# system default interimap --debug || error ! grep -E "^remote: Disabling SSL protocols: " <"$STDERR" || error # TODO deprecated ! grep -E "^remote: Minimum SSL/TLS protocol version: " <"$STDERR" || error ! grep -E "^remote: Maximum SSL/TLS protocol version: " <"$STDERR" || error grep -E "^remote: SSL protocol: TLSv" <"$STDERR" || error # backup config install -m0600 "$XDG_CONFIG_HOME/interimap/config" "$XDG_CONFIG_HOME/interimap/config~" with_remote_tls_protocols() { install -m0600 "$XDG_CONFIG_HOME/interimap/config~" "$XDG_CONFIG_HOME/interimap/config" printf "SSL_protocols = %s\\n" "$*" >>"$XDG_CONFIG_HOME/interimap/config" } # disable TLSv1.2 and earlier with_remote_tls_protocols "!SSLv2" "!SSLv3" "!TLSv1" "!TLSv1.1" "!TLSv1.2" interimap --debug || error grep -Fx "remote: Disabling SSL protocols: SSLv3, TLSv1, TLSv1.1, TLSv1.2" <"$STDERR" || error grep -E "^remote: SSL protocol: TLSv1\.3 " <"$STDERR" || error interimap || error grep -E "^remote: WARNING: SSL_protocols is deprecated " <"$STDERR" || error "no deprecation warning" # force TLSv1.2 with_remote_tls_protocols "TLSv1.2" interimap --debug || error grep -Fx "remote: Disabling SSL protocols: SSLv3, TLSv1, TLSv1.1, TLSv1.3" <"$STDERR" || error grep -E "^remote: SSL protocol: TLSv1\.2 " <"$STDERR" || error # force TLSv1 to TLSv1.2 with_remote_tls_protocols "TLSv1" "TLSv1.1" "TLSv1.2" interimap --debug || error grep -Fx "remote: Disabling SSL protocols: SSLv3, TLSv1.3" <"$STDERR" || error grep -E "^remote: SSL protocol: TLSv(1\.[12])? " <"$STDERR" || error # force SSLv2 and SSLv3; this fails due to dovecot's ssl_min_protocol=TLSv1 with_remote_tls_protocols "SSLv2" "SSLv3" ! interimap --debug || error grep -Fx "remote: Disabling SSL protocols: TLSv1, TLSv1.1, TLSv1.2, TLSv1.3" <"$STDERR" || error grep -Fx "remote: ERROR: Can't initiate TLS/SSL handshake" <"$STDERR" || error # make sure we didn't send any credentials or started speaking IMAP ! grep -E "^remote: C: .* (AUTHENTICATE|LOGIN) " <"$STDERR" || error grep -Fx "remote: IMAP traffic (bytes): recv 0 sent 0" <"$STDERR" || error # new interface: SSL_protocol_{min,max} with_remote_tls_protocol_min_max() { install -m0600 "$XDG_CONFIG_HOME/interimap/config~" "$XDG_CONFIG_HOME/interimap/config" if [ -n "${1-}" ]; then printf "SSL_protocol_min = %s\\n" "$1" >>"$XDG_CONFIG_HOME/interimap/config" fi if [ -n "${2-}" ]; then printf "SSL_protocol_max = %s\\n" "$2" >>"$XDG_CONFIG_HOME/interimap/config" fi } # disable TLSv1.2 and earlier # XXX this test assumes that TLSv1.3 is the highest version supported with_remote_tls_protocol_min_max "TLSv1.3" interimap --debug || error grep -Fx "remote: Minimum SSL/TLS protocol version: TLSv1.3" <"$STDERR" || error ! grep -E "^remote: Maximum SSL/TLS protocol version: " <"$STDERR" || error grep -E "^remote: SSL protocol: TLSv1\.3 " <"$STDERR" || error # force TLSv1.2 with_remote_tls_protocol_min_max "TLSv1.2" "TLSv1.2" interimap --debug || error grep -Fx "remote: Minimum SSL/TLS protocol version: TLSv1.2" <"$STDERR" || error grep -Fx "remote: Maximum SSL/TLS protocol version: TLSv1.2" <"$STDERR" || error grep -E "^remote: SSL protocol: TLSv1\.2 " <"$STDERR" || error # disable TLSv1.2 and later with_remote_tls_protocol_min_max "" "TLSv1.1" interimap --debug || error ! grep -E "^remote: Minimum SSL/TLS protocol version: " <"$STDERR" || error grep -Fx "remote: Maximum SSL/TLS protocol version: TLSv1.1" <"$STDERR" || error grep -E "^remote: SSL protocol: TLSv1\.1 " <"$STDERR" || error # force SSLv3 to to TLSv1.1 with_remote_tls_protocol_min_max "SSLv3" "TLSv1.1" interimap --debug || error grep -Fx "remote: Minimum SSL/TLS protocol version: SSLv3" <"$STDERR" || error grep -Fx "remote: Maximum SSL/TLS protocol version: TLSv1.1" <"$STDERR" || error grep -E "^remote: SSL protocol: TLSv1(\.1)? " <"$STDERR" || error # force SSLv3; this fails due to dovecot's ssl_min_protocol=TLSv1 with_remote_tls_protocol_min_max "SSLv3" "SSLv3" ! interimap --debug || error grep -Fx "remote: Minimum SSL/TLS protocol version: SSLv3" <"$STDERR" || error grep -Fx "remote: Maximum SSL/TLS protocol version: SSLv3" <"$STDERR" || error grep -Fx "remote: ERROR: Can't initiate TLS/SSL handshake" <"$STDERR" || error # make sure we didn't send any credentials or started speaking IMAP ! grep -E "^remote: C: .* (AUTHENTICATE|LOGIN) " <"$STDERR" || error grep -Fx "remote: IMAP traffic (bytes): recv 0 sent 0" <"$STDERR" || error # vim: set filetype=sh :