Re: certificated validation

Szépe Viktor <[email protected]>
Newsgroups gmane.network.lftp.user
Message-ID <[email protected]>
Your software is very tricky. After --with-ssl=yes openssl is not  
denoted (in the bottom line) but doing some TLS operation!

After set ssl:ca-path /etc/ssl/certs/ OR set ssl:ca-file  
/etc/ssl/certs/ca-certificates.crt
lftp says:
<--- 234 AUTH TLS successful
---> OPTS MLST modify;perm;size;type;UNIX.group;UNIX.mode;UNIX.owner;
Certificate depth: 0; subject: /OU=Domain Control  
Validated/OU=PositiveSSL/CN=s1.tarhelydiktator.eu; issuer:  
/C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA  
Limited/CN=PositiveSSL CA 2
ERROR: Certificate verification: unable to get local issuer certificate
**** SSL_connect: unable to get local issuer certificate

Could you test it and fix it? An example hostname is s1.tarhelydiktator.eu
With set ftp:ssl-force yes  you won't reach the password prompt.

Thank you!


# /home/viktor/src/lftp-4.5.2/src/lftp --version
LFTP | Version 4.5.2 | Copyright (c) 1996-2014 Alexander V. Lukyanov

LFTP is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.

This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
GNU General Public License for more details.

You should have received a copy of the GNU General Public License
along with LFTP.  If not, see <http://www.gnu.org/licenses/>.

Send bug reports and questions to the mailing list <[email protected]>.

Libraries used: Readline 6.2, Expat 2.1.0, zlib 1.2.7







Idézem/Quoting "Alexander V. Lukyanov" <[email protected]>:

> On Wed, Jun 11, 2014 at 01:55:23AM +0200, Szépe Viktor wrote:
>> Could you help me how to solve to "Not trusted: no issuer was found" error?
>> Maybe lftp cannot parse ca-certificates.crt? (Debian wheezy)
>> 4.5.1 does the same.
>> Also with fresh ca bundle
>> https://github.com/bagder/ca-bundle/blob/master/ca-bundle.crt
>>
>> You can try running  lftp eu1.solid-hosting.net  yourself without a  
>> password.
>>
>> Thank you!
>>
>>
>> openssl says it is OK
>
> You can try to compile lftp with openssl (configure --with-openssl)  
> and see if it helps.
>
> --
>    Alexander.


Szépe Viktor
-- 
+36-20-4242498  [email protected]  skype: szepe.viktor
Budapest, XX. kerület





_______________________________________________
lftp mailing list
[email protected]
http://univ.uniyar.ac.ru/mailman/listinfo/lftp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.