Ticket #6500 (closed patch: fixed)
NSS plugin doesn't verify SSL certificates
| Reported by: | ari | Owned by: | wehlhard |
|---|---|---|---|
| Milestone: | 2.5.0 | Component: | libpurple |
| Version: | 2.4.3 | Keywords: | |
| Cc: | MarkDoliner |
Description
Originally from http://bugs.debian.org/492434:
I recently set up a Jabber server. I used the default snakeoil certificate. When I configured Pidgin to connect to my new server, using SSL, it connected without any complaint whatsoever.
(Pidgin in Debian/Ubuntu is built with NSS, under the recommendation of you guys. The GNUTLS plugin apparently does do proper certificate verification. This is a fairly major problem, since people assuming their connections are secure can be subject to man-in-the-middle attacks.)
Attachments
Change History
Note: See
TracTickets for help on using
tickets.



