Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #240713 > unrolled thread

Re: Jessie iceweasel: This Connection is Untrusted

Started by"Thomas Schmitt" <scdbackup@gmx.net>
First post2021-10-01 12:30 +0200
Last post2021-10-01 17:20 +0200
Articles 5 — 3 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 12:30 +0200
    Re: Jessie iceweasel: This Connection is Untrusted <tomas@tuxteam.de> - 2021-10-01 12:50 +0200
      Re: Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 13:30 +0200
        Re: Jessie iceweasel: This Connection is Untrusted <tomas@tuxteam.de> - 2021-10-01 13:40 +0200
        Re: Jessie iceweasel: This Connection is Untrusted David Wright <deblis@lionunicorn.co.uk> - 2021-10-01 17:20 +0200

#240713 — Re: Jessie iceweasel: This Connection is Untrusted

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2021-10-01 12:30 +0200
SubjectRe: Jessie iceweasel: This Connection is Untrusted
Message-ID<D3nXI-3Ul-5@gated-at.bofh.it>
Hi,

Andrew M.A. Cater wrote:
> Honestly - I'd suggest disconnecting the machine from the Internet until
> you are able to upgrade it - it's far enough out of support that it's now
> ELTS.
> I'd suggest that you consider immediate upgrade if you can

I know and am working long term on changing the situation.
Iceweasel is confined to no Javascript and the machine cannot (easily)
be reached from outside. Nevertheless it should be able to reach out
to some conservatively programmed web sites.


> - what is the reason you cannot?

Business, proprietary software, housebroken hardware, my big mouth that
GNU/Linux will not terminate service just because it is too old, ...

If the premium-but-old hardware breaks or if the browser itself breaks
with an important web site, then i have better arguments for a new system.
But a mere lack of https certificates is no strong reason. It just lets me
look stupid, currently.

So any cool sysadmin trick would be welcome, which does not change more
than necessary on this time-frozen system.


Have a nice day :)

Thomas

[toc] | [next] | [standalone]


#240714

From<tomas@tuxteam.de>
Date2021-10-01 12:50 +0200
Message-ID<D3oh3-417-1@gated-at.bofh.it>
In reply to#240713

[Multipart message — attachments visible in raw view] — view raw

On Fri, Oct 01, 2021 at 12:22:10PM +0200, Thomas Schmitt wrote:
> Hi,
> 
> Andrew M.A. Cater wrote:
> > Honestly - I'd suggest disconnecting the machine from the Internet until
> > you are able to upgrade it - it's far enough out of support that it's now
> > ELTS.
> > I'd suggest that you consider immediate upgrade if you can

I assume Thomas knows pretty well what he's doing. He'd know much
better than me, in any case :-)

[...]

> So any cool sysadmin trick would be welcome, which does not change more
> than necessary on this time-frozen system.

If I've understood you correctly, you only have to do with a limited
set of sites. If this set is limited enough, you could perhaps look
up the root CAs certifying those (using a browser in a more modern
place), export them, and import them in your patient's browser.

It is excruciatingly manual (that's how browsers like their users,
but I disgress), but for a few sites (or just as a proof of concept,
to make sure a sprinkling of root CAs might solve your problem at
all) it might be useful.

> Have a nice day :)

Love your sig :)

Cheers
 - t

[toc] | [prev] | [next] | [standalone]


#240715

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2021-10-01 13:30 +0200
Message-ID<D3oTL-4tv-1@gated-at.bofh.it>
In reply to#240714
Hi,

tomas@tuxteam.de wrote:
> I assume Thomas knows pretty well what he's doing. He'd know much
> better than me, in any case :-)

Regrettably my sysadmin skills are severely underdeveloped.
I am qualified for the task only by being the guy who has Linux at home
and by having made fun of upgrade woes with other kinds of system.


> If I've understood you correctly, you only have to do with a limited
> set of sites.

I would prefer not to rely on an allow-list.

So i currently ponder how to transplant the certificates from a Debian 10
machine.
man update-ca-certificates talks of
  /etc/ssl/certs
  /etc/ca-certificates.conf
  /usr/share/ca-certificates
In the latter i see on Debian 10:
  ./mozilla
with 126 .crt files.
The Debian 8 machine has 172 files in there.
The ca-certificates.conf files seem just to list those files on both
machines.

So a brute force attempt would be to rename the two directories and
the file to other names and to then copy the Debian 10 stuff to the
original names. The new /etc/ssl/certs would start empty and be
populated by update-ca-certificates(8).

Well, same old question: How bad an idea is this ?
What should i read before making such theories ?


Have a nice day :)

Thomas

[toc] | [prev] | [next] | [standalone]


#240717

From<tomas@tuxteam.de>
Date2021-10-01 13:40 +0200
Message-ID<D3p3r-4wJ-3@gated-at.bofh.it>
In reply to#240715

[Multipart message — attachments visible in raw view] — view raw

On Fri, Oct 01, 2021 at 01:20:01PM +0200, Thomas Schmitt wrote:

[...]

> So a brute force attempt would be to rename the two directories and
> the file to other names and to then copy the Debian 10 stuff to the
> original names. The new /etc/ssl/certs would start empty and be
> populated by update-ca-certificates(8).

Assuming Mozilla relies on those and doesn't have everything stashed
away locally. I don't even know where to start to find that out :-(

> Well, same old question: How bad an idea is this ?
> What should i read before making such theories ?

Actually, if you back up things, you don't have much to lose, have
you?

And then we'd have an answer to the above question, too ;-)

Here [1] is something about adding roots to a browser's little closed
world, in case the above fails.

Cheers & good luck

[1] https://wiki.mozilla.org/CA/AddRootToFirefox

 - t

[toc] | [prev] | [next] | [standalone]


#240729

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2021-10-01 17:20 +0200
Message-ID<D3sum-6Gm-5@gated-at.bofh.it>
In reply to#240715
On Fri 01 Oct 2021 at 13:20:01 (+0200), Thomas Schmitt wrote:

> I would prefer not to rely on an allow-list.
> 
> So i currently ponder how to transplant the certificates from a Debian 10
> machine.
> man update-ca-certificates talks of
>   /etc/ssl/certs
>   /etc/ca-certificates.conf
>   /usr/share/ca-certificates
> In the latter i see on Debian 10:
>   ./mozilla
> with 126 .crt files.
> The Debian 8 machine has 172 files in there.
> The ca-certificates.conf files seem just to list those files on both
> machines.
> 
> So a brute force attempt would be to rename the two directories and
> the file to other names and to then copy the Debian 10 stuff to the
> original names. The new /etc/ssl/certs would start empty and be
> populated by update-ca-certificates(8).
> 
> Well, same old question: How bad an idea is this ?
> What should i read before making such theories ?

Looking at the Packages files for wheezy and stretch, the dependencies
haven't changed:

  stretch
Package: ca-certificates
Version: 20200601~deb9u1
Installed-Size: 380
Maintainer: Michael Shuler <michael@pbandjelly.org>
Architecture: all
Depends: openssl (>= 1.0.0), debconf (>= 0.5) | debconf-2.0

  wheezy
Package: ca-certificates
Version: 20130119+deb7u1
Installed-Size: 432
Maintainer: Michael Shuler <michael@pbandjelly.org>
Architecture: all
Depends: openssl (>= 1.0.0), debconf (>= 0.5) | debconf-2.0

So under the circumstances, having backed up the files in /etc
and /usr/share for ca-certificates and openssl, I would install
stretch's version manually, using the variant syntax:
  apt ./ca-certificates_20200601~deb9u1_all.deb

Cheers,
David.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web