Dovecotのerror.logでfts_skが無い!
とひたすら書かれているのに気付き、対処を行う。
先ず、それ(fts_sk)が何だか判らない。
そして探し回ったら、Apple Onlyらしい。最終的に辿り着いたのが2006-2010 Dovecot authors, see the included COPYING fileだったりする。
稼働中のServer.app(made by Apple)からのコピーだから拙かったのだろう。
10-mail.confを次のように変更。
|
1 2 |
#mail_plugins = quota zlib acl fts fts_sk mail_plugins = quota zlib acl fts |
これでエラーは出なくなる。
と、再起動したら……
|
1 |
Oct 27 15:34:07 master: Warning: Time moved forwards by 0.119279 seconds - adjusting timeouts. |
何か悪いことした?いらないモノ削っただけよ??
時刻が合ってないよってことらしい。細け〜な〜とも思いつつ、きっちりやってくれてんのね。
info.logではユーザ名が入るようになった。
|
1 2 |
Oct 27 15:38:06 imap-login: Info: ID sent: name=Mac OS X Mail, version=11.5 (3445.9.7), os=Mac OS X, os-version=10.13.6 (17G14042), vendor=Apple Inc.: user=<>, rip=192.168.0.35, lip=192.168.0.35, TLS Oct 27 15:38:06 imap-login: Info: Login: user=<support>, method=PLAIN, rip=192.168.0.35, lip=192.168.0.35, mpid=95189, TLS |
入っていないのもあるけれど、これはクライアントの問題だろう。
opensslでimapに接続してみる。
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 |
#openssl s_client -connect macmi2:143 -starttls imap CONNECTED(00000005) --- Certificate chain 0 s:CN = mail.k-in.co.jp i:C = JP, O = "SECOM Trust Systems CO.,LTD.", CN = FujiSSL Public Validation Authority - G3 a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256 v:NotBefore: Oct 2 07:48:28 2021 GMT; NotAfter: Oct 21 14:59:59 2022 GMT --- Server certificate -----BEGIN CERTIFICATE----- MIIGcjCCBVqgAwIBAgIQWblqq0ZC9wF87cDd5QpWYTANBgkqhkiG9w0BAQsFADBn MQswCQYDVQQGEwJKUDElMCMGA1UEChMcU0VDT00gVHJ1c3QgU3lzdGVtcyBDTy4s TFRELjExMC8GA1UEAxMoRnVqaVNTTCBQdWJsaWMgVmFsaWRhdGlvbiBBdXRob3Jp dHkgLSBHMzAeFw0yMTEwMDIwNzQ4MjhaFw0yMjEwMjExNDU5NTlaMBoxGDAWBgNV BAMTD21haWwuay1pbi5jby5qcDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC ggEBALJb4MnWneANDfTOd2FwLehdFkXnGHSBancLyj1Bku/R9aNVrTNsRiutDTFD 4ep1u36BmoGNjF9iHz+GBWFBJGkbuRDzl/jvPyDYre+U4g1ku48EVgjkFUec5toW TdmJwwNs/z4pA+XTfHPGY6ew+Z4hipneiX3m9k5jV5yNE80rD2zB9Cs00UVMQcZ0 sNUfK0qH+ThvhRo4aDnz8cW/9R0CaIcGj6IiBxaQgolAZzjVFeKlCbfklZln2otx 1x9mx3w6pGv2npdcSTNMrFlKA3AvFT0s1ubCBpza8hXNBjkOH+ugevwE80DyHzAd KzGtQAJ18V5dN5OF49ZCm1Dn94ECAwEAAaOCA2UwggNhMB8GA1UdIwQYMBaAFLzr 2RHgUWRv//B0Tw1aq0pPLXgnMD4GCCsGAQUFBwEBBDIwMDAuBggrBgEFBQcwAYYi aHR0cDovL25pamltbzMub2NzcC5zZWNvbXRydXN0Lm5ldDAaBgNVHREEEzARgg9t YWlsLmstaW4uY28uanAwXAYDVR0gBFUwUzBHBgoqgwiMmxtugVUBMDkwNwYIKwYB BQUHAgEWK2h0dHBzOi8vcmVwbzEuc2Vjb210cnVzdC5uZXQvc3BwY2EvbmlqaW1v My8wCAYGZ4EMAQIBMBMGA1UdJQQMMAoGCCsGAQUFBwMBMEYGA1UdHwQ/MD0wO6A5 oDeGNWh0dHA6Ly9yZXBvMS5zZWNvbXRydXN0Lm5ldC9zcHBjYS9uaWppbW8zL2Z1 