Pidgin fails to connect to MSN, citing an issue with omega.contacts.msn.com

Bug #677284 reported by Chow Loong Jin
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
pidgin (Ubuntu)
New
Undecided
Unassigned
Nominated for Maverick by Chow Loong Jin

Bug Description

Binary package hint: pidgin

When attempting to connect to MSN, Pidgin fails to load the contact list, citing an issue with the SSL certificate of omega.contacts.msn.com. This happened due to Microsoft renewing both the omega.contacts.msn.com certificate, as well as their certification authority certificate "Microsoft Secure Server Authority". Hence, the certificate in /usr/share/purple/ca-certs/Microsoft_Secure_Server_Authority.pem is outdated.

Replacing this certificate should fix this issue.

Revision history for this message
Chow Loong Jin (hyperair) wrote :
Revision history for this message
Chow Loong Jin (hyperair) wrote :

Okay, I think the problem seems a little deeper. It looks like omega.contacts.msn.com is being load-balanced between multiple mirrors, some of which have the new certificate, and some of which have the old certificate. So what happens is that Pidgin uses one server first, caches one certificate, and then switches to another server (they use DNS RR load-balancing) and then discovers that the other server does not use the same certificate and then crashes and burns. Deleting the omega.contacts.msn.com certificate fixes the issue temporarily until the next time the server is switched around.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.