Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #178767 > unrolled thread

claws-mail sending failure

Started by"Charles E. Blair" <c-blair@illinois.edu>
First post2017-03-13 18:20 +0100
Last post2017-03-21 03:30 +0100
Articles 4 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  claws-mail sending failure "Charles E. Blair" <c-blair@illinois.edu> - 2017-03-13 18:20 +0100
    Re: claws-mail sending failure David Wright <deblis@lionunicorn.co.uk> - 2017-03-14 04:40 +0100
      Re: Re: claws-mail sending failure "Charles E. Blair" <c-blair@illinois.edu> - 2017-03-18 23:10 +0100
        Re: claws-mail sending failure David Wright <deblis@lionunicorn.co.uk> - 2017-03-21 03:30 +0100

#178767 — claws-mail sending failure

From"Charles E. Blair" <c-blair@illinois.edu>
Date2017-03-13 18:20 +0100
Subjectclaws-mail sending failure
Message-ID<tkBNw-3I1-33@gated-at.bofh.it>
   I have been using claws-mail for several years.  After
I changed the server used for sending mail, receiving has
continued to work but not sending.

   When I closed claws-mail after a failure, my screen
displayed

> Warning SSL connection failed (A TLS packet with
> unexpected length was received)
> Warning couldn't start TLS session

   I reproduce below part of ./claws-mail/claws.log

   Any advice on how to fix things would be appreciated.

[11:12:41] * message: Account 'c-blair@imap.illinois.edu': Connecting to IMAP4 server: imap.illinois.edu...
...
[11:12:41] IMAP4> Logging c-blair to imap.illinois.edu using LOGIN
[11:12:42] IMAP4< LOGIN completed.
[11:12:42] IMAP4< Login to imap.illinois.edu successful
[11:12:42] IMAP4< 5 OK [READ-WRITE] SELECT completed. 
[11:12:42] IMAP4- [fetching UIDs...]
[11:12:42] IMAP4< 6 OK FETCH completed. 
[11:12:42] IMAP4> 8 NOOP 
[11:12:42] IMAP4< 8 OK NOOP completed. 
[11:12:42] IMAP4> 9 UID STORE 6854 +FLAGS.SILENT (\Seen) 
[11:12:42] IMAP4< 9 OK STORE completed. 
[11:12:42] * message: Account 'c-blair@imap.illinois.edu': Connecting to SMTP server: smtp.illinois.edu ...
[11:12:42] SMTP< 220 smtp.illinois.edu Microsoft ESMTP MAIL Service ready at Mon, 13 Mar 2017 11:12:41 -0500
[11:12:42] ESMTP< 250-smtp.illinois.edu Hello [192.17.23.217]
[11:12:42] ESMTP< 250-STARTTLS
[11:12:42] ESMTP> STARTTLS
[11:12:42] ESMTP< 220 2.0.0 SMTP server ready
[11:12:42] ** warning: couldn't start TLS session
[11:12:42] *** error: Error occurred while sending the message.

[toc] | [next] | [standalone]


#178807

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2017-03-14 04:40 +0100
Message-ID<tkLtv-2yn-3@gated-at.bofh.it>
In reply to#178767
On Mon 13 Mar 2017 at 11:35:31 (-0500), Charles E. Blair wrote:
>    I have been using claws-mail for several years.  After
> I changed the server used for sending mail, receiving has
> continued to work but not sending.
> 
>    When I closed claws-mail after a failure, my screen
> displayed
> 
> > Warning SSL connection failed (A TLS packet with
> > unexpected length was received)
> > Warning couldn't start TLS session
> 
>    I reproduce below part of ./claws-mail/claws.log
> 
>    Any advice on how to fix things would be appreciated.

What was the previous server and port number that you used
previously for sending?

I can connect to smtp.illinois.edu on port 587 just fine, though
I obviously have no login credentials (and don't want any).

It looks to me as if you may be connecting unencrypted, and then
trying to start TLS. I connected encrypted, received a certificate,
and then I said "ehlo junk". I received:

250-smtp.illinois.edu Hello [192.17.23.217]
250-SIZE 104857600
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-AUTH GSSAPI NTLM LOGIN
250-8BITMIME
250-BINARYMIME
250 CHUNKING

It seems a bit dated, having AUTH LOGIN but no PLAIN.
I think that just means you send the username and password separately,
rather than together in one line.

> [11:12:42] * message: Account 'c-blair@imap.illinois.edu': Connecting to SMTP server: smtp.illinois.edu ...
> [11:12:42] SMTP< 220 smtp.illinois.edu Microsoft ESMTP MAIL Service ready at Mon, 13 Mar 2017 11:12:41 -0500
> [11:12:42] ESMTP< 250-smtp.illinois.edu Hello [192.17.23.217]
> [11:12:42] ESMTP< 250-STARTTLS
> [11:12:42] ESMTP> STARTTLS
> [11:12:42] ESMTP< 220 2.0.0 SMTP server ready
> [11:12:42] ** warning: couldn't start TLS session
> [11:12:42] *** error: Error occurred while sending the message.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#179005

From"Charles E. Blair" <c-blair@illinois.edu>
Date2017-03-18 23:10 +0100
Message-ID<tmuHT-4rH-1@gated-at.bofh.it>
In reply to#178807
   Thanks very much for your reply.

   I have an older machine running claws-mail 3.8.1
and a newer machine running 3.11.1.  Some but not
all correspondents stopped being able to receive
messages from my 3.8.1 machine, while still hearing
from 3.11.1.  I changed the 3.8.1 "sent" configuration
(which had previously used a different server), to
be the same as the 3.11.1 settings, including the
use of the 587 port and TLS.  These in turn were based
on documentation provided by the server.

   You talk about "running encrypted" vs unencrypted.
Is this something I can control using the "preferences
for current account"?

   I had one specific worry.  The failure to send on
3.8.1 was accompanied by the message

> Warning SSL connection failed (A TLS packet with
> unexpected length was received)

In my ignorance, I thought this might mean malware
was adding something to my messages.

[toc] | [prev] | [next] | [standalone]


#179075

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2017-03-21 03:30 +0100
Message-ID<tnhIB-5f1-5@gated-at.bofh.it>
In reply to#179005
On Sat 18 Mar 2017 at 16:48:27 (-0500), Charles E. Blair wrote:
>    Thanks very much for your reply.
> 
>    I have an older machine running claws-mail 3.8.1
> and a newer machine running 3.11.1.  Some but not
> all correspondents stopped being able to receive
> messages from my 3.8.1 machine, while still hearing
> from 3.11.1.  I changed the 3.8.1 "sent" configuration
> (which had previously used a different server), to
> be the same as the 3.11.1 settings, including the
> use of the 587 port and TLS.  These in turn were based
> on documentation provided by the server.
> 
>    You talk about "running encrypted" vs unencrypted.
> Is this something I can control using the "preferences
> for current account"?

If you mean "Can I tell claws to use an encrypted connection?"
I don't know as I don't use claws.

I think you have to start the connection in the "modern" way,
ie encrypted from the very start:

$ openssl s_client -starttls smtp -crlf -connect smtp.illinois.edu:587

connects for me, and I get (after the certificate stuff):

New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-AES256-SHA384
    Session-ID:
    E03400003695C6119FF38C21EDA71FC390543AEF8A4C0709A080536A0269072E
    Session-ID-ctx: 
    Master-Key:
    CEAAA20DCF811A292E5280ED709A250931C11C1DA68606192FA429E16DB12A2816A286DE7AE8573DC250F4CF59E043A1
    Key-Arg   : None
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1490060955
    Timeout   : 300 (sec)
    Verify return code: 0 (ok)
---
250 CHUNKING
ehlo hostname ←←←←←that's me typing.
250-smtp.illinois.edu Hello [192.17.23.217]
250-SIZE 104857600
250-PIPELINING
250-DSN
250-ENHANCEDSTATUSCODES
250-AUTH GSSAPI NTLM LOGIN
250-8BITMIME
250-BINARYMIME
250 CHUNKING
^C ←←←←←that's me typing.

I think some of these systems will happily say they support
STARTTLS if you connect unencrypted, but then throw you off
when you try to start TLS at that late stage.

I agree with someone in the other thread: use exim as an MTA
(I suppose that strictly it's an MSA, Mail Submission Agent)
as it knows how to do this stuff. All my email goes out
through wheezy's exim unless I'm on the road. Then it's jessie.

Just bear in mind that using exim means that emails are queued
for delivery, so "mail sent" does not mean the email has left
your machine already. tail -F /var/log/exim/mainlog    will
show you what's going out (if you are in the "adm" group).

>    I had one specific worry.  The failure to send on
> 3.8.1 was accompanied by the message
> 
> > Warning SSL connection failed (A TLS packet with
> > unexpected length was received)
> 
> In my ignorance, I thought this might mean malware
> was adding something to my messages.

I can only guess that this might be the late start-TLS failing.

Cheers,
David.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web