After updating the Webtop app to version 1.5.9, users cannot log in to Webtop. The problem was reported on installations where the Mail application uses an expired or self-signed TLS certificate.
Steps to reproduce
- Configure the Mail application with an expired or self-signed TLS certificate
- Install or update Webtop to version 1.5.9
- Log in to Webtop with a mail user
Expected behavior
Login succeeds, as with previous Webtop versions.
Actual behavior
Webtop reports a login error. Dovecot logs a TLS handshake failure:
dovecot[106831]: imap-login: Disconnected: Connection closed: SSL_accept() failed: error:0A000416:SSL routines::ssl/tls alert certificate unknown: SSL alert number 46 (no auth attempts in 0 secs): user=<>, rip=10.5.4.1, lip=10.5.4.1, TLS handshaking: SSL_accept() failed: error:0A000416:SSL routines::ssl/tls alert certificate unknown: SSL alert number 46, session=<GeQjBK9cpI4KBQQB>
Webtop logs:
webapp[34271]: 2026-09-30 10:23:40 [ERROR] com.sonicle.webtop.mail.MailAccount - Error connecting to the mail server 10.5.4.1
webapp[34271]: jakarta.mail.MessagingException: STARTTLS failure
Hypothesis: Dovecot advertises STARTTLS on the internal IMAP connection, and a new Webtop library now tries to enable encryption, failing certificate validation.
To check whether the IMAP server certificate is affected (replace the IP with the node VPN IP address):
openssl s_client -connect 10.5.4.1:143 -starttls imap </dev/null | grep ^Verify
Workaround: configure a valid TLS certificate for the Mail application.
Components
- Webtop 1.5.9 (ns8-webtop)
- Mail (Dovecot)
See also
After updating the Webtop app to version 1.5.9, users cannot log in to Webtop. The problem was reported on installations where the Mail application uses an expired or self-signed TLS certificate.
Steps to reproduce
Expected behavior
Login succeeds, as with previous Webtop versions.
Actual behavior
Webtop reports a login error. Dovecot logs a TLS handshake failure:
Webtop logs:
Hypothesis: Dovecot advertises STARTTLS on the internal IMAP connection, and a new Webtop library now tries to enable encryption, failing certificate validation.
To check whether the IMAP server certificate is affected (replace the IP with the node VPN IP address):
Workaround: configure a valid TLS certificate for the Mail application.
Components
See also