thunderbird / thunderbird/thunderbird-android

Expired or revoked client certificate does not generate error on IMAP connection

Open
#8,646 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Kotlin
Stars
14k
Forks
2.8k
Avg merge
3d 3h
Merged PRs (30d)
57

Description

Checklist
  • I have used the search function to see if someone else has already submitted the same bug report.
  • I will describe the problem with as much detail as possible.
App

K-9 Mail

App version

8.1

Where did you get the app from?

Google Play

Android version

Checked in Android 14 (LineageOS) and 15 (original Google firmware)

Device model

No response

Steps to reproduce
  1. Configure IMAP+SMTP account in K-9 Mail with same client cert auth for both.
  2. Make client cert invalid (i.e. revoke it or wait until expired to force server treat this cert as invalid) and refresh IMAP inbox in K-9 Mail. No error notification will be displayed nor new mail fetched (even if present in inbox).
  3. Try to send e-mail using SMTP from K-9 Mail. Error notifcation will be thrown and after this, refreshing IMAP inbox starts to display error notifications too on IMAP connections.
Expected behavior

IMAP connections with invalid client cert should produce error notification even if no SMTP connection with same invalid cert was tried.

Actual behavior

IMAP connections with invalid client cert do not produce error notification if no SMTP connection with same invalid cert was tried.

Logs

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the issue in K-9 Mail 8.1 on Android with an expired or revoked client certificate, testing IMAP before SMTP. Compare whether IMAP and SMTP produce error notifications; done means invalid IMAP client certificates consistently notify the user and do not require an SMTP attempt first.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, kotlin
Domain
mobile, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.