On Fri, 2 May 2014 07:49:51 -0400 (EDT) "Jaldhar H. Vyas" <[email protected]> wrote: > On Fri, 2 May 2014, Holger Levsen wrote: > > > Hi,
Hi, > > > > I've just read this bug report and must say that it's an excellent example > > how > > perfect is the enemy of good. > > > > Lenny has long been released by now and this mail isn't helping, except > > maybe > > to ask: time to reconsider the "wontfix" tag? > > > > God knows I'm not an expert on security matters but I asked DDs who > are and at that time they were pretty insistent that this is not a good > idea. In light of recent events, being able to do IMAP and POP3 over SSL > out of the box would be great but will using the snakeoil certificate > actually be secure or just give the illusion of security? If so, that is > not just not perfect, it is actually bad. What do you think is the problem here? The security of the server is checked client-side. So, if your IMAP client doesn't warn the user on self-signed certificates (or expired, or bad ones), the security hole is there. (I guess you know that the snakeoil certificate is created in ssl-cert's postinst and not packaged directly?) > If the consensus has changed I'll reconsider this but I'm not aware that > it has. Do you have pointers to your described consensus? Seen the number of reverse-deps (14 depends and 4 recommends) of ssl-cert, it seems that the consensus is to use it. This is also an opportunity to fix #732263. Summary: please reconsider your wontfix. Regards Mathieu -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

