PDA

View Full Version : Email server cert name mismatch


DogAndPony
06-05-2008, 12:58 AM
Yo, peeps!

A client emailed me with this: There's a server name mismatch in the cert used for POP mail on one of his domains. It's not surprising, since the cert server name is secure.futurequest.net, and the server he's logging into is pop.hisdomain.com.

But he's only recently (last few days?) been seeing this. Is this due to a replaced cert after the vulnerability? Anything else changed on the server?

Just curious...

For now, I told him to check the "Always trust..." box in Apple Mail. I think that should do the trick.

Terra
06-05-2008, 01:06 AM
Reference the last paragraph in:
http://www.aota.net/forums/showthread.php?postid=138389#post138389

It is cost prohibitive for us to give every account a domain specific CERT, therefore we use a privately signed global CERT for the intent of just encrypting the POP traffic...

DogAndPony
06-05-2008, 01:13 AM
Hey, T!

Reference the last paragraph in:
http://www.aota.net/forums/showthread.php?postid=138389#post138389

It is cost prohibitive for us to give every account a domain specific CERT, therefore we use a privately signed global CERT for the intent of just encrypting the POP traffic...Right... That's why I was saying it's not surprising.

I don't know why his client is just now griping after all this time. Might be a new security feature in the latest-downloaded update to Apple Mail.

Thanks for the link!