thunderbird's LDAP support requires SHA1

Bug #1658348 reported by James Troup
14
This bug affects 1 person
Affects Status Importance Assigned to Milestone
thunderbird (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

We recently tightened up the SSL ciphers offered by our corporate LDAP
server and it broke Thunderbird's LDAP integration. Specifically
Thunderbird couldn't connect unless SHA1 ciphersuites were offered by
the LDAP server.

Didn't work:

prio ciphersuite protocols pfs
1 AES256-SHA256 TLSv1.2 None None
2 AES128-SHA256 TLSv1.2 None None

olcTLSCipherSuite: NORMAL:-VERS-SSL3.0:-DHE-DSS:-ARCFOUR-128:-3DES-CBC:-CAMELLIA-128-CBC:-CAMELLIA-256-CBC:-SHA1

Did work:

prio ciphersuite protocols pubkey_size signature_algoritm trusted ticket_hint ocsp_staple npn pfs
1 AES256-SHA256 TLSv1.2 2048 sha256WithRSAEncryption True None False None None None
2 AES256-SHA TLSv1,TLSv1.1,TLSv1.2 2048 sha256WithRSAEncryption True None False None None None
3 AES128-SHA256 TLSv1.2 2048 sha256WithRSAEncryption True None False None None None
4 AES128-SHA TLSv1,TLSv1.1,TLSv1.2 2048 sha256WithRSAEncryption True None False None None None

olcTLSCipherSuite: NORMAL:-VERS-SSL3.0:-DHE-DSS:-ARCFOUR-128:-3DES-CBC:-CAMELLIA-128-CBC:-CAMELLIA-256-CBC

Revision history for this message
James Troup (elmo) wrote :

thunderbird is 1:45.5.1+build1-0ubuntu0.16.04.1 FWIW and slapd is 2.4.28-1.1ubuntu4.6 (from Ubuntu 12.04)

Revision history for this message
gf (gf-interlinks-deactivatedaccount) wrote :

Hello James,
Thank you for submitting this bug and reporting a problem with LDAP in Thunderbird. You made this bug report in 2017 and there have been several versions of Ubuntu and Thunderbird since then.

Could you confirm that this is no longer a problem and that we can close the ticket?
If it is still a problem, are you still interested in finding a solution to this bug?
If you are, could you run the following (only once):
apport-collect BUGNUMBER
and upload the updated logs and and any other logs that are relevant for this particular issue.

Thank you again for helping make Ubuntu and Thunderbird better.
G

Changed in thunderbird (Ubuntu):
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for thunderbird (Ubuntu) because there has been no activity for 60 days.]

Changed in thunderbird (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.