0:05 AM
_smf_ has quit
0:23 AM
niftylettuce joined the channel
3:56 AM
donspaulding joined the channel
3:58 AM
donspaulding joined the channel
3:59 AM
ultimatt has quit
4:04 AM
donspaulding joined the channel
4:13 AM
donspaulding joined the channel
4:51 AM
donspaul_ joined the channel
5:19 AM
donspaulding joined the channel
5:30 AM
grasser has quit
5:31 AM
grasser joined the channel
7:53 AM
dexus_ joined the channel
7:58 AM
DoubleMalt joined the channel
8:27 AM
hatse_ joined the channel
9:03 AM
dopesong joined the channel
9:52 AM
DarkSorrow joined the channel
9:52 AM
DarkSorrow
hello
9:55 AM
dexus_
hi
10:32 AM
dopesong_ joined the channel
10:33 AM
dopesong has quit
10:57 AM
cek
11:07 AM
vivek779 joined the channel
11:34 AM
DarkSorrow has quit
11:50 AM
dexus_
cek, no has no time think first in the later time...
12:31 PM
dopesong_ has quit
12:37 PM
vivek779 has quit
12:39 PM
DarkSorrow joined the channel
12:53 PM
dopesong joined the channel
12:57 PM
dopesong has quit
13:11 PM
miefda joined the channel
13:24 PM
miefda
hi, can anyone give i a hint. I get: "[core] Plugin tls timed out on hook unrecognized_command - make sure it calls the callback " only for some hosts like
mx2.slc.paypal.com
13:33 PM
baudehlo
Anything else in the logs?
13:37 PM
dexus_
cek: [ERROR] [3E8775CC-A4E7-488C-979A-164B88ABD529.1.1] [outbound] Ongoing connection failed to 207.250.26.89:25 : Error: 140092332267392:error:14082174:SSL routines:ssl3_check_cert_and_algorithm:dh key too small:../deps/openssl/openssl/ssl/s3_clnt.c:3554:
13:38 PM
cek
fucking finally.
13:38 PM
now, this essentially means mail is lost to taht destinatino as haraka will retyr with tls on and fail
13:39 PM
so we need to make a workaround by disabling tls for hosts that have such obscure errors
13:39 PM
And obviously, your users lost hell lot of mail if you didn't catch this issue earlier.
13:40 PM
dexus_
13:40 PM
its comming from failing openssl
13:43 PM
13:43 PM
so if you need to communicate with there servers you can contact ther postmaster and ask they to update dhparams
13:45 PM
cek
no shit it's coming off remote party
13:45 PM
I've had 30 such hosts in June alone
13:46 PM
donspaulding joined the channel
13:51 PM
EyePulp joined the channel
13:52 PM
dexus_
its sucks if the admin on other platforms sleeping and dont manage there server yes thats bad....
13:53 PM
miefda
baudehlo: nope loglevel was too low :-/
13:54 PM
cek
you don't get the situation boy, we can't have that answer to customer which is sending to government address, or just any address.
13:54 PM
Mail either is delivered or they switch service.
13:56 PM
miefda: search on github/issues, or use latest version
13:58 PM
dexus_
cek there are two ways:
13:58 PM
a) you build nodejs your self and fix openssl to allow smaller dhparams
14:00 PM
14:02 PM
btw. we working on b) , but you can contribute if you have a other solution...
14:23 PM
cek
that ain't the solution
14:23 PM
i won't go through every host on internet
14:23 PM
and allowing weaker dh is as good as not using tls at all
14:26 PM
dexus_
I know, but it's not a problem of haraka but NodeJS
14:26 PM
and openssl
14:28 PM
Therefore, it not helps you whine around here. Or you have an idea how to fix it?
14:40 PM
cek
i'm just reporting an important issue that's sitting there for 6 months
14:46 PM
dexus_
if we take it just for 4 months if at all NodeJS 0.10.39 was when then the trigger.
14:51 PM
donspaulding joined the channel
14:52 PM
miefda has quit
15:20 PM
donspaulding has quit
15:35 PM
donspaulding joined the channel
15:40 PM
donspaulding joined the channel
16:06 PM
donspaulding has quit
16:15 PM
teknix joined the channel
16:26 PM
17SADXFTL joined the channel
16:26 PM
teknix has quit
16:28 PM
teknix joined the channel
16:35 PM
ultimatt joined the channel
16:40 PM
ultimatt
> a) you build nodejs your self and fix openssl to allow smaller dhparams
16:40 PM
I'd amend that to say:
16:41 PM
a) you build nodejs your self and BREAK openssl to allow smaller dhparams
16:42 PM
what we talked about for TLS issues like that in the past was:
16:43 PM
a) keep track of hosts that have working TLS
16:43 PM
b) keep track of hosts that fail TLS
16:43 PM
c) one-time disable TLS for hosts where it failed the previous time
16:43 PM
Such that, TLS will automatically resume working when the remote fixes it
16:44 PM
and hosts with working TLS should *never* connect w/o working TLS (prevent MITM downgrades)
16:45 PM
dexus_
why you close #938 with some open tasks?
16:46 PM
ultimatt
b/c node 0.12 is a a non-starter, and open tasks have their own issue
16:47 PM
dopesong joined the channel
16:47 PM
dexus_
ok
16:48 PM
ultimatt
16:49 PM
for inbound
16:51 PM
dopesong has quit
17:06 PM
dexus_ has quit
17:25 PM
DarkSorrow has quit
17:37 PM
dopesong joined the channel
18:04 PM
dexus joined the channel
18:04 PM
dexus has quit
18:05 PM
dexus joined the channel
18:07 PM
dexus joined the channel
18:07 PM
dexus
re
18:20 PM
donspaulding joined the channel
19:17 PM
hatse_ has quit
19:24 PM
cek
I don't worry about inbound,because it's *their* problem
19:24 PM
customers will compain to sending party as the senders will get the bounces
19:25 PM
in outbound tls, our clients get nondelivery reports, so it's our problem
19:27 PM
ultimatt
since it hurts you, add a 'no_tls_hosts' feature to outbound
19:58 PM
teknix has quit
20:11 PM
teknix joined the channel
20:18 PM
donspaulding joined the channel
21:07 PM
FlowRidda joined the channel
21:10 PM
FlowRidda has left the channel
21:44 PM
dopesong has quit
23:23 PM
EyePulp has quit
23:38 PM
teknix has quit
23:49 PM
EyePulp joined the channel