Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Memories of you remind me of you. -- Karl Lehenbauer


computers / alt.comp.software.thunderbird / How to add an exception in Thunderbird for a private certificate?

SubjectAuthor
* How to add an exception in Thunderbird for a private certificate?Carlos E.R.
+* How to add an exception in Thunderbird for a private certificate?Andy Burns
|`* How to add an exception in Thunderbird for a private certificate?Carlos E.R.
| `* How to add an exception in Thunderbird for a private certificate?Andy Burns
|  `* How to add an exception in Thunderbird for a private certificate?Carlos E.R.
|   `* How to add an exception in Thunderbird for a private certificate?Andy Burns
|    `* How to add an exception in Thunderbird for a private certificate?Carlos E.R.
|     `- How to add an exception in Thunderbird for a private certificate?Andy Burns
`* How to add an exception in Thunderbird for a private certificate? [SOLVED]Carlos E.R.
 `- How to add an exception in Thunderbird for a private certificate? [SOLVED]Carlos E.R.

1
How to add an exception in Thunderbird for a private certificate?

<h5u26kxkok.ln2@Telcontar.valinor>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2503&group=alt.comp.software.thunderbird#2503

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.comp.software.thunderbird
Subject: How to add an exception in Thunderbird for a private certificate?
Date: Fri, 29 Dec 2023 14:28:49 +0100
Lines: 60
Message-ID: <h5u26kxkok.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
X-Trace: individual.net 7a84hBusvZCWnijg9KSdNw+OTPY0fiZCnJQl2IINDioPG86C7B
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:pSULCpN+B5L1cyKIJVONg1Teh8U= sha256:2q2/sBObuo1XcLdMx9DQLbnuZ+3x9Q8tfC43jCp7FXM=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
 by: Carlos E.R. - Fri, 29 Dec 2023 13:28 UTC

Hi,

I am on TB 115.5.0 on Linux. Since some recent update TB is unable to
retrieve mail on my LAN dovecot server which uses a private certificate.

Notice that I can not use a public certificate, because I don't have a
public domain. My domain name is faked.

I had notes from previous occurrences:

+++···························

Thunderbird (2023-07-02):

<2.6> 2023-07-02T13:52:31.144979+02:00 Telcontar dovecot - - -
imap-login: Disconnected: Connection closed: SSL_accept() failed:
error:14094412:SSL routines:ssl3_re
ad_bytes:sslv3 alert bad certificate: SSL alert number 42 (no auth
attempts in 0 secs): user=<>, rip=127.0.0.1, lip=127.0.0.1, TLS
handshaking: SSL_accept() failed:
error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate:
SSL alert number 42, session=<2DNWr3//7I5/AAAB>
<2.6> 2023-07-02T13:52:32.244736+02:00 Telcontar dovecot - - -
imap-login: Disconnected: Connection closed: SSL_accept() failed:
error:14094412:SSL routines:ssl3_re
ad_bytes:sslv3 alert bad certificate: SSL alert number 42 (no auth
attempts in 0 secs): user=<>, rip=127.0.0.1, lip=127.0.0.1, TLS
handshaking: SSL_accept() failed:
error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate:
SSL alert number 42, session=<CPtmr3///I5/AAAB>

Regenerate certificates.

cd /etc/dovecot
rm /etc/ssl/private/dovecot.pem
rm /etc/ssl/private/dovecot.crt
bash mkcert.sh
time openssl dhparam -out /etc/dovecot/dh.pem 4096

Delete certificate in Thunderbird (settings, search for "cert"), Manage
Certificates, Servers tab.
Then "Get messages / "cer", authorize cert.
···························++-

Problem is, Thunderbird just can't read the emails, and never prompts
about the certificate, so it is impossible to create an exception. TB
just keeps silent (checking server capabilities).

Is there a way to force TB to just accept the certificate and get along?

--
Cheers, Carlos.

Re: How to add an exception in Thunderbird for a private certificate?

<kv80b2Fca4mU1@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2504&group=alt.comp.software.thunderbird#2504

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@andyburns.uk (Andy Burns)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
Date: Fri, 29 Dec 2023 13:36:32 +0000
Lines: 8
Message-ID: <kv80b2Fca4mU1@mid.individual.net>
References: <h5u26kxkok.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net dfRMzibQwT1tBQpdm9s3tgKDICrV2BQAhwANbp0gmwrgdTgf36
Cancel-Lock: sha1:DEdGwMEnei563HcCjr+0lKRCDcY= sha256:omvDPMiDAUjpbm8G5D6GgfN+aPDUOHPdPQXiQ/AEunc=
User-Agent: Mozilla Thunderbird
Content-Language: en-GB
In-Reply-To: <h5u26kxkok.ln2@Telcontar.valinor>
 by: Andy Burns - Fri, 29 Dec 2023 13:36 UTC

Carlos E.R. wrote:

> TB is unable to retrieve mail on my LAN dovecot server which uses a
> private certificate.

import your server's cert (or your ca's root cert) into TB

Settings/Privacy&Security/ManageCertificates

Re: How to add an exception in Thunderbird for a private certificate?

<p1136kxhjo.ln2@Telcontar.valinor>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2505&group=alt.comp.software.thunderbird#2505

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!news.samoylyk.net!3.eu.feeder.erje.net!2.eu.feeder.erje.net!feeder.erje.net!newsreader4.netcologne.de!news.netcologne.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
Date: Fri, 29 Dec 2023 15:18:01 +0100
Lines: 15
Message-ID: <p1136kxhjo.ln2@Telcontar.valinor>
References: <h5u26kxkok.ln2@Telcontar.valinor>
<kv80b2Fca4mU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net M0vAUvXZEXNwidw64YdjdAw/hEBZXYBoWOH6C5YeqfFRrYLxlP
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:0Jv/Wcjthih6uSG0RXC7yrbidUQ= sha256:oYP+ANloDFMOVg4H7OZ3Gjxshm8z1OPE1mnjKi1bG1A=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <kv80b2Fca4mU1@mid.individual.net>
 by: Carlos E.R. - Fri, 29 Dec 2023 14:18 UTC

On 2023-12-29 14:36, Andy Burns wrote:
> Carlos E.R. wrote:
>
>> TB is unable to retrieve mail on my LAN dovecot server which uses a
>> private certificate.
>
> import your server's cert (or your ca's root cert) into TB
>
> Settings/Privacy&Security/ManageCertificates

There is no ca.

--
Cheers, Carlos.

Re: How to add an exception in Thunderbird for a private certificate?

<kv84c3Fca4mU5@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2506&group=alt.comp.software.thunderbird#2506

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!news.samoylyk.net!newsfeed.pionier.net.pl!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@andyburns.uk (Andy Burns)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
Date: Fri, 29 Dec 2023 14:45:21 +0000
Lines: 21
Message-ID: <kv84c3Fca4mU5@mid.individual.net>
References: <h5u26kxkok.ln2@Telcontar.valinor>
<kv80b2Fca4mU1@mid.individual.net> <p1136kxhjo.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net GgYfzVzN7SHm+/kGRXX2eQPRyiUHRVttOdmpza8CpUaJHvMpfx
Cancel-Lock: sha1:NnbeTwe2MdNifDP9c6cZrwz/nUs= sha256:UkA7jgeRkWtccDaOcy6429VOwtJtXcpzzVeoQEEeEOs=
User-Agent: Mozilla Thunderbird
Content-Language: en-GB
In-Reply-To: <p1136kxhjo.ln2@Telcontar.valinor>
 by: Andy Burns - Fri, 29 Dec 2023 14:45 UTC

Carlos E.R. wrote:

> Andy Burns wrote:
>
>> Carlos E.R. wrote:
>>
>>> TB is unable to retrieve mail on my LAN dovecot server which uses a
>>> private certificate.
>>
>> import your server's cert (or your ca's root cert) into TB
>>
>> Settings/Privacy&Security/ManageCertificates
>
> There is no ca.

