Re: ANN: getmail v. 5.9
Daniel Kahn Gillmor <[email protected]>
| Newsgroups | gmane.mail.getmail.user |
|---|---|
| Message-ID | <[email protected]> |
On Fri 2019-02-08 10:49:25 -0600, Charles Cazabon wrote: > No, because it's not supposed to be there :P Copy-paste error. I've removed > it from the online copy and regenerated the tarball (without bumping the > version) since it's still just a doc-only change. hm, ok, well the previous tarball was already uploaded to debian, and now won't match the distributed version. oh well. > There are a number of problems with this. The biggest one is that it will > cause connections to fail if the server name the user puts in their getmailrc > file resolves to the correct IP address but which the server does not consider > as (one of) its proper name(s). This happens a lot with servers having many > DNS aliases but which don't have valid SSL certificates installed for every > corresponding name. In this case, how is the client authenticating the server correctly anyway? surely the certificate failure would be causing a problem for them anyway, because the certificate wouldn't match the configured hostname. > So if I did this, getmail users with working configs that upgraded could > suddenly find themselves unable to retrieve mail, with no obvious cause as to > why. The benefits don't outweigh this risk. Can you give an example of a config that would be broken? It sounds like the current scenario is *also* breaking working configs with no obvious cause, so if we have a way that we could just fix it, that would be great. --dkg
signature.asc
(application/pgp-signature, 227 B)
-----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQTJDm02IAobkioVCed2GBllKa5f+AUCXF29IgAKCRB2GBllKa5f +BquAQD4RltEAvVivphnwNkon3IJCWFdnJtXSictNg3mQp6k5wEA8paQ5xgGJJf4 dgXErznnvLFnYdoyE9CEwpgyQ7oJYw4= =BPqS -----END PGP SIGNATURE-----