imap.google.com being spoofed?

Dima Pasechnik dimpase+olimap at gmail.com
Mon Oct 1 05:42:11 UTC 2012


Noticed offlineimap failing with

 ERROR: Server SSL fingerprint
'6d1b5b5ee0180ab493b71d3b94534b5ab937d042' for hostname
'imap.gmail.com' does not match configured fingerprint. Please verify
and set 'cert_fingerprint' accordingly if not set yet.

I have in my .offlineimaprc
cert_fingerprint=f3043dd689a2e7dddfbef82703a6c65ea9b634c1

Repeated attempts to connect only succeed if I set maxconnections = 1.
With maxconnections = 5 I see the above error popping up halfway the
offlineimap session
(different threads hit different certs, I suppose).

Is it a genuine hacking attempt going on, or some misconfiguration somewhere?

Any easy way to gather extra info on these connections?
(I program in Python, but I have no time to read and modify
offlineimap, at least not now...)


Thanks,
Dmitrii



More information about the OfflineIMAP-project mailing list