|
From: Rob M. <rob...@gm...> - 2007-08-20 13:56:44
|
On 8/20/07, Matthias Andree <mat...@gm...> wrote:
>
> Recent fetchmail versions should, if configured with sslfingerprint,
> suppress the warning that Anne quoted. The fingerprint can be obtained from
> fetchmail's verbose output.
True, but I've been badly bitten by that before - ISP uses self-signed
certificate, certificate is changed, mail no longer collected. I get
enough email that it became apparent within hours, but it still took
me longer than I'd have liked to identify the problem.
IMO sslfingerprint should only be used where it isn't possible to
otherwise validate a certificate.
--
Please keep list traffic on the list.
Rob MacGregor
Whoever fights monsters should see to it that in the process he
doesn't become a monster. Friedrich Nietzsche
|