Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #269345 > unrolled thread

sanity check for /etc/ssl/certs?

Started byHarald Dunkel <harald.dunkel@aixigo.com>
First post2024-05-14 17:10 +0200
Last post2024-05-15 09:00 +0200
Articles 4 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  sanity check for /etc/ssl/certs? Harald Dunkel <harald.dunkel@aixigo.com> - 2024-05-14 17:10 +0200
    Re: sanity check for /etc/ssl/certs? Marco Moock <mm@dorfdsl.de> - 2024-05-14 17:20 +0200
    Re: sanity check for /etc/ssl/certs? Jeffrey Walton <noloader@gmail.com> - 2024-05-14 22:10 +0200
      Re: sanity check for /etc/ssl/certs? Harald Dunkel <harald.dunkel@aixigo.com> - 2024-05-15 09:00 +0200

#269345 — sanity check for /etc/ssl/certs?

FromHarald Dunkel <harald.dunkel@aixigo.com>
Date2024-05-14 17:10 +0200
Subjectsanity check for /etc/ssl/certs?
Message-ID<IE1WW-djuf-19@gated-at.bofh.it>
Hi folks,

is there a sanity check for /etc/ssl/certs included in Bookworm?
I've got one host with some missing symlinks in this directory, eg.

	root@dpcl064:/etc/ssl/certs# ls -al *SSL.com*
	ls: cannot access '*SSL.com*': No such file or directory

Other hosts show

	root@dpcl082:/etc/ssl/certs# ls -al *SSL.com*
	lrwxrwxrwx 1 root root 82 Jul 16  2018 SSL.com_EV_Root_Certification_Authority_ECC.pem -> /usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_ECC.crt
	lrwxrwxrwx 1 root root 85 Jul 16  2018 SSL.com_EV_Root_Certification_Authority_RSA_R2.pem -> /usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt
	lrwxrwxrwx 1 root root 79 Jul 16  2018 SSL.com_Root_Certification_Authority_ECC.pem -> /usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_ECC.crt
	lrwxrwxrwx 1 root root 79 Jul 16  2018 SSL.com_Root_Certification_Authority_RSA.pem -> /usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_RSA.crt

The files in /usr/share/ca-certificates are available, of course.
The access rights seem OK. update-ca-certificates or reinstalling
ca-certificates (with overwrite) didn't solve this problem.


Every helpful comment is highly appreciated.

Harri

[toc] | [next] | [standalone]


#269347

FromMarco Moock <mm@dorfdsl.de>
Date2024-05-14 17:20 +0200
Message-ID<IE26B-djxd-1@gated-at.bofh.it>
In reply to#269345
Am 14.05.2024 um 16:44:05 Uhr schrieb Harald Dunkel:

> is there a sanity check for /etc/ssl/certs included in Bookworm?

Is ca-certificates installed?
If so, reinstall it.

-- 
kind regards
Marco

Send unsolicited bulk mail to 1715697845muell@cartoonies.org

[toc] | [prev] | [next] | [standalone]


#269362

FromJeffrey Walton <noloader@gmail.com>
Date2024-05-14 22:10 +0200
Message-ID<IE6Df-dmOp-1@gated-at.bofh.it>
In reply to#269345

[Multipart message — attachments visible in raw view] — view raw

On Tue, May 14, 2024 at 3:10 PM Harald Dunkel <harald.dunkel@aixigo.com>
wrote:

> Hi folks,
>
> is there a sanity check for /etc/ssl/certs included in Bookworm?
> I've got one host with some missing symlinks in this directory, eg.
>
>         root@dpcl064:/etc/ssl/certs# ls -al *SSL.com*
>         ls: cannot access '*SSL.com*': No such file or directory
>

It is hard to say what is going on.

I see them in Debian Unstable:

$ find /etc/ssl/certs -iname '*ssl.com*'
/etc/ssl/certs/SSL.com_TLS_RSA_Root_CA_2022.pem
/etc/ssl/certs/SSL.com_EV_Root_Certification_Authority_RSA_R2.pem
/etc/ssl/certs/SSL.com_TLS_ECC_Root_CA_2022.pem
/etc/ssl/certs/SSL.com_Root_Certification_Authority_RSA.pem
/etc/ssl/certs/SSL.com_Root_Certification_Authority_ECC.pem
/etc/ssl/certs/SSL.com_EV_Root_Certification_Authority_ECC.pem

I don't see anything in Debian's bug reporter about removing ssl.com;
confer, <https://bugs.debian.org/cgi-bin/pkgreport.cgi?pkg=ca-certificates>.
And ssl.com is included in Mozilla and Chrome's root program.


> Other hosts show
>
>         root@dpcl082:/etc/ssl/certs# ls -al *SSL.com*
>         lrwxrwxrwx 1 root root 82 Jul 16  2018
> SSL.com_EV_Root_Certification_Authority_ECC.pem ->
> /usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_ECC.crt
>         lrwxrwxrwx 1 root root 85 Jul 16  2018
> SSL.com_EV_Root_Certification_Authority_RSA_R2.pem ->
> /usr/share/ca-certificates/mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt
>         lrwxrwxrwx 1 root root 79 Jul 16  2018
> SSL.com_Root_Certification_Authority_ECC.pem ->
> /usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_ECC.crt
>         lrwxrwxrwx 1 root root 79 Jul 16  2018
> SSL.com_Root_Certification_Authority_RSA.pem ->
> /usr/share/ca-certificates/mozilla/SSL.com_Root_Certification_Authority_RSA.crt
>
> The files in /usr/share/ca-certificates are available, of course.
> The access rights seem OK. update-ca-certificates or reinstalling
> ca-certificates (with overwrite) didn't solve this problem.
>

Hazarding a guess... Have you upgraded that system over the years? That may
explain why you are seeing old artifacts and dead symlinks.

Maybe you should run `symlinks -r / | grep dangling` to locate dead
symlinks, and then run `symlink -r -d /` to delete them (once you are
satisfied with the resulting list).

Jeff

[toc] | [prev] | [next] | [standalone]


#269370

FromHarald Dunkel <harald.dunkel@aixigo.com>
Date2024-05-15 09:00 +0200
Message-ID<IEgMh-dsTB-15@gated-at.bofh.it>
In reply to#269362
Problem was, /etc/ca-certificates.conf was not regenerated, even with

	apt install --reinstall -o Dpkg::Options::="--force-confask,confnew,confmiss" ca-certificates

Regards
Harri

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web