ANNOUNCE: OfflineImap 6.5.4

Eygene Ryabinkin rea-fbsd at codelabs.ru
Tue Jun 5 11:28:03 UTC 2012


Tue, Jun 05, 2012 at 09:53:13AM +0200, Jonas H??rsch wrote:
> On Tue, Jun 05 2012, Oon-Ee Ng wrote:
> > Which gives me the problem as reported here -
> > http://permalink.gmane.org/gmane.mail.imap.offlineimap.general/5625
> >
> > Establishing connection to imap.gmail.com:993
> > ERROR: Server SSL fingerprint 'f3043dd689a2e7dddfbef82703a6c65ea9b634c1' for hos
> > tname 'imap.gmail.com' does not match configured fingerprint. Please verify and
> > set 'cert_fingerprint' accordingly if not set yet.
> > *** Finished account 'ML' in 0:00
> 
> if you add (as the error description tries to tell) a line
> 
> cert_fingerprint = f3043dd689a2e7dddfbef82703a6c65ea9b634c1
> 
> to the repository section of your gmail account, offlineimap will sync
> again AND prevent anyone from impersonating the gmail imap server from
> now on.

... until the current certificate will expire and you'll be forced
to stick the new value for the cert_fingerprint.

The better way is to specify the path to the CA certificate bundle
in the option 'sslcacertfile' of the given repository: if you trust
the CA, then the validation will be performed and will survive the
changes of the server's certificate (provided it is done correctly).
-- 
Eygene Ryabinkin                                        ,,,^..^,,,
[ Life's unfair - but root password helps!           | codelabs.ru ]
[ 82FE 06BC D497 C0DE 49EC  4FF0 16AF 9EAE 8152 ECFB | freebsd.org ]
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/offlineimap-project/attachments/20120605/9cc15f95/attachment.pgp>


More information about the OfflineIMAP-project mailing list