Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #240729

Re: Jessie iceweasel: This Connection is Untrusted

From David Wright <deblis@lionunicorn.co.uk>
Newsgroups linux.debian.user
Subject Re: Jessie iceweasel: This Connection is Untrusted
Date 2021-10-01 17:20 +0200
Message-ID <D3sum-6Gm-5@gated-at.bofh.it> (permalink)
References <D3oh3-417-1@gated-at.bofh.it> <D3oTL-4tv-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Fri 01 Oct 2021 at 13:20:01 (+0200), Thomas Schmitt wrote:

> I would prefer not to rely on an allow-list.
> 
> So i currently ponder how to transplant the certificates from a Debian 10
> machine.
> man update-ca-certificates talks of
>   /etc/ssl/certs
>   /etc/ca-certificates.conf
>   /usr/share/ca-certificates
> In the latter i see on Debian 10:
>   ./mozilla
> with 126 .crt files.
> The Debian 8 machine has 172 files in there.
> The ca-certificates.conf files seem just to list those files on both
> machines.
> 
> So a brute force attempt would be to rename the two directories and
> the file to other names and to then copy the Debian 10 stuff to the
> original names. The new /etc/ssl/certs would start empty and be
> populated by update-ca-certificates(8).
> 
> Well, same old question: How bad an idea is this ?
> What should i read before making such theories ?

Looking at the Packages files for wheezy and stretch, the dependencies
haven't changed:

  stretch
Package: ca-certificates
Version: 20200601~deb9u1
Installed-Size: 380
Maintainer: Michael Shuler <michael@pbandjelly.org>
Architecture: all
Depends: openssl (>= 1.0.0), debconf (>= 0.5) | debconf-2.0

  wheezy
Package: ca-certificates
Version: 20130119+deb7u1
Installed-Size: 432
Maintainer: Michael Shuler <michael@pbandjelly.org>
Architecture: all
Depends: openssl (>= 1.0.0), debconf (>= 0.5) | debconf-2.0

So under the circumstances, having backed up the files in /etc
and /usr/share for ca-certificates and openssl, I would install
stretch's version manually, using the variant syntax:
  apt ./ca-certificates_20200601~deb9u1_all.deb

Cheers,
David.

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Re: Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 12:30 +0200
  Re: Jessie iceweasel: This Connection is Untrusted <tomas@tuxteam.de> - 2021-10-01 12:50 +0200
    Re: Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 13:30 +0200
      Re: Jessie iceweasel: This Connection is Untrusted <tomas@tuxteam.de> - 2021-10-01 13:40 +0200
      Re: Jessie iceweasel: This Connection is Untrusted David Wright <deblis@lionunicorn.co.uk> - 2021-10-01 17:20 +0200

csiph-web