GnuTLS | Solaris (OpenIndiana) parameter handling problem in certtool (#1916)
Read-only notification of GnuTLS library development activities <[email protected]> Thu, 16 Jul 2026 10:34:46 +0000
| Newsgroups | gmane.comp.encryption.gpg.gnutls.devel |
|---|---|
| Message-ID | <[email protected]> |
--===============6477227137071193395==
Content-Type: multipart/alternative;
boundary="--==_mimepart_6a58b3c63f867_3719cf0865232";
charset=UTF-8
Content-Transfer-Encoding: 7bit
----==_mimepart_6a58b3c63f867_3719cf0865232
Content-Type: text/plain;
charset=UTF-8
Content-Transfer-Encoding: 7bit
Issue created by Thomas Dreibholz: https://gitlab.com/gnutls/gnutls/-/work_items/1916
## Description of problem:
I am testing with platform-independent scripts from the [X.509-Tools](https://www.nntb.no/~dreibh/system-tools/#x.509-tools) (Git: [https://github.com/dreibh/system-tools](https://github.com/dreibh/system-tools)), which tests CA hierarchies and certificates under different operating systems (multiple Linux distributions, FreeBSD, NetBSD, OpenBSD, MacOS). Background is to make sure that the CA/certificate setup works on all systems. Currently, I am experimenting with Solaris ([OpenIndiana](https://www.openindiana.org/), 2026.04 version).
Under Solaris, `certtool --verify` fails:
```
$ certtool --verify --verify-profile=future --load-ca-certificate=PATH_TO_CA.crt --infile=PATH_TO_USER_CERT.crt
certtool: ambiguous option -- verify
```
The same certtool call works fine under Linux, the BSDs, and MacOS.
The problems seems to be the strict handling of long options under Solaris: certtool has multiple options with prefix `--verify`:
```
-e, --verify-chain Verify a PEM encoded certificate chain
--verify Verify a PEM encoded certificate (chain) against a trusted set
--verify-hostname=str Specify a hostname to be used for certificate chain verification
--verify-email=str Specify a email to be used for certificate chain verification
- prohibits the option 'verify-hostname'
--verify-purpose=str Specify a purpose OID to be used for certificate chain verification
--verify-allow-broken Allow broken algorithms, such as MD5 for verification
--verify-profile=str Specify a security level profile to be used for verification
```
A solution could be to give the option a different name (e.g. `--verify-with-ca`), or a short option (`-E`). At the moment, it is not possible to verify a chain with a CA certificate under Solaris with GnuTLS certtool, i.e. an important feature is broken under Solaris.
## Version of gnutls used:
3.8.13
```
(x509) nornetpp@openindiana:~/src/system-tools/src/X509$ uname -a
SunOS openindiana 5.11 illumos-2b7388bd44 i86pc i386 i86pc
(x509) nornetpp@openindiana:~/src/system-tools/src/X509$ certtool --version
certtool 3.8.13
```
## Distributor of gnutls (e.g., Ubuntu, Fedora, RHEL)
OpenIndiana
```
(x509) nornetpp@openindiana:~/src/system-tools/src/X509$ pkg publisher
PUBLISHER TYPE STATUS P LOCATION
openindiana.org origin online F https://pkg.openindiana.org/hipster/
localhostoih origin online F http://sfe.opencsw.org/localhostoih/
```
--
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/work_items/1916
You're receiving this email because of your account on gitlab.com. Unsubscribe from this thread: https://gitlab.com/-/namespace/17175643/sent_notifications/5-ed0vakpmjgqlq8n9ew4skobyw-a84t7/unsubscribe | Manage all notifications: https://gitlab.com/-/profile/notifications | Help: https://gitlab.com/help
----==_mimepart_6a58b3c63f867_3719cf0865232
Content-Type: text/html;
charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www=
.w3.org/TR/REC-html40/loose.dtd">
<html lang=3D"en" style=3D'--code-editor-font: var(--default-mono-font, "=
GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, =
Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospac=
e;'>
<head>
<meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Type">=
<title>
GitLab
</title>
<style data-premailer=3D"ignore" type=3D"text/css">
a { color: #1068bf; }
</style>
<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Ro=
boto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Colo=
r Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size=
: inherit;
}
</style>
</head>
<body style=3D'font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.0=
1) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"=
Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif=
,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji=
";'>
<div class=3D"content">
<p class=3D"details" style=3D"font-style: italic; color: #626168;">
