Offline #3 2010-07-28 17:25:47 JohnieBraaf Member From: Belgium Registered: 2010-07-10 Posts: 15 Website Re: [SOLVED] Stunnel not logging Wow, I'm amazed of myself! You likely already have this set up if you were using outgoing.verizion.net previously.

For example you may see output like this: open("/usr/local/ssl/localCA/cacert.pem", O_RDONLY) = 3 stat("/usr/local/ssl/certs/f73e89fd.0", 0xbffff41c) = -1 ENOENT (No such file or directory) by which you see where it's looking for the

Do I need to have a Certificate Authority sign my key? This is common error code format used by windows and other windows compatible software and driver vendors.

Managed to get this problem fixed, before anyone had the chance to reply. ^_^So what did I do?Simply add a line for every service I use to the /etc/hosts.allow file like The rest of the system seems to be refusing the attempt to either create or use the tunnel; "we don't know you - go away". The stunnel source comes with an stunnel.pem file.

All configuration is done in the /etc/stunnel/stunnel.conf and related files. In some cases the error may have more parameters in Error Reading Certificate File /etc/ssl/certs/stunnel.pem format. The client recognizes the CA as trusted.

If helps - i still getting this error ............................................................ [[email protected] ~]# /usr/sbin/stunnel -d 995 -p /usr/share/ssl/certs/stunnel.pem -r localhost:pop3 2005.06.24 14:45:23 LOG3[7147:3086956768]: -d: No such file or directory (2) Syntax: stunnel [filename] It is a totally valid SSL certificate.

You can use this file if you wish. The dmesg.log and Xorg,0.log look normal by the way. You likely already have this set up if you were using outgoing.verizion.net previously.

The answer is sooooooo simple Stunnel.conf had [smtps] accept = 5000 connect = smtp.verizon.net:465 That's what was in my original source for a how-to. This creates your RSA private key in stunnel.pem and your Certificate Request These are only needed if you specifically compile stunnel to use DH, which is not the default.

He does have a problem with the certificate, but it is unrelated to what he is seeing here. If you concatenate the two, that should work. Stunnel does need a pem file, regardless whether or not the data is used.

Then run postfix reload. I'd edit this into the above post but I timed out on the edit window (10m). What should be there is [smtp] accept = 5000 connect = smtp.verizon.net:465 That is, the service I need to handle is smtp and not smtps.

I tried setting debug=7 (also, debug=debug - docs say that works) and defining the log file with output=/etc/stunnel/stunnel.log but the file isn't filling with debugging info:9178164 -rw-rw-rw- 1 nogroup 0 Aug

It is possible to have your key signed by a third party (certificate authority) instead if you wish. For all of the above methods, one sure-fire way to determine where stunnel is looking for your certificates is to trace the stunnel process when it runs and see what files A round of virtual beers on me! The following pages contain copies of various Certificate Authority (for example Thawte) certificates which were snagged from web browsers, etc.

So, copy these bits from the original.pem and paste them at the end of new.pem, namely -----BEGIN CERTIFICATE----- gUgePf2CbIMcIkWln8Ujse5WHe42wPFhwVM4Fwdkvy8WD6QoroYzJDzrcu1L15nF ... That cratered, too.

No such luck. It can also be caused if your computer is recovered from a virus or adware/spyware attack or by an improper shutdown of the computer. Edit: My original post here was in error; see Tom's post immediately below. I changed main.cf back to relayhost = [localhost]:5000 and restarted postfix.

So, just create another line in that file: Code: localhost user:pass Then run postmap /etc/postfix/saslpass (or whatever the path to the file is). After processing your information (and check) they will send you back a certificate which is of the form -----BEGIN CERTIFICATE----- certificate data here -----END CERTIFICATE----- This is your certificate.