Message boards : Questions and problems : HTTP error: Peer certificate cannot be authenticated with given CA certificates (with workaround)
Message board moderation
Previous · 1 · 2 · 3 · 4 · 5 · Next
Author | Message |
---|---|
Send message Joined: 1 Oct 21 Posts: 2 |
@Richard ty for fast reply :) |
Send message Joined: 12 Oct 06 Posts: 15 |
Hiya Thanks for posting the "fixed" file. I replaced my ca-bundle.crt file with the file on Google Drive and it works. regards Tim Founder, UK BOINC Team |
Send message Joined: 2 Oct 05 Posts: 404 |
I can load and edit the file, but cannot save it, it says it needs admin priv. I AM the admin. Wave upon wave of demented avengers march cheerfully out of obscurity into the dream. |
Send message Joined: 13 Feb 07 Posts: 21 |
Well, someone will solve the problem after the weekend. Let us give them time. |
Send message Joined: 2 Oct 05 Posts: 404 |
Agreed. Deadlines are still days away. Wave upon wave of demented avengers march cheerfully out of obscurity into the dream. |
Send message Joined: 29 Aug 05 Posts: 15563 |
I posted to the ticket again, asking if they can give an ETA. See #4530 if people want to urge there. |
Send message Joined: 5 Oct 06 Posts: 5129 |
I can load and edit the file, but cannot save it, it says it needs admin priv. I AM the admin.Right-click on your editor, and choose 'Run as administrator'. I'm in the same position as you. I'm an administrator, but not the administrator. Alternative solution: move the file to a non-protected location before attempting to edit it. |
Send message Joined: 24 Dec 19 Posts: 229 |
Can someone be more direct here, is this something that needs to be fixed on the BOINC Server side (at the project)? or at the client side software packages (at the host)? or something that requires a new BOINC software update (the client)? |
Send message Joined: 5 Oct 06 Posts: 5129 |
The full solution would be a release of an updated client - which is long overdue, anyway. Project server administrators may be able to take alleviating action, but that would be piecemeal, and not every project may have the necessary skills. The BOINC server has no role to play. I have a strongly-worded email in draft, which I intend to post 24 hours after this thread was opened - i.e. in about five minutes from now - unless something else happens first. Sent. |
Send message Joined: 24 Dec 19 Posts: 229 |
looks like for my upload issues seen at Universe@home on Linux Ubuntu 20.04.3, simply running the updates seems to have fixed it, one of the updates was the ca certificate. uploads now processing again. |
Send message Joined: 29 Aug 05 Posts: 15563 |
I have a strongly-worded email in draft, which I intend to post 24 hours after this thread was opened - i.e. in about five minutes from now - unless something else happens first.Too bad it didn't go to any list I seem to follow. Mind sending me a copy? |
Send message Joined: 5 Oct 06 Posts: 5129 |
It went to boinc_admin@googlegroups.com - I'd have thought you could get into that.I have a strongly-worded email in draft, which I intend to post 24 hours after this thread was opened - i.e. in about five minutes from now - unless something else happens first.Too bad it didn't go to any list I seem to follow. Mind sending me a copy? Two replies so far - Vitalii repeating what I just said, and Matt Blumberg saying that projects could sort it out for themselves. Neither answered the main question - "Where's Wally?" I'll send you the thread so far. |
Send message Joined: 5 Oct 06 Posts: 5129 |
looks like for my upload issues seen at Universe@home on Linux Ubuntu 20.04.3, simply running the updates seems to have fixed it, one of the updates was the ca certificate. uploads now processing again.That's a good point. So far, we've been treating it as a "Windows only" problem, but if Linux machines haven't been updated for a while, it might affect them too. I have two machines with CA updates waiting, and GPUGrid tasks around 80%. I'll wait till they finish, and see what happens. At least, Linux updates can be done at home, without needing a new client from Berkeley. Unless, that is, you're a corporate Linux user, with a system locked up by central IT admin tighter than a duck's arse. |
Send message Joined: 11 Mar 19 Posts: 1 |
Hello Richard, Thanks a lot. It works. Your file downloaded, replaced (with secure copy of original in case of), not restart needed, and.....working ! It is already the second time such problem occurs. The latest was in 2018. I think some project admin not follow theire project. Have a nice day, evening, morninig,..... depending when you will read. Once again, thank you |
Send message Joined: 28 Jun 10 Posts: 2703 |
That's a good point. So far, we've been treating it as a "Windows only" problem, but if Linux machines haven't been updated for a while, it might affect them too.[/quote] Presumably the linked googledocs cert bundle can replace the one in the BOINC folder just as I have done with my wine installation though I think I probably have a while before I need to worry though there are a couple of expired certificates in the bundle I currently have. |
Send message Joined: 10 May 07 Posts: 1444 |
According to this article quite a few big name websites also suffered outages on the LETS ENCRYPT certificate expiration. |
Send message Joined: 1 Oct 21 Posts: 1 |
Just wanted to inform everyone that I checked my certificate, it expires in 2028, and things are still snafu after updating my computer and restarting. Hopefully, they'll accept late results at these various projects... |
Send message Joined: 5 Oct 06 Posts: 5129 |
I have two machines with CA updates waiting, and GPUGrid tasks around 80%. I'll wait till they finish, and see what happens.My Linux machines have been making their hourly checkin to GPUGrid without problems, so the CA updates are irrelevant to this discussion. Linux (Mint) was ahead of the game at the last update. |
Send message Joined: 2 Oct 05 Posts: 404 |
>>> Right-click on your editor, and choose 'Run as administrator'. I edited and saved it from Visual Studio as administrator, saved and jobs uploading and reporting fine. Cheers Richard. Wave upon wave of demented avengers march cheerfully out of obscurity into the dream. |
Send message Joined: 5 Oct 06 Posts: 5129 |
A volunteer developer is working on creating an emergency release (take a bow, Vitalii). The new release will contain a fresh certificate bundle, sourced from a genuine and reliable public source: https://curl.se/docs/caextract.html You will need to rename cacert.pem to ca-bundle.crt, but it works with some of the projects that were having problems on Thursday (I haven't checked them all). If you feel nervous about downloading amateur hacks like mine, feel free to download from there instead. |
Copyright © 2024 University of California.
Permission is granted to copy, distribute and/or modify this document
under the terms of the GNU Free Documentation License,
Version 1.2 or any later version published by the Free Software Foundation.