1 |
2015-04-01 19:19 GMT+02:00 Gevisz <gevisz@×××××.com>: |
2 |
> This question does specifically relates to Gentoo distribution |
3 |
> but, as far as I have not subscribed to any other mailing list, |
4 |
> I dare to ask it here. |
5 |
> |
6 |
> So, I am using Claws Mail that downloads e-mails from several |
7 |
> google mail accounts (all are mine :) and about once or twice |
8 |
> in a month get into the situation when Claws asks me to verify |
9 |
> and change the google certificates, first in one direction and |
10 |
> soon after that (usually during the next downloading of my e-mails) |
11 |
> - in another. |
12 |
> |
13 |
> The situation is illustrated by the 2 message screenshots that are |
14 |
> attached to this e-mail. |
15 |
> |
16 |
> The strange thing for me is that, first, the Claws asks me to verify |
17 |
> and accept a newer certificate complaing that the old one is in some |
18 |
> aspect "bad", and soon after that it complains about a newer certificate |
19 |
> and asks me to verify and and accept the older one. |
20 |
> |
21 |
> I suspect that it is google that makes something wrong here. |
22 |
> |
23 |
> What do you think? |
24 |
|
25 |
Hi Gevisz |
26 |
|
27 |
I had a similar behavior with another tools : offlineimap |
28 |
It seems that Google changes certificates very often and/or uses |
29 |
different certificates on different connections |
30 |
|
31 |
For offlineimap, the solution is to use an option to check certificates : |
32 |
sslcacertfile = /etc/ssl/certs/ca-certificates.crt |
33 |
|
34 |
Maybe there is an option to do the same in Claws Mail. |
35 |
I found "Bug 2199 - Claws doesn't propery verify certification chain" |
36 |
[1] which affected a GMail user. |
37 |
It's fixed, so you may find what's been done. |
38 |
|
39 |
Best regards |
40 |
|
41 |
Mickaël Bucas |
42 |
|
43 |
[1] http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=2199 |