BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] SSL problems with imapfilter after upgrade to Debian 11
- Subject: [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- From: me at mattgillen.net (Matthew Gillen)
- Date: Sat, 28 Aug 2021 16:09:35 -0400
- In-reply-to: <612a4667.1c69fb81.9e5a3.1f66@mx.google.com>
- References: <6129532d.1c69fb81.ff7ce.e069@mx.google.com> <d46fbce7-4ade-540f-7d92-3c8e3b15a08f@mattgillen.net> <612a4667.1c69fb81.9e5a3.1f66@mx.google.com>
On 8/28/2021 10:21 AM, Rich Pieri wrote: > On Sat, 28 Aug 2021 01:54:15 -0400 > Matthew Gillen <me at mattgillen.net> wrote: > >> will tell you a fair bit about what the server is presenting to >> clients. (check the expiration on the cert; LetsEncrypt is only valid >> for 90 days; maybe your auto-renew is broken?) > > SSL is working correctly. Auto-renew is working correctly. Not > switching to STARTTLS. My other IMAP clients work just fine, it's only > imapfilter. > > https://github.com/lefcha/imapfilter > > And... I finally figured it out. Debian's most recent incarnations of > imapfilter or OpenSSL are being too strict about hostname matches and > bombing out and not providing useful error messages. > > But I also found a better workaround: tell imapfilter not to cache the > server certificate (options.certificates in the config file). Why this > works? Dunnow, but it does. That seems like a very odd thing to do. The server certificate is provided as part of the TLS handshake, every single time you connect. There is no point in caching it for performance reasons. Maybe they are trying to do a poor-man's certificate pinning, and their implementation is bad? That's the only thing I can think of that would make storing the server cert useful in any way. Matt
- Follow-Ups:
- [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- References:
- [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- From: me at mattgillen.net (Matthew Gillen)
- [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- Prev by Date: [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- Next by Date: [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- Previous by thread: [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- Next by thread: [Discuss] SSL problems with imapfilter after upgrade to Debian 11
- Index(es):