Staging: expose Notes IMAP with a valid certificate for the generated Mac profile #858

Open
opened 2026-10-02 16:21:22 +00:00 by kayg · 1 comment
Owner

Found during #476 Round 2 on 2026-10-02.

Staging at https://dev.calternal.com has a trusted HTTPS edge. Public DNS now returns 168.119.145.115. The server-generated Mac profile advertises a Notes account at dev.calternal.com:993.

On staging, as User calternal, ss -ltn lists 10.70.3.158:8080, DNS ports and NetBird SSH. There is no IMAP listener. The job brief confirms that Traefik exposes HTTP only. Therefore Apple Notes cannot use the generated account. Notes is not exposed, not a failed Notes sync test.

Expose the Notes IMAP listener through the staging edge with a certificate valid for dev.calternal.com. Verify TLS from the Mac and then rerun the Notes matrix. Check the profile validation responder if the Apple account needs it. Do not weaken certificate checks or change Mac trust settings. No production change is requested by this finding.

Acceptance: the generated profile can connect with normal certificate validation; create, edit, move and delete a Note in both directions with a second sync. The Mac was unreachable later in this run, so no direct Mac IMAP handshake is claimed.

Found during #476 Round 2 on 2026-10-02. Staging at `https://dev.calternal.com` has a trusted HTTPS edge. Public DNS now returns `168.119.145.115`. The server-generated Mac profile advertises a Notes account at `dev.calternal.com:993`. On staging, as User `calternal`, `ss -ltn` lists `10.70.3.158:8080`, DNS ports and NetBird SSH. There is no IMAP listener. The job brief confirms that Traefik exposes HTTP only. Therefore Apple Notes cannot use the generated account. Notes is **not exposed**, not a failed Notes sync test. Expose the Notes IMAP listener through the staging edge with a certificate valid for `dev.calternal.com`. Verify TLS from the Mac and then rerun the Notes matrix. Check the profile validation responder if the Apple account needs it. Do not weaken certificate checks or change Mac trust settings. No production change is requested by this finding. Acceptance: the generated profile can connect with normal certificate validation; create, edit, move and delete a Note in both directions with a second sync. The Mac was unreachable later in this run, so no direct Mac IMAP handshake is claimed.
Author
Owner

Real Mac evidence expands the impact of #858: installing the combined server-generated Calendar + Notes profile failed and rolled back Calendar as well. On macOS 27, mdmclient reported MailPayloadPlugin account-save failure, com.apple.accounts Code=1, nested error Code=60, Operation timed out connecting to dev.calternal.com on the default ports. The log then reported Install Failed and removed the calternal Calendar account payload. profiles list showed no calternal staging profile; Internet Accounts showed No accounts after Calendar/Reminders relaunch. No owner-password prompt appeared. HTTPS from the Mac returned 200 with TLS verification 0, and authenticated DAV discovery returned 207. The job will use a new server-generated profile with CalDAV access and no Notes scope to continue independent Calendar/Reminders testing. This does not verify Notes and does not change the edge.

Real Mac evidence expands the impact of #858: installing the combined server-generated Calendar + Notes profile failed and rolled back Calendar as well. On macOS 27, `mdmclient` reported `MailPayloadPlugin` account-save failure, `com.apple.accounts Code=1`, nested error `Code=60`, `Operation timed out` connecting to `dev.calternal.com` on the default ports. The log then reported `Install Failed` and removed the `calternal Calendar account` payload. `profiles list` showed no calternal staging profile; Internet Accounts showed `No accounts` after Calendar/Reminders relaunch. No owner-password prompt appeared. HTTPS from the Mac returned 200 with TLS verification 0, and authenticated DAV discovery returned 207. The job will use a new server-generated profile with CalDAV access and no Notes scope to continue independent Calendar/Reminders testing. This does not verify Notes and does not change the edge.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#858
No description provided.