Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1189242

Bug#1034586: always reports inactive/expired certificate on armhf

From Glenn Strauss <gs-bugs.debian.org@gluelogic.com>
Newsgroups linux.debian.bugs.dist
Subject Bug#1034586: always reports inactive/expired certificate on armhf
Date 2024-03-06 13:00 +0100
Message-ID <IeY6e-eNmZ-11@gated-at.bofh.it> (permalink)
References <Gm3fb-2Xx4-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


tobias.jakobi.compleo added more details in
https://redmine.lighttpd.net/issues/3244

The issue appears to be lighttpd being built with 64-bit time_t, but the
underlying openssl library being built with 32-bit time_t *and* exposing
an API interface using time_t.

The result is that lighttpd might issue error trace that a certificate
is expired when the certificate is not expired.  There should be no
other ill-effect besides the error trace at startup.

However, some distros have startup scripts which check config syntax,
and will treat `lighttpd -f /etc/lighttpd/lighttpd.conf -tt` as an error
if there is error trace, even if the lighttpd command exits 0 (success)
that the syntax is valid.

---

Most OS distros have migrated or are in the process of migrating to
64-bit time_t.  However, lighttpd 1.4.75 will contain a workaround for
older systems to address this issue with older libraries on armhf.

Back to linux.debian.bugs.dist | Previous | Next | Find similar | Unroll thread


Thread

Bug#1034586: always reports inactive/expired certificate on armhf Glenn Strauss <gs-bugs.debian.org@gluelogic.com> - 2024-03-06 13:00 +0100

csiph-web