Re: Make certificate verification great again

Alexander Lukyanov <[email protected]> Mon, 20 Mar 2017 21:21:38 +0000
Newsgroups gmane.network.lftp.user
Message-ID <CANnoEwoJmEHSscg7y=DrPYXSM_iHeQthNJw9fSqrKkHPnh4CQA@mail.gmail.com>
--===============6567184339200252267==
Content-Type: multipart/alternative; boundary=001a113e257c7f9229054b301db9

--001a113e257c7f9229054b301db9
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Does the "Not trusted" error happen just after connecting or when doing the
data connection? Can you provide at least the server name?

=D0=BF=D0=BD, 20 =D0=BC=D0=B0=D1=80. 2017 =D0=B3. =D0=B2 16:55, Nathana=C3=
=ABl Naeri <[email protected]>:

> It appears that "open -d https://www.seedbox.fr" works indeed
> ("Trusted", certificate chain printed out as in your previous
> message), but "open -d -p 21 -u USER,PASS SERVER.seedbox.fr" doesn't
> ("Certificate verification: Not trusted", same output as reported in
> my first message).
>
> Using lftp 4.7.7 with GnuTLS 3.5.10 and my CA bundle. I also checked
> manually that both your CA bundle and mine:
>   * don't include COMODORSAOrganizationValidationSecureServerCA.pem
>   * include COMODORSACertificationAuthority.pem
>   * don't include COMODORSAAddTrustCA.pem
> So they're not different in this respect. It's not clear to me, which
> one is the root CA certificate. Only the AddTrust one is self-signed,
> but the certificate chain printed by lftp with GnuTLS stops at the
> second one, while that using OpenSSL includes the last one.
>
> The server certificates coming from the HTTP and FTP servers are the
> same: I downloaded one from https://www.seedbox.fr using Firefox 52 >
> Page Info and the other from SERVER.seedbox.fr using "openssl s_client
> -connect SERVER.seedbox.fr:21 -starttls ftp": they're the same except
> for the end-of-line characters, and apply both to *.seedbox.fr.
>
> Is that an issue that this hosting company could do something about? I
> can ask their sysadmins for help.
>
> On Mon, Mar 20, 2017 at 12:52 PM, Alexander V. Lukyanov <[email protected]>
> wrote:
> > On Sat, Mar 18, 2017 at 09:13:27PM +0100, Nathana=C3=ABl Naeri wrote:
> >> Thank you for your answer. I have updated my version of GnuTLS to
> >> 3.5.10 and compiled lftp 4.7.7 against it. The resulting "./lftp
> >> --version" shows "Libraries used: Readline 6.3, Expat 2.1.0, GnuTLS
> >> 3.5.10, zlib 1.2.8". Yet the error I reported in my first message
> >> remains: "Certificate verification: Not trusted".
> >>
> >> What commands did you use in your last message to verify certificate
> >> chains? The output I get with openssl verify and certtool is quite
> >> different.
> >
> > I did "open -d https://www.seedbox.fr". My CA bundle is attached.
> >
> > --
> >    Alexander.
> _______________________________________________
> lftp mailing list
> [email protected]
> http://univ.uniyar.ac.ru/mailman/listinfo/lftp
>

