OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[TLS] smtpd: verify error:num=26:unsupported certificate purpose

From: Ralf Hildebrandt (Ralf.Hildebrandtcharite.de)
Date: Wed Oct 27 2004 - 10:01:22 CDT


wyeth.com uses TLS when sending mail to us, but our smtpd complains
about "verify error:num=26:unsupported certificate purpose".

So, the certificate was not issued for use with email.

But, how can I find out WHAT it was used for.
To try yourself, try sending email to unknownuserwyeth.com -- the
bounce will be sent using TLS if your server offers STARTTLS.

Oct 27 16:57:39 mail postfix/smtpd[30879]: SSL_accept:error in SSLv3 read client certificate A
Oct 27 16:57:39 mail postfix/smtpd[30879]: Peer cert verify depth=0 /C=US/ST=New York/L=Pearl River/O=Wyeth/OU=BNS/CN=imail-pr1.wyeth.com
Oct 27 16:57:39 mail postfix/smtpd[30879]: verify error:num=26:unsupported certificate purpose
Oct 27 16:57:39 mail postfix/smtpd[30879]: verify return:0

--
Ralf Hildebrandt Ralf.Hildebrandtcharite.de
http://www.arschkrebs.de/postfix/ Tel. +49 (0)30-450 570-155
Quit trying to hurt (slow down) millions abusive IPs. It's a waste of
time. Your MX is vastly outnumbered and is pissing into a hurricane.