Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #240709 > unrolled thread

Jessie iceweasel: This Connection is Untrusted

Started by"Thomas Schmitt" <scdbackup@gmx.net>
First post2021-10-01 09:50 +0200
Last post2021-10-01 17:40 +0200
Articles 7 — 6 participants

Back to article view | Back to linux.debian.user


Contents

  Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 09:50 +0200
    Re: Jessie iceweasel: This Connection is Untrusted "Andrew M.A. Cater" <amacater@einval.com> - 2021-10-01 12:00 +0200
    Re: Jessie iceweasel: This Connection is Untrusted Tobias Diekershoff <tobias.diekershoff@gmx.net> - 2021-10-01 14:10 +0200
      [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 18:40 +0200
        Re: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted <tomas@tuxteam.de> - 2021-10-01 19:30 +0200
        Re: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted mett <mett@pmars.jp> - 2021-10-02 19:20 +0200
    Re: Jessie iceweasel: This Connection is Untrusted Curt <curty@free.fr> - 2021-10-01 17:40 +0200

#240709 — Jessie iceweasel: This Connection is Untrusted

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2021-10-01 09:50 +0200
SubjectJessie iceweasel: This Connection is Untrusted
Message-ID<D3lsS-2it-3@gated-at.bofh.it>
Hi,

i am confronted with an old Debian 8 "jessie" machine where since
(probably) yesterday the Iceweasel browser does not work any more
with many websites. E.g.

  This Connection is Untrusted
  ...
  lists.debian.org uses an invalid security certificate.
  The certificate is not trusted because the issuer certificate is unknown.
  (Error code: sec_error_unknown_issuer)

Googling around (with Debian 10) gives me the idea that the installed
package ca-certificates is outdated.

It is currently not an option to upgrade the system to a newer Debian
version. I am even scared to do what i deduce from
  https://serverfault.com/questions/891734/debian-wheezy-outdated-root-certificates
namely:

- add to /etc/apt/sources.list :
    deb http://ftp.de.debian.org/debian-security/ jessie/updates main

- run:
    apt-get update
    apt-get install ca-certificates

Is this a good idea ? Will it do harm to the 6 year old system ?

---------------------------------------------------------------------------
If not a good idea:

Is there a known procedure to get and install the certificates manually ?
I see proposals to download .crt files and run
  update-ca-certificates --fresh

Where would i get a current set of certificates ?

How do i identify the certificates which the browser does not accept ?
wget does not tell me the certificate name either.


Have a nice day :)

Thomas

[toc] | [next] | [standalone]


#240711

From"Andrew M.A. Cater" <amacater@einval.com>
Date2021-10-01 12:00 +0200
Message-ID<D3nuF-3uV-3@gated-at.bofh.it>
In reply to#240709
On Fri, Oct 01, 2021 at 09:41:45AM +0200, Thomas Schmitt wrote:
> Hi,
> 
> i am confronted with an old Debian 8 "jessie" machine where since
> (probably) yesterday the Iceweasel browser does not work any more
> with many websites. E.g.
> 
>   This Connection is Untrusted
>   ...
>   lists.debian.org uses an invalid security certificate.
>   The certificate is not trusted because the issuer certificate is unknown.
>   (Error code: sec_error_unknown_issuer)
> 
> Googling around (with Debian 10) gives me the idea that the installed
> package ca-certificates is outdated.
> 
> It is currently not an option to upgrade the system to a newer Debian
> version. I am even scared to do what i deduce from
>   https://serverfault.com/questions/891734/debian-wheezy-outdated-root-certificates
> namely:
> 
> - add to /etc/apt/sources.list :
>     deb http://ftp.de.debian.org/debian-security/ jessie/updates main
> 
> - run:
>     apt-get update
>     apt-get install ca-certificates
> 
> Is this a good idea ? Will it do harm to the 6 year old system ?
> 
> ---------------------------------------------------------------------------
> If not a good idea:
> 
> Is there a known procedure to get and install the certificates manually ?
> I see proposals to download .crt files and run
>   update-ca-certificates --fresh
> 
> Where would i get a current set of certificates ?
> 
> How do i identify the certificates which the browser does not accept ?
> wget does not tell me the certificate name either.
> 
> 
> Have a nice day :)
> 
> Thomas
> 

Honestly - I'd suggest disconnecting the machine from the Internet until you
are able to upgrade it - it's far enough out of support that it's now ELTS.

https://deb.freexian.com/extended-lts/

I'd suggest that you consider immediate upgrade if you can - what is the 
reason you cannot?

All the very best, as ever,

Andy Cater

[toc] | [prev] | [next] | [standalone]


#240720

FromTobias Diekershoff <tobias.diekershoff@gmx.net>
Date2021-10-01 14:10 +0200
Message-ID<D3pwu-4W0-7@gated-at.bofh.it>
In reply to#240709

[Multipart message — attachments visible in raw view] — view raw

Hey Thomas

On Fri, 01 Oct 2021 09:41:45 +0200
"Thomas Schmitt" <scdbackup@gmx.net> wrote:

> i am confronted with an old Debian 8 "jessie" machine where since
> (probably) yesterday the Iceweasel browser does not work any more
> with many websites. E.g.

Are the untrusted certificates LetsEncrypt issued certs? Their old
R3 cert (signed by DST Root CA X3) expired Sept 29th (see e.g. [1]).
Maybe jessie has not gotten the new certs to trust LE certs now?

Greetings!
  Tobias

1: https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190

-- 
Bōsī se sȳrī glaesās

PGP-ID ......... 0x25FE376FF17694A1

[toc] | [prev] | [next] | [standalone]


#240737 — [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2021-10-01 18:40 +0200
Subject[SOLVED] Re: Jessie iceweasel: This Connection is Untrusted
Message-ID<D3tJL-7mq-5@gated-at.bofh.it>
In reply to#240720
Hi,

as tomas predicted it can be done by handwork.

Tobias Diekershoff gave a good hint but i was not smart enough to make
use of it before i found out the clicky way.

The solution was to import to iceweasel the certificate file

  /etc/ssl/certs/ISRG_Root_X1.pem

------------------------------------------------------------------------
Long story:

I replaced the directory trees
  /etc/ssl/certs
  /usr/share/ca-certificates
and the file
  /etc/ca-certificates.conf
by their counterparts of Debian 10. Then i ran
  update-ca-certificates
This did not help, even with newly started Iceweasel.

So i clicked my way through Preferences -> Advanced -> Cerificates to
button "View Certificates" which offers me an obscure list and a button
"Import". This gives me a file browser which i navigate to /etc/ssl/certs.
There are 128 .pem files from Debian 10.

To reduce the work i diffed the list of .pem files in both /etc/ssl/certs
and began to add those which are new in Debian 10: 49 files.
Many new ones did have no effect. But
  /etc/ssl/certs/ISRG_Root_X1.pem
gives me back a lot of those sites which were unaccessible since yesterday.

I will have to wait for complaints to see if any of the previously working
sites still fails. A quick tour over the usual suspects finds none.
I nevertheless investied the clickwork to import the other new .pem files.
Just in case i forget what i did today.


Tobias Diekershoff wrote:
> Are the untrusted certificates LetsEncrypt issued certs? Their old
> R3 cert (signed by DST Root CA X3) expired Sept 29th (see e.g.
> https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiratio
> n-september-2021/149190

Looks like you are right.
In hindsight the hint to "ISRG Root X1" is in there. But i don't understand
their nomenclature. I looked for "DST*R3*.pem" but found no such file
in /etc/ssl/certs. (It's like with man pages: I understand their text only
when i finally found out by try and error.)

-------------------------------------------------------------------------
Remaining riddles:

How i would be supposed to find the name of the decisive certificate when
iceweasel refuses ?

Another riddle is why wget still does not work without option
  --no-check-certificate
I found no hint in its man page about its default stash of certificates.
Will have to go on with research next week ...


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#240742 — Re: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted

From<tomas@tuxteam.de>
Date2021-10-01 19:30 +0200
SubjectRe: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted
Message-ID<D3uw9-7Sb-3@gated-at.bofh.it>
In reply to#240737

[Multipart message — attachments visible in raw view] — view raw

On Fri, Oct 01, 2021 at 06:32:21PM +0200, Thomas Schmitt wrote:
> Hi,
> 
> as tomas predicted it can be done by handwork.
> 
> Tobias Diekershoff gave a good hint but i was not smart enough to make
> use of it before i found out the clicky way.

Tobias is almost always spot-on :)

Cheers
 - t

[toc] | [prev] | [next] | [standalone]


#240810 — Re: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted

Frommett <mett@pmars.jp>
Date2021-10-02 19:20 +0200
SubjectRe: [SOLVED] Re: Jessie iceweasel: This Connection is Untrusted
Message-ID<D3QQ2-4JN-7@gated-at.bofh.it>
In reply to#240737

[Multipart message — attachments visible in raw view] — view raw

On 2021年10月2日 1:32:21 JST, Thomas Schmitt <scdbackup@gmx.net> wrote:
>Hi,
>
>as tomas predicted it can be done by handwork.
>
>Tobias Diekershoff gave a good hint but i was not smart enough to make
>use of it before i found out the clicky way.
>
>The solution was to import to iceweasel the certificate file
>
>  /etc/ssl/certs/ISRG_Root_X1.pem
>
>------------------------------------------------------------------------
>Long story:
>
>I replaced the directory trees
>  /etc/ssl/certs
>  /usr/share/ca-certificates
>and the file
>  /etc/ca-certificates.conf
>by their counterparts of Debian 10. Then i ran
>  update-ca-certificates
>This did not help, even with newly started Iceweasel.
>
>So i clicked my way through Preferences -> Advanced -> Cerificates to
>button "View Certificates" which offers me an obscure list and a button
>"Import". This gives me a file browser which i navigate to /etc/ssl/certs.
>There are 128 .pem files from Debian 10.
>
>To reduce the work i diffed the list of .pem files in both /etc/ssl/certs
>and began to add those which are new in Debian 10: 49 files.
>Many new ones did have no effect. But
>  /etc/ssl/certs/ISRG_Root_X1.pem
>gives me back a lot of those sites which were unaccessible since yesterday.
>
>I will have to wait for complaints to see if any of the previously working
>sites still fails. A quick tour over the usual suspects finds none.
>I nevertheless investied the clickwork to import the other new .pem files.
>Just in case i forget what i did today.
>
>
>Tobias Diekershoff wrote:
>> Are the untrusted certificates LetsEncrypt issued certs? Their old
>> R3 cert (signed by DST Root CA X3) expired Sept 29th (see e.g.
>> https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiratio
>> n-september-2021/149190
>
>Looks like you are right.
>In hindsight the hint to "ISRG Root X1" is in there. But i don't understand
>their nomenclature. I looked for "DST*R3*.pem" but found no such file
>in /etc/ssl/certs. (It's like with man pages: I understand their text only
>when i finally found out by try and error.)
>
>-------------------------------------------------------------------------
>Remaining riddles:
>
>How i would be supposed to find the name of the decisive certificate when
>iceweasel refuses ?
>
>Another riddle is why wget still does not work without option
>  --no-check-certificate
>I found no hint in its man page about its default stash of certificates.
>Will have to go on with research next week ...
>
>
>Have a nice day :)
>
>Thomas
>

Hi,

the final solution is:
-disable 
 the certs with an ! before
 the cert name
 (vi /etc/ca-certificates.conf:
   !DST_Root_CA_X3.crt)
-then, rebuild the cert directory
 (update-ca-certificates --fresh)
-then, restart your servers.

HTH

[toc] | [prev] | [next] | [standalone]


#240731

FromCurt <curty@free.fr>
Date2021-10-01 17:40 +0200
Message-ID<D3sNJ-6Nj-21@gated-at.bofh.it>
In reply to#240709
On 2021-10-01, Thomas Schmitt <scdbackup@gmx.net> wrote:
> Hi,
>
> i am confronted with an old Debian 8 "jessie" machine where since
> (probably) yesterday the Iceweasel browser does not work any more
> with many websites. E.g.
>
>   This Connection is Untrusted
>   ...
>   lists.debian.org uses an invalid security certificate.
>   The certificate is not trusted because the issuer certificate is unknown.
>   (Error code: sec_error_unknown_issuer)

They've talking about this here for the last few days.

I unfortunately have snipped your actual question but one workaround is
to install Firefox, which comes packed with it's own certificates (or
something of the sort).

Why you're browsing with an unsupported browser in an unsupported OS is
left as an exercise for yourself.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web