StartCom Certification Authority G2 CA cert missing

Bug #1255485 reported by Andrew Stubbs
260
This bug affects 2 people
Affects Status Importance Assigned to Milestone
ca-certificates (Ubuntu)
Fix Released
Undecided
Unassigned
Lucid
Won't Fix
Wishlist
Unassigned
Precise
Won't Fix
Wishlist
Unassigned
Quantal
Won't Fix
Wishlist
Unassigned

Bug Description

I'm getting this on a Lucid Lynx server:

$ wget https://www.sourceware.org
--2013-11-27 10:48:12-- https://www.sourceware.org/
Resolving www.sourceware.org... 209.132.180.131
Connecting to www.sourceware.org|209.132.180.131|:443... connected.
ERROR: cannot verify www.sourceware.org's certificate, issued by `/C=IL/O=StartCom Ltd./OU=Secure Digital Certificate Signing/CN=StartCom Class 1 Primary Intermediate Server CA':
  Self-signed certificate encountered.
To connect to www.sourceware.org insecurely, use `--no-check-certificate'.

Similarly with curl:

$ curl https://www.sourceware.org
curl: (60) SSL certificate problem, verify that the CA cert is OK. Details:
error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
More details here: http://curl.haxx.se/docs/sslcerts.html

curl performs SSL certificate verification by default, using a "bundle"
 of Certificate Authority (CA) public keys (CA certs). If the default
 bundle file isn't adequate, you can specify an alternate file
 using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
 the bundle, the certificate verification probably failed due to a
 problem with the certificate (it might be expired, or the name might
 not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
 the -k (or --insecure) option.

I presume the certificates are just too old, but there might be a problem with openssl, or something, I suppose.

Since Lucid is still supported for another 17 months, on the server, I think this ought to be fixed.

I'm marking it as a security issue even though it is the user's security that is vulnerable, not the system, so apologies if that's not appropriate.

affects: ssl-cert (Ubuntu) → ca-certificates (Ubuntu)
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Looks like Ubuntu 12.10 and older don't have the "StartCom Certification Authority G2" CA cert.

A workaround is to install that CA cert into /usr/local/share/ca-certificates, and run "sudo update-ca-certificates".

information type: Private Security → Public Security
Changed in ca-certificates (Ubuntu):
status: New → Fix Released
Changed in ca-certificates (Ubuntu Lucid):
status: New → Confirmed
Changed in ca-certificates (Ubuntu Precise):
status: New → Confirmed
Changed in ca-certificates (Ubuntu Quantal):
status: New → Confirmed
Changed in ca-certificates (Ubuntu Lucid):
importance: Undecided → Wishlist
Changed in ca-certificates (Ubuntu Precise):
importance: Undecided → Wishlist
Changed in ca-certificates (Ubuntu Quantal):
importance: Undecided → Wishlist
summary: - Lucid Lynx needs an update
+ StartCom Certification Authority G2 CA cert missing
Revision history for this message
NetBit73 (mmach) wrote :

BŁĄD: błąd kontroli certyfikatu dla dl.dropbox.com, wystawionego przez `/C=US/ST=Arizona/L=Scottsdale/O=GoDaddy.com, Inc./OU=http://certs.godaddy.com/repository//CN=Go Daddy Secure Certificate Authority - G2':
  Błąd lokalnej kontroli centrum certyfikacji.
Aby połączyć się z dl.dropbox.com w sposób niebezpieczny, można użyć `--no-check-certificate'.

Trusty 14.04 Kubuntu

Changed in ca-certificates (Ubuntu Quantal):
status: Confirmed → Won't Fix
Revision history for this message
Rolf Leggewie (r0lf) wrote :

lucid has seen the end of its life and is no longer receiving any updates. Marking the lucid task for this ticket as "Won't Fix".

Changed in ca-certificates (Ubuntu Lucid):
status: Confirmed → Won't Fix
Revision history for this message
Steve Langasek (vorlon) wrote :

The Precise Pangolin has reached end of life, so this bug will not be fixed for that release

Changed in ca-certificates (Ubuntu Precise):
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.