[FIX] base: smtp_auth=certificate with SSL/TLS

Start a SMTPS server with client certificate authentication. In Odoo
configure an outgoing mail server with encryption="ssl/tls" and
authentication="certicifate". Load a valid client certificate and key to
use with the SMTPS server then test the connection.

The connection fails because the client certificate wasn't sent during
the TLS handshake.

If you're having trouble running a SMTPS server, I made a script here:
https://gist.github.com/Julien00859/5090d1cff6c02197e5854aabb67bf5ac
It uses aiosmtpd, a light pure python smtp server, install it with pip.
You'll need to copy your snakeoil ssl key + cert inside your /tmp
directory and to expose them to your current user:

    # public cert
    cp /etc/ssl/certs/ssl-cert-snakeoil.pem /tmp

    # private key
    sudo cp /etc/ssl/private/ssl-cert-snakeoil.key /tmp
    sudo chmod 400 /tmp/ssl-cert-snakeoil.key
    sudo chown $USER /tmp/ssl-cert-snakeoil.key

task-3703209

closes odoo/odoo#162297

X-original-commit: b3d7c1fc9c017a4354dc4a6f8abfbf590bc26a51
Signed-off-by: Thibault Delavallee (tde) <tde@openerp.com>
This commit is contained in:
Julien Castiaux
2024-04-18 07:28:35 +00:00
parent 442e032cce
commit 1d49034782
+1 -1
View File
@@ -397,7 +397,7 @@ class IrMailServer(models.Model):
"You could use STARTTLS instead. "
"If SSL is needed, an upgrade to Python 2.6 on the server-side "
"should do the trick."))
connection = smtplib.SMTP_SSL(smtp_server, smtp_port, timeout=SMTP_TIMEOUT)
connection = smtplib.SMTP_SSL(smtp_server, smtp_port, timeout=SMTP_TIMEOUT, context=ssl_context)
else:
connection = smtplib.SMTP(smtp_server, smtp_port, timeout=SMTP_TIMEOUT)