bGxDUkwuY3JsMB0GA1UdDgQWBBQyU7ddw9ylp25Xx4MlBwB9dk/tLDAOBgNVHQ8B Af8EBAMCBaAwggH2BgorBgEEAdZ5AgQCBIIB5gSCAeIB4AB2ACl5vvCeOTkh8FZz n2Old+W+V32cYAr4+U1dJlwlXceEAAABfEAC+UYAAAQDAEcwRQIhANIL0YyG88UC ViyR5tQPtdyvPq54V2s4w96p3avQYIUwAiBqCUl22hG3Rv3/ccmFEuNacOFxSV6+ nzIYhvgVz29V2wB1AEalVet1+pEgMLWiiWn0830RLEF0vv1JuIWr8vxw/m1HAAAB fEAC/vUAAAQDAEYwRAIgGO7XEMzFA1fMuIFGG0Ut3VRE9rVY+kGc3w6UzOT+/3oC IFqvXDCcu44EzWMCtW5P5xsDXIT6Hwerf7CcoAnQLjekAHcAUaOw9f0BeZxWbbg3 eI8MpHrMGyfL956IQpoN/tSLBeUAAAF8QAMCEQAABAMASDBGAiEAgDruFN8C197t PPnonGFdZ00UonIW8sCR1YzaMHnoQWoCIQC2eCFTyMQ4ioIpjJvVX9pS5T52MFC1 nwGYy6ccFqO90wB2AEHIyrHfIkZKEMahOglCh15OMYsbA+vrS8do8JBilgb2AAAB fEADBDcAAAQDAEcwRQIgOmn5M1sYngPE9eUVAslnRkRusMgrGrRapOGApGDX8YUC IQD2hZMWVgnKkMx+odN+V+1tUdA4awrs3ZPwCpiG5qAJpDANBgkqhkiG9w0BAQsF AAOCAQEAZOhjEiDpyBk1w25uXu1Ebwl8Wu6+EmwBzSlEhq+2hjKTE0Ey/2VZms4l DfuqhdwIcCbm9K7xzOql/cAM4c68v8LvRAOA6uyTnuAuDe6A9bRw8XYeV8FD64pP Cit65hKJuLQiD7fJiJRKZ9rz0PMPqXfJEOdwdX39m0Lx05/6+h679Fn5zbsDse8X W+oA214ZLZgExQfLbkOY17v3+n9SyhjcI4c6pPe525+3RUFFrJRQj2GG29jKxl+J vB6fTJ/fxGji17WEm2XLHu1/Egeae4SrFxdmC4rGTHwIZzgB+Fhr9zTeSjzWUXgC 5a1IKwweil/TaLZNxuv4fia0NSPR7g== -----END CERTIFICATE----- subject=CN = mail.k-in.co.jp issuer=C = JP, O = "SECOM Trust Systems CO.,LTD.", CN = FujiSSL Public Validation Authority - G3 --- No client certificate CA names sent Peer signing digest: SHA256 Peer signature type: RSA-PSS Server Temp Key: X25519, 253 bits --- SSL handshake has read 2525 bytes and written 403 bytes Verification error: certificate has expired --- New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384 Server public key is 2048 bit Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 10 (certificate has expired) --- * BAD Error in IMAP command received by server. quit BAD Error in IMAP command received by server. * BYE Too many invalid IMAP commands. --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Session-ID: 58A4C86B9536597D085F96F83D6B2872D6CD9F911632758BD449B8D36681B330 Session-ID-ctx: Resumption PSK: 95E88ACA4F3256711537C0A2AAE2B599578677826CBD82B10D6F23D2B14A66017CC02B46FDF20A10C5C31F62B3507E7D PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 7200 (seconds) TLS session ticket: 0000 - 10 c5 39 10 54 41 03 91-87 54 eb 4f cc 56 ab 50 ..9.TA...T.O.V.P 0010 - 60 23 09 12 f7 2c bf ff-24 a1 81 27 bf 1e 0f d4 `#...,..$..'.... 0020 - 91 02 88 a1 24 62 92 a2-76 cb 4d 42 5a bd 38 df ....$b..v.MBZ.8. 0030 - 20 b7 8a 67 46 a7 7f 5e-22 3e 52 4a 3d 3d 67 c8 ..gF..^">RJ==g. 0040 - 29 be 25 ef 21 79 a6 29-e1 66 ab 83 4e e6 ed 47 ).%.!y.).f..N..G 0050 - 39 29 51 35 25 2e 3b c6-b5 00 31 5c a0 7f 8e f8 9)Q5%.;...1\.... 0060 - a5 b9 ac 0a b2 ab ee b5-1b 10 9d 19 ca 88 0c 24 ...............$ 0070 - be 0a 64 cb 3d 16 46 97-a1 2d f1 07 9a 9b 37 a5 ..d.=.F..-....7. 0080 - d6 80 7b 3d 2c d7 e9 16-9a 71 c7 a3 4b 06 d7 42 ..{=,....q..K..B 0090 - 06 e5 83 e8 a6 fb cb 4a-61 95 e8 ad ce 14 b3 16 .......Ja....... 00a0 - 52 bd 1c 53 07 a5 a4 30-d1 66 50 60 5c cc 74 28 R..S...0.fP`\.t( 00b0 - 95 fe f5 73 51 25 2f 13-06 7a 89 d3 e5 0e 7f 71 ...sQ%/..z.....q 00c0 - ba 3c 38 b2 64 1f aa 29-43 a3 de 5a 55 c5 39 75 .<8.d..)C..ZU.9u Start Time: 1666853146 Timeout : 7200 (sec) Verify return code: 10 (certificate has expired) Extended master secret: no Max Early Data: 0 --- read R BLOCK --- Post-Handshake New Session Ticket arrived: SSL-Session: Protocol : TLSv1.3 Cipher : TLS_AES_256_GCM_SHA384 Session-ID: D6B0D0EC5AD4D7E9813933D3E5B17F415F6A0E4AD3428EA6AC86EC36505E5F7E Session-ID-ctx: Resumption PSK: 0934816312FA4288D7512FF6D14B68D6563A1700A53103E757184644D8BD156035E30E164B409F07784CC2CD125B179B PSK identity: None PSK identity hint: None SRP username: None TLS session ticket lifetime hint: 7200 (seconds) TLS session ticket: 0000 - 10 c5 39 10 54 41 03 91-87 54 eb 4f cc 56 ab 50 ..9.TA...T.O.V.P 0010 - 14 91 d7 2d 92 be 15 fd-e3 99 a2 54 aa c6 a6 e4 ...-.......T.... 0020 - 87 7d 54 53 70 69 31 e8-30 54 da 9e 0e 08 2a c9 .}TSpi1.0T....*. 0030 - d6 10 67 13 cd 38 c2 36-45 2f b7 3a c3 85 7c f6 ..g..8.6E/.:..|. 0040 - b3 d4 2a c8 14 49 ed 4a-db cb b9 24 e7 e0 83 77 ..*..I.J...$...w 0050 - 51 cb ec 21 fb 4c 15 ef-34 3e db 20 39 c7 3a f0 Q..!.L..4>. 9.:. 0060 - a7 d2 a2 9d ae 92 d7 e1-94 00 97 ef 92 06 33 5e ..............3^ 0070 - 91 d4 ef cb fd 11 ce d4-71 86 20 a8 47 2c 13 6c ........q. .G,.l 0080 - 17 2d df 2d 1a 04 5d dd-47 8b a6 81 75 c8 5d cb .-.-..].G...u.]. 0090 - 42 1c 86 9a 20 63 5d f0-33 41 41 29 0d 82 1a b8 B... c].3AA).... 00a0 - be 97 65 ca b6 f1 45 0d-cf fb 39 7a f5 53 46 06 ..e...E...9z.SF. 00b0 - 04 e8 9f 90 bd d7 33 3d-18 ab 39 81 16 da 98 f0 ......3=..9..... 00c0 - 9e 96 c1 4d c5 ca b1 54-12 2d 38 6c d5 cc a6 c9 ...M...T.-8l.... Start Time: 1666853146 Timeout : 7200 (sec) Verify return code: 10 (certificate has expired) Extended master secret: no Max Early Data: 0 --- read R BLOCK closed |
きちんとできていると思う。
openssl s_client -connect macmi2:993(imaps)でも同様だ。(-starttls imapは外した。理由は付けると固まるから)
pop3s(port 995)は付けない。pop3(port 110)は付けることで同様の結果になった。
良いんでない?

