Re: TLS 1.3 and SNI; test script included
Charles Cazabon <[email protected]>
| Newsgroups | gmane.mail.getmail.user |
|---|---|
| Message-ID | <[email protected]> |
Matthias Andree <[email protected]> wrote: > Am 09.02.19 um 05:10 schrieb Charles Cazabon: > > Going from not supplying SNI at all to supplying SNI by default could > > break > > things regardless of whether certificate checking is in use or not; that's > > what I'm worried about. > > I know that at least two major several distributors have added SNI to > /fetchmail/ *unconditionally*, among them Fedora and FreeBSD. And you've heard no reports of regressions. That's a very interesting datapoint, Matthias - thanks. I've already figured out how to monkeypatch SNI into the Python stdlib imaplib module, so it's possible for me to make getmail supply it when the system Python and OpenSSL support TLS1.3 and SNI. I really would like to see some reports of people running my test script, but your info above is really valuable. Thanks again. Charles -- ----------------------------------------------------------------------- Charles Cazabon GPL'ed software available at: http://pyropus.ca/software/ -----------------------------------------------------------------------