Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

"No problem is so formidable that you can't walk away from it." -- C. Schulz


computers / comp.misc / Letsencrypt cert server fail?

SubjectAuthor
* Letsencrypt cert server fail?Mike Spencer
+* Re: Letsencrypt cert server fail?Andy Burns
|`* Re: Letsencrypt cert server fail?Mike Spencer
| `* Re: Letsencrypt cert server fail?Andy Burns
|  `- Re: Letsencrypt cert server fail?Mike Spencer
`* Re: Letsencrypt cert server fail?Oregonian Haruspex
 +- Re: Letsencrypt cert server fail?Bob Eager
 `* Re: Letsencrypt cert server fail?Visiblink
  `- Re: Letsencrypt cert server fail?Computer Nerd Kev

1
Letsencrypt cert server fail?

<87k0iwm1z4.fsf@bogus.nodomain.nowhere>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1174&group=comp.misc#1174

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: mds@bogus.nodomain.nowhere (Mike Spencer)
Newsgroups: comp.misc
Subject: Letsencrypt cert server fail?
Date: 02 Oct 2021 02:26:23 -0300
Organization: Bridgewater Institute for Advanced Study - Blacksmith Shop
Lines: 42
Message-ID: <87k0iwm1z4.fsf@bogus.nodomain.nowhere>
Injection-Info: reader02.eternal-september.org; posting-host="80758c0076535cda14db56bd1ce53e0b";
logging-data="8481"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18DJtY74Q4lH1fnAaC1Is/SkGSIIc3tvb0="
Cancel-Lock: sha1:i4ctpp7SdYa1UZH5hoMtuyw5PHs=
X-Newsreader: Gnus v5.7/Emacs 20.7
 by: Mike Spencer - Sat, 2 Oct 2021 05:26 UTC

Is Letsencrypt having a problem or is this something I don't
understand? (Lots of things, including the whole cert mechanism, I
don't understand.)

Numerous web sites failing to connect 1-2 Oct. 2021

Browser (Seamonkey) reports:

sec_error_expired_issuer_certificate

wget --no-check-certificate reports:

WARNING: cannot verify [DOMAIN_NAME]'s certificate, issued by
'CN=R3,O=Let\'s Encrypt,C=US':
Issued certificate has expired.

Sites that fail are themselves okay because the wget command succeeds
with --no-check-certificate.

Not all sites fail.

Example sites that fail:

slashdot.org
soylentnews.org
www.schneier.com
nymag.com

Example sites that DO NOT fail

google.com
www.nhc.noaa.gov
topics.nytimes.com
xkcd.com

Using Linux, Seamonkey 2.40 but another user has had same problem,
same date Oct 1, using Windows.

--
Mike Spencer Nova Scotia, Canada

Re: Letsencrypt cert server fail?

<irqdtaF562cU1@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1175&group=comp.misc#1175

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@andyburns.uk (Andy Burns)
Newsgroups: comp.misc
Subject: Re: Letsencrypt cert server fail?
Date: Sat, 2 Oct 2021 07:52:25 +0100
Lines: 7
Message-ID: <irqdtaF562cU1@mid.individual.net>
References: <87k0iwm1z4.fsf@bogus.nodomain.nowhere>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net 5AeZIAmUfP/1qgsWdpMhegHtRAA8ULCgfDAwIQxCJLXHYFZ4xR
Cancel-Lock: sha1:VizimU3XpOOUsBRCWIKPYGGERtY=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.1.2
Content-Language: en-GB
In-Reply-To: <87k0iwm1z4.fsf@bogus.nodomain.nowhere>
 by: Andy Burns - Sat, 2 Oct 2021 06:52 UTC

Mike Spencer wrote:

> Using Linux, Seamonkey 2.40 but another user has had same problem,
> same date Oct 1, using Windows.
Import the "ISRG Root X1" into seamonkey's certificate store under authorities?

<https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021>

Re: Letsencrypt cert server fail?

<87bl47nb0u.fsf@bogus.nodomain.nowhere>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1176&group=comp.misc#1176

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: mds@bogus.nodomain.nowhere (Mike Spencer)
Newsgroups: comp.misc
Subject: Re: Letsencrypt cert server fail?
Date: 02 Oct 2021 04:25:37 -0300
Organization: Bridgewater Institute for Advanced Study - Blacksmith Shop
Lines: 24
Message-ID: <87bl47nb0u.fsf@bogus.nodomain.nowhere>
References: <87k0iwm1z4.fsf@bogus.nodomain.nowhere> <irqdtaF562cU1@mid.individual.net>
Injection-Info: reader02.eternal-september.org; posting-host="80758c0076535cda14db56bd1ce53e0b";
logging-data="6712"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18QAkO5TsHPnATJdjaNRskLAHMVK2L4IYY="
Cancel-Lock: sha1:vGboZtchR5l3hYhfR3PcNA37WOw=
X-Newsreader: Gnus v5.7/Emacs 20.7
X-Clacks-Overhead: 4GH GNU Terry Pratchett
 by: Mike Spencer - Sat, 2 Oct 2021 07:25 UTC

Andy Burns <usenet@andyburns.uk> writes:

> Mike Spencer wrote:
>
>> Using Linux, Seamonkey 2.40 but another user has had same problem,
>> same date Oct 1, using Windows.
>
> <https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021>

Yes, after posting, I eventually found that with some bother.
With Linux, there's a workaround but it's a tedious PITA.

> Import the "ISRG Root X1" into seamonkey's certificate store under
> authorities?

I don't know how to do that but I'll try to find out directly.

Thank you very much.

--
Mike Spencer Nova Scotia, Canada

Re: Letsencrypt cert server fail?

<irqi04F5trhU1@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1177&group=comp.misc#1177

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.szaf.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: usenet@andyburns.uk (Andy Burns)
Newsgroups: comp.misc
Subject: Re: Letsencrypt cert server fail?
Date: Sat, 2 Oct 2021 09:02:11 +0100
Lines: 29
Message-ID: <irqi04F5trhU1@mid.individual.net>
References: <87k0iwm1z4.fsf@bogus.nodomain.nowhere>
<irqdtaF562cU1@mid.individual.net> <87bl47nb0u.fsf@bogus.nodomain.nowhere>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net NvUHxHdKkwbLUoBZ/qGH8g8YhMBkZWtt3BD9NK5IT8/IPqzJ1B
Cancel-Lock: sha1:cs9wmdANrBBXk60UnsyX7QCx304=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101
Thunderbird/91.1.2
Content-Language: en-GB
In-Reply-To: <87bl47nb0u.fsf@bogus.nodomain.nowhere>
 by: Andy Burns - Sat, 2 Oct 2021 08:02 UTC

Mike Spencer wrote:

> Andy Burns wrote:
>
>> Mike Spencer wrote:
>>
>>> Using Linux, Seamonkey 2.40 but another user has had same problem,
>>> same date Oct 1, using Windows.
>>
>> <https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021>
>
> Yes, after posting, I eventually found that with some bother.
> With Linux, there's a workaround but it's a tedious PITA.
>
>> Import the "ISRG Root X1" into seamonkey's certificate store under
>> authorities?
>
> I don't know how to do that but I'll try to find out directly.

I'm sure you'll figure it, but use wget or curl or something to grab the cert
file from

https://letsencrypt.org/certs/isrgrootx1.der

it's also available as a .pem if you have a reason to prefer that.

Then (and this is where, as a TB/FF user, I have to assume that SM is broadly
similar) Tools/Settings/Security/Certificates, select Authorities, click import
and select the file you just downloaded.

Re: Letsencrypt cert server fail?

<877detnaex.fsf@bogus.nodomain.nowhere>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1178&group=comp.misc#1178

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: mds@bogus.nodomain.nowhere (Mike Spencer)
Newsgroups: comp.misc
Subject: Re: Letsencrypt cert server fail?
Date: 03 Oct 2021 17:03:18 -0300
Organization: Bridgewater Institute for Advanced Study - Blacksmith Shop
Lines: 75
Message-ID: <877detnaex.fsf@bogus.nodomain.nowhere>
References: <87k0iwm1z4.fsf@bogus.nodomain.nowhere> <irqdtaF562cU1@mid.individual.net> <87bl47nb0u.fsf@bogus.nodomain.nowhere> <irqi04F5trhU1@mid.individual.net>
Injection-Info: reader02.eternal-september.org; posting-host="128c70724f8ac2f573e63d8741e22f4c";
logging-data="15690"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/CdO1hTBb0GyLH7BNBIJyNcBKLpd/em2o="
Cancel-Lock: sha1:A3QSp9fIJKSxSkbGkPkwBEkASas=
X-Newsreader: Gnus v5.7/Emacs 20.7
X-Clacks-Overhead: 4GH GNU Terry Pratchett
 by: Mike Spencer - Sun, 3 Oct 2021 20:03 UTC

Andy Burns <usenet@andyburns.uk> writes:

> Mike Spencer wrote:
>
>> Andy Burns wrote:
>>
>>> Mike Spencer wrote:
>>>
>>>> Using Linux, Seamonkey 2.40 but another user has had same problem,
>>>> same date Oct 1, using Windows.
>>>
>>> <https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021>
>>
>>> Import the "ISRG Root X1" into seamonkey's certificate store under
>>> authorities?
>>
>> I don't know how to do that but I'll try to find out directly.
>
> I'm sure you'll figure it, but use wget or curl or something to grab
> the cert file from
>
> https://letsencrypt.org/certs/isrgrootx1.der
>
> it's also available as a .pem if you have a reason to prefer that.

Good. Thank you. Did figure it out. Seamonkey appears to be working
as expected with sites using ISRG certs.

> Then (and this is where, as a TB/FF user, I have to assume that SM
> is broadly similar) Tools/Settings/Security/Certificates, select
> Authorities, click import and select the file you just downloaded.

Just so. Worked as intended. Next up: Try same for SM on Windows box
of SWMBO.

Digressing only slightly: Despite lots of (admittedly amateur) messing
about with assembler, C, Perl etc. from CP/M days into Linux and
TCP/IP, tech gets increasingly complex (in the technical as well as
the colloquial sense) and I've been getting old almost as fast since,
say, I first read K&R.

I'm not nearly as smart or as knowledgeable as Dan Geer but I'm
inclined to agree with him.

I am getting older, and I have to allow for the fact that perhaps that
explains everything, though I don't think so. I am, as a rule,
skeptical of coming to rely upon things that I don't know how they
work. If there's anything that I've come to be relatively adamant
about is that, as humans, we have repeatedly demonstrated that we can
quite clearly build things more complex than we can then manage, our
friends in finance and flash crashes being a fine example of that.

Given what I know in the cyber security arena, the number of things
that, in effect, nobody understands how they work causes me to say,
well, then why do I want to depend on it?

I understand basic concepts such as how PKC works in principle but the
whole HTTPS/PKC/certificate/digital-sig as a ball of wax remains
mostly a black box. Pop-up windows asking me to choose between or
approve things I don't understand are particularly intimidating. So
I'm hesitant to "just 'import' $FILE that comes from $SITE into
$HUGE_COMPLICATED_APP and click 'OK'" when I don't understand most of
the pieces involved in doing that.

Well, in any case, I did that and all appears to be well.

I need a nice lucid book that explains this stuff, more detailed than
pop-culture Luser level but less so than the large congeries of
relevant RFCs.

Usenet saves the day when the web goes dark! TYVM,

--
Mike Spencer Nova Scotia, Canada

Re: Letsencrypt cert server fail?

<sjmcd4$dfv$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1179&group=comp.misc#1179

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: no_email@invalid.invalid (Oregonian Haruspex)
Newsgroups: comp.misc
Subject: Re: Letsencrypt cert server fail?
Date: Thu, 7 Oct 2021 08:50:44 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 2
Message-ID: <sjmcd4$dfv$1@dont-email.me>
References: <87k0iwm1z4.fsf@bogus.nodomain.nowhere>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Thu, 7 Oct 2021 08:50:44 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="54ab8702a2b6a85291b460e7a05e74d8";
logging-data="13823"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+N0evtGVzbKoZKOZNdgqJk"
User-Agent: NewsTap/5.5 (iPad)
Cancel-Lock: sha1:1gFQcxEbSPGpozq8BXighkoyxS4=
sha1:cY/FCPB2Tb4Qs4d+YxnhQYHupTQ=
 by: Oregonian Haruspex - Thu, 7 Oct 2021 08:50 UTC

I just HATE LetsEncrypt. It’s such a pain in the ass unless you want to
give it’s script root permissions, to update.

Re: Letsencrypt cert server fail?

<is7t4aFl7dbU2@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1180&group=comp.misc#1180

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: news0009@eager.cx (Bob Eager)
Newsgroups: comp.misc
Subject: Re: Letsencrypt cert server fail?
Date: 7 Oct 2021 09:31:54 GMT
Lines: 13
Message-ID: <is7t4aFl7dbU2@mid.individual.net>
References: <87k0iwm1z4.fsf@bogus.nodomain.nowhere>
<sjmcd4$dfv$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net OB1rcj+fz0zOnDkV2PUrdgjd/di6SYPRUnwKlMCdnzLt66UX4C
Cancel-Lock: sha1:lAJPwU6jclSj2yTMJiq7NvpGCQk=
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
 by: Bob Eager - Thu, 7 Oct 2021 09:31 UTC

On Thu, 07 Oct 2021 08:50:44 +0000, Oregonian Haruspex wrote:

> I just HATE LetsEncrypt. It’s such a pain in the ass unless you want to
> give it’s script root permissions, to update.

You doesn't pay yer money, and yer takes yer choice...!

--
Using UNIX since v6 (1975)...

Use the BIG mirror service in the UK:
http://www.mirrorservice.org

Re: Letsencrypt cert server fail?

<20211007184507.3e80bcb6@thinkpad-l440.darkstar>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1181&group=comp.misc#1181

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: visiblink@mail.invalid (Visiblink)
Newsgroups: comp.misc
Subject: Re: Letsencrypt cert server fail?
Date: Thu, 7 Oct 2021 18:45:07 -0700
Organization: A noiseless patient Spider
Lines: 11
Message-ID: <20211007184507.3e80bcb6@thinkpad-l440.darkstar>
References: <87k0iwm1z4.fsf@bogus.nodomain.nowhere>
<sjmcd4$dfv$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Injection-Info: reader02.eternal-september.org; posting-host="14f5a8be390cc143a1d2099ea38bd6c4";
logging-data="26372"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18bFY+ORyGfyPuU7IIKXXNyzcV0csJ48k0="
Cancel-Lock: sha1:lGt/nNTr+ouG4CBw6I8hb/83N0I=
X-Newsreader: Claws Mail 3.17.8 (GTK+ 2.24.33; x86_64-pc-linux-gnu)
 by: Visiblink - Fri, 8 Oct 2021 01:45 UTC

On Thu, 7 Oct 2021 08:50:44 -0000 (UTC)
Oregonian Haruspex <no_email@invalid.invalid> wrote:

> I just HATE LetsEncrypt. It’s such a pain in the ass unless you want
> to give it’s script root permissions, to update.

I only use it for my XMPP server. There's no reason to use https on my
website, and there's the added bonus that Google no longer likes it,
since it's just plain old http.

Re: Letsencrypt cert server fail?

<sjoqpj$1dhi$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1182&group=comp.misc#1182

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!aioe.org!qIOX1ih6aAr2cXShbXfYNQ.user.46.165.242.75.POSTED!not-for-mail
From: not@telling.you.invalid (Computer Nerd Kev)
Newsgroups: comp.misc
Subject: Re: Letsencrypt cert server fail?
Date: Fri, 8 Oct 2021 07:08:36 -0000 (UTC)
Organization: Aioe.org NNTP Server
Message-ID: <sjoqpj$1dhi$1@gioia.aioe.org>
References: <87k0iwm1z4.fsf@bogus.nodomain.nowhere> <sjmcd4$dfv$1@dont-email.me> <20211007184507.3e80bcb6@thinkpad-l440.darkstar>
Injection-Info: gioia.aioe.org; logging-data="46642"; posting-host="qIOX1ih6aAr2cXShbXfYNQ.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/2.4.31 (i686))
X-Notice: Filtered by postfilter v. 0.9.2
 by: Computer Nerd Kev - Fri, 8 Oct 2021 07:08 UTC

Visiblink <visiblink@mail.invalid> wrote:
> On Thu, 7 Oct 2021 08:50:44 -0000 (UTC)
> Oregonian Haruspex <no_email@invalid.invalid> wrote:
>
>> I just HATE LetsEncrypt. It?s such a pain in the ass unless you want
>> to give it?s script root permissions, to update.
>
> I only use it for my XMPP server. There's no reason to use https on my
> website, and there's the added bonus that Google no longer likes it,
> since it's just plain old http.

I've got a website available over HTTP or HTTPS (using Let's
Encrypt, and no I can't say that I've mastered it either) and
google still includes page links to it with HTTP links instead of
HTTPS. If they really cared then it would be easy to make their
crawler check whether the same content was available over HTTPS.

Google still puts such HTTP links in first page results too, eg.
fifth result for a fairly non-specific search, so I think the
result de-ranking threats are a lot of hot air as well.

--
__ __
#_ < |\| |< _#

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor