EmailDiscussions.com  

Go Back   EmailDiscussions.com > Discussions about Email Services > Email Comments, Questions and Miscellaneous
Register FAQ Members List Calendar Today's Posts
Stay in touch wirelessly

Email Comments, Questions and Miscellaneous Share your opinion of the email service you're using. Post general email questions and discussions that don't fit elsewhere.

Reply
 
Thread Tools
Old 7 Jan 2015, 08:54 PM   #331
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
Quote:
Originally Posted by dodgeball View Post
Thank you for checking it out.

I manually checked a few settings with openssl s_client and the only
thing I saw was RC4 is still enabled.

openssl s_client -connect mx1.mxroute.com:25 -starttls smtp -tls1 -cipher RC4-SHA
openssl s_client -connect mx1.mxroute.com:25 -starttls smtp -tls1 -cipher RC4-MD5

Also a subdomain mentioned in an earlier comment has SSL3 enabled.
https://www.ssllabs.com/ssltest/anal...ng.mxroute.com

But the mx1.mxroute.com looked fine on ssllabs.com.
Thanks for catching that. That's on today's schedule now

Edit: Fixed!

Last edited by jarland : 8 Jan 2015 at 06:05 AM.
jarland is offline   Reply With Quote
Old 7 Jan 2015, 09:17 PM   #332
FredOnline
The "e" in e-mail
 
Join Date: Apr 2011
Location: Manchester UK
Posts: 2,616
Quote:
Originally Posted by jarland View Post
Been a long time coming... Sieve filtering to be implemented this Friday.
And I'm looking forward to trying it out!
FredOnline is offline   Reply With Quote
Old 8 Jan 2015, 09:31 AM   #333
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
Quote:
Originally Posted by FredOnline View Post
And I'm looking forward to trying it out!
Implemented earlier than planned. All set on everything but the unbranded server. Documentation will follow a bit later. It's Filters under Settings in webmail
jarland is offline   Reply With Quote
Old 8 Jan 2015, 11:44 AM   #334
dodgeball
Junior Member
 
Join Date: Jan 2015
Posts: 5
Quote:
Originally Posted by jarland View Post
Thanks for catching that. That's on today's schedule now

Edit: Fixed!
I see that billing.mxroute.com no longer shows SSL3, but I can still connect
with RC4 (and MD5!) to mx1.mxroute.com:25 with openssl s_client.

openssl s_client -connect mx1.mxroute.com:25 -starttls smtp -tls1 -cipher RC4-SHA
openssl s_client -connect mx1.mxroute.com:25 -starttls smtp -tls1 -cipher RC4-MD5

Thanks.
dodgeball is offline   Reply With Quote
Old 8 Jan 2015, 07:14 PM   #335
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
Quote:
Originally Posted by dodgeball View Post
I see that billing.mxroute.com no longer shows SSL3, but I can still connect
with RC4 (and MD5!) to mx1.mxroute.com:25 with openssl s_client.

openssl s_client -connect mx1.mxroute.com:25 -starttls smtp -tls1 -cipher RC4-SHA
openssl s_client -connect mx1.mxroute.com:25 -starttls smtp -tls1 -cipher RC4-MD5

Thanks.
MD5 was disabled in Apache but I went ahead and disabled in Nginx for kicks. You wouldn't have experienced successful SSL activity using MD5. You can't reasonably drop RC4 from a public production server.

https://community.qualys.com/blogs/s...orward-secrecy
jarland is offline   Reply With Quote
Old 8 Jan 2015, 09:48 PM   #336
dodgeball
Junior Member
 
Join Date: Jan 2015
Posts: 5
Quote:
Originally Posted by jarland View Post
MD5 was disabled in Apache but I went ahead and disabled in Nginx for kicks. You wouldn't have experienced successful SSL activity using MD5. You can't reasonably drop RC4 from a public production server.

