[Eisfair] Zertifikatsprobleme bei Fetchmail

Dirk Alberti Howy-1 at gmx.de
Mo Apr 24 12:16:21 CEST 2017


Hallo zusammen,

meine erste Reaktion: "Was is denn nu schon wieder?"... :-/

Mein Fetchmal beglückt mich neuerdings mit Emails, dass die Mailkonten 
nich abgerufen werden können.

fetchmail: awakened at Mon, 24 Apr 2017 11:39:06 (CEST)
fetchmail: Server certificate verification error: self signed certificate in certificate chain
fetchmail: Missing trust anchor certificate: /C=DE/O=Deutsche Telekom AG/OU=T-TeleSec Trust Center/CN=Deutsche Telekom Root CA 2
fetchmail: This could mean that the root CA's signing certificate is not in the trusted CA certificate location, or that c_rehash needs to be run on the certificate directory. For details, please see the documentation of --sslcertpath and --sslcertfile in the manual page.
fetchmail: OpenSSL reported: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
fetchmail: SSL connection failed.
fetchmail: socket error while fetching from*******@gmx.de at pop.gmx.net
fetchmail: Query status=2 (SOCKET)
fetchmail: Server certificate verification error: self signed certificate in certificate chain
fetchmail: Missing trust anchor certificate: /C=DE/O=T-Systems Enterprise Services GmbH/OU=T-Systems Trust Center/CN=T-TeleSec GlobalRoot Class 2
fetchmail: This could mean that the root CA's signing certificate is not in the trusted CA certificate location, or that c_rehash needs to be run on the certificate directory. For details, please see the documentation of --sslcertpath and --sslcertfile in the manual page.
fetchmail: OpenSSL reported: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
fetchmail: SSL connection failed.
fetchmail: socket error while fetching from*******@freenet.de at mx.freenet.de
fetchmail: Query status=2 (SOCKET)
fetchmail: Server certificate verification error: self signed certificate in certificate chain
fetchmail: Missing trust anchor certificate: /C=DE/O=Deutsche Telekom AG/OU=T-TeleSec Trust Center/CN=Deutsche Telekom Root CA 2
fetchmail: This could mean that the root CA's signing certificate is not in the trusted CA certificate location, or that c_rehash needs to be run on the certificate directory. For details, please see the documentation of --sslcertpath and --sslcertfile in the manual page.
fetchmail: OpenSSL reported: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed
fetchmail: SSL connection failed.

...und so weiter, für alle Mailkonten, die abgerufen werden sollen.

Was ich schon versucht habe:

Im Certs-Setup

5   Download ca certificate bundle
7   Update certs/crl hashes
8   Update revocation list(s)

und im Mail-Setup

Update fingerprints and certificates for fetchmail

Alles soweit erfolgreich ausgeführt, aber trotzdem gehts nicht und ich 
kriege regelmäßig diese Mails.

Fehlt das für das Zertifikat noch was?

Gruß
Dirk


Mehr Informationen über die Mailingliste Eisfair