From 1d49034782e3ff0e4384bad4e927a895e2a97839 Mon Sep 17 00:00:00 2001 From: Julien Castiaux Date: Wed, 14 Feb 2024 13:30:14 +0100 Subject: [PATCH] [FIX] base: smtp_auth=certificate with SSL/TLS Start a SMTPS server with client certificate authentication. In Odoo configure an outgoing mail server with encryption="ssl/tls" and authentication="certicifate". Load a valid client certificate and key to use with the SMTPS server then test the connection. The connection fails because the client certificate wasn't sent during the TLS handshake. If you're having trouble running a SMTPS server, I made a script here: https://gist.github.com/Julien00859/5090d1cff6c02197e5854aabb67bf5ac It uses aiosmtpd, a light pure python smtp server, install it with pip. You'll need to copy your snakeoil ssl key + cert inside your /tmp directory and to expose them to your current user: # public cert cp /etc/ssl/certs/ssl-cert-snakeoil.pem /tmp # private key sudo cp /etc/ssl/private/ssl-cert-snakeoil.key /tmp sudo chmod 400 /tmp/ssl-cert-snakeoil.key sudo chown $USER /tmp/ssl-cert-snakeoil.key task-3703209 closes odoo/odoo#162297 X-original-commit: b3d7c1fc9c017a4354dc4a6f8abfbf590bc26a51 Signed-off-by: Thibault Delavallee (tde) --- odoo/addons/base/models/ir_mail_server.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/odoo/addons/base/models/ir_mail_server.py b/odoo/addons/base/models/ir_mail_server.py index 8fd2d1504db..25dafa77ebf 100644 --- a/odoo/addons/base/models/ir_mail_server.py +++ b/odoo/addons/base/models/ir_mail_server.py @@ -397,7 +397,7 @@ class IrMailServer(models.Model): "You could use STARTTLS instead. " "If SSL is needed, an upgrade to Python 2.6 on the server-side " "should do the trick.")) - connection = smtplib.SMTP_SSL(smtp_server, smtp_port, timeout=SMTP_TIMEOUT) + connection = smtplib.SMTP_SSL(smtp_server, smtp_port, timeout=SMTP_TIMEOUT, context=ssl_context) else: connection = smtplib.SMTP(smtp_server, smtp_port, timeout=SMTP_TIMEOUT)