git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 3/3] send-email: set SSL options through IO::Socket::SSL::set_client_defaults

From
Thomas Rast <tr@thomasrast.ch>
Date
Dec 2, 2013, 23:23 UTC
Message-ID
<87k3fmon0v.fsf@linux-1gf2.Speedport_W723_V_Typ_A_1_00_098>
In-Reply-To
<CALkWK0nn867+3+cToc=QMyA0u+0oPJkq+nmB1T3DP+kiiwb72Q@mail.gmail.com>
Ramkumar Ramachandra <artagnon@gmail.com> writes:
Show 18 quoted lines
> Thomas Rast wrote:
>> When --smtp-encryption=ssl, we use a Net::SMTP::SSL connection,
>> passing its ->new all the options that would otherwise go to
>> Net::SMTP->new (most options) and IO::Socket::SSL->start_SSL (for the
>> SSL options).
>>
>> However, while Net::SMTP::SSL replaces the underlying socket class
>> with an SSL socket, it does nothing to allow passing options to that
>> socket.  So the SSL-relevant options are lost.
>
> Both [1/3] and [2/3] look good. However, I'm curious about this one:
> Net::SMTP::SSL inherits from IO::Socket::SSL, where new() is defined.
> In the documentation for IO::Socket::SSL,
>
>   $ perldoc IO::Socket::SSL
>
> I can see examples where SSL_verify_mode and SSL_ca_path are passed to
> new(). So, I'm not sure what this patch is about.

Net::SMTP::SSL is merely steals all the code from Net::SMTP into a class that has IO::Socket::SSL as its first inheritance line.

This works because Net::SMTP (no SSL) inherits from IO::Socket::INET instead, and uses SUPER:: methods to access the latter's features. So by effectively replacing IO::Socket::INET with IO::Socket::SSL, Net::SMTP::SSL can apply all of Net::SMTP's code on an SSL socket.

However!

That SUPER:: access does not pass anything SSLey. In particular, Net::SMTP::SSL->new (which is just the same as Net::SMTP->new) runs this to initialize its socket:

    $obj = $type->SUPER::new(
      PeerAddr => ($host = $h),
      PeerPort => $arg{Port} || 'smtp(25)',
      LocalAddr => $arg{LocalAddr},
      LocalPort => $arg{LocalPort},
      Proto     => 'tcp',
      Timeout   => defined $arg{Timeout}
      ? $arg{Timeout}
      : 120
      )

Note the conspicuous absence of any kind of SSL arguments, or any kind of args-I-don't-know-myself passthrough.

If you _do_ specify SSL arguments (i.e. key-value style arguments that would normally be accepted by IO::Socket::SSL->new) to Net::SMTP::SSL->new, they will simply be ignored, because of how the key-value argument passing treats the argument list as a hash.

Does that clarify it?

This is all assuming I got the details vaguely correct, and the source snippets are from my perl v5.18.1 installed by opensuse 13.1.

It turns out the server I was trying to talk to on Sunday had an expired certificate, and despite the code from 35035bb, my efforts to set SSL_VERIFY_NONE were futile. Until I noticed the set_client_defaults() trick. So I'm pretty convinced the patch does *something* right.

-- 
Thomas Rast
tr@thomasrast.ch
Previous: Ramkumar Ramachandra
Message 5 of 5 in “send-email: pass Debug to Net::SMTP::SSL::new”
  1. 1/3 send-email: pass Debug to Net::SMTP::SSL::newThomas Rast, Dec 1, 2013
  2. 2/3 send-email: --smtp-ssl-cert-path takes an argumentThomas Rast, Dec 1, 2013
  3. 3/3 send-email: set SSL options through IO::Socket::SSL::set_client_defaultsThomas Rast, Dec 1, 2013
  4. Ramkumar RamachandraDec 2, 2013
  5. Thomas RastDec 2, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.