Open
Bug 378004
Opened 19 years ago
Updated 3 years ago
Thunderbird describes mail server certificates as "Web site" certificates
Categories
(Thunderbird :: Security, defect)
Thunderbird
Security
Tracking
(Not tracked)
NEW
People
(Reporter: iane, Unassigned)
References
Details
(Whiteboard: [psm-cert-errors])
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
Build Identifier: version 2.0.0.0 (20070326)
Preferences...Advanced...Certificates...View Certificates...Web Sites
Thunderbird is describing mail server, and ldap server certificates as "web site" certificates. Similarly, when errors are found in certificates, Thunderbird pops up error dialogs with titles like "
Reproducible: Sometimes
Steps to Reproduce:
1. Set up an account pointing to a mail server with an unverifiable certificate. Eg, mail.susx.ac.uk, port 143, TLSv1
2. Read the dialog message carefully.
3. I've seen three different error messages, the more detailed messages refer to web servers.
Actual Results:
Dialogs refer to web servers
Expected Results:
Dialogs refer to email servers, or just "servers"
Comment 1•19 years ago
|
||
xref 333149
Comment 2•18 years ago
|
||
Naming issue?
Comment 3•17 years ago
|
||
Confirming that, in Thunderbird 2.0.0.21 (20090409), I see "your *browser* will trust...." etc. messages when adding/removing a cert.
Updated•16 years ago
|
Status: UNCONFIRMED → NEW
Ever confirmed: true
Comment 6•16 years ago
|
||
This bug was originally reported for TB 2.0
I believe most SSL error messages should have changed in TB 3.
Bug 531569 refers to TB 3 and claims to talk about "web" sites.
However, I don't see the term "web" shown anywhere in the screenshot.
I agree that mentioning "banks" may not be a perfect fit when talking about a mail server, but that UI is a general purpose UI, and a specific solution for mail servers hasn't been produced.
Comment 7•16 years ago
|
||
screenshot of this in TB 3: https://bugzilla.mozilla.org/attachment.cgi?id=414932
Comment 8•16 years ago
|
||
Yes, our cert exception handling is still focused on web sites, very unfortunately. We need something separate for all the non-https protocols.
Whiteboard: [psm-cert-errors]
Comment 11•9 years ago
|
||
If we're going to call 436318 a duplicate, then please note that the fix must address the workflow issues described therein (users needing to enter https://a1.postal.mail.dreamhost.com:995 instead of pop3s://a1.postal.mail.dreamhost.com to retrieve a certificate). If this is fixed with some simple changes to strings but the workflow remains the same, please re-open 436318.
Comment 12•9 years ago
|
||
It's also worth mentioning that bug 436318 requests 'a checkbox for "Use STARTTLS"' as a possibly superior workflow for certain mail server certificates (though that would not address the LDAP certificate exceptions). It might be worth reopening something specific for that, as well.
But as this bug enters its ninth year, I have no confidence that the bugfix will happen before the Mozilla foundation folds.
Updated•7 years ago
|
Assignee: dveditz → nobody
Updated•7 years ago
|
Severity: normal → minor
Updated•3 years ago
|
Severity: minor → S4
You need to log in
before you can comment on or make changes to this bug.
Description
•