Gnus development mailing list
 help / color / mirror / Atom feed
* Builtin GnuTLS support and certificate verification
@ 2013-11-02 11:22 Vincent Bernat
  2013-11-02 11:27 ` Julien Danjou
  0 siblings, 1 reply; 21+ messages in thread
From: Vincent Bernat @ 2013-11-02 11:22 UTC (permalink / raw)
  To: ding

Hi!

Now that Gnus is able to use the builtin TLS support shipped with Emacs,
we have no way to verify the remote certificate which leaves us open to
man-in-the-middle attacks.

Previously, changing `tls-program` to not use the `--insecure` switch
mades the deal.  Emacs builtin GNU TLS support allows certificate
verification but each application needs to enable it explicitely. I
didn't find any user switch to enable it globally or per application. Of
all the applications using GNU TLS, I have not found any that enables
this certificate verification stuff.

Is there a way to enable certificate verification for Gnus? If not, is
there a way to force the old way to do TLS (by using an external
program)?
-- 
Make sure all variables are initialised before use.
            - The Elements of Programming Style (Kernighan & Plauger)



^ permalink raw reply	[flat|nested] 21+ messages in thread

end of thread, other threads:[~2013-12-16 15:27 UTC | newest]

Thread overview: 21+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2013-11-02 11:22 Builtin GnuTLS support and certificate verification Vincent Bernat
2013-11-02 11:27 ` Julien Danjou
2013-11-02 17:40   ` Vincent Bernat
2013-11-02 21:09     ` Vincent Bernat
2013-11-03 11:53     ` Ted Zlatanov
2013-11-04 19:54       ` Vincent Bernat
2013-11-04 21:10         ` Ted Zlatanov
2013-11-04 22:38           ` Vincent Bernat
2013-11-11 15:45             ` Ted Zlatanov
2013-11-16 11:18               ` Vincent Bernat
2013-11-16 13:11                 ` Julien Danjou
2013-12-08  4:22                   ` Ted Zlatanov
2013-12-08  8:39                     ` Vincent Bernat
2013-12-08 16:08                       ` Ted Zlatanov
2013-12-14 18:06                         ` Ted Zlatanov
2013-12-16  1:39                           ` Katsumi Yamaoka
2013-12-16  6:31                             ` Herbert J. Skuhra
2013-12-16 13:51                               ` Tassilo Horn
2013-12-16 15:25                                 ` Ted Zlatanov
2013-12-16 15:24                               ` Ted Zlatanov
2013-12-16 15:27                             ` Ted Zlatanov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).