Thunderbird with cyrus-imapd: Why chose client certificate?

Stoyan Tzalev stockton at netbg.com
Thu Nov 13 10:50:49 EST 2008


I can confirm this on two separate cyrus installations - 2.3.7 and 2.3.12. I'm 
pretty sure both servers does NOT request any client certificate. One more 
thing - looks like this happens only when you have at least one client cert 
installed. 
I'll try to gather more debug info and will report back tomorrow.

Regards,
Stoyan


On Wednesday 05 November 2008 17:58:51 Frank Richter wrote:
> Hi,
> I've a cyrus-imapd 2.3.12 installation with these options in imapd.conf
>
> tls_cert_file: /etc/exim/etc/server.crt
> tls_key_file:  /etc/exim/etc/server.key
> tls_ca_file:   /etc/pki/tls/certs/ca-chain.crt
> tls_require_cert: 0
>
> SSL and STARTTLS are working fine.
>
> I've imported a personal S/MIME certificate to thunderbird. When
> connecting to the IMAP server (using STARTTLS), thunderbird asks me to
> select a client cert, showing (translated from German):
>     This website (!) requires a certificate for identification ...
>     Chose a certificate ...
>
> The server doesn't and shouldn't accept client certificates.
> So who is wrong? My configuration, thunderbird ...
>
> I hope somebody will enlighten me ...
>
> Thanks,
> Frank




More information about the Info-cyrus mailing list