So just import the self-signed cert and tell TB that you trust it

Or if it refuses that, make yourself a mini-ca using openSSL and create
a new cert for your dovecot that way?

Re: How to add an exception in Thunderbird for a private certificate?

<r1k36kxkvj.ln2@Telcontar.valinor>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2509&group=alt.comp.software.thunderbird#2509

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
Date: Fri, 29 Dec 2023 20:42:19 +0100
Lines: 87
Message-ID: <r1k36kxkvj.ln2@Telcontar.valinor>
References: <h5u26kxkok.ln2@Telcontar.valinor>
<kv80b2Fca4mU1@mid.individual.net> <p1136kxhjo.ln2@Telcontar.valinor>
<kv84c3Fca4mU5@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
X-Trace: individual.net nRmA6IxlvqrnKUw8d7znzQdP532fFf3Gc67NReirBKbgwc2fTO
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:owOSzGPIkDMjiYBd5c0U7Ov3W7A= sha256:Eg6oPgJPkykFKctPvzRI1SqKn7rV4lD1cpxMuwnjqW4=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <kv84c3Fca4mU5@mid.individual.net>
 by: Carlos E.R. - Fri, 29 Dec 2023 19:42 UTC

On 2023-12-29 15:45, Andy Burns wrote:
> Carlos E.R. wrote:
>
>> Andy Burns wrote:
>>
>>> Carlos E.R. wrote:
>>>
>>>> TB is unable to retrieve mail on my LAN dovecot server which uses a
>>>> private certificate.
>>>
>>> import your server's cert (or your ca's root cert) into TB
>>>
>>> Settings/Privacy&Security/ManageCertificates
>>
>> There is no ca.
>
> So just import the self-signed cert and tell TB that you trust it

How? It doesn't prompt. See below.

>
> Or if it refuses that, make yourself a mini-ca using openSSL and create
> a new cert for your dovecot that way?

That is above my abilities.

I did a test.

I created a new TB profile, and as account I added only my own
dovecot/postfix. TB found them instantly and offered to add an
exception. I said yes and it worked, instantly.

But the main TB profile DOES NOT ASK!

So in the test profile I looked in file "cert_override.txt" where there
is a single line for my private certificate. I stopped the main TB,
copied that line there, then started the main TB. Still can not read
mail from dovecot. It says "checking server capabilities" for a long time.

And Settings/Manage Certificates does not show the line for the local
server that I just wrote. It is ignored. My guess is that it needs
adding the certificate to cert9.db.

So, is there a way to force TB to add an exception?

Following some advice, yesterday I tried to:

<https://unix.stackexchange.com/questions/123367/thunderbird-fails-to-connect-to-dovecot-and-postfix>

+++·····················
* in the problematic email acount in incoming mail server
settings I temporarily changed the address of the mail server,
* I created a new account with correct incoming mails server adress,
when receiving emails I accepted wtih no problem the certificate,
* I deleted the new account.
* and I restored the correct address of the incoming mail server
in the original account.
·····················++-

(on step 1, I had to restart TB. There is no way out).

Nah, doesn't work.

The "new" account only sees "INBOX" folder. Does not ask for certificate
exception, only for the user password.

The old one sees them all (maybe cached), sees the mails (probably
cached), but can read none. It gets stuck at "checking mail server
capabilities" for a long time. Oh, it gave up silently without reading
the message.

--
Cheers, Carlos.

Re: How to add an exception in Thunderbird for a private certificate?

<kv8o9qFg7k5U2@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2510&group=alt.comp.software.thunderbird#2510

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@andyburns.uk (Andy Burns)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
Date: Fri, 29 Dec 2023 20:25:26 +0000
Lines: 26
Message-ID: <kv8o9qFg7k5U2@mid.individual.net>
References: <h5u26kxkok.ln2@Telcontar.valinor>
<kv80b2Fca4mU1@mid.individual.net> <p1136kxhjo.ln2@Telcontar.valinor>
<kv84c3Fca4mU5@mid.individual.net> <r1k36kxkvj.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 6fjWqhdNRlH+5K0D96iXyg5bPFcGQwggwlsy5tuoeutZb/vm+h
Cancel-Lock: sha1:EB6e+s1kuU/gMFmhvMf/rC8+dFg= sha256:RfqAjIxJERqztfq4hExICztpuj6s7xxmbtAFS2mSbcE=
User-Agent: Mozilla Thunderbird
Content-Language: en-GB
In-Reply-To: <r1k36kxkvj.ln2@Telcontar.valinor>
 by: Andy Burns - Fri, 29 Dec 2023 20:25 UTC

Carlos E.R. wrote:

> On 2023-12-29 15:45, Andy Burns wrote:
>> Carlos E.R. wrote:
>>
>>> Andy Burns wrote:
>>>
>>>> Carlos E.R. wrote:
>>>>
>>>>> TB is unable to retrieve mail on my LAN dovecot server which uses a
>>>>> private certificate.
>>>>
>>>> import your server's cert (or your ca's root cert) into TB
>>>>
>>>> Settings/Privacy&Security/ManageCertificates
>>>
>>> There is no ca.
>>
>> So just import the self-signed cert and tell TB that you trust it
>
> How? It doesn't prompt. See below.

go into settings, certificates as I said above, and there is an import
button on the servers tab ...

Re: How to add an exception in Thunderbird for a private certificate?

<ifo36kxqcp.ln2@Telcontar.valinor>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2511&group=alt.comp.software.thunderbird#2511

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
Date: Fri, 29 Dec 2023 21:57:54 +0100
Lines: 97
Message-ID: <ifo36kxqcp.ln2@Telcontar.valinor>
References: <h5u26kxkok.ln2@Telcontar.valinor>
<kv80b2Fca4mU1@mid.individual.net> <p1136kxhjo.ln2@Telcontar.valinor>
<kv84c3Fca4mU5@mid.individual.net> <r1k36kxkvj.ln2@Telcontar.valinor>
<kv8o9qFg7k5U2@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net HjcgSB89syISYm2TkwZArgdtkZxPLMtrXExHP9CrvuUk3xyQXE
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:VoIAS7SmvYu/1v93+8RS9lAR5JU= sha256:36PQjfJ8ztoPu8d3I6ssnqBIt/xGoZzoGxkxFB6HAhc=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <kv8o9qFg7k5U2@mid.individual.net>
 by: Carlos E.R. - Fri, 29 Dec 2023 20:57 UTC

On 2023-12-29 21:25, Andy Burns wrote:
> Carlos E.R. wrote:
>
>> On 2023-12-29 15:45, Andy Burns wrote:
>>> Carlos E.R. wrote:
>>>
>>>> Andy Burns wrote:
>>>>
>>>>> Carlos E.R. wrote:
>>>>>
>>>>>> TB is unable to retrieve mail on my LAN dovecot server which uses
>>>>>> a private certificate.
>>>>>
>>>>> import your server's cert (or your ca's root cert) into TB
>>>>>
>>>>> Settings/Privacy&Security/ManageCertificates
>>>>
>>>> There is no ca.
>>>
>>> So just import the self-signed cert and tell TB that you trust it
>>
>> How? It doesn't prompt. See below.
>
> go into settings, certificates as I said above, and there is an import
> button on the servers tab ...

What button?

Import certificate? Doesn't work. It demands an https:// address. What
do I put there, my local machine? Doesn't respond on https. I would have
to put the certificate on some reachable path, before TB can download it.

TB. Settings. Search for "cert".

Certificates
When a server requests my personal certificate:
( ) Select one automatically (*) Ask me every time

[*] Query OCSP responder servers to confirm the current validity of
certificates

[Manage Certificates]. Click.

Servers tab. There is an [Add Exception]. Click.

Location: [https:// ]

[Get Certificate] Grayed out, does not respond.

What now?

I fill: Location: [https://telcontar.valinor ]

Now click on [Get Certificate]

Responds:

No information Available
Unable to obtain information status for this site.

Telcontar:~ # ls -ltr /var/log/apache2/
total 2136
-rw-r--r-- 1 root root 10 Jun 7 2013 rcapache2.out
-rw-r--r-- 1 root root 782632 Dec 20 22:18 error_log
-rw-r--r-- 1 root root 1386721 Dec 29 20:04 access_log
Telcontar:~ #

Telcontar:~ # tail /var/log/apache2/access_log
....
192.168.1.14 - - [28/Dec/2023:20:57:09 +0100] "GET
/.well-known/autoconfig/mail/config-v1.1.xml?emailaddress=yo%40telcontar.valinor
HTTP/1.1" 404 1009 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:115.0)
Gecko/20100101 Thunderbird/115.5.0"
127.0.0.1 - - [29/Dec/2023:20:04:53 +0100] "GET
/.well-known/autoconfig/mail/config-v1.1.xml?emailaddress=cer%40telcontar.valinor
HTTP/1.1" 404 1009 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:115.0)
Gecko/20100101 Thunderbird/115.5.0"

I would have to setup some path on https on my simple internal apache
server, which currently does not do https, and no intention to, just to
be able to allow TB to import some certificate?

REALLY?

--
Cheers, Carlos.

Re: How to add an exception in Thunderbird for a private certificate?

<kv8tasFg7k5U5@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2514&group=alt.comp.software.thunderbird#2514

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@andyburns.uk (Andy Burns)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
Date: Fri, 29 Dec 2023 21:51:20 +0000
Lines: 14
Message-ID: <kv8tasFg7k5U5@mid.individual.net>
References: <h5u26kxkok.ln2@Telcontar.valinor>
<kv80b2Fca4mU1@mid.individual.net> <p1136kxhjo.ln2@Telcontar.valinor>
<kv84c3Fca4mU5@mid.individual.net> <r1k36kxkvj.ln2@Telcontar.valinor>
<kv8o9qFg7k5U2@mid.individual.net> <ifo36kxqcp.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net U+zMe2QyTWRLDbXViE8h+Qe3Gh0hqlyadITZ+GhvtY0Ot+YG8l
Cancel-Lock: sha1:bGwXoFhSWvKMsxztj1QQq31pu7I= sha256:BWVRs3Olr+ULHNiGvnpXDRYLDTF2Wu+eYhtww+iZaKI=
User-Agent: Mozilla Thunderbird
Content-Language: en-GB
In-Reply-To: <ifo36kxqcp.ln2@Telcontar.valinor>
 by: Andy Burns - Fri, 29 Dec 2023 21:51 UTC

Carlos E.R. wrote:

> What now?

ok, so you probably do need to setup your own mini-ca, to issue your own
cert to dovecot, it's pretty simple in a DOS windows for openSSL

then you can import your ca's root cert in the TB authorities tab, then
your mail server cert is trusted, because the ca is trusted.

https://jamielinux.com/docs/openssl-certificate-authority/

Re: How to add an exception in Thunderbird for a private certificate? [SOLVED]

<16i56kxdv4.ln2@Telcontar.valinor>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2527&group=alt.comp.software.thunderbird#2527

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!news.samoylyk.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
[SOLVED]
Date: Sat, 30 Dec 2023 14:22:41 +0100
Lines: 49
Message-ID: <16i56kxdv4.ln2@Telcontar.valinor>
References: <h5u26kxkok.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
X-Trace: individual.net bkG5XgquduUtv5Yi9iE2YgkWq8QDmt69xQ7SLnxhR0t0j3d85Q
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:uvA4LiLY61xNcyKgJEMk9WYTAV4= sha256:Sl8tWXgZ3RFPhejV+/CLGT2PwMBJjPa/LhDPwOuM6H4=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <h5u26kxkok.ln2@Telcontar.valinor>
 by: Carlos E.R. - Sat, 30 Dec 2023 13:22 UTC

