** Description changed:

  Binary package hint: ca-certificates
  
  Ubuntu 8.10
  Package: ca-certificates 20080514-0ubuntu1.1
  
  As example I will use just one certificate provided by package "ca-
  certificates", but the problem concerns more of them.
  
  Those certificates (pasted a few lines below) differ only in line length, 
content is the same.
  Debian-provided cert has 60-chars lines, and the one downloaded via web has 
64-chars lines, just like RFC 1421 suggests:
  "To represent the encapsulated text of a PEM message, the encoding function's 
output is delimited into text lines (using local conventions), with each line 
except the last containing exactly 64 printable characters and the final line 
containing 64 or fewer printable characters."
  
  
  Command `openssl x509 -in ....crt -text -noout` prints exactly same output 
for both certs.
- ...but when use for mySQL server (+yassl) certificate validation on client's 
side (mysql ...  --ssl-verify-server-cert) *only* 
Equifax_Secure_Global_eBusiness_CA-1.cer success. For debian provided cert I 
get "SSL Connection error", which means server certificete doesn't validate or 
other error with certificate.
+ So far, all seem to be fine, but ...but for example when I use these CA certs 
for mySQL server (with yassl) certificate validation on client's side (mysql 
...  --ssl-verify-server-cert) *only* Equifax_Secure_Global_eBusiness_CA-1.cer 
success. For debian provided cert I get "SSL Connection error", which means 
server certificete doesn't validate or other error with certificate.
  
  Shouldn't ubuntu-provided certificate be exactly the same as provided by root 
CA and be valid with RFC1421?
  It would prevent from errors I just mentioned.
  
  
  Here are both certificates:
  
  Equifax_Secure_Global_eBusiness_CA-1.cer (downloaded from 
http://www.geotrust.com/resources/root-certificates/)
  -----BEGIN CERTIFICATE-----
  MIICkDCCAfmgAwIBAgIBATANBgkqhkiG9w0BAQQFADBaMQswCQYDVQQGEwJVUzEc
  MBoGA1UEChMTRXF1aWZheCBTZWN1cmUgSW5jLjEtMCsGA1UEAxMkRXF1aWZheCBT
  ZWN1cmUgR2xvYmFsIGVCdXNpbmVzcyBDQS0xMB4XDTk5MDYyMTA0MDAwMFoXDTIw
  MDYyMTA0MDAwMFowWjELMAkGA1UEBhMCVVMxHDAaBgNVBAoTE0VxdWlmYXggU2Vj
  dXJlIEluYy4xLTArBgNVBAMTJEVxdWlmYXggU2VjdXJlIEdsb2JhbCBlQnVzaW5l
  c3MgQ0EtMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAuucXkAJlsTRVPEnC
  UdXfp9E3j9HngXNBUmCbnaEXJnitx7HoJpQytd4zjTov2/KaelpzmKNc6fuKcxtc
  58O/gGzNqfTWK8D3+ZmqY6KxRwIP1ORROhI8bIpaVIRw28HFkM9yRcuoWcDNM50/
  o5brhTMhHD4ePmBudpxnhcXIw2ECAwEAAaNmMGQwEQYJYIZIAYb4QgEBBAQDAgAH
  MA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAUvqigdHJQa0S3ySPY+6j/s1dr
  aGwwHQYDVR0OBBYEFL6ooHRyUGtEt8kj2Puo/7NXa2hsMA0GCSqGSIb3DQEBBAUA
  A4GBADDiAVGqx+pf2rnQZQ8w1j7aDRRJbpGTJxQx78T3LUX47Me/okENI7SS+RkA
  Z70Br83gcfxaz2TE4JaY0KNA4gGK7ycH8WUBikQtBmV1UsCGECAhX2xrD2yuCRyv
  8qIYNMR1pHMc8Y3c7635s3a0kr/clRAevsvIO1qEYBlWlKlV
  -----END CERTIFICATE-----
  
  
  Equifax_Secure_Global_eBusiness_CA.crt (shipped with ubuntu/ca-certificates)
  -----BEGIN CERTIFICATE-----
  MIICkDCCAfmgAwIBAgIBATANBgkqhkiG9w0BAQQFADBaMQswCQYDVQQGEwJV
  UzEcMBoGA1UEChMTRXF1aWZheCBTZWN1cmUgSW5jLjEtMCsGA1UEAxMkRXF1
  aWZheCBTZWN1cmUgR2xvYmFsIGVCdXNpbmVzcyBDQS0xMB4XDTk5MDYyMTA0
  MDAwMFoXDTIwMDYyMTA0MDAwMFowWjELMAkGA1UEBhMCVVMxHDAaBgNVBAoT
  E0VxdWlmYXggU2VjdXJlIEluYy4xLTArBgNVBAMTJEVxdWlmYXggU2VjdXJl
  IEdsb2JhbCBlQnVzaW5lc3MgQ0EtMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAw
  gYkCgYEAuucXkAJlsTRVPEnCUdXfp9E3j9HngXNBUmCbnaEXJnitx7HoJpQy
  td4zjTov2/KaelpzmKNc6fuKcxtc58O/gGzNqfTWK8D3+ZmqY6KxRwIP1ORR
  OhI8bIpaVIRw28HFkM9yRcuoWcDNM50/o5brhTMhHD4ePmBudpxnhcXIw2EC
  AwEAAaNmMGQwEQYJYIZIAYb4QgEBBAQDAgAHMA8GA1UdEwEB/wQFMAMBAf8w
  HwYDVR0jBBgwFoAUvqigdHJQa0S3ySPY+6j/s1draGwwHQYDVR0OBBYEFL6o
  oHRyUGtEt8kj2Puo/7NXa2hsMA0GCSqGSIb3DQEBBAUAA4GBADDiAVGqx+pf
  2rnQZQ8w1j7aDRRJbpGTJxQx78T3LUX47Me/okENI7SS+RkAZ70Br83gcfxa
  z2TE4JaY0KNA4gGK7ycH8WUBikQtBmV1UsCGECAhX2xrD2yuCRyv8qIYNMR1
  pHMc8Y3c7635s3a0kr/clRAevsvIO1qEYBlWlKlV
  -----END CERTIFICATE-----

** Description changed:

  Binary package hint: ca-certificates
  
  Ubuntu 8.10
  Package: ca-certificates 20080514-0ubuntu1.1
  
  As example I will use just one certificate provided by package "ca-
  certificates", but the problem concerns more of them.
  
  Those certificates (pasted a few lines below) differ only in line length, 
content is the same.
  Debian-provided cert has 60-chars lines, and the one downloaded via web has 
64-chars lines, just like RFC 1421 suggests:
  "To represent the encapsulated text of a PEM message, the encoding function's 
output is delimited into text lines (using local conventions), with each line 
except the last containing exactly 64 printable characters and the final line 
containing 64 or fewer printable characters."
  
  
  Command `openssl x509 -in ....crt -text -noout` prints exactly same output 
for both certs.
- So far, all seem to be fine, but ...but for example when I use these CA certs 
for mySQL server (with yassl) certificate validation on client's side (mysql 
...  --ssl-verify-server-cert) *only* Equifax_Secure_Global_eBusiness_CA-1.cer 
success. For debian provided cert I get "SSL Connection error", which means 
server certificete doesn't validate or other error with certificate.
+ So far, all seem to be fine, but ...but for example when I use these CA certs 
for mySQL(+yassl) server's certificate validation on client's side (mysql ...  
--ssl-verify-server-cert) *only* Equifax_Secure_Global_eBusiness_CA-1.cer 
success. For debian provided cert I get "SSL Connection error", which means 
server certificete doesn't validate or other error with certificate.
  
  Shouldn't ubuntu-provided certificate be exactly the same as provided by root 
CA and be valid with RFC1421?
  It would prevent from errors I just mentioned.
  
