GBat

Q: SMTP with SSL completely broken after iOS 8.4 update

Hello,

 

I'm an admin for a 500 user email system, about 200 of which are iPhones.  All users who have updated to 8.4 are unable to connect to our secure SMTP server.  This has never been an issue on previous iOS versions (server unchanged since 2011).

 

The server uses SMTP over SSL, MD5 Ch/Resp on port 587.

 

The sendmail server is logging the following on connection attempts:

 

Jul  3 10:30:36 mail1 sm-mta[23928]: STARTTLS=server, error: accept failed=0, SSL_error=5, errno=0, retry=-1

Jul  3 10:30:36 mail1 sm-mta[23928]: t63FUZlI023928: [***IP***] did not issue MAIL/EXPN/VRFY/ETRN during connection to MSA

iOS 8.4

Posted on Jul 3, 2015 8:35 AM

Close

Q: SMTP with SSL completely broken after iOS 8.4 update

  • All replies
  • Helpful answers

Page 1 Next
  • by miluc,

    miluc miluc Jul 4, 2015 3:20 AM in response to GBat
    Level 1 (0 points)
    Jul 4, 2015 3:20 AM in response to GBat

    I had this too (1 iPhone and iPad). Workaround: switch off the Handoff feature did the trick for me.

  • by Henningm,

    Henningm Henningm Jul 5, 2015 5:56 AM in response to miluc
    Level 1 (0 points)
    Jul 5, 2015 5:56 AM in response to miluc

    I have the same issue, but turning off the Handoff feature did not solve the problem

  • by Mjbowdler,

    Mjbowdler Mjbowdler Jul 5, 2015 6:01 PM in response to GBat
    Level 1 (0 points)
    Jul 5, 2015 6:01 PM in response to GBat

    after the same problem I switched off "use SSL" in SMTP settings and now email sends fine In my case

  • by NuclearMedia,

    NuclearMedia NuclearMedia Jul 6, 2015 6:55 AM in response to GBat
    Level 1 (0 points)
    Jul 6, 2015 6:55 AM in response to GBat

    I'm having this problem as well. iOS 8.4 devices hanging on SSL over SMTP 465 or 587.

     

    Many people are reporting this issue, yet not solutions posted online. If you solve the issue (client or server–side) please post here.

     

    Thanks!

  • by Mjbowdler,

    Mjbowdler Mjbowdler Jul 6, 2015 7:21 AM in response to NuclearMedia
    Level 1 (0 points)
    Jul 6, 2015 7:21 AM in response to NuclearMedia

    This from our email provider (Easyspace) has resolved the issue for our team:

     

    Auto detect account settings: off

    Outgoing server: smtp.iomartmail.com (this is the easyspace smtp server so you should insert your own)

    Outgoing server port: 587

    SSL: Off  (up until this point iOS 8.4 we always had to have SSL "ON")

    Authentication: Password

    Allow insecure authentication: on  (this isn't an option so we have used password and the same settings as email)

    Username: Full email address (this again is how easyspace run usernames so yours might be different)

    Password: *********

     

     

     

    Kind regards

     

    Martin

  • by NuclearMedia,

    NuclearMedia NuclearMedia Jul 6, 2015 7:22 AM in response to Mjbowdler
    Level 1 (0 points)
    Jul 6, 2015 7:22 AM in response to Mjbowdler

    In other words, turn off SSL? This defeats the purpose of SSL.

     

    If this is the only solution (and I've seen it advised elsewhere too), then the only conclusion is that iOS 8.4 is causing thousands of users to revert to insecure mail transport which is a major security flaw with the new iOS.

  • by Mjbowdler,

    Mjbowdler Mjbowdler Jul 6, 2015 7:27 AM in response to NuclearMedia
    Level 1 (0 points)
    Jul 6, 2015 7:27 AM in response to NuclearMedia

    Yep, a workaround


    The choice is "do you want your email to work or not before a proper fix comes along?"

     

    Got a way to go to be more unstable or less secure than a pc though !

     

    :-)

  • by NuclearMedia,

    NuclearMedia NuclearMedia Jul 6, 2015 7:50 AM in response to Mjbowdler
    Level 1 (0 points)
    Jul 6, 2015 7:50 AM in response to Mjbowdler

    Of course I want my email to work, and I have advised my clients of their options and of the risks. But the fact remains that, if indeed Apple has caused many users to turn off their SSL, even temporarily, they have made the users' information vulnerable and it is therefore a major security flaw. Not to mention, due to the widespread nature of this problem, it's not exactly going to be a secret from those who wish to exploit it.

     

    Eventually, after speaking with two Apple support reps, the issue was elevated to engineering. Hopefully I'll have good news for us all "in the next 2 business days".

  • by pbeltranc,

    pbeltranc pbeltranc Jul 6, 2015 1:20 PM in response to GBat
    Level 1 (0 points)
    Jul 6, 2015 1:20 PM in response to GBat

    Hello,

    Tengo el mismo problema corro un servidor sendmail  y uso el puerto 465 con SSL , desde la actualizacion  con la version ios 8.4 no se envían los correos y termina con tiempo de servidor agotado.

    He leido por ahi que desactivemos el SSL el SERVER SMTP , pero vulnera mi seguridad .

  • by gymsok99,

    gymsok99 gymsok99 Jul 7, 2015 7:00 AM in response to GBat
    Level 1 (0 points)
    Jul 7, 2015 7:00 AM in response to GBat

    I tried to turn SSL "OFF" , but then my email account started "Verifying"... stuck endlessly.

    Catch 22??? The "Verifying" tried to send an email which it can't?
    @Mjbowdler,: How did you turn SSL off?

     

    JimS

  • by Mjbowdler,

    Mjbowdler Mjbowdler Jul 7, 2015 7:10 AM in response to gymsok99
    Level 1 (0 points)
    Jul 7, 2015 7:10 AM in response to gymsok99

    You need to check with your pop email provider as the settings available to you  - whether your email will function with SSL off and what other settings need to be selected to allow this (assuming your provider will allow).  Our provider (Easyspace) allows the functionality but others may restrict because of the security risk that NuclearMedia has highlighted.

     

    We're all in workaround mode awaiting a proper fix.

  • by eluis,

    eluis eluis Jul 7, 2015 8:40 AM in response to GBat
    Level 1 (0 points)
    Jul 7, 2015 8:40 AM in response to GBat

    Is there any official position from Apple regarding this issue? When will be released the next update?

    My dozens of users are unable to send email trough their iPhones/iPads.

    Thanks..

  • by NuclearMedia,

    NuclearMedia NuclearMedia Jul 7, 2015 9:55 AM in response to GBat
    Level 1 (0 points)
    Jul 7, 2015 9:55 AM in response to GBat

    Apple provided this update: Use modern cryptographic practices when setting up SSL and TLS services on your server - Apple Support

     

    "To ensure security and privacy for your users, and interoperability with Apple products, server administrators should use a group size of 2048 bits or greater when using Diffie-Hellman key exchange. ...devices no longer connect to servers or webpages that are set up using weaker Diffie-Hellman encryption"

     

    If only someone had just shut out IE lt 9 this swiftly.

  • by drednaught_admin,

    drednaught_admin drednaught_admin Jul 8, 2015 1:43 PM in response to GBat
    Level 1 (0 points)
    Jul 8, 2015 1:43 PM in response to GBat

    Any admins with users experiencing this issue need to verify they've properly generated the initial STARTTLS config to an acceptable level.

    Sendmail and other mail programs have a default export compliant 512 key which you must generate to 2048 or high to resolve.

     

    More info: https://weakdh.org/sysadmin.html

Page 1 Next