Bug#492434: pidgin: Connects to Jabber server with bad SSL certificates, without warning

2008-08-03 Thread Miron Cuperman
As requested, NSS patch submitted to Pidgin in forwarded bug report, so there's no need to switch to GNUTLS. However, the second half of the patch above is still needed to grab CA certs from /etc/ssl/certs. Attaching just that part. --- pidgin-2.4.1/libpurple/certificate.c +++

Bug#492434: pidgin: Connects to Jabber server with bad SSL certificates, without warning

2008-08-02 Thread Miron Cuperman
I believe this bug was introduced with the fix for bug #401567. At that time, the SSL implementation was changed from GNUTLS to NSS. Unfortunately, the NSS plugin in pidgin does no certificate checking at all, meaning that any certificate is accepted (including malformed or self-signed