Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #240709 > unrolled thread
| Started by | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| First post | 2021-10-01 09:50 +0200 |
| Last post | 2021-10-01 17:40 +0200 |
| Articles | 7 — 6 participants |
Back to article view | Back to linux.debian.user
Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 09:50 +0200
Re: Jessie iceweasel: This Connection is Untrusted "Andrew M.A. Cater" <amacater@einval.com> - 2021-10-01 12:00 +0200
Re: Jessie iceweasel: This Connection is Untrusted Tobias Diekershoff <tobias.diekershoff@gmx.net> - 2021-10-01 14:10 +0200
[SOLVED] Re: Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 18:40 +0200
Re: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted <tomas@tuxteam.de> - 2021-10-01 19:30 +0200
Re: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted mett <mett@pmars.jp> - 2021-10-02 19:20 +0200
Re: Jessie iceweasel: This Connection is Untrusted Curt <curty@free.fr> - 2021-10-01 17:40 +0200
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2021-10-01 09:50 +0200 |
| Subject | Jessie iceweasel: This Connection is Untrusted |
| Message-ID | <D3lsS-2it-3@gated-at.bofh.it> |
Hi,
i am confronted with an old Debian 8 "jessie" machine where since
(probably) yesterday the Iceweasel browser does not work any more
with many websites. E.g.
This Connection is Untrusted
...
lists.debian.org uses an invalid security certificate.
The certificate is not trusted because the issuer certificate is unknown.
(Error code: sec_error_unknown_issuer)
Googling around (with Debian 10) gives me the idea that the installed
package ca-certificates is outdated.
It is currently not an option to upgrade the system to a newer Debian
version. I am even scared to do what i deduce from
https://serverfault.com/questions/891734/debian-wheezy-outdated-root-certificates
namely:
- add to /etc/apt/sources.list :
deb http://ftp.de.debian.org/debian-security/ jessie/updates main
- run:
apt-get update
apt-get install ca-certificates
Is this a good idea ? Will it do harm to the 6 year old system ?
---------------------------------------------------------------------------
If not a good idea:
Is there a known procedure to get and install the certificates manually ?
I see proposals to download .crt files and run
update-ca-certificates --fresh
Where would i get a current set of certificates ?
How do i identify the certificates which the browser does not accept ?
wget does not tell me the certificate name either.
Have a nice day :)
Thomas
[toc] | [next] | [standalone]
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Date | 2021-10-01 12:00 +0200 |
| Message-ID | <D3nuF-3uV-3@gated-at.bofh.it> |
| In reply to | #240709 |
On Fri, Oct 01, 2021 at 09:41:45AM +0200, Thomas Schmitt wrote: > Hi, > > i am confronted with an old Debian 8 "jessie" machine where since > (probably) yesterday the Iceweasel browser does not work any more > with many websites. E.g. > > This Connection is Untrusted > ... > lists.debian.org uses an invalid security certificate. > The certificate is not trusted because the issuer certificate is unknown. > (Error code: sec_error_unknown_issuer) > > Googling around (with Debian 10) gives me the idea that the installed > package ca-certificates is outdated. > > It is currently not an option to upgrade the system to a newer Debian > version. I am even scared to do what i deduce from > https://serverfault.com/questions/891734/debian-wheezy-outdated-root-certificates > namely: > > - add to /etc/apt/sources.list : > deb http://ftp.de.debian.org/debian-security/ jessie/updates main > > - run: > apt-get update > apt-get install ca-certificates > > Is this a good idea ? Will it do harm to the 6 year old system ? > > --------------------------------------------------------------------------- > If not a good idea: > > Is there a known procedure to get and install the certificates manually ? > I see proposals to download .crt files and run > update-ca-certificates --fresh > > Where would i get a current set of certificates ? > > How do i identify the certificates which the browser does not accept ? > wget does not tell me the certificate name either. > > > Have a nice day :) > > Thomas > Honestly - I'd suggest disconnecting the machine from the Internet until you are able to upgrade it - it's far enough out of support that it's now ELTS. https://deb.freexian.com/extended-lts/ I'd suggest that you consider immediate upgrade if you can - what is the reason you cannot? All the very best, as ever, Andy Cater
[toc] | [prev] | [next] | [standalone]
| From | Tobias Diekershoff <tobias.diekershoff@gmx.net> |
|---|---|
| Date | 2021-10-01 14:10 +0200 |
| Message-ID | <D3pwu-4W0-7@gated-at.bofh.it> |
| In reply to | #240709 |
[Multipart message — attachments visible in raw view] — view raw
Hey Thomas On Fri, 01 Oct 2021 09:41:45 +0200 "Thomas Schmitt" <scdbackup@gmx.net> wrote: > i am confronted with an old Debian 8 "jessie" machine where since > (probably) yesterday the Iceweasel browser does not work any more > with many websites. E.g. Are the untrusted certificates LetsEncrypt issued certs? Their old R3 cert (signed by DST Root CA X3) expired Sept 29th (see e.g. [1]). Maybe jessie has not gotten the new certs to trust LE certs now? Greetings! Tobias 1: https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190 -- Bōsī se sȳrī glaesās PGP-ID ......... 0x25FE376FF17694A1
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2021-10-01 18:40 +0200 |
| Subject | [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted |
| Message-ID | <D3tJL-7mq-5@gated-at.bofh.it> |
| In reply to | #240720 |
Hi, as tomas predicted it can be done by handwork. Tobias Diekershoff gave a good hint but i was not smart enough to make use of it before i found out the clicky way. The solution was to import to iceweasel the certificate file /etc/ssl/certs/ISRG_Root_X1.pem ------------------------------------------------------------------------ Long story: I replaced the directory trees /etc/ssl/certs /usr/share/ca-certificates and the file /etc/ca-certificates.conf by their counterparts of Debian 10. Then i ran update-ca-certificates This did not help, even with newly started Iceweasel. So i clicked my way through Preferences -> Advanced -> Cerificates to button "View Certificates" which offers me an obscure list and a button "Import". This gives me a file browser which i navigate to /etc/ssl/certs. There are 128 .pem files from Debian 10. To reduce the work i diffed the list of .pem files in both /etc/ssl/certs and began to add those which are new in Debian 10: 49 files. Many new ones did have no effect. But /etc/ssl/certs/ISRG_Root_X1.pem gives me back a lot of those sites which were unaccessible since yesterday. I will have to wait for complaints to see if any of the previously working sites still fails. A quick tour over the usual suspects finds none. I nevertheless investied the clickwork to import the other new .pem files. Just in case i forget what i did today. Tobias Diekershoff wrote: > Are the untrusted certificates LetsEncrypt issued certs? Their old > R3 cert (signed by DST Root CA X3) expired Sept 29th (see e.g. > https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiratio > n-september-2021/149190 Looks like you are right. In hindsight the hint to "ISRG Root X1" is in there. But i don't understand their nomenclature. I looked for "DST*R3*.pem" but found no such file in /etc/ssl/certs. (It's like with man pages: I understand their text only when i finally found out by try and error.) ------------------------------------------------------------------------- Remaining riddles: How i would be supposed to find the name of the decisive certificate when iceweasel refuses ? Another riddle is why wget still does not work without option --no-check-certificate I found no hint in its man page about its default stash of certificates. Will have to go on with research next week ... Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2021-10-01 19:30 +0200 |
| Subject | Re: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted |
| Message-ID | <D3uw9-7Sb-3@gated-at.bofh.it> |
| In reply to | #240737 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Oct 01, 2021 at 06:32:21PM +0200, Thomas Schmitt wrote: > Hi, > > as tomas predicted it can be done by handwork. > > Tobias Diekershoff gave a good hint but i was not smart enough to make > use of it before i found out the clicky way. Tobias is almost always spot-on :) Cheers - t
