threads / discuss / 61927

git send-email with ancient SMTP server … dh key too small

Subject: git send-email with ancient SMTP server … dh key too small

## tl;dr

3 messages between Aug 9, 2024 and Aug 10, 2024.

replies: 2people: 2as markdown or json

Matěj Cepl· Aug 9, 2024, 10:17 UTC · lore

When using git send-email sending to very ancient SMTP server (postfix 2.6.6 on CentOS 6), I get this error:

STARTTLS failed! SSL connect attempt failed error:0A00018A:SSL routines::dh key too small at /usr/libexec/git/git-send-email line 1638.

When looking what seems like a similar error at https://github.com/symfony/symfony/issues/44393 it seems I need to set `security_level` (whatever it is) to 1. Is it possible to do it just with configuration of git or do I need to patch something somewhere?

Thank you for any reply,
Matěj Cepl
-- 
http://matej.ceplovi.cz/blog/, @mcepl@floss.social
GPG Finger: 3C76 A027 CA45 AD70 98B5  BC1D 7920 5802 880B C9D8
 
Opportunity is missed by most people because it is dressed in
overalls and looks like work.
  -- Thomas A. Edison
brian m. carlson· Aug 9, 2024, 19:17 UTC · re: Matěj Cepl · lore

Re: git send-email with ancient SMTP server … dh key too smalll

On 2024-08-09 at 10:17:14, Matěj Cepl wrote:
> When using git send-email sending to very ancient SMTP server
> (postfix 2.6.6 on CentOS 6), I get this error:
> 
> STARTTLS failed! SSL connect attempt failed error:0A00018A:SSL routines::dh key too small at /usr/libexec/git/git-send-email line 1638.

This probably means that the DH key is insecure, so sending mail to this server with TLS probably won't provide sufficient security. You may want to reconsider using this mail server, especially since it hasn't had security updates for well over 3.5 years.

If you're using level 2, then the requirement is the equivalent of 112 bits of security, which is still inadequate by today's standards (which suggest 128 bits of security, or level 3). Level 1 is 80 bits, which is probably attackable by government agencies.

Show 5 quoted lines
> When looking what seems like a similar error at
> https://github.com/symfony/symfony/issues/44393 it seems I need
> to set `security_level` (whatever it is) to 1. Is it possible
> to do it just with configuration of git or do I need to patch
> something somewhere?

What you're looking for is an OpenSSL configuration on your system. On my Debian system, the configuration file is in `/etc/ssl/openssl.cnf`. The steps for what you need to set are available at several different places online. https://askubuntu.com/questions/1233186/ubuntu-20-04-how-to-set-lower-ssl-security-level is an example you can use.

I don't believe that Git provides a set of TLS configuration options for `git send-email`, but if it did, you could control the configuration by specifying cipher suites as `DEFAULT@SECLEVEL=1`. You might, but probably would not, need to configure the minimum protocol to something lower as well. I believe CentOS 6 does support TLS 1.2, so that should be a fine default and shouldn't need to be modified.

-- 
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA
Matěj Cepl· Aug 10, 2024, 10:27 UTC · re: brian m. carlson · lore

Re: git send-email with ancient SMTP server … dh key too smalll

On Fri Aug 9, 2024 at 9:17 PM CEST, brian m. carlson wrote:
> If you're using level 2, then the requirement is the equivalent of 112
> bits of security, which is still inadequate by today's standards (which
> suggest 128 bits of security, or level 3).  Level 1 is 80 bits, which is
> probably attackable by government agencies.

We are talking about sending patches to the public email lists (and yes, considering my other emails, I can live with them being snooped on by government agencies, they are welcome to my ramblings in emails).

Show 6 quoted lines
> What you're looking for is an OpenSSL configuration on your system.  On
> my Debian system, the configuration file is in `/etc/ssl/openssl.cnf`.
> The steps for what you need to set are available at several different
> places online.
> https://askubuntu.com/questions/1233186/ubuntu-20-04-how-to-set-lower-ssl-security-level
> is an example you can use.

Well, but that would degrade the security of the whole system for all purposes it uses OpenSSL, right? That’s rather too drastic.

Show 6 quoted lines
> I don't believe that Git provides a set of TLS configuration options for
> `git send-email`, but if it did, you could control the configuration by
> specifying cipher suites as `DEFAULT@SECLEVEL=1`.  You might, but
> probably would not, need to configure the minimum protocol to something
> lower as well.  I believe CentOS 6 does support TLS 1.2, so that should
> be a fine default and shouldn't need to be modified.

Thank you, I will take a look. I found https://stackoverflow.com/q/34176433 and https://stackoverflow.com/a/36417794, so I will take a look at the Perl code.

Best,
Matěj
-- 
http://matej.ceplovi.cz/blog/, @mcepl@floss.social
GPG Finger: 3C76 A027 CA45 AD70 98B5  BC1D 7920 5802 880B C9D8
 
See, when the GOVERNMENT spends money, it creates jobs; whereas
when the money is left in the hands of TAXPAYERS, God only knows
what they do with it. Bake it into pies, probably. Anything to
avoid creating jobs.
    -- Dave Barry

← back to recent threads