Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: Mutt: failure to check server certificate in SMTP TLS connection
From: dave b <db.pub.mail () gmail com>
Date: Wed, 16 Mar 2011 23:11:40 +1100

On 9 March 2011 16:41, Tim <tim-security () sentinelchicken org> wrote:
As port 587 is for port for TLS/STARTTLS and port 465 is for ssl if I
am not mistaken.

Please do point out if I have gotten this completely incorrect.

Nope, you're right, it looks like I got the two mixed up.
Good catch on the lack of certificate validation.

It also turns out that I didn't test this issue enough. As I didn't
test with both gnutls and openssl. I only tested with gnutls. Mutt
actually works as I would expect with imaps, smtps and smtp -- with
starttls connection when using openssl. mutt appears to  be _broken_
when using gnutls for imaps, smtps and smtp -- with starttls. (on mutt 1.5.20).

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]