Re: Invalid certificate error

Hunter Matthews <[email protected]>
Newsgroups gmane.network.up2date.current.devel
Message-ID <1006967870.10960.6.camel@jade>
I just re-read the documentation, and will clear it up in the next
snapshot. 


Its still a self signed certificate, BUT did you put a new RHNS-CA-CERT 
file in /usr/share/rhn? 

THe instructions in the 3rd paragraph cover how to generate this file.
Basically, it is the public part of the .pem file you already have, plus
(optionally) the text representation of the public part of the pem file.

Although the fact that you get an error from stunnel is suspect.

How did you generate the pem file that you are feeding to stunnel?



On Wed, 2001-11-28 at 04:43, Jonathan Byrne wrote:
> I just installed current-20011126 and made a self-signed
> certificate as outlined in docs/encryption.txt.
> 
> In that document it is stated about 2.7 clients that
> "I _think_ for them we'll need a true CA cert and signed cert."
> 
> I'm running Red Hat 7.2 with up2date-2.7.2-7.x.6 and
> get an invalid client certificate error when I run
> up2date aimed at my machine.
> 
> I have tried both the self-signed cert alone, and 
> catting it together with the Red Hat cert as 
> mentioned in encryption.txt, and both get this
> error. 
> 
> Has anyone gotten around this, or is it that case that
> a real certificate is in fact required?  If so, I'll look at
> downgrading to a 2.5 client and see how that goes.
> 
> Typical output:
> 
> From stunnel: 
> 
> Nov 28 18:38:39 yamame stunnel[16370]: 8000 connected from 203.216.0.50:45013
> Nov 28 18:38:39 yamame stunnel[16370]: SSL_accept: error:14094418:SSL routines:SSL3_READ_BYTES:tlsv1 alert unknown ca
> 
> From current:
> 
> client_address ('127.0.0.1', 44983)
> command POST
> path https://yamame.gol.ad.jp/XMLRPC
> headers Host: yamame.gol.ad.jp
> User-Agent: xmlrpclib.py/$Revision: 1.41 $
> Content-Type: text/xml
> X-Client-Version: 1
> Content-Length: 2103
> X-Info: XML-RPC Processor (C) Red Hat, Inc ($Revision: 1.30 $)
> 
> TIA,
> 
> Jonathan
> 
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server
> 
> 
-- 
Hunter Matthews                          Unix / Network Administrator
Office: BioScience 145/244               Duke Univ. Biology Department
Key: F0F88438 / FFB5 34C0 B350 99A4 BB02  9779 A5DB 8B09 F0F8 8438
Never take candy from strangers. Especially on the internet.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.