Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 365763 - net-mail/dovecot-2.0.11: tls for the openldap connection seems to have broken in this version
Summary: net-mail/dovecot-2.0.11: tls for the openldap connection seems to have broken...
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: AMD64 Linux
: Normal normal (vote)
Assignee: Eray Aslan
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-05-02 22:02 UTC by Charlie Clark
Modified: 2011-05-03 19:16 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Charlie Clark 2011-05-02 22:02:18 UTC
When trying to login to dovecot I get the following error in the slapd debug log:

TLS trace: SSL_accept:before/accept initialization
tls_read: want=11, got=11
  0000:  30 1d 02 01 01 77 18 80  16 31 2e                  0....w...1.       
TLS trace: SSL_accept:error in SSLv2/v3 read client hello A
TLS: can't accept: error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol.
connection_read(13): TLS accept failure error=-1 id=1002, closing

This worked fine before the dovecot upgrade.

Reproducible: Always

Steps to Reproduce:
1.setup dovecot-2.0.11 and openldap-2.4.24
2.Configure both for tls
3.Use self-signed certificates (not sure if this is needed)
4.Configure dovecot to only use imaps
5.Run slapd with '-d 255'
Actual Results:  
Log into dovecot over imaps and you should get the messages mentioned, also the authentication will fail for obvious reasons.

Expected Results:  
Successful login and no tls errors reported by openldap.

server dovecot # emerge --info dovecot openldap
Portage 2.1.9.42 (default/linux/amd64/10.0/server, gcc-4.4.5, libc-0-r0, 2.6.37-gentoo-r4-funky x86_64)
=================================================================
                        System Settings
=================================================================
System uname: Linux-2.6.37-gentoo-r4-funky-x86_64-Quad-Core_AMD_Opteron-tm-_Processor_1354-with-gentoo-1.12.14
Timestamp of tree: Mon, 02 May 2011 02:30:01 +0000
ccache version 2.4 [enabled]
app-shells/bash:     4.1_p9
dev-lang/python:     2.7.1-r1, 3.1.3-r1
dev-util/ccache:     2.4-r9
dev-util/cmake:      2.8.4
sys-apps/baselayout: 1.12.14-r1
sys-apps/sandbox:    2.4
sys-devel/autoconf:  2.65-r1
sys-devel/automake:  1.11.1
sys-devel/binutils:  2.20.1-r1
sys-devel/gcc:       4.4.5
sys-devel/gcc-config: 1.4.1-r1
sys-devel/libtool:   2.2.10
sys-devel/make:      3.81-r2
sys-kernel/linux-headers: 2.6.36.1
sys-libs/glibc:      2.11.3
virtual/os-headers:  0
ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="* -@EULA"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-O2 -march=native -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt /var/bind"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/php/apache2-php5.3/ext-active/ /etc/php/cgi-php5.3/ext-active/ /etc/php/cli-php5.3/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-O2 -march=native -pipe"
DISTDIR="/usr/portage/distfiles"
FEATURES="assume-digests binpkg-logs ccache distlocks fixlafiles fixpackages news parallel-fetch protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch"
FFLAGS=""
GENTOO_MIRRORS="ftp://gentoo.virginmedia.com/sites/gentoo http://www.mirrorservice.org/sites/www.ibiblio.org/gentoo/ rsync://mirror.bytemark.co.uk/gentoo/"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --stats --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync.gentoo.org/gentoo-portage"
USE="acl amd64 apache2 bash-completion berkdb bzip2 clamav cli cracklib crypt cxx fortran ftp gdbm iconv imap ipv6 ldap maildir mmx modules mp3 mudflap multilib mysql ncurses nls nptl nptlonly openmp pam pcre php readline samba session sse sse2 ssl static-libs sysfs syslog tcpd truetype udev unicode vhosts vim-syntax xml zlib" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" ALSA_PCM_PLUGINS="adpcm alaw asym copy dmix dshare dsnoop empty extplug file hooks iec958 ioplug ladspa lfloat linear meter mmap_emul mulaw multi null plug rate route share shm softvol" APACHE2_MODULES="actions alias auth_basic authn_alias authn_default authn_file authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ubx" INPUT_DEVICES="keyboard mouse evdev" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" PHP_TARGETS="php5-3" RUBY_TARGETS="ruby18" USERLAND="GNU" VIDEO_CARDS="fbdev glint intel mach64 mga neomagic nouveau nv r128 radeon savage sis tdfx trident vesa via vmware dummy v4l" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account" 
Unset:  CPPFLAGS, CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LANG, LC_ALL, LINGUAS, MAKEOPTS, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS

=================================================================
                        Package Settings
=================================================================

net-mail/dovecot-2.0.11 was built with the following:
USE="berkdb bzip2 ipv6 ldap maildir managesieve (multilib) mysql pam sieve ssl zlib -caps -cydir -doc -kerberos -mbox -mdbox -postgres -sdbox -sqlite -suid -vpopmail"


net-nds/openldap-2.4.24 was built with the following:
USE="berkdb crypt ipv6 (multilib) samba ssl syslog tcpd -cxx -debug -experimental -gnutls -icu -iodbc -kerberos -minimal -odbc -overlays -perl -sasl (-selinux) -slp -smbkrb5passwd"
CFLAGS="-O2 -march=native -pipe -D_GNU_SOURCE"
CXXFLAGS="-O2 -march=native -pipe -D_GNU_SOURCE"
server dovecot # doveconf -n
# 2.0.11: /etc/dovecot/dovecot.conf
# OS: Linux 2.6.37-gentoo-r4-funky x86_64 Gentoo Base System release 1.12.14 ext4
base_dir = /var/run/dovecot/
first_valid_gid = 1001
first_valid_uid = 1000
listen = *
login_greeting = Welcome to the mail server.
mail_location = maildir:/srv/mail/imap/example.local/recipients/%u
managesieve_notify_capability = mailto
managesieve_sieve_capability = fileinto reject envelope encoded-character vacation subaddress comparator-i;ascii-numeric relational regex imap4flags copy include variables body enotify environment mailbox date
passdb {
  args = /etc/dovecot/dovecot-ldap.conf.ext
  driver = ldap
}
plugin/sieve = ~/.dovecot.sieve
plugin/sieve_dir = ~/sieve
protocols = imap
ssl_cert = </etc/dovecot/ssl/dovecot.pem
ssl_key = </etc/dovecot/ssl/newreq.pem
userdb {
  args = /etc/dovecot/dovecot-ldap.conf.ext
  driver = ldap
}
protocol lda {
  mail_plugins = sieve
}
server dovecot # cat /etc/dovecot/dovecot-ldap.conf.ext | grep -v '^#'
hosts = 127.0.0.1:636
dn = cn=dovecot,dc=example,dc=com
dnpass = *******
tls = yes
tls_require_cert = never
auth_bind = yes
auth_bind_userdn = uid=%u,ou=People,dc=example,dc=com
ldap_version = 3
base = ou=People,dc=example,dc=com
user_attrs = homeDirectory=home,uidNumber=uid,gidNumber=gid
user_filter = (&(objectClass=inetOrgPerson)(uid=%u))
pass_attrs = uid=user,userPassword=password
pass_filter = (&(objectClass=inetOrgPerson)(uid=%u))
iterate_attrs = uid=user
iterate_filter = (objectClass=inetOrgPerson)
default_pass_scheme = CRYPT

Before the upgrade I had a couple of different settings above:

#hosts = 127.0.0.1:636
uris = ldaps://127.0.0.1
#tls = yes
tls_ca_cert_file = /etc/openldap/ssl/cacert.pem
tls_require_cert = hard

I changed these to see if it made any difference but it doesn't seem to have.
Comment 1 Eray Aslan gentoo-dev 2011-05-03 09:16:46 UTC
Looks like a configuration problem.  You can use ldaps (port 636) or STARTTLS (port 389) to connect to your LDAP server but you cannot use STARTTLS for a ldaps request AFAIK. (tls=yes means use STARTTLS).

Also, using TLS for communication on localhost does not buy you any security.
Comment 2 Charlie Clark 2011-05-03 10:46:19 UTC
server dovecot # grep -v '^#' /etc/dovecot/dovecot-ldap.conf.ext
hosts = 127.0.0.1:636
dn = cn=dovecot,dc=example,dc=com
dnpass = *******
tls_require_cert = never
auth_bind = yes
auth_bind_userdn = uid=%u,ou=People,dc=example,dc=com
ldap_version = 3
base = ou=People,dc=example,dc=com
user_attrs = homeDirectory=home,uidNumber=uid,gidNumber=gid
user_filter = (&(objectClass=inetOrgPerson)(uid=%u))
pass_attrs = uid=user,userPassword=password
pass_filter = (&(objectClass=inetOrgPerson)(uid=%u))
iterate_attrs = uid=user
iterate_filter = (objectClass=inetOrgPerson)
default_pass_scheme = CRYPT

slapd debug snippet:

TLS trace: SSL_accept:before/accept initialization
tls_read: want=11, got=11
  0000:  30 36 02 01 01 60 31 02  01 03 04                  06...`1....       
TLS trace: SSL_accept:error in SSLv2/v3 read client hello A
TLS: can't accept: error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol.
connection_read(13): TLS accept failure error=-1 id=6718, closing

Still fails, I've tried a number of different TLS configurations to get this to work and none of them do. As I said, I had a working configuration before the configuration files changed and I've tried the configuration that I originally had set up as mentioned before. And I'm not doing it for security, I'm mainly doing it for the experience.
Comment 3 Eray Aslan gentoo-dev 2011-05-03 19:16:22 UTC
Try a minimum config to see if you can get TLS to work and add to your config from there.  Perhaps something like:

hosts = localhost
auth_bind = yes
ldap_version = 3
tls = yes
base = ou=People,dc=example,dc=com
user_attrs = homeDirectory=home,uidNumber=uid,gidNumber=gid
user_filter = (&(objectClass=inetOrgPerson)(uid=%u))
pass_attrs = uid=user,userPassword=password
pass_filter = (&(objectClass=inetOrgPerson)(uid=%u))
default_pass_scheme = CRYPT

In any case, you should try support forums and mailing lists.  You will get better help.  This is almost certainly a configuration error and not a bug.

Closing for now.