Re: Make certificate verification great again
Alexander Lukyanov <[email protected]> Mon, 20 Mar 2017 21:21:38 +0000
| Newsgroups | gmane.network.lftp.user |
|---|---|
| Message-ID | <CANnoEwoJmEHSscg7y=DrPYXSM_iHeQthNJw9fSqrKkHPnh4CQA@mail.gmail.com> |
--===============6567184339200252267== Content-Type: multipart/alternative; boundary=001a113e257c7f9229054b301db9 --001a113e257c7f9229054b301db9 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Does the "Not trusted" error happen just after connecting or when doing the data connection? Can you provide at least the server name? =D0=BF=D0=BD, 20 =D0=BC=D0=B0=D1=80. 2017 =D0=B3. =D0=B2 16:55, Nathana=C3= =ABl Naeri <[email protected]>: > It appears that "open -d https://www.seedbox.fr" works indeed > ("Trusted", certificate chain printed out as in your previous > message), but "open -d -p 21 -u USER,PASS SERVER.seedbox.fr" doesn't > ("Certificate verification: Not trusted", same output as reported in > my first message). > > Using lftp 4.7.7 with GnuTLS 3.5.10 and my CA bundle. I also checked > manually that both your CA bundle and mine: > * don't include COMODORSAOrganizationValidationSecureServerCA.pem > * include COMODORSACertificationAuthority.pem > * don't include COMODORSAAddTrustCA.pem > So they're not different in this respect. It's not clear to me, which > one is the root CA certificate. Only the AddTrust one is self-signed, > but the certificate chain printed by lftp with GnuTLS stops at the > second one, while that using OpenSSL includes the last one. > > The server certificates coming from the HTTP and FTP servers are the > same: I downloaded one from https://www.seedbox.fr using Firefox 52 > > Page Info and the other from SERVER.seedbox.fr using "openssl s_client > -connect SERVER.seedbox.fr:21 -starttls ftp": they're the same except > for the end-of-line characters, and apply both to *.seedbox.fr. > > Is that an issue that this hosting company could do something about? I > can ask their sysadmins for help. > > On Mon, Mar 20, 2017 at 12:52 PM, Alexander V. Lukyanov <[email protected]> > wrote: > > On Sat, Mar 18, 2017 at 09:13:27PM +0100, Nathana=C3=ABl Naeri wrote: > >> Thank you for your answer. I have updated my version of GnuTLS to > >> 3.5.10 and compiled lftp 4.7.7 against it. The resulting "./lftp > >> --version" shows "Libraries used: Readline 6.3, Expat 2.1.0, GnuTLS > >> 3.5.10, zlib 1.2.8". Yet the error I reported in my first message > >> remains: "Certificate verification: Not trusted". > >> > >> What commands did you use in your last message to verify certificate > >> chains? The output I get with openssl verify and certtool is quite > >> different. > > > > I did "open -d https://www.seedbox.fr". My CA bundle is attached. > > > > -- > > Alexander. > _______________________________________________ > lftp mailing list > [email protected] > http://univ.uniyar.ac.ru/mailman/listinfo/lftp > --001a113e257c7f9229054b301db9 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Does the "Not trusted" error happen just after c= onnecting or when doing the data connection? Can you provide at least the s= erver name?</div><br><div class=3D"gmail_quote"><div dir=3D"ltr">=D0=BF=D0= =BD, 20 =D0=BC=D0=B0=D1=80. 2017 =D0=B3. =D0=B2 16:55, Nathana=C3=ABl Naeri= <<a href=3D"mailto:[email protected]">[email protected]= </a>>:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 = .8ex;border-left:1px #ccc solid;padding-left:1ex">It appears that "ope= n -d <a href=3D"https://www.seedbox.fr" rel=3D"noreferrer" class=3D"gmail_m= sg" target=3D"_blank">https://www.seedbox.fr</a>" works indeed<br clas= s=3D"gmail_msg"> ("Trusted", certificate chain printed out as in your previous<br = class=3D"gmail_msg"> message), but "open -d -p 21 -u USER,PASS <a href=3D"http://SERVER.see= dbox.fr" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">SERVER.se= edbox.fr</a>" doesn't<br class=3D"gmail_msg"> ("Certificate verification: Not trusted", same output as reported= in<br class=3D"gmail_msg"> my first message).