Hide Forgot
Description of problem: dovecot proxy SSL connection requires certificate CRLs: Apr 18 14:21:40 hawk dovecot: imap-login: Invalid certificate: unable to get certificate CRL: /O=mail.cora.nwra.com/OU=Domain Control Validated/CN=mail.cora.nwra.com Apr 18 14:21:40 hawk dovecot: imap-login: Invalid certificate: unable to get certificate CRL: /C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certificates.godaddy.com/repository/CN=Go Daddy Secure Certification Authority/serialNumber=07969287 Apr 18 14:21:40 hawk dovecot: imap-login: Invalid certificate: unable to get certificate CRL: /C=US/O=The Go Daddy Group, Inc./OU=Go Daddy Class 2 Certification Authority Apr 18 14:21:40 hawk dovecot: imap-login: Invalid certificate: unable to get certificate CRL: /L=ValiCert Validation Network/O=ValiCert, Inc./OU=ValiCert Class 2 Policy Validation Authority/CN=http://www.valicert.com//emailAddress=info@valicert.com This has been fixed in recent releases with this patch: http://dovecot.org/list/dovecot-cvs/2011-November/019379.html Version-Release number of selected component (if applicable): dovecot-2.0.9-2.el6_1.1.i686 How reproducible: everytime Steps to Reproduce: 1. Enable auth-static.conf.ext in 10-auth.conf 2. Set something like: passdb { driver = static args = proxy=y host=mail.example.com nopassword=y ssl=y } 3. Connect to proxy Actual results: Connection fails Expected results: Connection works
I should note that the patch is in the current dovecot releases.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2015-1348.html