Re: No SSL on fetchmail?



On 2007-03-30, Garen Erdoisa <gerdoisa@xxxxxxxxxxxx> wrote:
Longfellow wrote:
How does one turn off SSL on fetchmail, or is that possible?


It depends on the port you connect to.

From man fetchmail:

<quote>
--ssl (Keyword: ssl) Causes the connection to the mail server to be
encrypted via SSL. Connect to the server using the specified base
protocol over a connection secured by SSL. SSL support must be present
at the server. If no port is specified, the connection is attempted
to the well known port of the SSL version of the base protocol. This is
generally a different port than the port used by the base protocol.
For IMAP, this is port 143 for the clear protocol and port 993 for the
SSL secured protocol.
</quote>

So, if you want to use fetchmail on an IMAP server without using SSL,
then have it connect to the server using port 143, or to port 110 for POP3.

I'd recommend that you continue to use SSL if your server supports it,
else you'll be sending your login username and password over an insecure
link each time fetchmail connects to the server.

Aha, that clarifies things. SSL with POP3 connects to a different port
than 110, then?

My ISP just upgraded their pop3 server software, causing interesting
stuff with windows machines, and causing no connectability for me. So I
called them up and they told be "click on..." at which point I told them
I wasn't running windows (dead silence). Finally the guy said that the
new software didn't support SSL. I asked him when that support would be
avaiable and he told me it would not be available, period.

So I reedited .muttrc to download and got mail that way (lots of hand
moving to different mailboxes... arggh) and a .muttrc1 for the second
mail box (#$%%^&). The I telneted into 110 and checked STAT for each
mailbox, and I'd gotten it all. So I killed the fetchmail daemon and
tried to figure out where to go from there. Wound up posting here.

On a hunch, I fired up the fetchmail daemon and turned out the light,
figuring come what may. Hours later, I sat down and turned on the
light, monitor came up and lo and behold, there was mail in all boxes!

I'm going to stop by the ISP today and ask what is going on. I think
the tech guy just didn't know what he was talking about, or maybe they
got enough complaints that they "did something".

I've got aDSL 24/7 to the ISP. The guy intimated that if there was a
packet sniffer, it would be on my own LAN (???), apparently implying
that nothing of the sort would be possible between my gateway and the
ISP. Don't know what's going on, but hope to find out.

Thanks,

Longfellow

.



Relevant Pages

  • Re: outlook express wont connect using ssl
    ... my smtp VS which is on 587 to the same settings as my default server ... the only difference is the port #. ... As soon as the cert has been added, SSL ...
    (microsoft.public.exchange.admin)
  • Re: outlook express wont connect using ssl
    ... my smtp VS which is on 587 to the same settings as my default server ... the only difference is the port #. ... SSL ...
    (microsoft.public.exchange.admin)
  • Re: No SSL on fetchmail?
    ... It depends on the port you connect to. ... encrypted via SSL. ... Connect to the server using the specified base ... This means you have to setup SSL server certificates for the pop3 and imap servers which are signed by a trusted certificate authority. ...
    (comp.mail.misc)
  • Re: SMTP using TCP port 587 /w SSL
    ... No support for client certificates. ... One solution is to point your SSL SMTP clients at an SSL-capable SMTP server ... In conclusion, Exchange supports RFC2487 standard TLS, but Outlook Express only supports it on port 25. ... However, I can setup OE6 to use SSL in a different> port, too, but when I send a mail, it always return something like this:> ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Need a fetchmail guru (JoAnne D.?) whos been using it to pop his/her gmail
    ... they flushed unless you tell fetchmail to --keep them. ... poll pop.gmail.com with proto pop3 ... options ssl ... and no port # is spec'd. ...
    (Fedora)