Hi,
I'm having several issues with the new certificates, can somebody help me solve them? I successfully uploaded new ssh key to fas (git push on fedorahosted.org is working for me), also I replaced the old certificates with new ones via fedora-packager-setup. Here is the ls:
-rw-rw-r-- 1 mso mso 2725 2008-08-24 10:25 fedora-browser-cert.p12 -rw------- 1 mso mso 8557 2008-08-19 15:49 .fedora.cert -rw-rw-r-- 1 mso mso 6162 2008-08-20 18:47 .fedora-server-ca.cert -rw-rw-r-- 1 mso mso 6162 2008-08-20 18:47 .fedora-upload-ca.cert
However, I cannot log in to koji web interface. Firefox (after confirming an exception for the new koji's ssh certificate) asks for my certificate, I use the fedora-browser-cert.p12 listed above. Details of the certificate:
Issued to: E=martin.sourada@gmail.com,CN=mso,OU=Upload Files,O=Fedora Project,ST=North Carolina,C=US Serial Number: 00:90 Valid from 19/08/08 15:49:44 to 19/08/09 15:49:44 Email: martin.sourada@gmail.com Issued by: E=admin@fedoraproject.org,CN=Fedora Project CA,OU=Fedora Project CA,O=Fedora Project,L=Raleigh,ST=North Carolina,C=US Stored in: Software Security Device
Then error page appears:
Secure Connection Failed ----------------------------------------------------------------------- An error occurred during a connection to koji.fedoraproject.org.
SSL peer cannot verify your certificate.
(Error code: ssl_error_bad_cert_alert) ----------------------------------------------------------------------- The page you are trying to view can not be shown because the authenticity of the received data could not be verified.
* Please contact the web site owners to inform them of this problem.
[Try again]
Any thoughts of what am I doing wrong? I deleted the old certificate from firefox and imported the new one, also I restarted firefox numerous times already and still no luck.
Also uploading new sources to cvs is not working for me (cvs co and cvs update does though):
make new-sources FILES=subtitleeditor-0.22.3.tar.gz
Checking : subtitleeditor-0.22.3.tar.gz on https://cvs.fedoraproject.org/repo/pkgs/upload.cgi... ERROR: could not check remote file status make: *** [new-sources] Error 255
Any thoughts what I am missing?
Thanks, Martin
On Mon, Aug 25, 2008 at 10:22:18AM +0200, Martin Sourada wrote:
Hi,
I'm having several issues with the new certificates, can somebody help me solve them? I successfully uploaded new ssh key to fas (git push on fedorahosted.org is working for me), also I replaced the old certificates with new ones via fedora-packager-setup. Here is the ls:
[...]
Any thoughts what I am missing?
I had done the update of certificates on Friday and had the same ssh handshake problems. Not finding out what was wrong today, I just refetched it after login https://admin.fedoraproject.org/accounts/home https://admin.fedoraproject.org/accounts/user/gencert
put the new gencert in ~/.fedora.cert reran /usr/bin/fedora-packager-setup and reimported the certificate in Firefox, restarted Firefox and now authentication works again. So my advice is to try again from the start downloading the new certificate,
Daniel
On Mon, 2008-08-25 at 15:10 +0200, Daniel Veillard wrote:
I had done the update of certificates on Friday and had the same ssh handshake problems. Not finding out what was wrong today, I just refetched it after login https://admin.fedoraproject.org/accounts/home https://admin.fedoraproject.org/accounts/user/gencert
put the new gencert in ~/.fedora.cert reran /usr/bin/fedora-packager-setup and reimported the certificate in Firefox, restarted Firefox and now authentication works again. So my advice is to try again from the start downloading the new certificate,
Daniel
Thanks! That finally solved the issue for me as well. Both for koji *and* CVS. Thanks again :)
Btw. works for epiphany as well, even though I am still unable to remove the old certificates.
Martin
Daniel Veillard a écrit :
I had done the update of certificates on Friday and had the same ssh handshake problems. Not finding out what was wrong today, I just refetched it after login https://admin.fedoraproject.org/accounts/home https://admin.fedoraproject.org/accounts/user/gencert
put the new gencert in ~/.fedora.cert reran /usr/bin/fedora-packager-setup and reimported the certificate in Firefox, restarted Firefox and now authentication works again. So my advice is to try again from the start downloading the new certificate,
Daniel
Which package provides fedora-packager-setup? Trying to locate if but it is not found on repository.
Luya
On Wed, 27 Aug 2008 01:08:50 -0700, Luya Tshimbalanga wrote:
Which package provides fedora-packager-setup? Trying to locate if but it is not found on repository.
fedora-packager
yum whatprovides /usr/bin/fedora-packager-setup repoquery --whatprovides /usr/bin/fedora-packager-setup
Michael Schwendt a écrit :
On Wed, 27 Aug 2008 01:08:50 -0700, Luya Tshimbalanga wrote:
Which package provides fedora-packager-setup? Trying to locate if but it is not found on repository.
fedora-packager
yum whatprovides /usr/bin/fedora-packager-setup repoquery --whatprovides /usr/bin/fedora-packager-setup
Got it. Thanks.
Luya
On Monday 25 August 2008 03:22:18 am Martin Sourada wrote:
Hi,
I'm having several issues with the new certificates, can somebody help me solve them? I successfully uploaded new ssh key to fas (git push on fedorahosted.org is working for me), also I replaced the old certificates with new ones via fedora-packager-setup. Here is the ls:
-rw-rw-r-- 1 mso mso 2725 2008-08-24 10:25 fedora-browser-cert.p12 -rw------- 1 mso mso 8557 2008-08-19 15:49 .fedora.cert -rw-rw-r-- 1 mso mso 6162 2008-08-20 18:47 .fedora-server-ca.cert -rw-rw-r-- 1 mso mso 6162 2008-08-20 18:47 .fedora-upload-ca.cert
However, I cannot log in to koji web interface. Firefox (after confirming an exception for the new koji's ssh certificate) asks for my certificate, I use the fedora-browser-cert.p12 listed above. Details of the certificate:
Issued to: E=martin.sourada@gmail.com,CN=mso,OU=Upload Files,O=Fedora Project,ST=North Carolina,C=US Serial Number: 00:90 Valid from 19/08/08 15:49:44 to 19/08/09 15:49:44 Email: martin.sourada@gmail.com Issued by: E=admin@fedoraproject.org,CN=Fedora Project CA,OU=Fedora Project CA,O=Fedora Project,L=Raleigh,ST=North Carolina,C=US Stored in: Software Security Device
The cert is old. all new and valid certs have a OU of "Fedora User Cert" please grab a new cert.
Dennis
On Mon, 2008-08-25 at 10:36 -0500, Dennis Gilmore wrote:
The cert is old. all new and valid certs have a OU of "Fedora User Cert" please grab a new cert.
Dennis
Thanks for the info. I already did it as Daniel suggested. Seems like I generated the new .fedora.cert too soon :-D
Martin