https://community.qualys.com/blogs/s...orward-secrecy
Ok, but RC4-MD5 is still working with port 25 and 587 on mx1.mxroute.com.
dodgeball is offline   Reply With Quote
Old 9 Jan 2015, 08:50 AM   #337
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
Quote:
Originally Posted by dodgeball View Post
Ok, but RC4-MD5 is still working with port 25 and 587 on mx1.mxroute.com.
MD5 disabled on Dovecot and Exim.
jarland is offline   Reply With Quote
Old 9 Jan 2015, 09:58 AM   #338
walesrob
Essential Contributor
 
Join Date: Dec 2006
Location: UK
Posts: 392
Looks like something is broken in IMAP, TBird gives this error:


Error: An error occurred during a connection to mx1.mxroute.com:993.

The server rejected the handshake because the client downgraded to a lower TLS version than the server supports.

(Error code: ssl_error_inappropriate_fallback_alert)


Aquamail email app also reporting same.

Both using SSL:993:Normal Password
walesrob is offline   Reply With Quote
Old 9 Jan 2015, 10:01 AM   #339
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
Quote:
Originally Posted by walesrob View Post
Looks like something is broken in IMAP, TBird gives this error:


Error: An error occurred during a connection to mx1.mxroute.com:993.

The server rejected the handshake because the client downgraded to a lower TLS version than the server supports.

(Error code: ssl_error_inappropriate_fallback_alert)


Aquamail email app also reporting same.

Both using SSL:993:Normal Password
Walked back the SSL settings I just changed on it. Working better now from your end? Will do some more testing before removing ciphers on Dovecot. It's not like it's a huge deal, people with up to date software should be using secure ciphers anyway, people need to remember SSL is a two part deal and server only plays half of it
jarland is offline   Reply With Quote
Old 9 Jan 2015, 10:04 AM   #340
walesrob
Essential Contributor
 
Join Date: Dec 2006
Location: UK
Posts: 392
Quote:
Originally Posted by jarland View Post
Walked back the SSL settings I just changed on it. Working better now from your end? Will do some more testing before removing ciphers on Dovecot. It's not like it's a huge deal, people with up to date software should be using secure ciphers anyway, people need to remember SSL is a two part deal and server only plays half of it
Jarland, you are the best IMAP working great
walesrob is offline   Reply With Quote
Old 9 Jan 2015, 10:05 AM   #341
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
Quote:
Originally Posted by walesrob View Post
Jarland, you are the best IMAP working great
That or a terrible admin for removing ciphers without heavy testing first

Always happy to help and listen to ideas for improvement.
jarland is offline   Reply With Quote
Old 9 Jan 2015, 11:54 AM   #342
dodgeball
Junior Member
 
Join Date: Jan 2015
Posts: 5
Quote:
Originally Posted by jarland View Post
MD5 disabled on Dovecot and Exim.
Thank you!
dodgeball is offline   Reply With Quote
Old 9 Jan 2015, 09:11 PM   #343
FredOnline
The "e" in e-mail
 
Join Date: Apr 2011
Location: Manchester UK
Posts: 2,616
Does anyone know if the Junk and Deleted Items folders in MXroute Roundcube have an auto purge after x days, and if so, how many days?
FredOnline is offline   Reply With Quote
Old 9 Jan 2015, 09:54 PM   #344
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
Quote:
Originally Posted by FredOnline View Post
Does anyone know if the Junk and Deleted Items folders in MXroute Roundcube have an auto purge after x days, and if so, how many days?
They do not. I like to stay hands off on things like that.
jarland is offline   Reply With Quote
Old 10 Jan 2015, 03:46 AM   #345
FredOnline
The "e" in e-mail
 
Join Date: Apr 2011
Location: Manchester UK
Posts: 2,616
MXroute policy revised

MXroute policy revised. Two sections added to the bottom.

https://mxroute.com/tos.html
FredOnline is offline   Reply With Quote
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT +9. The time now is 08:14 AM.

 

Copyright EmailDiscussions.com 1998-2022. All Rights Reserved. Privacy Policy