Message boards :
Number crunching :
Peer certificate cannot be authenticated with given CA certificates
Message board moderation
Previous · 1 · 2 · 3 · 4 · 5 · Next
Author | Message |
---|---|
Send message Joined: 1 May 07 Posts: 25 Credit: 2,107,498 RAC: 1,261 ![]() ![]() ![]() |
I can confirm that Linux (fedora 30) is working fine with no certificate issues. So far anyway on LHC & Rosetta |
Send message Joined: 17 Oct 06 Posts: 72 Credit: 42,404,784 RAC: 27,605 ![]() ![]() ![]() |
Add NumberFields@home as another project affected. I can see the images just fine however I am getting a big not secure icon in the top left of chrome. ![]() |
Send message Joined: 15 Nov 14 Posts: 602 Credit: 24,371,321 RAC: 0 ![]() ![]() |
I can confirm that Linux (fedora 30) is working fine with no certificate issues. So far anyway on LHC & Rosetta Yes, I am OK too uploading to Rosetta with Ubuntu 18.04.4. It is only my Windows 7 64-bit machine that is still stuck. |
Send message Joined: 27 Sep 08 Posts: 750 Credit: 570,528,951 RAC: 97,268 ![]() ![]() ![]() |
but the web link is http so by definition it wouldn't be secure :) if you link to https then it's all good. There is an expired cert that walli reports so it so a new build of BOINC needs to be made with updated certs. I made my own updated cert and it's working fine now it would appear. |
Send message Joined: 12 Aug 06 Posts: 337 Credit: 3,889,866 RAC: 23,476 ![]() ![]() ![]() |
but the web link is http so by definition it wouldn't be secure :) It needs to be rebuilt? Can't we just all get a new certificate file? I guess a new build would come out as an autoupdate to those who don't know about this? ![]() |
Send message Joined: 7 Apr 20 Posts: 2 Credit: 707,402 RAC: 0 ![]() ![]() |
No problems for me with Ubuntu running on a Raspberry Pi but Rosetta and LHC are both giving me certificate errors on Windows 10. I've even tried copying Linux's ca-certificates.crt and using it in the place of Window's ca-bundle.crt but it still errored. Not sure why Windows is erroring with the same certificates, but Linux isn't. |
Send message Joined: 18 Dec 15 Posts: 1571 Credit: 66,280,956 RAC: 163,052 ![]() ![]() ![]() |
There is an expired cert that walli reports so it so a new build of BOINC needs to be made with updated certs.Why, though, do other projects within BOINC work without problems, like GPUGRID and WCG ? |
Send message Joined: 27 Sep 08 Posts: 750 Credit: 570,528,951 RAC: 97,268 ![]() ![]() ![]() |
I guess that OK for some techy people, but not for average person. You can do what I did based on the discussion at the main boinc website. |
Send message Joined: 7 Apr 20 Posts: 2 Credit: 707,402 RAC: 0 ![]() ![]() |
This workaround on the Rosetta forum has fixed my Windows problems: https://boinc.bakerlab.org/rosetta/forum_thread.php?id=14006&postid=96882 |
Send message Joined: 27 Sep 08 Posts: 750 Credit: 570,528,951 RAC: 97,268 ![]() ![]() ![]() |
They don't use https, so they aren't effected. |
Send message Joined: 27 Sep 08 Posts: 750 Credit: 570,528,951 RAC: 97,268 ![]() ![]() ![]() |
I can only assume that windows is more strict with applying the times from certs? Although I find that hard to believe. I can imagine at 00:00 the Linux host will also fail over? |
Send message Joined: 12 Aug 06 Posts: 337 Credit: 3,889,866 RAC: 23,476 ![]() ![]() ![]() |
They don't use https, so they aren't effected. Universe does, but that continued to work. ![]() |
Send message Joined: 1 May 07 Posts: 25 Credit: 2,107,498 RAC: 1,261 ![]() ![]() ![]() |
Seems to be fixed with the workaround on https://boinc.bakerlab.org/rosetta/forum_thread.php?id=14006&postid=96882 LHC & Rosetta both seem to work. Other projects still work. |
Send message Joined: 17 Oct 06 Posts: 72 Credit: 42,404,784 RAC: 27,605 ![]() ![]() ![]() |
Seems to be fixed with the workaround on Can confirm that this works as well. Hopefully the BOINC team will be able to get a new build out with the new certs as well before everything breaks. |
Send message Joined: 12 Aug 06 Posts: 337 Credit: 3,889,866 RAC: 23,476 ![]() ![]() ![]() |
Seems to be fixed with the workaround on Does Boinc autoupdate? Otherwise 90% of users won't know what's wrong. ![]() |
![]() Send message Joined: 15 Jun 08 Posts: 2176 Credit: 185,045,681 RAC: 187,014 ![]() ![]() ![]() |
According to Sectigo's knowledge base (https://support.sectigo.com/Com_KnowledgeDetailPage?Id=kA03l00000117LT) there shouldn't be an issue if one of the following CA certs is available: USERTrust RSA Certification Authority: https://crt.sh/?id=1199354 COMODO RSA Certification Authority: https://crt.sh/?id=1720081 Both certs have been issued 2010 and are already included in BOINC's ca-bundle.crt from 2018: https://github.com/BOINC/boinc/blob/master/curl/ca-bundle.crt Since BOINC uses curl to send out HTTP requests and curl needs access to the cerificate list it should be checked if for some reason there are remains from older installations (BOINC/curl) that point to outdated certificate lists. |
Send message Joined: 18 Dec 15 Posts: 1571 Credit: 66,280,956 RAC: 163,052 ![]() ![]() ![]() |
Does Boinc autoupdate? Otherwise 90% of users won't know what's wrong.I don't think that BOINC updates automatically. Once a new version is published, everyone will have to install it manually. At least that's what I guess. And yes, most of the users won't know what's wrong all of a sudden, unless they start digging into all the forum postings at LHC and/or Rosetta :-( |
Send message Joined: 12 Aug 06 Posts: 337 Credit: 3,889,866 RAC: 23,476 ![]() ![]() ![]() |
Does Boinc autoupdate? Otherwise 90% of users won't know what's wrong.I don't think that BOINC updates automatically. Once a new version is published, everyone will have to install it manually. At least that's what I guess. If there's no autoupdate, I think this warrants an email to everyone from the affected projects (presumably a vast number of people have consented to emails from them in preferences). People may not see a notice within Boinc. A lot of folk not knowing what's happened may assume the projects are down and go to different ones. ![]() |
Send message Joined: 17 Oct 06 Posts: 72 Credit: 42,404,784 RAC: 27,605 ![]() ![]() ![]() |
Alot of people are about to find out about this the hard way turns out alot of people were using this cert provider. https://twitter.com/sleevi_/status/1266647545675210753 |
Send message Joined: 12 Aug 06 Posts: 337 Credit: 3,889,866 RAC: 23,476 ![]() ![]() ![]() |
I don't actually recall the internet being any unsafer before everyone started this SSL stuff. ![]() |
©2023 CERN