Empathy TLS error

Bug #1801429 reported by haggholm
24
This bug affects 5 people
Affects Status Importance Assigned to Milestone
empathy (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

When trying to connect to Google Talk from Empathy, I get an SSL error complaining about the certificate, which is allegedly

invalid2.invalid
Identity: invalid2.invalid
Verified by: invalid2.invalid
Expires: 01/01/30

This looks like the same kind of thing (caused by TLS 1.3?) as https://bugs.launchpad.net/ubuntu/cosmic/+source/fetchmail/+bug/1798786 (see also https://bugzilla.redhat.com/show_bug.cgi?id=1611815).

Tags: empathy tls
Revision history for this message
Robie Basak (racb) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better.

I'm not sure why this is filed against fetchmail?

You also haven't stated what version of empathy you're running nor what Ubuntu release you're running.

Changing the bug task to empathy for now, but marking it as Incomplete.

Unfortunately, we cannot work on this bug because your description didn't include enough information. You may find it helpful to read "How to report bugs effectively" http://www.chiark.greenend.org.uk/~sgtatham/bugs.html. We'd be grateful if you would then provide a more complete description of the problem. Once done, please change the bug status back to New.

affects: fetchmail (Ubuntu) → empathy (Ubuntu)
Changed in empathy (Ubuntu):
status: New → Incomplete
Revision history for this message
Jennifer Richards (jennifer-k) wrote :

This affects me as of updating to 18.10. All Google Talk accounts complain that the connection is untrusted. The certificate details show a CN of "invalid2.invalid" and an OU of "No SNI provided; please fix your client."

This completly blocks use of Empathy with Google Talk, as even trying to accept the untrusted connection fails to connect.

I traced this down last week and I believe this is caused by making a request using TLS1.3 without specifying the SNI properly. Google has apparently decided not to play along, instead rejecting such clients. This suggests that Empathy is incorrectly using TLS.

Changed in empathy (Ubuntu):
status: Incomplete → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.