Hello M.,

Sunday, December 5, 2004, 4:49:07 AM, you wrote:
> "TLS handshake failure. Invalid server certificate (This certificate
> has expired)." Of course because of cert expiration I couldn't get new
> mails and to do that I had to change my email account configuration
> from secure to regular. I was wondering why free programs like Mozilla
> let us use expired certificates and TB! does not? In my opinion _using
> expired cert is much more secure than using regular connection_.

I can't completely agree with silently being permitted to use expired
certs- false sense of security for those not paying attention.  But I
did learn some more in addition to the similar SSL/TLS issues I brought
up at the end of October.

Try something for me, to test it out.  Instead of completely degrading
to unsecure mode try StartTLS mode (initial conection made port 110 then
normal TLS established for the remainder of the session)

What I have happen is failure in SSL/TLS mode to dedicated port (995,
993, 465) due to TB choking (and not even allowing me to *view* the
certificates) but does allow me to permit, per session only/no
importing.

What I have found recently is I can get away with StartTLS mode and get
no prompt at all... it just works, no complaints.  Now *this* is a bug,
if the first forced fails are by design...

Also, I find TB behaves differently wrt certificate warnings if you are
behind a router/NAT or connected direct along with the SSL/TLS dedicated
vs. StartTLS modes.

> How about changing that and give us a choice to use it or not?

AMEN!

I want to be able to view every certificate TB negotiates with as well I
want the option to take authentication on myself and permanently allow
sessions with certs I say are good.  I do not care for TB making those
decisions for me- especially since it isn't following any apparent
standard.

sorry for adding my frustration rant to your post- you have resurfaced a
valid issue that seems to die quickly around here- which to me is
surprising since TB! is, IMO, one of the best security focused mail
clients around.

-- 
Most Sincerely,
 Mark (Army RedLeg)

Enjoying OTFPwdE with TheBat! Professional Edition v.3.0.2.10 on
Win2kSP4/Sony Vaio F430 laptop PIII-450/256MB. coming to you
"LIVE!, From Albuquerque" <g>

Eric Howes' on Protecting Your Privacy & Security:
https://netfiles.uiuc.edu/ehowes/www/
Good chance you'll find *all* the goodies here:
http://lists.gpick.com/
looking for a nice place off the beaten usenet path?  join us:
nntp://news.securecomp.org


________________________________________________________
 Current beta is 3.0.2.10 | 'Using TBBETA' information:
http://www.silverstones.com/thebat/TBUDLInfo.html
IMPORTANT: To register as a Beta tester, use this link first -
http://www.ritlabs.com/en/partners/testers/

Reply via email to