1 |
you guessed it correctly: My server has only one IP. |
2 |
|
3 |
On 10/17/07, Kalin KOZHUHAROV <kalin@××××××××.net> wrote: |
4 |
> |
5 |
> widyachacra wrote: |
6 |
> > Dear List Friends, |
7 |
> > |
8 |
> > I'm using netqmail for three(3) domains(virtual mail). I want to |
9 |
> > create separate CA certifications for each three(3) virtual mail |
10 |
> > domains. How can i do this? |
11 |
> Not sure what exactly you are trying to achieve, please clarify. |
12 |
> |
13 |
> Let me guess: |
14 |
> |
15 |
> Q: You want to use SMTP/SSL and probably POP3/SSL and you want the |
16 |
> server to respond with different server certificate (nothing to do with |
17 |
> CA) for each vdomain? |
18 |
> |
19 |
> A: You can NOT do this if you are running on a single IP. If you run |
20 |
> several instances of tcpserver (or sslserver from sys-apps/ucspi-ssl) it |
21 |
> probably can be easily done if you setup three instances on three |
22 |
> different IPs. But might not work, has to think it. You might need to |
23 |
> have a fourth "master" tcpserver. |
24 |
> In ASCII it might look like: |
25 |
> |
26 |
> client_1======>sslserver_1---tcpclient_1--- |
27 |
> \ |
28 |
> ....... |--->tcpserver_0-->qmail-smtpd |
29 |
> --- vpopmail |
30 |
> / |
31 |
> client_N======>sslserver_N---tcpclient_2--- |
32 |
> |
33 |
> Everything can be implemented on one machine with several IP addresses |
34 |
> (or ports, but it is messy). Similar stuff for the POP3/SSL. |
35 |
> Basically this is a dirtbag SSL accelerator ;-D |
36 |
> |
37 |
> DISCLAIMER: This is off-the-top-of-my-head, it might not work ;-) |
38 |
> |
39 |
> Kalin. |
40 |
> |
41 |
> -- |
42 |
> |[ ~~~~~~~~~~~~~~~~~~~~~~ ]| |
43 |
> +-> http://ThinRope.net/ <-+ |
44 |
> |[ ______________________ ]| |
45 |
> |
46 |
> -- |
47 |
> gentoo-server@g.o mailing list |
48 |
> |
49 |
> |
50 |
|
51 |
|
52 |
-- |
53 |
--- |
54 |
|
55 |
- Widyachacra Rajapaksha - |