Gentoo Archives: gentoo-user

From: Gevisz <gevisz@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] [OT] Strange behaviour of google certificates.
Date: Fri, 03 Apr 2015 06:52:09
Message-Id: 551e388e.ca9dc20a.5407.ffff9ee9@mx.google.com
In Reply to: Re: [gentoo-user] [OT] Strange behaviour of google certificates. by bitlord
1 On Fri, 3 Apr 2015 08:26:12 +0200 bitlord <bitlord0xff@×××××.com> wrote:
2
3 > On Thu, 2 Apr 2015 11:57:26 +0300
4 > Gevisz <gevisz@×××××.com> wrote:
5 >
6 > > On Thu, 2 Apr 2015 03:52:40 -0400 "Walter Dnes"
7 > > <waltdnes@××××××××.org> wrote:
8 > >
9 > > > On Wed, Apr 01, 2015 at 08:19:45PM +0300, Gevisz wrote
10 > > >
11 > > > > So, I am using Claws Mail that downloads e-mails from several
12 > > > > google mail accounts (all are mine :) and about once or twice
13 > > > > in a month get into the situation when Claws asks me to verify
14 > > > > and change the google certificates, first in one direction and
15 > > > > soon after that (usually during the next downloading of my
16 > > > > e-mails)
17 > > > > - in another.
18 > > > >
19 > ...
20 > > >
21 > > > The 2 servers probably have different certificates, which is why
22 > > > you get this behaviour. I suggest going into "apk mode" and
23 > > > putting an entry into your hosts file <G>, like...
24 > > >
25 > > > 173.194.192.108 pop.gmail.com
26 > > >
27 > > > This will force your system to always use the same server, and
28 > > > avoid the re-validation every time you hit the other server from
29 > > > the one you used the previous time.
30 > >
31 > > Thank you for your advice. Added that line to my /etc/hosts file.
32 > > After that Claws asked to verify the google certificate once again,
33 > > but I hope that that was the last time this month and that that
34 > > madness with google certificates finally ends. (Because in the last 2
35 > > days this situation repeated at least 20 or more times.)
36 > >
37 > >
38 > By looking at the screenshoots that is >=claws-mail-3.10.x (I think
39 > that is the version when it got support for validating certificate
40 > chains)? There is a option in Configuration > Edit Accounts ... then
41 > for every account you have "SSL" options, you can check to accept
42 > "unknown valid certificates" so it will do it automatically, won't ask
43 > if there is a new certificate and it is valid.
44
45 Thank you for your advice but I do not want to accept certificates
46 unverified and automatically and do not mind verifying a new goggle
47 certificate once a month or so. However, I do not want to see a madness
48 when my e-mail client asks me to verify the certificates that I have
49 already verified over and over again (as described above).
50
51 Sticking to only one gmail server, as advised by Walter,
52 so far solved the problem.
53
54 I write "so far" because there is a (very small) probability that
55 the madness ended by itself (because usually it took place not always
56 but at some periods when one gmail server already switched to a new
57 certificate and another one still uses the old certificate, I guess).
58
59 So, I have to wait one or two months (until they start to switch to
60 even more new certificate) to see how my e-mail client will react.