git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC/PATCH] send-email: die if CA path doesn't exist

From
John Keeping <john@keeping.me.uk>
Date
Nov 24, 2015, 23:10 UTC
Message-ID
<20151124231041.GC18913@serenity.lan>
In-Reply-To
<20151124222821.GA10058@sigill.intra.peff.net>
On Tue, Nov 24, 2015 at 05:28:21PM -0500, Jeff King wrote:
Show 24 quoted lines
> On Tue, Nov 24, 2015 at 10:17:08PM +0000, John Keeping wrote:
> 
> > I wonder if we should do this to help debug SSL issues:
> > 
> > -- >8 --
> > diff --git a/git-send-email.perl b/git-send-email.perl
> > index e057051..6d4e0ee 100755
> > --- a/git-send-email.perl
> > +++ b/git-send-email.perl
> > @@ -1317,6 +1317,10 @@ Message-Id: $message_id
> >  			require Net::SMTP::SSL;
> >  			$smtp_domain ||= maildomain();
> >  			require IO::Socket::SSL;
> > +			if ($debug_net_smtp) {
> > +				no warnings 'once';
> > +				$IO::Socket::SSL::DEBUG = 1;
> > +			}
> >  			# Net::SMTP::SSL->new() does not forward any SSL options
> >  			IO::Socket::SSL::set_client_defaults(
> >  				ssl_verify_params());
> > -- 8< --
> 
> That certainly looks like a reasonable thing to be doing, assuming that
> the output from IO::Socket::SSL is generally helpful.
It's a bit verbose for errors, but it does let you know what went wrong:
DEBUG: .../IO/Socket/SSL.pm:1796: SSL connect attempt failed error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
DEBUG: .../IO/Socket/SSL.pm:673: fatal SSL error: SSL connect attempt failed error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
DEBUG: .../IO/Socket/SSL.pm:1780: IO::Socket::IP configuration failed

It doesn't print anything when the SSL connection is established successfully, but I don't think that's a problem and if we jump to level 2 it starts logging things like:

DEBUG: .../IO/Socket/SSL.pm:687: waiting for fd to become ready: SSL wants a read first
DEBUG: .../IO/Socket/SSL.pm:707: socket ready, retrying connect
DEBUG: .../IO/Socket/SSL.pm:677: ssl handshake in progress
without adding anything useful.
Show 11 quoted lines
> > > > Maybe we shouldn't worry too much about that, but should instead put the
> > > > invalid path into the error message:
> > > > 
> > > > 	die "CA path \"$smtp_ssl_cert_path\" does not exist.";
> > > 
> > > Given what I wrote above, yeah, I'd agree that is sufficient (and I do
> > > think mentioning the path is helpful).
> > 
> > I'll change it to this in a re-roll.
> 
> Thanks.
Previous: Jeff KingNext: John Keeping
Message 7 of 11 in “send-email: die if CA path doesn't exist”
  1. send-email: die if CA path doesn't existJohn Keeping, Nov 17, 2015
  2. Jeff KingNov 20, 2015
  3. John KeepingNov 20, 2015
  4. Jeff KingNov 24, 2015
  5. John KeepingNov 24, 2015
  6. Jeff KingNov 24, 2015
  7. John KeepingNov 24, 2015
  8. send-email: die if CA path doesn't existJohn Keeping, Nov 24, 2015
  9. Jeff KingNov 24, 2015
  10. John KeepingNov 25, 2015
  11. Jeff KingNov 25, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.