Re: fetchmail and ssl certificates

Peter Pentchev <[email protected]>
Newsgroups gmane.mail.fetchmail.user
Message-ID <[email protected]>
On Thu, Jul 02, 2020 at 08:28:15AM -0500, Ranjan Maitra wrote:
> Hi,
> 
> Here is my .fetchmailrc
> 
> set daemon 301
> poll pop.gmx.com
>      protocol POP3
>      service 995
>      authenticate password
>      user "[email protected]"
>      ssl
>      sslfingerprint "5C:6B:60:FE:80:97:0B:13:EB:36:A3:66:48:28:7A:61:5E:B2:25:DA"
> mda 'procmail -d %s'
> keep
> 
> So, it worked fine till last night, but since this morning, this has not been working. Here is what I get:
> 
> $ fetchmail -c
> fetchmail: pop.gmx.com fingerprints do not match!
> fetchmail: OpenSSL reported: error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed
> fetchmail: pop.gmx.com: SSL connection failed.
> fetchmail: socket error while fetching from [email protected]@pop.gmx.com
> 
> 
> Here is how I verified my fingerprint:
> 
> ~$ openssl s_client -servername gmx.com -connect pop.gmx.com:995 | openssl x509 -fingerprint -noout
> depth=2 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root CA
> verify return:1
> depth=1 C = US, O = DigiCert Inc, OU = www.digicert.com, CN = GeoTrust RSA CA 2018
> verify return:1
> depth=0 C = DE, ST = Rheinland-Pfalz, L = Montabaur, O = 1&1 Mail & Media GmbH, CN = mout.gmx.com
> verify return:1
> SHA1 Fingerprint=5C:6B:60:FE:80:97:0B:13:EB:36:A3:66:48:28:7A:61:5E:B2:25:DA
> 
> Any suggestions as to what I am doing wrong?
> 
> I am on F32 (fully updated) which has fetchmail-6.4.1 and openssl-1:1.1.1g.

It seems that gmx.com have deployed the certificates for "mout.gmx.com"
on the services that listen for connections on the addresses for
"pop.gmx.com". The "CN = mout.gmx.com" part says "this certificate has
been issued to the mout.gmx.com server", and fetchmail is (rightly)
concerned about the hostname pop.gmx.com not being the same as that.

The real solution to the problem would be to let GMX know so that they
can deploy the correct certificate. A workaround so that you may fetch
your e-mail today would be to explicitly specify

  sslcommonname mout.gmx.com

...or something similar in your fetchmail configuration, so that it
knows to expect a certificate issued to a different host than the one it
thinks it's connecting to.

G'luck,
Peter

-- 
Peter Pentchev  [email protected] [email protected] [email protected]
PGP key:        http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint 2EE7 A7A5 17FC 124C F115  C354 651E EFB0 2527 DF13

_______________________________________________
Fetchmail-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/fetchmail-users
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEELuenpRf8EkzxFcNUZR7vsCUn3xMFAl7+KygACgkQZR7vsCUn
3xPbLBAAnG9twu0h52zHt8OSLcwn2aXP7W0vB3LJH1B4Bo4TKqLISMRyeukxQtk7
uM6pv+5NS1Y8oparY2WrzeBTUnQqz4WsNs7dFkzmX8U2Ojm4wwxwt6vNZyHuoisd
qlQqVQ38wdEgbqHIpCU7ADc7mkZ2BmJwohaBryC2NXleCau1YERYHQSjciEhnGtE
KyHr07XPOzwFDBo1DER1sbze+ynFiF+2Py0FPLeHdTz/CKbqyo9qMXVZvIWnOwB4
I9Qa1ZQGm91xQlN1Tmeo166Tnix6BRQ+cwQIYcRc8s1wo9hq+4Cd3HQ2JA1AGnLk
axufPyhVL49RjyJshERBcAxyS61SNvng5/wD9miIynnJi3uvNZHOV0qCaMLaKynh
0ue5CwnhQLbrpTT8lgVnLz36ob9iP0WA1wRWm8TiKDwe21OrqmaKYLXu4bu479Al
LNBO2fkW8cwed6vDADICxqxM1REFOzSVeBqYbK58dX8wYzPm/8zcXhblhOA6MLHC
GaoWm47mFE56Klhb71p8bwLNOo1oDC0clHVzSLJ2yv6Kmi1PiZup921trlke6a9/
2qNzLuf5xsZVg7pCee5sALhi9Dl3VTMZgs3DjfqOiDrtL2d75oWUv1XsrfAWWQ+E
B+IaSZg7DkSXiy9v4n3y9KYIShlmkfnGNqYvSx2jwIdtBY6pszg=
=KyFi
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.