{"thread":{"id":"34353","subject":"[PATCH] send-email: squelch warning from Net::SMTP::SSL","startedAt":"2013-07-05T10:18:31Z","lastAt":"2013-07-29T17:12:01Z","messageCount":7,"participants":["Ramkumar Ramachandra","John Keeping","Matthieu Moy","Colin Guthrie","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"222619","messageId":"1373019511-13232-1-git-send-email-artagnon@gmail.com","threadId":"34353","inReplyTo":null,"subject":"[PATCH] send-email: squelch warning from Net::SMTP::SSL","fromName":"Ramkumar Ramachandra","fromEmail":"artagnon@gmail.com","sentAt":"2013-07-05T10:18:31Z","receivedAt":"2013-07-05T10:18:31Z","isPatch":true,"sender":{"key":"r@artagnon.com","avatar":"https://avatars.githubusercontent.com/u/37226?v=4"},"body":"Due to a recent change in the Net::SMTP::SSL module, send-email emits\nthe following ugly warning everytime a email is sent via SSL:\n\n*******************************************************************\n Using the default of SSL_verify_mode of SSL_VERIFY_NONE for client\n is deprecated! Please set SSL_verify_mode to SSL_VERIFY_PEER\n together with SSL_ca_file|SSL_ca_path for verification.\n If you really don't want to verify the certificate and keep the\n connection open to Man-In-The-Middle attacks please set\n SSL_verify_mode explicitly to SSL_VERIFY_NONE in your application.\n*******************************************************************\n\nFix this by explicitly specifying SSL_verify_mode => SSL_VERIFY_NONE in\nNet::SMTP::SSL->start_SSL().\n\nHelped-by: brian m. carlson <sandals@crustytoothpaste.net>\nSigned-off-by: Ramkumar Ramachandra <artagnon@gmail.com>\n---\n git-send-email.perl | 4 +++-\n 1 file changed, 3 insertions(+), 1 deletion(-)\n\ndiff --git a/git-send-email.perl b/git-send-email.perl\nindex ecbf56f..758100d 100755\n--- a/git-send-email.perl\n+++ b/git-send-email.perl\n@@ -1193,10 +1193,12 @@ X-Mailer: git-send-email $gitversion\n \t\t\t\t\t\t Debug => $debug_net_smtp);\n \t\t\tif ($smtp_encryption eq 'tls' && $smtp) {\n \t\t\t\trequire Net::SMTP::SSL;\n+\t\t\t\tuse IO::Socket::SSL qw(SSL_VERIFY_NONE);\n \t\t\t\t$smtp->command('STARTTLS');\n \t\t\t\t$smtp->response();\n \t\t\t\tif ($smtp->code == 220) {\n-\t\t\t\t\t$smtp = Net::SMTP::SSL->start_SSL($smtp)\n+\t\t\t\t\t$smtp = Net::SMTP::SSL->start_SSL($smtp,\n+\t\t\t\t\t\t\t\t\t  SSL_verify_mode => SSL_VERIFY_NONE)\n \t\t\t\t\t\tor die \"STARTTLS failed! \".$smtp->message;\n \t\t\t\t\t$smtp_encryption = '';\n \t\t\t\t\t# Send EHLO again to receive fresh\n-- \n1.8.3.2.722.g3244e19.dirty\n"},{"id":"222620","messageId":"20130705104557.GL9161@serenity.lan","threadId":"34353","inReplyTo":"1373019511-13232-1-git-send-email-artagnon@gmail.com","subject":"Re: [PATCH] send-email: squelch warning from Net::SMTP::SSL","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2013-07-05T10:45:57Z","receivedAt":"2013-07-05T10:45:57Z","isPatch":true,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"On Fri, Jul 05, 2013 at 03:48:31PM +0530, Ramkumar Ramachandra wrote:\n> Due to a recent change in the Net::SMTP::SSL module, send-email emits\n> the following ugly warning everytime a email is sent via SSL:\n> \n> *******************************************************************\n>  Using the default of SSL_verify_mode of SSL_VERIFY_NONE for client\n>  is deprecated! Please set SSL_verify_mode to SSL_VERIFY_PEER\n>  together with SSL_ca_file|SSL_ca_path for verification.\n>  If you really don't want to verify the certificate and keep the\n>  connection open to Man-In-The-Middle attacks please set\n>  SSL_verify_mode explicitly to SSL_VERIFY_NONE in your application.\n> *******************************************************************\n> \n> Fix this by explicitly specifying SSL_verify_mode => SSL_VERIFY_NONE in\n> Net::SMTP::SSL->start_SSL().\n\nI don't think this is really \"fix\", it's more plastering over the\nproblem.  As the message from OpenSSL says, specifying this means that\nwe're explicitly saying that we don't want to check the server\ncertificate which loses half of the security of SSL.\n\nI'd rather leave this as it is (complete with the big scary error\nmessage) and eventually fix it properly by letting the user specify the\nca_file or ca_path.  