Skip to content

Webtop 1.5.9 login fails with invalid mail TLS certificate #8193

Description

@DavidePrincipi

After updating the Webtop app to version 1.5.9, users cannot log in to Webtop. The problem was reported on installations where the Mail application uses an expired or self-signed TLS certificate.

Steps to reproduce

  • Configure the Mail application with an expired or self-signed TLS certificate
  • Install or update Webtop to version 1.5.9
  • Log in to Webtop with a mail user

Expected behavior

Login succeeds, as with previous Webtop versions.

Actual behavior

Webtop reports a login error. Dovecot logs a TLS handshake failure:

dovecot[106831]: imap-login: Disconnected: Connection closed: SSL_accept() failed: error:0A000416:SSL routines::ssl/tls alert certificate unknown: SSL alert number 46 (no auth attempts in 0 secs): user=<>, rip=10.5.4.1, lip=10.5.4.1, TLS handshaking: SSL_accept() failed: error:0A000416:SSL routines::ssl/tls alert certificate unknown: SSL alert number 46, session=<GeQjBK9cpI4KBQQB>

Webtop logs:

webapp[34271]: 2026-09-30 10:23:40 [ERROR] com.sonicle.webtop.mail.MailAccount - Error connecting to the mail server 10.5.4.1
webapp[34271]: jakarta.mail.MessagingException: STARTTLS failure

Hypothesis: Dovecot advertises STARTTLS on the internal IMAP connection, and a new Webtop library now tries to enable encryption, failing certificate validation.

To check whether the IMAP server certificate is affected (replace the IP with the node VPN IP address):

openssl s_client -connect 10.5.4.1:143 -starttls imap </dev/null | grep ^Verify

Workaround: configure a valid TLS certificate for the Mail application.

Components

  • Webtop 1.5.9 (ns8-webtop)
  • Mail (Dovecot)

See also

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

testingPackages are available from testing repositories

Type

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions