mirror of
https://github.com/jberkel/sms-backup-plus.git
synced 2026-04-26 01:15:58 +03:00
[GH-ISSUE #391] Is session encrypted when "SSL (Optional)" is set? #330
Labels
No labels
AM+RCS
FAQ
awaiting response
backup
bespoke
bug
calendar
call log
cannot reproduce
cloudless
device-specific
documentation
dual- & multi-SIM
duplicate
feature-request
fixed in beta
good first issue
half-missing
help wanted
helpful
meta
misattribution
mms
other message sources
pull-request
question
rejuvenation
restore
schedule
security
stale
task
thanks
v1.5.1
v1.5.10
v1.5.11
v1.5.2
v1.5.3
v1.5.3
v1.5.4
v1.5.4
v1.5.5
v1.5.5
v1.5.6
v1.5.7
v1.5.8
v1.5.9
v1.6β
xoauth
~$ bounty $~
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/sms-backup-plus-jberkel#330
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @krpage on GitHub (Nov 11, 2013).
Original GitHub issue: https://github.com/jberkel/sms-backup-plus/issues/391
When the "SSL (Optional)" option is set as advised to work around self-signed certificates, is the connection to the server still encrypted using SSL? i.e. is it just the certificate acceptance level that is lowered? (in which case perhaps there could be a clearer option description?)
@strayer commented on GitHub (Dec 11, 2013):
I wondered about this too. When setting "SSL (Optional)" it looks like the app actually uses STARTTLS over SSL.
Since I disabled unencrypted logins on my mailserver I'm pretty sure that this option only disables certificate verification, but I couldn't find anything helpful in the code since this seems to be buried in some K9 classes and I couldn't track that down :(
It would be nice if someone could look into this and maybe update the descriptions, as suggested in the issue.
My mailserver logs this:
Dec 11 21:49:41 localhost dovecot: imap-login: Login: user=<...>, method=PLAIN, rip=123.123.123.123, lip=321.321.321.321, mpid=123, TLS, session=<...>
Note the TLS.