<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sendmail and tls in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-and-tls/m-p/6740044#M603376</link>
    <description>&lt;P&gt;I want to configure sendmail with tls&lt;/P&gt;
&lt;P&gt;i've set this .mc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;define(`SMART_HOST', `pos.domain.private')
define(`confCACERT_PATH', `/etc/mail/certs')dnl
define(`confCACERT', `/etc/mail/certs/.domain.private.crt')dnl
define(`confSERVER_CERT', `/etc/mail/certs/hpux2.domain.private.crt')dnl
define(`confSERVER_KEY', `/etc/mail/certs/hpux2..domain.private.key')dnl
define(`confCLIENT_CERT', `/etc/mail/certs/.domain.private')dnl
define(`confCLIENT_KEY', `/etc/mail/certs/.domain.private')dnl
define(`confRAND_FILE',`file:/etc/mail/randfile')dnl
D{tls_version}TLSv1
O UseTLS=True&lt;/PRE&gt;
&lt;P&gt;Compile ok.&lt;/P&gt;
&lt;P&gt;But tls give this error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;STARTTLS: Warning: safeopen(/etc/mail/randfile) failed&lt;/PRE&gt;
&lt;P&gt;I have tried /dev/urandom same error,i have tried chown root:smmsp randfile&lt;/P&gt;
&lt;P&gt;and chmod 660,nothing to do.&lt;/P&gt;
&lt;P&gt;What i miss?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. This thread has been moved&amp;nbsp;from General to HP-UX &amp;gt; messaging. - Hp Forum Moderator&lt;/P&gt;</description>
    <pubDate>Mon, 04 May 2015 03:13:20 GMT</pubDate>
    <dc:creator>uxbeginner22</dc:creator>
    <dc:date>2015-05-04T03:13:20Z</dc:date>
    <item>
      <title>sendmail and tls</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-and-tls/m-p/6740044#M603376</link>
      <description>&lt;P&gt;I want to configure sendmail with tls&lt;/P&gt;
&lt;P&gt;i've set this .mc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;define(`SMART_HOST', `pos.domain.private')
define(`confCACERT_PATH', `/etc/mail/certs')dnl
define(`confCACERT', `/etc/mail/certs/.domain.private.crt')dnl
define(`confSERVER_CERT', `/etc/mail/certs/hpux2.domain.private.crt')dnl
define(`confSERVER_KEY', `/etc/mail/certs/hpux2..domain.private.key')dnl
define(`confCLIENT_CERT', `/etc/mail/certs/.domain.private')dnl
define(`confCLIENT_KEY', `/etc/mail/certs/.domain.private')dnl
define(`confRAND_FILE',`file:/etc/mail/randfile')dnl
D{tls_version}TLSv1
O UseTLS=True&lt;/PRE&gt;
&lt;P&gt;Compile ok.&lt;/P&gt;
&lt;P&gt;But tls give this error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;STARTTLS: Warning: safeopen(/etc/mail/randfile) failed&lt;/PRE&gt;
&lt;P&gt;I have tried /dev/urandom same error,i have tried chown root:smmsp randfile&lt;/P&gt;
&lt;P&gt;and chmod 660,nothing to do.&lt;/P&gt;
&lt;P&gt;What i miss?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. This thread has been moved&amp;nbsp;from General to HP-UX &amp;gt; messaging. - Hp Forum Moderator&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 03:13:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-and-tls/m-p/6740044#M603376</guid>
      <dc:creator>uxbeginner22</dc:creator>
      <dc:date>2015-05-04T03:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: sendmail and tls</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-and-tls/m-p/6743353#M603377</link>
      <description>&lt;P&gt;Solution found&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the most important thing was,enable the database,and use egd instead of file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;divert(0)dnl
VERSIONID(`$Id: generic-hpux10.mc,v 8.13 2001/05/29 17:29:52 ca Exp $')
OSTYPE(hpux11)dnl
DOMAIN(generic)dnl
define(`_X400_UUCP_')dnl
define(`_MASQUERADE_ENVELOPE_')dnl
define(`MASQUERADE_NAME')dnl
define(`confTRY_NULL_MX_LIST',`T')dnl
define(`LUSER_RELAY',`name_of_luser_relay')dnl
define(`DATABASE_MAP_TYPE',`dbm')dnl
define(`_CLASS_U_')dnl
define(`LOCAL_RELAY')dnl
define(`MAIL_HUB')dnl
TRUST_AUTH_MECH(`GSSAPI DIGEST-MD5')dnl
FEATURE(always_add_domain)dnl
MAILER(local)dnl
MAILER(smtp)dnl
MAILER(openmail)dnl
MAILER(uucp)dnl
define(`SMART_HOST', `posta.serve.com')
define(`confCACERT_PATH', `/etc/mail/certs')dnl
define(`confCACERT', `/etc/mail/certs/serve.com.crt')dnl
define(`confSERVER_CERT', `/etc/mail/certs/hpux2.serve.com.crt')dnl
define(`confSERVER_KEY', `/etc/mail/certs/hpux2.serve.com.key')dnl
define(`confCLIENT_CERT', `/etc/mail/certs/hpux2.serve.com.crt')dnl
define(`confCLIENT_KEY', `/etc/mail/certs/hpux2.serve.com.key')dnl
define(`confRAND_FILE',`egd:/dev/urandom')dnl
D{tls_version}TLSv1
O UseTLS=True&lt;/PRE&gt;</description>
      <pubDate>Mon, 11 May 2015 21:03:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-and-tls/m-p/6743353#M603377</guid>
      <dc:creator>uxbeginner22</dc:creator>
      <dc:date>2015-05-11T21:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: sendmail and tls</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-and-tls/m-p/6743354#M603378</link>
      <description>&lt;P&gt;Latest question: is possible to disable ssl3 and enable only tlsv1?&lt;/P&gt;&lt;P&gt;On linux i did on .mc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;LOCAL_CONFIG
dnl# Do not allow the weak SSLv2:
O CipherList=HIGH
O ServerSSLOptions=+SSL_OP_NO_SSLv2 +SSL_OP_NO_SSLv3 +SSL_OP_CIPHER_SERVER_PREFERENCE
O ClientSSLOptions=+SSL_OP_NO_SSLv2 +SSL_OP_NO_SSLv3&lt;/PRE&gt;&lt;P&gt;But this solution didn't work on unix!&lt;/P&gt;&lt;P&gt;Sendmail won't accept this code and give error&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2015 21:06:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sendmail-and-tls/m-p/6743354#M603378</guid>
      <dc:creator>uxbeginner22</dc:creator>
      <dc:date>2015-05-11T21:06:01Z</dc:date>
    </item>
  </channel>
</rss>