Perhaps we can even set a sensible default,\nalthough I expect this needs to be platform-specific.\n"},{"id":"222621","messageId":"CALkWK0nWvmuxfZJF_Mk2MmJNxz4+=46m_pBtzjSZprLxABhNeA@mail.gmail.com","threadId":"34353","inReplyTo":"20130705104557.GL9161@serenity.lan","subject":"Re: [PATCH] send-email: squelch warning from Net::SMTP::SSL","fromName":"Ramkumar Ramachandra","fromEmail":"artagnon@gmail.com","sentAt":"2013-07-05T10:52:29Z","receivedAt":"2013-07-05T10:52:29Z","isPatch":true,"sender":{"key":"r@artagnon.com","avatar":"https://avatars.githubusercontent.com/u/37226?v=4"},"body":"John Keeping wrote:\n> I don't think this is really \"fix\", it's more plastering over the\n> problem.\n\nIt defaulted to SSL_VERIFY_NONE before Net::SMTP::SSL was updated, and\nthe behavior hasn't changed now.  The new version simply asks us to be\nexplicit about SSL_VERIFY_NONE, so we are aware about it.\n\n> I'd rather leave this as it is (complete with the big scary error\n> message) and eventually fix it properly by letting the user specify the\n> ca_file or ca_path.  Perhaps we can even set a sensible default,\n> although I expect this needs to be platform-specific.\n\nNothing scary about it: it eats up real estate, and that is annoying.\nI personally couldn't care less about ca_file, since all my emails are\nto public mailing lists anyway.  Work on specifying a proper ca_file\nas a follow-up, if you so desire.\n"},{"id":"222622","messageId":"vpqbo6hw8e9.fsf@anie.imag.fr","threadId":"34353","inReplyTo":"CALkWK0nWvmuxfZJF_Mk2MmJNxz4+=46m_pBtzjSZprLxABhNeA@mail.gmail.com","subject":"Re: [PATCH] send-email: squelch warning from Net::SMTP::SSL","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@grenoble-inp.fr","sentAt":"2013-07-05T11:31:10Z","receivedAt":"2013-07-05T11:31:10Z","isPatch":true,"sender":{"key":"matthieu.moy@grenoble-inp.fr","avatar":"https://gravatar.com/avatar/72c8a2705971a25dfaff23cece15130d405685845d911aedd5667ace277f3fc5?d=mp&s=160"},"body":"Ramkumar Ramachandra <artagnon@gmail.com> writes:\n\n> John Keeping wrote:\n>> I don't think this is really \"fix\", it's more plastering over the\n>> problem.\n>\n> It defaulted to SSL_VERIFY_NONE before Net::SMTP::SSL was updated, and\n> the behavior hasn't changed now.  The new version simply asks us to be\n> explicit about SSL_VERIFY_NONE, so we are aware about it.\n\n\"We\" as \"the Git developers\", yes. But your change makes sure users are\n_not_ aware about it. There's a long history of software ignoring SSL\ncertificates by default, I don't think we should cast in stone that we\ndon't want SSL certificate verification.\n\n-- \nMatthieu Moy\nhttp://www-verimag.imag.fr/~moy/\n"},{"id":"224118","messageId":"kstfht$p0e$1@ger.gmane.org","threadId":"34353","inReplyTo":"vpqbo6hw8e9.fsf@anie.imag.fr","subject":"Re: [PATCH] send-email: squelch warning from Net::SMTP::SSL","fromName":"Colin Guthrie","fromEmail":"gmane@colin.guthr.ie","sentAt":"2013-07-26T09:29:40Z","receivedAt":"2013-07-26T09:29:40Z","isPatch":true,"sender":{"key":"gmane@colin.guthr.ie","avatar":null},"body":"'Twas brillig, and Matthieu Moy at 05/07/13 12:31 did gyre and gimble:\n> Ramkumar Ramachandra <artagnon@gmail.com> writes:\n> \n>> John Keeping wrote:\n>>> I don't think this is really \"fix\", it's more plastering over the\n>>> problem.\n>>\n>> It defaulted to SSL_VERIFY_NONE before Net::SMTP::SSL was updated, and\n>> the behavior hasn't changed now.  The new version simply asks us to be\n>> explicit about SSL_VERIFY_NONE, so we are aware about it.\n> \n> \"We\" as \"the Git developers\", yes. But your change makes sure users are\n> _not_ aware about it. There's a long history of software ignoring SSL\n> certificates by default, I don't think we should cast in stone that we\n> don't want SSL certificate verification.\n\nFor what it's worth, after upgrading here, I got this error at the\nserver side:\n\nJul 26 10:15:41 foo.example.com postfix/smtpd[7736]: warning: TLS\nlibrary problem: 7736:error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1\nalert unknown ca:s3_pkt.c:1256:SSL alert number 48:\n\n\nThis is because my postfix doesn't have a ca bundle configured but all\nother mail clients have been fine before.\n\nWith the original patch here I could continue.\n\nI'd really love to see an option to set this to none in the .gitconfig,\nbut agree with the principle that it should be one by default and the\nsetting should over ride that.\n\nAll the best\n\nCol\n\nPS I'm mainly posting this such that people searching the intertubes for\nthe postfix error above and git-send-email will match at least this\nmessage and find the fix/workaround :)\n\n-- \n\nColin Guthrie\ngmane(at)colin.guthr.ie\nhttp://colin.guthr.ie/\n\nDay Job:\n  Tribalogic Limited http://www.tribalogic.net/\nOpen Source:\n  Mageia Contributor http://www.mageia.org/\n  PulseAudio Hacker http://www.pulseaudio.org/\n  Trac Hacker http://trac.edgewall.org/\n"},{"id":"224231","messageId":"7va9l51hkn.fsf@alter.siamese.dyndns.org","threadId":"34353","inReplyTo":"kstfht$p0e$1@ger.gmane.org","subject":"Re: [PATCH] send-email: squelch warning from Net::SMTP::SSL","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-07-29T16:01:12Z","receivedAt":"2013-07-29T16:01:12Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Colin Guthrie <gmane@colin.guthr.ie> writes:\n\n> For what it's worth, after upgrading here, I got this error at the\n> server side:\n>\n> Jul 26 10:15:41 foo.example.com postfix/smtpd[7736]: warning: TLS\n> library problem: 7736:error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1\n> alert unknown ca:s3_pkt.c:1256:SSL alert number 48:\n>\n>\n> This is because my postfix doesn't have a ca bundle configured but all\n> other mail clients have been fine before.\n>\n> With the original patch here I could continue.\n>\n> I'd really love to see an option to set this to none in the .gitconfig,\n\nIsn't that what the final patch committed under Ram's name\nimplements?\n\n    sendemail.smtpsslcertpath::\n           Path to ca-certificates (either a directory or a single file).\n           Set it to an empty string to disable certificate verification.\n\nor have we missed your use case?\n\n> but agree with the principle that it should be one by default and the\n> setting should over ride that.\n"},{"id":"224236","messageId":"51F6A261.40500@colin.guthr.ie","threadId":"34353","inReplyTo":"7va9l51hkn.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH] send-email: squelch warning from Net::SMTP::SSL","fromName":"Colin Guthrie","fromEmail":"gmane@colin.guthr.ie","sentAt":"2013-07-29T17:12:01Z","receivedAt":"2013-07-29T17:12:01Z","isPatch":true,"sender":{"key":"gmane@colin.guthr.ie","avatar":null},"body":"'Twas brillig, and Junio C Hamano at 29/07/13 17:01 did gyre and gimble:\n> Colin Guthrie <gmane@colin.guthr.ie> writes:\n> \n>> For what it's worth, after upgrading here, I got this error at the\n>> server side:\n>>\n>> Jul 26 10:15:41 foo.example.com postfix/smtpd[7736]: warning: TLS\n>> library problem: 7736:error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1\n>> alert unknown ca:s3_pkt.c:1256:SSL alert number 48:\n>>\n>>\n>> This is because my postfix doesn't have a ca bundle configured but all\n>> other mail clients have been fine before.\n>>\n>> With the original patch here I could continue.\n>>\n>> I'd really love to see an option to set this to none in the .gitconfig,\n> \n> Isn't that what the final patch committed under Ram's name\n> implements?\n> \n>     sendemail.smtpsslcertpath::\n>            Path to ca-certificates (either a directory or a single file).\n>            Set it to an empty string to disable certificate verification.\n> \n> or have we missed your use case?\n\nYeah that patch works fine if I set the certpath = \"\" in the config, and\nI even added that path to our packages.\n\nI read the mailing list after following the google trail and replied to\nthat specific message without realising a more recent patch was\navailable and then didn't post a followup saying the final patch worked\n- my bad!\n\nSorry about that, and thanks to everyone for the final patch :)\n\nCol\n\n\n-- \n\nColin Guthrie\ngmane(at)colin.guthr.ie\nhttp://colin.guthr.ie/\n\nDay Job:\n  Tribalogic Limited http://www.tribalogic.net/\nOpen Source:\n  Mageia Contributor http://www.mageia.org/\n  PulseAudio Hacker http://www.pulseaudio.org/\n  Trac Hacker http://trac.edgewall.org/\n"}]}