Re: 6.4.1 won't fetch mail from gmail; 6.3.26 does - root CA's signing certificate is not in the trusted CA certificate location
Matthias Andree <[email protected]>
| Newsgroups | gmane.mail.fetchmail.user |
|---|---|
| Message-ID | <[email protected]> |
Am 02.10.19 um 13:30 schrieb [email protected]: > 'fetchmail -v or fetchmail -v -v should show the issuer and subject common names' > > Hmmm... I log only the cert gmail issues. It sez depth 2, but > both certs are in the gmail cert, which isn't hashed because there are > multiple certs in 1 file. I hash the certs in /etc/ssl/certs by hand. This looks like a successful connect. And now? > fetchmail: 6.4.1 querying pop.gmail.com (protocol POP3) at Tue 01 Oct 2019 07:54:03 PM MDT: poll started > fetchmail: Trying to connect to 123.45.67.890/995...connected. > fetchmail: SSL verify callback depth 2: preverify_ok == 1, err = 0, ok > fetchmail: Certificate chain, from root to peer, starting at depth 2: > fetchmail: Issuer Organization: GlobalSign > fetchmail: Issuer CommonName: GlobalSign > fetchmail: Subject CommonName: GlobalSign > fetchmail: SSL verify callback depth 1: preverify_ok == 1, err = 0, ok > fetchmail: Certificate at depth 1: > fetchmail: Issuer Organization: GlobalSign > fetchmail: Issuer CommonName: GlobalSign > fetchmail: Subject CommonName: GTS CA 1O1 > fetchmail: SSL verify callback depth 0: preverify_ok == 1, err = 0, ok > fetchmail: Server certificate: > fetchmail: Issuer Organization: Google Trust Services > fetchmail: Issuer CommonName: GTS CA 1O1 > fetchmail: Subject CommonName: pop.gmail.com > fetchmail: Subject Alternative Name: pop.gmail.com > fetchmail: pop.gmail.com key fingerprint: redacted > fetchmail: pop.gmail.com fingerprints match. > fetchmail: SSL/TLS: using protocol TLSv1.3, cipher TLS_AES_256_GCM_SHA384, 256/256 secret/processed bits > fetchmail: POP3< +OK Gpop ready for requests from 123.45.67.890 x19mb40915764ocd