.

Re: dh key too small

<uchv9t$1lp6q$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=783&group=comp.mail.sendmail#783

  copy link   Newsgroups: comp.mail.sendmail
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: hzcnjkx...@tormails.com (None)
Newsgroups: comp.mail.sendmail
Subject: Re: dh key too small
Date: Mon, 28 Aug 2023 13:09:49 +0200
Organization: A noiseless patient Spider
Lines: 19
Message-ID: <uchv9t$1lp6q$1@dont-email.me>
References: <tjom10$guni$1@dont-email.me> <tkg6ql$7gk5$1@dont-email.me>
<tkij1u$5ea$1@news.misty.com> <uchs25$1laac$1@dont-email.me>
<uchtp3$er9$1@news.misty.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 28 Aug 2023 11:09:49 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="8306ba0f210bbf96dabe84891fc4fad2";
logging-data="1762522"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+FhIaHYM0SSZiCFDVqSoz5/NmqR9tzIUkjSpKpVIeSow=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.14.0
Cancel-Lock: sha1:LxupeS3siBd8YtTsaksALxaqCY8=
In-Reply-To: <uchtp3$er9$1@news.misty.com>
Content-Language: en-US
 by: None - Mon, 28 Aug 2023 11:09 UTC

>
>>> Server Temp Key: DH, 1024 bits
>
>> How do you get this dh key? If I do this on my server I get this
>
>> []# openssl s_client -connect xxxxxxxxxx:25 -starttls smtp | grep -i
'key'
>
> Maybe you are using a different openssl version (or .cnf file)
> or maybe the server configuration has been changed?

Indeed! old centos6 gives me the "Server Temp Key: DH, 1024 bits", while
new centos9 just presents me only with the error.

> Does the original problem still exist?
>

yes currently running with try_tls no

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor