Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Matthias Andree
Am 02.01.22 um 17:11 schrieb Karsten: Basically you can install the self-signed certificate (if you or a trusted party signed it, and you have transmitted it over a secure channel, for instance, via SFTP or SCP) into the trust store (assuming it suits both the TLS server and the signing CA roles

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Karsten
Am 02.01.22 um 16:07 schrieb Matthias Andree: > Am 02.01.22 um 14:03 schrieb Karsten: >> Am 02.01.22 um 12:15 schrieb Matthias Andree: I am the owner of the domain so nobody is hijacked! >>> Are you the owner of "mydomain.de" or of the unnamed domain you intended >>> not to show to the

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Karsten
Am 02.01.22 um 15:28 schrieb Matthias Andree: >>> Untrue. Messages were fetched without proper protection from >>> MITM/eavesdropping attacks, unless you were using *other* options to >>> ensure authenticity of the server. Which I doubt, else you would have >>> asked specific questions about

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Matthias Andree
Am 02.01.22 um 14:03 schrieb Karsten: Am 02.01.22 um 12:15 schrieb Matthias Andree: I am the owner of the domain so nobody is hijacked! Are you the owner of "mydomain.de" or of the unnamed domain you intended not to show to the public? Do you want to help with this new certificate issue or

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Matthias Andree
Am 02.01.22 um 14:24 schrieb Karsten: Am 02.01.22 um 12:28 schrieb Matthias Andree: But it would be helpful for others what must be done to create and install this new "client side certificate" that appears about 2018?   I think the certificate issue was there right from the beginning.

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Karsten
Am 02.01.22 um 12:28 schrieb Matthias Andree: > But it would be helpful for others what must be done to create and install > this new "client side certificate" that appears about 2018? >>>   I think the certificate issue was there right from the beginning. >> Definitely no. Mails where

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Karsten
Am 02.01.22 um 12:15 schrieb Matthias Andree: >> I am the owner of the domain so nobody is hijacked! > > Are you the owner of "mydomain.de" or of the unnamed domain you intended > not to show to the public? Do you want to help with this new certificate issue or discuss the ownership of domains?

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Matthias Andree
Am 02.01.22 um 11:54 schrieb Karsten: Am 01.01.22 um 17:53 schrieb László Böszörményi (GCS): On Sat, Jan 1, 2022 at 2:30 PM Karsten wrote: But it would be helpful for others what must be done to create and install this new "client side certificate" that appears about 2018? I think the

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Matthias Andree
Am 01.01.22 um 14:26 schrieb Karsten: Hello Matthias, Am 01.01.22 um 14:10 schrieb Matthias Andree: Notice something? i notice everything. :-) You hijack somebody else's domain for "anonymization" purposes and expect someone to help you, and you did not respond to hints the server CA's

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-02 Thread Karsten
Am 01.01.22 um 17:53 schrieb László Böszörményi (GCS): > On Sat, Jan 1, 2022 at 2:30 PM Karsten wrote: >> But it would be helpful for others what must be done to create and install >> this new "client side certificate" that >> appears about 2018? > I think the certificate issue was there right

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-01 Thread GCS
On Sat, Jan 1, 2022 at 2:30 PM Karsten wrote: > But it would be helpful for others what must be done to create and install > this new "client side certificate" that > appears about 2018? I think the certificate issue was there right from the beginning. OpenSSL might not have forced its usage or

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-01 Thread Karsten
Hello Matthias, Am 01.01.22 um 14:10 schrieb Matthias Andree: > Notice something? i notice everything. :-) > > You hijack somebody else's domain for "anonymization" purposes and > expect someone to help you, and you did not respond to hints the server > CA's signing certificate might be

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-01 Thread Karsten
Hello Matthias, Am 31.12.21 um 20:05 schrieb Matthias Andree: >> What must be done to get it working again? This question has not been answered. I could only find out that this problems did arrive with the introduction of TLS1.3. > Unless you own "mydomain.de" you've now hit innocent

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-01 Thread Matthias Andree
Happy new year Karsten. Am 01.01.22 um 13:53 schrieb Karsten: Hello Matthias, Am 31.12.21 um 20:05 schrieb Matthias Andree: What must be done to get it working again? This question has not been answered. [...] The security relevant logdata is of course anonymized or altered. Notice

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2022-01-01 Thread GCS
On Fri, Dec 31, 2021 at 8:09 PM Matthias Andree wrote: > > The log says: [...] > > fetchmail: Server certificate verification error: self signed certificate > > fetchmail: Missing trust anchor certificate: [...] > > What must be done to get it working again? Snipped to the relevant part of the

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2021-12-31 Thread Matthias Andree
Am 31.12.21 um 16:32 schrieb Karsten: Package: fetchmail Version: 6.4.16-4+deb11u1 Severity: important I upgraded the server from Debian 9 to 11 and afterwards it seems not possible to get fetchmail to work. I tried every possible option of ssl and sslproto, but fetchmail can't fetch the

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2021-12-31 Thread GCS
Hi Karsten, On Fri, Dec 31, 2021 at 4:36 PM Karsten wrote: > I upgraded the server from Debian 9 to 11 and afterwards it seems not > possible to get fetchmail to work. > > I tried every possible option of ssl and sslproto, but fetchmail can't fetch > the mails. > The log says: [...] >

Bug#1002910: fetchmail is not able to work with an imap server with TLS1.2 encryption

2021-12-31 Thread Karsten
Package: fetchmail Version: 6.4.16-4+deb11u1 Severity: important I upgraded the server from Debian 9 to 11 and afterwards it seems not possible to get fetchmail to work. I tried every possible option of ssl and sslproto, but fetchmail can't fetch the mails. The log says: fetchmail: Trying to