Issue created by <a href=3D"https://gitlab.com/dreibh">Thomas Dreibholz</=
a>: <a href=3D"https://gitlab.com/gnutls/gnutls/-/work_items/1916">#1916<=
/a>
</p>
<div class=3D"md" style=3D"position: relative; z-index: 1; color: #3a383f=
; word-wrap: break-word;">
<h2 id=3D"user-content-description-of-problem" dir=3D"auto" style=3D"marg=
in-top: 0px; margin-bottom: 10px;" align=3D"initial">Description of probl=
em:<a href=3D"#description-of-problem" aria-label=3D"Link to heading 'Des=
cription of problem:'" data-heading-content=3D"Description of problem:" c=
lass=3D"anchor" style=3D"margin-top: 0px;"></a>
</h2>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">I am testing with platform-independent scripts from the <a href=3D=
"https://www.nntb.no/~dreibh/system-tools/#x.509-tools" rel=3D"nofollow n=
oreferrer noopener" target=3D"_blank" style=3D"margin-top: 0px;">X.509-To=
ols</a> (Git: <a href=3D"https://github.com/dreibh/system-tools" rel=3D"n=
ofollow noreferrer noopener" target=3D"_blank">https://github.com/dreibh/=
system-tools</a>), which tests CA hierarchies and certificates under diff=
erent operating systems (multiple Linux distributions, FreeBSD, NetBSD, O=
penBSD, MacOS). Background is to make sure that the CA/certificate setup =
works on all systems. Currently, I am experimenting with Solaris (<a href=
=3D"https://www.openindiana.org/" rel=3D"nofollow noreferrer noopener" ta=
rget=3D"_blank">OpenIndiana</a>, 2026.04 version).</p>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">Under Solaris, <code style=3D'font-size: 90%; color: #18171d; wo=
rd-wrap: break-word; background-color: #ececef; border-radius: .25rem; ma=
rgin-top: 0px; font-weight: inherit; overflow-wrap: break-word; white-spa=
ce: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", =
"DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courie=
r New", "andale mono", "lucida console", monospace; font-variant-ligature=
s: none; word-break: keep-all; padding: 0.125rem 0.25rem;'>certtool --ver=
ify</code> fails:</p>
<div class=3D"gl-relative markdown-code-block js-markdown-code">
<pre class=3D"code highlight js-syntax-highlight language-plaintext" v-pr=
e=3D"true" style=3D'display: block; font-size: 14px; color: #3a383f; line=
-height: 1.6em; overflow-x: auto; border-radius: .25rem; position: relati=
ve; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans M=
ono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andal=
e mono", "lucida console", monospace; font-variant-ligatures: none; word-=
break: break-all; word-wrap: break-word; background-color: #fbfafd; margi=
n: 0px 0 1rem; padding: 12px; border: 1px solid #dcdcde;'><code style=3D'=
font-size: inherit; color: inherit; word-wrap: normal; word-break: keep-a=
ll; background-color: inherit; border-radius: .25rem; white-space: pre; m=
argin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "D=
ejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier =
New", "andale mono", "lucida console", monospace; font-variant-ligatures:=
none; overflow-wrap: normal; padding: unset;'><span id=3D"LC1" class=3D"=
line" data-lang=3D"plaintext" style=3D"margin-top: 0px;">$ certtool --ver=
ify --verify-profile=3Dfuture --load-ca-certificate=3DPATH_TO_CA.crt --i=
nfile=3DPATH_TO_USER_CERT.crt</span>
<span id=3D"LC2" class=3D"line" data-lang=3D"plaintext">certtool: ambiguo=
us option -- verify</span></code></pre>
<copy-code></copy-code><insert-code-snippet></insert-code-snippet>
</div>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">The same certtool call works fine under Linux, the BSDs, and Mac=
OS.</p>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">The problems seems to be the strict handling of long options und=
er Solaris: certtool has multiple options with prefix <code style=3D'font=
-size: 90%; color: #18171d; word-wrap: break-word; background-color: #ece=
cef; border-radius: .25rem; margin-top: 0px; font-weight: inherit; overfl=
ow-wrap: break-word; white-space: break-spaces; font-family: "GitLab Mono=
", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Con=
solas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", mo=
nospace; font-variant-ligatures: none; word-break: keep-all; padding: 0.1=
25rem 0.25rem;'>--verify</code>:</p>
<div class=3D"gl-relative markdown-code-block js-markdown-code">
<pre class=3D"code highlight js-syntax-highlight language-plaintext" v-pr=
e=3D"true" style=3D'display: block; font-size: 14px; color: #3a383f; line=
-height: 1.6em; overflow-x: auto; border-radius: .25rem; position: relati=
