sslcacertfile: "SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed"

Johannes Kastl mail at ojkastl.de
Fri Aug 12 14:28:43 BST 2011


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Sebastian,

thanks for your answer.

On 8/12/11 3:19 PM Sebastian Spaeth wrote:

> Openssl and python's ssl error messages are not exactly helpful and I
> am no SSL expert. Perhaps the certificate expired?

I created the sslcacertfile again, the same way I had created it weeks
ago
(https://github.com/nicolas33/offlineimap/blob/632f1fe61f9e7700ac46a5a077d94fe652be2a09/docs/FAQ.rst#how-do-i-generate-an-sslcacertfile-file).
And I diff'ed the two files. Which showed no difference.

Also, when connecting to the imap-Server via "openssl s_client -connect"
and using OSX's /System/Library/OpenSSL/certs as CAfile, I get a "Verify
return code: 0 (ok)".

So I guess the certificate should not be the problem. But I am not an
expert on that.

Of course, the error message in the newer versions of offlineimap
("Could not connect via SSL to host 'imap.gmx.net' and non-standard ssl
port 993 configured...") is not really helpful...

Regards,
Johannes
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk5FKosACgkQzi3gQ/xETbLL6wCfbB7ywG5p3/LUBaPUrzKwqNCC
JYUAnivIgbfIbtURikEbTeBTPJ+zUOEo
=28e2
-----END PGP SIGNATURE-----





More information about the OfflineIMAP-project mailing list