Hi, >>> Agreed. We need someone to run with -D and log it and IDEALLY run a few >>> right after to see if it resolves. I'm guessing one mirror is blocking >>> or >>> something. >> >> >> I've updated my sa-cron script to loop to try again should it fail due >> to this error, as well as provide the debugging info on every run. >> > I received some detailed information from one of the mirror hosters that > made me think I need to put back in a delay of the TXT update used by > sa-update to give the mirrors time to pull the new ruleset files. > > I have put a 10 minute delay in place on the DNS TXT updates which may clear > up this problem in roughly 12 hours. It looks like there was about a 6 > minute window when DNS had updated right after 08:31 AM UTC before all > mirrors had updated by 08:41 AM UTC. > > Thanks to all of those who enabled debugging. Please keep them enabled for > the next few days or weeks in case this doesn't complete resolve the issue.
Last night's run was successful, from sa-update.ena.com. I am curious about the "WARNING: This key is not certified with a trusted signature!" Is it just a self-signed cert? If you'd like the full output, please let me know. I'll leave the debugging enabled for another week. This will otherwise be the last post unless there's an error. All times are EST. Jan 11 04:10:02.765 [7209] dbg: channel: reading MIRRORED.BY file /var/lib/spamassassin/3.004002/updates_spamassassin_org/MIRRORED.BY Jan 11 04:10:02.765 [7209] dbg: channel: parsing MIRRORED.BY file for channel updates.spamassassin.org Jan 11 04:10:02.765 [7209] dbg: channel: found mirror http://sa-update.dnswl.org/ weight=3 Jan 11 04:10:02.765 [7209] dbg: channel: found mirror http://www.sa-update.pccc.com/ weight=5 Jan 11 04:10:02.765 [7209] dbg: channel: found mirror http://sa-update.secnap.net/ weight=5 Jan 11 04:10:02.765 [7209] dbg: channel: found mirror http://sa-update.space-pro.be/ weight=1 Jan 11 04:10:02.765 [7209] dbg: channel: found mirror http://sa-update.ena.com/ weight=5 Jan 11 04:10:02.765 [7209] dbg: channel: found mirror http://sa-update.razx.cloud/ weight=5 Jan 11 04:10:02.766 [7209] dbg: channel: found mirror http://sa-update.fossies.org/ weight=1 Jan 11 04:10:02.766 [7209] dbg: channel: found mirror http://sa-update.verein-clean.net/ weight=10 Jan 11 04:10:02.766 [7209] dbg: channel: found mirror http://sa-update.bitwell.fi/ weight=10 Jan 11 04:10:02.766 [7209] dbg: channel: found mirror http://sa-update.spamassassin.org/ weight=5 DNS A query: sa-update.ena.com -> 96.5.1.5, 96.4.1.5 Jan 11 04:10:02.796 [7209] dbg: channel: selected mirror http://sa-update.ena.com fetching http://sa-update.ena.com/1820847.tar.gz Jan 11 04:10:02.796 [7209] dbg: http: url: http://sa-update.ena.com/1820847.tar.gz Jan 11 04:10:02.796 [7209] dbg: http: downloading to: /var/lib/spamassassin/3.004002/updates_spamassassin_org/1820847.tar.gz, new Jan 11 04:10:02.797 [7209] dbg: util: executable for curl was found at /usr/bin/curl Jan 11 04:10:02.797 [7209] dbg: http: /usr/bin/curl -s -L -O --remote-time -g --max-redirs 2 --connect-timeout 30 --max-time 300 --fail -o 1820847.tar.gz -- http://sa-update.ena.com/1820847.tar.gz Jan 11 04:10:03.313 [7209] dbg: http: process [7265], exit status: exit 0 http: (curl) GET http://sa-update.ena.com/1820847.tar.gz, success fetching http://sa-update.ena.com/1820847.tar.gz.sha1 Jan 11 04:10:03.315 [7209] dbg: http: url: http://sa-update.ena.com/1820847.tar.gz.sha1 Jan 11 04:10:03.315 [7209] dbg: http: downloading to: /var/lib/spamassassin/3.004002/updates_spamassassin_org/1820847.tar.gz.sha1, new Jan 11 04:10:03.315 [7209] dbg: util: executable for curl was found at /usr/bin/curl Jan 11 04:10:03.315 [7209] dbg: http: /usr/bin/curl -s -L -O --remote-time -g --max-redirs 2 --connect-timeout 30 --max-time 300 --fail -o 1820847.tar.gz.sha1 -- http://sa-update.ena.com/1820847.tar.gz.sha1 Jan 11 04:10:03.394 [7209] dbg: http: process [7311], exit status: exit 0 http: (curl) GET http://sa-update.ena.com/1820847.tar.gz.sha1, success fetching http://sa-update.ena.com/1820847.tar.gz.asc Jan 11 04:10:03.394 [7209] dbg: http: url: http://sa-update.ena.com/1820847.tar.gz.asc Jan 11 04:10:03.394 [7209] dbg: http: downloading to: /var/lib/spamassassin/3.004002/updates_spamassassin_org/1820847.tar.gz.asc, new Jan 11 04:10:03.395 [7209] dbg: util: executable for curl was found at /usr/bin/curl Jan 11 04:10:03.395 [7209] dbg: http: /usr/bin/curl -s -L -O --remote-time -g --max-redirs 2 --connect-timeout 30 --max-time 300 --fail -o 1820847.tar.gz.asc -- http://sa-update.ena.com/1820847.tar.gz.asc Jan 11 04:10:03.468 [7209] dbg: http: process [7321], exit status: exit 0 http: (curl) GET http://sa-update.ena.com/1820847.tar.gz.asc, success Jan 11 04:10:03.470 [7209] dbg: sha1: verification wanted: 9e6b9fa533ac60fa622fdec544a83eb2b7941771 Jan 11 04:10:03.470 [7209] dbg: sha1: verification result: 9e6b9fa533ac60fa622fdec544a83eb2b7941771 Jan 11 04:10:03.470 [7209] dbg: channel: populating temp content file /tmp/.spamassassin72094nagfKtmp Jan 11 04:10:03.470 [7209] dbg: gpg: populating temp signature file Jan 11 04:10:03.471 [7209] dbg: util: secure_tmpfile created a temporary file /tmp/.spamassassin7209fKplaEtmp Jan 11 04:10:03.471 [7209] dbg: gpg: calling gpg Jan 11 04:10:03.481 [7209] dbg: gpg: gpg: Signature made Thu 11 Jan 2018 03:31:48 AM EST using RSA key ID 24F434CE Jan 11 04:10:03.481 [7209] dbg: gpg: [GNUPG:] SIG_ID RoAyMHgMMiGvqqH4rp7FGvLMmCM 2018-01-11 1515659508 Jan 11 04:10:03.482 [7209] dbg: gpg: [GNUPG:] GOODSIG 6C55397824F434CE updates.spamassassin.org Signing Key <rele...@spamassassin.org> Jan 11 04:10:03.482 [7209] dbg: gpg: gpg: Good signature from "updates.spamassassin.org Signing Key <rele...@spamassassin.org>" Jan 11 04:10:03.483 [7209] dbg: gpg: [GNUPG:] VALIDSIG 0C2B1D7175B852C64B3CDC716C55397824F434CE 2018-01-11 1515659508 0 4 0 1 2 00 5E541DC959CB8BAC7C78DFDC4056A61A5244EC45 Jan 11 04:10:03.483 [7209] dbg: gpg: [GNUPG:] TRUST_UNDEFINED Jan 11 04:10:03.483 [7209] dbg: gpg: gpg: WARNING: This key is not certified with a trusted signature! Jan 11 04:10:03.483 [7209] dbg: gpg: gpg: There is no indication that the signature belongs to the owner. Jan 11 04:10:03.483 [7209] dbg: gpg: Primary key fingerprint: 5E54 1DC9 59CB 8BAC 7C78 DFDC 4056 A61A 5244 EC45 Jan 11 04:10:03.483 [7209] dbg: gpg: Subkey fingerprint: 0C2B 1D71 75B8 52C6 4B3C DC71 6C55 3978 24F4 34CE Jan 11 04:10:03.483 [7209] dbg: gpg: found signature made by key 0C2B1D7175B852C64B3CDC716C55397824F434CE Jan 11 04:10:03.483 [7209] dbg: gpg: key id 0C2B1D7175B852C64B3CDC716C55397824F434CE is release trusted Jan 11 04:10:03.483 [7209] dbg: channel: file verification passed, testing update Jan 11 04:10:03.483 [7209] dbg: channel: extracting archive