Re: TLS Certificates

Adam Sjøgren <[email protected]>
Newsgroups gmane.discuss
Organization koldfront - analysis & revolution, Copenhagen, Denmark
Message-ID <[email protected]>
Lars writes:

> The certificate has now been installed and seems to work for me, even if
> Emacs doesn't seem to like Let's Encrypt certificates?  Or something?

The smtp one gnutls-cli likes:

  asjo@tullinup:~$ gnutls-cli --starttls-proto=smtp news.gmane.org
  Processed 134 CA certificate(s).
  Resolving 'news.gmane.org:smtp'...
  Connecting to '195.159.176.226:25'...
  - Certificate type: X.509
  - Got a certificate list of 2 certificates.
  - Certificate[0] info:
   - subject `CN=gwene.org', issuer `CN=Let's Encrypt Authority X3,O=Let's Encrypt,C=US', serial 0x042183a447b1ef540f11f18b884a67f127a6, RSA key 2048 bits, signed using RSA-SHA256, activated `2019-01-21 16:25:12 UTC', expires `2019-04-21 16:25:12 UTC', pin-sha256="yxWE6Lv4ZiaTVIqXQDrcgkYFtbnZFDxil4dfsDq0s/w="
          Public Key ID:
                  sha1:8fc60facedca707e6847386ebb076f468d31df0e
                  sha256:cb1584e8bbf8662693548a97403adc824605b5b9d9143c6297875fb03ab4b3fc
          Public Key PIN:
                  pin-sha256:yxWE6Lv4ZiaTVIqXQDrcgkYFtbnZFDxil4dfsDq0s/w=

  - Certificate[1] info:
   - subject `CN=Let's Encrypt Authority X3,O=Let's Encrypt,C=US', issuer `CN=DST Root CA X3,O=Digital Signature Trust Co.', serial 0x0a0141420000015385736a0b85eca708, RSA key 2048 bits, signed using RSA-SHA256, activated `2016-03-17 16:40:46 UTC', expires `2021-03-17 16:40:46 UTC', pin-sha256="YLh1dUR9y6Kja30RrAn7JKnbQG/uEtLMkBgFF2Fuihg="
  - Status: The certificate is trusted. 
  - Description: (TLS1.2)-(ECDHE-SECP256R1)-(RSA-SHA256)-(AES-256-GCM)
  - Session ID: AF:D6:A8:DF:F8:95:D4:1A:E0:8A:1A:E1:39:1C:AD:DC:FA:37:0B:8F:8C:74:9E:EA:9D:1A:BA:EF:A4:36:44:7F
  - Options: extended master secret, safe renegotiation,
  - Handshake was completed

But for nntp:

  asjo@tullinup:~$ host news.gmane.org
  news.gmane.org is an alias for blaine.gmane.org.
  blaine.gmane.org has address 195.159.176.226
  blaine.gmane.org mail is handled by 5 blaine.gmane.org.
  asjo@tullinup:~$ gnutls-cli --starttls-proto=nntp news.gmane.org
  Processed 134 CA certificate(s).
  Resolving 'news.gmane.org:nntp'...
  Connecting to '195.159.176.226:119'...
  - Certificate type: X.509
  - Got a certificate list of 1 certificates.
  - Certificate[0] info:
   - subject `CN=gwene.org', issuer `CN=Let's Encrypt Authority X3,O=Let's Encrypt,C=US', serial 0x042183a447b1ef540f11f18b884a67f127a6, RSA key 2048 bits, signed using RSA-SHA256, activated `2019-01-21 16:25:12 UTC', expires `2019-04-21 16:25:12 UTC', pin-sha256="yxWE6Lv4ZiaTVIqXQDrcgkYFtbnZFDxil4dfsDq0s/w="
          Public Key ID:
                  sha1:8fc60facedca707e6847386ebb076f468d31df0e
                  sha256:cb1584e8bbf8662693548a97403adc824605b5b9d9143c6297875fb03ab4b3fc
          Public Key PIN:
                  pin-sha256:yxWE6Lv4ZiaTVIqXQDrcgkYFtbnZFDxil4dfsDq0s/w=

  - Status: The certificate is NOT trusted. The certificate issuer is unknown. 
  *** PKI verification of server certificate failed...
  *** Fatal error: Error in the certificate.

It says it got a list of 2 certificates on smtp, but only 1 on nntp.
Perhaps that's the difference?


  Best regards,

    Adam

-- 
 "Personligt har jeg håndrullet fyrreogtyve kongelige         Adam Sjøgren
  joints, som jeg har planlagt at ryge inden jeg har     [email protected]
  spist min første reje-coctail."
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.