Bug#1143142: sendmail-bin: STARTTLS doesn't send all the certs in a certificate chain file [PATCH]
David Caldwell <[email protected]> Thu, 30 Jul 2026 14:48:03 -0700
| Newsgroups | gmane.linux.debian.qa-packages |
|---|---|
| Message-ID | <f4ec9573-9249-40d4-aa5c-c2cd6d856e57__43993.503337127$1785448175$gmane$org@porkrind.org> |
This is a multi-part message in MIME format. --------------pm0XFS8nZpEW24N35tTI0CUT Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Package: sendmail-bin Version: 8.18.2-2 Severity: normal Tags: patch Dear Maintainer, I was having certificate failures when sending mail to a sendmail submission server and traced the issue down to sendmail not sending the entire cert chain. The reason is that it uses SSL_CTX_use_certificate_file() to read the file and not SSL_CTX_use_certificate_chain_file(). Poking around the sendmail source I noticed that this was gated behind the _FFR_TLS_USE_CERTIFICATE_CHAIN_FILE define. I made a patch to debian/configure.ac to add that, rebuilt the package, and verified that it now sends the whole cert chain. I've attached the patch. I think it's an important feature--nowadays most "real" SSL certs have intermediates in them, especially in the LetsEncrypt/ACME space, and sendmail will not produce a validating cert chain unless this option is enabled. Thanks, David -- System Information: Debian Release: forky/sid APT prefers testing APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 6.17.13+deb14-amd64 (SMP w/8 CPU threads; PREEMPT) Kernel taint flags: TAINT_FIRMWARE_WORKAROUND Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages sendmail-bin depends on: ii debconf 1.5.92 ii libc6 2.42-17 ii libdb5.3t64 5.3.28+dfsg2-11+b1 ii libldap2 2.6.13+dfsg-1 ii liblockfile1 1.17-2+b2 ii libnsl3 2.0.1-2 ii libsasl2-2 2.1.28+dfsg1-11 ii libssl3t64 3.6.3-1 ii libwrap0 7.6.q-37 ii procps 2:4.0.6-2 ii sendmail-base 8.18.2-2 ii sendmail-cf 8.18.2-2 sendmail-bin recommends no packages. Versions of packages sendmail-bin suggests: ii libsasl2-modules 2.1.28+dfsg1-11 ii openssl 3.6.3-1 ii sasl2-bin 2.1.28+dfsg1-11 ii sendmail-doc 8.18.2-2 Versions of packages sensible-mda depends on: ii libc6 2.42-17 ii procmail 3.24+really3.22-6 Versions of packages rmail depends on: ii libc6 2.42-17 ii libldap2 2.6.13+dfsg-1 Versions of packages libmilter1.0.1 depends on: ii libc6 2.42-17 Versions of packages sendmail depends on: ii sendmail-base 8.18.2-2 ii sendmail-cf 8.18.2-2 ii sensible-mda 8.18.2-2 Versions of packages sendmail suggests: ii rmail 8.18.2-2 ii sendmail-doc 8.18.2-2 -- no debconf information --------------pm0XFS8nZpEW24N35tTI0CUT Content-Type: text/plain; charset=UTF-8; name="0001-Make-certificate-chains-work-in-TLS-with-a-FFR-flag-.patch" Content-Disposition: attachment; filename*0="0001-Make-certificate-chains-work-in-TLS-with-a-FFR-flag-.pa"; filename*1="tch" Content-Transfer-Encoding: base64 RnJvbSBmYzc0N2RlYmRiZWMyNDFjNzE5MjU3ZWQ0OTMwMDZiZWQ3YmRhN2JiIE1vbiBTZXAg MTcgMDA6MDA6MDAgMjAwMQpGcm9tOiBEYXZpZCBDYWxkd2VsbCA8ZGF2aWRAcG9ya3JpbmQu b3JnPgpEYXRlOiBUaHUsIDMwIEp1bCAyMDI2IDE0OjAwOjQ5IC0wNzAwClN1YmplY3Q6IFtQ QVRDSF0gTWFrZSBjZXJ0aWZpY2F0ZSBjaGFpbnMgd29yayBpbiBUTFMgd2l0aCBhICJGRlIi IGZsYWcgKCJGb3IKIEZ1dHVyZSBSZWxlYXNlIikKClNwZWNpZmljYWxseTogX0ZGUl9UTFNf VVNFX0NFUlRJRklDQVRFX0NIQUlOX0ZJTEUKV2l0aG91dCB0aGlzLCBTVEFSVFRMUyBvbmx5 IG9mZmVycyB1cCB0aGUgZmlyc3QgY2VydCBpbiB0aGUgZmlsZS4KLS0tCiBkZWJpYW4vY29u ZmlndXJlLmFjIHwgMiArKwogMSBmaWxlIGNoYW5nZWQsIDIgaW5zZXJ0aW9ucygrKQoKZGlm ZiAtLWdpdCBhL2RlYmlhbi9jb25maWd1cmUuYWMgYi9kZWJpYW4vY29uZmlndXJlLmFjCmlu ZGV4IDdhNzg4NTMuLjIyOTE5NWEgMTAwNjQ0Ci0tLSBhL2RlYmlhbi9jb25maWd1cmUuYWMK KysrIGIvZGViaWFuL2NvbmZpZ3VyZS5hYwpAQCAtMTQyOCw2ICsxNDI4LDggQEAgaWYgdGVz dCAkc21fZW5hYmxlX3RscyAhPSBubzsgdGhlbgogCQkJc21fc3VnZ2VzdHM9IiRzbV9zdWdn ZXN0cywgb3BlbnNzbCI7CiAJCQlzbV9zZW5kbWFpbF9lbnZkZWY9IiRzbV9zZW5kbWFpbF9l bnZkZWYgLURTVEFSVFRMUyI7CiAJCQlzbV9zZW5kbWFpbF9lbnZkZWY9IiRzbV9zZW5kbWFp bF9lbnZkZWYgLUREQU5FPTEiCisgICAgICAgICAgICAgICAgICAgICAgICAjIE1ha2UgVExT IHNlbmQgdGhlIHdob2xlIGNlcnQgY2hhaW4gaW5zdGVhZCBvZiB0aGUgdG9wbW9zdCBjZXJ0 IGluIGEgY2VydCBjaGFpbiBmaWxlLgorCQkJc21fc2VuZG1haWxfZW52ZGVmPSIkc21fc2Vu ZG1haWxfZW52ZGVmIC1EX0ZGUl9UTFNfVVNFX0NFUlRJRklDQVRFX0NIQUlOX0ZJTEU9MSIK IAkJCXNtX3NlbmRtYWlsX2xpYnM9IiRzbV9zZW5kbWFpbF9saWJzIC1sY3J5cHRvIC1sc3Ns IjsKIAkJCXNtX2Zmcj0iJHNtX2ZmciAtRF9GRlJfVExTX0VDIjsKIAllbGlmIHRlc3QgJHNt X2VuYWJsZV90bHMgPSBhdXRvOyB0aGVuCi0tIAoyLjUzLjAKCg== --------------pm0XFS8nZpEW24N35tTI0CUT--