On 2023-12-29 14:28, Carlos E.R. wrote:
> Hi,
>
> I am on TB 115.5.0 on Linux. Since some recent update TB is unable to
> retrieve mail on my LAN dovecot server which uses a private certificate.
>
> Notice that I can not use a public certificate, because I don't have a
> public domain. My domain name is faked.
>
>
> I had notes from previous occurrences:
>
>
> +++···························
>
> Thunderbird (2023-07-02):
>
....
> Regenerate certificates.
>
> cd /etc/dovecot
> rm /etc/ssl/private/dovecot.pem
> rm /etc/ssl/private/dovecot.crt
> bash mkcert.sh
> time openssl dhparam -out /etc/dovecot/dh.pem 4096
>
> Delete certificate in Thunderbird (settings, search for "cert"), Manage
> Certificates, Servers tab.
> Then "Get messages / "cer", authorize cert.
> ···························++-
>
>
> Problem is, Thunderbird just can't read the emails, and never prompts
> about the certificate, so it is impossible to create an exception. TB
> just keeps silent (checking server capabilities).
>
>
>
> Is there a way to force TB to just accept the certificate and get along?

Found the trick (actually Andrei Borzenkov found it).

Click on the INBOX folder. Then click on the "GET Messages" icon, which
is a tiny cloud icon at the top left of the left hand panel. Then, and
only then, TB asks about the certificate and offers to make an exception.

--
Cheers, Carlos.

Re: How to add an exception in Thunderbird for a private certificate? [SOLVED]

<jkp86kxs1n.ln2@Telcontar.valinor>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=2535&group=alt.comp.software.thunderbird#2535

  copy link   Newsgroups: alt.comp.software.thunderbird
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: robin_listas@es.invalid (Carlos E.R.)
Newsgroups: alt.comp.software.thunderbird
Subject: Re: How to add an exception in Thunderbird for a private certificate?
[SOLVED]
Date: Sun, 31 Dec 2023 19:48:19 +0100
Lines: 28
Message-ID: <jkp86kxs1n.ln2@Telcontar.valinor>
References: <h5u26kxkok.ln2@Telcontar.valinor>
<16i56kxdv4.ln2@Telcontar.valinor>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net i7bScTwfq3WjHu9FGZr4/w69b8LXH9LhvaXbuhASrTDuvWQynl
X-Orig-Path: Telcontar.valinor!not-for-mail
Cancel-Lock: sha1:HH+pYwidgLf9taby65QFtE3xKIQ= sha256:LDkgVqDqv5Q0vAZxJzyGn2XAgYgzgZQ0PLvuiX2+cKo=
User-Agent: Mozilla Thunderbird
Content-Language: es-ES, en-CA
In-Reply-To: <16i56kxdv4.ln2@Telcontar.valinor>
 by: Carlos E.R. - Sun, 31 Dec 2023 18:48 UTC

On 2023-12-30 14:22, Carlos E.R. wrote:
> On 2023-12-29 14:28, Carlos E.R. wrote:
>> Hi,

....

>> Is there a way to force TB to just accept the certificate and get along?
>
> Found the trick (actually Andrei Borzenkov found it).
>
> Click on the INBOX folder. Then click on the "GET Messages" icon, which
> is a tiny cloud icon at the top left of the left hand panel. Then, and
> only then, TB asks about the certificate and offers to make an exception.
>

More information:

<https://bugzilla.mozilla.org/show_bug.cgi?id=1764770>

Comments 49..52 are quite interesting.

Some comments say that you have to click the get messages button several
times, it is random.

--
Cheers, Carlos.


computers / alt.comp.software.thunderbird / How to add an exception in Thunderbird for a private certificate?

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor