Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #240713 > unrolled thread
| Started by | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| First post | 2021-10-01 12:30 +0200 |
| Last post | 2021-10-01 17:20 +0200 |
| Articles | 5 — 3 participants |
Back to article view | Back to linux.debian.user
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 12:30 +0200
Re: Jessie iceweasel: This Connection is Untrusted <tomas@tuxteam.de> - 2021-10-01 12:50 +0200
Re: Jessie iceweasel: This Connection is Untrusted "Thomas Schmitt" <scdbackup@gmx.net> - 2021-10-01 13:30 +0200
Re: Jessie iceweasel: This Connection is Untrusted <tomas@tuxteam.de> - 2021-10-01 13:40 +0200
Re: Jessie iceweasel: This Connection is Untrusted David Wright <deblis@lionunicorn.co.uk> - 2021-10-01 17:20 +0200
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2021-10-01 12:30 +0200 |
| Subject | Re: Jessie iceweasel: This Connection is Untrusted |
| Message-ID | <D3nXI-3Ul-5@gated-at.bofh.it> |
Hi, Andrew M.A. Cater wrote: > Honestly - I'd suggest disconnecting the machine from the Internet until > you are able to upgrade it - it's far enough out of support that it's now > ELTS. > I'd suggest that you consider immediate upgrade if you can I know and am working long term on changing the situation. Iceweasel is confined to no Javascript and the machine cannot (easily) be reached from outside. Nevertheless it should be able to reach out to some conservatively programmed web sites. > - what is the reason you cannot? Business, proprietary software, housebroken hardware, my big mouth that GNU/Linux will not terminate service just because it is too old, ... If the premium-but-old hardware breaks or if the browser itself breaks with an important web site, then i have better arguments for a new system. But a mere lack of https certificates is no strong reason. It just lets me look stupid, currently. So any cool sysadmin trick would be welcome, which does not change more than necessary on this time-frozen system. Have a nice day :) Thomas
[toc] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2021-10-01 12:50 +0200 |
| Message-ID | <D3oh3-417-1@gated-at.bofh.it> |
| In reply to | #240713 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Oct 01, 2021 at 12:22:10PM +0200, Thomas Schmitt wrote: > Hi, > > Andrew M.A. Cater wrote: > > Honestly - I'd suggest disconnecting the machine from the Internet until > > you are able to upgrade it - it's far enough out of support that it's now > > ELTS. > > I'd suggest that you consider immediate upgrade if you can I assume Thomas knows pretty well what he's doing. He'd know much better than me, in any case :-) [...] > So any cool sysadmin trick would be welcome, which does not change more > than necessary on this time-frozen system. If I've understood you correctly, you only have to do with a limited set of sites. If this set is limited enough, you could perhaps look up the root CAs certifying those (using a browser in a more modern place), export them, and import them in your patient's browser. It is excruciatingly manual (that's how browsers like their users, but I disgress), but for a few sites (or just as a proof of concept, to make sure a sprinkling of root CAs might solve your problem at all) it might be useful. > Have a nice day :) Love your sig :) Cheers - t
[toc] | [prev] | [next] | [standalone]
| From | "Thomas Schmitt" <scdbackup@gmx.net> |
|---|---|
| Date | 2021-10-01 13:30 +0200 |
| Message-ID | <D3oTL-4tv-1@gated-at.bofh.it> |
| In reply to | #240714 |
Hi, tomas@tuxteam.de wrote: > I assume Thomas knows pretty well what he's doing. He'd know much > better than me, in any case :-) Regrettably my sysadmin skills are severely underdeveloped. I am qualified for the task only by being the guy who has Linux at home and by having made fun of upgrade woes with other kinds of system. > If I've understood you correctly, you only have to do with a limited > set of sites. I would prefer not to rely on an allow-list. So i currently ponder how to transplant the certificates from a Debian 10 machine. man update-ca-certificates talks of /etc/ssl/certs /etc/ca-certificates.conf /usr/share/ca-certificates In the latter i see on Debian 10: ./mozilla with 126 .crt files. The Debian 8 machine has 172 files in there. The ca-certificates.conf files seem just to list those files on both machines. So a brute force attempt would be to rename the two directories and the file to other names and to then copy the Debian 10 stuff to the original names. The new /etc/ssl/certs would start empty and be populated by update-ca-certificates(8). Well, same old question: How bad an idea is this ? What should i read before making such theories ? Have a nice day :) Thomas
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2021-10-01 13:40 +0200 |
| Message-ID | <D3p3r-4wJ-3@gated-at.bofh.it> |
| In reply to | #240715 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Oct 01, 2021 at 01:20:01PM +0200, Thomas Schmitt wrote: [...] > So a brute force attempt would be to rename the two directories and > the file to other names and to then copy the Debian 10 stuff to the > original names. The new /etc/ssl/certs would start empty and be > populated by update-ca-certificates(8). Assuming Mozilla relies on those and doesn't have everything stashed away locally. I don't even know where to start to find that out :-( > Well, same old question: How bad an idea is this ? > What should i read before making such theories ? Actually, if you back up things, you don't have much to lose, have you? And then we'd have an answer to the above question, too ;-) Here [1] is something about adding roots to a browser's little closed world, in case the above fails. Cheers & good luck [1] https://wiki.mozilla.org/CA/AddRootToFirefox - t
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2021-10-01 17:20 +0200 |
| Message-ID | <D3sum-6Gm-5@gated-at.bofh.it> |
| In reply to | #240715 |
On Fri 01 Oct 2021 at 13:20:01 (+0200), Thomas Schmitt wrote: > I would prefer not to rely on an allow-list. > > So i currently ponder how to transplant the certificates from a Debian 10 > machine. > man update-ca-certificates talks of > /etc/ssl/certs > /etc/ca-certificates.conf > /usr/share/ca-certificates > In the latter i see on Debian 10: > ./mozilla > with 126 .crt files. > The Debian 8 machine has 172 files in there. > The ca-certificates.conf files seem just to list those files on both > machines. > > So a brute force attempt would be to rename the two directories and > the file to other names and to then copy the Debian 10 stuff to the > original names. The new /etc/ssl/certs would start empty and be > populated by update-ca-certificates(8). > > Well, same old question: How bad an idea is this ? > What should i read before making such theories ? Looking at the Packages files for wheezy and stretch, the dependencies haven't changed: stretch Package: ca-certificates Version: 20200601~deb9u1 Installed-Size: 380 Maintainer: Michael Shuler <michael@pbandjelly.org> Architecture: all Depends: openssl (>= 1.0.0), debconf (>= 0.5) | debconf-2.0 wheezy Package: ca-certificates Version: 20130119+deb7u1 Installed-Size: 432 Maintainer: Michael Shuler <michael@pbandjelly.org> Architecture: all Depends: openssl (>= 1.0.0), debconf (>= 0.5) | debconf-2.0 So under the circumstances, having backed up the files in /etc and /usr/share for ca-certificates and openssl, I would install stretch's version manually, using the variant syntax: apt ./ca-certificates_20200601~deb9u1_all.deb Cheers, David.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web