  
  Here are both certificates:
  
  Equifax_Secure_Global_eBusiness_CA-1.cer (downloaded from 
http://www.geotrust.com/resources/root-certificates/)
  -----BEGIN CERTIFICATE-----
  MIICkDCCAfmgAwIBAgIBATANBgkqhkiG9w0BAQQFADBaMQswCQYDVQQGEwJVUzEc
  MBoGA1UEChMTRXF1aWZheCBTZWN1cmUgSW5jLjEtMCsGA1UEAxMkRXF1aWZheCBT
  ZWN1cmUgR2xvYmFsIGVCdXNpbmVzcyBDQS0xMB4XDTk5MDYyMTA0MDAwMFoXDTIw
  MDYyMTA0MDAwMFowWjELMAkGA1UEBhMCVVMxHDAaBgNVBAoTE0VxdWlmYXggU2Vj
  dXJlIEluYy4xLTArBgNVBAMTJEVxdWlmYXggU2VjdXJlIEdsb2JhbCBlQnVzaW5l
  c3MgQ0EtMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAuucXkAJlsTRVPEnC
  UdXfp9E3j9HngXNBUmCbnaEXJnitx7HoJpQytd4zjTov2/KaelpzmKNc6fuKcxtc
  58O/gGzNqfTWK8D3+ZmqY6KxRwIP1ORROhI8bIpaVIRw28HFkM9yRcuoWcDNM50/
  o5brhTMhHD4ePmBudpxnhcXIw2ECAwEAAaNmMGQwEQYJYIZIAYb4QgEBBAQDAgAH
  MA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAUvqigdHJQa0S3ySPY+6j/s1dr
  aGwwHQYDVR0OBBYEFL6ooHRyUGtEt8kj2Puo/7NXa2hsMA0GCSqGSIb3DQEBBAUA
  A4GBADDiAVGqx+pf2rnQZQ8w1j7aDRRJbpGTJxQx78T3LUX47Me/okENI7SS+RkA
  Z70Br83gcfxaz2TE4JaY0KNA4gGK7ycH8WUBikQtBmV1UsCGECAhX2xrD2yuCRyv
  8qIYNMR1pHMc8Y3c7635s3a0kr/clRAevsvIO1qEYBlWlKlV
  -----END CERTIFICATE-----
  
  
  Equifax_Secure_Global_eBusiness_CA.crt (shipped with ubuntu/ca-certificates)
  -----BEGIN CERTIFICATE-----
  MIICkDCCAfmgAwIBAgIBATANBgkqhkiG9w0BAQQFADBaMQswCQYDVQQGEwJV
  UzEcMBoGA1UEChMTRXF1aWZheCBTZWN1cmUgSW5jLjEtMCsGA1UEAxMkRXF1
  aWZheCBTZWN1cmUgR2xvYmFsIGVCdXNpbmVzcyBDQS0xMB4XDTk5MDYyMTA0
  MDAwMFoXDTIwMDYyMTA0MDAwMFowWjELMAkGA1UEBhMCVVMxHDAaBgNVBAoT
  E0VxdWlmYXggU2VjdXJlIEluYy4xLTArBgNVBAMTJEVxdWlmYXggU2VjdXJl
  IEdsb2JhbCBlQnVzaW5lc3MgQ0EtMTCBnzANBgkqhkiG9w0BAQEFAAOBjQAw
  gYkCgYEAuucXkAJlsTRVPEnCUdXfp9E3j9HngXNBUmCbnaEXJnitx7HoJpQy
  td4zjTov2/KaelpzmKNc6fuKcxtc58O/gGzNqfTWK8D3+ZmqY6KxRwIP1ORR
  OhI8bIpaVIRw28HFkM9yRcuoWcDNM50/o5brhTMhHD4ePmBudpxnhcXIw2EC
  AwEAAaNmMGQwEQYJYIZIAYb4QgEBBAQDAgAHMA8GA1UdEwEB/wQFMAMBAf8w
  HwYDVR0jBBgwFoAUvqigdHJQa0S3ySPY+6j/s1draGwwHQYDVR0OBBYEFL6o
  oHRyUGtEt8kj2Puo/7NXa2hsMA0GCSqGSIb3DQEBBAUAA4GBADDiAVGqx+pf
  2rnQZQ8w1j7aDRRJbpGTJxQx78T3LUX47Me/okENI7SS+RkAZ70Br83gcfxa
  z2TE4JaY0KNA4gGK7ycH8WUBikQtBmV1UsCGECAhX2xrD2yuCRyv8qIYNMR1
  pHMc8Y3c7635s3a0kr/clRAevsvIO1qEYBlWlKlV
  -----END CERTIFICATE-----

-- 
ca-certificates differ from those provided by root CA
https://bugs.launchpad.net/bugs/314710
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to