Score:2

Dovecot:/Thunderbird sslv3 alert certificate expired: SSL alert number 45

sa flag

Thunderbird is silently failing to fetch messages for one of my mail servers. Looking in the server's dovecot logs I got the error message in the title, specifically:

imap-login: Info: Disconnected (no auth attempts in 0 secs): user=<>, rip=[IP redacted], lip=[IP redacted], TLS handshaking: SSL_accept() failed: error:14094415:SSL routines:ssl3_read_bytes:sslv3 alert certificate expired: SSL alert number 45, session=<Y/pyl7D8zuYXXew+>

I checked my certificates, which are LetsEncrypt certs I also use for the web server and, in a web browser, they showed as up to date.

Score:3
sa flag

Dovecot does not reload the certificates if it is not restarted. So when I restarted dovecot, it loaded the new versions of the certificates, and voila all was well. Notably, I had a dovecot reload in crontab, but I guess that extends only to configs and not to certs. I changed it to a restart for a hopefully more permanent fix.

I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.