ve; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans M=
ono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andal=
e mono", "lucida console", monospace; font-variant-ligatures: none; word-=
break: break-all; word-wrap: break-word; background-color: #fbfafd; margi=
n: 0px 0 1rem; padding: 12px; border: 1px solid #dcdcde;'><code style=3D'=
font-size: inherit; color: inherit; word-wrap: normal; word-break: keep-a=
ll; background-color: inherit; border-radius: .25rem; white-space: pre; m=
argin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "D=
ejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier =
New", "andale mono", "lucida console", monospace; font-variant-ligatures:=
none; overflow-wrap: normal; padding: unset;'><span id=3D"LC1" class=3D"=
line" data-lang=3D"plaintext" style=3D"margin-top: 0px;"> -e, --verify-=
chain Verify a PEM encoded certificate chain</span>
<span id=3D"LC2" class=3D"line" data-lang=3D"plaintext"> --verify =
Verify a PEM encoded certificate (chain) against a trusted s=
et</span>
<span id=3D"LC3" class=3D"line" data-lang=3D"plaintext"> --verify-h=
ostname=3Dstr Specify a hostname to be used for certificate chain verifi=
cation</span>
<span id=3D"LC4" class=3D"line" data-lang=3D"plaintext"> --verify-e=
mail=3Dstr Specify a email to be used for certificate chain verificat=
ion</span>
<span id=3D"LC5" class=3D"line" data-lang=3D"plaintext"> =
- prohibits the option 'verify-hostname'</span>
<span id=3D"LC6" class=3D"line" data-lang=3D"plaintext"> --verify-p=
urpose=3Dstr Specify a purpose OID to be used for certificate chain ver=
ification</span>
<span id=3D"LC7" class=3D"line" data-lang=3D"plaintext"> --verify-a=
llow-broken Allow broken algorithms, such as MD5 for verification</span>=
<span id=3D"LC8" class=3D"line" data-lang=3D"plaintext"> --verify-p=
rofile=3Dstr Specify a security level profile to be used for verificati=
on</span></code></pre>
<copy-code></copy-code><insert-code-snippet></insert-code-snippet>
</div>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">A solution could be to give the option a different name (e.g. <c=
ode style=3D'font-size: 90%; color: #18171d; word-wrap: break-word; backg=
round-color: #ececef; border-radius: .25rem; margin-top: 0px; font-weight=
: inherit; overflow-wrap: break-word; white-space: break-spaces; font-fam=
ily: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liber=
ation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lu=
cida console", monospace; font-variant-ligatures: none; word-break: keep-=
all; padding: 0.125rem 0.25rem;'>--verify-with-ca</code>), or a short opt=
ion (<code style=3D'font-size: 90%; color: #18171d; word-wrap: break-word=
; background-color: #ececef; border-radius: .25rem; font-weight: inherit;=
overflow-wrap: break-word; white-space: break-spaces; font-family: "GitL=
ab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono=
", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida conso=
le", monospace; font-variant-ligatures: none; word-break: keep-all; paddi=
ng: 0.125rem 0.25rem;'>-E</code>). At the moment, it is not possible to v=
erify a chain with a CA certificate under Solaris with GnuTLS certtool, i=
.e. an important feature is broken under Solaris.</p>
<h2 id=3D"user-content-version-of-gnutls-used" dir=3D"auto" style=3D"marg=
in-top: 20px; margin-bottom: 10px;" align=3D"initial">Version of gnutls u=
sed:<a href=3D"#version-of-gnutls-used" aria-label=3D"Link to heading 'Ve=
rsion of gnutls used:'" data-heading-content=3D"Version of gnutls used:" =
class=3D"anchor" style=3D"margin-top: 0px;"></a>
</h2>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">3.8.13</p>
<div class=3D"gl-relative markdown-code-block js-markdown-code">
<pre class=3D"code highlight js-syntax-highlight language-plaintext" v-pr=
e=3D"true" style=3D'display: block; font-size: 14px; color: #3a383f; line=
-height: 1.6em; overflow-x: auto; border-radius: .25rem; position: relati=
ve; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans M=
ono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andal=
e mono", "lucida console", monospace; font-variant-ligatures: none; word-=
break: break-all; word-wrap: break-word; background-color: #fbfafd; margi=
n: 0px 0 1rem; padding: 12px; border: 1px solid #dcdcde;'><code style=3D'=
font-size: inherit; color: inherit; word-wrap: normal; word-break: keep-a=
ll; background-color: inherit; border-radius: .25rem; white-space: pre; m=
argin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "D=
ejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier =
New", "andale mono", "lucida console", monospace; font-variant-ligatures:=
none; overflow-wrap: normal; padding: unset;'><span id=3D"LC1" class=3D"=
line" data-lang=3D"plaintext" style=3D"margin-top: 0px;">(x509) nornetpp@=
openindiana:~/src/system-tools/src/X509$ uname -a</span>
<span id=3D"LC2" class=3D"line" data-lang=3D"plaintext">SunOS openindiana=
5.11 illumos-2b7388bd44 i86pc i386 i86pc</span>
<span id=3D"LC3" class=3D"line" data-lang=3D"plaintext">(x509) nornetpp@o=
penindiana:~/src/system-tools/src/X509$ certtool --version</span>
<span id=3D"LC4" class=3D"line" data-lang=3D"plaintext">certtool 3.8.13</=
span></code></pre>
<copy-code></copy-code><insert-code-snippet></insert-code-snippet>
</div>
<h2 id=3D"user-content-distributor-of-gnutls-eg-ubuntu-fedora-rhel" dir=3D=
"auto" style=3D"margin-top: 20px; margin-bottom: 10px;" align=3D"initial"=
>Distributor of gnutls (e.g., Ubuntu, Fedora, RHEL)<a href=3D"#distributo=
r-of-gnutls-eg-ubuntu-fedora-rhel" aria-label=3D"Link to heading 'Distrib=
utor of gnutls (e.g., Ubuntu, Fedora, RHEL)'" data-heading-content=3D"Dis=
tributor of gnutls (e.g., Ubuntu, Fedora, RHEL)" class=3D"anchor" style=3D=
"margin-top: 0px;"></a>
</h2>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">OpenIndiana</p>
<div class=3D"gl-relative markdown-code-block js-markdown-code" style=3D"=
margin-bottom: 0px;">
<pre class=3D"code highlight js-syntax-highlight language-plaintext" v-pr=
e=3D"true" style=3D'display: block; font-size: 14px; color: #3a383f; line=
-height: 1.6em; overflow-x: auto; border-radius: .25rem; position: relati=
ve; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans M=
ono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andal=
e mono", "lucida console", monospace; font-variant-ligatures: none; word-=
break: break-all; word-wrap: break-word; background-color: #fbfafd; margi=
n: 0px 0 1rem; padding: 12px; border: 1px solid #dcdcde;'><code style=3D'=
font-size: inherit; color: inherit; word-wrap: normal; word-break: keep-a=
ll; background-color: inherit; border-radius: .25rem; white-space: pre; m=
argin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "D=
ejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier =
New", "andale mono", "lucida console", monospace; font-variant-ligatures:=
none; overflow-wrap: normal; padding: unset;'><span id=3D"LC1" class=3D"=
line" data-lang=3D"plaintext" style=3D"margin-top: 0px;">(x509) nornetpp@=
openindiana:~/src/system-tools/src/X509$ pkg publisher</span>
<span id=3D"LC2" class=3D"line" data-lang=3D"plaintext">PUBLISHER =
TYPE STATUS P LOCATION</span>
<span id=3D"LC3" class=3D"line" data-lang=3D"plaintext">openindiana.org =
origin online F https://pkg.openindiana.org/hipster/</span>=
<span id=3D"LC4" class=3D"line" data-lang=3D"plaintext">localhostoih =
origin online F http://sfe.opencsw.org/localhostoih/</span><=
/code></pre>
<copy-code></copy-code><insert-code-snippet></insert-code-snippet>
</div>
</div>
</div>
<div class=3D"footer" style=3D"margin-top: 10px;">
<p style=3D"font-size: small; color: #626168;">
=E2=80=94
<br>
Reply to this email directly or <a href=3D"https://gitlab.com/gnutls/gnut=
ls/-/work_items/1916">view it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target=3D"_blan=
k" rel=3D"noopener noreferrer" href=3D"https://gitlab.com">gitlab.com</a>=
. <a href=3D"https://gitlab.com/-/namespace/17175643/sent_notifications/5=
-ed0vakpmjgqlq8n9ew4skobyw-a84t7/unsubscribe" target=3D"_blank" rel=3D"no=
opener noreferrer">Unsubscribe</a> from this thread =C2=B7 <a href=3D"htt=
ps://gitlab.com/-/profile/notifications" target=3D"_blank" rel=3D"noopene=
r noreferrer" class=3D"mng-notif-link">Manage all notifications</a> =C2=B7=
<a href=3D"https://gitlab.com/help" target=3D"_blank" rel=3D"noopener no=
referrer" class=3D"help-link">Help</a>
<span style=3D"color: transparent; font-size: 0; display: none; overflow:=
hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://gitlab.com/gnutls/gnutls/-/work_it=
ems/1916 at 1784198086
</span>
<script type=3D"application/ld+json">{"@context":"http://schema.org","@ty=
pe":"EmailMessage","action":{"@type":"ViewAction","name":"View Work item"=
,"url":"https://gitlab.com/gnutls/gnutls/-/work_items/1916"}}</script>
</p>
</div>
</body>
</html>
----==_mimepart_6a58b3c63f867_3719cf0865232--
--===============6477227137071193395==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Gnutls-devel mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnutls-devel
--===============6477227137071193395==--