After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 551607 - Evolution: add a way to accept "bad" ssl certificate permanently.
Evolution: add a way to accept "bad" ssl certificate permanently.
Status: RESOLVED DUPLICATE of bug 328216
Product: evolution
Classification: Applications
Component: general
2.22.x (obsolete)
Other All
: Normal enhancement
: ---
Assigned To: Evolution Shell Maintainers Team
Evolution QA team
Depends on:
Blocks:
 
 
Reported: 2008-09-10 05:09 UTC by Nick Jenkins
Modified: 2010-05-20 18:24 UTC
See Also:
GNOME target: ---
GNOME version: Unversioned Enhancement



Description Nick Jenkins 2008-09-10 05:09:35 UTC
When you have an SSL certificate which is bad, then there does not seem to be any way to prevent being prompted about it every time that Evolution starts.

For example, every time I start up evolution, I get this prompt:
-------------------------------
Evolution warning:
SSL Certificate check for mail.dreamhost.com:

Issuer:            E=support@dreamhost.com,CN=New Dream Network Certificate Authority,OU=Security,O="New Dream Network, LLC",L=Los Angeles,ST=California,C=US
Subject:           E=support@dreamhost.com,CN=*.mail.dreamhost.com,OU=Security,O=Dreamhost.com,L=Brea,ST=California,C=US
Fingerprint:       17:f7:f2:ff:4a:9d:c3:d3:2b:8a:e9:12:47:c4:a4:28
Signature:         BAD

Do you wish to accept?   Cancel / OK
-------------------------------

This certificate is beyond my control, and it would be nice to be able to add it permanently. I have applied the following steps, but the problem persists:

* Open your web hosting site using https in firefox (I used my https webmail - https://webmail.dreamhost.com/ ).
* Double-click on the padlock icon in the status bar at the bottom of the window.
* Click on the security tab.
* Click view certificate.
* Click details.
* Click export.
* Save as an X.509 Certificate (first option).
* Open Evolution.
* Edit>Preferences>Certficates
* Click Import
* Browse to the certificate you just saved, click Open
* This successfully imports the certificate as a trusted authority, but I still get a prompt from evolution, presumably because the certificate name for the shared server doesn't match my mail server name.

The feature request is that it would be nice to be able to say on the "SSL Certificate check" dialog box "accept permanently" or "add as trusted certificate", to be able to solve this once and for all.

There is more discussion about this problem here:  http://ubuntuforums.org/showthread.php?t=800064

If it helps, this is in Evolution 2.22.3.1.
Comment 1 Andrea Mayer 2009-03-23 15:39:21 UTC
Can confirm this. However I would it consider as a minor bug than an enhancement because the Evolution warning messages gives the user the possibility to accept the certificate by clicking "OK" but it really doesn't accept it (but only for this one session)
Comment 2 bernhard 2009-03-23 18:22:58 UTC
would be great and save much time! thanks in advance
Comment 3 Milan Crha 2010-05-20 18:24:29 UTC
Thanks for the bug report. This particular bug has already been reported into our bug tracking system, but please feel free to report any further bugs you find.

*** This bug has been marked as a duplicate of bug 328216 ***