After upgrade to v38.1.0 cannot get emails (using self-signed SSL certificates with 512bit keys ) because of Logjam/weak Diffie-Hellman key mitigation
Categories
(Thunderbird :: Security, defect)
Tracking
(Not tracked)
People
(Reporter: jimoe, Unassigned)
References
()
Details
(Keywords: regression, Whiteboard: [regression:TB38][support])
Updated•10 years ago
|
Updated•10 years ago
|
Comment 7•10 years ago
|
||
Comment 8•10 years ago
|
||
Comment 9•10 years ago
|
||
| Reporter | ||
Comment 10•10 years ago
|
||
Comment 11•10 years ago
|
||
Comment 12•10 years ago
|
||
Comment 13•7 years ago
|
||
Comment 14•7 years ago
|
||
Comment 15•7 years ago
|
||
Updated•7 years ago
|
Comment 16•6 years ago
|
||
We have two issues.
First, we lack proper UI reporting if SSL/TLS connections go wrong. We should improve that. That should be handled in bug 1187797.
Second, the inability to allow connections to certain servers. This is decided by the maintainers of the NSS security library, who maintain the implementation of the SSL/TLS protocol that Thunderbird uses. From my past experience working with them, they usually make reasonable decisions, to achieve compromises between backwards compatibility, and avoiding new security issues.
If the NSS maintainers decide that a certain type of connection shall no longer be permissible, then Thunderbird should follow that decision. The correct solution is then for server operators to fix their server configuration, which usually is possible without much trouble.
Again, the important part is bug 1187797, in order to allow users to identify the reason for failures, and get server admins to perform the required security hardening.
So, I'd like to mark this bug as wontfix, because we are unable to allow overriding of connections to servers with insecure settings.
Description
•