kaddressbook cannot connect to ldap server if it cannot verify the secure connection

Bug #163737 reported by Nikos Mavrogiannopoulos
2
Affects Status Importance Assigned to Milestone
kdepim (Ubuntu)
Won't Fix
Undecided
Unassigned

Bug Description

Binary package hint: kaddressbook

If one tries to connect to an ldap server that uses ldaps (ssl tunnel for ldap) and the certificate verification fails, it does not offer an option to trust this certificate, or ignore the certificate status. It just fails. This is unacceptable, since for a self-signed certificate it will always fail and there is no way to override this.

Revision history for this message
Richard Birnie (rbirnie-deactivatedaccount) wrote :

Do you still see this bug? If so could you let us know what version of Ubuntu you are currently running and what version of kaddressbook.

thanks
Rich

Changed in kdepim:
status: New → Incomplete
Revision history for this message
Nikos Mavrogiannopoulos (nmavrogiannopoulos) wrote : Re: [Bug 163737] Re: kaddressbook cannot connect to ldap server if it cannot verify the secure connection

It still occurs to me. The problem is that the TLS handshake is
correctly completed (verified via wireshark) and then the client
(kaddressbook) sends alert notifying certificate is not trusted and
terminates the connection. At no point I get a pop up to accept this
certificate.

I have the latest ubuntu and

kaddressbook --version
Qt: 3.3.8b
KDE: 3.5.10
KAddressBook: 3.5.10

regards,
Nikos

On Tue, Sep 23, 2008 at 9:19 PM, Richard Birnie <email address hidden> wrote:
> Do you still see this bug? If so could you let us know what version of
> Ubuntu you are currently running and what version of kaddressbook.
>
> thanks
> Rich
>
> ** Changed in: kdepim (Ubuntu)
> Status: New => Incomplete
>
> --
> kaddressbook cannot connect to ldap server if it cannot verify the secure connection
> https://bugs.launchpad.net/bugs/163737
> You received this bug notification because you are a direct subscriber
> of the bug.
>

Changed in kdepim:
status: Incomplete → New
Revision history for this message
Richard Birnie (rbirnie-deactivatedaccount) wrote :

Thanks for following up sorry for the slow response

Is this only a problem with ldap or does it occur for any https/SSL system? I don't know much about ldap I'm afraid. I discussed this with some developers over irc and we wondered if it was a generic problem with not getting pop-ups for untrusted certificates.

For the sake of eliminating the obvious. Have you ever had the pop up display correctly for an untrusted certificate? That box should have options for 'deny' and 'don't show again' or words to that effect. Does anyone else use the machine and is it possible they could have clicked deny and don't show again?

Changed in kdepim:
status: New → Incomplete
Revision history for this message
Nikos Mavrogiannopoulos (nmavrogiannopoulos) wrote :

Richard Birnie wrote:
> Thanks for following up sorry for the slow response
>
> Is this only a problem with ldap or does it occur for any https/SSL
> system? I don't know much about ldap I'm afraid. I discussed this with
> some developers over irc and we wondered if it was a generic problem
> with not getting pop-ups for untrusted certificates.

In konqueror I had pop up for untrusted certificates and if I point
konqueror to the same server using https at port 636 I get a pop up.

> options for 'deny' and 'don't show again' or words to that effect. Does
> anyone else use the machine and is it possible they could have clicked
> deny and don't show again?

No this is not the case. I'm the only user in that pc.

regards,
Nikos

Changed in kdepim:
status: Incomplete → New
Revision history for this message
Jonathan Thomas (echidnaman) wrote :

KAddressBook has been deemed unmaintained by the KDE team, since they are rewriting it for KDE 4.4. This means that we cannot provide bugfixes for the pre-4.4 version. Thanks for understanding and have a nice day.

Changed in kdepim (Ubuntu):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.