[Bug 854927] Re: c_rehash creating bogus links to ca-certificates.crt

Colin Watson cjwatson at canonical.com
Wed Sep 21 12:29:54 UTC 2011


Is this really the entirety of the bug?  With the new openssl but the
old ca-certificates, I ran:

  $ sudo update-ca-certificates --fresh
  ...
  $ ls -l /usr/lib/ssl/certs/55a10908.0
lrwxrwxrwx 1 root root 19 2011-09-21 13:27 /usr/lib/ssl/certs/55a10908.0 -> ca-certificates.crt
  $ curl -sS http://launchpad.net
  <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
  <html><head>
  <title>301 Moved Permanently</title>
  </head><body>
  <h1>Moved Permanently</h1>
  <p>The document has moved <a href="https://launchpad.net/">here</a>.</p>
  <hr>
  <address>Apache/2.2.14 (Ubuntu) Server at launchpad.net Port 80</address>
  </body></html>

What am I missing?  While we could certainly change c_rehash to make
sure it always prefers .pem files over .crt (and that might be
preferable anyway), I wonder why libssl is unable to deal with the .crt
files ...

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to openssl in Ubuntu.
https://bugs.launchpad.net/bugs/854927

Title:
  c_rehash creating bogus links to ca-certificates.crt

Status in “ca-certificates” package in Ubuntu:
  Fix Released
Status in “openssl” package in Ubuntu:
  Triaged
Status in “ca-certificates” source package in Oneiric:
  Fix Released
Status in “openssl” source package in Oneiric:
  Triaged

Bug description:
  $ wget https://www.google.com
  --2011-09-20 18:12:46--  https://www.google.com/
  Resolving www.google.com... 209.85.169.105, 209.85.169.106, 209.85.169.147, ...
  Connecting to www.google.com|209.85.169.105|:443... connected.
  ERROR: cannot verify www.google.com's certificate, issued by `/C=ZA/O=Thawte Consulting (Pty) Ltd./CN=Thawte SGC CA':
    Unable to locally verify the issuer's authority.
  To connect to www.google.com insecurely, use `--no-check-certificate'.

  $ curl -sS https://launchpad.net 
  curl: (35) error:0B07C065:x509 certificate routines:X509_STORE_add_cert:cert already in hash table

  ProblemType: Bug
  DistroRelease: Ubuntu 11.10
  Package: openssl 1.0.0e-2ubuntu1
  ProcVersionSignature: User Name 3.0.0-11.18-virtual 3.0.4
  Uname: Linux 3.0.0-11-virtual i686
  ApportVersion: 1.23-0ubuntu1
  Architecture: i386
  Date: Tue Sep 20 18:11:11 2011
  Ec2AMI: ami-00000090
  Ec2AMIManifest: FIXME
  Ec2AvailabilityZone: nova
  Ec2InstanceType: m1.small
  Ec2Kernel: unavailable
  Ec2Ramdisk: unavailable
  ProcEnviron:
   LANG=en_US.UTF-8
   SHELL=/bin/bash
  SourcePackage: openssl
  UpgradeStatus: No upgrade log present (probably fresh install)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ca-certificates/+bug/854927/+subscriptions




More information about the foundations-bugs mailing list