You can subscribe to this list here.
2004 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
(16) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(1) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2005 |
Jan
(2) |
Feb
|
Mar
(4) |
Apr
|
May
|
Jun
|
Jul
(8) |
Aug
(21) |
Sep
(17) |
Oct
(35) |
Nov
(39) |
Dec
(55) |
2006 |
Jan
(70) |
Feb
(11) |
Mar
(55) |
Apr
(27) |
May
(73) |
Jun
(47) |
Jul
(63) |
Aug
(27) |
Sep
(52) |
Oct
(39) |
Nov
(87) |
Dec
(15) |
2007 |
Jan
(23) |
Feb
(46) |
Mar
(108) |
Apr
(63) |
May
(54) |
Jun
(34) |
Jul
(29) |
Aug
(103) |
Sep
(46) |
Oct
(69) |
Nov
(29) |
Dec
(17) |
2008 |
Jan
(45) |
Feb
(32) |
Mar
(25) |
Apr
(17) |
May
(39) |
Jun
(20) |
Jul
(64) |
Aug
(31) |
Sep
(38) |
Oct
(20) |
Nov
(42) |
Dec
(50) |
2009 |
Jan
(10) |
Feb
(38) |
Mar
(3) |
Apr
(29) |
May
(41) |
Jun
(31) |
Jul
(21) |
Aug
(53) |
Sep
(49) |
Oct
(26) |
Nov
(28) |
Dec
(15) |
2010 |
Jan
(83) |
Feb
(38) |
Mar
(33) |
Apr
(44) |
May
(9) |
Jun
(16) |
Jul
(35) |
Aug
(38) |
Sep
(11) |
Oct
(35) |
Nov
(68) |
Dec
(19) |
2011 |
Jan
(16) |
Feb
(69) |
Mar
(42) |
Apr
(54) |
May
(56) |
Jun
(29) |
Jul
|
Aug
(65) |
Sep
(3) |
Oct
(39) |
Nov
(33) |
Dec
(4) |
2012 |
Jan
(31) |
Feb
(21) |
Mar
(26) |
Apr
(13) |
May
(38) |
Jun
(39) |
Jul
(14) |
Aug
(31) |
Sep
(8) |
Oct
(32) |
Nov
(12) |
Dec
(16) |
2013 |
Jan
(40) |
Feb
(22) |
Mar
(21) |
Apr
(15) |
May
(13) |
Jun
(9) |
Jul
(34) |
Aug
(10) |
Sep
(10) |
Oct
|
Nov
(7) |
Dec
(1) |
2014 |
Jan
(25) |
Feb
(9) |
Mar
(8) |
Apr
(12) |
May
(7) |
Jun
|
Jul
(7) |
Aug
(4) |
Sep
(27) |
Oct
(25) |
Nov
(18) |
Dec
(3) |
2015 |
Jan
(18) |
Feb
(13) |
Mar
(4) |
Apr
(19) |
May
(11) |
Jun
|
Jul
(1) |
Aug
(7) |
Sep
(6) |
Oct
(4) |
Nov
(19) |
Dec
(6) |
2016 |
Jan
|
Feb
(8) |
Mar
(14) |
Apr
|
May
(11) |
Jun
|
Jul
(2) |
Aug
(3) |
Sep
(10) |
Oct
|
Nov
(11) |
Dec
(17) |
2017 |
Jan
(17) |
Feb
(35) |
Mar
|
Apr
(4) |
May
(8) |
Jun
(2) |
Jul
(16) |
Aug
|
Sep
(5) |
Oct
(11) |
Nov
(15) |
Dec
(10) |
2018 |
Jan
|
Feb
(3) |
Mar
|
Apr
(3) |
May
(2) |
Jun
(8) |
Jul
|
Aug
(10) |
Sep
(17) |
Oct
(15) |
Nov
(12) |
Dec
(10) |
2019 |
Jan
(4) |
Feb
(14) |
Mar
(33) |
Apr
(17) |
May
(7) |
Jun
(6) |
Jul
(2) |
Aug
(4) |
Sep
(22) |
Oct
(13) |
Nov
|
Dec
|
2020 |
Jan
(36) |
Feb
(19) |
Mar
(31) |
Apr
(2) |
May
(22) |
Jun
(7) |
Jul
(25) |
Aug
(9) |
Sep
(17) |
Oct
(52) |
Nov
(13) |
Dec
(9) |
2021 |
Jan
(23) |
Feb
(13) |
Mar
(9) |
Apr
(15) |
May
(3) |
Jun
(7) |
Jul
(4) |
Aug
(23) |
Sep
(3) |
Oct
(8) |
Nov
(28) |
Dec
(9) |
2022 |
Jan
(38) |
Feb
(2) |
Mar
(56) |
Apr
(24) |
May
(29) |
Jun
(22) |
Jul
(6) |
Aug
(1) |
Sep
|
Oct
(13) |
Nov
(2) |
Dec
|
2023 |
Jan
(6) |
Feb
(1) |
Mar
(1) |
Apr
(4) |
May
|
Jun
|
Jul
(21) |
Aug
(5) |
Sep
(1) |
Oct
|
Nov
(5) |
Dec
|
2024 |
Jan
(15) |
Feb
(4) |
Mar
|
Apr
(4) |
May
(11) |
Jun
(9) |
Jul
(1) |
Aug
|
Sep
(9) |
Oct
(9) |
Nov
(1) |
Dec
(1) |
2025 |
Jan
(7) |
Feb
|
Mar
|
Apr
(3) |
May
|
Jun
(10) |
Jul
|
Aug
(1) |
Sep
(12) |
Oct
(11) |
Nov
|
Dec
|
From: jdebert <jd...@ga...> - 2014-03-17 04:37:03
|
Hi, I'm trying to track down what's causing mail received via IMAP4 using fetchmail have mangled Subject lines when the Subject is not ASCII. This appears in the ISP mailbox: Subject: [opensuse-ja] =?ISO-2022-JP?B?UmU6IFtvcGVuc3VzZS1qYV0gTGlicmVvZmZpY2Ugd3JpdGUgGyRCSUEyaExkQmobKEI=?= and it is received locally like this: Subject: [opensuse-ja] Re: [opensuse-ja] Libreoffice write $BIA2hLdBj(B Is it the IMAP protocol doing the mangling? If so, is there a fetchmail option to resolve this? Any help would be most appreciated! jd |
From: Matthias A. <mat...@gm...> - 2014-02-21 09:36:41
|
Am 20.02.2014 21:09, schrieb Matthias Andree: > Am 20.02.2014 09:51, schrieb sup...@gm...: >>> I am not seeing that, which is the reason why I referred you to the FAQ >>> to provide more information. Including the version number of fetchmail >>> and your detailed configuration - chances are that the bug has been >>> fixed years ago, and chances are that I'm not finding it because I lack >>> the configuration to reproduce your exact situation. The logging logic >>> used under fetchmail's hood is quite complex. >> >> >> As it turns out I am using IMAP (it is a bit early here and I just conflated pop/imap) >> > > As the FAQ URL will tell you, outdated versions are unsupported. Which is to say: Please check if 6.3.26 already solves your problems. It has been out for a while, and it has accumulated several logging patches over time, as you can see here: <https://gitorious.org/fetchmail/fetchmail/source/3a2c448860a3902f75ef05b21711a8a9c1592677:NEWS#L65> or here: <http://sourceforge.net/p/fetchmail/git/ci/legacy_63/tree/NEWS> |
From: Matthias A. <mat...@gm...> - 2014-02-20 21:09:50
|
Am 20.02.2014 09:51, schrieb sup...@gm...: >> I am not seeing that, which is the reason why I referred you to the FAQ >> to provide more information. Including the version number of fetchmail >> and your detailed configuration - chances are that the bug has been >> fixed years ago, and chances are that I'm not finding it because I lack >> the configuration to reproduce your exact situation. The logging logic >> used under fetchmail's hood is quite complex. > > > As it turns out I am using IMAP (it is a bit early here and I just conflated pop/imap) > As the FAQ URL will tell you, outdated versions are unsupported. |
From: <sup...@gm...> - 2014-02-20 09:51:07
|
> I am not seeing that, which is the reason why I referred you to the FAQ > to provide more information. Including the version number of fetchmail > and your detailed configuration - chances are that the bug has been > fixed years ago, and chances are that I'm not finding it because I lack > the configuration to reproduce your exact situation. The logging logic > used under fetchmail's hood is quite complex. As it turns out I am using IMAP (it is a bit early here and I just conflated pop/imap) fetchmail -V This is fetchmail release 6.3.19+POP2+GSS+RPA+NTLM+SDPS+SSL+OPIE+NLS+KRB5. poll xxxx.xxxx.xxxx protocol imap port 993 user "xxxxx" pass "xxxxx" ssl keep smtphost localhost smtpname xxxxx fetchlimit 500 set daemon 30 set logfile /home/xxxxx/.fetchmail.log |
From: Matthias A. <mat...@gm...> - 2014-02-20 09:43:00
|
Am 20.02.2014 09:32, schrieb sup...@gm...: > I'll answer all these posts at once: > > fetchmail -s - that is what I am using now, I would prefer to keep logging messages > delivered and errors rather than just errors but this is better than nothing - thanks. I > am using deamon mode. > > I don't have access to an imap server and the pop3 server is very lightly loaded - > which is why I'm using pop3. > > It would be nice to have a slightly more configurable logging system and I'd consider > hammering the log file with repeated noflush messages a bit of a bug - surely > reporint this once for each message is enough? but it isn't that big a deal. I am not seeing that, which is the reason why I referred you to the FAQ to provide more information. Including the version number of fetchmail and your detailed configuration - chances are that the bug has been fixed years ago, and chances are that I'm not finding it because I lack the configuration to reproduce your exact situation. The logging logic used under fetchmail's hood is quite complex. |
From: <sup...@gm...> - 2014-02-20 09:33:02
|
I'll answer all these posts at once: fetchmail -s - that is what I am using now, I would prefer to keep logging messages delivered and errors rather than just errors but this is better than nothing - thanks. I am using deamon mode. I don't have access to an imap server and the pop3 server is very lightly loaded - which is why I'm using pop3. It would be nice to have a slightly more configurable logging system and I'd consider hammering the log file with repeated noflush messages a bit of a bug - surely reporint this once for each message is enough? but it isn't that big a deal. Cheers, SA |
From: Matthias A. <mat...@gm...> - 2014-02-20 00:14:39
|
Am 20.02.2014 00:12, schrieb Matthias Andree: > Am 19.02.2014 13:20, schrieb sup...@gm...: >> >> I need to use a log file with fetchmail but the log files grow very quickly >> and fill up with lots of non useful information. I need to leave message on >> my server and every time the server is polled I get this: >> >> fetchmail: skipping message xxxxxx not flushed repeated 1000s of times once for >> each message stored on the server - I'm loging 50k+ every minute. Since I poll a >> copuple of times a minute this file growes extremely large very quickly. >> >> I assumed there was a way to configure fetchmail to change what it logs, maybe only >> report errors and mail it actually fetches but I can't find any way to suppress the rest. >> >> Is there an easy way to do this? > > See <http://www.fetchmail.info/fetchmail-FAQ.html#G3>. > > Also report the options you usually use - in daemon mode and without -v > there should not be excess logging. In doubt, try fetchmail -s. Note that "daemon mode" means you use -d 300 or similar, or "set daemon 300" in your configuration (run control) file. |
From: Matthias A. <mat...@gm...> - 2014-02-20 00:12:06
|
Am 19.02.2014 13:20, schrieb sup...@gm...: > > I need to use a log file with fetchmail but the log files grow very quickly > and fill up with lots of non useful information. I need to leave message on > my server and every time the server is polled I get this: > > fetchmail: skipping message xxxxxx not flushed repeated 1000s of times once for > each message stored on the server - I'm loging 50k+ every minute. Since I poll a > copuple of times a minute this file growes extremely large very quickly. > > I assumed there was a way to configure fetchmail to change what it logs, maybe only > report errors and mail it actually fetches but I can't find any way to suppress the rest. > > Is there an easy way to do this? See <http://www.fetchmail.info/fetchmail-FAQ.html#G3>. Also report the options you usually use - in daemon mode and without -v there should not be excess logging. In doubt, try fetchmail -s. |
From: Gene H. <ghe...@wd...> - 2014-02-19 18:00:53
|
On Wednesday 19 February 2014 11:14:04 sup...@gm... did opine: > I need to use a log file with fetchmail but the log files grow very > quickly and fill up with lots of non useful information. I need to > leave message on my server and every time the server is polled I get > this: > > fetchmail: skipping message xxxxxx not flushed repeated 1000s of times > once for each message stored on the server - I'm loging 50k+ every > minute. Since I poll a copuple of times a minute this file growes > extremely large very quickly. > > I assumed there was a way to configure fetchmail to change what it logs, > maybe only report errors and mail it actually fetches but I can't find > any way to suppress the rest. > > Is there an easy way to do this? > > Ta SA > wow, an actual email from the fetchmail list! Its been a month or more! I can't answer your question except to suggest doing the unixish idea of putting a grep session between fetchmail's logging output, and the log. I don't but I have the log setup in the logrotate scheme for automatic maintenance making logfile sizes a non-worry here. As I also use mailfilter, called from a fetchmail pre-connect setup, mailfilters important details are then interspersed in the fetchmail log. When I want to watch for FP's going by, I do a tail -fn500 /var/log/fetchmail.log|grep Deny - and see only that which mailfilter has denied, (a mailfilter deny means it was deleted from the server and never even downloaded) and why. Its often 250 character lines to scan thru but it works. A sample output line: mailfilter: Deny: THRINAXODON <bio...@gm...>: NEW STUNNING RESEARCH DISPROVES EVOLUTIONARY FAIRY-TALES, Wed, 19 Feb 2014 08:30:06 -0800 (PST) ["^Injection-Info:.*glegroups" matches "Injection-Info: glegroupsg2000goo.googlegroups.com; posting-host=108.7.207.66; posting- account=0tXOfgoAAADN80t3OPNQdANuhlP13P3k "]. google-groups are a great source of spam, I block the whole thing. ;-) The point being that a similar command line type approach can reduce the size of the data stored if that is a concern. Since the logfile is a command line in your .fetchmailrc, it may be possible to do the filtering right in that line that is intended to specify where the logfile is kept. But that is not something I have actually tried. If you make it work, please post how you did it so that others can also learn this new trick. > _______________________________________________ > fetchmail-users mailing list > fet...@li... > https://lists.berlios.de/mailman/listinfo/fetchmail-users Cheers, Gene -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene> NOTICE: Will pay 100 USD for an HP-4815A defective but complete probe assembly. |
From: <sup...@gm...> - 2014-02-19 13:20:22
|
I need to use a log file with fetchmail but the log files grow very quickly and fill up with lots of non useful information. I need to leave message on my server and every time the server is polled I get this: fetchmail: skipping message xxxxxx not flushed repeated 1000s of times once for each message stored on the server - I'm loging 50k+ every minute. Since I poll a copuple of times a minute this file growes extremely large very quickly. I assumed there was a way to configure fetchmail to change what it logs, maybe only report errors and mail it actually fetches but I can't find any way to suppress the rest. Is there an easy way to do this? Ta SA |
From: Joe Acquisto-j. <jo...@j4...> - 2014-01-31 12:40:09
|
> Thanks for volunteering that info. I may now have enough to continue on my > own for a bit. I'll post back in within a few days. Quick as a flash, exporting the root and chain from FF 26 and rehashing, cleared up the CA complaints. Still tells me the connection is insecure, tho. |
From: Joe Acquisto-j. <jo...@j4...> - 2014-01-31 01:39:26
|
>>> On 1/30/2014 at 2:55 PM, Matthias Andree <mat...@gm...> wrote: > Am 26.01.2014 18:42, schrieb Joe Acquisto-j4: >>> Figured it out. The docs are clear enough, once read. Compiled and >>> running. >>> >>> Still getting noise about certs, but much more descriptive. Still fetching, > >>> so, I'll leave the sleuthing for another day. >>> >>> joe a. >>> >> >> Try as I might, I still get this error, which I presume means it does not > like or >> cannot find the "my side" cert: >> >> fetchmail: Server certificate verification error: unable to get local issuer > certificate >> >> Also get this one, which I presume is the ISP end's problem (obfuscated CN): >> >> fetchmail: Broken certification chain at: /C=US/O=GeoTrust, Inc./CN=xxxxSSL > CA > > If you require help from here onwards, you will have to provide > unadulterated logs, per instructions laid out at > <http://www.fetchmail.info/fetchmail-FAQ.html#G3>. > > The only advised munging is your removing unaffected account logging, > and removing password exchange dialogs if there are digests or thereabouts. > > I understand the desire for privacy, but theorizing about what might > have gone wrong in cases of DNS or SSL trouble is not taking us anywhere. > > Make sure that you have the root certificate that signed the server's > certification chain in the "trust store" for OpenSSL. > > The default location is OpenSSL's default path (usually > /etc/ssl/certs/*.0 or /usr/ssl/certs/*.0 - you get the .0 symlinks by > installing a .pem file into that directory and running c_rehash > afterwards), or you can use the sslcertfile or sslcertpath options to > point fetchmail to trusted files. If you have the root certificate for > the chain, save it in PEM format and run > > fetchmail --sslcertfile /path/for/that/file.pem > > and see if that helps. Many up-to-date distributions ship with a set of > trust anchors from the mozilla project, the packages are often called > ca-certificates, root-certificates, or similar. > _______________________________________________ > fetchmail-users mailing list > fet...@li... > https://lists.berlios.de/mailman/listinfo/fetchmail-users Thanks for volunteering that info. I may now have enough to continue on my own for a bit. I'll post back in within a few days. |
From: Matthias A. <mat...@gm...> - 2014-01-30 21:15:19
|
Am 29.01.2014 05:06, schrieb com...@bl...: > Hi, all, > > since over 12 years I'm using fetchmail to poll a bunch of mail > accounts at different providers using POP3. > > I've successfully compiled and used versions fetchmail-5.9.11, > fetchmail-5.9.12, fetchmail-5.9.13, Fetchmail-6.3.9, and > Fetchmail-6.3.26 on various versions of Linux. I'm also > subscribed to the fetchmail mailing lists - upon now as reader > only. > > So, I could claim NOT to be a newbie in respect to fetchmail, and > I here say a big THANK YOU for all the efforts in maintaining > and developing this program. > > BUT, I'm a total newbie in respect of SSL :-( > > A couple of weeks ago, one of my providers made SSL mandatory > and I (think) I got it for this one. > > But now, another provider makes SSL mandatory too and I'm in > big trouble, since it doesn't work :-( > > I've read the README.SSL and I also visited the mentioned > openssl website hoping to download certificates. But they > now claim NOT to provide certificates any more. > > Now I'm a bit confused :-( > > The only change of my setup, was to insert keyword 'ssl' > into my .fetchmailrc file. I noticed, that fetchmail now > tries to poll via port 995 (the provider's docu also tells > to use this port) - without ssl port 110 was polled. > > I'm NOT sure whether it's a problem with their serverside > software or whether I should provide any sort of local > certificate - and in the latter case: how to do this.. > > My question: What to do next ? > > Here the info/files (a bit obfuscated) You may need to give > me any helpful hints: > >> === f-V.txt ========================================== >> >> This is fetchmail release 6.3.26+SSL+NLS. >> >> Copyright (C) 2002, 2003 Eric S. Raymond >> Copyright (C) 2004 Matthias Andree, Eric S. Raymond, >> Robert M. Funk, Graham Wilson >> Copyright (C) 2005 - 2012 Sunil Shetye >> Copyright (C) 2005 - 2013 Matthias Andree >> Fetchmail comes with ABSOLUTELY NO WARRANTY. This is free software, and you >> are welcome to redistribute it under certain conditions. For details, >> please see the file COPYING in the source or documentation directory. >> This product includes software developed by the OpenSSL Project >> for use in the OpenSSL Toolkit. (http://www.openssl.org/) >> >> Fallback MDA: (none) >> Linux MYMACHINE 2.6.27.7-9-pae #1 SMP 2008-12-04 18:10:04 +0100 i686 i686 i386 GNU/Linux >> Taking options from command line >> >> === .fetchmailrc.new.nokill.WEBB ===================== >> >> set idfile /home/Fetchmail/Id/.fetchids.WEBB >> set postmaster=webm-bla >> >> poll pop3.PROVIDER-1.de >> proto pop3 >> no dns >> uidl >> tracepolls >> auth password >> >> user web...@MY... is webm-bla >> pass TOPSECRET >> ssl >> >> keep >> nofetchall >> norewrite >> >> === cmd.fm =========================================== >> >> fetchmail -v --fetchlimit 0 -c -f /home/Fetchmail/Rc/.fetchmailrc.new.nokill.WEBB >& fm-c.log.3 >> >> === fm-c.log.3 ======================================= >> >> fetchmail: --check mode enabled, not fetching mail >> fetchmail: 6.3.26 querying pop3.PROVIDER-1.de (protocol POP3) at Tue 28 Jan 2014 07:52:26 PM CET: poll started >> Trying to connect to 22.222.222.222/995...connected. >> fetchmail: Server certificate verification error: unable to get local issuer certificate >> fetchmail: Broken certification chain at: /C=DE/O=Deutsche Telekom AG/OU=T-TeleSec Trust Center/CN=Deutsche Telekom Root CA 2 So this (after CN= at the end) is the root certificate you need to install. Depending on your distribution there is a package with Mozilla's collection of root certificates - just installing that package should fix the problem. Typical package names are: ca-certificates (Ubuntu 12.04, Fedora 20) ca-certificates-mozilla (openSUSE) ca_root_nss (FreeBSD ports) Other than that, you can download the certificate from <http://www.telesec.de/pki/roots.html>. |
From: Matthias A. <mat...@gm...> - 2014-01-30 21:08:51
|
Am 24.01.2014 18:21, schrieb Christoph Schmidt: > Hi, (sorry, not used to the rules of this mailing list) Please do not reply to digests, but unpack the digest and reply to an individual message, else you will be starting new threads and I may miss your questions. In doubt, subscribe to the plaintext version. > thanks for the answer and hints. > I thought the scenario was clear - but anyway I added the configuration > file : > Here the working one : > poll "pop.t-online.de" envelope "X-envelope-to:" protocol POP3 aka > t-online.de no dns : user "xy" there with password "secret" is * here > fetchall nokeep ; > > This works since years. > isp switches now to ssl, which creates the need of changes to something > like : > poll "securepop.t-online.de" envelope 'X-ENVELOPE-TO:' protocol POP3 no > dns : user "xy" there with password "secret" is * here fetchall nokeep > ssl > sslfingerprint "CE:CF:FE:44:69:3A:EF:EF:73:42:97:60:B0:41:95:35" > sslcertck > sslcertpath /etc/ssl/fetchmaild/certs/; > > But this results in /var/log/mail.info : > Jan 24 15:11:10 NasenLap1 fetchmail[1308]: restarting fetchmail > (/etc/fetchmailrc changed) > Jan 24 15:11:10 NasenLap1 fetchmail[1308]: starting fetchmail 6.3.18 daemon > Jan 24 15:11:23 NasenLap1 fetchmail[1308]: terminated with signal 15 > Jan 24 15:11:24 NasenLap1 fetchmail[2016]: fetchmail 6.3.18 Dämon wird > gestartet > Jan 24 15:11:24 NasenLap1 fetchmail[2016]: Authentifikationsfehlschlag > bei xy...@se... In spite of the further hints I am giving below: Please obtain an up to date fetchmail version (6.3.26), retry with the newer version, and then show verbose logs, per <http://www.fetchmail.info/fetchmail-FAQ.html#G3>. NOTE: I will not ask for verbose logs for a third time; if your next inquiry does not contain verbose logging, I will ignore your message. > Jan 24 15:11:24 NasenLap1 fetchmail[2016]: Hilfe (auf Englisch): siehe > http://www.fetchmail.info/fetchmail-FAQ.html#R15 > Jan 24 15:11:24 NasenLap1 fetchmail[2016]: Abfragestatus=3 (AUTHFAIL) > > as I said, the domain is rewritten to xy...@se... > But my user is xy...@t-... - not xy...@se... > (Also xy...@po... is accepted - by the way) Actually the logging is for the user + @ + server's name. The @securepop.t-online.de is not sent as part of the username, unless you type it inside the user "xy...@se..." - which will result in logging about xy...@se...@securepop.t-online.de. > If I change to : > poll "securepop.t-online.de" envelope 'X-ENVELOPE-TO:' protocol POP3 no > dns : user "xy...@t-..." there with password "secret" is * here keep > ssl > sslfingerprint "CE:CF:FE:44:69:3A:EF:EF:73:42:97:60:B0:41:95:35" > sslcertck > sslcertpath /etc/ssl/fetchmaild/certs/; > > I get the following result : > > Jan 24 15:21:26 NasenLap1 fetchmail[2016]: starte fetchmail erneut > (/etc/fetchmailrc verändert) > Jan 24 15:21:26 NasenLap1 fetchmail[2016]: fetchmail 6.3.18 Dämon wird > gestartet > Jan 24 15:21:26 NasenLap1 fetchmail[2016]: Authentifikationsfehlschlag > bei xy...@t-...@securepop.t-online.de > Jan 24 15:21:26 NasenLap1 fetchmail[2016]: Hilfe (auf Englisch): siehe > http://www.fetchmail.info/fetchmail-FAQ.html#R15 > Jan 24 15:21:26 NasenLap1 fetchmail[2016]: Abfragestatus=3 (AUTHFAIL) > > > I can change also to xy...@po... - same error > (cs....@po...@securepop.t-online.de) Note you may set a separate e-mail password: 1. http://kommunikationsdienste.t-online.de/email/verschluesselung/anleitungen/andere.html 2. https://kundencenter.telekom.de/kundencenter/kundendaten/passwoerter/e-mail-passwort/index.html |
From: Matthias A. <mat...@gm...> - 2014-01-30 20:55:32
|
Am 26.01.2014 18:42, schrieb Joe Acquisto-j4: >> Figured it out. The docs are clear enough, once read. Compiled and >> running. >> >> Still getting noise about certs, but much more descriptive. Still fetching, >> so, I'll leave the sleuthing for another day. >> >> joe a. >> > > Try as I might, I still get this error, which I presume means it does not like or > cannot find the "my side" cert: > > fetchmail: Server certificate verification error: unable to get local issuer certificate > > Also get this one, which I presume is the ISP end's problem (obfuscated CN): > > fetchmail: Broken certification chain at: /C=US/O=GeoTrust, Inc./CN=xxxxSSL CA If you require help from here onwards, you will have to provide unadulterated logs, per instructions laid out at <http://www.fetchmail.info/fetchmail-FAQ.html#G3>. The only advised munging is your removing unaffected account logging, and removing password exchange dialogs if there are digests or thereabouts. I understand the desire for privacy, but theorizing about what might have gone wrong in cases of DNS or SSL trouble is not taking us anywhere. Make sure that you have the root certificate that signed the server's certification chain in the "trust store" for OpenSSL. The default location is OpenSSL's default path (usually /etc/ssl/certs/*.0 or /usr/ssl/certs/*.0 - you get the .0 symlinks by installing a .pem file into that directory and running c_rehash afterwards), or you can use the sslcertfile or sslcertpath options to point fetchmail to trusted files. If you have the root certificate for the chain, save it in PEM format and run fetchmail --sslcertfile /path/for/that/file.pem and see if that helps. Many up-to-date distributions ship with a set of trust anchors from the mozilla project, the packages are often called ca-certificates, root-certificates, or similar. |
From: Joe Acquisto-j. <jo...@j4...> - 2014-01-29 17:37:30
|
>>> fetchmail: This could mean that the server did not provide the intermediate CA's certificate(s), which is nothing fetchmail could do anything about. For details, >>>please see the README.SSL-SERVER document that ships with fetchmail. >>>fetchmail: This could mean that the root CA's signing certificate is not in the trusted CA certificate location, or that c_rehash needs to be run on the certificate >>>directory. For details, please see the documentation of --sslcertpath and --sslcertfile in the manual page. >>Did you read those? Did they not help you resolve the issue? I can say that, for my issue, they did not help at all. It is not clear, to me, which, if any, refer to the "server side" (the fetch-ee, "them") and the "client side" (the fetch-er, me). I am no SSL expert, but I have setup SSL (sucessfully) for other "stuff". Of course, it does not help that my provider alternately tells me the do not support SSL, then points me to their docs which say they do. Sigh. |
From: Rob M. <rob...@gm...> - 2014-01-29 16:34:36
|
On Wed, Jan 29, 2014 at 4:06 AM, <com...@bl...> wrote: > Hi, all, <---SNIP---> > > Now I'm a bit confused :-( > > The only change of my setup, was to insert keyword 'ssl' > into my .fetchmailrc file. I noticed, that fetchmail now > tries to poll via port 995 (the provider's docu also tells > to use this port) - without ssl port 110 was polled. That's normal - the SSL version of POP3 (POP3s) uses 995/TCP, just like IMAPs uses 993/TCP > I'm NOT sure whether it's a problem with their serverside > software or whether I should provide any sort of local > certificate - and in the latter case: how to do this.. > > My question: What to do next ? That's up to you - you can do absolutely nothing and it'll continue to basically "just work". Alternatively you can make the necessary changes so that the certificates verify. >> fetchmail: This could mean that the server did not provide the intermediate CA's certificate(s), which is nothing fetchmail could do anything about. For details, please see the README.SSL-SERVER document that ships with fetchmail. >> fetchmail: This could mean that the root CA's signing certificate is not in the trusted CA certificate location, or that c_rehash needs to be run on the certificate directory. For details, please see the documentation of --sslcertpath and --sslcertfile in the manual page. Did you read those? Did they not help you resolve the issue? -- Please keep list traffic on the list. Rob MacGregor Whoever fights monsters should see to it that in the process he doesn't become a monster. Friedrich Nietzsche |
From: <com...@bl...> - 2014-01-29 05:12:24
|
Hi, all, since over 12 years I'm using fetchmail to poll a bunch of mail accounts at different providers using POP3. I've successfully compiled and used versions fetchmail-5.9.11, fetchmail-5.9.12, fetchmail-5.9.13, Fetchmail-6.3.9, and Fetchmail-6.3.26 on various versions of Linux. I'm also subscribed to the fetchmail mailing lists - upon now as reader only. So, I could claim NOT to be a newbie in respect to fetchmail, and I here say a big THANK YOU for all the efforts in maintaining and developing this program. BUT, I'm a total newbie in respect of SSL :-( A couple of weeks ago, one of my providers made SSL mandatory and I (think) I got it for this one. But now, another provider makes SSL mandatory too and I'm in big trouble, since it doesn't work :-( I've read the README.SSL and I also visited the mentioned openssl website hoping to download certificates. But they now claim NOT to provide certificates any more. Now I'm a bit confused :-( The only change of my setup, was to insert keyword 'ssl' into my .fetchmailrc file. I noticed, that fetchmail now tries to poll via port 995 (the provider's docu also tells to use this port) - without ssl port 110 was polled. I'm NOT sure whether it's a problem with their serverside software or whether I should provide any sort of local certificate - and in the latter case: how to do this.. My question: What to do next ? Here the info/files (a bit obfuscated) You may need to give me any helpful hints: > === f-V.txt ========================================== > > This is fetchmail release 6.3.26+SSL+NLS. > > Copyright (C) 2002, 2003 Eric S. Raymond > Copyright (C) 2004 