**** BEGIN LOGGING AT Fri Mar 11 02:59:58 2016 Mar 11 10:40:17 using N900 sucks sometimes ... like now I need to use Pulse Secure Mar 11 11:01:31 wth is that? Mar 11 11:23:21 propietary vpn? Mar 11 12:26:03 it's software used with Juniper firewalls. vpn as ceene indicated. Mar 11 12:26:23 there are clients for android & ios, as usual :) Mar 11 12:27:35 there is client for linux desktop (binary), but even that is not trivial to use. most reports indicate failure, unless you're on redhat (no surprise, i guess?) Mar 11 12:43:27 regarding ssl3, i have just been helping a friend with his server, and for IMAPS i had to temporarily enable ssl3. in general we understand that to be vulnerable (poodle), right? then i ran the test on google imap server, and they also have ssl3 enabled. am i missing something? Mar 11 12:55:24 Sicelo: oooer... what mailclient required ssl3 ??? Mar 11 12:57:35 my courier-imap-ssl has TLS_PROTOCOL="TLS1.2" Mar 11 12:57:45 and i believe it works with the n900 mailclient Mar 11 12:58:03 i.e. not allowing SSL2 SSL3 TLS1.0 TLS1.1 Mar 11 12:58:23 not sure Mar 11 12:58:40 well, how did you come to "for IMAPS i had to temporarily enable ssl3" Mar 11 12:59:22 I did indeed hear google have lax ssl allowance on inbound connections, though that doesn't mean your client has to be set to allow low-grade encryption Mar 11 12:59:31 testing with openssl s_client -connect server:993 Mar 11 13:00:23 using 'openssl' binary on maemo ? Mar 11 13:00:28 yes Mar 11 13:00:31 that might just be outdated or somesuch Mar 11 13:00:41 hmm, possible Mar 11 13:00:45 i'd ignore that and test with the maemo mailclient Mar 11 13:01:00 0.9.8zf Mar 11 13:01:03 aaaaaaaaah Mar 11 13:01:18 yes old tool Mar 11 13:01:24 definitely don't use that Mar 11 13:01:47 though raises questions what (unpatched?) openssl / gnutls libraries the maemo browser and mailclient are linked against Mar 11 13:01:56 let me check what's inside ED Mar 11 13:02:03 ??ED?? Mar 11 13:02:38 easy debian :) Mar 11 13:02:49 there is a talk.maemo.org thread about that easy deiban Mar 11 13:02:59 somebody did the needed hacks to make a jessie armhf image Mar 11 13:03:22 wheezy armel architecture (old images) is not included in debian long term support Mar 11 13:03:36 squeeze (older!) armel image is now also debian archived Mar 11 13:04:22 okay :) Mar 11 13:04:28 let me ssh to my home pc Mar 11 13:05:19 http://talk.maemo.org/showpost.php?p=1446540&postcount=3138 Mar 11 13:06:12 they had to patch for older pulseaudio and older linux kernel Mar 11 13:06:22 but now armhf, will run faster and up-to-date / supported Mar 11 13:06:31 also it looks likely jessie-armhf will be -lts supported Mar 11 13:24:20 Sicelo: try openconnect Mar 11 13:24:50 it has support for cisco anyconnect and iirc they were working on juniper suff as well Mar 11 13:26:42 bencoh: looks good indeed. will try it :) Mar 11 13:57:40 enyc: thanks for the nudge. disabled ssl3 again, and tls working even with maemo's openssl Mar 11 14:42:49 Sicelo: hard to sort out at first, not always know what change(s) you actually needed etc etc! Mar 11 23:43:03 Pali: new kdepim-noakonadi kmail fails to build :< Mar 11 23:47:29 nm, I think I'm doing osmething wrong Mar 12 01:11:49 Luke-Jr: it builds fine for me... **** ENDING LOGGING AT Sat Mar 12 02:59:58 2016