From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Lars Magne Ingebrigtsen Newsgroups: gmane.emacs.bugs Subject: bug#16784: 24.3; Problems opening NNTP connection: failing starttls because of a non-verified certificate Date: Mon, 24 Mar 2014 13:14:12 +0100 Message-ID: References: <86bny5r5lj.fsf@dod.no> <87ob24ctq3.fsf@lifelogs.com> <874n2t3ozq.fsf@lifelogs.com> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: ger.gmane.org 1395663311 4294 80.91.229.3 (24 Mar 2014 12:15:11 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Mon, 24 Mar 2014 12:15:11 +0000 (UTC) To: 16784@debbugs.gnu.org Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Mon Mar 24 13:15:21 2014 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1WS3mf-0001ML-RA for geb-bug-gnu-emacs@m.gmane.org; Mon, 24 Mar 2014 13:15:18 +0100 Original-Received: from localhost ([::1]:36091 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WS3me-0000t2-Sj for geb-bug-gnu-emacs@m.gmane.org; Mon, 24 Mar 2014 08:15:16 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:46604) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WS3mW-0000qJ-Vt for bug-gnu-emacs@gnu.org; Mon, 24 Mar 2014 08:15:14 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1WS3mR-0003XM-Ra for bug-gnu-emacs@gnu.org; Mon, 24 Mar 2014 08:15:08 -0400 Original-Received: from debbugs.gnu.org ([140.186.70.43]:45585) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WS3mR-0003We-Os for bug-gnu-emacs@gnu.org; Mon, 24 Mar 2014 08:15:03 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.80) (envelope-from ) id 1WS3mR-00005o-3e; Mon, 24 Mar 2014 08:15:03 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Lars Magne Ingebrigtsen Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org, bugs@gnus.org Resent-Date: Mon, 24 Mar 2014 12:15:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 16784 X-GNU-PR-Package: emacs,gnus X-GNU-PR-Keywords: Original-Received: via spool by 16784-submit@debbugs.gnu.org id=B16784.1395663280305 (code B ref 16784); Mon, 24 Mar 2014 12:15:02 +0000 Original-Received: (at 16784) by debbugs.gnu.org; 24 Mar 2014 12:14:40 +0000 Original-Received: from localhost ([127.0.0.1]:46766 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1WS3m1-0008WS-0a for submit@debbugs.gnu.org; Mon, 24 Mar 2014 08:14:40 -0400 Original-Received: from hermes.netfonds.no ([80.91.224.195]:58618) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1WS3lv-0008WF-N5 for 16784@debbugs.gnu.org; Mon, 24 Mar 2014 08:14:35 -0400 Original-Received: from cm-84.215.51.58.getinternet.no ([84.215.51.58] helo=stories.gnus.org) by hermes.netfonds.no with esmtpsa (TLS1.0:DHE_RSA_AES_128_CBC_SHA1:16) (Exim 4.72) (envelope-from ) id 1WS3lc-00045l-Gx for 16784@debbugs.gnu.org; Mon, 24 Mar 2014 13:14:12 +0100 Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAElBMVEVBTFw4RFNNVWSOlaAy NkIkJi8NWn0KAAACeklEQVQ4ja1TS47lIAw0Fm8PiOyNQ+9bry8QMmafRHD/q0wx6t18VoMSlMh2 UVU2FH9fbm30h0D8VyDQd7H7reLrL+t/BnTt+/e7lr7xIuAiqxjvn4+W+KiSayr+2ImdJcosx3YI ISmyeI1IMNUy2ELioGttj6Zde6LXkIYsIpdUoh6lMcL1pou2+agLgXxAyLMyLRDAlmmnZBdICeBl FSQlGiaxOyWm5EPJ6b01fqOO6lSV4FujoDiG8JP3t6sU8+VitlTufqq3oO+P+bw10zYiBKZ8FhSI yyDVB0AohuAalLTkzmaRX2MvM30JZZuWWHo4/KHlJOWnWj+/SNgFlOfBDhC1wbH9c86H+lVi5iQ4 NYexekwQqJ20QHCf0dlw1ha+ioOB0DGbQdm4WCLSYgtQ7wQusD21j1TE+hHfZRu3gjlRFAbWaKhO GY5bwhElU57DTZVsUFUHi81TUlwWO9ezS/4qyIyGBhRweXR187Zz9Wi7gM1UL/UD7oq+7uKCt0ty kjmSenRRK6mfC13DK0hPkCETRsD/pS3ffVioI4NafhaFodRIttP/6ucLhLherh/af9BdW06aLQiy GYzhSXF9UmBifxazNqMAymy5DxP7gTG51qjVEWPjnjBTZU0iRrfPRL6fAOttWT5O3Ql88D3NMrF+ TBgoHQCVbnfACjHK4NInNjXMu1KJZuixZhETsN76o8zrjGmwoSJ3haXbcSplXOfJvaU1fqxOZcB9 OUbgQTrygM/zrJpxAsz3LWrGzZpG6JXWQ+cEdy3ecKGU7iaSSnLzYFhj+caInrElZLMUWB9Xtr5G bF9lA1Fq8Gba4jStD+jNGHo8PwFhzaukIiiSlAAAAABJRU5ErkJggg== X-Now-Playing: Fennesz, Sakamoto's _Flumina (1)_: "0404" X-Hashcash: 1:23:140324:sb@dod.no::mWS11y0hixPbV0OF:000000001x2Y X-Hashcash: 1:23:140324:16784@debbugs.gnu.org::heCoQt9f21DSz9cG:0000000000000000000000000000000000000002BlpQ In-Reply-To: (Steinar Bang's message of "Fri, 21 Mar 2014 11:33:59 +0100") User-Agent: Gnus/5.13001 (Ma Gnus v0.10) Emacs/24.3.50 (gnu/linux) X-MailScanner-ID: 1WS3lc-00045l-Gx MailScanner-NULL-Check: 1396268053.03873@8s6NeWIDwqpkkDOa4MiVOw X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.15 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x X-Received-From: 140.186.70.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.bugs:87297 Archived-At: Steinar Bang writes: >>>>>> Lars Magne Ingebrigtsen : > >> Ted Zlatanov writes: > SB> I would like one of the following solutions: > SB> 1. The possibility to switch off the attempted upgrade to STARTTLS for > SB> NNTP connections > >>> I think Lars has to give an opinion here. > >> I think we should always do encryption, even though we can't do validation. > > The reason I asked for this, is that if an ecryption I didn't ask for > causes the connection to fail, I would like to be able to turn it off > and have my unsafe connection. Yeah, but I's saying that the connection shouldn't fail. >"? If you didn't ask for encryption, but Emacs decides to do STARTTLS anyway, then Emacs should not do identity validation. Except perhaps just issue a message saying "couldn't validate TLS identity" or something at the most. -- (domestic pets only, the antidote for overdose, milk.) bloggy blog: http://lars.ingebrigtsen.no