Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 686462 - app-misc/ca-certificates: sectigo certificates not recognized as secure
Summary: app-misc/ca-certificates: sectigo certificates not recognized as secure
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-05-21 09:34 UTC by Agostino Sarubbo
Modified: 2019-05-21 11:40 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2019-05-21 09:34:09 UTC
Today I got an issue regarding a certificate issued by Sectigo (https://sectigo.com)

I don't have issues with chromium, but I'm unable to use tools like curl that uses the system certificates.

If I manually add the following certificate I have no problems:
https://www.tbs-certificates.co.uk/FAQ/en/SectigoRSADomainValidationSecureServerCA.html

Please consider if it should be installed.
Thanks
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2019-05-21 09:54:26 UTC
1) We never add any certificates on our own. We use whatever Mozilla is shipping (through Debian). So you would have to ask Mozilla...

BUT... I don't think there's a missing certificate:

1) Which app-misc/ca-certificates version are you using?

2) Tell us how you built curl (GnuTLS and OpenSSL for example can pick different certificate paths).

3) Logs! It's still possible that you connect to a different endpoint then I do and that your endpoint is just miss-configured while my endoint works. At least we will need the certificate including chain send by server to you...

That said, I cannot reproduce your report with current ca-certificates-20190110.3.43 in ~arch.
Comment 2 Agostino Sarubbo gentoo-dev 2019-05-21 11:40:35 UTC
There was a missing intermediate certificate. Sorry for the spam