Microsoft OAuth may fail with certain certificate setups in 102.7.1
Categories
(Thunderbird :: Security, defect)
Tracking
(Not tracked)
People
(Reporter: sancus, Unassigned)
References
(Blocks 1 open bug, Regression)
Details
(Keywords: regression)
Note: This bug DOES NOT occur on 103+, do not comment here if your bug occurs on those versions.
| Reporter | ||
Updated•3 years ago
|
| Reporter | ||
Updated•3 years ago
|
Just wondering... could this be related?
Thanks,
Mario
| Reporter | ||
Comment 2•3 years ago
•
|
||
(In reply to mabian69 from comment #1)
Just wondering... could this be related?
This is a regression caused by the fix for bug 1810760 in 102 only. We know the likely cause, it's the channel code that we had to hack in because 102 branch is too old to have a big fetch fix in Gecko versions 103+.
Using outlook.office365.com:995 with POP3 in a corporate "work" instance.
102.7.1 After startup, Thunderbird displays the Account Setup page. After filling in the credentials and selecting POP3, you get the "You are about to override how Thunderbird identifies this site." dialog. Confirming the security exception does nothing, "Get Certificate" returns "This site attempts to identify itself with invalid information"
110.0b3 (64-bit) has the same symptoms as 102.7.1
111.0a1 (2023-02-02) (64-bit) Daily authorizes correctly -- signs in with no problem. Entering the info on the Account Setup page, takes you to the Microsoft OAUTH dialog, where you enter your password, get redirected back to thunderbird, and you are signed in.
Andrei looked at my Certificate for outlook, and noticed that it had been modified by my Avast antivirus scanner. Using 102.7.1, and uninstalling Avast (and presumably it cleaned up its certificate messes), I was able to connect to outlook.office365.com and download messages.
| Reporter | ||
Comment 5•3 years ago
|
||
Yeah, incidentally, Avast has an article about how to fix this: https://support.avast.com/en-ww/article/91/#pc
That said, the MITM SSL scanning "feature" of antivirus is, IMO, a terrible idea that makes you vulnerable to things like Superfish since you are completely trusting the antivirus software with all of your traffic.
Closing this though, thanks for reporting!
Description
•