Gentoo Archives: gentoo-user

From: Gevisz <gevisz@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] [OT] Strange behaviour of google certificates.
Date: Thu, 02 Apr 2015 04:45:31
Message-Id: 551cc964.a4b3980a.2fed.04fa@mx.google.com
In Reply to: Re: [gentoo-user] [OT] Strange behaviour of google certificates. by "Mickaël Bucas"
1 On Wed, 1 Apr 2015 23:41:55 +0200 Mickaël Bucas <mbucas@×××××.com> wrote:
2
3 > 2015-04-01 19:19 GMT+02:00 Gevisz <gevisz@×××××.com>:
4 Correction:
5 This question does *not* specifically relates to Gentoo distribution
6 > > but, as far as I have not subscribed to any other mailing list,
7 > > I dare to ask it here.
8 > >
9 > > So, I am using Claws Mail that downloads e-mails from several
10 > > google mail accounts (all are mine :) and about once or twice
11 > > in a month get into the situation when Claws asks me to verify
12 > > and change the google certificates, first in one direction and
13 > > soon after that (usually during the next downloading of my e-mails)
14 > > - in another.
15
16 Actually it does it for every gmail account and at different times.
17 So, yesterday, I "veryfied" google certificates *a lot* of times.
18
19 > > The situation is illustrated by the 2 message screenshots that are
20 > > attached to this e-mail.
21 > >
22 > > The strange thing for me is that, first, the Claws asks me to verify
23 > > and accept a newer certificate complaing that the old one is in some
24 > > aspect "bad", and soon after that it complains about a newer certificate
25 > > and asks me to verify and and accept the older one.
26 > >
27 > > I suspect that it is google that makes something wrong here.
28 > >
29 > > What do you think?
30 >
31 > Hi Gevisz
32 >
33 > I had a similar behavior with another tools : offlineimap
34 > It seems that Google changes certificates very often and/or uses
35 > different certificates on different connections
36
37 Probably, but why they do it?
38
39 > For offlineimap, the solution is to use an option to check certificates :
40 > sslcacertfile = /etc/ssl/certs/ca-certificates.crt
41 >
42 > Maybe there is an option to do the same in Claws Mail.
43 > I found "Bug 2199 - Claws doesn't propery verify certification chain"
44 > [1] which affected a GMail user.
45 > It's fixed, so you may find what's been done.
46 >
47 > Best regards
48 >
49 > Mickaël Bucas
50 >
51 > [1] http://www.thewildbeast.co.uk/claws-mail/bugzilla/show_bug.cgi?id=2199
52
53 Thank you for the link. I will study it later, in the evening.