Activity log for bug #1153289

Date Who What changed Old value New value Message
2013-03-10 15:24:13 Stefan Hammer bug added bug
2013-03-10 15:24:23 Stefan Hammer nominated for series tomdroid/beta
2013-03-10 15:24:23 Stefan Hammer bug task added tomdroid/beta
2013-03-10 15:24:23 Stefan Hammer nominated for series tomdroid/stable
2013-03-10 15:24:23 Stefan Hammer bug task added tomdroid/stable
2013-03-10 15:24:28 Stefan Hammer tomdroid/stable: milestone 0.6.1
2013-03-12 21:24:56 Stefan Hammer description We need to accept self signed SSL certificates to be able to sync securely with Rainy. Ideally it would look like this: On authentification (and on any other sync, the certificate could change...) we should catch the ssl exception, extract the certificate and show it to the user. If the user agrees, we will store the certificate and use it. For a quick fix we could just accept all certificates. Tomboy is doing it too. There is of course the chance of a man in the middle attack in this case. further reading: http://nelenkov.blogspot.co.at/2011/12/using-custom-certificate-trust-store-on.html http://developer.android.com/training/articles/security-ssl.html#UnknownCa http://stackoverflow.com/questions/2642777/trusting-all-certificates-using-httpclient-over-https We need to accept self signed SSL certificates to be able to sync securely with Rainy. Ideally it would look like this: On authentification (and on any other sync, the certificate could change...) we should catch the ssl exception, extract the certificate and show it to the user. If the user agrees, we will store the certificate and use it. For a quick fix we could just accept all certificates. There is of course the chance of a man in the middle attack in this case. further reading: http://nelenkov.blogspot.co.at/2011/12/using-custom-certificate-trust-store-on.html http://developer.android.com/training/articles/security-ssl.html#UnknownCa http://stackoverflow.com/questions/2642777/trusting-all-certificates-using-httpclient-over-https
2013-03-12 23:22:05 Stefan Hammer tomdroid/beta: status Triaged Fix Committed
2013-03-12 23:22:20 Stefan Hammer tomdroid/beta: assignee Stefan Hammer (j-4)
2013-03-13 10:39:33 Stefan Hammer tomdroid/stable: status New Fix Committed
2013-03-13 10:39:35 Stefan Hammer tomdroid/stable: assignee Stefan Hammer (j-4)
2013-03-18 22:18:56 Stefan Hammer tomdroid/stable: status Fix Committed Fix Released
2013-05-07 16:52:33 ˆ bug added subscriber ˆ
2013-10-24 10:06:38 Stefan Hammer tomdroid: status Fix Committed Fix Released