Package: cadaver
Version: 0.23.3-2.1+b1
Severity: normal

I'm trying to use cadaver on stable/amd64, the version I've got here
differs from the newest packages both by having a binary non-maintainer
upload for amd64 (giving the "+b1" on my version, i.e. I have that) and
a non-maintainer upload that only fixes building issues (as far as I 
can see - giving the change for "-2.1" to "-2.2" - I don't have that).
In total I don't believe those differences matter for this issue.

When I try to use cadaver, I get this:
dav:!> open https://files.one.com
WARNING: Untrusted server certificate presented for `confluence.one.com':
Issued to: internal-it.one.com
Issued by: Let's Encrypt, US
Certificate is valid from Wed, 27 Apr 2022 15:35:02 GMT to Tue, 26 Jul 2022 
15:35:01 GMT
Do you wish to accept the certificate? (y/n)


When I visit that site in a browser, it doesn't say anything about that
certificate, if I view it I can see it has 11 alternate names, of which
files.one.com is the second. We're witin the validity period that cadaver 
sees and it actually shows the first alternate name in the "Untrusted
server certificate presented"-message, perhaps cadaver (or some library
it uses) doesn't properly support that many alternate names?

This might be the same issue as reported in
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741366
but that bug report doesn't contain any info about the certificate
offered, so it's hard to tell.

.Henrik

-- System Information:
Debian Release: 11.3
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-13-amd64 (SMP w/8 CPU threads)
Kernel taint flags: TAINT_WARN, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE
Locale: LANG=da_DK.UTF-8, LC_CTYPE=da_DK.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages cadaver depends on:
ii  libc6             2.31-13+deb11u3
ii  libgcrypt20       1.8.7-6
ii  libgnutls30       3.7.1-5
ii  libncurses6       6.2+20201114-2
ii  libneon27-gnutls  0.31.2-1
ii  libreadline8      8.1-1
ii  libtinfo6         6.2+20201114-2
ii  libxml2           2.9.10+dfsg-6.7+deb11u2

cadaver recommends no packages.

cadaver suggests no packages.

-- no debconf information

  • Bug#1012810: cadaver: Doesn't recognise SSL cert (p... Henrik Christian Grove

Reply via email to