Koozali.org: home of the SME Server

Lets Encrypt and Android...Sharing experience and pb

Offline georgios

  • ***
  • 81
  • +0/-0
Lets Encrypt and Android...Sharing experience and pb
« on: February 16, 2017, 12:11:43 AM »
Hi, dear friend,

To share some experience :

I decided last December to switch to Lets Encrypt certificate for our SME 9.1 email server (in order to stop the basic unsigned certificate) for the well know reason.

First Test in December (we have 70/80 users), after having switch to 1st LetsEncrypt SSL certificate:

 - OK for receiving/sending mail from Outlook, Thunderbird, Ios, Mac (mail), Android (only Samsung S7, Huawei P8)
- Problem with "LIGHT" Android Phone like Samsung A3, Huawei lite, some custom Android phone from our mobile provider "Android Vofadone Smartphone"

After having turn to the Lets encrypt certificate, no emails were downloaded on the "Light" Android phone.
the thing is we have around 8 Android phones and I had to clear the data of the application of Mail or Remove/add the account in order to receive the email of our server.

Second Test: 2nd week of February  the LetsEncrypt SSL certificate has been renewed automatically by the cron job.

Result = Same Problem, we can't receive/send emails with the "Light" Android mobile phone.


I decided to move to my *.domain.com wild card SSL certificate (rapidSSL).

Why : just because I do not have time to check 10 phones every 3 months.

FYI: my Android "problem" phones are configured with Mail basic app. from Android in Imap (SSL) or ActiveSync (SOGo).



Offline Stefano

  • *
  • 10,839
  • +2/-0
Re: Lets Encrypt and Android...Sharing experience and pb
« Reply #1 on: February 16, 2017, 12:27:57 AM »
Hi georgios.. sounds like a email client issue.. I used k9-mail on a 30€ vodafone branded phone with android 4.4 (IIRC), letsencrypt cert and had no issues..

will try again if I find that phone again and report back, but don't hold your breath

Offline ReetP

  • *
  • 3,731
  • +5/-0
Re: Lets Encrypt and Android...Sharing experience and pb
« Reply #2 on: February 16, 2017, 07:31:53 PM »
1. Don't mix certificates if you can help it. Saves confusion :-)

2. Built in clients are pants. Period. Android... K9 is good and I have used it for a long time but watch for changes that aren't clearly announced (see recent pgp client change)  Profimail is good as well.

3. iOS 10 seems to have an issue with certs with multiple hosts/domains. Make sure you configure the mail server as whatever the first host/domain is in your domains.txt file (and therefore in your letencrypt cert) or you may get errors.
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation