Allowing less secure apps - "Goozilla" vs Mozilla

Markus Schönhaber fedora-users at list-post.mks-mail.de
Fri Feb 6 10:56:16 UTC 2015


Am 06.02.2015 um 05:31 schrieb poma:

> Send Message Error
> 
> Sending of message failed. The SMTP server smtp.gmail.com does not
> seem to support encrypted passwords. If you just set up this account,
> please try changing to 'Normal password' as the 'Authentication
> method' in the 'Account Settings | Server settings'. If it used to
> work and now suddenly fails, please contact your email administrator
> or provider.

AFAICT, what recent Thunderbird versions call "encrypted password" does
mean that some challenge-response authentication mechanism (like
CRAM-MD5) is used, so that the client can prove to the server that it
really knows the correct password, without sending it in plain text.
These mechanisms were useful, when no encrypted connection to the server
was available.
BUT, if you use a TLS-secured communication channel to the server (as
you should!), the use of challenge-response mechanisms is pointless (and
not supported by gmail), since the communication is already encrypted.
Therefore, choosing "Normal password" is the way to go.

-- 
Regards
  mks


More information about the users mailing list