Bug 2230034 - TLS broken for POP3 and SMTP connections [8.4.z]
Summary: TLS broken for POP3 and SMTP connections [8.4.z]
Keywords:
Status: NEW
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: thunderbird
Version: 8.4
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Jan Horak
QA Contact: Jiri Prajzner
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-08-08 14:15 UTC by Jan Horak
Modified: 2023-08-09 13:44 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-164842 0 None None None 2023-08-08 14:17:29 UTC
Red Hat Knowledge Base (Solution) 7028011 0 None None None 2023-08-09 13:44:33 UTC

Description Jan Horak 2023-08-08 14:15:35 UTC
This bug was initially created as a copy of Bug #2229981

I am copying this bug because: 



Description of problem:
TLS is broken on the latest thunderbird release

Version-Release number of selected component (if applicable):
thunderbird-102.14.0-1.el7_9.x86_64

How reproducible:
Always

Steps to Reproduce:
1. Configure thunderbird to use TLS for pop3 or smtp connections
2. Update thunderbird to 102.14.0-1.el7_9.x86_64
3. Launch thunderbird and attempt tls connection

Actual results:
TLS connection fails with the following entry in maillog:

Aug  7 19:06:15 mail_server dovecot: pop3-login: Disconnected (no auth attempts in 0 secs): user=<>, rip=192.168.0.1, lip=192.168.0.1, TLS handshaking: SSL_accept() failed: error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate: SSL alert number 42, session=<ddk1GlkCBqjAqAAB>

Expected results:
tls connections work as expected

Additional info:
Downgrading to thunderbird-102.13.0-2.el7_9.x86_64 fixes the issue
Disabling SSL/TLS security and sending authentication in plain text (highly undesirable) also works
TLS cert is self signed and imported into thunderbird, with expiry date 2028


Note You need to log in before you can comment on or make changes to this bug.