Hi,
Recently thunderbird stopped being able to connect to mail.talktalk.net.
When it connect another server I see.
304 14.502182 192.168.0.2 213.120.69.4 TLSv1.2 571 Clie… (читать ещё)
Hi,
Recently thunderbird stopped being able to connect to mail.talktalk.net.
When it connect another server I see.
304 14.502182 192.168.0.2 213.120.69.4 TLSv1.2 571 Client Hello
Outbound connection to imap server from thunderbird
306 14.515497 213.120.69.4 192.168.0.2 TLSv1.2 1500 Server Hello
reply from imap server
308 14.515497 213.120.69.4 192.168.0.2 TLSv1.2 771 Certificate, Server Key Exchange, Server Hello Done
cert exchange for tls 1.2
whereas for mail.talktalk.net I see.
9 146.403246 192.168.0.2 153.92.174.228 TLSv1.3 571 Client Hello
41 146.440457 153.92.174.228 192.168.0.2 TLSv1.3 1500 Server Hello, Change Cipher Spec, Application Data
49 146.442019 153.92.174.228 192.168.0.2 TLSv1.3 1385 Application Data
51 146.452209 192.168.0.2 153.92.174.228 TLSv1.3 134 Change Cipher Spec, Application Data
The cert exchange from hello doesn't start.
They will likely blame the client though I am fairly convinced it's or pki cert problem.
What the server hello contents contains.
TLSv1.3 Record Layer: Change Cipher Spec Protocol: Change Cipher Spec
Content Type: Change Cipher Spec (20)
Version: TLS 1.2 (0x0303)
Length: 1
Change Cipher Spec Message
My guess they've enabled tls 1.3 protocol but not configured it work and are relying a fall back to 1.2.
The working connection doesn't initilases as tls 1.2.
Is there a way force a thuinderbird to use a specific tls version by server.