Re: TLS Certificates

Lars Ingebrigtsen <[email protected]>
Newsgroups gmane.discuss
Message-ID <[email protected]>
Adam Sjøgren <[email protected]> writes:

> But for nntp:
>
>   asjo@tullinup:~$ host news.gmane.org

[...]

>   - Certificate[0] info:
>    - subject `CN=gwene.org', issuer `CN=Let's Encrypt Authority X3,O=Let's Encrypt,C=US', serial 0x042183a447b1ef540f11f18b884a67f127a6, RSA key 2048 bits, signed using RSA-SHA256, activated `2019-01-21 16:25:12 UTC', expires `2019-04-21 16:25:12 UTC', pin-sha256="yxWE6Lv4ZiaTVIqXQDrcgkYFtbnZFDxil4dfsDq0s/w="

First of all, the CN=gwene.org is wrong...  I've now fixed that by
making a separate certificate for news.gmane.org.  (innd doesn't like
Subject Alternative Names in certificates, apparently.)

> It says it got a list of 2 certificates on smtp, but only 1 on nntp.
> Perhaps that's the difference?

And, yes, that has to be the other problem, because I'm still getting
warnings.  Perhaps innd wants the intermediate certificate in its own
file?  Hm...

-- 
(domestic pets only, the antidote for overdose, milk.)
   bloggy blog: http://lars.ingebrigtsen.no
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.