Matthias Andree, Eric S. Raymond, > Robert M. Funk, Graham Wilson > Copyright (C) 2005 - 2012 Sunil Shetye > Copyright (C) 2005 - 2013 Matthias Andree > Fetchmail comes with ABSOLUTELY NO WARRANTY. This is free software, and you > are welcome to redistribute it under certain conditions. For details, > please see the file COPYING in the source or documentation directory. > This product includes software developed by the OpenSSL Project > for use in the OpenSSL Toolkit. (http://www.openssl.org/) > > Fallback MDA: (none) > Linux MYMACHINE 2.6.27.7-9-pae #1 SMP 2008-12-04 18:10:04 +0100 i686 i686 i386 GNU/Linux > Taking options from command line > > === .fetchmailrc.new.nokill.WEBB ===================== > > set idfile /home/Fetchmail/Id/.fetchids.WEBB > set postmaster=webm-bla > > poll pop3.PROVIDER-1.de > proto pop3 > no dns > uidl > tracepolls > auth password > > user web...@MY... is webm-bla > pass TOPSECRET > ssl > > keep > nofetchall > norewrite > > === cmd.fm =========================================== > > fetchmail -v --fetchlimit 0 -c -f /home/Fetchmail/Rc/.fetchmailrc.new.nokill.WEBB >& fm-c.log.3 > > === fm-c.log.3 ======================================= > > fetchmail: --check mode enabled, not fetching mail > fetchmail: 6.3.26 querying pop3.PROVIDER-1.de (protocol POP3) at Tue 28 Jan 2014 07:52:26 PM CET: poll started > Trying to connect to 22.222.222.222/995...connected. > fetchmail: Server certificate verification error: unable to get local issuer certificate > fetchmail: Broken certification chain at: /C=DE/O=Deutsche Telekom AG/OU=T-TeleSec Trust Center/CN=Deutsche Telekom Root CA 2 > fetchmail: This could mean that the server did not provide the intermediate CA's certificate(s), which is nothing fetchmail could do anything about. For details, please see the README.SSL-SERVER document that ships with fetchmail. > fetchmail: This could mean that the root CA's signing certificate is not in the trusted CA certificate location, or that c_rehash needs to be run on the certificate directory. For details, please see the documentation of --sslcertpath and --sslcertfile in the manual page. > fetchmail: Server certificate verification error: certificate not trusted > fetchmail: Server certificate: > fetchmail: Issuer Organization: T-Systems International GmbH > fetchmail: Issuer CommonName: TeleSec ServerPass DE-1 > fetchmail: Subject CommonName: pop3.PROVIDER-1.de > fetchmail: Subject Alternative Name: pop3.PROVIDER-1.de > fetchmail: Subject Alternative Name: pop3.PROVIDER-1.com > fetchmail: pop3.PROVIDER-1.de key fingerprint: 88:99:AA:BB:CC:DD:EE:FF:00:01:02:03:04:05:06:07 > fetchmail: Warning: the connection is insecure, continuing anyways. (Better use --sslcertck!) > fetchmail: POP3< +OK POP3 server ready (P0 DHE-RSA-AES256-SHA) <d77...@po...> > fetchmail: POP3> USER web...@MY... > fetchmail: POP3< +OK Waiting for password > fetchmail: POP3> PASS * > fetchmail: POP3< +OK User logged in > fetchmail: POP3> STAT > fetchmail: POP3< +OK 0 0 > fetchmail: No mail for web...@MY... at pop3.PROVIDER-1.de > fetchmail: POP3> QUIT > fetchmail: POP3< +OK Closing connection > fetchmail: 6.3.26 querying pop3.PROVIDER-1.de (protocol POP3) at Tue 28 Jan 2014 07:52:27 PM CET: poll completed > fetchmail: normal termination, status 1 > > ====================================================== MANY THX in advance for Your patience ! Rolf -- Dipl.phys. Rudolf Otto Blättner Email commsoft (at) blaettner-net.de |
From: Juergen E. <fli...@te...> - 2014-01-28 15:48:55
|
Hello Joe, > I want to time stamp the fetchmail log. > > Is there a secret to "preconnect" in the config file? I've fiddled > with it a bit but always get this when trying to start up. > > fetchmail:/blah/.fetchmailrc:7: syntax error at preconnect I'm using the following configuration: preconnect "echo 'fetchmail: awakened at '`date +'%a, %d %b %G %H:%M:%S (%Z)'`" postconnect "echo 'fetchmail: sleeping at '`date +'%a, %d %b %G %H:%M:%S (%Z)'` for 1200 seconds" Regards Juergen |
From: Joe Acquisto-j. <jo...@j4...> - 2014-01-26 18:42:39
|
> Figured it out. The docs are clear enough, once read. Compiled and > running. > > Still getting noise about certs, but much more descriptive. Still fetching, > so, I'll leave the sleuthing for another day. > > joe a. > Try as I might, I still get this error, which I presume means it does not like or cannot find the "my side" cert: fetchmail: Server certificate verification error: unable to get local issuer certificate Also get this one, which I presume is the ISP end's problem (obfuscated CN): fetchmail: Broken certification chain at: /C=US/O=GeoTrust, Inc./CN=xxxxSSL CA joe a. |
From: Joe Acquisto-j. <jo...@j4...> - 2014-01-26 16:06:15
|
>>> On 1/26/2014 at 9:38 AM, "Joe Acquisto-j4" <jo...@j4...> wrote: > I want to time stamp the fetchmail log. > > Is there a secret to "preconnect" in the config file? I've fiddled with it > a bit but always get this when > trying to start up. > > fetchmail:/blah/.fetchmailrc:7: syntax error at preconnect > > joe a. Operator error. It's a user option. As most know. joe a. |
