Account Setup shows multiple Invalid SSL Cert warnings for email domain (different from configured mail server)
Categories
(Thunderbird :: Account Manager, defect)
Tracking
(Not tracked)
People
(Reporter: kevin, Unassigned)
References
(Regression)
Details
(Keywords: regression)
Attachments
(1 file)
|
4.32 KB,
application/x-yaml
|
Details |
With Thunderbird Daily build 20221003095526, after completing the Account Setup wizard for an email address where the domain in the email address does not have a valid SSL certificate (but the configured mail server does) multiple (1, then 6 more in my tests) "Add Security Exception" for invalid SSL certificate dialog boxes are shown for the email domain. Steps to reproduce:
- Start Thunderbird using a new profile.
- Enter an email address where the domain does not have a valid SSL certificate. (I used klocke@bookanomic.com with IMAP server mail.kevinlocke.name)
- Press Done. Observe the "Add Security Exception" dialog box appears for the email domain (bookanomic.com in my test).
- Press Cancel. Observe 6 more "Add Security Exception" dialog boxes appear for the email domain (bookanomic.com in my test).
I bisected the issue to pushlog https://hg.mozilla.org/comm-central/pushloghtml?fromchange=4998d4d1b4f8e39f5d3e6b9f6abcb0dbef305c94&tochange=e482bbf11ffd77fe33b6a6ece87056bd5f5a1f6d suggesting it was regressed by Bug 1769493.
The improvements planned in Bug 1744319 may be related or relevant to this issue.
| Reporter | ||
Updated•4 years ago
|
Comment 1•4 years ago
|
||
If I cancel in when the dialog appears in step 3, I don't get any further dialogs.
| Reporter | ||
Comment 2•3 years ago
|
||
(In reply to Magnus Melin [:mkmelin] from comment #1)
If I cancel in when the dialog appears in step 3, I don't get any further dialogs.
I can confirm the additional 6 dialogs appear on Windows in addition to my original testing on Linux. Any ideas what mioght be causing the difference or how I could help you reproduce the behavior? Would you like me to create an IMAP account on bookanomic.com for you to test? If so, how can I send you the credentials.
Comment 3•3 years ago
|
||
Obviously I didn't have a password, so just left that blank. Can you confirm with that?
If still needed, please send me test account details to mkmelin at thunderbird.net
| Reporter | ||
Comment 4•3 years ago
|
||
(In reply to Magnus Melin [:mkmelin] from comment #3)
Obviously I didn't have a password, so just left that blank. Can you confirm with that?
Good thought. I'm able to reproduce the issue by completing Account Setup with a blank password using the following information:
| Field | Value |
|---|---|
| Your full name | Test |
| Email address | test@bookanomic.com |
| Password | |
| Protocol | IMAP |
| Hostname | mail.kevinlocke.name |
| Port | 143 |
| Connection security | STARTTLS |
| Authentication method | Normal password |
| Username | test |
Let me know if there's anything else I can do to help reproduce the issue, or more information I can provide.
| Reporter | ||
Comment 5•3 years ago
|
||
Thanks for mentioning Bug 1792470, I missed that one. For what it's worth, the server I'm using for testing (mail.kevinlocke.name/bookanomic.com) is running Radicale too.
Comment 6•3 years ago
|
||
Tried it again with the steps from comment 4. I only got one dialog, accepted the exception and everything seemed to work as it should.
Comment 7•3 years ago
|
||
Possible interference from firewall / antivirus?
| Reporter | ||
Comment 8•3 years ago
|
||
Apologies for my slow reply.
(In reply to Magnus Melin [:mkmelin] from comment #6)
Tried it again with the steps from comment 4. I only got one dialog, accepted the exception and everything seemed to work as it should.
Can you confirm that you declined the security exception (i.e. pressed "Cancel"), rather than accepted (i.e. pressed "Confirm Security Exception") in step 4 from comment 4? I do not see additional dialogs after accepting the exception, only after declining.
Also, to be clear, I think a single security exception prompt for a domain the user did not configure is also a bug, although I can understand the rationale. Let me know it would be worth opening a separate bug for that issue.
(In reply to Magnus Melin [:mkmelin] from comment #7)
Possible interference from firewall / antivirus?
I think that is unlikely, since I've been able to reproduce the issue on multiple hosts with different OSes in different environments without any third-party antivirus or firewall products.
Given the apparent difficulty of reproducing this issue, I'm attaching the Ansible playbook I've used to reproduce the issue on a fresh Debian Bullseye (11.5) host. If you'd like access to the host to investigate, please send me an SSH public key (e.g. via email to kevin@kevinlocke.name).
Comment 9•3 years ago
•
|
||
If I press Cancel, then I at least now get multiple dialogs yes.
I guess the first one is for mail, but the other ones for calendar and address book (which may not have been detected prior to bug 1769493)?
| Reporter | ||
Comment 10•3 years ago
|
||
(In reply to Magnus Melin [:mkmelin] from comment #9)
I guess the first one is for mail, but the other ones for calendar and address book (which may not have been detected prior to bug 1769493)?
CalDAV and CardDAV detection makes sense to me. Perhaps there are 6 because 3 attempts are made for each? I don't understand why TB would attempt to connect to a server other than the configured incoming and outgoing servers for mail though.
Comment 11•1 month ago
|
||
Still reproducible on Thunderbird 153.0.2 (aarch64), macOS 26.6.1, brand-new profile (fresh OS user account, Thunderbird profile deleted between tests) — three years after this was filed.
Same signature: multi-domain mail host serving per-domain Let's Encrypt certificates via SNI. Account setup for user@<domain> raises an "Add Security Exception" dialog showing a certificate for a different hosted domain than the configured mail server. Cancelling the dialog leaves a fully working account — send and receive both function — because the live connections send SNI and validate correctly. Only the setup-time certificate check trips.
Server environment: AlmaLinux 9, Plesk Obsidian, Dovecot 2.4.4, Postfix 3.5.25, all current. The server is correctly configured and returns the right per-domain certificate whenever the client sends SNI; the issue is entirely in the client's setup-time certificate check.
The certificate shown in the dialog is the server's default (no-SNI) certificate. Verified with openssl from the same Mac that Thunderbird runs on:
$ openssl s_client -connect mail.<domain>:995 -servername mail.<domain> | openssl x509 -noout -subject
subject=CN=<domain> # correct per-domain cert, WITH SNI (993 and 465 return the same correct cert)
$ openssl s_client -connect mail.<domain>:465 | openssl x509 -noout -subject
subject=CN=<server-default> # server default cert, NO SNI — exactly the certificate the dialog objects to
The account-setup certificate check appears to omit the SNI server_name extension (or to query the bare email domain rather than the configured server host), so it receives the default certificate and reports a mismatch. Occurs in both automatic and manual configuration.
Client environment is fully current (macOS 26.6.1, Apple Silicon), so this is not an old-platform artifact — the no-SNI setup-time cert fetch persists on the latest release. Confirming the regression from bug 1769493 is still present.
Comment 12•1 month ago
|
||
FOLLOWUP:
Concrete hostnames for the openssl evidence above — reproducible against my live server:
$ openssl s_client -connect mail.piperhosting.net:995 -servername mail.piperhosting.net | openssl x509 -noout -subject
subject=CN=piperhosting.net # correct per-domain cert, WITH SNI (993 and 465 return the same correct cert)
$ openssl s_client -connect mail.piperhosting.net:465 | openssl x509 -noout -subject
subject=CN=piperhosting.org # server default cert, NO SNI — exactly the certificate the dialog objects to
Both hostnames are publicly reachable, so a client pointed at mail.piperhosting.net will show the WITH-SNI vs NO-SNI certificate difference directly.
Description
•