Open Bug 378004 Opened 19 years ago Updated 3 years ago

Thunderbird describes mail server certificates as "Web site" certificates

Categories

(Thunderbird :: Security, defect)

defect

Tracking

(Not tracked)

People

(Reporter: iane, Unassigned)

References

Details

(Whiteboard: [psm-cert-errors])

User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3 Build Identifier: version 2.0.0.0 (20070326) Preferences...Advanced...Certificates...View Certificates...Web Sites Thunderbird is describing mail server, and ldap server certificates as "web site" certificates. Similarly, when errors are found in certificates, Thunderbird pops up error dialogs with titles like " Reproducible: Sometimes Steps to Reproduce: 1. Set up an account pointing to a mail server with an unverifiable certificate. Eg, mail.susx.ac.uk, port 143, TLSv1 2. Read the dialog message carefully. 3. I've seen three different error messages, the more detailed messages refer to web servers. Actual Results: Dialogs refer to web servers Expected Results: Dialogs refer to email servers, or just "servers"
xref 333149
Confirming that, in Thunderbird 2.0.0.21 (20090409), I see "your *browser* will trust...." etc. messages when adding/removing a cert.
Kaie are those strings in PSM ?
OS: Mac OS X → All
Hardware: PowerPC → All
Status: UNCONFIRMED → NEW
Ever confirmed: true
This bug was originally reported for TB 2.0 I believe most SSL error messages should have changed in TB 3. Bug 531569 refers to TB 3 and claims to talk about "web" sites. However, I don't see the term "web" shown anywhere in the screenshot. I agree that mentioning "banks" may not be a perfect fit when talking about a mail server, but that UI is a general purpose UI, and a specific solution for mail servers hasn't been produced.
Yes, our cert exception handling is still focused on web sites, very unfortunately. We need something separate for all the non-https protocols.
Whiteboard: [psm-cert-errors]
See Also: → 177688
If we're going to call 436318 a duplicate, then please note that the fix must address the workflow issues described therein (users needing to enter https://a1.postal.mail.dreamhost.com:995 instead of pop3s://a1.postal.mail.dreamhost.com to retrieve a certificate). If this is fixed with some simple changes to strings but the workflow remains the same, please re-open 436318.
It's also worth mentioning that bug 436318 requests 'a checkbox for "Use STARTTLS"' as a possibly superior workflow for certain mail server certificates (though that would not address the LDAP certificate exceptions). It might be worth reopening something specific for that, as well. But as this bug enters its ninth year, I have no confidence that the bugfix will happen before the Mozilla foundation folds.
Assignee: dveditz → nobody
Severity: normal → minor
Severity: minor → S4
You need to log in before you can comment on or make changes to this bug.