From: Joe Acquisto-j. <jo...@j4...> - 2014-01-26 15:38:20
|
I want to time stamp the fetchmail log. Is there a secret to "preconnect" in the config file? I've fiddled with it a bit but always get this when trying to start up. fetchmail:/blah/.fetchmailrc:7: syntax error at preconnect joe a. |
From: Joe Acquisto-j. <jo...@j4...> - 2014-01-26 05:46:39
|
>>> On 1/25/2014 at 10:51 PM, "Joe Acquisto-j4" <jo...@j4...> wrote: >>>> On 1/25/2014 at 5:21 PM, Matthias Andree <mat...@gm...> wrote: >> Am 25.01.2014 21:57, schrieb Joe Acquisto-j4: >>> Let's say I want to try the latest version. But I don't want to fire up a >> new box or vm to test it on. >>> >>> It's a problem when one is lazy, cheap and paranoid, (uh, I mean careful) >> all in one >>> >>> I'd like to make to a new directory, so I can fall back immediately if >> something goes south. >>> >>> I've never done a make install (or preliminary steps, if needed) to a custom > >> directory (or plural) >>> >>> Can this be done? Pointers, cookbook? >> >> Yes, you can do that. >> >> Download the tarball. >> Unpack the tarball. >> Configure with a --prefix of a directory outside the usual ways, for >> instance: >> >> ./configure --prefix=/opt/fetchmail --with-ssl >> [add other options as you see fit, >> --help=short will list special options, >> --help will list all options] >> >> make check >> make install (this is the only operation that requires privileges) >> >> Try: /opt/fetchmail/bin/fetchmail >> and add your usual options. >> >> If you like it, keep it, if you don't like it, or it goofs up, >> rm -rf /opt/fetchmail to remove it and let me know what went wrong. >> > > Configure tells me: "configure: error: SSL support enabled, but OpenSSL not > found" > > Yet it is and says it is "OpenSSL 0.9.8a 11 Oct 2005" > > I tried with and without " --with-ssl=where openssl is" > > joe a > > _______________________________________________ > fetchmail-users mailing list > fet...@li... > https://lists.berlios.de/mailman/listinfo/fetchmail-users Figured it out. The docs are clear enough, once read. Compiled and running. Still getting noise about certs, but much more descriptive. Still fetching, so, I'll leave the sleuthing for another day. joe a. |
From: Joe Acquisto-j. <jo...@j4...> - 2014-01-26 04:51:48
|
>>> On 1/25/2014 at 5:21 PM, Matthias Andree <mat...@gm...> wrote: > Am 25.01.2014 21:57, schrieb Joe Acquisto-j4: >> Let's say I want to try the latest version. But I don't want to fire up a > new box or vm to test it on. >> >> It's a problem when one is lazy, cheap and paranoid, (uh, I mean careful) > all in one >> >> I'd like to make to a new directory, so I can fall back immediately if > something goes south. >> >> I've never done a make install (or preliminary steps, if needed) to a custom > directory (or plural) >> >> Can this be done? Pointers, cookbook? > > Yes, you can do that. > > Download the tarball. > Unpack the tarball. > Configure with a --prefix of a directory outside the usual ways, for > instance: > > ./configure --prefix=/opt/fetchmail --with-ssl > [add other options as you see fit, > --help=short will list special options, > --help will list all options] > > make check > make install (this is the only operation that requires privileges) > > Try: /opt/fetchmail/bin/fetchmail > and add your usual options. > > If you like it, keep it, if you don't like it, or it goofs up, > rm -rf /opt/fetchmail to remove it and let me know what went wrong. > Configure tells me: "configure: error: SSL support enabled, but OpenSSL not found" Yet it is and says it is "OpenSSL 0.9.8a 11 Oct 2005" I tried with and without " --with-ssl=where openssl is" joe a |
From: Matthias A. <mat...@gm...> - 2014-01-25 23:21:27
|
Am 25.01.2014 21:57, schrieb Joe Acquisto-j4: > Let's say I want to try the latest version. But I don't want to fire up a new box or vm to test it on. > > It's a problem when one is lazy, cheap and paranoid, (uh, I mean careful) all in one > > I'd like to make to a new directory, so I can fall back immediately if something goes south. > > I've never done a make install (or preliminary steps, if needed) to a custom directory (or plural) > > Can this be done? Pointers, cookbook? Yes, you can do that. Download the tarball. Unpack the tarball. Configure with a --prefix of a directory outside the usual ways, for instance: ./configure --prefix=/opt/fetchmail --with-ssl [add other options as you see fit, --help=short will list special options, --help will list all options] make check make install (this is the only operation that requires privileges) Try: /opt/fetchmail/bin/fetchmail and add your usual options. If you like it, keep it, if you don't like it, or it goofs up, rm -rf /opt/fetchmail to remove it and let me know what went wrong. The list of things I need in case of trouble is in <http://www.fetchmail.info/fetchmail-FAQ.html#G3>. |