Explorar el Código

fix CertificateFile docs & samples

the mbsync manual says explicitly that the system's default certificate
store should *not* be specified.
however, the isync manual talked about CA certificates, which is (and
always was) exactly wrong.
also adjust both .sample rc files.
Oswald Buddenhagen hace 10 años
padre
commit
e054c575ea
Se han modificado 3 ficheros con 7 adiciones y 3 borrados
  1. 6 1
      src/compat/isync.1
  2. 1 1
      src/compat/isyncrc.sample
  3. 0 1
      src/mbsyncrc.sample

+ 6 - 1
src/compat/isync.1

@@ -259,7 +259,12 @@ established with the IMAP server.  (Default: \fIyes\fR)
 ..
 .TP
 \fBCertificateFile\fR \fIpath\fR
-File containing X.509 CA certificates used to verify server identities.
+File containing additional X.509 certificates used to verify server
+identities. Directly matched peer certificates are always trusted,
+regardless of validity.
+.br
+Note that the system's default certificate store is always used
+and should not be specified here.
 ..
 .TP
 \fBUseSSLv2\fR \fIyes\fR|\fIno\fR

+ 1 - 1
src/compat/isyncrc.sample

@@ -3,7 +3,7 @@
 #   doesn't specify it.
 
 # SSL server certificate file
-CertificateFile /etc/ssl/certs/ca-certificates.crt
+CertificateFile ~/.isync.certs
 
 # by default, expunge deleted messages (same as -e on command line)
 Expunge yes

+ 0 - 1
src/mbsyncrc.sample

@@ -26,7 +26,6 @@ Pass xxxxxxxx
 #  "Account Name" USERNAME
 #  "Password" PASSWORD
 #PassCmd "/usr/bin/security find-internet-password -w -a USERNAME -s IMAPSERVER ~/Library/Keychains/login.keychain"
-CertificateFile /etc/ssl/certs/ca-certificates.crt
 
 Channel work
 Master :work: