TLS v1.3 - Gnus and GnuTLS - Client resets connection

Chris Marusich <[email protected]>
Newsgroups gmane.emacs.gnus.general,gmane.network.gnutls.general
Message-ID <[email protected]>
Hi,

I just installed Ubuntu 19.04 fresh onto a machine.  Using Emacs (both
version 26.1 installed via apt, and also version 26.2 installed via
Guix) and Gnus configs that worked on a previous system, I tried setting
up nnimap for Gmail using TLS, but gnus failed to connect to
imap.gmail.com.  The *Messages* output was:

--8<---------------cut here---------------start------------->8---
Opening connection to imap.gmail.com via tls...
Unable to open server nnimap+gmail due to: Process *nnimap* not running
nnimap (gmail) open error: ‘’.  Continue? (y or n) n
Couldn’t open server on gmail
Warning: Unable to open server nnimap+gmail due to: Process *nnimap* not running
--8<---------------cut here---------------end--------------->8---

I also captured the following packets using Wireshark:


It seems the client aborted the connection by sending an RST packet to
the server.

I found two ways to fix the problem.  One way is to set gnutls-log-level
to 1 (or higher).  The other is to set gnutls-algorithm-priority to
"NORMAL:-VERS-TLS1.3".

If you set gnutls-log-level to 1, you get some interesting output, but
unfortunately none of it describes the problem, since the problem
doesn't occur!  It's surprising that increasing the log level solves the
problem.

If you set gnutls-algorithm-priority to "NORMAL:-VERS-TLS1.3", my
understanding is that you are telling GnuTLS you don't want to use
version 1.3, and then (in my case) Gnus will connect successfully to
imap.gmail.com using TLS v1.2.  I verified that using Wireshark.

This feels similar (but maybe not identical) to the following issue:

http://emacs.1067599.n8.nabble.com/Emacs-gnus-tls-IMAP-connection-problems-with-Google-tp474191p475443.html

There, the author encountered a problem that prevented them from
connecting to a website using TLS v1.3.  They resolved it by setting
gnutls-algorithm-priority like I did, but they were not using Gnus.
Earlier in the same thread, another person reported the exact same issue
as me: they couldn't connect to imap.gmail.com using Gnus, and they also
discovered that the problem went away when they set gnutls-log-level to
2.

Separately, I've also heard that when GnuTLS added support for TLS v1.3,
they made some changes that require callers to change the way they call
GnuTLS.  For example, consider this:

https://nikmav.blogspot.com/2018/05/gnutls-and-tls-13.html

"Post handshake authentication

[...] In GnuTLS the implementation relies on a new non-fatal error code
which must be handled by the client application. [...]"

I don't know if post handshake authentication has anything to do with
the error I saw (I have no reason to believe that it does), but I
mention this because it makes me wonder if perhaps Gnus needs to be
updated to play nicely with GnuTLS' implementation of TLS v1.3.

Another possibility is that Gmail's IMAP server is misbehaving, but I
don't know if the evidence supports that conclusion at this time.

Thoughts?  I'm glad I have a work-around, but if there's anything I can
do to help resolve the actual problem, please let me know.

-- 
Chris
unable-to-connect.jpg (image/jpeg, 62.8 KB) - not displayed
signature.asc (application/pgp-signature, 832 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEy/WXVcvn5+/vGD+x3UCaFdgiRp0FAl1L4o4ACgkQ3UCaFdgi
Rp1zNRAAxffKsxqfN1359i/yq1rN1y7UsNKTMkd71Iml9d025xNzWAuN8zP+DtV9
h6nk0pVvUXlkYPAhuch4PJIGMlbXrEKsc7S+03Xyt/sdqQi1lz/vLve5r66t5JZU
sHm4HyMij74fwGvtKAgu+aftmxpg2uXYKqX10v9Lfb61gNxQyruTMbeePCdMzalO
TmlR6fbUJbhq2qkHmHmo13UwOmaxOCepSMoHeCFpSkB32PNg3psnqoU+q0zqiizt
wTIsABkdSfccd05ttdKGpb6DKPI/FzSm1CXUwAKlB7FH545p/M/qjpadiwKDrOac
ziZa0gaQg0c3fhEfUIUBk3mNusd6gx/EPdhWTX3U1VxJelQM/HIGVhovM5Bjvmzc
mWkujTzUUs1UoYOLd+2U5ftpGgAlsc1qKJXpql+puvn8tV9geAnI6OKlZoJpLl1u
EvTo8PJnN10IOVeSlWjD257/yTvCzSIpZnMkO2pR4gx1xcV9vR6m8Mz3A1mcw1FQ
7NkYgh+YUiMBdyBaLdtljezenq02iqOnw0LDLM9y1JM29i+EVLwjtSb31+2Lha+G
SxZJStFZfJYAdaCfUjmjoeEa0BArUNejoZE+zXLb1HT+KChaWV5qpgVP/PifKGAM
vrJWZsnKa/7e/cvn6+dxbApDSWnl3c9RMXqEk0FHBW49YJviDeA=
=1xOK
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.