[toc] | [prev] | [next] | [standalone]
| From | mett <mett@pmars.jp> |
|---|---|
| Date | 2021-10-02 19:20 +0200 |
| Subject | Re: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted |
| Message-ID | <D3QQ2-4JN-7@gated-at.bofh.it> |
| In reply to | #240737 |
[Multipart message — attachments visible in raw view] — view raw
On 2021年10月2日 1:32:21 JST, Thomas Schmitt <scdbackup@gmx.net> wrote: >Hi, > >as tomas predicted it can be done by handwork. > >Tobias Diekershoff gave a good hint but i was not smart enough to make >use of it before i found out the clicky way. > >The solution was to import to iceweasel the certificate file > > /etc/ssl/certs/ISRG_Root_X1.pem > >------------------------------------------------------------------------ >Long story: > >I replaced the directory trees > /etc/ssl/certs > /usr/share/ca-certificates >and the file > /etc/ca-certificates.conf >by their counterparts of Debian 10. Then i ran > update-ca-certificates >This did not help, even with newly started Iceweasel. > >So i clicked my way through Preferences -> Advanced -> Cerificates to >button "View Certificates" which offers me an obscure list and a button >"Import". This gives me a file browser which i navigate to /etc/ssl/certs. >There are 128 .pem files from Debian 10. > >To reduce the work i diffed the list of .pem files in both /etc/ssl/certs >and began to add those which are new in Debian 10: 49 files. >Many new ones did have no effect. But > /etc/ssl/certs/ISRG_Root_X1.pem >gives me back a lot of those sites which were unaccessible since yesterday. > >I will have to wait for complaints to see if any of the previously working >sites still fails. A quick tour over the usual suspects finds none. >I nevertheless investied the clickwork to import the other new .pem files. >Just in case i forget what i did today. > > >Tobias Diekershoff wrote: >> Are the untrusted certificates LetsEncrypt issued certs? Their old >> R3 cert (signed by DST Root CA X3) expired Sept 29th (see e.g. >> https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiratio >> n-september-2021/149190 > >Looks like you are right. >In hindsight the hint to "ISRG Root X1" is in there. But i don't understand >their nomenclature. I looked for "DST*R3*.pem" but found no such file >in /etc/ssl/certs. (It's like with man pages: I understand their text only >when i finally found out by try and error.) > >------------------------------------------------------------------------- >Remaining riddles: > >How i would be supposed to find the name of the decisive certificate when >iceweasel refuses ? > >Another riddle is why wget still does not work without option > --no-check-certificate >I found no hint in its man page about its default stash of certificates. >Will have to go on with research next week ... > > >Have a nice day :) > >Thomas > Hi, the final solution is: -disable the certs with an ! before the cert name (vi /etc/ca-certificates.conf: !DST_Root_CA_X3.crt) -then, rebuild the cert directory (update-ca-certificates --fresh) -then, restart your servers. HTH
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2021-10-01 17:40 +0200 |
| Message-ID | <D3sNJ-6Nj-21@gated-at.bofh.it> |
| In reply to | #240709 |
On 2021-10-01, Thomas Schmitt <scdbackup@gmx.net> wrote: > Hi, > > i am confronted with an old Debian 8 "jessie" machine where since > (probably) yesterday the Iceweasel browser does not work any more > with many websites. E.g. > > This Connection is Untrusted > ... > lists.debian.org uses an invalid security certificate. > The certificate is not trusted because the issuer certificate is unknown. > (Error code: sec_error_unknown_issuer) They've talking about this here for the last few days. I unfortunately have snipped your actual question but one workaround is to install Firefox, which comes packed with it's own certificates (or something of the sort). Why you're browsing with an unsupported browser in an unsupported OS is left as an exercise for yourself.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web