Re: 2 Problems down... 1 to go...

Hunter Matthews <[email protected]>
Newsgroups gmane.network.up2date.current.devel
Message-ID <1014054801.8762.4.camel@jade>
On Sun, 2002-02-17 at 10:30, Michael H. Warfield wrote:
> Hello again...
> 
> 	The snapshot from the other day definitely seems to have nuked
> the "wrong arguement count" problem.  I would count that problem as shot.

Good to know.

> 	Part of the updates to RedHat 7.2 include an updated up2date
> package.  That package includes /usr/share/rhn/RHNS-CA-CERT.  Since it's
> not considered to be a configuration file, that cert gets overwritten
> unconditionally by the update rpm.  Result is that the configuration
> files point at the "current" server but the CERT file is for RedHat
> once again.  The connection is rejected due to an invalid cert and gets
> reported at an SSL Connect Error.  That error message is BOGUS and should
> report a certificate error, instead, but that's a RedHat bogosity.

Its in the python client ssl library, as far as I can tell.

> 
> 	So, problem #2 is fixed and I have a recommendation.  Please add
> a warning to the documentation about the RHNS-CA-CERT stating that it
> can get overwritten by any update to the up2date rpm.  A backup cert
> should be saved somewhere on the system for the case when this occurs.
> Also add a note that if you see the error "SSL_connect error" that the
> problem may be the server certificate on the client has been overwritten.
> It's certainly not obvious from that error.

The warning will go in the next release, which should be today or
tomorrow (and will be a 1.0 release candidate)

The plan for 1.0.1 or something is to include in the docs directory of
the server the needed spec file, and instructions for people to create
their own up2date client rpm, customized for their site.

 	I'm not sure if that's a bug or part of the spec or what.  It
> needs to be documented, at the very least, if it's not a "fixable" bug.
> Anyone else experiencing the above traceback, should check their
> system clocks and time synchronization.

I believe it to be a bug in the client, and yes, thats a FAQ. The new
question will be in the 1.0.rc1

Thanks


-- 
Hunter Matthews                          Unix / Network Administrator
Office: BioScience 145/244               Duke Univ. Biology Department
Key: F0F88438 / FFB5 34C0 B350 99A4 BB02  9779 A5DB 8B09 F0F8 8438
Never take candy from strangers. Especially on the internet.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.