[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#203787: marked as done (apache-ssl: ssl-certificate --force fails)



Your message dated Sun, 3 Aug 2003 18:24:34 +0200 (CEST)
with message-id <Pine.LNX.4.56.0308031816500.16155@trider-g7.ext.fabbione.net>
and subject line Bug#203787: apache-ssl: ssl-certificate --force fails
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--------------------------------------
Received: (at submit) by bugs.debian.org; 1 Aug 2003 15:34:19 +0000
>From rory.l@hopkins.co.uk Fri Aug 01 10:29:58 2003
Return-path: <rory.l@hopkins.co.uk>
Received: from mail.hopkins.co.uk (netpilot.hopkins.co.uk) [62.189.170.1] 
	by master.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 19ibqw-0005Bs-00; Fri, 01 Aug 2003 10:29:58 -0500
Received: from mhp_nt1.hopkins.co.uk (unknown [10.0.0.24])
	by netpilot.hopkins.co.uk (Postfix) with ESMTP id 88B411B016
	for <submit@bugs.debian.org>; Fri,  1 Aug 2003 16:29:06 +0100 (BST)
Received: from hopnet (hopnet.hopkins.co.uk [10.0.0.23]) by mhp_nt1.hopkins.co.uk with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13)
	id MXLXRYCK; Fri, 1 Aug 2003 16:24:38 +0100
Received: from root by hopnet with local (Exim 3.36 #1 (Debian))
	id 19ibop-0000sU-00; Fri, 01 Aug 2003 16:27:47 +0100
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: rory campbell-lange <rory.l@hopkins.co.uk>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: apache-ssl: ssl-certificate --force fails
X-Mailer: reportbug 2.19
Date: Fri, 01 Aug 2003 16:27:47 +0100
Message-Id: <[🔎] E19ibop-0000sU-00@hopnet>
X-BadReturnPath: root@hopnet.hopkins.co.uk rewritten as rory.l@hopkins.co.uk
  using "From" header
Delivered-To: submit@bugs.debian.org
X-Spam-Status: No, hits=-3.0 required=4.0
	tests=BAYES_10,HAS_PACKAGE,PENISACCENT
	version=2.53-bugs.debian.org_2003_07_20
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 2.53-bugs.debian.org_2003_07_20 (1.174.2.15-2003-03-30-exp)

Package: apache-ssl
Version: 1.3.27.0-2
Severity: normal

See error below (--->).

hopnet:/home/httpd/cgi-bin# ssl-certificate --force

        creating selfsigned certificate
        replace it with one signed by a certification authority (CA)
        
        enter your ServerName at the Common Name prompt
        
        If you want your certificate to expire after x days call this programm
        with -days x
        Generating a 1024 bit RSA private key
        .....................................++++++ .++++++
        writing new private key to '/etc/apache-ssl/apache.pem~new'
        -----
        You are about to be asked to enter information that will be incorporated
        into your certificate request.
        What you are about to enter is what is called a Distinguished Name or a DN.
        There are quite a few fields but you can leave some blank
        For some fields there will be a default value,
        If you enter '.', the field will be left blank.
        -----
        Country Name (2 letter code) [US]:UK
        State or Province Name (full name) []:London
        Locality Name (eg, city) []:London
        Organization Name (eg, company) []:Hopkins Architects
        Organizational Unit Name (eg, section) []:IT Department
        server name (eg. ssl.domain.tld; required!!!) [hopnet]:hopnet.hopkins.co.uk
        Email Address []:it@hopkins.co.uk
        /etc/apache-ssl/apache.pem~new: /C=UK/ST=London/L=London/O=Hopkins Architects/OU=IT Department/CN=hopnet.hopkins.co.uk/emailAddress=it@ hopkins.co.uk
--->    error 18 at 0 depth lookup:self signed certificate OK

-- System Information:
Debian Release: testing/unstable
Architecture: i386
Kernel: Linux hopnet 2.2.14-va.4.4-i586 #1 Tue Sep 5 15:18:51 PDT 2000 i686
Locale: LANG=C, LC_CTYPE=C

Versions of packages apache-ssl depends on:
ii  apache-common                 1.3.27.0-2 Support files for all Apache webse
ii  debconf                       1.2.35     Debian configuration management sy
ii  dpkg                          1.10.10    Package maintenance system for Deb
ii  libc6                         2.3.1-16   GNU C Library: Shared libraries an
ii  libdb4.1                      4.1.25-4   Berkeley v4.1 Database Libraries [
ii  libexpat1                     1.95.6-4   XML parsing C library - runtime li
ii  libmagic1                     4.02-4     File type determination library us
ii  libssl0.9.7                   0.9.7b-2   SSL shared libraries
ii  logrotate                     3.6.5-2    Log rotation utility
ii  mime-support                  3.23-1     MIME files 'mime.types' & 'mailcap
ii  openssl                       0.9.7b-2   Secure Socket Layer (SSL) binary a
ii  perl [perl5]                  5.8.0-18   Larry Wall's Practical Extraction 

-- debconf information excluded


---------------------------------------
Received: (at 203787-done) by bugs.debian.org; 3 Aug 2003 16:24:38 +0000
>From fabbione@fabbione.net Sun Aug 03 11:24:36 2003
Return-path: <fabbione@fabbione.net>
Received: from port5.ds1-sby.adsl.cybercity.dk (trider-g7.fabbione.net) [212.242.169.198] 
	by master.debian.org with esmtp (Exim 3.35 1 (Debian))
	id 19jLeu-0002UO-00; Sun, 03 Aug 2003 11:24:36 -0500
Received: from trider-g7.ext.fabbione.net (port5.ds1-sby.adsl.cybercity.dk [212.242.169.198])
	by trider-g7.fabbione.net (Postfix) with ESMTP id 1CF1636;
	Sun,  3 Aug 2003 18:24:35 +0200 (CEST)
Date: Sun, 3 Aug 2003 18:24:34 +0200 (CEST)
From: Fabio Massimo Di Nitto <fabbione@fabbione.net>
Sender: fabbione@trider-g7.ext.fabbione.net
To: rory campbell-lange <rory.l@hopkins.co.uk>,
	203787-done@bugs.debian.org
Subject: Re: Bug#203787: apache-ssl: ssl-certificate --force fails
In-Reply-To: <[🔎] E19ibop-0000sU-00@hopnet>
Message-ID: <Pine.LNX.4.56.0308031816500.16155@trider-g7.ext.fabbione.net>
References: <[🔎] E19ibop-0000sU-00@hopnet>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Delivered-To: 203787-done@bugs.debian.org
X-Spam-Status: No, hits=-12.5 required=4.0
	tests=BAYES_20,EMAIL_ATTRIBUTION,IN_REP_TO,PENISACCENT,
	      QUOTED_EMAIL_TEXT,REFERENCES,REPLY_WITH_QUOTES,
	      USER_AGENT_PINE
	autolearn=ham version=2.53-bugs.debian.org_2003_07_20
X-Spam-Level: 
X-Spam-Checker-Version: SpamAssassin 2.53-bugs.debian.org_2003_07_20 (1.174.2.15-2003-03-30-exp)

On Fri, 1 Aug 2003, rory campbell-lange wrote:

> --->    error 18 at 0 depth lookup:self signed certificate OK

I am closing this bug for different reasons.

The real problem is openssl. The script performs a call to:
openssl verify <certificate>

and as documented and already reported:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=151197

openssl verify is partially "broken", but this does not affect at all
ssl-certificate functionalities.

The "OK" at the end of the line shows that the entire ssl-certificate
script succeeded.

Thanks
Fabio



Reply to: