{"thread":{"id":"40872","subject":"[PATCH] send-email: enable SSL level 1 debug output","startedAt":"2015-11-25T00:02:23Z","lastAt":"2015-12-03T21:47:18Z","messageCount":2,"participants":["John Keeping"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"273678","messageId":"a56a8d728ffeb6a6c2b0f7decd0485a1906b8f25.1448409432.git.john@keeping.me.uk","threadId":"40872","inReplyTo":null,"subject":"[PATCH] send-email: enable SSL level 1 debug output","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2015-11-25T00:02:23Z","receivedAt":"2015-11-25T00:02:23Z","isPatch":true,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"If a server's certificate isn't accepted by send-email, the output is:\n\n\tUnable to initialize SMTP properly. Check config and use --smtp-debug.\n\nbut adding --smtp-debug=1 just produces the same output since we don't\nget as far as talking SMTP.\n\nTurning on SSL debug at level 1 gives:\n\n\tDEBUG: .../IO/Socket/SSL.pm:1796: SSL connect attempt failed error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed\n\tDEBUG: .../IO/Socket/SSL.pm:673: fatal SSL error: SSL connect attempt failed error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed\n\tDEBUG: .../IO/Socket/SSL.pm:1780: IO::Socket::IP configuration failed\n\nIO::Socket::SSL defines level 1 debug as \"print out errors from\nIO::Socket::SSL and ciphers from Net::SSLeay\".  In fact, it aliases\nNet::SSLeay::trace which is defined to guarantee silence at level 0 and\nonly emit error messages at level 1, so let's enable it by default.\n\nSigned-off-by: John Keeping <john@keeping.me.uk>\n---\nThis is the result of a previous discussion [0] but I decided to drop\nthe switch on --smtp-debug since level 1 only gives output on errors.\n\n[0] http://marc.info/?l=git&m=144840344331208&w=2\n\n git-send-email.perl | 1 +\n 1 file changed, 1 insertion(+)\n\ndiff --git a/git-send-email.perl b/git-send-email.perl\nindex e907e0e..918aafa 100755\n--- a/git-send-email.perl\n+++ b/git-send-email.perl\n@@ -1318,6 +1318,7 @@ Message-Id: $message_id\n \t\t\trequire Net::SMTP::SSL;\n \t\t\t$smtp_domain ||= maildomain();\n \t\t\trequire IO::Socket::SSL;\n+\t\t\t$IO::Socket::SSL::DEBUG = 1;\n \t\t\t# Net::SMTP::SSL->new() does not forward any SSL options\n \t\t\tIO::Socket::SSL::set_client_defaults(\n \t\t\t\tssl_verify_params());\n-- \n2.6.3.462.gbe2c914\n"},{"id":"273996","messageId":"26c6006ad88146e0abfdfcaf99be686a4fb050c4.1449179138.git.john@keeping.me.uk","threadId":"40872","inReplyTo":"a56a8d728ffeb6a6c2b0f7decd0485a1906b8f25.1448409432.git.john@keeping.me.uk","subject":"[PATCH v2] send-email: enable SSL level 1 debug output","fromName":"John Keeping","fromEmail":"john@keeping.me.uk","sentAt":"2015-12-03T21:47:18Z","receivedAt":"2015-12-03T21:47:18Z","isPatch":true,"sender":{"key":"john@keeping.me.uk","avatar":"https://avatars.githubusercontent.com/u/1702081?v=4"},"body":"If a server's certificate isn't accepted by send-email, the output is:\n\n\tUnable to initialize SMTP properly. Check config and use --smtp-debug.\n\nbut adding --smtp-debug=1 just produces the same output since we don't\nget as far as talking SMTP.\n\nTurning on SSL debug at level 1 gives:\n\n\tDEBUG: .../IO/Socket/SSL.pm:1796: SSL connect attempt failed error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed\n\tDEBUG: .../IO/Socket/SSL.pm:673: fatal SSL error: SSL connect attempt failed error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed\n\tDEBUG: .../IO/Socket/SSL.pm:1780: IO::Socket::IP configuration failed\n\nIO::Socket::SSL defines level 1 debug as \"print out errors from\nIO::Socket::SSL and ciphers from Net::SSLeay\".  In fact, it aliases\nNet::SSLeay::trace which is defined to guarantee silence at level 0 and\nonly emit error messages at level 1, so let's enable it by default.\n\nThe modification of warnings is needed to avoid a warning about:\n\n\tName \"IO::Socket::SSL::DEBUG\" used only once: possible typo\n\nSigned-off-by: John Keeping <john@keeping.me.uk>\n---\nSorry about the delay following up with this.\n\nI don't particularly like the need for brackets and modifying the\nwarnings here, but AFAIK there is no other way to avoid a warning that\nis likely to upset users (although I am far from a Perl expert).\n\n git-send-email.perl | 7 +++++++\n 1 file changed, 7 insertions(+)\n\ndiff --git a/git-send-email.perl b/git-send-email.perl\nindex e907e0e..72508be 100755\n--- a/git-send-email.perl\n+++ b/git-send-email.perl\n@@ -1318,6 +1318,13 @@ Message-Id: $message_id\n \t\t\trequire Net::SMTP::SSL;\n \t\t\t$smtp_domain ||= maildomain();\n \t\t\trequire IO::Socket::SSL;\n+\n+\t\t\t# Suppress \"variable accessed once\" warning.\n+\t\t\t{\n+\t\t\t\tno warnings 'once';\n+\t\t\t\t$IO::Socket::SSL::DEBUG = 1;\n+\t\t\t}\n+\n \t\t\t# Net::SMTP::SSL->new() does not forward any SSL options\n \t\t\tIO::Socket::SSL::set_client_defaults(\n \t\t\t\tssl_verify_params());\n-- \n2.6.3.462.gbe2c914\n"}]}