LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Linux From Scratch
User Name
Password
Linux From Scratch This Forum is for the discussion of LFS.
LFS is a project that provides you with the steps necessary to build your own custom Linux system.

Notices


Reply
  Search this Thread
Old 01-27-2021, 02:30 PM   #1
dptzippy
LQ Newbie
 
Registered: Dec 2020
Posts: 28

Rep: Reputation: Disabled
System cannot verify certificates from any HTTPS connections


As the title says, my system fails to verify security certificates for secured connections. This can be worked around, using a configuration file (for cURL), and "--no-check-connection" (for wget), but I can't always work around this issue, and until I get this fixed, I cannot install a web browser, I cannot use chat programs, installers/packages fail if they need to connect to the Internet, and I am really frustrated.

I have recompiled and reinstalled GnuTLS, cURL, OpenSSL, NSS, make-ca, but it still won't work. I use the default directories, as per BLFS, but I can't seem to get my connection to work. Does anybody know how to fix this? This problem affects the console, as well as GUI applications.


Thanks for the help!
- dptzippy
 
Old 01-27-2021, 03:00 PM   #2
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
Typically this means the root certificates from the sites you are trying to connect to, are not installed. Normally these are installed in modern distros but I know nothing about how this works in LFS.
 
1 members found this post helpful.
Old 01-27-2021, 06:11 PM   #3
dptzippy
LQ Newbie
 
Registered: Dec 2020
Posts: 28

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by sevendogsbsd View Post
Typically this means the root certificates from the sites you are trying to connect to, are not installed. Normally these are installed in modern distros but I know nothing about how this works in LFS.
Thank you for your reply. Would you happen to know of a place where I could download some kind of package, to install certificates?
 
Old 01-27-2021, 07:57 PM   #4
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
Normally these are installed with the OS, but you built the OS, that being blfs so I am not sure in that case. Do the docs say anything about root certificates? It is essentially a package with dozens of root certificates from various vendors and countries.

Sorry I am not being any more helpful than that but I have not ever built an LFS system.
 
Old 01-28-2021, 11:21 AM   #5
spiky0011
Senior Member
 
Registered: Jan 2011
Location: PLANET-SPIKE
Distribution: /LFS/Debian
Posts: 2,511
Blog Entries: 1

Rep: Reputation: 412Reputation: 412Reputation: 412Reputation: 412Reputation: 412
Try here
http://www.linuxfromscratch.org/blfs...s/make-ca.html
 
1 members found this post helpful.
Old 01-28-2021, 01:04 PM   #6
bryan_S
Member
 
Registered: Aug 2014
Location: N. Florida
Distribution: Linux-from-Scratch
Posts: 108

Rep: Reputation: Disabled
And, as is shown on that page: "make-ca -g" should do it. I manually download certdata.txt and run "make-ca" in the same directory - that also works.
 
Old 01-28-2021, 08:27 PM   #7
dptzippy
LQ Newbie
 
Registered: Dec 2020
Posts: 28

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by bryan_S View Post
And, as is shown on that page: "make-ca -g" should do it. I manually download certdata.txt and run "make-ca" in the same directory - that also works.
Okay, I tried reinstalling those packages, and rerunning the commands. Every single certificate issues a "Could not open certificate"/"Unable to read certificate" message, and nothing is fixed. What am I doing incorrectly?
 
Old 01-28-2021, 08:43 PM   #8
dptzippy
LQ Newbie
 
Registered: Dec 2020
Posts: 28

Original Poster
Rep: Reputation: Disabled
I just noticed that the output mentions an error in the script.

/usr/sbin/make-ca: line 650: 21776 Broken pipe printf $(awk '/^CKA_VALUE/{flag=1;next}/^END/{flag=0}flag{printf $0}' "${tempfile}")
21777 Segmentation fault | "${OPENSSL}" x509 -text -inform DER -fingerprint > tempfile.crt
Could not read certificate from tempfile.crt
Unable to load certificate
Could not read certificate from tempfile.crt
Unable to load certificate
Could not read certificate from tempfile.crt
Unable to load certificate
Could not read certificate from tempfile.crt
Unable to load certificate
Certificate: Trustis FPS Root CA
Keyhash:
Added to p11-kit anchor directory with trust 'C,C,'.
 
Old 05-01-2021, 05:30 PM   #9
themightydill
LQ Newbie
 
Registered: Apr 2021
Location: Edmonton, AB
Distribution: Arch and derivatives, Debian, Fedora, LFS 10.1
Posts: 20

Rep: Reputation: 10
delete post

Last edited by themightydill; 05-01-2021 at 07:39 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Help! LinuxMint: GoogleChrome: HTTPS: Self-signed certificates haertig Linux - Software 9 03-15-2017 01:54 AM
[SOLVED] Warnings about untrusted certificates while compiling ca-certificates Lennie Linux - Security 4 03-14-2013 02:31 AM
Apache, https & certificates per directory jonaskellens Linux - Newbie 5 11-25-2010 11:52 AM
openssl ssl error code 14090086 verify the CA cert is ok / certificate verify failed acummings Slackware 14 02-27-2009 01:51 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Linux From Scratch

All times are GMT -5. The time now is 10:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration