diff --git a/FAQ.md b/FAQ.md index 1e02326351..108544d542 100644 --- a/FAQ.md +++ b/FAQ.md @@ -606,6 +606,8 @@ This can be caused by using an incorrect host name, so first double-check the ho Please see the documentation of the email provider about the right host name. Sometimes the right host name is in the error message. +Another possible cause is [Certificate transparency](https://github.com/appmattus/certificatetransparency) failing, so try disabling it in the connection settings tab page. + You should try to fix this by contacting your provider or by getting a valid security certificate because invalid security certificates are insecure and allow [man-in-the-middle attacks](https://en.wikipedia.org/wiki/Man-in-the-middle_attack). If money is an obstacle, you can get free security certificates from [Let’s Encrypt](https://letsencrypt.org). diff --git a/index.html b/index.html index 0c6443b9c9..43ac18cc00 100644 --- a/index.html +++ b/index.html @@ -552,6 +552,7 @@ Therefore, this issue can only be resolved by your email provider, or by installing the GitHub version of the app (as an update) and enabling insecure connections in the account/identity settings.** -->

… Untrusted … not in certificate …
… Invalid security certificate (Can’t verify identity of server) …
… Chain validation failed … timestamp check failed … Certificate expired at …

This can be caused by using an incorrect host name, so first double-check the host name in the advanced identity/account settings (tap Manual setup and account options). Please see the documentation of the email provider about the right host name. Sometimes the right host name is in the error message.

+

Another possible cause is Certificate transparency failing, so try disabling it in the connection settings tab page.

You should try to fix this by contacting your provider or by getting a valid security certificate because invalid security certificates are insecure and allow man-in-the-middle attacks. If money is an obstacle, you can get free security certificates from Let’s Encrypt.

The quick, but unsafe solution (not advised), is to enable Insecure connections in the advanced identity settings (navigation menu, tap Settings, tap Manual setup, tap Identities, tap the identity, tap Advanced).

Alternatively, you can accept the fingerprint of invalid server certificates like this: