diff options
author | Matthias Andree <matthias.andree@gmx.de> | 2011-05-26 01:47:41 +0200 |
---|---|---|
committer | Matthias Andree <matthias.andree@gmx.de> | 2011-05-26 02:00:30 +0200 |
commit | 1e13bb35731999c4668883acd404ede047793e1e (patch) | |
tree | a881c8f44417ca86c36424a15fbdd6faaa734da9 /imap.c | |
parent | f285f5ee95765133b41d6ecae0f397b3b72fa6d4 (diff) | |
download | fetchmail-1e13bb35731999c4668883acd404ede047793e1e.tar.gz fetchmail-1e13bb35731999c4668883acd404ede047793e1e.tar.bz2 fetchmail-1e13bb35731999c4668883acd404ede047793e1e.zip |
Run S(TART)TLS negotiation under timeout alarm.
Reported missing by Thomas Jarosch.
Diffstat (limited to 'imap.c')
-rw-r--r-- | imap.c | 6 |
1 files changed, 4 insertions, 2 deletions
@@ -447,9 +447,9 @@ static int imap_getauth(int sock, struct query *ctl, char *greeting) * whether TLS is mandatory or opportunistic unless SSLOpen() fails * (see below). */ if (gen_transact(sock, "STARTTLS") == PS_SUCCESS - && SSLOpen(sock, ctl->sslcert, ctl->sslkey, "tls1", ctl->sslcertck, + && (set_timeout(mytimeout), SSLOpen(sock, ctl->sslcert, ctl->sslkey, "tls1", ctl->sslcertck, ctl->sslcertfile, ctl->sslcertpath, ctl->sslfingerprint, commonname, - ctl->server.pollname, &ctl->remotename) != -1) + ctl->server.pollname, &ctl->remotename)) != -1) { /* * RFC 2595 says this: @@ -473,9 +473,11 @@ static int imap_getauth(int sock, struct query *ctl, char *greeting) } else if (must_tls(ctl)) { /* Config required TLS but we couldn't guarantee it, so we must * stop. */ + set_timeout(0); report(stderr, GT_("%s: upgrade to TLS failed.\n"), commonname); return PS_SOCKET; } else { + set_timeout(0); if (outlevel >= O_VERBOSE) { report(stdout, GT_("%s: opportunistic upgrade to TLS failed, trying to continue\n"), commonname); } |