sslcacertfile troubleshooting :)

Daniel Shahaf d.s at daniel.shahaf.name
Wed Jan 18 11:51:31 GMT 2012


SamLT wrote on Wed, Jan 18, 2012 at 12:00:32 +0100:
> On Wed, Jan 18, 2012 at 08:13:49AM +0200, Daniel Shahaf wrote:
> | gnutls-cli --x509cafile slt/conf/certs/mail.mydomain.eu.cert -p 993 mail.mydomain.eu
> | Processed 3 CA certificate(s).
> | Resolving 'mail.mydomain.eu'...
> | Connecting to '56.159.87.64:993'...
> | *** Verifying server certificate failed...
> | *** Fatal error: Error in the certificate.
> | *** Handshake has failed
> | GnuTLS error: Error in the certificate
> 
> I have to add the --insecure option to connect successfully
> 
> This seems clear the certificate is faulty, but it's chained
> certificates, how do I know which ones is wrong? And why it is wrong?
> (none of them are expired).
> 
> Ok, this doesn't really belong to offlineimap ML anymore, but that kind
> of information may be usefull to other, so feel free to point me to the
> right direction.

For starters you could pass --verbose to gnutls-cli.





More information about the OfflineIMAP-project mailing list