Using the default of SSL_verify_mode of SSL_VERIFY_NONE for

Moderator: crythias

Post Reply
ARGO
OTRS newbie
Posts: 1
Joined: 12 Feb 2013, 22:45
OTRS Version?: 3.2.1
Real Name: Arnold Gordijn
Company: Xperteam

Using the default of SSL_verify_mode of SSL_VERIFY_NONE for

Post by ARGO » 12 Feb 2013, 23:04

Hi i'm having an issue after upgrading from 3.1.7 to 3.2.1 and also added modules to perl. Perl: 5.12.4

I get an email every 10 min with this content:
*******************************************************************
Using the default of SSL_verify_mode of SSL_VERIFY_NONE for client is deprecated! Please set SSL_verify_mode to SSL_VERIFY_PEER together with SSL_ca_file|SSL_ca_path for verification.
If you really don't want to verify the certificate and keep the connection open to Man-In-The-Middle attacks please set SSL_verify_mode explicitly to SSL_VERIFY_NONE in your application.
*******************************************************************
at /opt/otrs/Kernel/cpan-lib/Net/IMAP/Simple.pm line 159.
*******************************************************************
Using the default of SSL_verify_mode of SSL_VERIFY_NONE for client is deprecated! Please set SSL_verify_mode to SSL_VERIFY_PEER together with SSL_ca_file|SSL_ca_path for verification.
If you really don't want to verify the certificate and keep the connection open to Man-In-The-Middle attacks please set SSL_verify_mode explicitly to SSL_VERIFY_NONE in your application.
*******************************************************************
at /opt/otrs/Kernel/cpan-lib/Net/IMAP/Simple.pm line 159.


This are the perl modules

o CGI..............................ok (v3.63)
o Crypt::PasswdMD5.................ok (v1.3)
o Crypt::SSLeay....................Not installed! (optional - Required for Generic Interface SOAP SSL connections.)
o CSS::Minifier....................ok (v0.01)
o Date::Format.....................ok (v2.24)
o Date::Pcalc......................ok (v1.2)
o DBI..............................ok (v1.623)
o DBD::mysql.......................ok (v4.017)
o DBD::ODBC........................Not installed! (optional - Required to connect to a MS-SQL database.)
o DBD::Oracle......................Not installed! (optional - Required to connect to a Oracle database.)
o DBD::Pg..........................Not installed! (optional - Required to connect to a PostgreSQL database.)
o Digest::MD5......................ok (v2.52)
o Digest::SHA::PurePerl............ok (v5.81)
o Digest::SHA......................ok (v5.82)
o Encode::HanExtra.................ok (v0.23)
o Encode::Locale...................ok (v1.03)
o GD...............................ok (v2.44)
o GD::Text.......................ok (v0.86)
o GD::Graph......................ok (v1.44)
o GD::Graph::lines...............ok (v1.15)
o GD::Text::Align................ok (v1.18)
o IO::Scalar.......................ok (v2.110)
o IO::Wrap.........................ok (v2.110)
o JavaScript::Minifier.............ok (v1.05)
o JSON.............................ok (v2.53)
o JSON::PP.......................ok (v2.27200)
o JSON::XS.......................ok (v2.33)
o Locale::Codes....................ok (v3.24)
o LWP::UserAgent...................ok (v6.04)
o Mail::Internet...................ok (v2.12)
o Mail::POP3Client.................ok (v2.18)
o IO::Socket::SSL................ok (v1.83)
o Mail::IMAPClient.................ok (v3.32)
o IO::Socket::SSL................ok (v1.83)
o MIME::Base64.....................ok (v3.13)
o MIME::Tools......................ok (v5.428)
o ModPerl::Util....................ok (v2.000004)
o Apache::DBI....................ok (v1.11)
o Apache2::Reload................ok (v0.12)
o Net::DNS.........................ok (v0.68)
o Net::POP3........................ok (v2.29)
o Net::IMAP::Simple................ok (v1.2034)
o IO::Socket::SSL................ok (v1.83)
o Net::SMTP........................ok (v2.31)
o Authen::SASL...................ok (v2.16)
o Net::SMTP::SSL.................ok (v1.01)
o Net::SMTP::TLS::ButMaintained..ok (v0.20)
o Net::LDAP........................ok (v0.53)
o Net::SSL.........................Not installed! (optional - Required for Generic Interface SOAP SSL connections.)
o PDF::API2........................ok (v2.020)
o Compress::Zlib.................ok (v2.060)
o Storable.........................ok (v2.39)
o SOAP::Lite.......................ok (v0.715)
o version........................ok (v0.9901)
o Class::Inspector...............ok (v1.28)
o Text::CSV........................ok (v1.21)
o Text::CSV_PP...................ok (v1.29)
o Text::CSV_XS...................ok (v0.95)
o Time::HiRes......................ok (v1.9725)
o XML::Parser......................ok (v2.36)
o HTTP::Message....................ok (v6.06)
o HTTP::Headers..................ok (v6.05)
o URI..............................ok (v1.60)
o URI::Escape....................ok (v3.31)
o Scalar::Util.....................ok (v1.27)
o YAML::XS.........................ok (v0.38)


How can I fix this

Mike_B
Moderator
Posts: 266
Joined: 12 Jan 2010, 18:16
OTRS Version?: CVS HEAD

Re: Using the default of SSL_verify_mode of SSL_VERIFY_NONE

Post by Mike_B » 20 Mar 2013, 18:00

Hi, the workaround for this (waiting on other engineering on the Mail modules) is to downgrade IO::Socket::SSL to v1.78 or earlier.
see https://metacpan.org/source/SULLR/IO-So ... 84/Changes

We also have an OTRS bug report for this:

http://bugs.otrs.org/show_bug.cgi?id=8982

--
Mike
huntingbears.nl - @michielbeijen on Twitter

User avatar
carlosgallego
OTRS superhero
Posts: 241
Joined: 17 Nov 2011, 18:17
OTRS Version?: 2.4-3.0-3.1-3.2- 3.3
Real Name: Carlos Gallego
Location: Medellin, Colombia

Re: Using the default of SSL_verify_mode of SSL_VERIFY_NONE

Post by carlosgallego » 21 Mar 2013, 18:36

Hi Mike,

Do you know if exists a final solution for this bug?
The downgrade of the package could affect another function of OTRS.

Thanks for your help.
OTRS 2.4.7 > 3.3 Ubuntu Server - Centos - RedHat, MySQL - PostgresSQL OracleDB

iamhawks
OTRS newbie
Posts: 3
Joined: 25 Mar 2013, 13:10
OTRS Version?: 3.2.3

Re: Using the default of SSL_verify_mode of SSL_VERIFY_NONE

Post by iamhawks » 01 Apr 2013, 15:09

I have the same problem...

Post Reply