Bug 2111093 - "Microsec e-Szigno Root CA 2009" stop working after the latest update
Summary: "Microsec e-Szigno Root CA 2009" stop working after the latest update
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: ca-certificates
Version: 36
Hardware: Unspecified
OS: Unspecified
high
medium
Target Milestone: ---
Assignee: Bob Relyea
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-07-26 13:34 UTC by János Tamási
Modified: 2022-08-22 21:12 UTC (History)
9 users (show)

Fixed In Version: ca-certificates-2022.2.54-1.2.fc36
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-08-06 01:52:43 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FC-548 0 None None None 2022-07-26 13:36:52 UTC

Description János Tamási 2022-07-26 13:34:44 UTC
Description of problem:
After updating to the latest ca-certificates (2022.2.54-1.0.fc36) the "Microsec e-Szigno Root CA 2009" disappearing from the /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem file and sites using certificates issued by this CA are stop working.

Version-Release number of selected component (if applicable):
2022.2.54-1.0.fc36

How reproducible:
Install latest ca-certificates (2022.2.54-1.0.fc36)
curl https://gate.gov.hu

Actual results:
Unkown cert error

# curl https://gate.gov.hu
curl: (60) SSL certificate problem: self-signed certificate in certificate chain
More details here: https://curl.se/docs/sslcerts.html

curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and
how to fix it, please visit the web page mentioned above.

Comment 1 Bob Relyea 2022-07-26 21:45:20 UTC
So it's still in certdata.txt with TLS Email and code signing permissions.

It's in /usr/share/pki/ca-trust-source/ca-bundle.trust.p11-kit, but the trust object attributes are missing!

Comment 2 Bob Relyea 2022-07-26 21:47:31 UTC
Setting to assigned and raising the priority. This may not be the only cert that has this issue.

Comment 3 Bob Relyea 2022-07-27 22:34:39 UTC
ok, there are a number of certs, some of them have been missing for a while. The problem is p11-kit expects the labels on Trust objects and certs to be unique, and appearantly barfs if they aren't (well barfs on the trust objects that aren't).

I'll file a separate bug against p11-kit, but for now I'll make sure the merge script I use to merge code-signing certificates generates a unique label for each trust object and cert.

bob

Comment 4 John Soros 2022-08-03 08:31:49 UTC
Hello.
This issue is still present and prevents some hungarian websites from working.
It feels like some CA certificates that should be globally trusted not being trusted in fedora is a pretty big regression, especially since it was introduced in a stable version.
Workaround for now seems to be to
  dnf downgrade ca-certificates
This worked for me, though I think it only works for chrome and chromium, I've had this issue with firefox even before the latest ca-certificates update.
Thanks!

Comment 5 Bob Relyea 2022-08-03 16:58:41 UTC
I have patches that fix this, I'm just having build problems on f35 and f36. The rawhide package should be correct.

Comment 6 Fedora Update System 2022-08-04 18:09:28 UTC
FEDORA-2022-205041cb1c has been submitted as an update to Fedora 36. https://bodhi.fedoraproject.org/updates/FEDORA-2022-205041cb1c

Comment 7 Bob Relyea 2022-08-04 18:11:00 UTC
I've pushed builds to updates-testing. Please verify those builds fix this issue for you.

Comment 8 Fedora Update System 2022-08-05 01:53:18 UTC
FEDORA-2022-205041cb1c has been pushed to the Fedora 36 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2022-205041cb1c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2022-205041cb1c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 John Soros 2022-08-05 11:56:18 UTC
This fixed my issue in both firefox and chrome.
Thanks!

Comment 10 Fedora Update System 2022-08-06 01:52:43 UTC
FEDORA-2022-205041cb1c has been pushed to the Fedora 36 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 11 Andras Kovacs 2022-08-10 21:56:24 UTC
Please, help with the testing of the new Fedora 35 package too! https://bodhi.fedoraproject.org/updates/FEDORA-2022-3fc29aa0e1

Comment 12 Andras Kovacs 2022-08-18 08:28:09 UTC
The new, fixed ca-certificates package is still not available for Fedora 35 from the repo.

Comment 13 Bob Relyea 2022-08-22 21:12:59 UTC
That's because you were the only one to give it karma. It needs at least 2 testers, then the developers can push it. It was submitted by time On Thursday (Aug 18) and and pushed on Friday (Aug 19). It should be available now.


Note You need to log in before you can comment on or make changes to this bug.