Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #207425 > unrolled thread
| Started by | Tyler A <tylera@privatedemail.net> |
|---|---|
| First post | 2019-04-13 16:50 +0200 |
| Last post | 2019-04-19 17:50 +0200 |
| Articles | 7 — 2 participants |
Back to article view | Back to linux.debian.user
Correct way to install Intermediate certificates in Debian Tyler A <tylera@privatedemail.net> - 2019-04-13 16:50 +0200
Re: Correct way to install Intermediate certificates in Debian "Alexander V. Makartsev" <avbetev@gmail.com> - 2019-04-13 18:00 +0200
Re: Correct way to install Intermediate certificates in Debian Tyler A <tylera@privatedemail.net> - 2019-04-13 18:30 +0200
Re: Correct way to install Intermediate certificates in Debian Tyler A <tylera@privatedemail.net> - 2019-04-13 20:30 +0200
Re: Correct way to install Intermediate certificates in Debian "Alexander V. Makartsev" <avbetev@gmail.com> - 2019-04-15 13:40 +0200
Re: Correct way to install Intermediate certificates in Debian "Alexander V. Makartsev" <avbetev@gmail.com> - 2019-04-15 13:30 +0200
Re: Correct way to install Intermediate certificates in Debian Tyler A <tylera@privatedemail.net> - 2019-04-19 17:50 +0200
| From | Tyler A <tylera@privatedemail.net> |
|---|---|
| Date | 2019-04-13 16:50 +0200 |
| Subject | Correct way to install Intermediate certificates in Debian |
| Message-ID | <xMs8F-2pr-5@gated-at.bofh.it> |
Hi, I had trouble visiting these two websites in Firefox, Epiphany and verifying with OpenSSL. - Births Deaths and Marriages (Government of South Australia) https://bdm.cbs.sa.gov.au/bdmsaonline/dbweb.asp?dbcgm=1&prprc=oac - Hostplus Superannuation Fund https://hostplus.com.au/ It appears the issue according to ssllabs[0][1] is that the intermediate certificate is not provided to you when you visit the website. If you've visited another website with that certificate these sites will work for you as the intermediary certificates will be cached. Chrome and Internet Explorer will automatically download the certificate from the AIA URL, something that Firefox apparently won't do[2]. I was able to reproduce this issue on Debian 8, 9, Tails and Firefox on Windows 10. On Archlinux I was able to install this certificate trivially ie[3]: $ wget -c http://cacerts.thawte.com/ThawteRSACA2018.crt http://cacerts.geotrust.com/GeoTrustRSACA2018.crt $ sudo trust -v anchor GeoTrustRSACA2018.crt $ sudo trust -v anchor ThawteRSACA2018.crt They were then added: /etc/ca-certificates/trust-source ├── anchors ├── blacklist ├── GeoTrust_RSA_CA_2018.p11-kit └── Thawte_RSA_CA_2018.p11-kit Using OpenSSL I was then able to perform verification, (this in turn allowed wget, curl to also work): $ openssl s_client -connect hostplus.com.au:443 -showcerts $ openssl s_client -connect bdm.cbs.sa.gov.au:443 -showcerts I was also now able to visit the websites with a new Firefox profile, without getting the SEC_ERROR_UNKNOWN_ISSUER error. I decided to try this on Debian. $ sudo apt-get install p11-kit $ wget -c http://cacerts.thawte.com/ThawteRSACA2018.crt http://cacerts.geotrust.com/GeoTrustRSACA2018.crt $ sudo trust -v anchor GeoTrustRSACA2018.crt (p11-kit:1102) files_to_attrs: parsed file: GeoTrustRSACA2018.crt p11-kit: no configured writable location to store anchors $ sudo trust -v anchor ThawteRSACA2018.crt (p11-kit:1104) files_to_attrs: parsed file: ThawteRSACA2018.crt p11-kit: no configured writable location to store anchors 1) Why doesn't this work? 2) Is it related to [4][5][6]? 3) Can I fix it? The other way I had seen to do it was: $ sudo cp -vR *.crt /usr/local/share/ca-certificates 'GeoTrustRSACA2018.crt' -> '/usr/local/share/ca-certificates/GeoTrustRSACA2018.crt' 'ThawteRSACA2018.crt' -> '/usr/local/share/ca-certificates/ThawteRSACA2018.crt $ sudo update-ca-certificates --fresh Clearing symlinks in /etc/ssl/certs... done. Updating certificates in /etc/ssl/certs... rehash: warning: skipping GeoTrustRSACA2018.pem,it does not contain exactly one certificate or CRL rehash: warning: skipping ThawteRSACA2018.pem,it does not contain exactly one certificate or CRL 130 added, 0 removed; done. Running hooks in /etc/ca-certificates/update.d... done. However the sites do not seem to work in Firefox. I did wonder if that was whether Firefox could read that store or if it only used it's own one based on this link[7] - however that is pretty old. That is no reason however why it doesn't work with OpenSSL. Verify return code: 21 (unable to verify the first certificate) [0]: https://www.ssllabs.com/ssltest/analyze.html?d=bdm.cbs.sa.gov.au [1]: https://www.ssllabs.com/ssltest/analyze.html?d=hostplus.com.au [2]: https://bugzilla.mozilla.org/show_bug.cgi?id=399324 [3]: https://wiki.archlinux.org/index.php/Ca-certificates#Trust_a_certificate_authority_system-wide [4]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=752485 [5]: https://lists.freedesktop.org/archives/p11-glue/2017-July/000673.html [6]: https://github.com/p11-glue/p11-kit/issues/115 [7]: http://blog.xelnor.net/firefox-systemcerts/ -- Tyler (tya99) rsa4096/0x9C9954F88E388859
[toc] | [next] | [standalone]
| From | "Alexander V. Makartsev" <avbetev@gmail.com> |
|---|---|
| Date | 2019-04-13 18:00 +0200 |
| Message-ID | <xMtep-32s-1@gated-at.bofh.it> |
| In reply to | #207425 |
[Multipart message — attachments visible in raw view] — view raw
On 13.04.2019 19:40, Tyler A wrote: > Hi, > > I had trouble visiting these two websites in Firefox, Epiphany and > verifying with OpenSSL. > > - Births Deaths and Marriages (Government of South Australia) > https://bdm.cbs.sa.gov.au/bdmsaonline/dbweb.asp?dbcgm=1&prprc=oac > > - Hostplus Superannuation Fund > https://hostplus.com.au/ > > ... I can access both sites without any problems with my browser (Firefox). AFAIK, intermediate certs are not required to be installed, if they are valid and pass the check with Issuer Root CA cert. Only private certificates, that identify your client, are required to be installed, if remote server was configured to use them. Which is not the case for public web servers. Here [1] is the output from openssl for one connection attempt for both sites. Just to rule out possibility of any network misconfiguration, try to access both sites via Tor network or Opera browser's VPN feature, and without proxy server, if you use one. [1] https://pastebin.com/raw/Z48bKzDs -- With kindest regards, Alexander. ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org ⠈⠳⣄⠀⠀⠀⠀
[toc] | [prev] | [next] | [standalone]
| From | Tyler A <tylera@privatedemail.net> |
|---|---|
| Date | 2019-04-13 18:30 +0200 |
| Message-ID | <xMtHr-3rE-7@gated-at.bofh.it> |
| In reply to | #207428 |
On 13/4/19 3:57 pm, Alexander V. Makartsev wrote: > On 13.04.2019 19:40, Tyler A wrote: >> Hi, >> >> I had trouble visiting these two websites in Firefox, Epiphany and >> verifying with OpenSSL. >> >> - Births Deaths and Marriages (Government of South Australia) >> https://bdm.cbs.sa.gov.au/bdmsaonline/dbweb.asp?dbcgm=1&prprc=oac >> >> - Hostplus Superannuation Fund >> https://hostplus.com.au/ >> >> ... > I can access both sites without any problems with my browser (Firefox). Keep in mind, you must do this in a new profile. If you've ever visited a website which has used the certificate it will be cached, and the site will work. Firefox does not download the cert from the AIA link like IE/Chrome does. So if you have Chromium, that will work. This masks the issue. This particularly effected me because I used a amnesic environment ie debian-live-9.8.0-amd64-gnome.iso > AFAIK, intermediate certs are not required to be installed, if they are > valid and pass the check with Issuer Root CA cert. > Only private certificates, that identify your client, are required to be > installed, if remote server was configured to use them. Which is not the > case for public web servers. > Here [1] is the output from openssl for one connection attempt for both > sites. You seem to have some strange results there: > $ openssl s_client -connect hostplus.com.au:443 2>&1 > > depth=2 C = BE, O = GlobalSign nv-sa, OU = Root CA, CN = GlobalSign Root CA > verify return:1 > depth=1 C = BE, O = GlobalSign nv-sa, CN = GlobalSign CloudSSL CA - SHA256 - G3 > verify return:1 > depth=0 C = US, ST = Delaware, L = Dover, O = Incapsula Inc, CN = incapsula.com > verify return:1 > CONNECTED(00000003) > --- > Certificate chain > 0 s:/C=US/ST=Delaware/L=Dover/O=Incapsula Inc/CN=incapsula.com > i:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign CloudSSL CA - SHA256 - G3 > 1 s:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign CloudSSL CA - SHA256 - G3 > i:/C=BE/O=GlobalSign nv-sa/OU=Root CA/CN=GlobalSign Root CA Whereas: I got: > $ openssl s_client -connect hostplus.com.au:443 2>&1 > CONNECTED(00000003) > depth=0 CN = *.hostplus.com.au > verify error:num=20:unable to get local issuer certificate > verify return:1 > depth=0 CN = *.hostplus.com.au > verify error:num=21:unable to verify the first certificate > verify return:1 > --- > Certificate chain > 0 s:CN = *.hostplus.com.au > i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = GeoTrust RSA CA 2018 As for your other example: > $ openssl s_client -connect bdm.cbs.sa.gov.au:443 2>&1 > > depth=2 C = BE, O = GlobalSign nv-sa, OU = Root CA, CN = GlobalSign Root CA > verify return:1 > depth=1 C = BE, O = GlobalSign nv-sa, CN = GlobalSign CloudSSL CA - SHA256 - G3 > verify return:1 > depth=0 C = US, ST = Delaware, L = Dover, O = Incapsula Inc, CN = incapsula.com > verify return:1 > CONNECTED(00000003) > --- > Certificate chain > 0 s:/C=US/ST=Delaware/L=Dover/O=Incapsula Inc/CN=incapsula.com > i:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign CloudSSL CA - SHA256 - G3 > 1 s:/C=BE/O=GlobalSign nv-sa/CN=GlobalSign CloudSSL CA - SHA256 - G3 > i:/C=BE/O=GlobalSign nv-sa/OU=Root CA/CN=GlobalSign Root CA I got: > $ openssl s_client -connect bdm.cbs.sa.gov.au:443 2>&1 > CONNECTED(00000003) > depth=0 C = AU, L = Adelaide, O = Attorney General's Department, OU = Consumer and Business Services, CN = bdm.cbs.sa.gov.au > verify error:num=20:unable to get local issuer certificate > verify return:1 > depth=0 C = AU, L = Adelaide, O = Attorney General's Department, OU = Consumer and Business Services, CN = bdm.cbs.sa.gov.au > verify error:num=21:unable to verify the first certificate > verify return:1 > --- > Certificate chain > 0 s:C = AU, L = Adelaide, O = Attorney General's Department, OU = Consumer and Business Services, CN = bdm.cbs.sa.gov.au > i:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = Thawte RSA CA 2018 I got the same certificates from a European VPN as I did from in Australia (not what you got) which appears to be a CDN. > Just to rule out possibility of any network misconfiguration, try to > access both sites via Tor network or Opera browser's VPN feature, and > without proxy server, if you use one. > And no they didn't work on Tor on Tails either. -- Tyler (tya99) rsa4096/0x9C9954F88E388859
[toc] | [prev] | [next] | [standalone]
| From | Tyler A <tylera@privatedemail.net> |
|---|---|
| Date | 2019-04-13 20:30 +0200 |
| Message-ID | <xMvzA-4Hm-5@gated-at.bofh.it> |
| In reply to | #207429 |
I found a temporary solution that at least lets me visit the sites in Firefox.
However this doesn't fix OpenSSL (thus things like curl, wget).
#!/usr/bin/env bash
sudo apt-get install libnss3-tools
downloadCerts=(http://cacerts.thawte.com/ThawteRSACA2018.crt
http://cacerts.geotrust.com/GeoTrustRSACA2018.crt)
wget -c "${downloadCerts[@]}"
for f in *.crt; do
fbasename=${f%.crt}
openssl x509 -inform der -outform pem -in "$f" -out "$fbasename".pem
find ~ -name cert9.db -printf '%h\0' |
while IFS= read -rd '' certDir; do
certutil -A -n "${fbasename}" -t "TCu,Cuw,Tuw" -i "${fbasename}".pem -d sql:"$certDir"
done
done
--
Tyler (tya99)
rsa4096/0x9C9954F88E388859
[toc] | [prev] | [next] | [standalone]
| From | "Alexander V. Makartsev" <avbetev@gmail.com> |
|---|---|
| Date | 2019-04-15 13:40 +0200 |
| Message-ID | <xN87U-38n-1@gated-at.bofh.it> |
| In reply to | #207431 |
[Multipart message — attachments visible in raw view] — view raw
On 13.04.2019 23:21, Tyler A wrote:
> I found a temporary solution that at least lets me visit the sites in Firefox.
>
> However this doesn't fix OpenSSL (thus things like curl, wget).
>
> #!/usr/bin/env bash
>
> sudo apt-get install libnss3-tools
>
> downloadCerts=(http://cacerts.thawte.com/ThawteRSACA2018.crt
> http://cacerts.geotrust.com/GeoTrustRSACA2018.crt)
>
> wget -c "${downloadCerts[@]}"
>
> for f in *.crt; do
> fbasename=${f%.crt}
> openssl x509 -inform der -outform pem -in "$f" -out "$fbasename".pem
> find ~ -name cert9.db -printf '%h\0' |
> while IFS= read -rd '' certDir; do
> certutil -A -n "${fbasename}" -t "TCu,Cuw,Tuw" -i "${fbasename}".pem -d sql:"$certDir"
> done
> done
>
This script imports certificates into Mozilla Firefox own NSS DB.
You can do the same procedure more easily in Firefox GUI with
"Certificate Manager". ("Preferences" >> "Privacy & Security", click
"View Certificates")
--
With kindest regards, Alexander.
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org
⠈⠳⣄⠀⠀⠀⠀
[toc] | [prev] | [next] | [standalone]
| From | "Alexander V. Makartsev" <avbetev@gmail.com> |
|---|---|
| Date | 2019-04-15 13:30 +0200 |
| Message-ID | <xN7Ye-35a-13@gated-at.bofh.it> |
| In reply to | #207429 |
[Multipart message — attachments visible in raw view] — view raw
On 13.04.2019 21:20, Tyler A wrote: > On 13/4/19 3:57 pm, Alexander V. Makartsev wrote: >> On 13.04.2019 19:40, Tyler A wrote: >>> Hi, >>> >>> I had trouble visiting these two websites in Firefox, Epiphany and >>> verifying with OpenSSL. >>> >>> - Births Deaths and Marriages (Government of South Australia) >>> https://bdm.cbs.sa.gov.au/bdmsaonline/dbweb.asp?dbcgm=1&prprc=oac >>> >>> - Hostplus Superannuation Fund >>> https://hostplus.com.au/ >>> >>> ... >> I can access both sites without any problems with my browser (Firefox). > Keep in mind, you must do this in a new profile. If you've ever visited > a website which has used the certificate it will be cached, and the site > will work. Yes, my mistake, I've neglected that and now was able to repro your issue. As for your question about certificate installation. Apparently (I hope somebody will correct me on that), p11-kit doesn't provide a writable software pkcs#11 token for user to add/remove CA certificates, but 'gnome-keyring' does, and you should use it if you want to work with personal certificates, private keys, etc. However, most applications won't recognize the objects from gnome-keyring pkcs#11 module automatically and should be configured to use it by providing correct pkcs#11 module URI. So, that aside, in order to add CA certificates to "System Trust" token, provided by "p11-kit-trust" pkcs#11 module, you have to use "update-ca-certificates" utility. 1. Download CA certificates. 2. Process them with "openssl" to make them trusted and put them in special folder recognized by "update-ca-certificates" utility. $ sudo openssl x509 -inform der -in ./ThawteRSACA2018.crt -trustout -out /usr/local/share/ca-certificates/ThawteRSACA2018.crt $ sudo openssl x509 -inform der -in ./GeoTrustRSACA2018.crt -trustout -out /usr/local/share/ca-certificates/GeoTrustRSACA2018.crt 3. Start "update-ca-certificates" utility $ sudo update-ca-certificates -f 4. Check that certificates were added with "trust" utility. $ trust list --filter=ca-anchors --purpose=server-auth | egrep "GeoTrust RSA CA 2018|Thawte RSA CA 2018" label: GeoTrust RSA CA 2018 label: Thawte RSA CA 2018 That is it. Now a few remarks. Mozilla Firefox uses it's own NSS DB to store certificates and don't use other pkcs#11 modules and tokens, such as "System Trust", by default, so you have to configure it. In Firefox browser, open "Preferences" >> "Privacy & Security", click "Security Devices" and click "Load". Type in module name and module path: Name: "p11-kit-trust PKCS#11 Module" Path: "/usr/lib/x86_64-linux-gnu/pkcs11/p11-kit-trust.so" New module should appear on the left pane with "System Trust" token. If you select it, it will have "/etc/ssl/certs/ca-certificates.crt" in its Description. After that, problem sites should work without any additional actions. Any program that automatically uses compiled certificates in "/etc/ssl/certs/ca-certificates.crt" (updated by "update-ca-certificates"), like curl, wget, openssl, etc, should work with those sites too. Additionally you can specify a pkcs#11 token URI to use in their command line parameters: $ p11tool --list-tokens Token 0: URL: pkcs11:model=p11-kit-trust;manufacturer=PKCS%2311%20Kit;serial=1;token=System%20Trust Label: System Trust Type: Trust module Manufacturer: PKCS#11 Kit Model: p11-kit-trust Serial: 1 Module: p11-kit-trust.so > > I got the same certificates from a European VPN as I did from in > Australia (not what you got) which appears to be a CDN. > -- With kindest regards, Alexander. ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org ⠈⠳⣄⠀⠀⠀⠀
[toc] | [prev] | [next] | [standalone]
| From | Tyler A <tylera@privatedemail.net> |
|---|---|
| Date | 2019-04-19 17:50 +0200 |
| Message-ID | <xODW1-1Iy-5@gated-at.bofh.it> |
| In reply to | #207478 |
On 15/4/19 11:36 am, Alexander V. Makartsev wrote:
>> On 13.04.2019 23:21, Tyler A wrote:
>> I found a temporary solution that at least lets me visit the sites in Firefox.
>>
>> However this doesn't fix OpenSSL (thus things like curl, wget).
>>
>> #!/usr/bin/env bash
>>
>> sudo apt-get install libnss3-tools
>>
>> downloadCerts=(http://cacerts.thawte.com/ThawteRSACA2018.crt
>> http://cacerts.geotrust.com/GeoTrustRSACA2018.crt)
>>
>> wget -c "${downloadCerts[@]}"
>>
>> for f in *.crt; do
>> fbasename=${f%.crt}
>> openssl x509 -inform der -outform pem -in "$f" -out "$fbasename".pem
>> find ~ -name cert9.db -printf '%h\0' |
>> while IFS= read -rd '' certDir; do
>> certutil -A -n "${fbasename}" -t "TCu,Cuw,Tuw" -i "${fbasename}".pem -d sql:"$certDir"
>> done
>> done
>
> This script imports certificates into Mozilla Firefox own NSS DB.
> You can do the same procedure more easily in Firefox GUI with
> "Certificate Manager". ("Preferences" >> "Privacy & Security", click
> "View Certificates")
Yes I know. I wrote it :), it was a improved version of https://stackoverflow.com/a/48424709
On 15/4/19 11:29 am, Alexander V. Makartsev wrote:
> Yes, my mistake, I've neglected that and now was able to repro your issue.
> As for your question about certificate installation. Apparently (I hope somebody will correct me on that),
> p11-kit doesn't provide a writable software pkcs#11 token for user to add/remove CA certificates, but
> 'gnome-keyring' does, and you should use it if you want to work with personal certificates, private keys, etc.
Ah yes. I have that and gnome-keyring and polkit-gnome on my Archlinux machine.
I should mention, it appears hostplus.com.au has fixed their site and it
now issues the certificate so we can no longer test against that.
If you look at the ssllabs.com test it now says (whereas they were both
Incomplete before.
Sent by server GeoTrust RSA CA 2018
Chain issues Incorrect order, Contains anchor
Whereas if you look at bdm.cbs.sa.gov.au
Extra download Thawte RSA CA 2018
Chain issues Incomplete
The latter one still doesn't work so we can test with that.
> However, most applications won't recognize the objects from gnome-keyring pkcs#11 module automatically and
> should be configured to use it by providing correct pkcs#11 module URI.
>
> So, that aside, in order to add CA certificates to "System Trust" token,
> provided by "p11-kit-trust" pkcs#11 module,
> you have to use "update-ca-certificates" utility.
> 1. Download CA certificates.
> 2. Process them with "openssl" to make them trusted and put them in special folder recognized by "update-ca-certificates" utility.
> $ sudo openssl x509 -inform der -in ./ThawteRSACA2018.crt -trustout -out /usr/local/share/ca-certificates/ThawteRSACA2018.crt
> $ sudo openssl x509 -inform der -in ./GeoTrustRSACA2018.crt -trustout -out /usr/local/share/ca-certificates/GeoTrustRSACA2018.crt
>
> 3. Start "update-ca-certificates" utility
> $ sudo update-ca-certificates -f
>
> 4. Check that certificates were added with "trust" utility.
> $ trust list --filter=ca-anchors --purpose=server-auth | egrep "GeoTrust RSA CA 2018|Thawte RSA CA 2018"
> label: GeoTrust RSA CA 2018
> label: Thawte RSA CA 2018
>
> That is it. Now a few remarks. Mozilla Firefox uses it's own NSS DB to store certificates and don't use other pkcs#11 modules and tokens, such as "System Trust", by default, so you have to configure it.
> In Firefox browser, open "Preferences" >> "Privacy & Security", click "Security Devices" and click "Load".
> Type in module name and module path:
> Name: "p11-kit-trust PKCS#11 Module"
> Path: "/usr/lib/x86_64-linux-gnu/pkcs11/p11-kit-trust.so"
> New module should appear on the left pane with "System Trust" token. If you select it, it will have "/etc/ssl/certs/ca-certificates.crt" in its Description.
> After that, problem sites should work without any additional actions.
>
> Any program that automatically uses compiled certificates in "/etc/ssl/certs/ca-certificates.crt" (updated by "update-ca-certificates"), like curl, wget, openssl, etc, should work with those sites too.
> Additionally you can specify a pkcs#11 token URI to use in their command line parameters:
> $ p11tool --list-tokens
> Token 0:
> URL: pkcs11:model=p11-kit-trust;manufacturer=PKCS%2311%20Kit;serial=1;token=System%20Trust
> Label: System Trust
> Type: Trust module
> Manufacturer: PKCS#11 Kit
> Model: p11-kit-trust
> Serial: 1
> Module: p11-kit-trust.so
On ArchLinux I noticed that under:
Preferences" >> "Privacy & Security", >> "Security Devices" there is:
"Builtin Roots Module"
/etc/ca-certificates/trust-source
Status Ready
Description /etc/ca-certificates/trust-source
Manufacturer PKCS#11 Kit
HW Version 0.23
FW Version 0.0
Label System Trust
Manufacturer PKCS#11 Kit
Serial Number 1
HW Version 0.23
FW Version 0.0
I wonder if this has anything to do with the --with-system-nss[1] compile option?
I wrote this script which seems to work:
#!/usr/bin/env bash
downloadCerts=(http://cacerts.thawte.com/ThawteRSACA2018.crt)
wget -c "${downloadCerts[@]}"
for f in *.crt; do
fbasename=${f%.crt}
sudo openssl x509 -inform der -in "$f" -trustout -out /usr/local/share/ca-certificates/"$f"
done
sudo update-ca-certificates -f
find ~ -name pkcs11.txt -printf '%h\0' |
while IFS= read -rd '' pkcs11Files; do
if grep -Fxq "name=p11-kit-trust PKCS#11 Module" "$pkcs11Files"/pkcs11.txt
then
echo "Not adding device to $pkcs11Files/pkcs11.txt"
else
echo "Adding device to $pkcs11Files/pkcs11.txt"
cat <<EOF >> "$pkcs11Files"/pkcs11.txt
library=/usr/lib/x86_64-linux-gnu/pkcs11/p11-kit-trust.so
name=p11-kit-trust PKCS#11 Module
NSS=trustOrder=100
EOF
fi
done
[0]: https://support.mozilla.org/en-US/questions/1022183
[1]: https://git.archlinux.org/svntogit/packages.git/tree/trunk/PKGBUILD?h=packages/firefox#n86
--
Tyler (tya99)
rsa4096/0x9C9954F88E388859
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web