Re: invisible-mirror.net uses untrusted certificate

Thomas Dickey <[email protected]>
Newsgroups gmane.comp.web.lynx.devel
Message-ID <[email protected]>
On Sun, Oct 03, 2021 at 02:45:29PM +0200, Andreas Metzler wrote:
> Hello,
> 
> looks like invisible-mirror.net stumbled over the recent letsencrypt
> change
> <https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/>

yes... I read about it, but didn't know it would bite me.

I just installed a new certificate (which presumably because it's signed
by a new R3...) works.  That doesn't agree with this comment:

https://community.letsencrypt.org/t/help-thread-for-dst-root-ca-x3-expiration-september-2021/149190

	"Most problems related to DST Root CA X3 expiring will not be solved by
	force renewal."

> it sends a chain signed by the expired R3 cert:
> ametzler@argenau:/tmp/EXIM4$ gnutls-cli invisible-mirror.net
> Processed 127 CA certificate(s).
> Resolving 'invisible-mirror.net:443'...
> Connecting to '160.153.42.69:443'...
> - Certificate type: X.509
> - Got a certificate list of 2 certificates.
> - Certificate[0] info:
>  - subject `CN=invisible-mirror.net', issuer `CN=R3,O=Let's Encrypt,C=US', serial 0x0361c3003e1413e8655113f8907eeb16e4b4, RSA key 2048 bits, signed using RSA-SHA256, activated `2021-08-01 17:19:48 UTC', expires `2021-10-30 17:19:46 UTC', pin-sha256="LnOGaFwh9ztb+ce0tQdEB/Gx3A0dBPJjYzDn+Sdu+8A="
>         Public Key ID:
>                 sha1:1b7234964165216ed84d88ad8d5f8c836fc01f72
>                 sha256:2e7386685c21f73b5bf9c7b4b5074407f1b1dc0d1d04f2636330e7f9276efbc0
>         Public Key PIN:
>                 pin-sha256:LnOGaFwh9ztb+ce0tQdEB/Gx3A0dBPJjYzDn+Sdu+8A=
> 
> - Certificate[1] info:
>  - subject `CN=R3,O=Let's Encrypt,C=US', issuer `CN=DST Root CA X3,O=Digital Signature Trust Co.', serial 0x400175048314a4c8218c84a90c16cddf, RSA key 2048 bits, signed using RSA-SHA256, activated `2020-10-07 19:21:40 UTC', expires `2021-09-29 19:21:40 UTC', pin-sha256="jQJTbIh0grw0/1TkHSumWb+Fs0Ggogr621gT3PvPKG0="
> - Status: The certificate is NOT trusted. The certificate chain uses expired certificate.
> *** PKI verification of server certificate failed...
> *** Fatal error: Error in the certificate.
> 
> Net sure why it works in firefox, but it fails with lynx.

perhaps firefox has a bug :-)

-- 
Thomas E. Dickey <[email protected]>
https://invisible-island.net
ftp://ftp.invisible-island.net
signature.asc (application/pgp-signature, 659 B)
-----BEGIN PGP SIGNATURE-----

iQGzBAABCgAdFiEEGYgtkt2kxADCLA1WzCr0RyFnvgMFAmFZxZwACgkQzCr0RyFn
vgOOKQwAyQIsdMyAya9wi4HpH43UrL6tkqRhulrWxY0CA0lWBxznFUYabQR/0cQf
6tzR2x67A5u51yqQG+pLn7NhKVQr+jMP1+cbVbjEU6AhDa03gTpZteRbw8+Lfuv2
1RKcD7UT7rATf0GrBV4rpJ8b4M19qthx1m6QzoYw/c04JxxvvnoPiPnGUyArDvM5
c7OiokdF2I+gghy+nrmBgQ5rzZH9OXGHf7AlPxrpYW7+Rk2Bwm6+m7AZsaDPO+1i
Kv/GdMgdGNAysKNA4ejjs8g9jLBggKxCfCnzsKGSeJsbsHyYyU4GZQII+nrp7C2R
nkZ9CH2NdEqP3sgppm693q2bJozr9VxI+WGZK4osfslErYjRH16RCibMO5HJcce9
5ml9QOYfbmW4LUAtclGjgB2HMsZr5vbKQjTT27uOX6Tf5kcsLtm8mzbWgdGhhdBB
sQzCdfKAd5PSOg+ZdhYuvkgyzoN0JPL4po4c1TgYqFPeort5AoK42aLKjjMCcyiu
WI3OfQDv
=7hxs
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.