Please convert to use the system's crypto policy for SSL and TLS: https://fedoraproject.org/wiki/Changes/CryptoPolicy#Scope If this program is compiled against gnutls, change the default priority string to be "@SYSTEM" or to use gnutls_set_default_priority(). If this program is compiled against openssl, and there is no default cipher list specified, you don't need to modify it. Otherwise replace the default cipher list with "PROFILE=SYSTEM". If this program obtains its cipher list (or priority) using a configuration file, please update the shipped configuration files with the appropriate string that sets the system policy. In all cases verify (as described in the URL above) that the application uses the system's crypto profiles. Please contact me for any questions.
A quick reminder; this is a blocker for #1076390. if you have no resources to pursue that please contact me.
Any update on this issue?
Not yet. As I understand it, given the configuration, it should be enough to change /etc/dovecot/conf.d/10-ssl.conf ssl_cipher_list to PROFILE=SYSTEM. I've tried that together with changig system configuration from legacy to future, but it changed nothing. I did not yet have the time to investigate why nothing happened.
Hi, is there any way I can help to speed that up?
No longer blocks the Fedora change. However, the packet needs to be updated to adhere to the policy anyway.
This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle. Changing version to '22'. More information and reason for this action is here: https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22
(In reply to Michal Hlavinka from comment #3) > Not yet. > As I understand it, given the configuration, it should be enough to change > /etc/dovecot/conf.d/10-ssl.conf ssl_cipher_list to PROFILE=SYSTEM. > > I've tried that together with changig system configuration from legacy to > future, but it changed nothing. I did not yet have the time to investigate > why nothing happened. When you change the system policy you need to run update-crypto-policies. What is the blocker for that issue?
Fixed in dovecot-2.2.18-4.fc22 dovecot-2.2.18-5.fc23 dovecot-2.2.18-5.fc24
Thanks.