Pages: 1
RSS
Self-signed certificate rejected
 
I download email from my own server. I use TLS connections, but with TB 11.4.3, the handshake fails because the certificate is self-signed. I have added it to the certificate store (address book), but it is still rejected.  I can now only download mail by clicking OK in the dialog that pops up.  But I should not have to do that.  What is the workaround?
 
I'm not sure it will work in your case, but try Options -> S/MIME and TLS... -> Microsoft CryptoAPI
 
Problem solved.  This was a new machine I just built, and the motherboard driver package included a particular Norton Antivirus version, which it installed. Norton was trapping the self-signed certificate, inserting itself into the TLS handshake. I uninstalled the Norton AV.  No more TLS issues.
 
Great, thanks for the feedback, this is good to know. I was just writing the other day on another thread about avoiding old bloated AV software. Case in point!
 
AV software vendors must pay a lot of money to get their bloatware bundled, since modern Windows systems don't need it. Apparently the advertising is working, as I constantly hear people worrying about what AV they should have.
 
Exactly. On all computers I have, MS Defender and common sense have been doing the job for years now.
Pages: 1