Bug in DreamHosts's SSL certificates for email exp
Posted by: rtanglao
Posted on: 2009-08-21 14:43:00
[as reported in on Get Satisfaction:
http://getsatisfaction.com/dreamhost/topics/bug_in_dreamhostss_ssl_certificates_for_email_exposed_in_thunderbird_2_0_0_23]
Hi DreamHost Support Folks:
This is Roland from Thunderbird support. Thunderbird is an email client from Mozilla Messaging.
Mozilla Messaging just released Thunderbird 2.0.0.23 which exposes a "bug" (see *DETAILS* below) in DreamHost's SSL certificates. This "bug" affects all DreamHost customers who use email on DreamHost and who use Thunderbird 2.0.0.23
Not sure if you can fix this "bug", so just filing this problem here as "heads up". Will also file it via your normal support channels. I'm also going to file a reply to this problem with a link to this topic at our Get Satisfaction which is:
http://getsatisfaction.com/mozilla_messaging
...Roland "Technical Support Lead", Mozilla Messaging
roland@mozillamessaging.com
+1 604 729 7924
*DETAILS* from https://bugzilla.mozilla.org/show_bug.cgi?id=511921
Thunderbird prior to 2.0.0.23 still contained the bug that allowed * in an SSL cert to match more than one atom of a hostname (which actually violates the spec).
Thunderbird 2.0.0.23 changed the behavior so that a domain name with more than one atom in the spot where the * is in the cert name properly rejects the cert as an invalid hostname. Dreamhost has mailservers named with a pattern like:
a1.postal.mail.dreamhost.com.
Their cert says *.mail.dreamhost.com.