git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] send-email: squelch warning from Net::SMTP::SSL

From
John Keeping <john@keeping.me.uk>
Date
Jul 5, 2013, 10:45 UTC
Message-ID
<20130705104557.GL9161@serenity.lan>
In-Reply-To
<1373019511-13232-1-git-send-email-artagnon@gmail.com>
On Fri, Jul 05, 2013 at 03:48:31PM +0530, Ramkumar Ramachandra wrote:
Show 14 quoted lines
> Due to a recent change in the Net::SMTP::SSL module, send-email emits
> the following ugly warning everytime a email is sent via SSL:
> 
> *******************************************************************
>  Using the default of SSL_verify_mode of SSL_VERIFY_NONE for client
>  is deprecated! Please set SSL_verify_mode to SSL_VERIFY_PEER
>  together with SSL_ca_file|SSL_ca_path for verification.
>  If you really don't want to verify the certificate and keep the
>  connection open to Man-In-The-Middle attacks please set
>  SSL_verify_mode explicitly to SSL_VERIFY_NONE in your application.
> *******************************************************************
> 
> Fix this by explicitly specifying SSL_verify_mode => SSL_VERIFY_NONE in
> Net::SMTP::SSL->start_SSL().

I don't think this is really "fix", it's more plastering over the problem. As the message from OpenSSL says, specifying this means that we're explicitly saying that we don't want to check the server certificate which loses half of the security of SSL.

I'd rather leave this as it is (complete with the big scary error message) and eventually fix it properly by letting the user specify the ca_file or ca_path. Perhaps we can even set a sensible default, although I expect this needs to be platform-specific.

Previous: Ramkumar RamachandraNext: Ramkumar Ramachandra
Message 2 of 7 in “send-email: squelch warning from Net::SMTP::SSL”
  1. send-email: squelch warning from Net::SMTP::SSLRamkumar Ramachandra, Jul 5, 2013
  2. John KeepingJul 5, 2013
  3. Ramkumar RamachandraJul 5, 2013
  4. Matthieu MoyJul 5, 2013
  5. Colin GuthrieJul 26, 2013
  6. Junio C HamanoJul 29, 2013
  7. Colin GuthrieJul 29, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.