On Fri, 2 May 2014 07:49:51 -0400 (EDT) "Jaldhar H. Vyas"
<[email protected]> wrote:
> On Fri, 2 May 2014, Holger Levsen wrote:
>
> > Hi,

Hi,

> >
> > I've just read this bug report and must say that it's an excellent example 
> > how
> > perfect is the enemy of good.
> >
> > Lenny has long been released by now and this mail isn't helping, except 
> > maybe
> > to ask: time to reconsider the "wontfix" tag?
> >
>
> God knows I'm not an expert on security matters but I asked DDs who
> are and at that time they  were pretty insistent that this is not a good
> idea.  In light of recent events, being able to do IMAP and POP3 over SSL
> out of the box would be great but will using the snakeoil certificate
> actually be secure or just give the illusion of security?  If so, that is
> not just not perfect, it is actually bad.

What do you think is the problem here? The security of the server is
checked client-side.
So, if your IMAP client doesn't warn the user on self-signed
certificates (or expired, or bad ones), the security hole is there.

(I guess you know that the snakeoil certificate is created in
ssl-cert's postinst and not packaged directly?)

> If the consensus has changed I'll reconsider this but I'm not aware that
> it has.

Do you have pointers to your described consensus? Seen the number of
reverse-deps (14 depends and 4 recommends) of ssl-cert, it seems that
the consensus is to use it.

This is also an opportunity to fix #732263.

Summary: please reconsider your wontfix.

Regards

Mathieu


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to