Open Bug 826662 Opened 13 years ago Updated 3 years ago

Connect to LDAP server using StartTLS (not SSL)

Categories

(Thunderbird :: Address Book, enhancement)

enhancement

Tracking

(Not tracked)

People

(Reporter: mehmet, Unassigned)

References

Details

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:17.0) Gecko/20100101 Firefox/17.0 Build ID: 20121229012531 Steps to reproduce: I am trying to connect to my ldap server, which requires confidentiality with TLS over port 389, not SSL over 636 and I think this is not supported over thunderbird. I thought that this would be supported by TB already and was shocked to see that it is not. So this is basically an enhancement request...
Severity: normal → enhancement
checked. ldapsearch -ZZ -h myserver -p 389 works for me, this is (supposedly anyway) STARTTLS ( not TLS :) TLS/SSL on 636 is what thunderbird will use. What you ask for would be starttls on 389.
Status: UNCONFIRMED Meaning: This bug has recently been added to the database. Nobody has validated that this bug is true. Users who have the "canconfirm" permission set may confirm this bug, changing its state to NEW. Or, it may be directly resolved and marked RESOLVED. A more than 2 years old bug? Someone must be joking or what. But yeah, we have a chat "feature" in the e-mail client and other useless options... Time to find a professional e-mail client. Thanks anyway.
It might be advantageous to know if the server supports startTLS connections, like Zimbra-ldap service for LDAP lookups from TBird, does TBird inherently support startTLS as well? As of version 45.7.0, there's really no way to select a TLS option from TBird Addressbook for ldap lookups.
I am confirming this bug. I am running Thunderbird 45.8.0 on Centos 7 and there is no way to enable StartTLS for an LDAP address book.
I am confirming this bug. I am running Thunderbird 45.8.0 on MAc and there is no way to enable StartTLS for an LDAP address book.
just upgraded I am confirming this bug. I am running Thunderbird 52.0.1 on MAC and there is no way to enable StartTLS for an LDAP address book.

I have the same Bug on Thunderbird 60.6.1.
Is it planed to fix/enhance it?

Just a few more notes on this (after looking at Bug 1576364):
There are a couple of methods for setting up a secure LDAP connection:

LDAP over SSL

  • Client connects on a different port (636 by default) and an encrypted connection is negotiated before any LDAP traffic is exchanged.
  • Was never formalised in the spec, and has been deprecated since LDAPv3 (around 2003).
  • The current LDAP code handles this by opening a plain socket, then immediately asking the "starttls" socket provider to wrap it. It does this to force SSLv2, as some LDAP servers apparently have trouble with SSLv3.

LDAP with StartTLS

  • Client connects to the same port for both secure and open connections (389 by default)
  • there's an LDAP extension which adds a "startTLS" operation. This upgrades the plaintext connection to a secure one.

From wikipedia:

A common alternative method of securing LDAP communication is using an SSL tunnel. The default port for LDAP over SSL is 636. The use of LDAP
over SSL was common in LDAP Version 2 (LDAPv2) but it was never standardized in any formal specification. This usage has been deprecated along > with LDAPv2, which was officially retired in 2003

The ldap C API seems to have some support for the StartTLS extension, but it's not exposed via the C++ wrappers.
However, it might be better to avoid using the C API - it's largely concerned with negotiating the handshake, callbacks to handle fetching and storing certificates and all that. Would be much have the existing "starttls" socket provider (nsTLSSocketProvider) sort all that out.

The LDAP configuration GUI would also need a little tweak to show StartTLS as an option.

It just occurred to me that no GUI changes should be required.
StartTLS should be the default connection type if the "use SSL" checkbox is not checked:
As part of the startup, the client sends an LDAP startTLS request to the server and if the server supports it, they switch (client calls startTLS on the socket). If the server doesn't support startTLS the connection stays unencrypted.

Depends. For mail that used to be the case (a long time ago), but "StartTLS if available" is obviously insecure.

True. I can see the benefit of a "I require StartTLS" GUI option.
Still, seems reasonable to upgrade from unsecured to StartTLS (if available) even without the user specifically requesting it.

Yeah as long as the UI doesn't imply to the user that the connection is secure (which it isn't really), it's no worse than today. Just of questionable value.

Status: UNCONFIRMED → NEW
Ever confirmed: true
OS: Linux → All
Hardware: x86_64 → All
Summary: Connect to LDAP server using TLS (not SSL) → Connect to LDAP server using StartTLS (not SSL)
Version: 17 Branch → unspecified
Severity: normal → S3

Issue may be obsolete now. I cannot confirm whether TLS is being used (and not STARTTLS) with port 389, but the server I am using for LDAP says in its documentation that unencrypted connections are denied. I am able to connect over tcp/389 - with "Use Secure Connection (SSL)" option disabled as well as over tcp/636 (with SSL) .

You need to log in before you can comment on or make changes to this bug.