Unable to verify self signed certificate

Bug #1875781 reported by Taiten Peng
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Snapcraft
New
Undecided
Unassigned
openssl (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

See the upstream bug background
https://github.com/openssl/openssl/issues/1418

The issue initially was caught in a case when developers works behind company firewall and requires install company self signed certificate on Ubuntu host in order to access internet via company proxy.

User may experience unable to access internet services via https protocol when even manually installed root trust ca-certificate on host machine due to openssl unable to verify some type of self signed certificate.

This is also causing problems for snapcraft developers who work behind proxy servers unable to build snap packages.

There is a fix going into openssl upstream apparently
https://github.com/openssl/openssl/pull/10587

Just create a bug here to track this issue in Ubuntu in order to make sure we merge upstream fixes ultimately.

Similar case reported by other users:
[1] https://serverfault.com/questions/966846/cannot-trust-development-https-self-signed-certificate-in-ubuntu-18-04-2-lts
[2] https://stackoverflow.com/questions/55485511/how-to-run-dotnet-dev-certs-https-trust/59702094#59702094

Taiten Peng (taitenpeng)
description: updated
Taiten Peng (taitenpeng)
description: updated
Revision history for this message
Dimitri John Ledkov (xnox) wrote :

The patch to address this is rather large, and doesn't quite apply cleanly to 1.1.1f that we currently ship.

Also there is a workaround for this - just generate a better / different self-signed cert which is identified as such by openssl.

But I do understand that doing that may be very inconvenient as well.

Changed in openssl (Ubuntu):
status: New → Triaged
importance: Undecided → Medium
Taiten Peng (taitenpeng)
affects: snapcraft (Ubuntu) → snapcraft
Revision history for this message
Adrien Nader (adrien) wrote (last edit ):

The corresponding patch has been merged in newer releases which have since been shipped. I'm going to mark this issue as Fix Released for openssl.

Changed in openssl (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.