opensmtpd ssl cert path error

Bug #1492595 reported by Tom Worster
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
opensmtpd (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

smtpd logs the following:

    warn: unable to load CA file /etc/ssl/cert.pem: No such file or directory
    smtp-out: Server certificate verification failed on session ffffffff8c188871

If https://bugs.archlinux.org/task/38125 is correct then it is a compile time configuration problem.

1) Description: Ubuntu 14.04.1 LTS
Release: 14.04
Linux hv5 3.13.0-44-generic #73-Ubuntu SMP Tue Dec 16 00:22:43 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux

2) opensmtpd:
  Installed: 5.4.1p1-1
  Candidate: 5.4.1p1-1
  Version table:
 *** 5.4.1p1-1 0
        500 http://us.archive.ubuntu.com/ubuntu/ trusty/universe amd64 Packages
        100 /var/lib/dpkg/status

3) smtpd use the system SSL certs.

4) smtpd attempted to use SSL certs from a different location.

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

information type: Private Security → Public Security
Changed in opensmtpd (Ubuntu):
status: New → Incomplete
Revision history for this message
Tom Worster (fsb-deactivatedaccount) wrote :

I don't really understand Marc's comment but I think it is talking about procedures for getting patches into security updates. But I don't think that's relevant at the moment.

What I want to do was report a bug in a package. Please help me understand how I should do that so that the report might reach someone who could fix it.

Revision history for this message
Yonas (yonas-y) wrote :

I ran into this as well. A workaround is:

ln -s /etc/ssl/certs/ca-certificates.crt /etc/ssl/cert.pem

Revision history for this message
Yonas (yonas-y) wrote :

This is not a security update. It's a compile time problem.

Changed in opensmtpd (Ubuntu):
status: Incomplete → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.