Mailing List ecs-isp@2rosenthals.com Archived Message #183

From: "Steven Levine" <ecs-isp@2rosenthals.com> Full Headers
Undecoded message
Subject: Re: [eCS-ISP] Stunnel 5.58
Date: Mon, 08 Mar 2021 14:02:23 -0800
To: "eCS ISP Mailing List" <ecs-isp@2rosenthals.com>

In <list-1731312@2rosenthals.com>, on 03/08/21
   at 06:46 PM, "Massimo S." <ecs-isp@2rosenthals.com> said:

Hi Massimo,

>i copied the entire DIR on the AOS VM
>yes, there it do not crash, but exit with this text:

>[!] SSL_CTX_use_certificate_chain_file: ssl/ssl_rsa.c:301:
>error:140AB18F:SSL  routines:SSL_CTX_use_certificate:ee key too small

If you read carefully, you should notice that this is exactly the same
error I discussed in one of my prior messages.  You are using an obsolete
stunnel.pem file which was built with 1024 byte keys.

Are you building your own stunnel.pem file or using the stunnel.pem Paul
supplied?  If you are building your own and don't want to rebuild them
right away, review my prior message for the workaround.

If you are using the stunnel.pem Paul supplies, you need to update the AOS
VM to use this certificate, which is built with 2048 bit keys.

Let use know if updating stunnel.pem allows stunnel start on the AOS VM.

Steven

--
----------------------------------------------------------------------
"Steven Levine" <steve53@earthlink.net>  Warp/DIY/BlueLion etc.
www.scoug.com www.arcanoae.com www.warpcave.com
----------------------------------------------------------------------


Subscribe: Feed, Digest, Index.
Unsubscribe
Mail to ListMaster