Create self-signed certificate for Dovecot

Reuben Budiardja techlist at pathfinder.phys.utk.edu
Thu Sep 22 16:14:16 UTC 2005


Hello,
I have two (personal) mail servers both running dovecot.  I only allow 
imaps  service for better security. Both using just the default 
certificates.

I am wondering how do I create my own self-signed certificate that works 
with dovecot ? I tried searching the web but I've not found what I need 
yet. I've tried running "make dovecot.pem" in /usr/share/ssl/certs, but 
after creating a new dovecot.pem, I got:

imap-login: Can't load private key file 
/usr/share/ssl/private/dovecot.pem: error:0
B080074:x509 certificate routines:X509_check_private_key:key values mismatch
Sep 22 12:14:35 pathfinder last message repeated 2 times
Sep 22 12:14:35 pathfinder dovecot: Login process died too early - 
shutting down
Sep 22 12:14:35 pathfinder dovecot: child 22839 (login) returned error 89

Any help ?

One of the reason I want to create a new self-signed certificate is that 
thunderbird complained that my certificate serial number is not unique, 
when it tries to access my other mail server (also running dovecot with 
imaps). I don't know why thunderbird does that while kmail works just 
fine with the two mail servers.

Thanks for any info or pointer.

Reuben D. Budiardja




More information about the fedora-list mailing list