<br class=3D"gmail_msg"> <br class=3D"gmail_msg"> Using lftp 4.7.7 with GnuTLS 3.5.10 and my CA bundle. I also checked<br cla= ss=3D"gmail_msg"> manually that both your CA bundle and mine:<br class=3D"gmail_msg"> =C2=A0 * don't include COMODORSAOrganizationValidationSecureServerCA.pe= m<br class=3D"gmail_msg"> =C2=A0 * include COMODORSACertificationAuthority.pem<br class=3D"gmail_msg"= > =C2=A0 * don't include COMODORSAAddTrustCA.pem<br class=3D"gmail_msg"> So they're not different in this respect. It's not clear to me, whi= ch<br class=3D"gmail_msg"> one is the root CA certificate. Only the AddTrust one is self-signed,<br cl= ass=3D"gmail_msg"> but the certificate chain printed by lftp with GnuTLS stops at the<br class= =3D"gmail_msg"> second one, while that using OpenSSL includes the last one.<br class=3D"gma= il_msg"> <br class=3D"gmail_msg"> The server certificates coming from the HTTP and FTP servers are the<br cla= ss=3D"gmail_msg"> same: I downloaded one from <a href=3D"https://www.seedbox.fr" rel=3D"noref= errer" class=3D"gmail_msg" target=3D"_blank">https://www.seedbox.fr</a> usi= ng Firefox 52 ><br class=3D"gmail_msg"> Page Info and the other from <a href=3D"http://SERVER.seedbox.fr" rel=3D"no= referrer" class=3D"gmail_msg" target=3D"_blank">SERVER.seedbox.fr</a> using= "openssl s_client<br class=3D"gmail_msg"> -connect <a href=3D"http://SERVER.seedbox.fr:21" rel=3D"noreferrer" class= =3D"gmail_msg" target=3D"_blank">SERVER.seedbox.fr:21</a> -starttls ftp&quo= t;: they're the same except<br class=3D"gmail_msg"> for the end-of-line characters, and apply both to *.<a href=3D"http://seedb= ox.fr" rel=3D"noreferrer" class=3D"gmail_msg" target=3D"_blank">seedbox.fr<= /a>.<br class=3D"gmail_msg"> <br class=3D"gmail_msg"> Is that an issue that this hosting company could do something about? I<br c= lass=3D"gmail_msg"> can ask their sysadmins for help.<br class=3D"gmail_msg"> <br class=3D"gmail_msg"> On Mon, Mar 20, 2017 at 12:52 PM, Alexander V. Lukyanov <<a href=3D"mail= to:[email protected]" class=3D"gmail_msg" target=3D"_blank">[email protected]</a>>= wrote:<br class=3D"gmail_msg"> > On Sat, Mar 18, 2017 at 09:13:27PM +0100, Nathana=C3=ABl Naeri wrote:<= br class=3D"gmail_msg"> >> Thank you for your answer. I have updated my version of GnuTLS to<= br class=3D"gmail_msg"> >> 3.5.10 and compiled lftp 4.7.7 against it. The resulting "./l= ftp<br class=3D"gmail_msg"> >> --version" shows "Libraries used: Readline 6.3, Expat 2.= 1.0, GnuTLS<br class=3D"gmail_msg"> >> 3.5.10, zlib 1.2.8". Yet the error I reported in my first mes= sage<br class=3D"gmail_msg"> >> remains: "Certificate verification: Not trusted".<br cla= ss=3D"gmail_msg"> >><br class=3D"gmail_msg"> >> What commands did you use in your last message to verify certifica= te<br class=3D"gmail_msg"> >> chains? The output I get with openssl verify and certtool is quite= <br class=3D"gmail_msg"> >> different.<br class=3D"gmail_msg"> ><br class=3D"gmail_msg"> > I did "open -d <a href=3D"https://www.seedbox.fr" rel=3D"noreferr= er" class=3D"gmail_msg" target=3D"_blank">https://www.seedbox.fr</a>".= My CA bundle is attached.<br class=3D"gmail_msg"> ><br class=3D"gmail_msg"> > --<br class=3D"gmail_msg"> >=C2=A0 =C2=A0 Alexander.<br class=3D"gmail_msg"> _______________________________________________<br class=3D"gmail_msg"> lftp mailing list<br class=3D"gmail_msg"> <a href=3D"mailto:[email protected]" class=3D"gmail_msg" target=3D"_blank">= [email protected]</a><br class=3D"gmail_msg"> <a href=3D"http://univ.uniyar.ac.ru/mailman/listinfo/lftp" rel=3D"noreferre= r" class=3D"gmail_msg" target=3D"_blank">http://univ.uniyar.ac.ru/mailman/l= istinfo/lftp</a><br class=3D"gmail_msg"> </blockquote></div> --001a113e257c7f9229054b301db9-- --===============6567184339200252267== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lftp mailing list [email protected] http://univ.uniyar.ac.ru/mailman/listinfo/lftp --===============6567184339200252267==--