--001a113e257c7f9229054b301db9
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Does the &quot;Not trusted&quot; error happen just after c=
onnecting or when doing the data connection? Can you provide at least the s=
erver name?</div><br><div class=3D"gmail_quote"><div dir=3D"ltr">=D0=BF=D0=
=BD, 20 =D0=BC=D0=B0=D1=80. 2017 =D0=B3. =D0=B2 16:55, Nathana=C3=ABl Naeri=
 &lt;<a href=3D"mailto:[email protected]">[email protected]=
</a>&gt;:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 =
.8ex;border-left:1px #ccc solid;padding-left:1ex">It appears that &quot;ope=
n -d <a href=3D"https://www.seedbox.fr" rel=3D"noreferrer" class=3D"gmail_m=
sg" target=3D"_blank">https://www.seedbox.fr</a>&quot; works indeed<br clas=
s=3D"gmail_msg">
(&quot;Trusted&quot;, certificate chain printed out as in your previous<br =
class=3D"gmail_msg">
message), but &quot;open -d -p 21 -u USER,PASS <a href=3D"http://SERVER.see=
dbox.fr" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">SERVER.se=
edbox.fr</a>&quot; doesn&#39;t<br class=3D"gmail_msg">
(&quot;Certificate verification: Not trusted&quot;, same output as reported=
 in<br class=3D"gmail_msg">
my first message).<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Using lftp 4.7.7 with GnuTLS 3.5.10 and my CA bundle. I also checked<br cla=
ss=3D"gmail_msg">
manually that both your CA bundle and mine:<br class=3D"gmail_msg">
=C2=A0 * don&#39;t include COMODORSAOrganizationValidationSecureServerCA.pe=
m<br class=3D"gmail_msg">
=C2=A0 * include COMODORSACertificationAuthority.pem<br class=3D"gmail_msg"=
>
=C2=A0 * don&#39;t include COMODORSAAddTrustCA.pem<br class=3D"gmail_msg">
So they&#39;re not different in this respect. It&#39;s not clear to me, whi=
ch<br class=3D"gmail_msg">
one is the root CA certificate. Only the AddTrust one is self-signed,<br cl=
ass=3D"gmail_msg">
but the certificate chain printed by lftp with GnuTLS stops at the<br class=
=3D"gmail_msg">
second one, while that using OpenSSL includes the last one.<br class=3D"gma=
il_msg">
<br class=3D"gmail_msg">
The server certificates coming from the HTTP and FTP servers are the<br cla=
ss=3D"gmail_msg">
same: I downloaded one from <a href=3D"https://www.seedbox.fr" rel=3D"noref=
errer" class=3D"gmail_msg" target=3D"_blank">https://www.seedbox.fr</a> usi=
ng Firefox 52 &gt;<br class=3D"gmail_msg">
Page Info and the other from <a href=3D"http://SERVER.seedbox.fr" rel=3D"no=
referrer" class=3D"gmail_msg" target=3D"_blank">SERVER.seedbox.fr</a> using=
 &quot;openssl s_client<br class=3D"gmail_msg">
-connect <a href=3D"http://SERVER.seedbox.fr:21" rel=3D"noreferrer" class=
=3D"gmail_msg" target=3D"_blank">SERVER.seedbox.fr:21</a> -starttls ftp&quo=
t;: they&#39;re the same except<br class=3D"gmail_msg">
for the end-of-line characters, and apply both to *.<a href=3D"http://seedb=
ox.fr" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">seedbox.fr<=
/a>.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
Is that an issue that this hosting company could do something about? I<br c=
lass=3D"gmail_msg">
can ask their sysadmins for help.<br class=3D"gmail_msg">
<br class=3D"gmail_msg">
On Mon, Mar 20, 2017 at 12:52 PM, Alexander V. Lukyanov &lt;<a href=3D"mail=
to:[email protected]" class=3D"gmail_msg" target=3D"_blank">[email protected]</a>&gt;=
 wrote:<br class=3D"gmail_msg">
&gt; On Sat, Mar 18, 2017 at 09:13:27PM +0100, Nathana=C3=ABl Naeri wrote:<=
br class=3D"gmail_msg">
&gt;&gt; Thank you for your answer. I have updated my version of GnuTLS to<=
br class=3D"gmail_msg">
&gt;&gt; 3.5.10 and compiled lftp 4.7.7 against it. The resulting &quot;./l=
ftp<br class=3D"gmail_msg">
&gt;&gt; --version&quot; shows &quot;Libraries used: Readline 6.3, Expat 2.=
1.0, GnuTLS<br class=3D"gmail_msg">
&gt;&gt; 3.5.10, zlib 1.2.8&quot;. Yet the error I reported in my first mes=
sage<br class=3D"gmail_msg">
&gt;&gt; remains: &quot;Certificate verification: Not trusted&quot;.<br cla=
ss=3D"gmail_msg">
&gt;&gt;<br class=3D"gmail_msg">
&gt;&gt; What commands did you use in your last message to verify certifica=
te<br class=3D"gmail_msg">
&gt;&gt; chains? The output I get with openssl verify and certtool is quite=
<br class=3D"gmail_msg">
&gt;&gt; different.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; I did &quot;open -d <a href=3D"https://www.seedbox.fr" rel=3D"noreferr=
er" class=3D"gmail_msg" target=3D"_blank">https://www.seedbox.fr</a>&quot;.=
 My CA bundle is attached.<br class=3D"gmail_msg">
&gt;<br class=3D"gmail_msg">
&gt; --<br class=3D"gmail_msg">
&gt;=C2=A0 =C2=A0 Alexander.<br class=3D"gmail_msg">
_______________________________________________<br class=3D"gmail_msg">
lftp mailing list<br class=3D"gmail_msg">
<a href=3D"mailto:[email protected]" class=3D"gmail_msg" target=3D"_blank">=
[email protected]</a><br class=3D"gmail_msg">
<a href=3D"http://univ.uniyar.ac.ru/mailman/listinfo/lftp" rel=3D"noreferre=
r" class=3D"gmail_msg" target=3D"_blank">http://univ.uniyar.ac.ru/mailman/l=
istinfo/lftp</a><br class=3D"gmail_msg">
</blockquote></div>

--001a113e257c7f9229054b301db9--

--===============6567184339200252267==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lftp mailing list
[email protected]
http://univ.uniyar.ac.ru/mailman/listinfo/lftp

--===============6567184339200252267==--