# git send-email with ancient SMTP server … dh key too small

3 messages from 2024-08-09 to 2024-08-10. Participants: Matěj Cepl, brian m. carlson.
Thread: https://gitlist.dev/t/61927

## Matěj Cepl, 2024-08-09 10:17

Subject: git send-email with ancient SMTP server … dh key too small
Message-ID: <D3BAXOA4NL74.29XYKS0IO8UFC@cepl.eu>
URL: https://gitlist.dev/e/D3BAXOA4NL74.29XYKS0IO8UFC%40cepl.eu

```
When using git send-email sending to very ancient SMTP server
(postfix 2.6.6 on CentOS 6), I get this error:

STARTTLS failed! SSL connect attempt failed error:0A00018A:SSL routines::dh key too small at /usr/libexec/git/git-send-email line 1638.

When looking what seems like a similar error at
https://github.com/symfony/symfony/issues/44393 it seems I need
to set `security_level` (whatever it is) to 1. Is it possible
to do it just with configuration of git or do I need to patch
something somewhere?

Thank you for any reply,

Matěj Cepl

-- 
http://matej.ceplovi.cz/blog/, @mcepl@floss.social
GPG Finger: 3C76 A027 CA45 AD70 98B5  BC1D 7920 5802 880B C9D8
 
Opportunity is missed by most people because it is dressed in
overalls and looks like work.
  -- Thomas A. Edison

```

## brian m. carlson, 2024-08-09 19:17

Subject: Re: git send-email with ancient SMTP server … dh key too smalll
Message-ID: <ZrZrVpYdSPb731_p@tapette.crustytoothpaste.net>
URL: https://gitlist.dev/e/ZrZrVpYdSPb731_p%40tapette.crustytoothpaste.net
In-Reply-To: <D3BAXOA4NL74.29XYKS0IO8UFC@cepl.eu>

```
On 2024-08-09 at 10:17:14, Matěj Cepl wrote:
> When using git send-email sending to very ancient SMTP server
> (postfix 2.6.6 on CentOS 6), I get this error:
> 
> STARTTLS failed! SSL connect attempt failed error:0A00018A:SSL routines::dh key too small at /usr/libexec/git/git-send-email line 1638.

This probably means that the DH key is insecure, so sending mail to this
server with TLS probably won't provide sufficient security.  You may
want to reconsider using this mail server, especially since it hasn't
had security updates for well over 3.5 years.

If you're using level 2, then the requirement is the equivalent of 112
bits of security, which is still inadequate by today's standards (which
suggest 128 bits of security, or level 3).  Level 1 is 80 bits, which is
probably attackable by government agencies.

> When looking what seems like a similar error at
> https://github.com/symfony/symfony/issues/44393 it seems I need
> to set `security_level` (whatever it is) to 1. Is it possible
> to do it just with configuration of git or do I need to patch
> something somewhere?

What you're looking for is an OpenSSL configuration on your system.  On
my Debian system, the configuration file is in `/etc/ssl/openssl.cnf`.
The steps for what you need to set are available at several different
places online.
https://askubuntu.com/questions/1233186/ubuntu-20-04-how-to-set-lower-ssl-security-level
is an example you can use.

I don't believe that Git provides a set of TLS configuration options for
`git send-email`, but if it did, you could control the configuration by
specifying cipher suites as `DEFAULT@SECLEVEL=1`.  You might, but
probably would not, need to configure the minimum protocol to something
lower as well.  I believe CentOS 6 does support TLS 1.2, so that should
be a fine default and shouldn't need to be modified.
-- 
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA

```

## Matěj Cepl, 2024-08-10 10:27

Subject: Re: git send-email with ancient SMTP server … dh key too smalll
Message-ID: <D3C5RQ4Q7N5K.1OE55HRDAYH0A@cepl.eu>
URL: https://gitlist.dev/e/D3C5RQ4Q7N5K.1OE55HRDAYH0A%40cepl.eu
In-Reply-To: <ZrZrVpYdSPb731_p@tapette.crustytoothpaste.net>

```
On Fri Aug 9, 2024 at 9:17 PM CEST, brian m. carlson wrote:
> If you're using level 2, then the requirement is the equivalent of 112
> bits of security, which is still inadequate by today's standards (which
> suggest 128 bits of security, or level 3).  Level 1 is 80 bits, which is
> probably attackable by government agencies.

We are talking about sending patches to the public email lists
(and yes, considering my other emails, I can live with them
being snooped on by government agencies, they are welcome to my
ramblings in emails).

> What you're looking for is an OpenSSL configuration on your system.  On
> my Debian system, the configuration file is in `/etc/ssl/openssl.cnf`.
> The steps for what you need to set are available at several different
> places online.
> https://askubuntu.com/questions/1233186/ubuntu-20-04-how-to-set-lower-ssl-security-level
> is an example you can use.

Well, but that would degrade the security of the whole system for
all purposes it uses OpenSSL, right? That’s rather too drastic.

> I don't believe that Git provides a set of TLS configuration options for
> `git send-email`, but if it did, you could control the configuration by
> specifying cipher suites as `DEFAULT@SECLEVEL=1`.  You might, but
> probably would not, need to configure the minimum protocol to something
> lower as well.  I believe CentOS 6 does support TLS 1.2, so that should
> be a fine default and shouldn't need to be modified.

Thank you, I will take a look. I found
https://stackoverflow.com/q/34176433 and
https://stackoverflow.com/a/36417794, so I will take a look at
the Perl code.

Best,

Matěj

-- 
http://matej.ceplovi.cz/blog/, @mcepl@floss.social
GPG Finger: 3C76 A027 CA45 AD70 98B5  BC1D 7920 5802 880B C9D8
 
See, when the GOVERNMENT spends money, it creates jobs; whereas
when the money is left in the hands of TAXPAYERS, God only knows
what they do with it. Bake it into pies, probably. Anything to
avoid creating jobs.
    -- Dave Barry


```
