Your message dated Fri, 4 Apr 2008 21:08:00 +0200
with message-id <[EMAIL PROTECTED]>
and subject line Re: Bug#463978: empathy: Not trusted SSL would not allow 
connect
has caused the Debian Bug report #463978,
regarding empathy: Not trusted SSL would not allow connect
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
463978: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463978
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: empathy
Version: 0.21.5.2-1
Severity: normal

Hi,
I'm not sure if this belongs to empathy or telepathy-gabble. Anyway:

I just upgraded empathy and it decided to not trust my server's SSL
certificate showing up and error with no option to trust the server
certificate which would leave the average user with an empty contact
list and an error without any options ;(

I found out that: /apps/telepathy/mc/accounts/jabber0/param-old-ssl
set to True in gconf would solve the problem, but "param-old-ssl"
seems to mean "I'm gonna disappear" so, maybe empathy should provide
someway to Trust server certificates or at least give some direction
to the user on what to do.

On the meantime, maybe "param-old-ssl" should default to True to not
screw things for the users which could have trouble solving the
problem (Not everybody would look into gconf).

Cheers,
Marc

PS: How can I make telepathy trust my server's certificate? ;))

-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (900, 'testing'), (500, 'gutsy'), (300, 'unstable'), (150, 
'experimental'), (100, 'stable')
Architecture: i386 (i686)

Kernel: Linux 2.6.24-1-686 (SMP w/2 CPU cores)
Locale: LANG=es_ES.UTF-8, LC_CTYPE=es_ES.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages empathy depends on:
ii  libaspell15                0.60.5-1      GNU Aspell spell-checker runtime l
ii  libatk1.0-0                1.20.0-1      The ATK accessibility toolkit
ii  libbonobo2-0               2.20.3-1      Bonobo CORBA interfaces library
ii  libc6                      2.7-6         GNU C Library: Shared libraries
ii  libcairo2                  1.4.14-1      The Cairo 2D vector graphics libra
ii  libdbus-1-3                1.1.2-1       simple interprocess messaging syst
ii  libdbus-glib-1-2           0.74-1        simple interprocess messaging syst
ii  libebook1.2-9              1.12.3-1      Client library for evolution addre
ii  libedataserver1.2-9        1.12.3-1      Utility library for evolution data
ii  libempathy-gtk9            0.21.5.2-1    High-level library and user-interf
ii  libempathy7                0.21.5.2-1    High-level library and user-interf
ii  libgconf2-4                2.20.1-2+b1   GNOME configuration database syste
ii  libglade2-0                1:2.6.2-1     library to load .glade files at ru
ii  libglib2.0-0               2.14.5-2      The GLib library of C routines
ii  libgnome2-0                2.20.1.1-1    The GNOME 2 library - runtime file
ii  libgnomevfs2-0             1:2.20.1-1    GNOME Virtual File System (runtime
ii  libgtk2.0-0                2.12.5-2      The GTK+ graphical user interface 
ii  libmissioncontrol-client0  4.55-1        Library to interact with Telepathy
ii  liborbit2                  1:2.14.10-0.1 libraries for ORBit2 - a CORBA ORB
ii  libpango1.0-0              1.19.3-1      Layout and rendering of internatio
ii  libpopt0                   1.10-3        lib for parsing cmdline parameters
ii  libtelepathy-glib0         0.7.0-1       Telepathy framework - GLib connect
ii  libtelepathy2              0.3.1-1       Telepathy framework - GLib library
ii  libx11-6                   2:1.0.3-7     X11 client-side library
ii  libxml2                    2.6.31.dfsg-1 GNOME XML library

Versions of packages empathy recommends:
ii  telepathy-gabble              0.7.1-1    Jabber/XMPP connection manager
ii  telepathy-salut               0.3.0-1    Link-local XMPP connection manager

-- no debconf information



--- End Message ---
--- Begin Message ---
Package: empathy
Version: 0.22.0-1
Thanks,

On Mon, Feb 04, 2008 at 02:04:31PM +0100, Marc Fargas wrote:
> Package: empathy
> Version: 0.21.5.2-1
> Severity: normal
> 
> Hi,
> I'm not sure if this belongs to empathy or telepathy-gabble. Anyway:
> 
> I just upgraded empathy and it decided to not trust my server's SSL
> certificate showing up and error with no option to trust the server
> certificate which would leave the average user with an empty contact
> list and an error without any options ;(
> 
> I found out that: /apps/telepathy/mc/accounts/jabber0/param-old-ssl
> set to True in gconf would solve the problem, but "param-old-ssl"
> seems to mean "I'm gonna disappear" so, maybe empathy should provide
> someway to Trust server certificates or at least give some direction
> to the user on what to do.
> 
> On the meantime, maybe "param-old-ssl" should default to True to not
> screw things for the users which could have trouble solving the
> problem (Not everybody would look into gconf).

The current default is to not require encryption. If you server supports TLS
then gabble will always try to use TLS, but it will ignore SSL errors.

> PS: How can I make telepathy trust my server's certificate? ;))

That's a bit of an unanswered questions. Debians loudmouth should trust your
server certificate if it's in the standard ssl locations. The other part is
that there are currently no mechanisms in telepathy to ask the UI about
certifcate errors. We're still pondering on the right way to make that happen

Closing it for now as the UI provides the user with enough configuration
options to ignore ssl errors.

  Sjoerd
-- 
Research is the best place to be: you work your buns off, and if it works
you're a hero; if it doesn't, well -- nobody else has done it yet either,
so you're still a valiant nerd.


--- End Message ---

Reply via email to