Hi, Is your SLES 12 up to date? The SLES12SP4 - Pool and Updates repositories are being used and zypper refresh && zypper update tells me it is up to date. This is a freshly installed machine. The DST Root CA X3 was removed from our CA Bundle to avoid triggering this problem. Ciao, Marcus On Tue, Dec 07, 2021 at 01:07:09PM +0000, Mathias Radtke wrote:
Hi we are currently struggling with testing our sles12 packages on download.opensuse.org
The certificate gets rejected because it is expired
openssl s_client -showcerts -connect download.opensuse.org:443
CONNECTED(00000003)
depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
---
Certificate chain
0 s:/CN=opensuse.org
i:/C=US/O=Let's Encrypt/CN=R3
Hi, If you do not have LTSS for SLES 12 SP4, you will need to manually remove the CA from the trust store. - ll /usr/share/pki/trust/DST* - Remove the DST_Root_CA_X3... if present - Run update-ca-certificates Ciao, Marcus On Tue, Dec 07, 2021 at 02:16:54PM +0000, Mathias Radtke wrote:
Hi,
Is your SLES 12 up to date?
The SLES12SP4 - Pool and Updates repositories are being used and zypper refresh && zypper update tells me it is up to date. This is a freshly installed machine.
The DST Root CA X3 was removed from our CA Bundle to avoid triggering this problem.
Ciao, Marcus On Tue, Dec 07, 2021 at 01:07:09PM +0000, Mathias Radtke wrote:
Hi we are currently struggling with testing our sles12 packages on download.opensuse.org
The certificate gets rejected because it is expired
openssl s_client -showcerts -connect download.opensuse.org:443
CONNECTED(00000003)
depth=3 O = Digital Signature Trust Co., CN = DST Root CA X3
verify error:num=10:certificate has expired
notAfter=Sep 30 14:01:15 2021 GMT
---
Certificate chain
0 s:/CN=opensuse.org
i:/C=US/O=Let's Encrypt/CN=R3
participants (2)
-
Marcus Meissner
-
Mathias Radtke