Project

General

Profile

Bug #5259

sysmoBTS: fix ca-certificates

Added by keith 6 days ago. Updated 5 days ago.

Status:
Feedback
Priority:
High
Assignee:
Category:
-
Target version:
-
Start date:
10/12/2021
Due date:
% Done:

70%

Spec Reference:

Description

Since the LetEncrypt Root CA expiry fiasco a sysmobts is unable to use https, not least to access the sysmocom repos.

This script will disable the X3 cert and add the new LE root.

#!/bin/bash

grep isrgrootx1.pem /etc/ca-certificates.conf && exit

wget -q --no-check-certificate https://letsencrypt.org/certs/isrgrootx1.pem -O /usr/share/ca-certificates/isrgrootx1.pem
sed -i '/^mozilla\/AffirmTrust_Commercial.crt/i isrgrootx1.pem' /etc/ca-certificates.conf
sed -i '/^mozilla\/DST_Root_CA_X3/s/^/!/' /etc/ca-certificates.conf
update-ca-certificates

Maybe we can also somehow update the yocto/poky opkg package "ca-certificates"?

sysmocom-nitb-image-sysmobts-v2-20211014074622.rootfs.ubi sysmocom-nitb-image-sysmobts-v2-20211014074622.rootfs.ubi 36.4 MB test build image with ca-certificates package 20210119 laforge, 10/14/2021 08:10 AM

History

#1 Updated by laforge 6 days ago

  • Status changed from New to In Progress
  • Assignee changed from sysmocom to laforge
  • % Done changed from 0 to 20

tried to resolve it for 201705-nightly in:

commit 8d3ccdf0eb5c555684287f4fb51bba51dc2ed4f3
Author: Harald Welte <laforge@osmocom.org>
Date:   Tue Oct 12 21:13:03 2021 +0200

    ca-certificates: Migrate from DST_X3 to ISRG_X1

    Closes: OS#5259

https://git.sysmocom.de/sysmo-bts/meta-sysmocom-bsp/commit/8d3ccdf0eb5c555684287f4fb51bba51dc2ed4f3

let's see if that works and then introduce the change to 201705 next.

#2 Updated by laforge 5 days ago

It seems like adding the new cert to a package is insufficient, we also need to remove
the expired one from the ca-certificates package.

I'm currently doing a local build of OE with a new ca-certificates package from 2021, hoping
this will fix it.

#3 Updated by laforge 5 days ago

please test the attached image if it resolves the problem. thanks!

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 48.8 MB)